在线指纹认证 [英] Online fingerprint authentication

查看:138
本文介绍了在线指纹认证的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

该公司有一个基于Web的打孔卡应用程序,但我的老板想让员工使用其指纹而不是可共享的密码进行打孔和打孔.是否可以使用任何免费/开源/商业SDK?使用基于Java或ActiveX的可嵌入组件?

The company has a web-based punch card application, but my boss wants to make employees punch in and out using their fingerprint rather than sharable passwords. Is there any free/open source/commercial SDKs that can be used? With a Java or ActiveX based embeddable component?

谢谢.

推荐答案

您正在使用哪个指纹识别器?

Which fingerprint reader are you using?

1)Microsoft指纹读取器(以前为Digital Persona) 2)Eikon阅读器 3)其他?

1) Microsoft Fingerprint Reader (Formerly Digital Persona) 2) Eikon Reader 3) Other?

一个简单的解决方案是利用其中一个附带的自动表格填充工具,并围绕密码预定义64+字节长的随机数据块建立密码系统.保留基于Web的系统,但要使用最小限度的表单(建议不要通过javascript输入客户端密码),并说明用户应触摸指纹扫描仪以进行打入/打出.

An easy solution is to take advantage of the automatic form-filling tools that come with either, and build a password system around that where the passwords are predefined 64+ byte long random blocks of data. Keep your web-based system but have a very minimal form that discourages entering the password client-side (through javascript), and explains that the user should touch the fingerprint scanner to punch in/out.

如果可能的话,请每位员工使用他们的指纹设置自动登录,然后将他们移开视线,然后私下输入密码,而无需他们注视,从而使他们进入注册系统.

If possible, take each employee through the registration system by having them setup an auto-login with their fingerprint, having them look away and then privately entering the password without them watching.

当然,技术娴熟的员工很容易在以后使用星号键(在Windows上)或dom Explorer/Debugger等工具对其进行黑客入侵,但它应该提供最低级别的安全性,至少不会与您当前的系统一样容易共享(我收集的是您的目标).

Of course this is easily hacked by a tech-savy employee using a tool like asterisk key (on windows) or a dom explorer / debugger later but it should provide a minimum level of security and at the very least won't be as easily shared as your current system (which I gather is your goal).

此外,指纹对于确定的攻击实际上并不能提供任何类型的安全性.愚蠢的腻子,强力胶水和五分钟时间可以可靠地复制周围的任何印刷品.只要您接受此问题,就可以了.

Also, fingerprints don't really provide any type of security for a determined attack. Silly putty, superglue, and five minutes can reliably replicate any prints lying around. As long as you accept this issue you'll be OK.

这篇关于在线指纹认证的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆