A face recognition data protection method and system

Through the combination of quantum key management and the national secret algorithm, the security problem of face information under quantum computing attacks is solved, efficient protection of face information is achieved, and dependence on foreign technologies is reduced.

CN116028955BActive Publication Date: 2025-06-27SHENZHEN GUOXIN QUANTUM TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310097236.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-10
Publication Date
2025-06-27
Estimated Expiration
2043-02-10

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively protect facial information, especially when facing emerging attack methods such as quantum computing, and it depends on foreign technologies and products.

Method used

Quantum key generation and distribution technology is adopted, combined with the Guoxin algorithm, the face feature values ​​are encrypted and decrypted through quantum keys K1 and K2 to ensure the security of the key and resist quantum threats.

Benefits of technology

Ensure the security of the key from a physical level, resist the quantum threats caused by traditional encryption algorithms, improve network throughput and computing power, get rid of dependence on foreign technologies and products, and build an industry network security environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116028955B_ABST
    Figure CN116028955B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of face recognition, and provides a face recognition data protection method and system. The method includes: generating quantum key K1 and quantum key K2; distributing quantum key K1 and quantum key K2; the face registration machine obtaining the first face feature value; the face recognition terminal collecting the second face feature value; the face registration machine encrypting the first face feature value through quantum key K1 and the national cryptography algorithm to generate the encrypted face feature value ciphertext B. The system includes: a quantum key management and service platform, a quantum key distribution network, a face registration machine, a face recognition terminal, a face recognition server, and a plaintext database. The face recognition data protection method and system of the present invention ensure the security of the key from the physical level, can resist the quantum threats suffered by traditional encryption algorithms; get rid of the dependence on foreign technologies and products, and build a network security environment for the industry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of face recognition, and particularly relates to a face recognition data protection method and system. Background Art

[0002] With the continuous development of the digital age, the usage scenarios of personal information have been continuously integrated into all aspects of daily life, and face recognition has become an essential part of functions such as "identity authentication" and "password entry" on mobile devices. According to the compliance key points of the life cycle of personal information such as collection, storage, transmission, and deletion in the Personal Information Protection Law, the encryption and decryption protection of face information have become an important current requirement.

[0003] The national cryptographic algorithm is a domestic cryptographic algorithm recognized by the National Cryptography Administration. It has a wide range of application fields and can be used to encrypt and protect internal information during the transmission process or encryption process, and can also be used for various security certifications, online banking, digital signatures, etc. to prevent illegal third parties from obtaining information content.

[0004] Currently, the rapid development of quantum computing has had a greater impact and threat on current data transmission and identity authentication products based on classical cryptographic algorithms, and the security of online devices and data faces great risks.

[0005] Therefore, implementing the compliance requirements for face information and enabling it to resist emerging attack means such as current quantum computing is an urgent problem to be solved currently. Summary of the Invention

[0006] Aiming at the defects in the prior art, a face recognition data protection method and system provided by the present invention ensure the security of the key from the physical level, can resist the quantum threat to traditional encryption algorithms; get rid of the dependence on foreign technologies and products, and build a network security environment for the industry.

[0007] To solve the above technical problems, the present invention proposes the following technical solutions:

[0008] A face recognition data protection method includes the following steps:

[0009] Generate a quantum key K1 and a quantum key K2;

[0010] Distribute the quantum key K1 and the quantum key K2: Distribute the quantum key K1 to the face registration machine and the face recognition server, distribute the quantum key K2 to the user key storage medium and the face recognition server, and the user key storage medium sends the quantum key K2 to the face recognition terminal;

[0011] The face registration machine obtains a first face feature value;

[0012] The face recognition terminal collects a second face feature value;

[0013] The face registration machine encrypts the first face feature value through the quantum key K1 and the national cryptography algorithm to generate the ciphertext B of the face feature value;

[0014] The face recognition terminal encrypts the second face feature value through the quantum key K2 and the national cryptography algorithm to generate the ciphertext A of the face feature value;

[0015] Send ciphertext B: The face recognition registration machine sends the ciphertext B to the face recognition server;

[0016] Send ciphertext A: The face recognition terminal sends the ciphertext A to the face recognition server;

[0017] The face recognition server decrypts the ciphertext B through the quantum key K1 and the national cryptography algorithm to generate the plaintext B1 of the face feature value;

[0018] The face recognition server decrypts the ciphertext A through the quantum key K2 and the national cryptography algorithm to generate the plaintext A1 of the face feature value;

[0019] Save plaintext B1: The face recognition server saves the plaintext B1 in the plaintext database;

[0020] The plaintext database matches the plaintext A1 with the plaintext B1 to obtain the matching result C1;

[0021] The face recognition server encrypts the matching result C1 through the quantum key K2 and the national cryptography algorithm to obtain the ciphertext C of the matching result C1;

[0022] Send ciphertext C: The face recognition server sends the ciphertext C to the face recognition terminal;

[0023] The face recognition terminal decrypts the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1.

[0024] Further, the process of generating the quantum key K1 and the quantum key K2 includes the following steps:

[0025] Generate quantum random numbers;

[0026] Inject keys;

[0027] Generate the quantum key K1 and the quantum key K2 according to the quantum random numbers and the keys.

[0028] Further, the national cryptography algorithm is one of the SM2 encryption algorithm, the SM3 encryption algorithm, or the SM4 encryption algorithm.

[0029] Further, the process of the face recognition terminal decrypting the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1 includes the following steps:

[0030] When the comparison result C1 is a normal value, the face recognition is successful;

[0031] When the comparison result C1 is an abnormal value, the face recognition fails.

[0032] The present invention also provides a face recognition data protection system, including:

[0033] A quantum key management and service platform, which is used to generate the quantum key K1 and the quantum key K2;

[0034] A quantum key distribution network, which is used to distribute the quantum key K1 and the quantum key K2: distributing the quantum key K1 to the face registration machine and the face recognition server, distributing the quantum key K2 to the user key storage medium and the face recognition server, and the user key storage medium sending the quantum key K2 to the face recognition terminal;

[0035] A face registration machine, which is used to obtain the first face feature value;

[0036] A face recognition terminal, which is used to collect the second face feature value;

[0037] A face registration machine, which is used to encrypt the first face feature value through the quantum key K1 and the national cryptography algorithm to generate the face feature value ciphertext B;

[0038] A face recognition terminal, which is used to encrypt the second face feature value through the quantum key K2 and the national cryptography algorithm to generate the face feature value ciphertext A;

[0039] A face recognition registration machine, which is used to send the ciphertext B to the face recognition server;

[0040] A face recognition terminal, which is used to send the ciphertext A to the face recognition server;

[0041] A face recognition server, which is used to decrypt the ciphertext B through the quantum key K1 and the national cryptography algorithm to generate the face feature value plaintext B1;

[0042] A face recognition server, which is used to decrypt the ciphertext A through the quantum key K2 and the national cryptography algorithm to generate the face feature value plaintext A1;

[0043] A face recognition server, which is used to save the plaintext B1 in the plaintext database;

[0044] A plaintext database, which is used to match the plaintext A1 with the plaintext B1 to obtain the matching result C1;

[0045] A face recognition server, which is used to encrypt the matching result C1 through the quantum key K2 and the national cryptography algorithm to obtain the ciphertext C of the matching result C1;

[0046] A face recognition server, which is used to send the ciphertext C to the face recognition terminal;

[0047] A face recognition terminal, which is used to decrypt the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1.

[0048] Further, the quantum key management and service platform includes:

[0049] A quantum random number generator, which is used to generate quantum random numbers;

[0050] A quantum key injection module, which is used to inject keys;

[0051] A quantum key generator, which is used to generate the quantum key K1 and the quantum key K2 according to the quantum random number and the key.

[0052] Further, the national cryptography algorithm is one of the SM2 encryption algorithm, the SM3 encryption algorithm or the SM4 encryption algorithm.

[0053] Further, the process of the face recognition terminal decrypting the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1 includes the following steps:

[0054] When the comparison result C1 is a normal value, face recognition is successful;

[0055] When the comparison result C1 is an abnormal value, face recognition fails.

[0056] It can be seen from the above technical solutions that the beneficial effects of the present invention are as follows: In the process of secret key distribution, since the quantum satellite randomly sends photons with different polarization states as the carriers of the password, once the quantum is measured, it will be destroyed and it is difficult to be accurately replicated. Therefore, quantum encryption guarantees the security of the key from the physical level; through the combination of the quantum key and the national cryptography algorithm, quantum empowerment is given to the national cryptography algorithm, improving the network throughput and computing power, and being able to resist the quantum threats suffered by the traditional algorithms. Description of the Drawings

[0057] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required to be used in the description of the specific embodiments or the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.

[0058] Figure 1 It is a flowchart of the method of the present invention;

[0059] Figure 2 It is a module diagram of the system of the present invention. Specific embodiments

[0060] The embodiments of the technical solution of the present invention will be described in detail below with reference to the accompanying drawings. The following embodiments are only used to illustrate the technical solution of the present invention more clearly, so they are only examples and cannot be used to limit the protection scope of the present invention.

[0061] Please refer to Figure 1 , a face recognition data protection method provided in this embodiment includes the following steps:

[0062] Generate quantum key K1 and quantum key K2.

[0063] Distribute quantum key K1 and quantum key K2: Distribute quantum key K1 to the face registration machine and the face recognition server, and distribute quantum key K2 to the user key storage medium and the face recognition server. The user key storage medium sends quantum key K2 to the face recognition terminal. During the process of key distribution, since the quantum satellite randomly sends photons with different polarization states as the carrier of the password, once the quantum is measured, it will be destroyed and it is difficult to be accurately replicated. Therefore, quantum encryption guarantees the security of the key from the physical level. The user key storage medium includes, but is not limited to, forms such as Ukey and password cards for storing quantum keys.

[0064] The face registration machine obtains the first face feature value, and the first feature value is the face feature information obtained by the face registration machine from the face information registration terminal. The first face feature value is the face feature value pre-saved by the user before face recognition.

[0065] The face recognition terminal collects the second face feature value, and the second face feature value is the face feature information collected when the user uses the face recognition terminal.

[0066] The face registration machine encrypts the first face feature value through quantum key K1 and the national cryptography algorithm to generate the ciphertext B of the face feature value.

[0067] The face recognition terminal encrypts the second face feature value through quantum key K2 and the national cryptography algorithm to generate the ciphertext A of the face feature value.

[0068] Send ciphertext B: The face recognition registration machine sends ciphertext B to the face recognition server.

[0069] Send ciphertext A: The face recognition terminal sends ciphertext A to the face recognition server.

[0070] The face recognition server decrypts the ciphertext B through the quantum key K1 and the national cryptography algorithm to generate the plaintext B1 of the face feature value.

[0071] The face recognition server decrypts the ciphertext A through the quantum key K2 and the national cryptography algorithm to generate the plaintext A1 of the face feature value.

[0072] Save the plaintext B1: The face recognition server saves the plaintext B1 in the plaintext database.

[0073] The plaintext database matches the plaintext A1 with the plaintext B1 to obtain the matching result C1. The plaintext database is located in the face recognition server.

[0074] The face recognition server encrypts the matching result C1 through the quantum key K2 and the national cryptography algorithm to obtain the ciphertext C of the matching result C1.

[0075] Send the ciphertext C: The face recognition server sends the ciphertext C to the face recognition terminal.

[0076] The face recognition terminal decrypts the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1.

[0077] Encrypt the first face feature value through the face registration machine, encrypt the second face feature value through the face recognition terminal, then decrypt the ciphertext A and the ciphertext B through the face recognition server respectively, match the plaintext A1 and the plaintext B1, encrypt the matching result C1 in the face recognition server, decrypt the received ciphertext C in the face recognition terminal. Through the combination of the quantum key and the national cryptography algorithm, quantum empowerment is given to the national cryptography algorithm, improving the network throughput and computing power, being able to resist the quantum threat to traditional algorithms, and ensuring the security during the transmission of the face feature value.

[0078] In this embodiment, the process of generating the quantum key K1 and the quantum key K2 includes the following steps.

[0079] Generate quantum random numbers.

[0080] Inject keys.

[0081] Generate the quantum key K1 and the quantum key K2 according to the quantum random numbers and the keys. Use the quantum random number generator and the quantum key distribution network to generate true random numbers at high speed, improve the computing power, and be able to resist the quantum threat to traditional encryption algorithms.

[0082] In this embodiment, the national cryptographic algorithm is one of the SM2 encryption algorithm, the SM3 encryption algorithm, or the SM4 encryption algorithm. SM2 has a higher security strength; the algorithm structure of SM3 is the MD (Merkle-Damgard) structure, with stronger collision resistance; SM4 has undergone non-linear transformation and has better security than foreign encryption algorithms. Using the national cryptographic algorithm can get rid of the dependence on foreign technologies and products and build a network security environment for the industry. When in use, the SM2 encryption algorithm, the SM3 encryption algorithm, or the SM4 encryption algorithm can be selected according to the actual situation.

[0083] In this embodiment, the process in which the face recognition terminal decrypts the received ciphertext C through the quantum key K2 and the national cryptographic algorithm to obtain the comparison result C1 includes the following steps.

[0084] When the comparison result C1 is a normal value, face recognition is successful and the user can use it normally.

[0085] When the comparison result C1 is an abnormal value, face recognition fails and the user cannot use it normally.

[0086] Please refer to Figure 2 , a face recognition data protection system, including a quantum key management and service platform, a quantum key distribution network, a face registration machine, a face recognition terminal, a face recognition server, and a plaintext database.

[0087] The quantum key management and service platform is used to generate the quantum key K1 and the quantum key K2.

[0088] The quantum key distribution network is used to distribute the quantum key K1 and the quantum key K2: distribute the quantum key K1 to the face registration machine and the face recognition server, and distribute the quantum key K2 to the user key storage medium and the face recognition server. The user key storage medium sends the quantum key K2 to the face recognition terminal. During the process of key distribution, since the quantum satellite randomly sends photons with different polarization states as the carrier of the password, once the quantum is measured, it will be destroyed and it is difficult to be accurately replicated. Therefore, quantum encryption guarantees the security of the key from a physical level. The user key storage medium includes but is not limited to forms such as Ukey and password cards for storing the quantum key.

[0089] The face registration machine is used to obtain the first face feature value. The first feature value is the face feature information obtained by the face registration machine from the face information registration terminal. The first face feature value is the face feature value pre-saved by the user before face recognition.

[0090] The face recognition terminal is used to collect the second face feature value. The second face feature value is the face feature information collected when the user uses the face recognition terminal.

[0091] The face registration machine is used to encrypt the first face feature value through the quantum key K1 and the national cryptography algorithm to generate the ciphertext B of the face feature value.

[0092] The face recognition terminal is used to encrypt the second face feature value through the quantum key K2 and the national cryptography algorithm to generate the ciphertext A of the face feature value.

[0093] The face recognition registration machine is used to send the ciphertext B to the face recognition server.

[0094] The face recognition terminal is used to send the ciphertext A to the face recognition server.

[0095] The face recognition server is used to decrypt the ciphertext B through the quantum key K1 and the national cryptography algorithm to generate the plaintext B1 of the face feature value.

[0096] The face recognition server is used to decrypt the ciphertext A through the quantum key K2 and the national cryptography algorithm to generate the plaintext A1 of the face feature value.

[0097] The face recognition server is used to save the plaintext B1 in the plaintext database.

[0098] The plaintext database is used to match the plaintext A1 with the plaintext B1 to obtain the matching result C1. The plaintext database is located in the face recognition server.

[0099] The face recognition server is used to encrypt the matching result C1 through the quantum key K2 and the national cryptography algorithm to obtain the ciphertext C of the matching result C1.

[0100] The face recognition server is used to send the ciphertext C to the face recognition terminal.

[0101] The face recognition terminal is used to decrypt the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1.

[0102] By encrypting the first face feature value through the face registration machine, encrypting the second face feature value through the face recognition terminal, then decrypting the ciphertext A and the ciphertext B respectively through the face recognition server, matching the plaintext A1 and the plaintext B1, encrypting the matching result C1 in the face recognition server, decrypting the received ciphertext C in the face recognition terminal, through the combination of the quantum key and the national cryptography algorithm, quantum empowerment is provided for the national cryptography algorithm, the network throughput and computing power are improved, the quantum threat suffered by the traditional algorithm can be resisted, and the security in the transmission process of the face feature value is guaranteed.

[0103] In this embodiment, the quantum key management and service platform includes a quantum random number generator, a quantum key injection module, and a quantum key generator.

[0104] The quantum random number generator is used to generate quantum random numbers.

[0105] The quantum key injection module is used to inject keys.

[0106] The quantum key generator is used to generate quantum keys K1 and K2 based on quantum random numbers and keys. By using the quantum random number generator and the quantum key distribution network, true random numbers can be generated at high speed, the computing power can be improved, and the quantum threats to traditional encryption algorithms can be resisted.

[0107] In this embodiment, the national cryptographic algorithm is one of the SM2 encryption algorithm, the SM3 encryption algorithm, or the SM4 encryption algorithm. SM2 has higher security strength; the algorithm structure of SM3 is the MD (Merkle-Damgard) structure, and the collision resistance is stronger; SM4 has undergone non-linear transformation, and its security is better than that of foreign encryption algorithms. Using the national cryptographic algorithm can get rid of the dependence on foreign technologies and products and build a network security environment for the industry. When in use, the SM2 encryption algorithm, the SM3 encryption algorithm, or the SM4 encryption algorithm can be selected according to the actual situation.

[0108] In this embodiment, the process of the face recognition terminal decrypting the received ciphertext C through the quantum key K2 and the national cryptographic algorithm to obtain the comparison result C1 includes the following steps.

[0109] When the comparison result C1 is a normal value, the face recognition is successful and the user can use it normally.

[0110] When the comparison result C1 is an abnormal value, the face recognition fails and the user cannot use it normally.

[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered by the scope of the claims and the description of the present invention.

Claims

1. A face recognition data protection method, characterized in that, It includes the following steps: Generate quantum key K1 and quantum key K2; Distribute quantum key K1 and quantum key K2: Distribute quantum key K1 to the face registration machine and the face recognition server, distribute quantum key K2 to the user key storage medium and the face recognition server, and the user key storage medium sends quantum key K2 to the face recognition terminal; The face registration machine obtains the first face feature value; The face recognition terminal collects the second face feature value; The face registration machine encrypts the first face feature value through quantum key K1 and the national cryptography algorithm to generate the ciphertext B of the face feature value; The face recognition terminal encrypts the second face feature value through quantum key K2 and the national cryptography algorithm to generate the ciphertext A of the face feature value; Send ciphertext B: The face recognition registration machine sends ciphertext B to the face recognition server; Send ciphertext A: The face recognition terminal sends ciphertext A to the face recognition server; The face recognition server decrypts ciphertext B through quantum key K1 and the national cryptography algorithm to generate the plaintext B1 of the face feature value; The face recognition server decrypts ciphertext A through quantum key K2 and the national cryptography algorithm to generate the plaintext A1 of the face feature value; Save plaintext B1: The face recognition server saves plaintext B1 in the plaintext database; The plaintext database matches plaintext A1 with plaintext B1 to obtain the matching result C1; The face recognition server encrypts the matching result C1 through quantum key K2 and the national cryptography algorithm to obtain the ciphertext C of the matching result C1; Send ciphertext C: The face recognition server sends ciphertext C to the face recognition terminal; The face recognition terminal decrypts the received ciphertext C through quantum key K2 and the national cryptography algorithm to obtain the comparison result C1.

2. The face recognition data protection method according to claim 1, characterized in that, The process of generating quantum key K1 and quantum key K2 includes the following steps: Generate quantum random numbers; Charge the key; Generate quantum key K1 and quantum key K2 according to the quantum random numbers and the key.

3. A face recognition data protection method according to claim 1, characterized in that, The national cryptography algorithm is one of the SM2 encryption algorithm, the SM3 encryption algorithm, or the SM4 encryption algorithm.

4. The face recognition data protection method according to claim 1, characterized in that The process that the face recognition terminal decrypts the received ciphertext C through quantum key K2 and the national cryptography algorithm to obtain the comparison result C1 includes the following steps: When the comparison result C1 is a normal value, face recognition is successful; When the comparison result C1 is an abnormal value, face recognition fails.

5. A face recognition data protection system, characterized in that, It includes: A quantum key management and service platform, which is used to generate quantum key K1 and quantum key K2; A quantum key distribution network, which is used to distribute quantum key K1 and quantum key K2: Distribute quantum key K1 to the face registration machine and the face recognition server, distribute quantum key K2 to the user key storage medium and the face recognition server, and the user key storage medium sends quantum key K2 to the face recognition terminal; A face registration machine, which is used to obtain the first face feature value; A face recognition terminal, which is used to collect the second face feature value; A face registration machine, which is used to encrypt the first face feature value through quantum key K1 and the national cryptography algorithm to generate the ciphertext B of the face feature value; A face recognition terminal, which is used to encrypt the second face feature value through the quantum key K2 and the national cryptography algorithm to generate the ciphertext A of the face feature value; A face recognition registration machine, which is used to send the ciphertext B to the face recognition server; A face recognition terminal, which is used to send the ciphertext A to the face recognition server; A face recognition server, which is used to decrypt the ciphertext B through the quantum key K1 and the national cryptography algorithm to generate the plaintext B1 of the face feature value; A face recognition server, which is used to decrypt the ciphertext A through the quantum key K2 and the national cryptography algorithm to generate the plaintext A1 of the face feature value; A face recognition server, which is used to save the plaintext B1 in the plaintext database; The plaintext database, which is used to match the plaintext A1 with the plaintext B1 to obtain the matching result C1; A face recognition server, which is used to encrypt the matching result C1 through the quantum key K2 and the national cryptography algorithm to obtain the ciphertext C of the matching result C1; A face recognition server, which is used to send the ciphertext C to the face recognition terminal; A face recognition terminal, which is used to decrypt the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1.

6. A face recognition data protection system according to claim 5, characterized in that, The quantum key management and service platform includes: A quantum random number generator, which is used to generate quantum random numbers; A quantum key injection module, which is used to inject keys; A quantum key generator, which is used to generate the quantum key K1 and the quantum key K2 according to the quantum random numbers and the keys.

7. A face recognition data protection system according to claim 5, characterized in that, The national cryptography algorithm is one of the SM2 encryption algorithm, the SM3 encryption algorithm or the SM4 encryption algorithm.

8. A face recognition data protection system according to claim 5, characterized in that, The process that the face recognition terminal decrypts the received ciphertext C through the quantum key K2 and the national cryptography algorithm to obtain the comparison result C1 includes the following steps: When the comparison result C1 is a normal value, the face recognition is successful; When the comparison result C1 is an abnormal value, the face recognition fails.

Citation Information

Patent Citations

  • Information transmission encryption method based on combination of national secret algorithm and quantum communication technology

    CN109462471A

  • Identity recognition system based on quantum confidential data

    CN112926519A