Identity authentication method and system based on block chain

By collecting biometrics and optical flow analysis methods on the user login page, combining blockchain technology to monitor user identity compliance and server risks in real time, the problems of risk assessment lag and information abuse in the existing identity authentication methods are solved, and the security and efficiency of identity authentication are improved.

CN120342624AActive Publication Date: 2025-07-18HEZHENG TECHNOLOGY (YUNNAN) CO LTD

Patent Information

Application Number
CN202510457094.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-13
Publication Date
2025-07-18
Estimated Expiration
2045-04-13

AI Technical Summary

Technical Problem

The existing identity authentication methods lack continuous monitoring of user behavior and device status, and cannot identify abnormal operations after authentication, resulting in lagging risk assessment, and lack of effective supervision of user information when repeated submissions on different platforms, which is easy to be abused.

Method used

By collecting facial recognition confidence and iris matching on the user login page, hash encryption is performed, and combined with optical flow analysis to detect the optical flow change matrix of the facial video stream, calculate the cosine similarity of the facial optical flow, generate hash values and update them to the blockchain, monitor user identity compliance in real time, and collect security assessment data every certain period of time to calculate risk assessment coefficients, and dynamically adjust security protection measures.

Benefits of technology

It improves the security and accuracy of identity authentication, enhances the protection of user information, monitors server authentication access risks in real time, prevents security incidents, and improves information management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342624A_ABST
    Figure CN120342624A_ABST
Patent Text Reader

Abstract

The invention discloses an identity authentication method and system based on a block chain, and particularly relates to the technical field of identity authentication security. Comprising the steps of S01, user login request verification, S02, user identity detection enhancement verification, S03, user identity authentication abnormity control, S04, user access security assessment data acquisition, S05, user access security analysis and S06, user access security assessment. The face recognition confidence, the iris matching degree and the user face video stream are collected on the user login page, the user identity compliance is verified, the safety of identity verification is improved, the authentication accuracy is improved, the safety evaluation data of the authentication server in the block chain network are collected, the user authentication access risk evaluation coefficient is calculated, and the user authentication access risk evaluation efficiency is improved. And the server authentication access risk is monitored, so that the change of the server authentication access risk can be monitored in real time, the occurrence of security events is effectively prevented, and the user information management efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of identity authentication security, and more specifically, to an identity authentication method and system based on blockchain. Background Art

[0002] Blockchain adopts a distributed ledger structure, where data is stored in multiple nodes instead of a single centralized server. Once data is recorded on the blockchain, it is difficult to be tampered with. This immutability feature ensures the authenticity and integrity of user identity information. At the same time, through the traceability function, the source and change records of information can be clearly understood.

[0003] With the acceleration of the digitalization process, various online services and businesses have flourished, covering almost all aspects of people's lives, from social networks, online finance to government services, supply chain management, etc. In this process, identity authentication, as a key link to ensure the security of information systems and confirm the legitimate identity of users, has become increasingly important.

[0004] However, in actual use, there are still some drawbacks. For example, existing identity authentication methods mostly adopt one-time verification, such as password login, lacking continuous monitoring of user behavior and device status, and unable to identify abnormal operations after authentication, resulting in lagging risk assessment.

[0005] In existing identity authentication methods, when users register on different platforms, they need to repeatedly submit personal identity information, which is independently stored and managed by each platform, lacking an effective supervision mechanism, resulting in the easy abuse of user information without authorization. Summary of the Invention

[0006] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides an identity authentication method and system based on blockchain to solve the problems raised in the above background art.

[0007] To achieve the above object, the present invention provides the following technical solution: An identity authentication method based on blockchain, comprising the following steps:

[0008] Step S01: User login request verification: used to verify the credibility of the user's biometric features on the user login page, perform hash encryption on the biometric feature credibility, and send it to the authentication server.

[0009] Step S02: Enhanced verification of user identity detection: based on optical flow analysis, detect the user's facial video stream, extract the optical flow change matrix of consecutive frames, calculate the cosine similarity of the user's facial optical flow, perform hash encryption on the cosine similarity of the facial optical flow, and send it to the authentication server.

[0010] Step S03: Abnormal control of user identity authentication: It is used to verify the compliance of the user's identity through the authentication server and trigger an abnormal risk warning for user identity authentication.

[0011] Step S04: Collection of user access security assessment data: It is used to collect the security assessment data of the authentication server in the blockchain network every j time periods and transmit the security assessment data to Step S05.

[0012] Step S05: Analysis of user access security: It is used to receive the security assessment data transmitted by the user access security assessment data collection step and calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period.

[0013] Step S06: Evaluation of user access security: It is used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the authentication access risk of the server.

[0014] Preferably, the specific content of the said Step S01: Verification of user login request is as follows:

[0015] Step S11: When the user logs in to the page, collect the face recognition confidence and iris matching degree of the user's login device, and mark them as kl i , kh i , where i = 1, 2,... n, and i represents the number of the ith user login device;

[0016] Step S12: The calculation formula of the biometric credibility is as follows:

[0017]

[0018] Among them, HL i represents the biometric credibility of the ith user login device, kl i represents the face recognition confidence of the ith user login device, kh i represents the iris matching degree of the ith user login device, and e represents the natural constant;

[0019] Step S13: Obtain the biometric credibility of the user login device and generate a new hash value to update the blockchain.

[0020] Preferably, the specific content of the said Step S02: Enhanced verification of user identity detection is as follows:

[0021] Step S21: Collect the user's facial video stream of the user login device through the camera, extract the displacement vector between consecutive frames, and generate the optical flow change matrix M of consecutive frames i ;

[0022] Step S22: Convert the optical flow change matrix of consecutive frames into an optical flow change vector V i ;

[0023] Step S23: The calculation formula for the facial optical flow cosine similarity is as follows:

[0024]

[0025] where SV i represents the facial optical flow cosine similarity of the i-th user logging in to the device, V i represents the optical flow change vector of the i-th user logging in to the device, and V 预 represents a preset optical flow change vector;

[0026] Step S23: Obtain the facial optical flow cosine similarity of the user logging in to the device, and generate a new hash value to update the blockchain.

[0027] Preferably, the step S03: User identity authentication exception control is specifically as follows:

[0028] Step S31: Extract the historical hash value of the biometric credibility of the user logging in to the device, where t = 1, 2,... m, and t represents the number of the t-th hash value;

[0029] Step S32: Extract the historical hash value of the facial optical flow cosine similarity of the user logging in to the device,

[0030] Step S33: Perform user identity compliance verification by calculating the user identity compliance scoring index:

[0031]

[0032] where, represents the user identity compliance scoring index of the t-th hash value of the i-th user logging in to the device, represents the biometric credibility hash value of the t-th hash value of the i-th user logging in to the device, represents the biometric credibility hash value of the (t - 1)-th hash value of the i-th user logging in to the device, represents the facial optical flow cosine similarity hash value of the t-th hash value of the i-th user logging in to the device, represents the facial optical flow cosine similarity hash value of the (t - 1)-th hash value of the i-th user logging in to the device;

[0033] Step S34: Obtain the latest user identity compliance scoring index of the authentication server, and compare it with the preset user identity compliance scoring index. If the latest user identity compliance scoring index is greater than the preset user identity compliance scoring index, it indicates that the user login identity verification fails, and the user login page request is rejected. Otherwise, it indicates that the user login identity verification is successful, and step S04 is executed.

[0034] Preferably, the security assessment data includes the number of users with failed authentication, the user identity authentication frequency, the number of occurrences of user information tampering events, and the total number of user information queries and modifications.

[0035] Preferably, the calculation formula for the user authentication access risk assessment coefficient is:

[0036]

[0037] where β u represents the user authentication access risk assessment coefficient in the u-th time period, cp u represents the risk index of the authentication server in the u-th time period, cg u represents the risk rate of user information tampering in the u-th time period, Δcp represents the mean value of the authentication server risk index, Δcg represents the mean value of the user information tampering risk rate, and σ1 and σ2 respectively represent the standard deviations of the authentication server risk index and the user information tampering risk rate;

[0038] Specifically, where q represents the number of time periods.

[0039] Preferably, the user authentication access risk assessment coefficient is specifically:

[0040] Step S51: Calculate the risk index of the authentication server for each time period based on the number of users with failed authentication and the user identity authentication frequency:

[0041]

[0042] where cp u represents the risk index of the authentication server in the u-th time period, ps u represents the number of users with failed authentication in the u-th time period, pd max represents the maximum value of the user identity authentication frequency, ps max represents the maximum value of the number of users with failed authentication, j represents the interval time, and e represents the natural constant;

[0043] Step S52: Calculate the risk rate of user information tampering for each time period based on the number of occurrences of user information tampering events and the total number of user information queries and modifications:

[0044]

[0045] Among them, cg u represents the risk rate of user information tampering in the u-th time period, and gf u represents the number of occurrences of user information tampering events in the u-th time period, and gz u represents the total number of user information queries and modifications in the u-th time period.

[0046] Preferably, the step S06: User access security evaluation is specifically as follows:

[0047] Obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the j-th time period, and compare it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient in a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there is a security risk in the server authentication access during this time period, and the authentication server has a weak ability to protect user information. Notify the administrator to enhance the security protection measures of the authentication server to improve the user information protection ability. On the contrary, if the user authentication access risk assessment coefficient in a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access security is relatively high during this time period, and the authentication server has a strong ability to protect user information, and the current security protection measures can be continued.

[0048] Preferably, a blockchain-based identity authentication system includes:

[0049] User login request verification module: used to verify the biometric credibility of the user on the user login page, perform hash encryption on the biometric credibility, and send it to the authentication server;

[0050] User identity detection enhanced verification module: based on optical flow analysis, detect the user's facial video stream, extract the optical flow change matrix of consecutive frames, calculate the facial optical flow cosine similarity of the user, perform hash encryption on the facial optical flow cosine similarity, and send it to the authentication server;

[0051] User identity authentication exception control module: used to verify the compliance of the user's identity through the authentication server and trigger an alarm for the risk of user identity authentication exception;

[0052] User access security evaluation data collection module: used to collect the security evaluation data of the authentication server in the blockchain network every j time periods, and transmit the security evaluation data to the user access security analysis module;

[0053] User access security analysis module: used to calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period through security assessment data;

[0054] User access security assessment module: used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the server authentication access risk.

[0055] Technical effects and advantages of the present invention:

[0056] 1. The present invention provides a blockchain-based identity authentication method and system. When the user logs in to the page, it collects the face recognition confidence and iris matching degree of the user's login device, verifies the credibility of the user's biometric features, performs hash encryption on the biometric feature credibility, and sends it to the authentication server. It collects the user's facial video stream of the login device through the camera, extracts the displacement vector between consecutive frames, generates the optical flow change matrix of consecutive frames, converts the optical flow change matrix of consecutive frames into an optical flow change vector, calculates the facial optical flow cosine similarity of the user, performs hash encryption on the facial optical flow cosine similarity, and sends it to the authentication server. Furthermore, by calculating the user identity compliance score index, it verifies the user identity compliance and triggers the user identity authentication exception risk warning. It is beneficial to improve the security of user identity verification and enhance the authentication accuracy through multi-factor cross-verification. It is beneficial to provide reliable guarantee for data transmission security by hash encryption transmission, making it difficult for attackers to restore the original information from the encrypted data, and further enhancing the security of identity authentication;

[0057] 2. The present invention provides an identity authentication method and system based on blockchain. By collecting the security assessment data of the authentication server in the blockchain network every j time periods, calculating the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the j-th time period, and comparing it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient in a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there are security risks in the server authentication access during this time period, and the authentication server has weak protection ability for user information. Notify the administrator to enhance the security protection measures of the authentication server and improve the user information protection ability. On the contrary, if the user authentication access risk assessment coefficient in a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access in this time period is relatively secure, and the authentication server has strong protection ability for user information. The current security protection measures can be continued. This is conducive to dynamically tracking the running state of the authentication server, real-time monitoring the changes in the server authentication access risk, thereby taking targeted measures to solve problems, effectively preventing the occurrence of security incidents, improving the risk management efficiency of server authentication access through active monitoring of server authentication access risks, enhancing the initiative of server user information security management, ensuring user information security, and promoting the wide application of blockchain technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 It is a schematic flowchart of an identity authentication method based on blockchain according to the present invention.

[0059] Figure 2 It is a schematic structural diagram of an identity authentication system based on blockchain according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0060] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0061] Please refer to Figure 1 As shown, the present invention provides an identity authentication method based on blockchain, including the following steps:

[0062] Step S01: User login request verification: used to verify the credibility of the user's biometric characteristics on the user login page, perform hash encryption on the biometric credibility, and send it to the authentication server.

[0063] In a possible design, Step S01: User login request verification is specifically:

[0064] Step S11: When the user logs in to the page, collect the face recognition confidence and iris matching degree of the user's login device, and mark them as kl i , kh i , where i = 1, 2,... n, and i represents the number of the i-th user login device;

[0065] Step S12: The calculation formula for the biometric credibility is:

[0066]

[0067] where, HL i represents the biometric credibility of the i-th user login device, kl i represents the face recognition confidence of the i-th user login device, kh i represents the iris matching degree of the i-th user login device, and e represents the natural constant;

[0068] Step S13: Obtain the biometric credibility of the user login device, and generate a new hash value to update the blockchain.

[0069] The said Step S02: Enhanced verification of user identity detection: Detect the user's facial video stream based on optical flow analysis, extract the optical flow change matrix of consecutive frames, calculate the facial optical flow cosine similarity of the user, perform hash encryption on the facial optical flow cosine similarity, and send it to the authentication server.

[0070] In a possible design, the said Step S02: Enhanced verification of user identity detection is specifically:

[0071] Step S21: Collect the user's facial video stream of the user login device through the camera, extract the displacement vector between consecutive frames, and generate the optical flow change matrix M of consecutive frames i ;

[0072] Step S22: Convert the optical flow change matrix of consecutive frames into the optical flow change vector V i ;

[0073] Step S23: The calculation formula for the facial optical flow cosine similarity is:

[0074]

[0075] where, SV i represents the facial optical flow cosine similarity of the i-th user login device, V i represents the optical flow change vector of the i-th user login device, and V 预 represents the preset optical flow change vector;

[0076] Step S23: Obtain the facial optical flow cosine similarity of the user's logged-in device, and generate a new hash value to update the blockchain.

[0077] The said step S03: User identity authentication exception control: It is used to verify the compliance of the user's identity through the authentication server and trigger a risk warning for user identity authentication exceptions.

[0078] In a possible design, the said step S03: User identity authentication exception control is specifically as follows:

[0079] Step S31: Extract the historical hash value of the biometric credibility of the user's logged-in device, where t = 1, 2,... m, and t represents the number of the t-th hash value;

[0080] Step S32: Extract the historical hash value of the facial optical flow cosine similarity of the user's logged-in device,

[0081] Step S33: Verify the compliance of the user's identity by calculating the user identity compliance scoring index:

[0082]

[0083] where, represents the user identity compliance scoring index of the t-th hash value of the i-th user's logged-in device, represents the biometric credibility hash value of the t-th hash value of the i-th user's logged-in device, represents the biometric credibility hash value of the (t - 1)-th hash value of the i-th user's logged-in device, represents the facial optical flow cosine similarity hash value of the t-th hash value of the i-th user's logged-in device, represents the facial optical flow cosine similarity hash value of the (t - 1)-th hash value of the i-th user's logged-in device;

[0084] Step S34: Obtain the latest user identity compliance scoring index of the authentication server, compare it with the preset user identity compliance scoring index. If the latest user identity compliance scoring index is greater than the preset user identity compliance scoring index, it indicates that the user's login identity verification fails, and the user's login page request is rejected. Otherwise, it indicates that the user's login identity verification is successful, and step S04 is executed.

[0085] The present invention provides another specific embodiment as follows:

[0086] The user identity compliance scoring index reflects the dynamic change degree of the user's biometric characteristics and facial optical flow data. The higher the index, the greater the possibility of user identity authentication exception;

[0087] Step S1: The current facial optical flow cosine similarity hash value of a certain user logging in to the device is 120, and the previous facial optical flow cosine similarity hash value is 100;

[0088] Step S2: The current facial optical flow cosine similarity hash value of a certain user logging in to the device is 70, and the previous facial optical flow cosine similarity hash value is 80;

[0089] Step S3: Calculate the user identity compliance scoring index:

[0090]

[0091] Step S4: Set the preset user identity compliance scoring index to 1.0. Since 1.34 > 1.0, it indicates that the user login authentication fails, and the user login page request is rejected.

[0092] The said step S04: User access security assessment data collection: It is used to collect the security assessment data of the authentication server in the blockchain network every j time periods, and transmit the security assessment data to step S05.

[0093] In a possible design, the security assessment data includes the number of users with failed authentication, the user authentication frequency, the number of occurrences of user information tampering events, and the total number of user information queries and modifications.

[0094] The said step S05: User access security analysis: It is used to receive the security assessment data transmitted by the user access security assessment data collection step, and calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period.

[0095] In a possible design, the said step S05: User access security analysis is specifically:

[0096] Step S51: Calculate the risk index of the authentication server for each time period through the number of users with failed authentication and the user authentication frequency:

[0097]

[0098] Among them, cp u represents the risk index of the authentication server in the u-th time period, ps u represents the number of users with failed authentication in the u-th time period, pd max represents the maximum value of the user authentication frequency, ps max represents the maximum value of the number of users with failed authentication, j represents the interval time, and e represents the natural constant;

[0099] Step S52: Calculate the user information tampering risk rate for each time period based on the number of user information tampering events and the total number of user information queries and modifications:

[0100]

[0101] where, cg u represents the user information tampering risk rate for the u-th time period, gf u represents the number of user information tampering events for the u-th time period, gz u represents the total number of user information queries and modifications for the u-th time period;

[0102] Step S53: The calculation formula for the user authentication access risk assessment coefficient is:

[0103]

[0104] where, β u represents the user authentication access risk assessment coefficient for the u-th time period, Δcp represents the average value of the authentication server risk indicators, Δcg represents the average value of the user information tampering risk rate, and σ1 and σ2 respectively represent the standard deviations of the authentication server risk indicators and the user information tampering risk rate;

[0105] Step S54: where, q represents the number of time periods;

[0106] The said Step S06: User access security assessment: It is used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the j-th time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the authentication access risk of the server.

[0107] In a possible design, the said Step S06: User access security assessment is specifically:

[0108] Obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the j-th time period, compare it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient for a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there is a security risk in the server authentication access during this time period, and the authentication server has a weak ability to protect user information. Notify the management staff to enhance the security protection measures of the authentication server and improve the user information protection ability. On the contrary, if the user authentication access risk assessment coefficient for a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access security is relatively high during this time period, and the authentication server has a strong ability to protect user information, and the current security protection measures can be continued.

[0109] Please refer to Figure 2 As shown, the present invention provides a blockchain-based identity authentication system, including:

[0110] User login request verification module: used to verify the credibility of the user's biometric features on the user login page, perform hash encryption on the biometric feature credibility, and send it to the authentication server;

[0111] User identity detection enhanced verification module: based on optical flow analysis, detect the user's facial video stream, extract the optical flow change matrix of consecutive frames, calculate the cosine similarity of the user's facial optical flow, perform hash encryption on the cosine similarity of the facial optical flow, and send it to the authentication server;

[0112] User identity authentication exception control module: used to verify the compliance of the user's identity through the authentication server and trigger an alarm for the risk of user identity authentication exceptions;

[0113] User access security assessment data collection module: used to collect the security assessment data of the authentication server in the blockchain network every j time periods and transmit the security assessment data to the user access security analysis module;

[0114] User access security analysis module: used to calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period through the security assessment data;

[0115] User access security assessment module: used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the authentication access risk of the server.

[0116] In this embodiment, it should be specifically noted that the present invention collects the face recognition confidence and iris matching degree of the user login device when the user logs in to the page, verifies the credibility of the user's biometric features, performs hash encryption on the biometric feature credibility, and sends it to the authentication server. The user's facial video stream of the user login device is collected through the camera, the displacement vector between consecutive frames is extracted, the optical flow change matrix of consecutive frames is generated, the optical flow change matrix of consecutive frames is converted into an optical flow change vector, the cosine similarity of the user's facial optical flow is calculated, and the cosine similarity of the facial optical flow is subjected to hash encryption and sent to the authentication server. Furthermore, by calculating the user identity compliance scoring index, the compliance of the user's identity is verified, and an alarm for the risk of user identity authentication exceptions is triggered. This is beneficial to improving the security of user identity verification and enhancing the authentication accuracy through multi-factor cross-verification. It is beneficial to provide reliable protection for data transmission security by transmitting through hash encryption, making it difficult for attackers to restore the original information from the encrypted data, and further enhancing the security of identity authentication;

[0117] The present invention collects the security assessment data of the authentication server in the blockchain network every j time periods, calculates the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the j-th time period, and compares it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient in a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there are security risks in the server authentication access during this time period, and the authentication server has weak protection ability for user information. The management personnel are notified to enhance the security protection measures of the authentication server to improve the user information protection ability. On the contrary, if the user authentication access risk assessment coefficient in a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access during this time period is relatively secure, and the authentication server has strong protection ability for user information. The current security protection measures can be continued. This is conducive to dynamically tracking the operating status of the authentication server, real-time monitoring the changes in the server authentication access risk, thereby taking targeted measures to solve problems, effectively preventing the occurrence of security incidents, improving the risk management efficiency of server authentication access through active monitoring of server authentication access risks, enhancing the initiative of server user information security management, ensuring user information security, and promoting the wide application of blockchain technology.

[0118] Finally, the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A blockchain-based identity authentication method, characterized in that, It includes the following steps: Step S01: User login request verification: Used to verify the biometric credibility of the user on the user login page, perform hash encryption on the biometric credibility, and send it to the authentication server; Step S02: Enhanced verification of user identity detection: Based on optical flow analysis, detect the user's facial video stream, extract the optical flow change matrix of consecutive frames, calculate the cosine similarity of the user's facial optical flow, perform hash encryption on the cosine similarity of the facial optical flow, and send it to the authentication server; Step S03: Abnormal control of user identity authentication: Used to verify the compliance of the user's identity through the authentication server and trigger an alarm for the risk of abnormal user identity authentication; Step S04: Collection of user access security assessment data: Used to collect the security assessment data of the authentication server in the blockchain network every j time periods and transmit the security assessment data to Step S05; Step S05: Analysis of user access security: Used to receive the security assessment data transmitted by the user access security assessment data collection step and calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the jth time period; Step S06: Assessment of user access security: Used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the jth time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the authentication access risk of the server.

2. The identity authentication method based on blockchain according to claim 1, characterized in that: The specific content of Step S01: User login request verification is as follows: Step S11: When the user logs in to the page, collect the face recognition confidence and iris matching degree of the user's logged-in device, and mark them as kl i , kh i , where i = 1, 2,... n, and i represents the number of the i-th user's logged-in device; Step S12: The calculation formula for the biometric credibility is: Among them, HL i represents the biometric credibility of the i-th user logging in to the device, kl i represents the face recognition confidence of the i-th user logging in to the device, kh i represents the iris matching degree of the i-th user logging in to the device, and e represents the natural constant; Step S13: Obtain the biometric credibility of the user login device and generate a new hash value to update the blockchain.

3. The method for blockchain-based identity authentication according to claim 1, wherein: The specific content of Step S02: Enhanced verification of user identity detection is as follows: Step S21: Collect the user's facial video stream of the device logged in by the user through the camera, extract the displacement vectors between consecutive frames, and generate the optical flow change matrix M of consecutive frames i ; Step S22: Convert the optical flow change matrix of consecutive frames into an optical flow change vector V i ; Step S23: The calculation formula for the cosine similarity of the facial optical flow is: Among them, SV i represents the facial optical flow cosine similarity of the i-th user logging in to the device, and V i represents the optical flow change vector of the i-th user logging in to the device, and V 预 represents a preset optical flow change vector; Step S23: Obtain the cosine similarity of the facial optical flow of the user login device and generate a new hash value to update the blockchain.

4. The identity authentication method based on blockchain according to claim 3, characterized in that: The specific content of Step S03: Abnormal control of user identity authentication is as follows: Step S31: Extract the historical hash value of the biometric credibility of the user's logged-in device, where t = 1, 2,... m, and t represents the number of the t-th hash value; Step S32: Extract the historical hash value of the facial optical flow cosine similarity of the user's logged-in device, Step S33: Verify the compliance of the user's identity by calculating the user identity compliance score index: Among them, represents the user identity compliance scoring index of the t-th hash value of the i-th user's logged-in device, represents the biometric credibility hash value of the t-th hash value of the i-th user's logged-in device, represents the biometric credibility hash value of the (t - 1)-th hash value of the i-th user's logged-in device, represents the facial optical flow cosine similarity hash value of the t-th hash value of the i-th user's logged-in device, represents the facial optical flow cosine similarity hash value of the (t - 1)-th hash value of the i-th user's logged-in device; Step S34: Obtain the latest user identity compliance score index of the authentication server, compare it with the preset user identity compliance score index. If the latest user identity compliance score index is greater than the preset user identity compliance score index, it indicates that the user login identity verification fails, and the user login page request is rejected. Otherwise, it indicates that the user login identity verification is successful, and Step S04 is executed.

5. The method for blockchain-based identity authentication according to claim 1, wherein: The security assessment data includes the number of users with failed identity verification, the frequency of user identity verification, the number of occurrences of user information tampering events, and the total number of user information queries and modifications.

6. The method for blockchain-based identity authentication according to claim 1, characterized in that: The calculation formula for the user authentication access risk assessment coefficient is: Among them, β u represents the user authentication access risk assessment coefficient for the u-th time period, cp u represents the authentication server risk index for the u-th time period, cg u represents the user information tampering risk rate for the u-th time period, Δcp represents the mean value of the authentication server risk index, Δcg represents the mean value of the user information tampering risk rate, and σ1 and σ2 respectively represent the standard deviations of the authentication server risk index and the user information tampering risk rate; Specifically, where q represents the number of time periods.

7. An identity authentication method based on blockchain according to claim 6, characterized in that: The specific content of the user authentication access risk assessment coefficient is: Step S51: Calculate the risk indicators of the authentication server for each time period through the number of users with failed identity verification and the frequency of user identity verification: Among them, cp u represents the risk index of the authentication server in the u-th time period, ps u represents the number of users with authentication failures in the u-th time period, pd max represents the maximum value of the user authentication frequency, ps max represents the maximum value of the number of users with authentication failures, j represents the interval time, and e represents the natural constant; Step S52: Calculate the risk rate of user information tampering for each time period through the number of occurrences of user information tampering events and the total number of user information queries and modifications: Among them, cg u represents the risk rate of user information tampering in the u-th time period, gf u represents the number of occurrences of user information tampering events in the u-th time period, gz u represents the total number of user information queries and modifications in the u-th time period.

8. The identity authentication method based on blockchain according to claim 1, wherein: The specific content of Step S06: Assessment of user access security is as follows: Obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the j-th time period, and compare it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient for a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there are security risks in the server authentication access during this time period, and the authentication server has weak protection capabilities for user information. Notify the administrator to enhance the security protection measures of the authentication server and improve the user information protection capabilities. On the contrary, if the user authentication access risk assessment coefficient for a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access is relatively secure during this time period, and the authentication server has strong protection capabilities for user information. The current security protection measures can be continued.

9. A blockchain-based identity authentication system that uses a blockchain-based identity authentication method as described in any one of claims 1-8, characterized in that: Including: User login request verification module: used to verify the credibility of the user's biometric characteristics on the user login page, perform hash encryption on the biometric credibility, and send it to the authentication server; User identity detection enhanced verification module: based on optical flow analysis, detect the user's facial video stream, extract the optical flow change matrix of consecutive frames, calculate the facial optical flow cosine similarity of the user, perform hash encryption on the facial optical flow cosine similarity, and send it to the authentication server; User identity authentication exception control module: used to verify the compliance of the user's identity through the authentication server and trigger an alarm for the risk of user identity authentication exceptions; User access security assessment data collection module: used to collect the security assessment data of the authentication server in the blockchain network every j time periods and transmit the security assessment data to the user access security analysis module; User access security analysis module: used to calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the j-th time period through the security assessment data; User access security assessment module: used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network for the j-th time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the server authentication access risk.

Citation Information

Patent Citations

  • Science and technology service platform cross-domain identity authentication scheme based on a block chain

    CN113676447A

  • Heterogeneous identity alliance risk assessment system and method based on block chain, and terminal

    CN114139203A

  • Zero-trust network access control method and system based on time window dynamic switching

    CN116545731A

  • Method for enhancing cross-domain identity authentication security of block chain

    CN117353892A

  • Network data information security protection method based on block chain technology

    CN118013560A

Cited By

  • AI identity authentication system and method based on user behaviors

    CN120639506A

  • AI identity authentication system and method based on user behavior

    CN120639506B

  • Multi-party protocol remote signing system and signing method based on block chain technology

    CN121000365A