Intelligent warehouse login verification method and system based on dynamic living body detection

By collecting and analyzing users' real-time interactive action data, generating liveness verification confidence and identity vectors, and performing dynamic password-enhanced authentication and permission matching, the problems of identity extraction and automatic permission matching in the warehousing system are solved, thereby improving the security and convenience of the system.

CN120675759APending Publication Date: 2025-09-19SHANDONG LUNENG SOFTWARE TECH
View PDF 0 Cites 6 Cited by

Patent Information

Application Number
CN202510810136.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing liveness detection technology lacks the ability to accurately extract user identity identifiers and effectively associate permissions in warehousing systems, making it impossible to automatically match permissions. In addition, the authentication process is not secure enough and can be easily cracked.

Method used

By collecting the user's real-time interactive action data, using the preset liveness detection algorithm to perform dynamic biometric analysis, the liveness verification confidence and user identity identification vector are generated, based on which dynamic password enhanced authentication is performed, and storage permissions are automatically matched to generate a multi-layer encrypted dynamic access token.

Benefits of technology

The security and convenience of logging into the warehouse system have been improved, ensuring that only legitimate users can log in according to their permissions, reducing the risk of illegal intrusion and simplifying the operating process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675759A_ABST
    Figure CN120675759A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, provides an intelligent warehouse login verification method and system based on dynamic living body detection, and is used for realizing accurate generation of an identity label vector, enhanced authentication of a dynamic password and automatic matching of warehouse authority while accurately performing living body detection. And the security and convenience of warehousing system login are comprehensively improved. The method comprises the following steps: collecting real-time interaction action data of a warehousing system login user, calling a preset living body detection algorithm to carry out dynamic biological characteristic analysis on the real-time interaction action data, and generating a living body verification confidence coefficient and a user identity identification vector; performing dynamic password enhanced authentication according to the living body verification confidence coefficient and a preset security authentication threshold value, and generating a dynamic access token containing multiple layers of encryption identifiers; and based on the user identity identification vector and the dynamic access token, executing storage permission automatic matching processing, and outputting a login verification result associated with the user permission level to the storage system according to the permission matching label.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology, and in particular relates to an intelligent warehouse login verification method and system based on dynamic liveness detection. Background Art

[0002] With the advancement of digitalization, liveness detection technology has become a key security measure in various systems. Liveness detection aims to distinguish real people from forgeries like photos and videos through various technical methods. Initially, it relied on simple image comparison. As forgery technology has advanced, liveness detection has evolved into multi-dimensional detection methods based on motion and expression.

[0003] However, existing liveness detection technology applications have numerous shortcomings. Traditional liveness detection focuses solely on whether a person is alive, lacking the ability to accurately extract user identities and effectively link them to permissions. This inability to automatically match permissions results in inefficient and inefficient system permissions management. Traditional technologies also offer inadequate security for authentication, with single authentication methods easily vulnerable to cracking and unable to effectively defend against increasingly sophisticated intrusion methods. Summary of the Invention

[0004] The present invention provides an intelligent warehouse login verification method and system based on dynamic liveness detection, which is used to accurately perform liveness detection while achieving precise generation of identity identification vectors, dynamic password-enhanced authentication, and automatic matching of warehouse permissions, thereby comprehensively improving the security and convenience of warehouse system login.

[0005] In the first aspect, an embodiment of the present invention provides an intelligent warehouse login verification method based on dynamic liveness detection, which is applied to an intelligent warehouse login verification system, and the method includes: collecting real-time interactive action data of users logging into the warehouse system, the real-time interactive action data including limb movement trajectories and biometric responses generated when the users logging into the warehouse system execute dynamic verification instructions; calling a preset liveness detection algorithm to perform dynamic biometric analysis on the real-time interactive action data, and generate a liveness verification confidence and a user identity identification vector; performing dynamic password enhanced authentication based on the liveness verification confidence and a preset security authentication threshold, and generating a dynamic access token containing multiple layers of encrypted identification; performing automatic warehouse permission matching processing based on the user identity identification vector and the dynamic access token, and outputting a login verification result associated with the user permission level to the warehouse system according to the permission matching label.

[0006] In a second aspect, an embodiment of the present invention provides an intelligent warehouse login verification system, which includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the above method.

[0007] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, which includes a computer program. When the computer program runs on an intelligent warehouse login verification system, the computer program is used to enable the intelligent warehouse login verification system to execute the steps of the above method.

[0008] The embodiment of the present invention creatively realizes the intelligent and secure login verification of the warehousing system. First, by collecting real-time interactive action data covering limb movement trajectory and biometric response, the user's dynamic information can be fully obtained; wherein, the preset liveness detection algorithm is used for dynamic biometric analysis, which can accurately generate liveness verification confidence and user identity identification vector, thereby effectively judging whether it is a real user; further based on the liveness verification confidence and security authentication threshold, dynamic password enhanced authentication is carried out, which can generate multi-layer encrypted dynamic access tokens, thereby improving the security of authentication; finally, the warehouse permissions are automatically matched and the login verification results are output, which not only ensures that only legitimate users can log in according to the permissions, but also simplifies the operation process, reduces the risk of illegal intrusion, and provides efficient and secure identity authentication for the warehousing system. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 A flow chart of an intelligent warehouse login verification method based on dynamic liveness detection provided by an embodiment of the present invention.

[0010] Figure 2 This is a structural diagram of an intelligent warehouse login and verification system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0011] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the technical solutions of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments described in the present invention document without making any creative efforts shall fall within the scope of protection of the technical solutions of the present invention.

[0012] See also Figure 1 , which is an intelligent warehouse login verification method based on dynamic liveness detection provided in an embodiment of the present invention. This method can be applied to an intelligent warehouse login verification system. The specific process is as follows: Step 101 to Step 104.

[0013] Step 101: Collecting real-time interactive action data of a user logged into the warehousing system, wherein the real-time interactive action data includes a body movement trajectory and a biometric response generated when the user logged into the warehousing system executes a dynamic verification instruction.

[0014] In the intelligent warehousing system login scenario, when the user initiates a login request, the system will start the data collection process.

[0015] For the collection of limb motion trajectories, take the movement of various parts of the user's body during the login verification process of the terminal device as an example. For example, when the user's hand clicks the screen, slides the operating lever, etc., a series of position change information in space will be generated. The above information is recorded in the form of three-dimensional coordinates to form limb motion trajectory data, which can be represented as an LM trajectory set, where each position information is an element in the set.

[0016] For biometric responses, such as changes in a user's bioelectrical signals during an action, these changes are captured by specialized sensors and converted into corresponding electrical signal data. This data is then aggregated into real-time interactive action data, ensuring its integrity and accuracy for subsequent analysis.

[0017] In an optional embodiment, step 101 includes: Step 1011: Send the dynamic verification instruction to the user terminal corresponding to the user who logs into the warehousing system, where the dynamic verification instruction includes at least one set of preset action combinations and corresponding execution time windows.

[0018] Optionally, the system sends dynamic verification instructions to the terminal device of each logged-in user. Taking the terminal device of a certain user U as an example, the system will send a set of preset action combinations, such as requiring the user to first click a series of specified icons on the screen in a common order, recorded as icon sequence I. The order of the click actions and the duration of each click action constitute this set of preset action combinations. At the same time, an execution time window is set for this set of preset action combinations, for example, starting from the moment the system sends the instruction and ending at the set time, recorded as time interval T. The user needs to complete the specified action combination within this time interval to ensure the real-time and effectiveness of the verification.

[0019] Step 1012: Collecting three-dimensional limb motion trajectory data, touch surface pressure data, and bioelectric response signals generated by the user logged into the warehouse system performing the at least one set of preset action combinations within the execution time window.

[0020] When the user performs a preset action combination within the execution time window T, the system starts to collect various types of data. For three-dimensional limb motion trajectory data, taking the motion trajectory of the user's hand in three-dimensional space when clicking on the icon sequence I as an example, the built-in spatial positioning sensor is used to obtain the three-dimensional coordinate information of the hand at different times in real time to form a three-dimensional limb motion trajectory data set LM3D. Each element in the set is a three-dimensional coordinate value at a certain moment. In terms of touch surface pressure data, when the user clicks on the icon on the screen, the pressure sensor at the bottom of the screen will sense the size and change of the click pressure. The above pressure information forms a touch surface pressure data set TP. The elements in the set correspond to the pressure values ​​of different click actions. The bioelectric response signal is the bioelectric signal emitted by the user's body collected by the bioelectric monitoring device worn by the user during the user's operation, forming a bioelectric response signal set BE. The elements in the set are the bioelectric signal intensity values ​​at different times.

[0021] Step 1013: perform spatial normalization processing on the three-dimensional limb motion trajectory data to generate a limb motion trajectory vector; perform dynamic gradient analysis on the touch surface pressure data to extract the pressure change feature vector; perform time-frequency decomposition on the bioelectric response signal to generate a biometric response spectrum feature.

[0022] The 3D limb motion trajectory data set LM3D is spatially normalized. First, a standard spatial reference frame is determined. Each 3D coordinate value in the set is mapped to this standard frame according to certain transformation rules, ensuring that the limb motion trajectory data of different users has a uniform spatial scale and direction. For example, each dimension of all coordinate values ​​is normalized by dividing the coordinate value by the maximum value in that dimension, so that the coordinate value is within the range of 0 to 1. After this process, the limb motion trajectory vector LMV is formed.

[0023] Dynamic gradient analysis is performed on the touch surface pressure data set TP. The pressure difference between adjacent time points is calculated—that is, the pressure value at the next time point minus the pressure value at the previous time point—to obtain the pressure change value. Statistical analysis is then performed on these pressure change values, such as calculating the mean and standard deviation. These statistics form the pressure change characteristic vector (PCV), which reflects the characteristics of the pressure change.

[0024] A time-frequency decomposition is performed on the bioelectric response signal set BE. Common time-frequency analysis algorithms, such as the wavelet transform, are used to convert the bioelectric response signal from the time domain to the frequency domain. The distribution of the signal across different frequency components is analyzed, and information such as the energy distribution in different frequency bands is obtained. This information constitutes the biosignature response spectrum feature (BSF), providing a more comprehensive understanding of the characteristics of the bioelectric signal.

[0025] Step 1014: performing time-series alignment and fusion on the limb motion trajectory vector, the pressure change feature vector, and the biometric response spectrum feature to form the real-time interactive action data.

[0026] First, based on the timestamp information, the limb motion trajectory vector LMV, the pressure change feature vector PCV, and the biometric response spectrum feature BSF are time-aligned. This ensures that the elements in each vector correspond in time, that is, different types of features at the same moment can be accurately matched. Then, a splicing method is used to fuse the three vectors, arranging them in a certain order. For example, the limb motion trajectory vector is placed first, followed by the pressure change feature vector, and finally the biometric response spectrum feature. This forms a new real-time interactive action data vector RID that integrates multiple features, completing the data collection and preliminary processing.

[0027] Step 102: Calling a preset liveness detection algorithm to perform dynamic biometric analysis on the real-time interactive action data to generate a liveness verification confidence level and a user identity identification vector.

[0028] Among them, the system starts the preset liveness detection algorithm and analyzes the collected real-time interactive action data vector RID. The algorithm is designed to determine whether the current operation is performed by a real living user and extract the user's identity information.

[0029] In an optional embodiment, step 102 includes: Step 1021: Extracting the spatiotemporal correlation features of the real-time interactive action data through the spatiotemporal feature encoding layer of the liveness detection algorithm; wherein the spatiotemporal correlation features include: acceleration continuity representation of limb motion trajectory, dynamic symmetry parameters of pressure distribution, and quantitative indicators of synchronization between bioelectric signals and action execution.

[0030] At the spatiotemporal feature encoding layer, for limb motion trajectories, the rate of change of elements in the limb motion trajectory vector (LMV) at adjacent moments, i.e., acceleration, is calculated. Acceleration continuity over time is analyzed by calculating the difference between adjacent acceleration values ​​and performing statistical analysis to obtain the acceleration continuity representation (ACR). This representation indicates whether limb motion exhibits a natural pattern of acceleration change.

[0031] For pressure distribution, analyze the spatial and temporal distribution of pressure values ​​in the touch surface pressure data set TP. Calculate the center of the pressure distribution and observe the symmetry of the pressure values ​​around the center. Using common calculation methods, such as calculating the symmetry moment of the pressure distribution, we obtain the dynamic symmetry parameter (PSP) of the pressure distribution, which is used to measure the symmetry characteristics of the pressure distribution.

[0032] For the synchronization between bioelectric signals and action execution, the time series of the bioelectric response signal set BE and the limb motion trajectory vector LMV are compared to determine the corresponding time points of the bioelectric signal changes and the limb movement execution, calculate the time delay between the two, and perform statistical analysis to obtain the quantitative index SSI of synchronization between bioelectric signals and action execution, so as to evaluate the degree of synchronization between bioelectric signals and actions. The above-mentioned spatiotemporal correlation features together constitute the feature set used for subsequent analysis.

[0033] Step 1022: Input the spatiotemporal correlation features into the biometric feature discrimination layer of the liveness detection algorithm for discrimination processing to generate liveness discrimination features that characterize the dynamic consistency of the user's biometric features.

[0034] A set of spatiotemporal correlation features, including acceleration continuity (ACR), the dynamic symmetry parameter (PSP) of pressure distribution, and the quantification of synchronization between bioelectric signals and action execution (SSI), are input into the biometric discrimination layer. This layer uses common discrimination algorithms, such as machine learning-based classification algorithms, to compare the input features with pre-defined real-life feature models. These features are analyzed to determine whether they conform to the characteristic patterns of real-life users during operation. By calculating metrics such as similarity and distance between features, a corresponding calculation and judgment process is used to generate liveness discrimination features (LDFs) that represent the dynamic consistency of the user's biometrics, thereby determining whether the current operation is from a real live user.

[0035] Step 1023: Compare the liveness discrimination feature with the preset discrimination feature, and generate the liveness verification confidence level according to the comparison result.

[0036] In an embodiment of the present invention, the generated liveness discrimination feature LDF is compared in detail with the preset discrimination feature. The preset discrimination feature is a standard feature pattern obtained by training based on a large amount of real live and non-live sample data. The similarity score between the liveness discrimination feature LDF and the preset discrimination feature is calculated. For example, the cosine similarity algorithm is used to calculate the cosine value of the angle between the two feature vectors. The closer the cosine value of the angle is to 1, the higher the similarity. According to the similarity score, the similarity score is mapped to a confidence interval of 0 to 1 through a pre-set conversion rule to generate a liveness verification confidence LC, which is used to indicate the possibility that the current operation is a real live operation.

[0037] Step 1024: When the liveness verification confidence meets the preset security baseline condition, the spatiotemporal correlation features are mined by the identity feature extraction layer of the liveness detection algorithm to generate the user identity identification vector containing the user's biological behavior state identification.

[0038] Optionally, when the liveness verification confidence level (LC) is greater than or equal to a preset security baseline condition (e.g., the corresponding baseline value; it should be noted that the dimensions of the liveness verification confidence level (LC) and the baseline value are unified through existing algorithms), it indicates that the current operation is likely to be performed by a real live user. At this point, the identity feature extraction layer is activated. This layer conducts in-depth mining of the spatiotemporal correlation feature set, using commonly used feature extraction algorithms, such as principal component analysis (PCA) to analyze the acceleration continuity representation (ACR), the dynamic symmetry parameter (PSP) of the pressure distribution, and the synchronization quantitative index (SSI) between the bioelectric signal and the action execution. This layer extracts identification information that can represent the user's unique bio-behavioral state. This identification information is organized and encoded to form a user identity identification vector (UIV) containing the user's bio-behavioral state identifier, which is used for subsequent identity confirmation and permission matching operations.

[0039] Step 103: Perform dynamic password enhanced authentication based on the liveness verification confidence and a preset security authentication threshold, and generate a dynamic access token containing multiple layers of encrypted identifiers.

[0040] Optionally, the system compares and analyzes the liveness verification confidence LC with a preset security authentication threshold to determine the encryption strength of the dynamic password and generates a multi-layer encrypted dynamic access token to ensure the security of system access.

[0041] In an optional embodiment, step 103 includes: Step 1031: dynamically compare the liveness verification confidence with the security authentication threshold, and determine the encryption strength level of the dynamic password according to the difference interval of the confidence deviation from the threshold.

[0042] First, the difference between the liveness verification confidence level (LC) and the preset security authentication threshold (ST) is calculated. If the difference is greater than the set positive threshold (D1), the liveness verification confidence level is high, and the dynamic password encryption strength level is determined to be low, for example, EL1. If the difference is less than the negative threshold (-D1) and greater than the negative threshold (-D2) (D2 > D1), the encryption strength level is medium, EL2. If the difference is less than the negative threshold (-D2), the liveness verification confidence level is low, and the encryption strength level is high, EL3. Through this dynamic comparison and difference interval judgment, the appropriate encryption strength level is determined to balance security and verification efficiency.

[0043] Step 1032: Based on the encryption strength level, at least two encryption algorithms are selected from a preset asymmetric encryption algorithm pool for combination to generate a multi-layer nested encryption algorithm combination.

[0044] In an embodiment of the present invention, the preset asymmetric encryption algorithm pool includes a variety of different commonly used encryption algorithms, such as Algorithm A, Algorithm B, and Algorithm C. When the encryption strength level is EL1, Algorithm A and Algorithm B are selected from the algorithm pool for combination; when the encryption strength level is EL2, Algorithm B and Algorithm C are selected for combination; when the encryption strength level is EL3, Algorithm A, Algorithm B, and Algorithm C are selected for combination. The selected encryption algorithms are nested in a certain order. For example, Algorithm A is used to encrypt the data for the first time, and then the encrypted result is used as input and Algorithm B is used for the second encryption. At the EL3 level, Algorithm C is used for the third encryption. This forms a multi-layer nested encryption algorithm combination EAC to ensure encryption strength and security.

[0045] Step 1033: extract the biometric behavior state identifier from the user identity identifier vector, and concatenate the biometric behavior state identifier with the real-time generated timestamp to form a dynamic password factor.

[0046] Optionally, the biometric behavior status identifier (BBSI) is extracted from the user identity vector (UIV). Simultaneously, the system generates a timestamp (TS) in real time, which records the time of the current operation. The BBSI and timestamp (TS) are concatenated in a specific order (e.g., placing the BBSI first and the timestamp after) to form the dynamic password factor (DPF), which provides the basis for subsequent encryption operations.

[0047] Step 1034: Perform layer-by-layer nested encryption processing on the dynamic password factor through the encryption algorithm combination, embed the algorithm identifier corresponding to the selected encryption algorithm in the encryption algorithm combination after each layer of encryption, and generate an intermediate encryption identifier.

[0048] In this embodiment of the present invention, a multi-layered, nested encryption algorithm combination (EAC) is used to encrypt the dynamic password factor (DPF). First, the dynamic password factor (DPF) is encrypted using the first encryption algorithm in the combination (e.g., Algorithm A), resulting in the first encryption result (E1). Algorithm A's identifier (IA) is then embedded in E1, indicating that this layer of encryption was performed using Algorithm A. Next, E1, with the identifier, is encrypted using the second encryption algorithm in the combination (e.g., Algorithm B), resulting in the second encryption result (E2). Algorithm B's identifier (IB) is then embedded in E2. At the EL3 level, E2 is encrypted using Algorithm C, resulting in the third encryption result (E3). Algorithm C's identifier (IC) is then embedded in E2. These encryption results (E1, E2, and E3) with the algorithm identifiers together constitute the intermediate encryption identifier (IEI).

[0049] Step 1035: Concatenate the intermediate encryption identifiers in order of encryption levels, and set an integrity verification code based on a dynamic check code at the end of the concatenation sequence to generate a dynamic access token containing the multiple layers of encryption identifiers.

[0050] Optionally, the intermediate encrypted identifiers IEI are concatenated in order of the encryption hierarchy. Specifically, the first encryption result E1, the second encryption result E2 (and E3, if a third encryption is performed), and so on are concatenated in sequence to form a continuous sequence of encrypted identifiers. A dynamic checksum is then calculated for this sequence, for example, using a hash algorithm to generate a checksum value. This checksum is then appended to the end of the concatenated sequence as the integrity verification code ICV. Ultimately, this sequence of multiple layers of encrypted identifiers and integrity verification codes constitutes the dynamic access token DAT, which is used for subsequent authorization verification and system access.

[0051] Step 104: Performing automatic storage authority matching processing based on the user identity vector and the dynamic access token, and outputting a login verification result associated with the user authority level to the storage system according to the authority matching tag.

[0052] Optionally, the system uses the user identity vector UIV and the dynamic access token DAT to perform automatic matching operations of storage permissions to determine the user's permission level and output the corresponding login verification result to the storage system.

[0053] In an optional embodiment, step 104 includes: Step 1041: parse the multi-layer encryption identifier from the dynamic access token, perform layer-by-layer reverse verification on the multi-layer encryption identifier based on a preset integrity verification code, strip off the algorithm identifier corresponding to each layer of encryption identifier and extract the original spliced ​​data of the dynamic password factor.

[0054] First, the multi-layer encrypted identification components are separated from the dynamic access token (DAT). Then, the multi-layer encrypted identification components are reverse-verified layer by layer based on the preset integrity verification code (ICV). Starting from the last layer of encrypted identification, the corresponding decryption algorithm (corresponding to the encryption algorithm) is used for decryption. During the decryption process, the algorithm identifier corresponding to each layer of encrypted identification is stripped off. For example, from the encryption result containing the algorithm C identifier (IC), the decryption algorithm of algorithm C is used to decrypt the previous layer of encryption, and the IC is stripped off. This process continues until all layers of reverse verification and decryption operations are completed, ultimately extracting the original concatenated data of the dynamic password factor (DPF), namely, the concatenation of the biometric behavioral state identifier (BBSI) and the timestamp (TS).

[0055] Step 1042: Perform timestamp synchronization verification on the original spliced ​​data based on the biometric behavior state identifier in the user identity identification vector, and generate permission matching request data containing the user identity unique identifier.

[0056] Optionally, the bio-behavioral state identifier (BBSI) in the user identity vector (UIV) is compared with the bio-behavioral state identifier in the original concatenated data extracted from the dynamic access token to ensure consistency. The timestamp (TS) in the original concatenated data is then synchronously verified to ensure that the timestamp is within a reasonable time range, for example, whether the difference from the current system time is within the allowable error range. After this comparison and timestamp synchronization verification, the bio-behavioral state identifier (BBSI) is integrated with the verified timestamp information to generate permission matching request data (PMRD) containing the user's unique identity identifier for subsequent permission matching operations.

[0057] Step 1043: Input the permission matching request data into the warehouse permission database, traverse the preset permission mapping table based on the user identity unique identifier, and obtain the permission identifier set and operation scope constraint conditions associated with the user identity unique identifier.

[0058] In this step, the permission matching request data PMRD is input into the warehouse permission database. The database stores a preset permission mapping table, which records the correspondence between different user identities, corresponding permission identifiers, and operational scope constraints. Based on the user identity uniqueness identifier in the permission matching request data, the system searches and traverses the preset permission mapping table to determine the permission identifier set PI and operational scope constraints ORC associated with the user identity uniqueness identifier. This information clearly defines the user's permissions and the operational scope restrictions of the permissions.

[0059] Step 1044: performing multi-dimensional feature dimensionality reduction processing on the permission identification set to generate a user permission feature vector, and performing spatial similarity matching between the user permission feature vector and the user identity identification vector to generate a permission association strength coefficient.

[0060] It can be understood that for the permission identification set PI, a multi-dimensional feature dimensionality reduction algorithm, such as the principal component analysis algorithm, is used to process the permission identification information of multiple dimensions in the set, extract the main characteristic components, and form the user permission feature vector UPV. Then, the spatial similarity between the user permission feature vector UPV and the user identity identification vector UIV is calculated. For example, the cosine similarity algorithm is used to calculate the cosine value of the angle between the two vectors. The larger the value, the higher the similarity between the two vectors. After certain conversions and calculations, this similarity value generates the permission association strength coefficient PAC, which is used to measure the closeness of the association between user identity and permission.

[0061] Step 1045: Generate a dynamic permission mapping relationship based on the permission association strength coefficient and the preset permission level threshold, and label the dynamic permission mapping relationship in combination with the operation range constraint to form a permission matching label that includes an access authorization path and an operation instruction whitelist.

[0062] For example, the permission association strength coefficient (PAC) is compared with the preset permission level threshold. Based on the comparison results, the user's permission level is determined, and a dynamic permission mapping relationship is generated to clarify the correspondence between the user's permission level and specific permissions. Then, combined with the operation scope constraint (ORC), the dynamic permission mapping relationship is labeled and encapsulated. For example, information such as the access authorization path and the operation instruction whitelist is organized and encoded to form a permission matching label (PML) that contains all permission-related information. This label clearly defines the user's permission scope and operation requirements.

[0063] Step 1046: Combine and encrypt the permission matching tag and the integrity verification code in the dynamic access token to generate a login verification result that carries the user permission level identifier and token verification status, and send the login verification result to the warehouse system to trigger the access control policy of the corresponding permission level.

[0064] Optionally, the permission matching tag PML and the integrity verification code ICV in the dynamic access token DAT are combined and encrypted. A commonly used encryption algorithm, such as a symmetric encryption algorithm, is used to take the permission matching tag PML and the integrity verification code ICV as input for encryption operations. During the encryption process, the data is subjected to common transformations and processing to ensure the security and integrity of the data. After encryption, a login verification result LVR is generated that carries the user permission level identifier and the token verification status. The login verification result LVR contains the user's permission level information, which clarifies the scope of operations that the user can perform in the warehousing system; it also contains the token verification status, which is used to inform the warehousing system of the validity and legality of the dynamic access token. After the login verification result LVR is generated, the system sends it to the warehousing system. After the warehousing system receives the login verification result LVR, it first checks the token verification status therein to confirm the validity of the dynamic access token. If the token verification passes, the access control policy corresponding to the permission level is triggered based on the user permission level identifier carried in the login verification result.

[0065] For example, if a user's permission level is high, they can perform advanced cargo management operations, such as modifying inventory quantities and adjusting cargo storage locations. If the permission level is intermediate, they can only perform some routine operations, such as viewing inventory information and submitting cargo entry and exit requests. If the permission level is low, the scope of operations is even more limited, perhaps only being able to view basic cargo information. In this way, each user can only access and operate the functions and data that match their permission level, ensuring the security of the warehouse system and the confidentiality of data.

[0066] It can be seen that the application of the above technical solution can achieve accurate generation of identity identification vectors, dynamic password enhanced authentication and automatic matching of storage permissions while accurately performing liveness detection, comprehensively improving the security and convenience of storage system login.

[0067] In an alternative embodiment, the method further comprises: Step 201: Acquire a historical attack behavior dataset, wherein the historical attack behavior dataset includes forged biometric features, mechanically repeated actions, and synthetic video attack samples.

[0068] To improve the system's security and anti-attack capabilities, it is necessary to collect historical attack behavior data. This data is collected from multiple sources, such as security monitoring records, network security reports, and abnormal behavior data discovered during internal testing. For forged biometric samples, data such as bioelectrical signals and simulated body movement trajectories forged through technical means are recorded to form the forged biometric set FB. Mechanically repetitive action samples, data on mechanical, regularly repetitive body movements, are collected to form the mechanically repetitive action set MR. Synthetic video attack samples, data from fake operation videos created through synthesis techniques, such as body movement information and touch operation simulations, are recorded to form the synthetic video attack sample set SV. These three sets are combined to form the historical attack behavior dataset HAD, which provides data support for subsequent model training.

[0069] Step 202: Perform feature space adversarial mapping on the historical attack behavior dataset and the real user action data samples through an adversarial training model to obtain an adversarial mapping result.

[0070] In an embodiment of the present invention, the adversarial training model aims to learn the differences between real user action data samples and historical attack behavior data sets by allowing them to compete in feature space, thereby improving the robustness and recognition ability of the model.

[0071] Preferably, step 202 further includes: Step 221: extracting action sequence segments of forged biometric features, periodic trajectory data of mechanically repeated actions, and inter-frame difference features of synthetic video attack samples from the historical attack behavior dataset to generate an attack feature vector.

[0072] As can be understood, for the forged biometric feature set FB in the historical attack behavior dataset HAD, the action sequences corresponding to the forged biometric features are analyzed to extract representative action sequence fragments. For example, in the operations corresponding to forged bioelectric signals, the action sequence information at key time points is extracted to form the forged biometric action sequence fragment set FBA. From the mechanical repetitive action set MR, the periodic patterns of the actions are analyzed and periodic trajectory data is extracted. For example, the period length of the repetitive actions and the pattern of the motion trajectory are determined to form the mechanical repetitive action periodic trajectory data set MRP. For the synthetic video attack sample set SV, the differences between video frames are calculated to extract inter-frame difference features. For example, by calculating the changes in object position, color, and other information between adjacent frames, the inter-frame difference feature set SVD of the synthetic video attack sample is formed. The data in these three sets are integrated and encoded, and the different types of data are converted into vector form according to certain rules. Ultimately, the attack feature vector AV is generated for subsequent adversarial training.

[0073] Step 2022: Separate the dynamic change characteristics of the limb movement trajectory, the random fluctuation characteristics of the bioelectric response, and the instantaneous gradient characteristics of the touch pressure distribution from the real user action data sample to generate a real feature vector.

[0074] Optionally, the limb motion trajectory data is analyzed from the real user action data samples. The changes in the limb motion trajectory at different times are observed, and the dynamic change features, such as the speed change and direction change of the limb movement, are extracted to form the limb motion trajectory dynamic change feature set LMD. For the bioelectric response data, its random fluctuations in the time series are analyzed, and the random fluctuation features, such as the random fluctuations in the bioelectric signal intensity, are extracted to form the bioelectric response random fluctuation feature set BER. In terms of touch pressure distribution data, the instantaneous rate of change of pressure is calculated, and the instantaneous gradient features are extracted, such as the rapid rise and fall of pressure when clicking the screen, to form the touch pressure distribution instantaneous gradient feature set TPG. The data of these three sets are sorted and converted, and converted into vector form according to the commonly used mapping rules to generate the real feature vector RV as the basic data for countering the attack feature vector.

[0075] Step 2023: Input the attack feature vector and the true feature vector into the adversarial generative network of the adversarial training model, and through alternating iterative training, make the generator output of the adversarial generative network have the same statistical distribution as the true feature vector in the time-frequency domain.

[0076] Optionally, the attack feature vector AV and the true feature vector RV are input into the adversarial generative network of the adversarial training model. The adversarial generative network consists of a generator and a discriminator. During the training process, the goal of the generator is to generate adversarial noise perturbations that have the same statistical distribution as the true feature vector RV in the time-frequency domain. Through alternating iterative training, the generator continuously adjusts its own parameters to generate noise perturbations that are closer to the distribution of the true feature vector. For example, in each iteration, the generator generates an adversarial noise perturbation vector based on the current parameters, and then the discriminator distinguishes the perturbation vector from the true feature vector. If the discriminator can accurately distinguish, it means that the perturbation vector generated by the generator is not realistic enough and the generator needs to adjust the parameters; if the discriminator cannot distinguish, it means that the generator's generation effect is better. Through such continuous alternating iterations, the adversarial noise perturbation output by the generator becomes closer and closer to the statistical distribution of the true feature vector in the time-frequency domain.

[0077] Step 2024: Inject the adversarial noise perturbation into the attack feature vector, perform feature space adversarial mapping, and generate an adversarial feature distribution difference between the attack feature distribution carrying the adversarial perturbation and the true feature distribution.

[0078] Optionally, the adversarial noise perturbation vector output by the generator is injected into the attack feature vector AV. During the injection process, the noise perturbation is fused with the attack feature vector according to certain rules, such as adding corresponding elements or other commonly used fusion methods. After the noise perturbation is injected, an adversarial mapping operation is performed on the attack feature vector in the feature space. Through a commonly used transformation algorithm, the attack feature vector after the noise perturbation is injected is mapped to a new feature space, and the difference between the new attack feature distribution and the real feature distribution represented by the real feature vector RV is calculated. This difference is measured by commonly used calculation indicators, such as calculating the distance metric between the two distributions, such as Euclidean distance, KL divergence, etc., to form an adversarial feature distribution difference AFD between the attack feature distribution after carrying the adversarial perturbation and the real feature distribution, which is used for subsequent discrimination and parameter adjustment.

[0079] Step 2025: Perform adversarial gradient backpropagation on the adversarial feature distribution difference through the discriminator of the adversarial training model to calculate the adversarial loss value between the attack feature vector and the true feature vector in the dimensions of spatiotemporal continuity and biometric randomness.

[0080] Optionally, the discriminator of the adversarial training model analyzes the adversarial feature distribution difference (AFD). The discriminator determines the degree of difference between the attack feature distribution after noise perturbation and the true feature distribution. Using the adversarial gradient backpropagation algorithm, the discriminator feeds its judgment back to the generator and itself to adjust the model parameters. During this process, the adversarial loss values ​​of the attack feature vector AV and the true feature vector RV are calculated in the dimensions of spatiotemporal continuity and biometric randomness. In the spatiotemporal continuity dimension, the temporal and spatial variations of the attack and true features are analyzed to determine whether they are continuous and conform to normal behavioral patterns. The difference between the two in these dimensions is calculated and converted into a loss value. In the biometric randomness dimension, the random variations of the attack and true features in terms of biometric characteristics, such as the random fluctuation patterns of bioelectric signals, are compared. The difference is calculated and converted into a loss value. The loss values ​​in these two dimensions are combined to obtain the total adversarial loss value (ALV), which is used to measure the model's performance in distinguishing true from attack features.

[0081] Step 2026: Dynamically adjust the generator weight parameters of the adversarial generative network according to the adversarial loss value, so that the adversarial noise perturbation output by the generator forms an adversarial mapping result that maximizes feature confusion between the attack feature vector and the true feature vector.

[0082] Optionally, the weight parameters of the generator of the adversarial generative network are dynamically adjusted according to the calculated adversarial loss value ALV. Using optimization algorithms such as gradient descent, the weight parameters of the generator are adjusted according to the size of the adversarial loss value and the gradient direction. If the adversarial loss value is large, it means that the adversarial noise perturbation generated by the generator does not confuse the attack features and the real features well, and the adjustment range of the weight parameters needs to be increased; if the adversarial loss value is small, it means that the generation effect of the generator is good, and the adjustment range of the weight parameters can be appropriately reduced. By continuously adjusting the weight parameters of the generator according to the adversarial loss value, the adversarial noise perturbation output by the generator can form an adversarial mapping result that maximizes feature confusion between the attack feature vector AV and the real feature vector RV. This result makes the attack features and the real features more difficult to distinguish in the feature space, thereby improving the performance of the adversarial training model.

[0083] Step 203: Optimize the feature discrimination layer of the living body detection algorithm by using the adversarial mapping result and the preset dynamic weight adjustment mechanism.

[0084] Optionally, the adversarial mapping results are used as a basis for optimizing the feature discrimination layer of the liveness detection algorithm. The preset dynamic weight adjustment mechanism is a set of pre-set rules used to adjust the weights of each feature in the feature discrimination layer based on the adversarial mapping results. For example, for features that appear to be more important in distinguishing between real and attack features during the adversarial mapping process, their weights in the feature discrimination layer are increased through the dynamic weight adjustment mechanism; for those less important features, their weights are reduced. In this way, the feature discrimination layer's attention to different features is optimized, allowing the feature discrimination layer to more accurately identify real biological features and attack behaviors, thereby improving the accuracy and robustness of the liveness detection algorithm.

[0085] Step 204: Determine the robustness index of the optimized liveness detection algorithm through noise interference data; and reversely adjust the feature discrimination layer decision parameters and attention weight distribution of the optimized liveness detection algorithm according to the difference between the robustness index and the preset index.

[0086] As you can understand, to evaluate the performance of the optimized liveness detection algorithm, we input noise interference data. This noise interference data simulates various interference factors that may occur in real applications, such as sensor noise and environmental interference. By analyzing the algorithm's performance under noise interference, we determine the robustness indicators of the optimized liveness detection algorithm. For example, we calculate indicators such as the recognition accuracy and false positive rate under noise interference to serve as a basis for measuring robustness.

[0087] Compare the obtained robustness index with the preset index. If the robustness index does not meet the preset index requirements, it means that the robustness of the algorithm needs to be further improved. Based on the difference between the two, the decision parameters and attention weight distribution of the feature discrimination layer of the optimized liveness detection algorithm are adjusted in reverse. For example, if it is found that the algorithm deviates from the judgment of certain features when facing a certain type of noise interference, then the decision parameters related to these features in the feature discrimination layer are adjusted, and the attention weight distribution is adjusted at the same time, so that the algorithm pays more attention to those features that are more critical for accurate judgment in noisy environments, thereby further optimizing the performance of the algorithm and improving its robustness.

[0088] In an exemplary implementation, after outputting the login verification result associated with the user authority level to the warehousing system according to the authority matching tag, the method further includes: Step 301: Monitor the calling frequency of the dynamic access token in the warehousing system and the security level of the associated operation instructions.

[0089] After a user logs in to the warehousing system and obtains authorization, the system begins real-time monitoring of the use of dynamic access tokens within the warehousing system. The call frequency of the dynamic access token is recorded by recording the number of times the token is used to access system functions within a unit of time. For example, within an hour, the number of times the token is called is counted to form a call frequency record CF. At the same time, the security level of each operation instruction performed using the dynamic access token is assessed. The security level is determined based on factors such as the sensitivity of the operation and the potential impact on the system. For example, operations that modify inventory data have a higher security level, while simple inventory information queries have a lower security level. The security level of each operation instruction is recorded to form an operation instruction security level set SCL for subsequent analysis.

[0090] Step 302: When the calling frequency exceeds a preset threshold or the security level reaches a preset risk level, a dynamic token update request is triggered.

[0091] The preset threshold is a call frequency value pre-set based on normal system usage and security policies, denoted as PT. The preset risk level is a grading standard based on the security impact of an operation instruction, denoted as PR. When the monitored call frequency CF exceeds the preset threshold PT, it indicates that the dynamic access token is being used too frequently, potentially posing a risk of abnormal operation. Alternatively, when the security level of an operation instruction in the operation instruction security level set SCL reaches the preset risk level PR, it indicates that the current operation has a high security risk. In both cases, the system triggers a dynamic token update request to ensure system security.

[0092] Step 303: Generate a new dynamic password factor according to the user identity vector and the real-time timestamp, and generate a new dynamic access token based on a multi-layer nested encryption algorithm combination.

[0093] This involves extracting relevant identification information from the user identity vector (UIV) and combining it with the system's real-time timestamp (TS). Following the same method used to generate the dynamic password factor, these information and timestamp are concatenated to form a new dynamic password factor (NDPF). Next, based on the current system's security requirements and pre-defined encryption strategies, a multi-layered nested encryption algorithm combination is selected, such as a suitable algorithm from a pre-defined pool of asymmetric encryption algorithms. The new dynamic password factor (NDPF) is encrypted layer by layer. The corresponding algorithm identifier is embedded after each encryption layer, ultimately generating a new dynamic access token (NDAT) to replace the old one, reducing system security risks.

[0094] Step 304: Replace the dynamic access token with the new dynamic access token, and send a token update instruction to the warehouse system to synchronously update the access control policy.

[0095] Optionally, the newly generated dynamic access token NDAT replaces the currently used dynamic access token DAT. Simultaneously, a token update instruction is sent to the warehousing system, instructing it to use the new dynamic access token. Upon receiving the token update instruction, the warehousing system synchronously updates its access control policy based on the permission information and identifier in the new dynamic access token. For example, the system updates the permissions associated with the user, ensuring that the user can only perform operations consistent with their permissions using the new dynamic access token, thereby safeguarding system security and data integrity.

[0096] In an exemplary implementation, after outputting the login verification result associated with the user authority level to the warehousing system according to the authority matching tag, the method further includes: Step 401: intercept the touch track and warehouse interface interaction actions during the user operation in real time, and extract the operation behavior timing characteristics; compare the operation behavior timing characteristics with the operation instruction whitelist in the permission matching tag for action compliance, and generate a behavior deviation index.

[0097] As users operate the warehouse system, the system captures touch traces on the operating terminal in real time, recording the location and timing of actions such as sliding and clicking the screen. This data forms a touch trace set TT. Simultaneously, user interactions with the warehouse interface, such as opening menus and selecting functional modules, are captured, and the time and sequence of these actions are recorded to form a warehouse interface interaction action set WI. Temporal features of these actions are extracted from these two sets, such as analyzing the time intervals between touch traces and the order of interaction actions. This forms a temporal feature set OBT.

[0098] The permission matching tag (PML) contains a whitelist of operational instructions, which specifies the operational instructions that a user can perform within their permission scope and their order. The OBT, a temporal feature set of operational behavior, is compared with the whitelist of operational instructions, and the differences between the two are calculated. For example, this checks whether the actual operational instructions performed by the user are on the whitelist and whether the order of operations complies with the specified settings. Using common calculation methods, these differences are quantified into a behavioral deviation index (BDI), which measures the degree to which user operational behavior complies with the specified permission settings.

[0099] Step 402: When the behavior deviation index exceeds the preset alarm threshold, freeze the current dynamic access token and reactivate the liveness detection algorithm for secondary identity verification; update the permission matching tag based on the secondary verification result, and store the abnormal operation behavior trajectory and permission adjustment record through the warehouse system log.

[0100] The preset alarm threshold, denoted as AT, is a value set based on system security requirements and normal operating conditions. When the behavioral deviation index (BDI) exceeds the preset alarm threshold AT, it indicates that the user's operation behavior may be abnormal and pose a security risk. At this time, the system immediately freezes the currently used dynamic access token (DAT), preventing the user from continuing operations. Simultaneously, the liveness detection algorithm is reactivated to perform a second identity verification on the user.

[0101] During the secondary identity verification process, the user's real-time interactive action data is collected again and analyzed according to the previous liveness detection process to generate a new liveness verification confidence score and user identity vector. Based on the secondary verification results, the authenticity of the user's identity and the accuracy of their permissions are determined. If any issues with user permissions are found, such as incorrect permissions being granted or the user performing an operation beyond their authorized permissions, the permission matching label (PML) is updated based on the verification results.

[0102] Finally, the warehouse system logs are used to store the user's abnormal operation behavior traces, including touch traces, interactive actions and other information, as well as permission adjustment records. The above log records are of great reference value for subsequent security audits, problem troubleshooting and system optimization, and help improve the security and reliability of the system.

[0103] In a non-limiting embodiment, after outputting the login verification result associated with the user authority level to the warehousing system based on the authority matching tag, it also includes: continuously collecting device environment data of the user terminal, performing distribution similarity calculation on the historical environment baseline bound to the device environment data and the user identity identification vector, and generating an environment anomaly confidence; when the environment anomaly confidence reaches a preset interception condition, stripping the encryption identifier of the dynamic access token and injecting an environment verification invalidation mark; interrupting the current session of the warehousing system according to the environment verification invalidation mark, and re-issuing a dynamic verification instruction to the user terminal to start the environment synchronization verification process.

[0104] Optionally, the system continuously collects device environment data from user terminals, including information such as device model, operating system version, sensor status, and network connectivity, to form a device environment data set (ED). The user identity vector (UIV) is bound to a historical environment baseline (HEB). This baseline is a reference standard established based on the user's past device environment data under normal operating conditions. It contains information such as the normal distribution range of various device environment parameters.

[0105] The distribution similarity between the device environment data set ED and the historical environment baseline HEB is calculated. Common similarity calculation algorithms, such as cosine similarity and KL divergence, are used to measure the similarity between the current device environment data and the historical environment baseline. This calculation yields the environmental anomaly confidence level (EAC), which reflects the likelihood of an anomaly in the current device environment compared to the historical environment.

[0106] The preset interception condition is a pre-set environmental anomaly confidence threshold, denoted as IC, based on the system's security policy. When the environmental anomaly confidence level (EAC) reaches the preset interception condition (IC), it indicates that the current device environment may be abnormal and pose a security risk. At this point, the system processes the dynamic access token (DAT), stripping its encryption identifier and deleting its original security. Simultaneously, an environmental verification failure flag is injected into the dynamic access token to indicate a problem with the device environment corresponding to the token.

[0107] Upon detecting an environmental verification failure, the warehousing system immediately terminates the current session, preventing the user from continuing operations. This is to prevent potential malicious activity from exploiting an abnormal device environment to harm the system. Subsequently, the system reissues dynamic verification instructions to the user terminal. These instructions are similar to those issued during login, but focus more on verifying the device environment. For example, the instructions may require the user to perform common operations to verify that the device's sensors are functioning properly, or to confirm that the current network connection meets security requirements.

[0108] After the user terminal receives the new dynamic verification instruction, it starts the environment synchronization verification process. The user needs to complete the corresponding operation according to the instruction, and the system will once again collect the device environment data and the user's real-time interactive action data during the operation. The collected data will be transmitted back to the warehousing system, and the system will conduct a detailed analysis of the data. First, verify whether the device environment meets the system's security standards and the user's historical environment baseline. If the device environment still has abnormalities, the system may further prompt the user to check the device or change the network environment, etc. If the environment verification passes, the system will regenerate the dynamic access token and update the permission matching tag to ensure that the user can continue to operate in a safe environment, while ensuring the security of the system and the confidentiality of the data.

[0109] In a non-limiting embodiment, after outputting the login verification result associated with the user permission level to the warehouse system based on the permission matching tag, it also includes: parsing the access authorization path in the permission matching tag, and monitoring the mapping relationship between the user operation instructions and the path resources of the access authorization path in real time; dynamically adjusting the warehouse session validity period according to the data sensitivity of the user operation instructions, and extracting the operation interval duration to generate a session activity parameter; when the session activity parameter is lower than a preset activity threshold, terminating the current warehouse session and clearing the cached data of the dynamic access token; sending a session termination instruction to the warehouse system, and generating a session log and a permission recovery status code based on the user identity identification vector.

[0110] Among them, the system first parses the access authorization path in the permission matching tag PML. The access authorization path clarifies the path information of each functional module and data resource that the user is allowed to access in the warehouse system. For example, the user can access certain data in the inventory management module through common menu options and operation steps. The system monitors the mapping relationship between user operation instructions and the path resources of the access authorization path in real time to ensure that each user's operation instruction is within the scope of the authorized path. For example, when a user initiates an operation instruction, the system will check whether the instruction corresponds to a path resource in the access authorization path. If it does not correspond, it will be judged as an illegal operation.

[0111] The system dynamically adjusts the storage session validity period based on the data sensitivity of user operations. Data sensitivity is determined by the importance and confidentiality of the data involved in the operation. For example, modifying the total inventory volume has a higher data sensitivity, while a simple query of the inventory item name has a lower data sensitivity. For operations with high data sensitivity, the system will appropriately shorten the storage session validity period to reduce the risk of data leakage; for operations with low data sensitivity, the session validity period can be relatively extended.

[0112] At the same time, the system extracts the duration of user operation intervals—the time interval between two consecutive operation commands—to generate a session activity parameter. For example, the system calculates the number of user operations and the intervals between operations over a period of time using common calculation methods to derive the session activity parameter SA. The preset activity threshold, denoted as ST, is a standard value set based on normal system usage. When the session activity parameter SA falls below the preset activity threshold ST, it indicates inactive user operation and may be idle for an extended period. To conserve system resources and ensure system security, the system terminates the current storage session.

[0113] When a session is terminated, the system clears the cached data of the dynamic access token to prevent the token from being used illegally. It then sends a session termination command to the warehousing system, informing it that the session has ended. Based on the user identity vector (UIV), the system generates a session log. The session log records all user operations during the session, including operation instructions, operation time, and operation results, facilitating subsequent auditing and analysis. At the same time, a permission revocation status code is generated, indicating that the user's permissions have been revoked, ensuring that the user cannot perform unauthorized operations after the session ends. Through these measures, the system can effectively manage user sessions, ensuring system security and the rational use of resources.

[0114] When implementing the above technical solution, technical personnel in the relevant field can further optimize the execution logic of the solution by optimizing the linkage logic of liveness detection confidence and encryption strategy based on the multi-factor dynamic authentication framework and feature space alignment algorithm in the existing technology.

[0115] To address the inverse correlation between liveness verification confidence and encryption strength, a dynamic encryption strength mapping mechanism based on trusted device binding can be introduced. The device fingerprint hash value and confidence weighting function can be used to construct a composite encryption level decision model, so that the encryption strength can be reduced in high-confidence scenarios through device credibility compensation, rather than relying solely on a single-dimensional decision based on biometric confidence.

[0116] For the timing contradiction between the user identity vector and the dynamic token, the biological behavior state identifier and the timestamp generated in the liveness detection phase can be pre-spliced ​​based on the time-sensitive hashing (TSH) algorithm to generate the initial identity vector before the liveness verification is completed. It is then temporarily stored in the trusted execution environment (TEE) through a lightweight encryption channel to ensure that the complete identification data can be directly called when the dynamic token is generated.

[0117] In the adversarial training optimization phase, the discriminator objective function can be reconstructed through the improved gradient-penalized Wasserstein generative adversarial network (WGAN-GP), constraining the generator to only superimpose adversarial perturbations in the attack feature space. At the same time, the contrastive learning loss function is used to enhance the discriminator's ability to distinguish between attack features and real features in the time-frequency domain high-order statistics (such as Mel-frequency cepstral coefficient differences), thereby avoiding model performance degradation caused by feature confusion.

[0118] To address the issue of inconsistent dimensions, a hybrid normalization technique needs to be used before data fusion: Min-Max normalization is performed on the three-dimensional limb motion trajectory data to the [0, 1] interval, the touch pressure data is dynamically calculated using the Z-Score normalization value through the sensor range parameters, and the bioelectric signal uses segmented energy normalization (SEN) to eliminate individual physiological differences. Finally, a fusion feature vector of unified dimension is formed through attention-weighted splicing.

[0119] To address the dimensionality mismatch problem in the calculation of permission association strength, the dynamic time warping (DTW) algorithm and deep metric learning (DML) can be combined to construct a cross-dimensional similarity calculation model. The twin neural network is used to extract the latent space projection of the user permission feature vector and the identity identification vector, and the cosine similarity is calculated in the projection space to eliminate the impact of dimensional differences.

[0120] In addition, the dynamic verification code generation mechanism can be reconstructed through nested HMAC-SHA256 chain hashing, using the output of each layer of encryption identification as the salt value for the hash calculation of the next layer, and embedding a nonlinear combination of the previous hash values ​​in the final integrity verification code, thereby resisting the risk of token tampering under man-in-the-middle attacks.

[0121] It should be noted that those skilled in the art can and should know that the above-mentioned improvement scheme, while being compatible with the original technical framework, effectively improves and optimizes the logic and dimensions by introducing mature technologies such as device environment binding, timing-sensitive encryption, and cross-domain feature alignment. At the same time, by enhancing the clarity of the judgment boundaries and the robustness of data standardization of adversarial training, it further improves the system's biometric recognition accuracy and dynamic token security in complex attack scenarios.

[0122] The embodiment of the present invention creatively realizes the intelligent and secure login verification of the warehousing system. First, by collecting real-time interactive action data covering limb movement trajectory and biometric response, the user's dynamic information can be fully obtained; wherein, the preset liveness detection algorithm is used for dynamic biometric analysis, which can accurately generate liveness verification confidence and user identity identification vector, thereby effectively judging whether it is a real user; further based on the liveness verification confidence and security authentication threshold, dynamic password enhanced authentication is carried out, which can generate multi-layer encrypted dynamic access tokens, thereby improving the security of authentication; finally, the warehouse permissions are automatically matched and the login verification results are output, which not only ensures that only legitimate users can log in according to the permissions, but also simplifies the operation process, reduces the risk of illegal intrusion, and provides efficient and secure identity authentication for the warehousing system.

[0123] Based on the same inventive concept, the embodiment of the present invention also provides an intelligent warehouse login verification system. Figure 2 As shown, it is a structural diagram of a possible intelligent warehouse login verification system provided in an embodiment of the present invention. Figure 2 In the embodiment, the intelligent warehouse login verification system 200 includes a processor 210 and a memory 220. The memory 220 stores a computer program executable by the processor 210. The processor 210 can perform the steps of the intelligent warehouse login verification method based on dynamic liveness detection by executing the instructions stored in the memory 220.

[0124] Based on the same inventive concept, an embodiment of the present invention provides a computer-readable storage medium, which includes a computer program. When the computer program is run on an intelligent warehouse login verification system, the computer program is used to enable the intelligent warehouse login verification system to execute the steps of the intelligent warehouse login verification method based on dynamic liveness detection. In some possible implementations, various aspects of the intelligent warehouse login verification method based on dynamic liveness detection provided by the present invention can also be implemented in the form of a program product, which includes a computer program. When the program product is run on an intelligent warehouse login verification system, the computer program is used to enable the intelligent warehouse login verification system to execute the steps of the intelligent warehouse login verification method based on dynamic liveness detection. For example, the intelligent warehouse login verification system can execute the following steps: Figure 1 Follow the steps shown in .

[0125] In the technical solutions involved in the above-mentioned embodiments of the present invention, whether it is performing comparison calculations of multi-dimensional features or constructing composite parameters, if there are problems caused by significant differences in the number of dimensions, dimensional units and semantic meanings of different features, technical personnel in this field, based on their professional knowledge and past practical experience, are fully able to understand that these differences need to be properly handled so that the calculation results are accurate and comparable, and avoid situations such as logical confusion and unclear mathematical meaning.

[0126] Specifically, when faced with features having different numbers of dimensions, those skilled in the art may employ various strategies to accurately calculate the similarity, matching degree, or feature distance between different features.

[0127] Feature selection is a common method. For a high-dimensional feature set, we can select the most representative subset of features from the high-dimensional features, matching the number of low-dimensional features based on metrics such as feature importance and relevance. Feature selection is performed using methods such as the chi-square test and information gain to identify the most valuable features for the technical solution. This reduces the high-dimensional features to a dimension comparable to the low-dimensional features, allowing for similarity or distance calculations.

[0128] Feature extraction is also an effective method. By constructing a suitable feature extraction model, features of different dimensions can be mapped into a common low-dimensional feature space. Principal component analysis (PCA) can not only handle dimensional differences but also project high-dimensional features into a low-dimensional space composed of principal components, making features of different dimensions comparable in this low-dimensional space. Furthermore, deep learning models such as autoencoders can also be used for feature extraction. They automatically learn the latent representation of input features and convert features of different dimensions into feature vectors of the same dimensionality, enabling subsequent similarity, matching, or feature distance calculations.

[0129] Alternatively, kernel methods can be used. Kernel functions can calculate the similarity between features in a high-dimensional space without explicitly mapping the features to that space. For features with varying numbers of dimensions, appropriate kernel functions, such as Gaussian or polynomial kernel functions, can be selected to directly calculate the similarity between them. This approach avoids the direct computational difficulties associated with varying feature dimensions and effectively measures the relationships between features in either the original feature space or an implicit high-dimensional space.

[0130] When processing the comparison of multi-dimensional features, in order to achieve comparable alignment of feature spaces, those skilled in the art may adopt a variety of existing common technical means.

[0131] Standardization preprocessing is a widely used and effective method. It transforms raw feature data into a standard normal distribution with a mean of 0 and a standard deviation of 1 by performing a specific linear transformation on the data. This process essentially eliminates the influence of different dimensions between features, allowing all features to be compared at the same scale. For example, in a dataset containing features of different dimensions, after standardization preprocessing, similarity or distance calculations can be performed on these features at the same scale, avoiding calculation bias caused by different dimensions.

[0132] Mapping transformation is also an effective way to solve the problem of dimensional differences. It can map the original features into a new space based on the specific properties of the features and actual business needs. In this new space, features of different dimensions can be better comparable. For those features with nonlinear relationships, those skilled in the art can use logarithmic transformation, power transformation, etc. to convert them into linear relationships, which makes it easier to calculate similarity or distance. For example, when processing some features with exponential growth trends, they can be converted into linear relationships through logarithmic transformation, making subsequent calculations more accurate and convenient.

[0133] Spatial projection is also an important technical approach. It projects a high-dimensional feature space into a low-dimensional space while preserving as much important information between features as possible. By carefully selecting the appropriate projection direction and projection dimension, technicians can reduce the dimensionality of the data while effectively minimizing the impact of dimensional differences on computational results. Common spatial projection methods include principal component analysis (PCA) and linear discriminant analysis (LDA). Taking PCA as an example, it projects high-dimensional data into a low-dimensional space composed of the principal components by finding their directions. This simplifies the data structure while reducing the interference of dimensional differences on feature comparison.

[0134] In the process of constructing composite parameters (such as loss function values), different parameter items often have different dimensions. Those skilled in the art can adopt normalization processing or an adaptive weight allocation mechanism based on distribution characteristics.

[0135] Normalization involves unifying the value ranges of different parameter items into a fixed interval, such as [0, 1]. This approach eliminates the impact of dimensional differences and ensures that all parameter items have equal importance during weighted fusion. Common normalization methods include min-max normalization and Z-score normalization. For example, min-max normalization performs a linear transformation on parameter items, scaling their value range to the interval [0, 1]. This allows weighted fusion of parameters of different dimensions to be performed under the same standard.

[0136] The adaptive weight allocation mechanism based on distribution characteristics dynamically adjusts the weights of different parameter items according to their distribution characteristics. For parameter items with large variance, those skilled in the art can appropriately reduce their weights; for parameter items with small variance, those skilled in the art can appropriately increase their weights. Doing so can make the composite loss function pay more attention to those parameter items with smaller variances, thereby improving the stability and generalization ability of the model. For example, in a composite loss function containing multiple parameter items, if the variance of a parameter item is large, it means that its fluctuation is more drastic, which may have an adverse effect on the stability of the model. In this case, reducing its weight can reduce this adverse effect; and for parameter items with smaller variance, increasing their weight can make the model pay more attention to the information reflected by the parameter item, thereby improving the overall performance of the model.

[0137] The general technical approaches described above for solving the feature matching and loss balancing problems are common knowledge in the field. These techniques have been fully validated and widely used in numerous practical applications, and those skilled in the art can skillfully and flexibly apply these methods to address similar dimensional discrepancies.

[0138] The formulas and calculation processes involved in the embodiments of the present invention, whether used for multi-dimensional feature comparison or composite loss function construction, strictly follow the principle of dimensional correspondence. The variables in each formula have clear and definite physical meanings, and their operation logic is also fully consistent with basic mathematical and physical logic. The operation results must be the reasonable results expected by the present invention. Those skilled in the art have the ability to comprehensively apply the above-mentioned general technical means according to specific data conditions and business needs, and effectively solve the various problems caused by the number of dimensions, dimensional differences, etc. in the multi-dimensional feature comparison calculation and composite loss function construction in the embodiments, and ensure the accuracy, reliability and feasibility of the technical solution of the present invention.

Claims

1. An intelligent warehouse login verification method based on dynamic liveness detection, characterized in that: include: Collecting real-time interactive action data of users logged into the warehousing system, wherein the real-time interactive action data includes the body movement trajectory and biometric response generated when the user logged into the warehousing system executes a dynamic verification instruction; Calling a preset liveness detection algorithm to perform dynamic biometric analysis on the real-time interactive action data to generate a liveness verification confidence level and a user identity identification vector; Performing dynamic password enhanced authentication based on the liveness verification confidence level and a preset security authentication threshold to generate a dynamic access token containing multiple layers of encrypted identifiers; Automatic storage authority matching processing is performed based on the user identity vector and the dynamic access token, and a login verification result associated with the user authority level is output to the storage system according to the authority matching tag.

2. The method according to claim 1, wherein The real-time interactive action data of users logging into the storage system is collected, including: Sending the dynamic verification instruction to the user terminal corresponding to the user logged into the warehousing system, wherein the dynamic verification instruction includes at least one set of preset action combinations and corresponding execution time windows; Collecting three-dimensional limb motion trajectory data, touch surface pressure data, and bioelectric response signals generated by the user logged into the warehouse system performing the at least one set of preset action combinations within the execution time window; Performing spatial normalization processing on the three-dimensional limb motion trajectory data to generate a limb motion trajectory vector; performing dynamic gradient analysis on the touch surface pressure data to extract a pressure change feature vector; performing time-frequency decomposition on the bioelectric response signal to generate a biometric response spectrum feature; The limb motion trajectory vector, the pressure change feature vector and the biological characteristic response spectrum feature are temporally aligned and fused to form the real-time interactive action data.

3. The method according to claim 1, wherein The calling of a preset liveness detection algorithm to perform dynamic biometric analysis on the real-time interactive action data to generate a liveness verification confidence level and a user identity identification vector includes: Extracting spatiotemporal correlation features of the real-time interactive action data through the spatiotemporal feature encoding layer of the liveness detection algorithm; wherein the spatiotemporal correlation features include: acceleration continuity representation of limb motion trajectory, dynamic symmetry parameters of pressure distribution, and quantitative indicators of synchronization between bioelectric signals and action execution; Inputting the spatiotemporal correlation features into the biometric feature discrimination layer of the liveness detection algorithm for discrimination processing to generate liveness discrimination features that characterize the dynamic consistency of the user's biometric features; Comparing the liveness discrimination feature with a preset discrimination feature, and generating the liveness verification confidence level according to the comparison result; When the liveness verification confidence meets the preset safety baseline condition, the spatiotemporal correlation features are mined by the identity feature extraction layer of the liveness detection algorithm to generate the user identity identification vector containing the user's biological behavior state identification.

4. The method according to claim 1, wherein The method of performing dynamic password enhanced authentication based on the liveness verification confidence and a preset security authentication threshold to generate a dynamic access token containing multiple layers of encryption identifiers includes: Dynamically comparing the liveness verification confidence with the security authentication threshold, and determining the encryption strength level of the dynamic password based on the difference interval between the confidence and the threshold; Selecting at least two encryption algorithms from a preset asymmetric encryption algorithm pool based on the encryption strength level and combining them to generate a multi-layer nested encryption algorithm combination; Extracting the biometric behavior state identifier from the user identity vector, and concatenating the biometric behavior state identifier with a timestamp generated in real time to form a dynamic password factor; Performing layer-by-layer nested encryption processing on the dynamic password factor by using the encryption algorithm combination, embedding an algorithm identifier corresponding to the selected encryption algorithm in the encryption algorithm combination after each layer of encryption, and generating an intermediate encryption identifier; The intermediate encryption identifiers are serially connected in the order of encryption levels, and an integrity verification code based on a dynamic check code is set at the end of the serial sequence to generate a dynamic access token containing the multiple layers of encryption identifiers.

5. The method according to claim 1, wherein The automatic storage authority matching process is performed based on the user identity vector and the dynamic access token, and the login verification result associated with the user authority level is output to the storage system according to the authority matching tag, including: Parsing the multi-layer encryption identifier from the dynamic access token, performing layer-by-layer reverse verification on the multi-layer encryption identifier based on a preset integrity verification code, stripping the algorithm identifier corresponding to each layer of encryption identifier and extracting the original spliced ​​data of the dynamic password factor; Performing timestamp synchronization verification on the original spliced ​​data based on the biometric behavior state identifier in the user identity identification vector, and generating permission matching request data containing a unique identifier of the user identity; Input the permission matching request data into the warehouse permission database, traverse the preset permission mapping table based on the user identity unique identifier, and obtain the permission identifier set and operation scope constraint conditions associated with the user identity unique identifier; Performing multi-dimensional feature dimensionality reduction processing on the permission identification set to generate a user permission feature vector, and performing spatial similarity matching between the user permission feature vector and the user identity identification vector to generate a permission association strength coefficient; Generate a dynamic permission mapping relationship based on the permission association strength coefficient and a preset permission level threshold, and label the dynamic permission mapping relationship in combination with the operation range constraint condition to form a permission matching label including an access authorization path and an operation instruction whitelist; The permission matching tag is combined with the integrity verification code in the dynamic access token for encryption to generate a login verification result carrying the user permission level identifier and the token verification status, and the login verification result is sent to the warehousing system to trigger the access control policy of the corresponding permission level.

6. The method according to claim 1, wherein The method further comprises: Acquire a historical attack behavior dataset, wherein the historical attack behavior dataset includes forged biometrics, mechanically repeated actions, and synthetic video attack samples; Performing feature space adversarial mapping on the historical attack behavior dataset and real user action data samples through an adversarial training model to obtain an adversarial mapping result; Optimizing the feature discrimination layer of the living body detection algorithm by using the adversarial mapping results and a preset dynamic weight adjustment mechanism; The robustness index of the optimized liveness detection algorithm is determined by noise interference data; according to the difference between the robustness index and the preset index, the feature discrimination layer decision parameters and attention weight distribution of the optimized liveness detection algorithm are reversely adjusted.

7. The method according to claim 6, wherein The adversarial mapping of the historical attack behavior dataset and the real user action data samples using the adversarial training model to obtain the adversarial mapping result includes: Extracting action sequence segments of forged biometric features, periodic trajectory data of mechanically repeated actions, and inter-frame difference features of synthetic video attack samples from the historical attack behavior dataset to generate an attack feature vector; Separating the dynamic change characteristics of the limb movement trajectory, the random fluctuation characteristics of the bioelectric response, and the instantaneous gradient characteristics of the touch pressure distribution from the real user action data sample to generate a real feature vector; Inputting the attack feature vector and the true feature vector into the adversarial generative network of the adversarial training model, and through alternating iterative training, making the generator of the adversarial generative network output an adversarial noise perturbation with the same statistical distribution as the true feature vector in the time-frequency domain; Injecting the adversarial noise perturbation into the attack feature vector, performing feature space adversarial mapping, and generating an adversarial feature distribution difference between the attack feature distribution carrying the adversarial perturbation and the true feature distribution; Performing adversarial gradient backpropagation on the adversarial feature distribution difference through the discriminator of the adversarial training model to calculate the adversarial loss value between the attack feature vector and the true feature vector in the dimensions of spatiotemporal continuity and biometric randomness; The generator weight parameters of the adversarial generative network are dynamically adjusted according to the adversarial loss value, so that the adversarial noise perturbation output by the generator forms an adversarial mapping result that maximizes feature confusion between the attack feature vector and the true feature vector.

8. The method according to claim 1, characterized in that After outputting the login verification result associated with the user authority level to the warehousing system according to the authority matching tag, the method further includes: Monitoring the calling frequency of the dynamic access token in the storage system and the security level of the associated operation instructions; When the call frequency exceeds a preset threshold or the security level reaches a preset risk level, a dynamic token update request is triggered; Generate a new dynamic password factor based on the user identity vector and the real-time timestamp, and generate a new dynamic access token based on a multi-layer nested encryption algorithm combination; The dynamic access token is replaced with the new dynamic access token, and a token update instruction is sent to the warehousing system to synchronously update the access control policy.

9. The method according to claim 1, characterized in that After outputting the login verification result associated with the user authority level to the warehousing system according to the authority matching tag, the method further includes: Real-time capture of user touch traces and warehouse interface interaction actions during operation to extract temporal features of operation behaviors; Compare the temporal characteristics of the operation behavior with the whitelist of operation instructions in the permission matching tag for action compliance to generate a behavior deviation index; When the behavior deviation index exceeds the preset alarm threshold, the current dynamic access token is frozen and the liveness detection algorithm is reactivated for secondary identity verification; The permission matching tag is updated based on the secondary verification results, and the abnormal operation behavior trajectory and permission adjustment records are stored through the warehouse system log.

10. An intelligent warehouse login verification system, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor is enabled to perform the steps of any one of the methods of claims 1 to 9.

Citation Information

Cited By

  • Multi-mode voiceprint identity intelligent verification method

    CN120877741A

  • A multi-modal voiceprint identity intelligent verification method

    CN120877741B

  • Identity authentication method and system based on multiple authentication of user identity

    CN121150968A

  • AI vision-based transformer substation operator dynamic authority management and control system

    CN121278706A

  • Non-contact laser on-line measurement method for thickness of corrugated board

    CN121612184A