Method and system for identity authentication

By grouping users and training classifiers for each group in ECG biometric systems, the method enhances accuracy and robustness, addressing the challenge of similar ECG characteristics in large populations.

TWI932160BActive Publication Date: 2026-07-11NATIONAL TSING HUA UNIVERSITY
0 Cites 0 Cited by

Patent Information

Application Number
TW114113444
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2026-07-11
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

Existing ECG biometric systems face challenges in maintaining high accuracy and robustness due to similar ECG characteristics among individuals, especially in large populations, leading to reduced recognition rates and reliability.

Method used

A decentralized approach is employed, where users are assigned to multiple user groups based on biometric information, and classifiers are trained for each group to authenticate users within their respective groups, using techniques like feature extraction and machine learning models to enhance accuracy.

Benefits of technology

This method improves the recognition rate and robustness of biometric systems by reducing feature repetition and optimizing computational resources, ensuring accurate identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMG-2_DRAW_114113444-A0305-14-0001-1
    Figure IMG-2_DRAW_114113444-A0305-14-0001-1
  • Figure IMG-2_DRAW_114113444-A0305-14-0002-2
    Figure IMG-2_DRAW_114113444-A0305-14-0002-2
  • Figure IMG-2_DRAW_114113444-A0305-14-0003-3
    Figure IMG-2_DRAW_114113444-A0305-14-0003-3
Patent Text Reader

Abstract

This invention proposes a method and system for identity authentication. The system includes a server. The server includes one or more non-transitory computer-readable memories and at least one processor. The one or more non-transitory computer-readable memories store one or more computer-executable instructions. The at least one processor is coupled to the one or more non-transitory computer-readable memories and is configured to execute the one or more computer-executable instructions to cause the server to assign users to multiple user groups based on multiple biometric information of multiple users, and to generate multiple classifiers corresponding to these user groups based on the multiple biometric information. Each classifier is trained to authenticate users in its corresponding user group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a biometric technology, and more particularly to a method and system for identity authentication using physiological biometric signals. Prior Technology

[0002] Electrocardiogram (ECG) signals are a type of physiological biometric signal widely used in biometric technology. Unlike external biometric features such as fingerprints, faces, and irises, ECG signals originate from an individual's cardiac electrical activity and are characterized by their difficulty in forgery, immutability, and real-time dynamic changes, giving them advantages in identity authentication and security verification systems. Existing ECG biometric technologies typically involve signal acquisition, feature extraction, and comparison to ensure the accuracy of identity verification.

[0003] In theory, each person's ECG signal should be unique because the anatomical structure and electrophysiological characteristics of the heart vary from person to person. However, in practical applications, due to various factors such as environmental variations in signal acquisition (e.g., electrode contact quality, noise), changes in physiological state (e.g., stress, fatigue), and the accuracy of the algorithm, the extracted feature data may exhibit some repetition or similar patterns. Therefore, when ECG biometric systems are applied to large populations (e.g., hundreds of people), the ECG characteristics of some individuals may be highly similar to those of others, thus reducing the recognition rate and affecting the reliability of identity authentication.

[0004] While existing technologies have proposed various methods to improve the accuracy of ECG biometrics, such as enhancing signal preprocessing techniques and improving feature extraction algorithms, effectively reducing ECG feature repetition rates and improving recognition accuracy remains a major challenge in this field. Therefore, an improved method is urgently needed to ensure that ECG biometric systems, and even other types of biometric systems, maintain high accuracy and robustness in large-scale application scenarios. Summary of the Invention

[0005] In view of this, the present invention provides a method and system for identity authentication that can utilize a decentralized concept to reduce the repetition rate of biometric features, thereby improving the accuracy and robustness of the biometric system.

[0006] A first aspect of the invention provides a system for identity authentication, including a server. The server includes one or more non-transitory computer-readable memories and at least one processor. The one or more non-transitory computer-readable memories store one or more computer-executable instructions. The at least one processor is coupled to the one or more non-transitory computer-readable memories and is configured to execute the one or more computer-executable instructions to cause the server to assign users to multiple user groups based on multiple biometric information of multiple users, and to generate multiple classifiers corresponding to these user groups based on the multiple biometric information. Each classifier is trained to authenticate users in its corresponding user group.

[0007] In some embodiments of the first aspect, the at least one processor described above is further configured to execute one or more computer-executable instructions to cause the server to send each classifier to the device associated with a user in the corresponding user group.

[0008] In some embodiments of the first aspect, the system further includes the aforementioned plurality of devices. The device for sending each classifier to a user associated with a corresponding user group includes sending the first classifier to a first device associated with the first user. The first device is configured to: obtain a first biometric signal of the first user; obtain a plurality of first biometric features corresponding to the first biometric signal; and authenticate the first user based on the plurality of first biometric features using the first classifier.

[0009] In some embodiments of the first aspect, the at least one processor described above is further configured to execute one or more computer-executable instructions to cause the server to: receive an authentication request, the authentication request including second biometric information and group information; select one of a plurality of classifiers based on the group information; and use the selected classifier to identify the identity of the registrant corresponding to the authentication request based on the second biometric information.

[0010] In some embodiments of the first aspect, the at least one processor described above is further configured to execute one or more computer-executable instructions to cause the server to: receive an authentication request, the authentication request including second biometric information; obtain multiple identification results based on the second biometric information using multiple classifiers; calculate the similarity between the second biometric feature corresponding to the second biometric information and the biometric feature corresponding to each identification result, so as to select the biometric feature corresponding to the highest similarity; and identify the login identity corresponding to the authentication request based on the identification result associated with the selected biometric feature.

[0011] In some embodiments of the first aspect, the aforementioned login identity corresponds to one of the users, and the aforementioned at least one processor is further configured to execute one or more computer-executable instructions to cause the server to: define a plurality of verification thresholds corresponding to a plurality of users, the login identity corresponding to a first verification threshold; verify the identification based on the first verification threshold after successful identification of the login identity; and determine whether to grant the authentication request after successful verification of the identification.

[0012] In some embodiments of the first aspect, the at least one processor described above is further configured to execute one or more computer-executable instructions to cause the server to: receive a registration request from a registrant, the registration request including third biometric information; calculate multiple intra-group dispersion values ​​after the registrant has joined multiple user groups based on the third biometric information; select the user group corresponding to the largest of the multiple intra-group dispersion values; assign the registrant to the selected user group; and fine-tune the classifier corresponding to the selected user group based on the third biometric information.

[0013] In some embodiments of the first aspect, assigning users to multiple user groups based on multiple first biometric information of multiple users includes: grouping the users into multiple approximate user groups based on feature similarity and multiple first biometric information; and distributing users in each approximate user group to different user groups in the multiple user groups.

[0014] In some embodiments of the first aspect, assigning users to multiple user groups based on multiple first biometric information of multiple users includes: randomly assigning users to different user groups within the multiple user groups.

[0015] A second aspect of the invention provides a method for identity authentication, comprising: assigning multiple users to multiple user groups based on multiple biometric information of multiple users; and generating multiple classifiers corresponding to these user groups based on the multiple biometric information. Each classifier is trained to authenticate users in its corresponding user group.

[0016] A third aspect of the present invention provides an identity authentication method applicable to at least one device. The identity authentication method includes: obtaining a user's physiological biometric signal; obtaining multiple biometric features corresponding to the physiological biometric signal; and authenticating the user using one of multiple classifiers based on these first biometric features. The multiple classifiers correspond to multiple user groups, each classifier being generated based on the biometric information of all users in its corresponding user group, and the user belonging to the user group corresponding to one of the classifiers. Simple Explanation of the Diagram

[0017] Figure 1 illustrates a schematic diagram of a system for identity authentication according to an embodiment of the present invention. Figure 2 illustrates a flowchart of a method for identity authentication according to an embodiment of the present invention. Figure 3 illustrates a schematic diagram of multiple classifiers corresponding to multiple user groups according to an embodiment of the present invention. Figure 4 illustrates a flowchart of the registration process for a registrant according to an embodiment of the present invention. Figure 5 illustrates a schematic diagram of a registrant registering according to an embodiment of the present invention. Figure 6 illustrates a flowchart of the login authentication process according to an embodiment of the present invention. Figure 7 illustrates a flowchart of the login authentication process according to an embodiment of the present invention. Figure 8 illustrates a flowchart of the login authentication process according to an embodiment of the present invention. Figure 9 shows a schematic block diagram of a computing system according to an embodiment of the present invention. Implementation

[0018] The following description contains specific information relating to exemplary embodiments of the present invention. The accompanying drawings and detailed description are merely exemplary embodiments. However, the invention is not limited to these exemplary embodiments. Other variations and embodiments of the invention will occur to those skilled in the art. Unless otherwise stated, the same or corresponding elements in the drawings are indicated by the same or corresponding reference numerals. Furthermore, the drawings and illustrations in this invention are generally not drawn to scale and are not intended to correspond to actual relative dimensions.

[0019] For the purposes of consistency and ease of understanding, the same features are indicated by reference numerals in the exemplary drawings (although this is not the case in some examples). However, features in different embodiments may differ in other respects, and therefore should not be narrowly limited to the features shown in the drawings.

[0020] The terms "at least one embodiment," "one embodiment," "multiple embodiments," "different embodiments," "some embodiments," and "this embodiment" indicate that the embodiments of the present invention described herein may include specific features, structures, or characteristics, but not every possible embodiment of the present invention must include such specific features, structures, or characteristics. Furthermore, the repeated use of the phrases "in one embodiment" and "in this embodiment" does not necessarily refer to the same embodiment, although they may be identical. Moreover, the use of phrases such as "embodiment" in connection with "the present invention" does not imply that all embodiments of the present invention must include specific features, structures, or characteristics, and should be understood as "at least some embodiments of the present invention" including the stated specific features, structures, or characteristics. The term "coupled" is defined as a connection, whether direct or indirect through an intermediate element, and is not necessarily limited to physical connections. When the term "comprising" is used, it means "including but not limited to," which explicitly indicates an open inclusion or relationship of combinations, groups, series, and equivalents.

[0021] Furthermore, for illustrative and non-restrictive purposes, specific details such as functional entities, technologies, protocols, and standards are elaborated to provide an understanding of the described technologies. In other examples, detailed descriptions of well-known methods, technologies, systems, architectures, etc., are omitted to avoid obscuring the explanatory narrative with unnecessary details.

[0022] The terms "first," "second," and "third," etc., used in the specification and accompanying drawings of this invention are for distinguishing different objects, not for describing a specific order, and do not necessarily correspond to "first," "second," and "third" in the claims. Furthermore, the term "comprising," and any variations thereof, is intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or modules is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other steps or modules inherent to these processes, methods, products, or apparatuses.

[0023] This invention proposes a system and method for identity authentication based on biometric information using a distributed approach. It must be noted that biometric information may include (e.g., pre-processed or unprocessed) physiological biometric signals and / or biometric features extracted from physiological biometric signals. In several embodiments of this invention, electrocardiogram (ECG) signals are used as examples of physiological biometric signals, and ECG features are used as examples of biometric features to illustrate the technology and effectiveness of this invention. However, this invention is not limited to the above. Those skilled in the art can apply the method proposed in this invention to other types of biometric information based on the technical concepts described in these embodiments.

[0024] In current biometric authentication systems, the recognition rate suffers as the number of users increases, and the required storage space and computing power also become challenging. Therefore, this invention proposes several embodiments to address these problems.

[0025] When a new user (e.g., a new registrant) is added, the classification model needs to be retrained using data from all existing users (e.g., all users who have previously registered), which results in a significant consumption of computational resources, especially when there are many users in the system. Therefore, this invention also proposes some embodiments to solve the above problems.

[0026] Figure 1 illustrates a schematic diagram of a system for identity authentication according to an embodiment of the present invention.

[0027] Referring to Figure 1, in this embodiment of the invention, the system 1 for identity authentication includes a server 10. For example, the system 1 may be an electrocardiogram (ECG) recognition system, and the server 10 may be the central server of the ECG recognition system.

[0028] Specifically, server 10 first assigns users to multiple user groups based on their biometric information (e.g., electrocardiogram signals / features), grouping users with relatively similar or comparable indistinguishable biometric information into different user groups. Then, for each user group, a classifier is generated using the biometric information of the users within that group. Each classifier can then be used to authenticate users within its corresponding user group while maintaining a high recognition rate.

[0029] It must be noted that the term "authentication" as used in this article can include "identification" and / or "verification". Identification refers to recognizing the identity of an object, such as a facial recognition system that can identify the identity of a person by analyzing a face, while verification refers to confirming whether an identity is valid, such as a mobile phone verifying the unlocker / login user by entering a password.

[0030] In some embodiments, system 1 further includes one or more terminal devices 20, 30, each terminal device 20, 30 corresponding to one or more users. For example, terminal device 20 may be a portable device, while terminal device 30 may be a fixed-point device such as a cash register system or access control system. The present invention does not limit the specific implementation of the terminal devices.

[0031] In some embodiments, the establishment of System 1 includes different stages such as setup, enrollment, and application (e.g., authentication), which will be described below with reference to the accompanying drawings.

[0032] [Establishment]

[0033] Figure 2 illustrates a flowchart of a method for identity authentication according to an embodiment of the present invention; Figure 3 illustrates a schematic diagram of multiple classifiers C1-Cn corresponding to multiple user groups G1-Gn according to an embodiment of the present invention. In Figure 2, the method for identity authentication is presented, for example, as flow 200. Furthermore, the method is executed, for example, by server 10 in system 1.

[0034] Please refer to Figures 2 and 3. In action S210, the server 10 assigns these users to multiple user groups G1~Gn (n is a natural number greater than 1) based on multiple biometric information of multiple users.

[0035] Specifically, server 10 first obtains multiple biometric data entries from multiple users (e.g., 50 entries per user). Then, based on some or all of the biometric data from the multiple users (e.g., 15 or 50 entries per user), server 10 assigns the users to multiple user groups G1 to Gn according to the biometric features (e.g., 15 or 50 sets per user, with each biometric data entry corresponding to a set of biometric features). For example, users with similar biometric features are assigned to different user groups as much as possible. It must be noted that this invention does not limit the specific determination of n; those skilled in the art can define it according to their needs (e.g., preset as a fixed value, determined based on the number of users, etc.).

[0036] In some embodiments, the operations performed by the server 10 based on multiple biometric information include operations based on multiple physiological biometric signals, such as using physiological biometric signals as input to a subsequent model.

[0037] In some embodiments, the operation performed by the server 10 based on multiple biometric information includes using a feature extractor to extract multiple sets of biometric features from multiple biometric information (e.g., physiological biometric signals).

[0038] In some embodiments, the aforementioned biometric information includes physiological biometric signals, such as electrocardiogram (ECG) signals. In some embodiments, the feature extractor is trained by the server 10 itself; in other embodiments, the feature extractor is not trained by the server 10 itself (e.g., it is pre-stored in the server 10).

[0039] In some embodiments, server 10 may train a machine learning model using an architecture including a feature extractor, based on multiple biometric records from multiple users. After training, the feature extractor can be used to extract biometric features from the biometric records.

[0040] For example, server 10 can utilize multiple ECG signals from multiple users (e.g., 15 ECG signals per user) and train a machine learning model using the AlexNet architecture, which includes a feature extractor (e.g., including convolutional layers and a first fully connected layer) and a classifier (e.g., including the last two fully connected layers). Therefore, after the machine learning model is trained, a trained feature extractor can be obtained (e.g., by extracting the convolutional layers and the first fully connected layer of the AlexNet architecture). However, this invention does not limit the specific architecture choice, and those skilled in the art can also choose other architectures such as ResNet.

[0041] In some embodiments, one or more of the multiple electrocardiogram signals from the multiple users described above may be synthetic electrocardiogram signals generated by synthesis.

[0042] In some embodiments, the server 10 may use a feature extractor to extract biometric features corresponding to multiple users, and then group the multiple users into multiple approximate user groups based on feature similarity, wherein users in each approximate user group have similar biometric features. Finally, for each approximate user group, the users are distributed among different user groups.

[0043] For example, server 10 can use the aforementioned feature extractor to extract ECG features corresponding to multiple users (e.g., 15 ECG signals per user, therefore 15 ECG features per user), and then calculate the average ECG feature for each user based on these ECG features. Subsequently, a clustering algorithm (e.g., K-means) is used to cluster these users based on these average ECG features, and then for each group (e.g., approximate user group), n users are repeatedly selected and distributed among n user groups G1~Gn. However, this invention does not limit the specific algorithm selection, and those skilled in the art can also choose other algorithms such as Support Vector Machine (SVM), KNN, etc. It is worth mentioning that a biometric information or ECG signal can correspond to a biometric feature or ECG feature. Since this biometric feature or ECG feature is composed of, for example, a vector containing multiple elements, the term "group" is used as the unit of feature in this document.

[0044] In some embodiments, for each remaining user not assigned to user groups G1 to Gn, the server 10 calculates, for example, the within-class scatter of the biometric features of the remaining user in each user group after the remaining user joins each user group, and assigns the remaining user to one of the user groups based on the within-class scatter. For example, the server 10 may select the user group that corresponds to the largest within-class scatter after the remaining user joins, to add the remaining user, in order to maintain high feature diversity within the same user group. Those skilled in the art to which this invention pertains will know the specific methods for calculating the within-class scatter based on multiple features or vectors within a group, and therefore will not be elaborated here.

[0045] In some embodiments, for each remaining user who has not been assigned to user groups G1 to Gn, the server 10 may randomly add them to one of the user groups.

[0046] In some embodiments, the aforementioned biometric information includes biometric features, such as electrocardiogram features extracted from electrocardiogram signals. In such embodiments, server 10 can directly assign multiple users to multiple user groups G1~Gn based on their biometric features without using a feature extractor.

[0047] In some embodiments, the aforementioned biometric information may be derived from a database (e.g., a PTB electrocardiogram diagnostic database). In some instances, the aforementioned biometric information may be generated through synthesis. In some embodiments, the aforementioned biometric information may be collected by server 10 when multiple users register with system 1.

[0048] Please return to Figures 2 and 3. In action S220, server 10 will generate multiple classifiers C1 to Cn corresponding to multiple user groups G1 to Gn based on multiple biometric information of multiple users.

[0049] Specifically, based on multiple biometric data entries from multiple users (e.g., 15 or 50 entries per user), server 10 trains a classifier for each user group based on the biometric features of all users in each user group (e.g., 15 or 50 sets per user, with each biometric data entry corresponding to a set of biometric features). Each classifier can then be used to authenticate users within its corresponding user group. For example, server 10 trains a classifier C1 corresponding to user group G1 based on the biometric features of users in user group G1 to authenticate users in user group G1; server 10 trains a classifier C2 corresponding to user group G2 based on the biometric features of all users in user group G2 to authenticate users in user group G2, and so on.

[0050] In some embodiments, for each user in each user group, the server 10 may obtain the average value and covariance of multiple sets of biometric features corresponding to that user, and expand the biometric feature data for each user using multivariate normal distribution sampling. In this way, the problem that the amount of data in the user group is insufficient to train a sufficiently accurate classifier is solved.

[0051] For example, for each user in user group G1, server 10 can expand to 900 biometric features using multivariate normal distribution sampling based on the average and covariance of its corresponding multiple (e.g., 15 or 50) biometric features. In this way, each user can have 500 biometric features as a training set, 200 biometric features as a validation set, and 200 biometric features as a test set to train the classifier C1 corresponding to user group G1.

[0052] In some embodiments, for each user, the server 10 calculates and records the corresponding electrocardiogram characteristics.

[0053] Taking the first user in user group G1 as an example, server 10 can obtain 15 electrocardiogram (ECG) features of the first user used to train classifier C1 through a feature extractor, and then take the statistics (e.g., average value) of these 15 ECG features as the ECG features corresponding to the first user. In the same way, server 10 can obtain the ECG features corresponding to all users in system 1.

[0054] In some embodiments, for each user, the server 10 also defines a verification threshold for that user based on multiple biometric information of that user (e.g., 15 biometric information that are the same as the biometric information used in action S210 out of 50 biometric information) and multiple other biometric information (e.g., another 10 biometric information out of 50 biometric information).

[0055] Taking the first user in user group G1 as an example, server 10 can obtain 15 electrocardiogram (ECG) features used to train classifier C1 for the first user (hereinafter referred to as first ECG features), and another 10 ECG features for the first user (hereinafter referred to as second ECG features). Then, server 10 uses kernel density estimation (KDE) to calculate 10 scores for each of the 10 second ECG features against the 15 first ECG features, and defines a validation threshold based on the statistics of these 10 scores. For example, th = μ - kσ is defined, where th is the validation threshold, μ and σ are the mean and standard deviation of the 10 scores, respectively, and k is a preset natural number. Accordingly, server 10 can obtain the validation threshold corresponding to the first user, and obtain the validation thresholds corresponding to all users in system 1 in the same way.

[0056] After completing process 200, system 1 can retain information on multiple users (e.g., account number, identification code, corresponding one or more sets of biometric features (e.g., electrocardiogram features), verification threshold, and / or the relationship between them and multiple user groups G1~Gn), as well as multiple classifiers C1~Cn (e.g., classifier parameters, architecture, and / or the correspondence between classifiers and multiple user groups G1~Gn), thus completing the construction of system 1 for identity authentication. For example, when a specific user needs to authenticate their identity, it can be done through the classifier corresponding to their user group. However, it must be noted that the specific method of identity authentication can include various forms (e.g., the division of labor among multiple different devices in system 1, etc.). Several feasible forms will be exemplarily described in one or more embodiments regarding the system application stage below, and those skilled in the art can extend or extrapolate to other forms.

[0057] In some embodiments, server 10 sends each classifier C1~Cn (and the data of all users in its associated user groups G1~Gn) to the terminal devices 20 and 30 associated with each user in the corresponding user group G1~Gn. In this way, users can perform authentication operations using the received classifiers through their associated terminal devices 20 and 30. For example, each user in user group G1 can use classifier C1 for authentication through their associated terminal devices 20 and 30 (e.g., all their portable devices or their membership POS systems); each user in user group G2 can use classifier C2 for authentication through their associated terminal devices 20 and 30 (e.g., all their portable devices or their membership POS systems), and so on.

[0058] In some embodiments, the server 10 sends the feature extractor to all the aforementioned terminal devices 20 and 30 so that they can extract features from the physiological biometric signals to extract biometric features.

[0059] [register]

[0060] Figure 4 illustrates a flowchart of a registrant registering according to an embodiment of the present invention; Figure 5 illustrates a schematic diagram of a registrant 50 registering according to an embodiment of the present invention. The registration method performed by the registrant in Figure 4 is presented, for example, as process 400. Furthermore, the registration method will be described from the viewpoint of server 10 in system 1; therefore, process 400 is executed, for example, by server 10 in system 1.

[0061] When a new user wants to join the system 1 used for identity authentication, they must first register. In the relevant embodiments, this new user who registers is referred to as the registrant.

[0062] Referring to Figures 4 and 5, in action S410, server 10 receives a registration request from registrant 50. Specifically, the registration request is a request sent by registrant 50 to system 1 for identity authentication, which includes one or more biometric information 510 corresponding to registrant 50.

[0063] In some embodiments, the biometric information 510 corresponding to the registrant 50 is, for example, an electrocardiogram (ECG) signal (e.g., with or without preprocessing). In some embodiments, the biometric information 510 corresponding to the registrant 50 is, for example, an ECG feature.

[0064] In action S420, the server 10 calculates the intragroup distribution values ​​V1 to Vn of the registrant 50 after joining each user group G1 to Gn based on the biometric information 510 in the received registration request.

[0065] Specifically, based on biometric information 510, server 10 obtains the biometric features corresponding to registrant 50, and then calculates the intragroup dispersion values ​​V1 to Vn of all biometric features after adding multiple existing biometric features corresponding to the existing users to the biometric features corresponding to registrant 50.

[0066] In some embodiments, biometric information 510 is, for example, an electrocardiogram signal, so the server 10 first uses a feature extractor to extract the biometric features corresponding to the registrant 50.

[0067] In action S430, server 10 selects the user group Gk corresponding to the largest value Vk (where k is a positive integer not less than 1 and not greater than n) among the group distribution values ​​V1~Vn. In action S440, server 10 assigns registrant 50 to the selected user group Gk. Therefore, registrant 50 will become one of the users in user group Gk.

[0068] In action S450, server 10 fine-tunes the classifier Ck corresponding to the selected user group Gk based on biometric information 510.

[0069] In some embodiments, the server 10 obtains the biometric features corresponding to the registrant 50, and then fine-tunes the classifier Gk based on the biometric features.

[0070] In some embodiments, when it is desired to increase the amount of data, the server 10 can obtain the average value and covariance of multiple biometric features corresponding to the registrant 50, and use multivariate normal distribution sampling to expand the data of biometric features corresponding to the registrant 50, and then fine-tune the classifier Gk accordingly.

[0071] After completing process 400, registrant 50 successfully completed registration in System 1 and was assigned to and joined user group Gk.

[0072] In some embodiments, server 10 sends classifier Ck to the terminal devices 20, 30 associated with all users in user group Gk to update the fine-tuned classifier Ck.

[0073] [application]

[0074] When a user wants to use System 1 for identity authentication, this user is referred to as a login user in the relevant embodiments. In some embodiments, the login user authenticates with one or more devices (e.g., server 10) that hold classifiers C1 to Cn.

[0075] Figure 6 illustrates a flowchart of user authentication according to an embodiment of the present invention. The authentication method performed by the user in Figure 6 is presented, for example, as process 600. Furthermore, the authentication method is described from the viewpoint of server 10 in system 1; therefore, process 600 is executed, for example, by server 10 in system 1. However, it must be noted that in other embodiments, classifiers C1-Cn (and feature extractors) may also be sent to other devices, and process 600 may be executed by those other devices.

[0076] Referring to Figure 6, in action S610, server 10 receives an authentication request from the user, wherein the authentication request includes (for example, biometric information corresponding to the user).

[0077] In some embodiments, the biometric information corresponding to the logged-in user is, for example, an electrocardiogram (ECG) signal (e.g., with or without preprocessing). For instance, the logged-in user can obtain an ECG signal over a period of time using an ECG signal measurement device and then send this ECG signal to server 10. In some embodiments, server 10 uses a feature extractor to extract the biometric features corresponding to the logged-in user from the biometric information. For example, server 10 uses a feature extractor to extract ECG features from the ECG signal.

[0078] In some embodiments, the biometric information corresponding to the logged-in user is, for example, electrocardiogram (ECG) features. For instance, the logged-in user can obtain ECG signals over a period of time using an ECG signal measurement device, and then use a feature extractor (e.g., in the logged-in user's terminal device 20) to obtain ECG features based on these ECG signals, and then send the ECG features to the server 10.

[0079] In action S620, server 10 uses multiple classifiers C1 to Cn to obtain multiple identification results based on the biometric information corresponding to the logged-in user. In some embodiments, the identification results are the output results of the classifiers on the biometric information (e.g., physiological biometric signals and / or biometric features) of the logged-in user.

[0080] For example, server 10 inputs the electrocardiogram features of the logged-in user into classifiers C1 to Cn respectively to obtain multiple (e.g., n) identification results. In other words, for each classifier, server 10 will obtain one identification result (e.g., identifying the logged-in user as a user), so for example, a total of n identification results will be obtained.

[0081] For example, server 10 inputs the ECG features of the logged-in user into classifier C1 to obtain a first identification result (e.g., identifying the logged-in user as a first user); and inputs the ECG features of the logged-in user into classifier C2 to obtain a second identification result (e.g., identifying the logged-in user as a second user), and so on.

[0082] In action S630, server 10 calculates the similarity between the biometric feature corresponding to the biometric information and the biometric feature corresponding to each identification result, and selects the biometric feature corresponding to the highest similarity. In addition, an identification result may correspond to a user, and each user may correspond to a biometric feature (e.g., electrocardiogram feature), as described in the previous paragraphs.

[0083] In some embodiments, the similarity between features can be represented by Euclidean distance, with a smaller Euclidean distance indicating higher similarity. However, it must be noted that this invention does not limit the specific implementation of feature similarity; those skilled in the art can design and / or choose according to their needs. For example, feature similarity can also be represented by cosine similarity or other parameters.

[0084] For example, server 10 calculates a first similarity between the ECG features of the logged-in user and the ECG features corresponding to the first identification result (e.g., the first user); and calculates a second similarity between the ECG features of the logged-in user and the ECG features corresponding to the second identification result (e.g., the second user), and so on, and then selects the ECG feature corresponding to the highest similarity (e.g., when the second similarity is the highest among n similarities, the ECG feature corresponding to the second identification result (e.g., the second user) is selected).

[0085] In action S640, server 10 identifies the login user corresponding to the authentication request based on the identification result associated with the selected biometric feature. Specifically, the biometric feature selected in action S630 is associated with an identification result, and this identification result corresponds to a user. Therefore, server 10 can identify the login user as this user.

[0086] For example, when server 10 selects the electrocardiogram feature corresponding to the second identification result in action S630, and since the second identification result corresponds to the second user, server 10 will identify the login identity corresponding to the authentication request as the second user.

[0087] In some embodiments, after the server 10 identifies the identity of the login user corresponding to the authentication request (also known as successful identification), it will further verify the final identification result (that is, the login user identity).

[0088] Specifically, server 10 can acquire multiple biometric features corresponding to the identified login user's identity (e.g., 15 electrocardiogram features used to calculate the verification threshold corresponding to the login user's identity), and then use kernel density estimation to calculate the verification score of the biometric feature selected in action S630 (e.g., the electrocardiogram feature corresponding to the second user) against the acquired multiple biometric features (e.g., the 15 electrocardiogram features used to calculate the verification threshold corresponding to the login user's identity), and verify the final identification result based on the verification score and the verification threshold. For example, if the verification score is higher than the verification threshold, the verification passes (e.g., login is successful or the authentication request is approved), otherwise the verification fails (e.g., login fails or the authentication request is not approved).

[0089] This further ensures that the person logging in is not an outsider to System 1 (e.g., a user who has never registered with System 1), thus improving the system's accuracy.

[0090] Figure 7 illustrates a flowchart of user authentication according to an embodiment of the present invention. The authentication method performed by the user in Figure 7 is presented, for example, as process 700. Furthermore, the authentication method is described from the viewpoint of server 10 in system 1; therefore, process 700 is executed, for example, by server 10 in system 1. However, it must be noted that in other embodiments, classifiers C1~Cn (and feature extractors) may also be sent to other devices, and process 700 may be executed by those other devices.

[0091] Referring to Figure 7, in action S710, server 10 receives an authentication request from the user, which includes biometric information and group information. Specifically, the group information includes, for example, an indication of a user group. Furthermore, the details of the biometric information included in the authentication request are the same as in the embodiment of Figure 6, and will not be repeated here.

[0092] In action S720, server 10 selects one of multiple classifiers C1 to Cn based on group information. Specifically, server 10 selects the classifier (e.g., C1) corresponding to the user group (e.g., user group G1) indicated by the group information.

[0093] In action S730, server 10 uses the selected classifier to identify the login user's identity based on biometric information in the authentication request.

[0094] In some embodiments, the server 10 may input the biometric features corresponding to the biometric information into a selected classifier, and the classifier may output the identity of the logged-in person as the final identification result.

[0095] For example, when server 10 selects classifier C1, server 10 will input electrocardiogram features into classifier C1, and classifier C1 will output the first user as the output result. Therefore, server 10 will identify the logged-in person as the first user, and thus obtain the final identification result.

[0096] In some embodiments, after the server 10 identifies the identity of the login user corresponding to the authentication request (also known as successful identification), it will further verify the final identification result (that is, the login user identity).

[0097] Specifically, when server 10 identifies the identity of the logged-in user using the selected classifier, it can obtain multiple biometric features corresponding to the identified logged-in user identity (e.g., 15 electrocardiogram features used to calculate the verification threshold corresponding to the logged-in user identity). Then, it uses kernel density estimation to calculate the verification score of the biometric features (e.g., electrocardiogram features) corresponding to the authentication request against the aforementioned multiple biometric features (e.g., the 15 electrocardiogram features used to calculate the verification threshold corresponding to the logged-in user identity). The final identification result is verified based on the verification score and the verification threshold. For example, if the verification score is higher than the verification threshold, the verification passes (e.g., login is successful or the authentication request is approved); otherwise, the verification fails (e.g., login fails or the authentication request is not approved).

[0098] This further ensures that the person logging in is not an outsider to System 1 (e.g., a user who has never registered with System 1), thus improving the system's accuracy.

[0099] Figure 8 illustrates a flowchart of user authentication according to an embodiment of the present invention. The authentication method performed by the user in Figure 8 is presented, for example, as process 800. Furthermore, the authentication method is performed, for example, by a first device associated with a first user in user group G1 of system 1. However, it should be noted that the same authentication method can be performed by other users, by other terminal devices of the first user, or by other terminal devices of other users of system 1. Furthermore, the first device described below is not limited to a single device and can be implemented through the collaboration of multiple devices.

[0100] As described in the previous paragraphs, server 10 can send the data of the feature extractor, each classifier C1~Cn, and all users in their associated user groups G1~Gn to the terminal devices 20 and 30 associated with each user in the corresponding user group G1~Gn. Therefore, the first device may, for example, store data such as the feature extractor, classifier C1, and the first user's account, identification code, corresponding biometric features, and / or verification threshold.

[0101] Referring to Figure 8, in action S810, the first device acquires the physiological biometric signal of the first user.

[0102] In some embodiments, the physiological biometric signal is, for example, an electrocardiogram (ECG) signal.

[0103] For example, a first user can obtain an electrocardiogram (ECG) signal over a period of time using an ECG signal measuring device (e.g., located on or coupled to the first device).

[0104] In action S820, the first device acquires multiple first biometric features corresponding to the physiological biometric signal. Specifically, the first device uses a feature extractor to extract multiple biometric features from the physiological biometric signal.

[0105] For example, server 10 uses a feature extractor to extract ECG features from the ECG signal.

[0106] In action S830, the first device uses classifier C1 to authenticate the first user based on biometric features.

[0107] For example, the first device inputs electrocardiogram features into classifier C1, and classifier C1 outputs, for example, the first user as the output result (e.g., identification result).

[0108] In some embodiments, when the first device authenticates the first user using classifier C1, it can obtain multiple biometric features corresponding to the first user (e.g., 15 electrocardiogram features used to calculate the verification threshold corresponding to the first user). Then, it uses kernel density estimation to calculate the verification score of the biometric features (e.g., electrocardiogram features) obtained in action S820 against the multiple biometric features (e.g., the 15 electrocardiogram features used to calculate the verification threshold corresponding to the first user), and verifies the final identification result based on the verification score and the verification threshold. For example, if the verification score is higher than the verification threshold, the verification passes (e.g., the first user authentication / login is successful); otherwise, the verification fails (e.g., the first user authentication / login fails).

[0109] Figure 9 shows a schematic block diagram of a computing system according to an embodiment of the present invention.

[0110] Referring to Figure 9, the authentication method described herein can be implemented on one or more computing systems 900 having various hardware components. In other words, the computing system 900 can be implemented as a system 1, server 10, and / or terminal devices 20, 30 for authentication. In some embodiments, the computing system 900 can be implemented, for example, as an electronic device, which includes, but is not limited to, one or more of the following components: a central processing unit (CPU) 910, a graphics processing unit (GPU) 920, an input / output element 930, a network element 940, and a memory 950, which can communicate and transmit data via the system bus 960. However, the present invention does not limit the specific model, quantity, and configuration of the components, and those skilled in the art can adjust, select, or add or remove components according to the specific needs and operating environment when implementing the present invention.

[0111] In some embodiments, the main computing core within the computing system 900 is one or more processors 910. These processors 910 are responsible for running the main computational processes and related control logic of algorithms such as deep learning. In some embodiments, the processor 910 is used to execute processing instructions (i.e., machine-executable instructions) stored in a non-volatile computer-readable medium (e.g., storage device 970).

[0112] In some embodiments, to improve the computational efficiency of deep learning, the computing system 900 may further include one or more image processors 920 specifically designed for performing massive parallel computations. These image processors 920 can effectively enhance the system's computational power during deep learning training and inference.

[0113] In some embodiments, the computing system 900 may include a variety of input / output elements 930 for receiving user input and displaying system output. For example, these input / output elements 930 may include a keyboard, mouse, touchpad, display screen, speaker, and other types of sensing devices.

[0114] In some embodiments, the computing system 900 may also include a network element 940 for network communication. For example, this network element 940 may include a network interface card for wired or wireless network connections, or a communication module for 3G, 4G, 5G or other wireless communication technologies.

[0115] In some embodiments, the computing system 900 may include one or more memory elements 950, such as volatile memory elements like random access memory (RAM). The memory 950 may be used to store parameters of a deep learning model, as well as other data and programs used to run algorithms such as deep learning. In some embodiments, the memory 950 may, for example, store a feature extractor.

[0116] In addition, the computing system 900 may include one or more of the following components: storage device 970, power management component 980, and various other components 990.

[0117] In some embodiments, the computing system 900 may include one or more storage devices 970, such as non-volatile memory elements like hard disk drives (HDDs) or solid-state drives (SSDs). These storage devices 970 can be used to store information such as the code, training data, and model parameters of deep learning software. Furthermore, the storage devices 970 can also be used to store intermediate results and final outputs of deep learning and other algorithms.

[0118] In some embodiments, the computing system 900 may include one or more power management elements 980 for providing power to various hardware components of the computing system 900 and managing their power consumption. This power management element 980 may include a battery, a power converter, and other power management devices.

[0119] In some embodiments, the computing system 900 may also include various other (hardware) components 990, such as cooling fans, heat sinks, and other various control and monitoring devices, which are not limited thereto.

[0120] Furthermore, the embodiments described herein can also be implemented as one or more computer program products, including computer programs having one or more instructions. Specifically, a computer program (also referred to as a program, software, script, or code) can be presented in any form of programming language, and this computer program can be deployed in any form. During the operation of the computing system 900 (e.g., an electronic device), the instructions, or a portion thereof, may also reside wholly or at least partially within the processor 910 to cause the processor 910 to perform the methods described herein.

[0121] In summary, the method and system for identity authentication proposed in this invention employ a distributed architecture to reduce the duplication rate of biometric features, thereby improving the scalability, accuracy, and robustness of the identity authentication system utilizing biometric information. Furthermore, under this architecture, this invention also proposes a more efficient and computationally efficient registration method.

[0122] Based on the above description, it is evident that various techniques can be used to implement the concepts described in this application without departing from the scope of these concepts. Furthermore, although the concepts have been described with specific reference to certain embodiments, those skilled in the art will recognize that changes in form and detail may be made without departing from the scope of these concepts. Thus, the described embodiments are to be considered illustrative rather than restrictive in all respects. Moreover, it should be understood that this application is not limited to the specific embodiments described above, but many rearrangements, modifications, and substitutions can be made without departing from the scope of the invention.

[0123] 1: System 10: Server 20, 30: Terminal devices 400, 600, 700, 800: Process 50: Registrants 510: Biometric Information 900: Computing System 910: Processor 920: Image Processor 930: Input / Output Components 940: Network Components 950: Memory 960: Busbar 970: Storage devices 980: Power Management Component 990: Other components C1, C2, Ck, Cn: Classifiers G1, G2, Gk, Gn: User groups S210, S220: Steps for methods used in identity authentication S410, S420, S430, S440, S450: Registration Steps S610, S620, S630, S640, S710, S720, S730, S810, S820, S830: Certification Steps V1, V2, Vk, Vn: Within-group scatter values

Claims

1. A system for identity authentication, comprising: A server includes: one or more non-transitory computer-readable memories storing one or more computer-executable instructions; and at least one processor coupled to the one or more non-transitory computer-readable memories and configured to execute the one or more computer-executable instructions, such that the server: allocates the users to multiple user groups based on multiple first biometric information of multiple users using a clustering algorithm, wherein the allocation includes: grouping the users into multiple approximate user groups based on feature similarity according to the first biometric information; and distributing the users in each approximate user group to different user groups within the user groups; and training with the first biometric information in each user group to generate multiple classifiers corresponding to the user groups, wherein each classifier is trained to identify one or more users in the corresponding user group.

2. The system as claimed in claim 1, wherein the at least one processor is further configured to execute the one or more computer-executable instructions to cause the server to: send each classifier to one or more devices associated with the one or more users in the corresponding user group.

3. The system as described in claim 2, further comprising the one or more devices, wherein sending each classifier to the one or more devices associated with the one or more users in the corresponding user group includes sending a first classifier to a first device associated with a first user, and the first device is configured to: obtain a first physiological biometric signal of the first user; obtain a plurality of first biometric features corresponding to the first physiological biometric signal; and authenticate the first user based on the first biometric features using the first classifier.

4. The system of claim 1, wherein the at least one processor is further configured to execute the one or more computer-executable instructions to cause the server to: receive an authentication request, the authentication request including second biometric information and group information; select one of the classifiers based on the group information; and use the selected classifier to identify the identity of the registrant corresponding to the authentication request based on the second biometric information.

5. The system of claim 1, wherein the at least one processor is further configured to execute the one or more computer-executable instructions to cause the server to: receive an authentication request, the authentication request including second biometric information; obtain multiple identification results based on the second biometric information using the classifiers respectively; calculate the similarity between a second biometric feature corresponding to the second biometric information and a biometric feature corresponding to each of the identification results, to select the biometric feature corresponding to the highest similarity; and identify the identity of the login person corresponding to the authentication request based on the identification result associated with the selected biometric feature.

6. The system as described in claim 4 or 5, wherein the logged-in identity corresponds to one of the users, and the at least one processor is further configured to execute the one or more computer-executable instructions to cause the server to: define a plurality of authentication thresholds corresponding to the users, the logged-in identity corresponding to a first authentication threshold; verify the authentication based on the first authentication threshold after successful identification of the logged-in identity; and determine whether to grant the authentication request after successful verification of the identification.

7. The system of claim 1, wherein the at least one processor is further configured to execute the one or more computer-executable instructions to cause the server to: receive a registration request from a registrant, the registration request including third biometric information; calculate, based on the third biometric information, multiple intra-group dispersion values ​​for the registrant after joining the user groups; select the user group corresponding to the largest of the intra-group dispersion values; assign the registrant to the selected user group; and fine-tune the classifier corresponding to the selected user group based on the third biometric information.

8. A method for identity authentication, comprising: Based on multiple biometric information of multiple users, a clustering algorithm is used to assign these users to multiple user groups. The assignment includes: grouping the users into multiple approximate user groups based on feature similarity and the biometric information; and distributing the users in each approximate user group to different user groups within the user groups; and training multiple classifiers corresponding to the user groups using the biometric information in each user group, wherein each classifier is trained to authenticate one or more users in the corresponding user group.

9. An identity authentication method, applicable to at least one device, the identity authentication method comprising: Obtain the user's physiological biometric signal; obtain multiple biometric features corresponding to the physiological biometric signal; based on these biometric features, authenticate the user using one of multiple classifiers, wherein: these classifiers correspond to multiple user groups, each of these classifiers is generated by training with biometric information of all users in a corresponding user group among these user groups, wherein these user groups are formed by using a clustering algorithm to group these users into multiple approximate user groups based on feature similarity, and then distributing the users in each approximate user group to different user groups, and the user belongs to the user group corresponding to one of these classifiers.