A method, system, electronic device and storage medium for permission recognition

Through the collaborative work of terminal devices and servers, permission information is updated in real time, solving the security risks of permission identification devices during non-adaptive updates, and achieving higher recognition accuracy and security.

CN113961889BActive Publication Date: 2025-08-01HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111217234.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-19
Publication Date
2025-08-01
Estimated Expiration
2041-10-19

AI Technical Summary

Technical Problem

During the non-adaptive update period, the existing permission identification device can still identify objects that lose permissions through permissions, resulting in security risks and inaccurate identification.

Method used

Through the collaborative work of the terminal device and the server, the permission information and feature information of the target to be identified are updated in real time, and the first and second feature extraction algorithms are used for comparison to ensure the accuracy of permission recognition.

Benefits of technology

It improves the accuracy of permission recognition, reduces security problems caused by inaccurate identification, and ensures real-time and security of permission recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113961889B_ABST
    Figure CN113961889B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method, system, electronic device and storage medium for permission recognition. The method includes: obtaining the target biometric feature of the target to be recognized; extracting the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; sending the target biometric feature or the target feature information to the server; receiving the permission comparison result sent by the server; if the permission comparison result is that the target to be recognized has the access permission to the terminal device, determining that the target to be recognized passes the permission recognition, and updating the permission information and feature information of the target to be recognized in the local database. Applying this method makes the biometric permission recognition more accurate and greatly reduces the security problems caused by inaccurate permission recognition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electronic information processing, and particularly to a method, a system, an electronic device and a storage medium for permission identification. Background Art

[0002] In order to strengthen security management, many enterprises use permission identification devices to identify the permissions of employees entering and leaving the unit. Only employees identified as having permissions can enter the unit. Specifically, the permission identification device can obtain the image features of the object to be identified, and compare the image features with the image features stored in the local database. If the comparison result shows that the object to be identified has the passing permission, it can be released.

[0003] However, currently, permission identification devices usually update the local image feature data adaptively, which makes objects that lose their permissions during non - adaptive updates able to pass through the permission identification, that is, the permission identification is not accurate enough, leading to potential safety hazards. For example, the passing permission of object A to enter unit X expires during the non - adaptive update period of the permission identification device. Since the permission identification device has not updated the passing permission of object A, there may be a problem that object A can still enter unit X after the passing permission expires. Therefore, the current permission identification method has relatively large safety hazards. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a method, a system, an electronic device and a storage medium for permission identification, so as to improve the accuracy of permission identification and reduce the safety problems caused by inaccurate permission identification.

[0005] In a first aspect, an embodiment of the present invention provides a method for permission identification, which is applied to a terminal device of a permission identification system. The permission identification system further includes a server. The method includes:

[0006] Obtain the target biometric feature of the target to be identified;

[0007] Based on the first feature extraction algorithm of the terminal device, extract the target feature information of the target biometric feature; if the comparison between the target feature information and the local database fails, and when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server, and when the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server;

[0008] Receive the permission comparison result sent by the server; the permission comparison result is determined by the server based on the target biometric feature or the target feature information;

[0009] If the result of the permission comparison indicates that the target to be identified has the access permission to the terminal device, it is determined that the target to be identified passes the permission identification, and based on the result of the permission comparison, the permission information and feature information of the target to be identified in the local database are updated.

[0010] Optionally, updating the permission information and feature information of the target to be identified in the local database includes:

[0011] In the case where the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, update the target biometric feature and permission information;

[0012] In the case where the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the target feature information.

[0013] Optionally, after extracting the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device, it further includes:

[0014] If the target feature information matches the local database successfully, when the terminal device enables secondary authentication of the access permission, send the identity identifier of the target to be identified to the server;

[0015] Receive the secondary authentication result of the access permission sent by the server; the secondary authentication result of the access permission is determined by the server based on the identity identifier;

[0016] If the secondary authentication result of the access permission indicates that the target to be identified does not have the access permission to the terminal device, prompt that the target to be identified fails the permission identification.

[0017] Optionally, the method further includes:

[0018] Receive the first permission update instruction sent by the server, where the first permission update instruction includes: first feature information and permission information to be updated;

[0019] In the case where the first feature extraction algorithm is consistent with the second feature extraction algorithm, based on the first feature information and the permission information to be updated, update the feature information and permission information of the target to be updated in the local database;

[0020] In the case where the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, extract the second feature information of the biometric feature of the target to be updated based on the first feature extraction algorithm, and update the feature information and permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated.

[0021] Optionally, updating the feature information and permission information of the target to be updated in the local database based on the first feature information and the permission information to be updated includes:

[0022] Comparing the first feature information with the feature information stored in the local database;

[0023] If there is feature information in the local database that matches the first feature information, replace the feature information of the target to be updated in the local database with the first feature information, and update the access permission of the target to be updated according to the permission information to be updated;

[0024] If there is no feature information in the local database that matches the first feature information, determine whether the number of targets stored in the local database reaches a preset number;

[0025] If it does not reach the preset number, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database according to the preset polling deletion rule, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0026] Optionally, updating the feature information and permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated includes:

[0027] Comparing the second feature information with the feature information stored in the local database;

[0028] If there is feature information in the local database that matches the second feature information, replace the feature information of the target to be updated in the local database with the second feature information, and update the access permission of the target to be updated according to the permission information to be updated;

[0029] If there is no feature information in the local database that matches the second feature information, determine whether the number of targets stored in the local database reaches a preset number;

[0030] If the preset quantity is not reached, store the second feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if the preset quantity is reached, according to the preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the second feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0031] Optionally, the method further includes:

[0032] Receive a second permission update instruction sent by the server, where the second permission update instruction includes: biometric features and permission information to be updated;

[0033] Extract biometric feature information corresponding to the biometric features based on the first feature extraction algorithm of the terminal device;

[0034] Compare the biometric feature information with the feature information stored in the local database;

[0035] If there is feature information in the local database that matches the biometric feature information, replace the feature information of the target to be updated in the local database with the biometric feature information, and update the access permission of the target to be updated according to the permission information to be updated;

[0036] If there is no feature information in the local database that matches the biometric feature information, determine whether the number of targets stored in the local database reaches a preset quantity;

[0037] If the preset quantity is not reached, store the biometric feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if the preset quantity is reached, according to the preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the biometric feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0038] Optionally, the method further includes:

[0039] For each target in the local database, determine whether the access permission of the target has expired;

[0040] If it has expired, delete the data corresponding to the target in the local database;

[0041] If it has not expired, the load of the terminal device is obtained, a corresponding management strategy is determined based on the load, and data corresponding to each target in the local database is updated based on the determined management strategy until all targets in the local database are polled.

[0042] Optionally, before determining whether the access permission of each target in the local database has expired, the method further includes:

[0043] Determine whether the current time is within the preset permission recognition peak time period;

[0044] If yes, determining whether the load of the terminal device reaches a preset load threshold;

[0045] If the preset load threshold is reached, data corresponding to the target that has no authority identification record within the second preset time period in the local database is deleted.

[0046] In a second aspect, an embodiment of the present invention provides a method for identifying permissions, which is applied to a server of a permission identification system, wherein the permission identification system also includes a terminal device. The method includes:

[0047] receiving a target biometric feature or target feature information of a target to be identified sent by the terminal device;

[0048] Determining an authority comparison result for the target to be identified based on the target biometric feature or the target feature information;

[0049] The permission comparison result is sent to the terminal device.

[0050] Optionally, the authority identification system further includes an authority management platform;

[0051] Before receiving the target biometric feature or target feature information of the target to be identified sent by the terminal device, the method further includes:

[0052] Receive information from the permission management platform about the permission groups to which each target belongs; wherein each permission group includes at least one terminal device, and each target has access rights to each terminal device in the permission group to which it belongs;

[0053] The determining, based on the target biometric feature or the target feature information, a result of authority comparison for the target to be identified includes:

[0054] comparing the feature information extracted based on the target biometric feature or the target feature information with the feature information stored in the server database, and determining the permission group to which the target to be identified belongs;

[0055] If there is feature information in the server database that matches the target feature information or the extracted feature information, and the terminal device is included in the permission group to which the target to be identified belongs, then the result of the permission identification of the target to be identified through the terminal device and the expiration information of the target to be identified having the access permission to the terminal device are determined as the permission comparison result;

[0056] If there is feature information in the server database that matches the target feature information or the extracted feature information, and the terminal device is not included in the permission group to which the target to be identified belongs, then the result of the target to be identified failing to pass the permission identification of the terminal device and the information that the target to be identified does not have the access permission to the terminal device are determined as the permission comparison result;

[0057] If there is no feature information in the server database that matches the target feature information and the extracted feature information, then the result of the target to be identified failing to pass the permission identification of the terminal device is determined as the permission comparison result.

[0058] In a third aspect, an embodiment of the present invention provides a permission identification system, and the system includes a server and a terminal device;

[0059] The terminal device is configured to obtain the target biometric feature of the target to be identified; extract the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server, and if the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server;

[0060] The server is configured to receive the target biometric feature or the target feature information of the target to be identified sent by the terminal device; determine the permission comparison result for the target to be identified based on the target biometric feature or the target feature information, and send the permission comparison result to the terminal device;

[0061] The terminal device is further configured to receive the permission comparison result sent by the server; if the permission comparison result is that the target to be identified has the access permission to the terminal device, determine that the target to be identified passes the permission identification, and update the permission information and the feature information of the target to be identified in the local database based on the permission comparison result.

[0062] Optionally, the terminal device is specifically configured to update the target biometric feature and the permission information when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm; and update the target feature information when the first feature extraction algorithm is consistent with the second feature extraction algorithm.

[0063] Optionally, the terminal device is further configured to, if the comparison between the target feature information and the local database is successful, and when the secondary authentication of the access permission is enabled on the terminal device, send the identity identifier of the target to be recognized to the server; receive the secondary authentication result of the access permission sent by the server; the secondary authentication result of the access permission is determined by the server based on the identity identifier; if the secondary authentication result of the access permission indicates that the target to be recognized does not have the access permission to the terminal device, prompt that the target to be recognized fails the permission recognition.

[0064] Optionally, the terminal device is further configured to receive a first permission update instruction sent by the server, where the first permission update instruction includes: the biometric feature of the target to be updated, the first feature information, and the permission information to be updated; when the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the feature information and the permission information of the target to be updated in the local database based on the first feature information and the permission information to be updated; when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, extract the second feature information of the biometric feature of the target to be updated based on the first feature extraction algorithm, and update the feature information and the permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated.

[0065] Optionally, the terminal device is specifically configured to compare the first feature information with the feature information stored in the local database; if there is feature information in the local database that matches the first feature information, replace the feature information of the target to be updated in the local database with the first feature information, and update the access permission of the target to be updated according to the permission information to be updated; if there is no feature information in the local database that matches the first feature information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission recognition within the first preset time period in the local database according to the preset polling deletion rule, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0066] Optionally, the terminal device is specifically configured to compare the second feature information with the feature information stored in the local database; if there is feature information matching the second feature information in the local database, replace the feature information of the target to be updated in the local database with the second feature information, and update the access permission of the target to be updated according to the access permission information to be updated; if there is no feature information matching the second feature information in the local database, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database according to the preset polling deletion rule, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

[0067] Optionally, the terminal device is further configured to receive a second permission update instruction sent by the server, where the second permission update instruction includes: biometric features and access permission information to be updated; extract biometric information corresponding to the biometric features based on the first feature extraction algorithm of the terminal device; compare the biometric information with the feature information stored in the local database; if there is feature information matching the biometric information in the local database, replace the feature information of the target to be updated in the local database with the biometric information, and update the access permission of the target to be updated according to the access permission information to be updated; if there is no feature information matching the biometric information in the local database, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the biometric information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database according to the preset polling deletion rule, store the biometric information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

[0068] Optionally, the terminal device is further configured to determine whether the access permission of each target in the local database has expired; if it has expired, delete the data corresponding to the target in the local database; if it has not expired, obtain the load of the terminal device, determine the corresponding management policy based on the load, and update the data corresponding to each target in the local database based on the determined management policy until all the targets in the local database have been polled.

[0069] Optionally, the terminal device is further configured to determine whether the current time is within a preset permission recognition peak time period before determining whether the access permission of each target for the local database has expired; if so, determine whether the load of the terminal device reaches a preset load threshold; if the preset load threshold is reached, delete the data corresponding to the target without permission recognition records within a second preset time period in the local database.

[0070] Optionally, the system further includes a permission management platform;

[0071] The permission management platform is configured to assign a permission group to which each target belongs and send information on the permission group to which each target belongs to the server, where each permission group includes at least one terminal device, and each target has access permissions for each terminal device within its permission group;

[0072] The server is further configured to receive the information on the permission group to which each target belongs sent by the permission management platform;

[0073] Specifically, the server is further configured to compare the feature information extracted based on the target biometric or the target feature information with the feature information stored in the server database, and determine the permission group to which the target to be recognized belongs; if there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs includes the terminal device, then determine the result of the permission recognition of the target to be recognized through the terminal device and the expiration information of the access permission of the target to be recognized for the terminal device as the permission comparison result; if there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs does not include the terminal device, then determine the result that the target to be recognized fails the permission recognition of the terminal device and the information that the target to be recognized does not have the access permission of the terminal device as the permission comparison result; if there is no feature information in the server database that matches the target feature information and the extracted feature information, then determine the result that the target to be recognized fails the permission recognition of the terminal device as the permission comparison result.

[0074] In a fourth aspect, an embodiment of the present invention provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, where the processor, the communication interface, and the memory complete mutual communication through the communication bus;

[0075] The memory is used to store a computer program;

[0076] A processor, when executing a program stored in a memory, implements the method steps described in any one of the first aspect or the second aspect above.

[0077] In a fifth aspect, an embodiment of the present invention provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method steps described in any one of the first aspect or the second aspect above are implemented.

[0078] Beneficial effects of the embodiments of the present invention:

[0079] By using the method provided in the embodiment of the present invention, the target biometric feature of the target to be recognized is obtained; the target feature information of the target biometric feature is extracted based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, the target biometric feature is sent to the server, and if the first feature extraction algorithm is consistent with the second feature extraction algorithm, the target feature information is sent to the server; the permission comparison result sent by the server is received; if the permission comparison result indicates that the target to be recognized has the access permission to the terminal device, it is determined that the target to be recognized passes the permission recognition, and based on the permission comparison result, the permission information and feature information of the target to be recognized in the local database are updated. That is, by combining the local database of the terminal device and the server database to update the access permission of the target to be recognized in real time, the biometric permission recognition is made more accurate, and the security problems caused by inaccurate permission recognition are greatly reduced.

[0080] Of course, when implementing any product or method of the present invention, it is not necessarily required to achieve all the above-mentioned advantages simultaneously. BRIEF DESCRIPTION OF THE DRAWINGS

[0081] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other embodiments based on these drawings.

[0082] Figure 1 It is a flowchart of a permission recognition method provided by an embodiment of the present invention;

[0083] Figure 2 It is a flowchart of a secondary authentication of permission provided by an embodiment of the present invention;

[0084] Figure 3 It is a system topology diagram of a permission recognition system;

[0085] Figure 4 It is a flowchart of determining a permission comparison result;

[0086] Figure 5 A flowchart of permission update provided by an embodiment of the present invention;

[0087] Figure 6 Another flowchart of permission update provided by an embodiment of the present invention;

[0088] Figure 7 Another flowchart of permission update provided by an embodiment of the present invention;

[0089] Figure 8 A schematic structural diagram of a permission recognition system provided by an embodiment of the present invention;

[0090] Figure 9 Another schematic structural diagram of a permission recognition system provided by an embodiment of the present invention;

[0091] Figure 10 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners

[0092] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art based on this application belong to the protection scope of the present invention.

[0093] In order to improve the accuracy of permission recognition and reduce security problems caused by inaccurate permission recognition, an embodiment of the present invention provides a permission recognition method, system, electronic device, computer-readable storage medium, and computer program product.

[0094] Next, the permission recognition method provided by the embodiment of the present invention will be introduced first. The permission recognition method provided by the embodiment of the present invention can be applied to the terminal device of the permission recognition system, and the permission recognition system further includes a server. Among them, the terminal device of the permission recognition system can be any electronic device with functions of biometric feature extraction, analysis, and comparison, which is not specifically limited here. The server of the permission recognition system can be a device with functions of biometric feature extraction, analysis, and comparison, and capable of providing services and interfaces externally.

[0095] Figure 1 A flowchart of the permission recognition method provided by an embodiment of the present invention, as Figure 1 shown, the method includes:

[0096] S101, obtaining the target biometric feature of the target to be recognized.

[0097] S102, extract the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server, and when the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server.

[0098] S103, receive the permission comparison result sent by the server.

[0099] Wherein, the permission comparison result is determined by the server based on the target biometric feature or the target feature information.

[0100] S104, if the permission comparison result indicates that the target to be recognized has the access permission to the terminal device, determine that the target to be recognized passes the permission recognition, and based on the permission comparison result, update the permission information and feature information of the target to be recognized in the local database.

[0101] By using the method provided in the embodiments of the present invention, obtain the target biometric feature of the target to be recognized; extract the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server, and when the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server; receive the permission comparison result sent by the server; if the permission comparison result indicates that the target to be recognized has the access permission to the terminal device, determine that the target to be recognized passes the permission recognition, and based on the permission comparison result, update the permission information and feature information of the target to be recognized in the local database. That is, by combining the local database of the terminal device and the server database to update the access permission of the target to be recognized in real time, the biometric permission recognition is made more accurate, and the security problems caused by inaccurate permission recognition are largely reduced.

[0102] In the embodiments of the present invention, the permission recognition system can be applied to the intelligent access control of each unit. For example, it can be determined whether the target to be recognized passing through the access point has the access permission through the permission recognition system. The target to be recognized with the access permission can be released, while the target to be recognized without the access permission is not released. The target to be recognized can be any person who wants to pass through the access point.

[0103] In an embodiment of the present invention, specifically, if a designated part of the target to be recognized (such as the face) appears in the capture lens of the terminal device of the permission recognition system, it can be determined that the terminal device of the permission recognition system has received a permission recognition instruction for the target to be recognized; or, if a designated button of the terminal device (such as a permission recognition button) is triggered, it can also be determined that the terminal device has received a permission recognition instruction for the target to be recognized. Then, after receiving the permission recognition instruction, the terminal device can capture an image of the designated part of the target to be recognized as the target biometric of the target to be recognized.

[0104] In an embodiment of the present invention, a first feature extraction algorithm is configured in the terminal device of the permission recognition system, and a second feature extraction algorithm is configured in the server of the permission recognition system. Both the first feature extraction algorithm and the second feature extraction algorithm are algorithms for extracting feature information for the target biometric. For example, if the target biometric is an image of the face of the target to be recognized, the first feature extraction algorithm can be used to extract the feature information of the face image of the target to be recognized as the target feature information. When the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, the terminal device sends the target biometric to the server, and the server can use the second feature extraction algorithm to extract the feature information of the face image of the target to be recognized as the feature information of the target to be recognized.

[0105] In one implementation, after extracting the target feature information of the target biometric, step S102 may specifically include steps A1 - A5:

[0106] Step A1: Compare the target feature information with the feature information stored in the local database of the terminal device.

[0107] Step A2: If the target feature information matches the local database, it is determined that the target to be recognized passes the permission recognition, and the permission recognition event is recorded, and then the step of ending the permission recognition is executed.

[0108] Specifically, if there is feature information in the local database that matches the target feature information, it is determined that the target feature information matches the local database.

[0109] Step A3: If the target feature information fails to match the local database, it is determined whether the first feature extraction algorithm is consistent with the second feature algorithm. If they are consistent, step A4 is executed; if they are inconsistent, step A5 is executed.

[0110] Specifically, if there is no feature information in the local database that matches the target feature information, it is determined that the target feature information fails to match the local database.

[0111] Step A4: Send the target feature information to the server.

[0112] Step A5: Send the target biometric feature to the server.

[0113] The local database of the terminal device pre-stores the feature information of multiple targets with access rights to the terminal device.

[0114] For example, a terminal device Y is set at the entrance of the office area of Unit X. The terminal device Y has pre-collected the feature information of the staff of Unit X and stored the collected feature information of the staff in the local database. When a person wants to enter the office area of Unit X, the terminal device Y can collect the facial image of the person and extract the feature information of the person corresponding to the facial image according to the first feature extraction algorithm. Then, the feature information of the person is compared with the feature information stored in the local database. If the comparison result shows that there is feature information in the local database that matches the feature information of the person, it means that the person to enter is a staff member of Unit X, and then they can be let through. If the comparison result shows that there is no feature information in the local database that matches the feature information of the person, it is necessary to further compare the feature information through the server to determine whether the person is a staff member of Unit X. Specifically, if the comparison result shows that there is no feature information in the local database that matches the feature information of the person, it is determined whether the first feature extraction algorithm is consistent with the second feature algorithm. If they are consistent, the feature information of the person is sent to the server. If they are inconsistent, the facial image is sent to the server.

[0115] It can be seen that in this embodiment, it is not necessary for the server to pre-distribute the access rights of the target to the terminal device in advance. Instead, the terminal device and the server can be combined to perform real-time access rights identification on the target to be identified. Moreover, the feature information of the targets that often enter and exit the area where the terminal device is located can be saved in the local database of the terminal device, improving the access efficiency.

[0116] In another implementation manner, Figure 2 is a flowchart of a secondary authentication of permissions provided by an embodiment of the present invention. As Figure 2 shown, after extracting the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device, it further includes:

[0117] S201, if the comparison between the target feature information and the local database is successful, and in the case where the secondary authentication of the access permission is enabled on the terminal device, send the identity identifier of the target to be identified to the server.

[0118] Specifically, in this step, the target feature information can be compared with the feature information stored in the local database of the terminal device. If there is feature information in the local database that matches the target feature information, it is determined that the comparison between the target feature information and the local database is successful.

[0119] The terminal device is set with an authority secondary authentication function. If the comparison between the target feature information and the local database is successful and the terminal device enables the access permission function, the identity identifier of the target to be recognized is sent to the server.

[0120] S202, receive the access permission secondary authentication result sent by the server.

[0121] Among them, the access permission secondary authentication result is determined by the server based on the identity identifier. Specifically, after receiving the identity identifier of the target to be recognized, the server can compare the target feature information with the feature information stored in the server according to the identity identifier. If there is feature information in the server storage that matches the target feature information, the server determines that the target to be recognized has the access permission of the terminal device as the access permission secondary authentication result; if there is no feature information in the server storage that matches the target feature information, the server determines that the target to be recognized does not have the access permission of the terminal device as the access permission secondary authentication result. After determining the access permission secondary authentication result, the server can send the access permission secondary authentication result to the terminal device.

[0122] S203, if the access permission secondary authentication result is that the target to be recognized does not have the access permission of the terminal device, prompt that the target to be recognized fails the permission recognition.

[0123] For example, if the specific application scenario is the access control system of Company X, that is, the terminal device is the access control card punching device of Company X. For the target to be recognized A, if the access permission secondary authentication result is that the target to be recognized A does not have the access permission of the access control card punching device of Company X, it can be prompted that the target to be recognized A fails the permission recognition of the access control card punching device, that is, the access control of Company X cannot be opened for the target to be recognized A.

[0124] It can be seen that in this embodiment, on the one hand, it is not necessary for the server to issue the access permission of the target to the terminal device in advance. Instead, the access permission of the target to be recognized can be identified in real time by combining the terminal device and the server. On the other hand, when the terminal device successfully compares the target feature information with the local database, it does not directly allow the target to be recognized to pass the access permission. Instead, the server further identifies the access permission of the target to be recognized. That is, the access permission of the target to be recognized is identified multiple times by the terminal device and the server, which not only ensures the accuracy of the access permission identification, but also further improves the application security of the access permission identification method provided by the embodiments of the present invention.

[0125] In one embodiment, after the terminal device sends the target biometric feature or target feature information of the target to be recognized to the server, the server can receive the target biometric feature or target feature information of the target to be recognized sent by the terminal device, and then determine the access permission comparison result for the target to be recognized based on the target biometric feature or the target feature information, and send the access permission comparison result to the terminal device.

[0126] In another embodiment, the access permission recognition system further includes an access permission management platform. Before the server receives the target biometric feature or target feature information of the target to be recognized sent by the terminal device, it can first receive the information of each target's affiliated access permission group sent by the access permission management platform. Wherein, each target may correspond to one or more access permission groups, each terminal device corresponds to one access permission group, each access permission group includes at least one terminal device, and each target has the access permission of each terminal device within its affiliated access permission group.

[0127] Figure 3 A system topology diagram of the access permission recognition system is shown in Figure 3 As shown, the terminal device ( Figure 3 represented by "biometric recognition terminal" in Figure 3 ) in the access permission recognition system is connected to the server ( Figure 3 represented by "intelligent analysis server" in Figure 3As shown, the permission management platform divides biometric terminal A and biometric terminal B into permission group 1. Only the targets belonging to permission group 1 can have the access permissions to biometric terminal A and biometric terminal B, that is, only the targets belonging to permission group 1 can have the access permissions to the access control points corresponding to biometric terminal A and biometric terminal B. Moreover, if the target to be recognized passes the permission recognition of biometric terminal A, the server will automatically issue the access permission of the target to be recognized to biometric terminal A, but will not issue it to other biometric terminals simultaneously.

[0128] It can be seen that in this embodiment, by dividing the terminal devices into permission groups, the purpose of classified permission control is achieved. Furthermore, when the intelligent analysis server issues the access permission of the target to be recognized to the biometric terminal, it will synchronously issue information such as the storage time of the access permission of the target to be recognized and the biometric features of the target to be recognized as the basis for the access permission judgment of the biometric terminal.

[0129] Figure 4 It is a flowchart for determining the permission comparison result. As Figure 4 shown, if the server receives the target biometric features of the target to be recognized sent by the terminal device, the server can determine the permission comparison result by the following steps:

[0130] S401, based on the second feature extraction algorithm, extract the feature information of the target biometric features.

[0131] The server is pre-configured with the second feature extraction algorithm. If the target biometric features are the face image of the target to be recognized, the second feature extraction algorithm can correspondingly be the face image feature extraction algorithm.

[0132] S402, compare the feature information with the feature information stored in the server database.

[0133] The server database pre-stores the feature information of the targets with access permissions to each terminal device. As Figure 3 shown, the server database pre-stores: the feature information of the targets with access permissions to biometric terminal A, the feature information of the targets with access permissions to biometric terminal B, the feature information of the targets with access permissions to biometric terminal C, the feature information of the targets with access permissions to biometric terminal C, the feature information of the targets with access permissions to biometric terminal D, the feature information of the targets with access permissions to biometric terminal E, and the feature information of the targets with access permissions to biometric terminal F. Moreover, the server also pre-records the information of the permission groups to which each target belongs. For example, as Figure 3 shown, the server records that target A belongs to permission group 1.

[0134] S403, if there is no feature information in the server database that matches the feature information, then determine the result that the target to be identified fails the permission identification by the terminal device as the permission comparison result.

[0135] If there is no feature information in the server database that matches the feature information, it means that the feature information of the target to be identified is not recorded in the server, that is, the target to be identified does not have the access permission of any terminal device connected to the server.

[0136] After the server determines the permission comparison result, it can send the permission comparison result to the terminal device. After receiving the permission comparison result, the terminal device can directly prompt that the permission identification of the target to be identified fails and record the permission comparison event.

[0137] S404, if there is feature information in the server database that matches the feature information, then determine whether the permission group to which the target to be identified belongs includes the terminal device.

[0138] S405, if the permission group to which the target to be identified belongs includes the terminal device, then determine the result that the target to be identified passes the permission identification by the terminal device, and the expiration information of the access permission of the target to be identified for the terminal device as the permission comparison result.

[0139] If there is feature information in the server database that matches the feature information, it means that the feature information of the target to be identified is recorded in the server. If the permission group to which the target to be identified belongs includes the terminal device, it means that the target to be identified has the access permission of the terminal device.

[0140] After the server determines the permission comparison result, it can send the permission comparison result to the terminal device. After receiving the permission comparison result, the terminal device can determine that the target to be identified passes the permission identification and record the permission comparison event. And the terminal device can also receive the biometric feature of the target to be identified and the second feature comparison algorithm sent by the server, and update the information corresponding to the target to be identified in the local database by using the biometric feature of the target to be identified, the second feature comparison algorithm and the expiration information of the access permission of the target to be identified.

[0141] S406, if the permission group to which the target to be identified belongs does not include the terminal device, then determine the result that the target to be identified fails the permission identification by the terminal device, and the information that the target to be identified does not have the access permission of the terminal device as the permission comparison result.

[0142] If there is feature information in the server database that matches the feature information, it indicates that the feature information of the target to be identified is recorded in the server. If the permission group to which the target to be identified belongs does not include the terminal device, it means that the target to be identified has the access permission to the terminal device and has the access permissions to each terminal device within its belonging permission group.

[0143] The server can send the permission comparison result to the terminal device. After receiving the permission comparison result, the terminal device can determine that the target to be identified fails the permission identification, prompt that the target to be identified does not have the access permission to the terminal device, and record the permission comparison event.

[0144] In this embodiment, if the server receives the target feature information of the target to be identified sent by the terminal device, the server can determine the permission comparison result by the following steps B1 - B5:

[0145] Step B1: Compare the target feature information with the feature information stored in the server database.

[0146] Step B2: If there is no feature information in the server database that matches the target feature information, then determine the result that the target to be identified fails the permission identification of the terminal device as the permission comparison result.

[0147] Step B3: If there is feature information in the server database that matches the target feature information, then determine whether the permission group to which the target to be identified belongs includes the terminal device.

[0148] Step B4: If the permission group to which the target to be identified belongs includes the terminal device, then determine the result that the target to be identified passes the permission identification of the terminal device, and the expiration information of the access permission of the target to be identified to the terminal device, as the permission comparison result.

[0149] Step B5: If the permission group to which the target to be identified belongs does not include the terminal device, then determine the result that the target to be identified fails the permission identification of the terminal device, and the information that the target to be identified does not have the access permission to the terminal device, as the permission comparison result.

[0150] It can be seen that in this embodiment, it is not necessary for the server to issue the access permission of the target to the terminal device in advance. Instead, the terminal device and the server can be combined to perform real-time permission identification on the target to be identified. Moreover, by dividing the terminal devices into different permission groups through the permission management platform, the purpose that the access permissions of the same target on different terminal devices are different can be achieved. For example, the target to be identified has access permission on the first floor of the office area, but does not have access permission on the 15th floor, etc. It can also be achieved that the access permissions of different targets on the same terminal device are different, so as to restrict the entry and exit of the target. For example, only a small number of people with access permission can enter the leader's office. For the targets that often enter and exit the area where the terminal device is located, moreover, the feature information of the targets that often enter and exit the area where the terminal device is located can be saved in the local database of the terminal device to improve the access efficiency.

[0151] In one embodiment, the step of updating the permission information and feature information of the target to be identified in the local database may specifically include steps C1 - C2:

[0152] Step C1: When the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, update the target biometric feature and permission information.

[0153] If the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, the biometric feature of the target to be identified stored in the local database of the terminal device can be directly replaced with the target biometric feature, and the permission of the target to be identified stored in the local database of the terminal device can be directly replaced with the permission information.

[0154] Illustrated by an example, if the target to be identified is person P who wants to pass through the access control point, the target biometric feature can be the face image of person P, the target feature information can be the feature information of this face image extracted by the server according to the second feature extraction algorithm configured by it, and the permission information of person P can be the access permission certificate and access permission period that person P has. If the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, the face image of person P captured by the terminal device during this permission authentication process can be directly used to replace the face image of person P stored in the local database of the terminal device, and the permission information of person P determined during this permission authentication process can be directly used to replace the permission of person P stored in the local database of the terminal device.

[0155] Step C2: When the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the target feature information.

[0156] If the first feature extraction algorithm is the same as the second feature extraction algorithm, the target feature information can be directly used to replace the feature information of the target to be recognized stored in the local database of the terminal device. For example, the terminal device can use the first feature extraction algorithm to extract the feature information of the face image of person P taken during this authentication process. If the first feature extraction algorithm is the same as the second feature extraction algorithm, the feature information of this face image of person P extracted by the terminal device can be directly used to replace the feature information of person P stored in the local database of the terminal device.

[0157] It can be seen that in this embodiment, it is possible to determine whether to update the information of the target to be recognized according to whether the first feature extraction algorithm is the same as the second feature extraction algorithm. In the case of inconsistency, update the target biometric feature and permission information, and in the case of consistency, update the target feature information, which can avoid duplicate updates and missing updates of the information of the target to be recognized. Moreover, updating the information of the target to be recognized in a timely manner can also reduce the error in permission recognition caused by non-update, improving the accuracy of permission recognition.

[0158] Figure 5 The following is a flowchart of permission update provided by an embodiment of the present invention. As Figure 5 shown, the permission update may include the following steps:

[0159] S501, receive a first permission update instruction sent by the server.

[0160] Among them, the first permission update instruction includes: the biometric feature of the target to be updated, the first feature information, and the permission information to be updated.

[0161] In an embodiment of the present invention, when the permission information of the target recorded in the server changes, the server can send a first permission update instruction to the terminal device. If the target to be updated is a person who wants to pass through the access point, the biometric feature of the target to be updated can be the face image of the person, the first feature information can be the feature information of this face image extracted by the server according to the second feature extraction algorithm configured by it, and the permission information to be updated can be the access permission certificate and the access permission period of the target to be updated.

[0162] S502, when the first feature extraction algorithm is the same as the second feature extraction algorithm, based on the first feature information and the permission information to be updated, update the feature information and permission information of the target to be updated in the local database.

[0163] After receiving the first permission update instruction sent by the server, the terminal device can determine whether the first feature extraction algorithm configured by the terminal device is consistent with the second feature extraction algorithm configured by the server. If they are consistent, the terminal device can update the permission information of the target to be updated by following steps D1 - D4:

[0164] Step D1: Compare the first feature information with the feature information stored in the local database.

[0165] Step D2: If there is feature information matching the first feature information in the local database, replace the feature information of the target to be updated in the local database with the first feature information, and update the access permission of the target to be updated according to the permission information to be updated.

[0166] Specifically, the validity period of the access permission of the target to be updated in the local database can be updated according to the access permission certificate and access permission period of the target to be updated in the permission information to be updated.

[0167] Step D3: If there is no feature information matching the first feature information in the local database, determine whether the number of targets stored in the local database reaches a preset number.

[0168] Wherein, the preset number is the maximum number of targets that the local database can store.

[0169] Step D4: If it does not reach the preset number, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if it reaches the preset number, according to the preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0170] The first preset time period can be set to the most recent 30 days, 15 days, or 7 days, etc. Among them, the first preset time period can be set to 30 days, 15 days, or 7 days in order of priority.

[0171] The preset polling deletion rule is: It is possible to find each target in the local database that has not undergone permission identification within the most recent first preset time period, delete the data corresponding to the target that has not undergone permission identification for the longest time, then store the first feature information in the local database, and determine the validity period of the access permission of the target to be updated according to the access permission certificate and access permission period of the target to be updated in the permission information to be updated, and record the validity period of the access permission of the target to be updated in the local database.

[0172] S503. When the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, extract the second feature information of the biometric feature of the target to be updated based on the first feature extraction algorithm, and update the feature information and permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated.

[0173] Specifically, if the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, the terminal device can update the permission information of the target to be updated by the following steps E1 - E4:

[0174] Step E1: Compare the second feature information with the feature information stored in the local database.

[0175] Step E2: If there is feature information in the local database that matches the second feature information, replace the feature information of the target to be updated in the local database with the second feature information, and update the access permission of the target to be updated according to the permission information to be updated.

[0176] Step E3: If there is no feature information in the local database that matches the second feature information, determine whether the number of targets stored in the local database reaches a preset number.

[0177] Step E4: If the preset number is not reached, store the second feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if the preset number is reached, according to the preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the second feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0178] Specifically, it is possible to find each target in the local database that has not undergone permission identification within the most recent first preset time period, delete the data corresponding to the target that has not undergone permission identification for the longest time, then store the second feature information in the local database, and determine the validity period of the access permission of the target to be updated according to the access permission certificate and access permission period of the target to be updated in the permission information to be updated, and record the validity period of the access permission of the target to be updated in the local database.

[0179] It can be seen that in this embodiment, the data in the local repository of the terminal device can be updated in a timely manner through the first permission update instruction sent by the server, reducing the permission recognition errors caused by non-update, improving the accuracy of permission recognition, and reducing the security problems caused by inaccurate permission recognition.

[0180] In another embodiment, Figure 6 Another flowchart of permission update provided by an embodiment of the present invention is as Figure 6 shown. The permission update may include the following steps:

[0181] S601, receiving a second permission update instruction sent by the server.

[0182] In an embodiment of the present invention, when the permission information of the target recorded in the server changes, the server can send a second permission update instruction to the terminal device. The second permission update instruction may include: biometric features and permission information to be updated. If the target to be updated is a person who wants to pass through the access point, the biometric feature of the target to be updated may be the facial image of the person, and the permission information to be updated may be the access permission certificate and access permission period of the target to be updated.

[0183] S602, extracting biometric information corresponding to the biometric feature based on a first feature extraction algorithm of the terminal device.

[0184] After receiving the biometric feature and the permission information to be updated of the target to be updated, the terminal device can use the first feature extraction algorithm to extract the biometric information of the biometric feature of the target to be updated. Specifically, if the biometric feature of the target to be updated is a facial image and the first feature extraction algorithm is a first image feature extraction algorithm, the terminal device can use the first image feature extraction algorithm to extract the image feature of the facial image of the target to be updated as the biometric information.

[0185] S603, comparing the biometric information with the feature information stored in the local database.

[0186] S604, if there is feature information in the local database that matches the biometric information, replacing the feature information of the target to be updated in the local database with the biometric information, and updating the access permission of the target to be updated according to the permission information to be updated.

[0187] Specifically, the validity period of the access permission of the target to be updated in the local database can be updated according to the access permission certificate and access permission period of the target to be updated in the permission information to be updated.

[0188] S605, if there is no feature information matching the biometric information in the local database, determine whether the number of targets stored in the local database reaches a preset number.

[0189] S606, if the preset number is not reached, store the biometric information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if the preset number is reached, according to the preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the biometric information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0190] For example, if the maximum number of targets that the local database can store is 100, the preset number can be set to 100, and the first preset time period can be set to the most recent 30 days. If the number of targets stored in the local database is less than 100, the biometric information can be directly stored in the local database, and the validity period of the access permission of the target to be updated in the local database can be updated; if the number of targets stored in the local database is not less than 100, each target that has not undergone permission identification within the most recent 30 days in the local database can be found, and the data corresponding to the target that has not undergone permission identification for the longest time can be deleted. If the number of targets stored in the local database is less than 100 after deleting this target, the biometric information can be stored in the local database, and the validity period of the access permission of the target to be updated in the local database can be updated. If the number of targets stored in the local database is not less than 100 after deleting this target, continue to delete the data corresponding to the target that has not undergone permission identification for the longest time within the most recent 30 days in the local database until the number of targets stored in the local database reaches 99 after deleting the target, and then store the biometric information in the local database, and update the validity period of the access permission of the target to be updated in the local database.

[0191] It can be seen that in this embodiment, the data in the local storage of the terminal device can also be updated in time through the second permission update instruction issued by the server, reducing the permission identification error caused by non-update, improving the accuracy of permission identification, and reducing the security problems caused by inaccurate permission identification.

[0192] Figure 7 Another flowchart of permission update provided by the embodiment of the present invention is as Figure 7 shown, and the permission update can be as follows:

[0193] S701. For each target in the local database, determine whether the access permission of the target has expired.

[0194] In this embodiment, the terminal device can periodically poll and update the access permissions of each target in the local database by setting a permission update period. The terminal device can also determine the corresponding management policy based on its own load and update the access permissions of each target in the local database according to the management policy.

[0195] S702. If it has expired, delete the data corresponding to the target in the local database.

[0196] The server can send the expiration date of each target to the terminal device.

[0197] S703. If it has not expired, obtain the load of the terminal device, determine the corresponding management policy based on the load, and update the data corresponding to each target in the local database based on the determined management policy until all the targets in the local database have been polled.

[0198] If the load of the terminal device is less than 50% of the preset total load, determine the corresponding management policy as: delete the data corresponding to the target in the local database that has no permission recognition record within 90 days;

[0199] If the load of the terminal device is greater than or equal to 50% of the preset total load and less than 75% of the preset total load, determine the corresponding management policy as: delete the data corresponding to the target in the local database that has no permission recognition record within 60 days;

[0200] If the load of the terminal device is greater than or equal to 75% of the preset total load and less than 90% of the preset total load, determine the corresponding management policy as: delete the data corresponding to the target in the local database that has no permission recognition record within 30 days;

[0201] If the load of the terminal device is greater than or equal to 90% of the preset total load and less than 95% of the preset total load, determine the corresponding management policy as: delete the data corresponding to the target in the local database that has no permission recognition record within 15 days;

[0202] If the load of the terminal device is greater than or equal to 95% of the preset total load, determine the corresponding management policy as: delete the data corresponding to the target in the local database that has no permission recognition record within 70 days.

[0203] Wherein, the preset total load is the maximum load of the terminal device.

[0204] The terminal device can be set to automatically delete the data corresponding to the target in the local database after the expiration of the target's expiration date. The terminal device can also be set not to automatically delete the data corresponding to the target in the local database after the expiration of the target's expiration date, but to update the data corresponding to the target in the local database according to the determined management policy.

[0205] Before performing the step of determining whether the access permission of each target for the local database has expired, it can also be determined whether the current time is within a preset permission recognition peak time period; if so, it is determined whether the load of the terminal device reaches a preset load threshold; if the preset load threshold is reached, the data corresponding to the target without permission recognition records within the second preset time period in the local database is deleted.

[0206] Among them, the second preset time period can be 7 days before the current time, and the preset load threshold is 95% of the preset total load. That is, if the time when the terminal device receives the permission update trigger instruction is within the preset permission recognition peak time period, and the load of the terminal device reaches 95% of the preset total load, the data corresponding to the target without permission recognition records within 7 days in the local database is deleted.

[0207] The preset permission recognition peak time period can be set according to the actual application situation. For example, it can be set to 8:00 to 10:00 every morning, 11:00 to 14:00 every noon, and 17:00 to 21:00 every evening.

[0208] It can be seen that in this embodiment, the terminal device can update the data in the local repository by itself, reduce the permission recognition errors caused by non-update, improve the accuracy of permission recognition, and further reduce the security problems caused by inaccurate permission recognition.

[0209] Corresponding to the above permission recognition method, an embodiment of the present invention also provides a permission recognition system. The permission recognition system provided by the embodiment of the present invention will be introduced below. Figure 8 A schematic structural diagram of the permission recognition system provided by an embodiment of the present invention is as Figure 8 shown, the system includes a server 810 and a terminal device 820;

[0210] The terminal device 820 is configured to obtain the target biometric feature of the target to be recognized; extract the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server 810, and when the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server 810;

[0211] The server 810 is configured to receive the target biometric feature or the target feature information of the target to be recognized sent by the terminal device; determine the permission comparison result for the target to be recognized based on the target biometric feature or the target feature information, and send the permission comparison result to the terminal device 820;

[0212] The terminal device 820 is further configured to receive the permission comparison result sent by the server; if the permission comparison result indicates that the target to be recognized has the access permission to the terminal device, determine that the target to be recognized passes the permission recognition, and update the permission information and the feature information of the target to be recognized in the local database based on the permission comparison result.

[0213] It can be seen that the system provided by the embodiment of the present invention obtains the target biometric feature of the target to be recognized; extracts the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server, and when the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server; receive the permission comparison result sent by the server; if the permission comparison result indicates that the target to be recognized has the access permission to the terminal device, determine that the target to be recognized passes the permission recognition, and update the permission information and the feature information of the target to be recognized in the local database based on the permission comparison result. That is, by combining the local database of the terminal device and the server database to update the access permission of the target to be recognized in real time, the biometric permission recognition is made more accurate, and the security problems caused by inaccurate permission recognition are greatly reduced.

[0214] Optionally, the terminal device 820 is specifically configured to update the target biometric feature and the permission information when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, and update the target feature information when the first feature extraction algorithm is consistent with the second feature extraction algorithm.

[0215] Optionally, the terminal device 820 is further configured to, if the target feature information matches the local database and the terminal device enables secondary authentication of the access permission, send the identity identifier of the target to be recognized to the server; receive the secondary authentication result of the access permission sent by the server; the secondary authentication result of the access permission is determined by the server based on the identity identifier; if the secondary authentication result of the access permission indicates that the target to be recognized does not have the access permission to the terminal device, prompt that the target to be recognized fails the permission recognition.

[0216] Optionally, the terminal device 820 is further configured to receive a first permission update instruction sent by the server, where the first permission update instruction includes: the biometric feature of the target to be updated, the first feature information, and the permission information to be updated; when the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the feature information and the permission information of the target to be updated in the local database based on the first feature information and the permission information to be updated; when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, extract the second feature information of the biometric feature of the target to be updated based on the first feature extraction algorithm, and update the feature information and the permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated.

[0217] Optionally, the terminal device 820 is specifically configured to compare the first feature information with the feature information stored in the local database; if there is feature information in the local database that matches the first feature information, replace the feature information of the target to be updated in the local database with the first feature information, and update the access permission of the target to be updated according to the permission information to be updated; if there is no feature information in the local database that matches the first feature information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission recognition within the first preset time period in the local database according to the preset polling deletion rule, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

[0218] Optionally, the terminal device 820 is specifically configured to compare the second feature information with the feature information stored in the local database; if there is feature information in the local database that matches the second feature information, replace the feature information of the target to be updated in the local database with the second feature information, and update the access permission of the target to be updated according to the access permission information to be updated; if there is no feature information in the local database that matches the second feature information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, according to a preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

[0219] Optionally, the terminal device 820 is further configured to receive a second permission update instruction sent by the server, where the second permission update instruction includes: biometric features and access permission information to be updated; extract biometric feature information corresponding to the biometric features based on a first feature extraction algorithm of the terminal device; compare the biometric feature information with the feature information stored in the local database; if there is feature information in the local database that matches the biometric feature information, replace the feature information of the target to be updated in the local database with the biometric feature information, and update the access permission of the target to be updated according to the access permission information to be updated; if there is no feature information in the local database that matches the biometric feature information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the biometric feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, according to a preset polling deletion rule, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database, store the biometric feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

[0220] Optionally, the terminal device 820 is further configured to determine, for each target in the local database, whether the access permission of the target has expired; if it has expired, delete the data corresponding to the target in the local database; if it has not expired, obtain the load of the terminal device, determine a corresponding management strategy based on the load, and update the data corresponding to each target in the local database based on the determined management strategy until all the targets in the local database have been polled.

[0221] Optionally, the terminal device 820 is further configured to determine whether the current time is within a preset permission recognition peak time period before determining whether the access permission of each target for the local database has expired; if so, determine whether the load of the terminal device reaches a preset load threshold; if the preset load threshold is reached, delete the data corresponding to the target that has no permission recognition record within a second preset time period in the local database.

[0222] Optionally, referring to Figure 9 , the system further includes a permission management platform 910;

[0223] The permission management platform 910 is configured to assign a permission group to which each target belongs and send information about the permission group to which each target belongs to the server, where each permission group includes at least one terminal device, and each target has access permissions for each terminal device within its assigned permission group.

[0224] The server 8,10 is further configured to receive information about the permission group to which each target belongs sent by the permission management platform.

[0225] Specifically, the server 810 is further configured to compare the feature information extracted based on the target biometric or the target feature information with the feature information stored in the server database, and determine the permission group to which the target to be recognized belongs; if there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs includes the terminal device, then determine the result of the permission recognition of the target to be recognized through the terminal device and the expiration information of the access permission of the target to be recognized for the terminal device as the permission comparison result; if there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs does not include the terminal device, then determine the result that the target to be recognized fails the permission recognition through the terminal device and the information that the target to be recognized does not have access permission for the terminal device as the permission comparison result; if there is no feature information in the server database that matches the target feature information and the extracted feature information, then determine the result that the target to be recognized fails the permission recognition through the terminal device as the permission comparison result.

[0226] It can be seen that when applying the permission recognition system provided by the embodiments of the present invention, it is not necessary for the server to issue the access permission of the target to the terminal device in advance. Instead, the terminal device and the server can be combined to perform real-time permission recognition on the target to be recognized. Moreover, by dividing the terminal devices into different permission groups through the permission management platform, it is possible to achieve different access permissions for the same target on different terminal devices, and it is also possible to achieve different access permissions for different targets on the same terminal device, so as to achieve the purpose of restricting the access of the target. In addition, the characteristic information of the targets that often enter and exit the area where the terminal device is located can be saved in the local database of the terminal device to improve the access efficiency.

[0227] The embodiments of the present invention also provide an electronic device, as Figure 10 shown, which includes a processor 1001, a communication interface 1002, a memory 1003, and a communication bus 1004. Among them, the processor 1001, the communication interface 1002, and the memory 1003 communicate with each other through the communication bus 1004.

[0228] The memory 1003 is used to store a computer program.

[0229] When the processor 1001 is used to execute the program stored on the memory 1003, it implements the steps of the permission recognition method described in any of the above embodiments.

[0230] The communication bus mentioned in the above electronic device may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0231] The communication interface is used for communication between the above electronic device and other devices.

[0232] The memory may include a Random Access Memory (RAM), and may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.

[0233] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0234] In another embodiment provided by the present invention, a computer-readable storage medium is further provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any of the above-mentioned permission recognition methods are implemented.

[0235] In another embodiment provided by the present invention, a computer program product containing instructions is further provided. When it runs on a computer, the computer is caused to execute any of the permission recognition methods in the above-mentioned embodiments.

[0236] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a Solid State Disk (SSD)).

[0237] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.

[0238] Each embodiment in this specification is described in a related manner. For the same and similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the system, electronic device, computer-readable storage medium and computer program product, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the partial description of the method embodiments for the relevant parts.

[0239] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.

Claims

1. A permission recognition method, characterized in that, A terminal device applied to a permission recognition system, the permission recognition system further includes a server and a permission management platform, and the method includes: Obtain the target biometric feature of the target to be recognized; Based on the first feature extraction algorithm of the terminal device, extract the target feature information of the target biometric feature; if the comparison between the target feature information and the local database fails, and the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server, and if the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server; wherein, the server is used to receive the information of each target's permission group sent by the permission management platform before receiving the target biometric feature or the target feature information sent by the terminal device; each permission group includes at least one terminal device, and each target has the access permission of each terminal device within its affiliated permission group; Receive the permission comparison result sent by the server and the biometric feature of the target to be recognized; the permission comparison result is determined by the server based on the target biometric feature or the target feature information; wherein, when there is feature information in the server database that matches the target feature information or the feature information extracted based on the target biometric feature, and the permission group to which the target to be recognized belongs includes the terminal device, the permission comparison result indicates: the result of the target to be recognized passing the permission recognition of the terminal device, and the expiration information of the access permission of the target to be recognized for the terminal device; when there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs does not include the terminal device, the permission comparison result indicates: the result of the target to be recognized failing to pass the permission recognition of the terminal device, and the information that the target to be recognized does not have the access permission of the terminal device; when there is no feature information in the server database that matches the target feature information and the extracted feature information, the permission comparison result indicates: the result of the target to be recognized failing to pass the permission recognition of the terminal device; If the permission comparison result is that the target to be recognized has the access permission of the terminal device, determine that the target to be recognized passes the permission recognition, and update the permission information and feature information of the target to be recognized in the local database based on the permission comparison result and the received biometric feature of the target to be recognized.

2. The method according to claim 1, wherein The updating the permission information and feature information of the target to be recognized in the local database includes: When the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, update the target biometric feature and permission information; When the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the target feature information.

3. The method according to claim 1, wherein After extracting the target feature information of the target biometric feature by the first feature extraction algorithm based on the terminal device, the following steps are further included: If the comparison between the target feature information and the local database is successful, and when the secondary authentication of the access permission is enabled on the terminal device, send the identity identifier of the target to be recognized to the server; Receive the secondary authentication result of the access permission sent by the server; the secondary authentication result of the access permission is determined by the server based on the identity identifier; If the secondary authentication result of the access permission indicates that the target to be recognized does not have the access permission to the terminal device, prompt that the target to be recognized fails the permission recognition.

4. The method according to claim 1, wherein The method further includes: Receive the first permission update instruction sent by the server, where the first permission update instruction includes: first feature information and permission information to be updated; When the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the feature information and permission information of the target to be updated in the local database based on the first feature information and the permission information to be updated; When the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, extract the second feature information of the biometric feature of the target to be updated based on the first feature extraction algorithm, and update the feature information and permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated.

5. The method according to claim 4, characterized in that, The step of updating the feature information and permission information of the target to be updated in the local database based on the first feature information and the permission information to be updated includes: Compare the first feature information with the feature information stored in the local database; If there is feature information in the local database that matches the first feature information, replace the feature information of the target to be updated in the local database with the first feature information, and update the access permission of the target to be updated according to the permission information to be updated; If there is no feature information in the local database that matches the first feature information, determine whether the number of targets stored in the local database reaches a preset number; If it does not reach the preset number, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission recognition within the first preset time period in the local database according to the preset polling deletion rule, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

6. The method according to claim 4, wherein The step of updating the feature information and permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated includes: Compare the second feature information with the feature information stored in the local database; If there is feature information matching the second feature information in the local database, replace the feature information of the target to be updated in the local database with the second feature information, and update the access permission of the target to be updated according to the access permission information to be updated; If there is no feature information matching the second feature information in the local database, determine whether the number of targets stored in the local database reaches a preset number; If it does not reach the preset number, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database according to the preset polling deletion rule, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

7. The method according to claim 1, characterized in that, The method further includes: Receiving a second permission update instruction sent by the server, where the second permission update instruction includes: biometric features and access permission information to be updated; Extracting biometric information corresponding to the biometric features based on the first feature extraction algorithm of the terminal device; Comparing the biometric information with the feature information stored in the local database; If there is feature information matching the biometric information in the local database, replace the feature information of the target to be updated in the local database with the biometric information, and update the access permission of the target to be updated according to the access permission information to be updated; If there is no feature information matching the biometric information in the local database, determine whether the number of targets stored in the local database reaches a preset number; If it does not reach the preset number, store the biometric information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, delete the data corresponding to the target that has not undergone permission identification within the first preset time period in the local database according to the preset polling deletion rule, store the biometric information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

8. The method according to claim 1, characterized in that, The method further includes: For each target in the local database, determine whether the access permission of the target has expired; If it has expired, delete the data corresponding to the target in the local database; If it has not expired, obtain the load of the terminal device, determine the corresponding management policy based on the load, and update the data corresponding to each target in the local database based on the determined management policy until all the targets in the local database have been polled.

9. The method according to claim 8, wherein Before determining whether the access permission of each target in the local database has expired, it further includes: Determining whether the current time is within a preset permission identification peak time period; If so, determine whether the load of the terminal device reaches a preset load threshold; If a preset load threshold is reached, delete the data corresponding to the target in the local database that has no permission recognition record within a second preset time period.

10. A permission recognition method, characterized in that, A server applied to a permission recognition system, the permission recognition system further includes a terminal device, and the method includes: Receiving the target biometric feature or target feature information of the target to be recognized sent by the terminal device; wherein, the target feature information is obtained by extracting based on a first feature extraction algorithm of the terminal device; the target biometric feature is: when the comparison between the target feature information and the local database fails, and the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, the terminal device sends it to the server; the target feature information is: when the comparison between the target feature information and the local database fails, and the first feature extraction algorithm is consistent with the second feature extraction algorithm, the terminal device sends it to the server; Determining a permission comparison result for the target to be recognized based on the target biometric feature or the target feature information; Sending the permission comparison result and the biometric feature of the target to be recognized to the terminal device; The permission recognition system further includes a permission management platform; Before receiving the target biometric feature or target feature information of the target to be recognized sent by the terminal device, it further includes: Receiving the information of the permission groups to which each target belongs sent by the permission management platform; wherein, each permission group includes at least one terminal device, and each target has the access permission to each terminal device within its belonging permission group; The determining a permission comparison result for the target to be recognized based on the target biometric feature or the target feature information includes: Comparing the feature information extracted based on the target biometric feature or the target feature information with the feature information stored in the server database, and determining the permission group to which the target to be recognized belongs; If there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs includes the terminal device, then determine the result of the target to be recognized passing the permission recognition of the terminal device, and the expiration information of the target to be recognized having the access permission to the terminal device as the permission comparison result; If there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs does not include the terminal device, then determine the result of the target to be recognized failing to pass the permission recognition of the terminal device, and the information that the target to be recognized does not have the access permission to the terminal device as the permission comparison result; If there is no feature information in the server database that matches the target feature information and the extracted feature information, then determine the result of the target to be recognized failing to pass the permission recognition of the terminal device as the permission comparison result.

11. A permission recognition system, characterized in that, The system includes a server and a terminal device; The terminal device is used to obtain the target biometric feature of the target to be recognized; Extract the target feature information of the target biometric feature based on the first feature extraction algorithm of the terminal device; if the comparison between the target feature information and the local database fails, and the first feature extraction algorithm is inconsistent with the second feature extraction algorithm of the server, send the target biometric feature to the server; if the first feature extraction algorithm is consistent with the second feature extraction algorithm, send the target feature information to the server; The server is configured to receive the target biometric feature or target feature information of the target to be recognized sent by the terminal device; determine the permission comparison result for the target to be recognized based on the target biometric feature or the target feature information, and send the permission comparison result and the biometric feature of the target to be recognized to the terminal device; The terminal device is further configured to receive the permission comparison result and the biometric feature of the target to be recognized sent by the server; If the permission comparison result indicates that the target to be recognized has the access permission to the terminal device, determine that the target to be recognized passes the permission recognition, and update the permission information and feature information of the target to be recognized in the local database based on the permission comparison result and the received biometric feature of the target to be recognized; The system further includes a permission management platform; The permission management platform is configured to assign a permission group to each target and send the information of the permission group to which each target belongs to the server, where each permission group includes at least one terminal device, and each target has the access permission to each terminal device within its assigned permission group; The server is further configured to receive the information of the permission group to which each target belongs sent by the permission management platform; Specifically, the server is further configured to compare the feature information extracted based on the target biometric feature or the target feature information with the feature information stored in the server database, and determine the permission group to which the target to be recognized belongs; if there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs includes the terminal device, then determine the result that the target to be recognized passes the permission recognition of the terminal device, and the expiration information of the access permission of the target to be recognized to the terminal device as the permission comparison result; if there is feature information in the server database that matches the target feature information or the extracted feature information, and the permission group to which the target to be recognized belongs does not include the terminal device, then determine the result that the target to be recognized fails to pass the permission recognition of the terminal device, and the information that the target to be recognized does not have the access permission to the terminal device as the permission comparison result; if there is no feature information in the server database that matches the target feature information and the extracted feature information, then determine the result that the target to be recognized fails to pass the permission recognition of the terminal device as the permission comparison result.

12. The system according to claim 11, wherein, The terminal device is specifically configured to update the target biometric feature and permission information when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm; and update the target feature information when the first feature extraction algorithm is consistent with the second feature extraction algorithm.

13. The system according to claim 11, wherein The terminal device is further configured to, if the target feature information is successfully compared with the local database and the terminal device enables secondary authentication of the access permission, send the identity identifier of the target to be recognized to the server; Receive the secondary authentication result of the access permission sent by the server; The secondary authentication result of the access permission is determined by the server based on the identity identifier. If the secondary authentication result of the access permission indicates that the target to be recognized does not have the access permission to the terminal device, prompt that the target to be recognized fails the permission recognition.

14. The system according to claim 11, wherein The terminal device is further configured to receive the first permission update instruction sent by the server, where the first permission update instruction includes: the biometric feature of the target to be updated, the first feature information, and the permission information to be updated; when the first feature extraction algorithm is consistent with the second feature extraction algorithm, update the feature information and permission information of the target to be updated in the local database based on the first feature information and the permission information to be updated; when the first feature extraction algorithm is inconsistent with the second feature extraction algorithm, extract the second feature information of the biometric feature of the target to be updated based on the first feature extraction algorithm, and update the feature information and permission information of the target to be updated in the local database based on the second feature information and the permission information to be updated.

15. The system according to claim 14, wherein The terminal device is specifically configured to compare the first feature information with the feature information stored in the local database; if there is feature information in the local database that matches the first feature information, replace the feature information of the target to be updated in the local database with the first feature information, and update the access permission of the target to be updated according to the permission information to be updated; if there is no feature information in the local database that matches the first feature information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated; If it reaches the preset number, delete the data corresponding to the target that has not undergone permission recognition within the first preset time period in the local database according to the preset polling deletion rule, store the first feature information in the local database, and record the access permission of the target to be updated according to the permission information to be updated.

16. The system according to claim 14, wherein The terminal device is specifically configured to compare the second feature information with the feature information stored in the local database; if there is feature information in the local database that matches the second feature information, replace the feature information of the target to be updated in the local database with the second feature information, and update the access permission of the target to be updated according to the access permission information to be updated; if there is no feature information in the local database that matches the second feature information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, according to the preset polling deletion rule, delete the data corresponding to the targets that have not undergone permission identification within the first preset time period in the local database, store the second feature information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

17. The system according to claim 11, wherein The terminal device is further configured to receive a second permission update instruction sent by the server, where the second permission update instruction includes: biometric features and access permission information to be updated; extract the biometric information corresponding to the biometric features based on the first feature extraction algorithm of the terminal device; compare the biometric information with the feature information stored in the local database; if there is feature information in the local database that matches the biometric information, replace the feature information of the target to be updated in the local database with the biometric information, and update the access permission of the target to be updated according to the access permission information to be updated; if there is no feature information in the local database that matches the biometric information, determine whether the number of targets stored in the local database reaches a preset number; if it does not reach the preset number, store the biometric information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated; if it reaches the preset number, according to the preset polling deletion rule, delete the data corresponding to the targets that have not undergone permission identification within the first preset time period in the local database, store the biometric information in the local database, and record the access permission of the target to be updated according to the access permission information to be updated.

18. The system according to claim 11, wherein The terminal device is further configured to determine, for each target in the local database, whether the access permission of the target has expired; if it has expired, delete the data corresponding to the target in the local database; if it has not expired, obtain the load of the terminal device, determine the corresponding management policy based on the load, and update the data corresponding to each target in the local database based on the determined management policy until all the targets in the local database have been polled.

19. The system according to claim 17, wherein The terminal device is further configured to determine whether the current time is within a preset permission identification peak time period before determining, for each target in the local database, whether the access permission of the target has expired; If so, determine whether the load of the terminal device reaches a preset load threshold; If the preset load threshold is reached, delete the data corresponding to the target that has no permission recognition record within the second preset time period in the local database.

20. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus; The memory is used to store computer programs; The processor, when executing the program stored on the memory, implements the method steps described in any one of claims 1-9 or 10.

21. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the method steps described in any one of claims 1-9 or 10.

Citation Information

Patent Citations

  • Biological information identification method, device, terminal, system and storage medium

    CN110096996A

  • Personnel identification method and device and storage medium

    CN111368622A