Method, apparatus, computer device, and storage medium for generating user characteristics
By performing mixed processing and encryption calculations on local terminals to generate hybrid encryption features, the problem of privacy data leakage in biometric recognition is solved, ensuring the security and privacy protection of user characteristics.
Patent Information
- Application Number
- CN202111349442.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-15
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2041-11-15
AI Technical Summary
In biometric recognition technology, users' privacy data is easily leaked, and the prior art cannot effectively protect the user's biometric information security.
By performing mixed processing and encryption calculations on the local terminal, hybrid encryption features are generated and transmitted to the cloud server, homomorphic encryption algorithms are used to ensure the security of biometrics and terminal features and avoid cloud data leakage.
It realizes the security of biometric and terminal features in the case of cloud data leakage, prevents privacy data from being stolen, and meets the requirements of the Personal Information Protection Law.
Smart Images

Figure CN114048453B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and particularly to a method, apparatus, computer device, and storage medium for generating user features. Background Art
[0002] With the rapid development of biometric recognition technology, the biometric recognition methods have gradually increased. A variety of biometric recognition algorithms have also been successfully applied to identity authentication fields such as mobile payment and e-commerce.
[0003] In the related art, when a user performs identity authentication, it is necessary to obtain the user feature information to be authenticated and compare it with the user feature information pre-stored in the cloud to determine whether the identity authentication of the user to be authenticated passes. Also, since the user feature information compared in the related art is biometric features related to user privacy. In this way, once the biometric data pre-stored in the cloud is stolen, the user's privacy data will be leaked, posing a serious threat to the user's privacy data. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a method, apparatus, computer device, computer-readable storage medium, and computer program product for generating user features that can ensure that privacy data is not leaked.
[0005] In a first aspect, this application provides a method for generating user features. The method includes:
[0006] Obtain the target biometric feature of a target object and the terminal feature of the terminal corresponding to the target object, where the terminal feature includes the physical feature and / or environmental feature of the terminal;
[0007] Perform a mixing process on the target biometric feature and the terminal feature to obtain a mixed feature;
[0008] Perform an encryption calculation on the mixed feature through an encryption algorithm to obtain a mixed encrypted feature, and use the mixed encrypted feature as the user feature and transmit it to a cloud server.
[0009] In one embodiment, the obtaining the target biometric feature of a target object includes:
[0010] Collect the original biometric feature of the target object;
[0011] Calculate the confidence corresponding to the original biometric feature through a preset confidence determination algorithm;
[0012] If the confidence corresponding to the original biometric feature is greater than a preset confidence threshold, determine the original biometric feature as the target biometric feature.
[0013] In one embodiment, before the step of collecting the original biometric features of the target object, the method further includes:
[0014] In response to an identity binding request, obtain the identity authentication information in the identity binding request;
[0015] If it is determined that the identity authentication information passes the verification, output the collection prompt information of the original biometric features.
[0016] In one embodiment, the mixing the target biometric feature and the terminal feature to obtain a mixed feature includes:
[0017] Perform mixed calculations on the biometric feature and each of the terminal features respectively to obtain a mixed feature.
[0018] In one embodiment, the method further includes:
[0019] Obtain a biometric feature to be detected and multiple terminal features to be detected;
[0020] For each terminal feature to be detected, perform encryption calculations on the biometric feature to be detected and the terminal feature to be detected through an encryption algorithm to obtain a mixed encrypted feature to be detected;
[0021] Compare the multiple mixed encrypted features to be detected with the mixed encrypted features in the cloud server to obtain multiple comparison results;
[0022] If the multiple comparison results meet the preset verification passing conditions, determine that the biometric feature to be detected and the multiple terminal features to be detected pass the verification.
[0023] In one embodiment, the if the multiple comparison results meet the preset verification passing conditions, determine that the biometric feature to be detected and the multiple terminal features to be detected pass the verification includes:
[0024] In the multiple comparison results, determine the target number of the comparison results indicating comparison failures;
[0025] According to a preset fault tolerance algorithm and the target number, determine the fault tolerance number; [[ID=3८]]
[0026] If the fault tolerance number is not greater than the number of types of the terminal features to be detected, determine that the biometric feature to be detected and the multiple terminal features to be detected pass the verification.
[0027] In a second aspect, the present application further provides a device for generating user features. The device includes:
[0028] An acquisition module, configured to acquire the target biometric feature of a target object and the terminal feature of the terminal corresponding to the target object, where the terminal feature includes one or more physical features or environmental features of the terminal;
[0029] A mixing module, configured to mix the target biometric feature and the terminal feature to obtain a mixed feature;
[0030] An encryption calculation module, configured to perform an encryption calculation on the mixed feature through an encryption algorithm to obtain a mixed encrypted feature, and transmit the mixed encrypted feature to a cloud server.
[0031] In one embodiment, the acquisition module includes:
[0032] An acquisition unit, configured to acquire the original biometric feature of the target object;
[0033] A calculation unit, configured to calculate the confidence level corresponding to the original biometric feature through a preset confidence level determination algorithm;
[0034] A comparison unit, configured to determine the original biometric feature as the target biometric feature if the confidence level corresponding to the original biometric feature is greater than a preset confidence level threshold.
[0035] In one embodiment, the device further includes:
[0036] A binding module, configured to acquire the identity authentication information in the identity binding request in response to an identity binding request;
[0037] An output prompt information module, configured to output a collection prompt information of the original biometric feature if it is determined that the identity authentication information is verified.
[0038] In one embodiment, the mixing module is specifically configured to:
[0039] Perform a mixing calculation on the biometric feature and each terminal feature respectively to obtain a mixed feature.
[0040] In one embodiment, the device further includes:
[0041] A to-be-detected feature acquisition module, configured to acquire a to-be-detected biometric feature and multiple to-be-detected terminal features;
[0042] A to-be-detected mixed encrypted feature determination module, configured to perform an encryption calculation on the to-be-detected biometric feature and the to-be-detected terminal feature through an encryption algorithm for each to-be-detected terminal feature to obtain a to-be-detected mixed encrypted feature;
[0043] A comparison result acquisition module, configured to compare multiple of the to-be-detected hybrid encryption features with the hybrid encryption features in the cloud server to obtain multiple comparison results;
[0044] A verification module, configured to determine that the to-be-detected biometric feature and multiple to-be-detected terminal features pass verification if the multiple comparison results meet a preset verification passing condition.
[0045] In one embodiment, the verification module includes:
[0046] A target quantity determination unit, configured to determine a target quantity of comparison results indicating comparison failures among the multiple comparison results;
[0047] A fault tolerance quantity determination unit, configured to determine a fault tolerance quantity according to a preset fault tolerance algorithm and the target quantity;
[0048] A verification unit, configured to determine that the to-be-detected biometric feature and multiple to-be-detected terminal features pass verification if the fault tolerance quantity is not greater than the quantity of types of the to-be-detected terminal features.
[0049] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0050] Obtain a target biometric feature of a target object and terminal features of a terminal corresponding to the target object, where the terminal features include physical features and / or environmental features of the terminal;
[0051] Perform hybrid processing on the target biometric feature and the terminal features to obtain hybrid features;
[0052] Perform encryption calculation on the hybrid features through an encryption algorithm to obtain hybrid encryption features, and use the hybrid encryption features as user features and transmit them to a cloud server.
[0053] In a fourth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0054] Obtain a target biometric feature of a target object and terminal features of a terminal corresponding to the target object, where the terminal features include physical features and / or environmental features of the terminal;
[0055] Perform hybrid processing on the target biometric feature and the terminal features to obtain hybrid features;
[0056] Perform encryption calculation on the mixed features through an encryption algorithm to obtain mixed encrypted features, and use the mixed encrypted features as user features and transmit them to the cloud server.
[0057] In a fifth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0058] Obtain the target biometric feature of the target object and the terminal feature of the terminal corresponding to the target object, where the terminal feature includes the physical feature and / or environmental feature of the terminal;
[0059] Perform hybrid processing on the target biometric feature and the terminal feature to obtain hybrid features;
[0060] Perform encryption calculation on the hybrid features through an encryption algorithm to obtain mixed encrypted features, and use the mixed encrypted features as user features and transmit them to the cloud server.
[0061] In the above method, device, computer device, storage medium and computer program product for generating user features, by calculating the biometric feature of the target object and the terminal feature of the terminal used by the target object, hybrid features are obtained; through a preset homomorphic encryption algorithm, homomorphic encryption calculation is performed on the hybrid features to obtain mixed encrypted features. Since the process of the mixed encrypted features is all performed on the user's local client, and only the mixed encrypted features are transmitted to the cloud, even if the cloud data is leaked, since the mixed decryption fingerprint cannot be analyzed, the security of the biometric feature and terminal feature of the target object is ensured. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 It is a schematic flowchart of a method for generating user features in an embodiment;
[0063] Figure 2 It is a schematic flowchart of a step for determining a target biometric feature in an embodiment;
[0064] Figure 3 It is a schematic flowchart of a step for outputting a biometric feature collection prompt message in an embodiment;
[0065] Figure 4 It is a schematic flowchart of a verification step in an embodiment;
[0066] Figure 5 It is a schematic flowchart of a comparison step in an embodiment;
[0067] Figure 6 It is a schematic structural diagram of an identity verification in an embodiment;
[0068] Figure 7 A schematic diagram of a hybrid biometric fingerprint collection phase in one embodiment;
[0069] Figure 8 is a schematic diagram of a hybrid biometric fingerprint verification stage in one embodiment;
[0070] Figure 9 is a structural block diagram of a device for generating user features in one embodiment;
[0071] Figure 10 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0072] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0073] With the rapid development of biometric recognition technology, various biometric recognition algorithms have been applied to identity authentication scenarios such as mobile payments and e-commerce. However, this has led to the leakage of users' biometric fingerprint privacy information, the illegal tampering and eavesdropping and replay of biometric information, and the emergence of numerous problems such as fraud, replay, and impersonation. Therefore, protecting individual biometric privacy and preventing the replicable use of biometrics are paramount in the development of biometric-based identity authentication technology.
[0074] In one embodiment, Figure 1 As shown, a method for generating user characteristics is provided. This embodiment uses the method applied to a terminal as an example for illustration. It is understandable that the method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. The above-mentioned terminals can be, but are not limited to, various personal computers, laptops, smart phones, tablet computers, Internet of Things devices and portable wearable devices. Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server can be implemented as an independent server or a server cluster composed of multiple servers. In this embodiment, the method for generating user characteristics is applied to a terminal and includes the following steps:
[0075] Step 402: Acquire target biometric features of the target object and terminal features of the terminal corresponding to the target object.
[0076] Among them, the terminal features include the physical features and / or environmental features of the terminal. That is to say, the number of terminal features can be one or more, and the types of terminal features can include one or more of the physical features and environmental features of the terminal.
[0077] Specifically, the target object can be any user, for example, it can be the user whose identity needs to be verified; the terminal corresponding to the target object can be the terminal device used by the user whose identity needs to be verified, such as a mobile phone, a tablet computer, etc.; the physical features of the terminal can be the factory id (Identity document) of the terminal device, the MAC address (Media Access Control Address) of the 4G (4th generation) network of the terminal device, the MAC address of the wireless network of the terminal device, the IMEI (International Mobile Equipment Identity) of the terminal device, the uuid (Universally Unique Identifier) of the terminal device, etc.; the environmental features of the terminal can be the login location information, login time information, etc. of the terminal. The target biometric feature of the target object can be the physiological feature of the user whose identity needs to be verified, and can include one or more of iris feature, fingerprint feature, face image feature, voiceprint feature, gait feature.
[0078] Step 404, perform a hybrid processing on the target biometric feature and the terminal features to obtain a hybrid feature.
[0079] Specifically, in the local environment corresponding to the terminal, the terminal can perform a hybrid processing on the target biometric feature and the terminal device to obtain the processed hybrid feature.
[0080] Optionally, the terminal can obtain multiple biometric features and multiple terminal features. For example, the terminal can obtain m target biometric features and n terminal features. For each target biometric feature, the terminal can respectively perform a hybrid with each terminal feature to obtain n hybrid sub-features. In this way, the hybrid feature corresponding to each target biometric feature can be a set containing n hybrid sub-features. When m target biometric features are obtained, m hybrid features can be correspondingly calculated, and each hybrid feature contains n hybrid sub-features.
[0081] Optionally, the terminal can also mix multiple biometric features with each terminal feature respectively to obtain mixed features. That is to say, the terminal can perform mixed calculations on m target biometric features with each terminal feature respectively to obtain a mixed feature group. In this way, the mixed feature group contains n mixed features. Each mixed feature is obtained by performing a mixed calculation on m target biometric features and one terminal feature.
[0082] Step 406: Perform an encryption calculation on the mixed features through an encryption algorithm to obtain mixed encrypted features, and use the mixed encrypted features as user features and transmit them to the cloud server.
[0083] Specifically, the encryption algorithm can be any algorithm with encryption function. For example, it can be a homomorphic encryption algorithm, or an md(MD5 Message-Digest Algorithm) algorithm, etc. The terminal can input the mixed features into the encryption algorithm in the local environment, so that the terminal can perform an encryption calculation on the mixed features to obtain the encryption result output by the encryption algorithm, and use this encryption result as the mixed encrypted features. In this way, the terminal can use the mixed encrypted features as the user features of the target object, and transmit the user features of the target object and the identity identification information of the target object to the cloud server together.
[0084] In the above method for generating user features, by calculating the biometric features of the target object and the terminal features of the terminal used by the target object, mixed features are obtained; through a preset homomorphic encryption algorithm, homomorphic encryption calculation is performed on the mixed features to obtain mixed encrypted features. Since the process of mixed encrypted features is all performed on the user's local client, and only the mixed encrypted features are transmitted to the cloud, even if the cloud data is leaked, due to the mixed decryption fingerprints being unable to be parsed, the security of the biometric features and terminal features of the target object is ensured, and the hidden danger of excessive collection of the user's personal privacy data by the service provider of the cloud server is also avoided.
[0085] In one embodiment, as Figure 2 shown, the specific processing process of step 402 "obtain the target biometric features of the target object" includes:
[0086] Step 502: Collect the original biometric features of the target object.
[0087] Specifically, the terminal can include a biometric collection device. In this way, the terminal can directly collect the original biometric features of the target object through the biometric collection device. Among them, the original biometric features are the features directly collected by the collection device and not screened by the terminal.
[0088] Step 506: Calculate the confidence level corresponding to the original biometric feature through a preset confidence level determination algorithm.
[0089] Specifically, the preset confidence level algorithm can be the recognition algorithm corresponding to the target biometric feature. If the target biometric feature is a face image feature, then the corresponding preset confidence level determination algorithm can be a face recognition algorithm, such as the DeepID1 recognition algorithm. The confidence level corresponding to the original biometric feature can be the degree to which the original biometric feature can be applied to identity verification, that is, the application degree. If the target biometric feature is a face image feature, then the meaning represented by the corresponding confidence level can be the clarity, integrity, etc. of the collected face image feature. The terminal can perform recognition and calculation on the collected original biometric feature through the preset confidence level determination algorithm, and the calculation result output by this algorithm is the confidence level of the collected original biometric feature.
[0090] Step 508: If the confidence level corresponding to the original biometric feature is greater than the preset confidence level threshold, then determine the original biometric feature as the target biometric feature.
[0091] Specifically, the terminal compares the calculated confidence level corresponding to the original biometric feature with the preset confidence level threshold corresponding to the original biometric feature. If the calculated confidence level is greater than the preset confidence level threshold, then it can be determined that the original biometric feature collected by the terminal can be used for identity verification. In this way, the terminal can use the collected original biometric feature as the target biometric feature, and store the target biometric feature and the corresponding identity identification information of the target object in the database of the terminal local area.
[0092] For example, when the original biometric feature is a face image feature, if the confidence level corresponding to the collected face image is greater than the preset face feature confidence level threshold, then it can be determined that the clarity, integrity, etc. of the face image feature collected by the terminal all meet the clarity requirements and integrity requirements, etc. of face recognition. If the preset confidence level determination algorithm is the DeepID1 recognition algorithm, then the corresponding preset confidence level threshold can be 97.45%.
[0093] Optionally, the terminal can collect m types of original biometric features, and each type of original biometric feature can be denoted as x m , and the confidence level corresponding to the original biometric feature calculated by the terminal can be denoted as f(x m ), where m is a positive integer.
[0094] In this embodiment, by calculating and recognizing the collected original biometric features and storing the original biometric features greater than the preset confidence level threshold, the convenience and accuracy of identity verification based on the original biometric features can be improved.
[0095] It should be noted that the scenario where the user performs identity authentication can be the scenario when the user logs in to the terminal device for identity authentication, or the scenario when the user logs in to the software program in the terminal device. The user performs identity authentication based on the corresponding terminal, and the user can perform identity authentication through user name information, mobile phone verification code, static password information, OTP password information (One Time Password, one-time password), etc.
[0096] In order to improve the verification experience of the user on the terminal side and facilitate the user to perform identity authentication on the terminal side, identity authentication can also be performed through the user's biometric features. Then, the biometric features of the user need to be pre-stored on the cloud server. Also, since there is a risk of privacy leakage in storing the user's biometric feature information on the cloud server, therefore, the present invention provides a method for generating user features, and the user features generated by this method can avoid the problem of leakage of the user's biometric features.
[0097] In one embodiment, as Figure 3 shown, before the step of collecting the original biometric features of the target object, the method for generating user features further includes:
[0098] Step 602, in response to an identity binding request, obtain the identity authentication information in the identity binding request.
[0099] Specifically, the identity binding request can be a request to bind the user features corresponding to the user on the terminal; the identity authentication information can be user name information, mobile phone verification code, static password information, OTP password information. The user sends an identity binding request to the terminal device and inputs the identity authentication information to the terminal device. The terminal determines whether the user who sends the identity binding request can pass the verification through the identity authentication information in the identity binding request.
[0100] Step 604, if it is determined that the identity authentication information passes the verification, output a collection prompt message for the original biometric features.
[0101] Specifically, an identity authentication information database can be pre-stored in the terminal. The terminal compares the identity authentication information in the identity binding request with the identity authentication information pre-stored in the identity authentication information database. If the terminal determines that the above two identity authentication information is consistent, then it can be determined that the identity authentication information in the identity binding request passes the verification. In this way, the terminal can issue a collection prompt message for the original biometric features of the user.
[0102] In one embodiment, the specific processing process of step 404 "perform hybrid processing on the target biometric feature and the terminal feature to obtain a hybrid feature" includes:
[0103] The target biometric feature is respectively mixed and calculated with each terminal feature to obtain a mixed feature.
[0104] Specifically, if there are multiple terminal features obtained by the terminal, then during the mixed calculation, the terminal needs to respectively mix and calculate the target biometric feature with each terminal to obtain a mixed sub-feature corresponding to each terminal feature. In this way, the terminal can combine multiple mixed sub-features into a set of mixed sub-features, that is, the mixed feature.
[0105] In one embodiment, as Figure 4 shown, the method for generating the user feature further includes:
[0106] Step 702, obtain the biometric feature to be detected and multiple terminal features to be detected.
[0107] Specifically, when the user performs identity authentication based on the terminal, the terminal needs to obtain the biometric feature of the user for identity authentication and multiple terminal features.
[0108] Step 704, for each terminal feature to be detected, through an encryption algorithm, encrypt and calculate the biometric feature to be detected and the terminal feature to be detected to obtain a mixed encrypted feature to be detected.
[0109] Specifically, for each terminal feature to be detected, the terminal needs to perform a mixed calculation on the terminal feature to be detected and the biometric feature to be detected. After obtaining the result of the mixed calculation, through the encryption algorithm, the terminal encrypts and calculates the result of the mixed calculation to obtain the corresponding mixed encrypted feature to be detected. That is to say, the terminal can obtain multiple mixed encrypted features to be detected, and the number of mixed encrypted features to be detected is the same as the number of terminal features collected by the terminal.
[0110] Step 706, compare the multiple mixed encrypted features to be detected with the mixed encrypted features in the cloud server to obtain multiple comparison results.
[0111] Specifically, for each user, the cloud server stores the mixed encrypted features corresponding to the user. The terminal can transmit the multiple mixed encrypted features to be detected to the cloud server, and on the cloud server, compare the multiple mixed encrypted features to be detected with the mixed encrypted features in the cloud server respectively to obtain the comparison result corresponding to each mixed encrypted feature to be detected.
[0112] Specifically, the mixed encrypted features stored on the cloud server can be a group of mixed encrypted features, which can include multiple mixed encrypted features obtained after the target biometric feature is respectively mixed and calculated with multiple terminal features and encrypted. In this way, each mixed encrypted feature to be detected can be compared with the corresponding mixed encrypted feature in the group of mixed encrypted features in the cloud server to obtain multiple comparison results.
[0113] Step 708, if multiple comparison results meet the preset verification passing conditions, determine that the biometric feature to be detected and multiple terminal features to be detected pass the verification.
[0114] Specifically, if multiple comparison results determined by the terminal meet the preset verification passing conditions, the terminal can determine that the biometric feature to be detected and multiple terminal features to be detected pass the verification, that is, the user identity verification passes.
[0115] In one embodiment, as Figure 5 shown, the specific processing procedure of step 708 "if multiple comparison results meet the preset verification passing conditions, determine that the biometric feature to be detected and multiple terminal features to be detected pass the verification" includes:
[0116] Step 802, in multiple comparison results, determine the target quantity of the comparison results indicating comparison failures.
[0117] Specifically, the terminal needs to determine the quantity of the comparison results indicating comparison failures as the target quantity. That is to say, the terminal needs to determine the quantity of the terminal features with verification failures.
[0118] Step 804, according to the preset fault tolerance algorithm and the target quantity, determine the fault tolerance quantity.
[0119] Specifically, the preset fault tolerance algorithm can be the Byzantine fault tolerance algorithm. The terminal can perform fault tolerance calculation through the preset fault tolerance algorithm and the target quantity to obtain the fault tolerance quantity.
[0120] Step 806, if the fault tolerance quantity is not greater than the quantity of the types of terminal features to be detected, determine that the biometric feature to be detected and multiple terminal features to be detected pass the verification.
[0121] Specifically, if the fault tolerance quantity calculated by the terminal is less than or equal to the quantity of the types of terminal features to be detected, then the terminal can determine that the multiple comparison results obtained meet the preset verification passing conditions. That is to say, the terminal can determine that the biometric feature to be detected and multiple terminal features to be detected pass the verification.
[0122] Hereinafter, the method for generating user features can be described in detail in combination with a specific embodiment.
[0123] Specifically, the biometric feature can be a face image feature, and the terminal features can be the login location feature, the factory ID of the terminal device, and the MAC address of the 4G network of the terminal device. In this way, the terminal can calculate the confidence level corresponding to the face image feature through a preset confidence level determination algorithm for the face image feature collected by the collection device. When the calculated confidence level is greater than the preset face image feature threshold, the biometric feature collected by the collection device can be used as the target biometric feature. In this way, for each terminal feature, the terminal can separately perform hybrid calculation on the terminal feature and the target biometric feature, and perform encryption calculation through an encryption algorithm to obtain the hybrid encrypted feature corresponding to each terminal feature. And the terminal can transmit the multiple hybrid encrypted features corresponding to the user to the cloud server for storage.
[0124] In this way, in a scenario where the user needs to perform identity verification, the terminal can obtain the biometric feature to be detected and multiple terminal features to be detected. The terminal can obtain the face image feature to be detected, the login location feature to be detected, the login time feature to be detected, the factory ID of the terminal device to be detected, and the MAC address of the 4G network of the terminal device to be detected. The terminal needs to perform hybrid calculation on the face image feature to be detected and the login location feature to be detected and perform encryption calculation through an encryption algorithm to obtain the hybrid encrypted feature to be detected corresponding to the login location feature to be detected. And the terminal needs to compare the hybrid encrypted feature to be detected corresponding to the login location feature to be detected with the corresponding hybrid encrypted feature stored in the cloud server to obtain the comparison result corresponding to the login location feature to be detected.
[0125] [[ID=...]] Similarly, the terminal needs to perform hybrid calculation on the face image feature to be detected and the factory ID of the terminal device to be detected and perform encryption calculation through an encryption algorithm to obtain the hybrid encrypted feature to be detected corresponding to the factory ID of the terminal device to be detected. And the terminal needs to compare the hybrid encrypted feature to be detected corresponding to the factory ID of the terminal device to be detected with the corresponding hybrid encrypted feature stored in the cloud server to obtain the comparison result corresponding to the factory ID of the terminal device to be detected.
[0126] Similarly, the terminal needs to perform hybrid calculation on the face image feature to be detected and the MAC address of the 4G network of the terminal device to be detected and perform encryption calculation through an encryption algorithm to obtain the hybrid encrypted feature to be detected corresponding to the MAC address of the 4G network of the terminal device to be detected. And the terminal needs to compare the hybrid encrypted feature to be detected corresponding to the MAC address of the 4G network of the terminal device to be detected with the corresponding hybrid encrypted feature stored in the cloud server to obtain the comparison result corresponding to the MAC address of the 4G network of the terminal device to be detected.
[0127] Similarly, the terminal needs to perform hybrid calculations on the face image features to be detected and the login time features to be detected, and through an encryption algorithm, obtain the hybrid encrypted features to be detected corresponding to the login time features to be detected. Moreover, the terminal needs to compare the hybrid encrypted features to be detected corresponding to the login time features to be detected with the corresponding hybrid encrypted features stored in the cloud server to obtain the comparison result corresponding to the login time features to be detected.
[0128] In this way, the terminal can obtain four comparison results. For example, the target number of the comparison results indicating comparison failure among the above three comparison results can be 1, for example, the MAC address comparison of the 4G network of the terminal device to be detected fails. The fault tolerance number calculated by the terminal through the Byzantine fault tolerance algorithm and the target number can be 4. Also, since the number of types of terminal features can be 4, it can be determined that the verification is passed. It's just that the 4G network used by the user for identity verification has been changed, which does not affect the authenticity of the user's identity.
[0129] The present invention forms a fingerprint with terminal features by mixing biometric fingerprints with physical unique identifiers of intelligent terminals such as device id, uuid, imei, and wireless mac, and sends multiple non-raw biometric fingerprints to the server. It introduces a Byzantine fault tolerance problem algorithm to verify multiple hybrid fingerprints, providing a new matching verification mechanism for hybrid biometric information and customer identity information. By mixing biometric fingerprints with the physical unique identifier of the terminal, it can prevent the biometric fingerprints from being stolen or imitated, digitally simulated, face masks, 3D printed, recorded, etc., a series of biometric replication and utilization methods. By sending non-raw biometric fingerprints to the cloud server, it meets the requirement that the privacy information of personal biometric fingerprints is not overly collected and leaked by service providers, and at the same time meets the requirement in the Personal Information Protection Law that personal biometric fingerprints are not stored in the cloud.
[0130] In addition, by introducing a homomorphic encryption algorithm, it is ensured that during the verification process, the feature fingerprints still meet the feature recognition algorithm after being mixed with the physical features of the terminal within a certain threshold range. By introducing a Byzantine fault tolerance algorithm, it can be ensured that when the customer normally changes the terminal device, changes the WIFI, etc., there is no need to re-verify, and at the same time, it can be ensured that even if the biometric fingerprints are illegally copied and utilized, successful login cannot be achieved.
[0131] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are displayed in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0132] The present invention also provides an authentication system, as Figure 6 shown. The authentication system may include a biometric extraction module 101, a biometric fingerprint recognition algorithm module 102, a terminal physical unique identifier collection module 103, a homomorphic encryption algorithm module 104, an identity authentication gateway module 105, and a cloud computing and data storage module 106. Among them, the biometric extraction module 101 is used to collect biometric features such as iris features, fingerprint features, face image features, voiceprint features, and gait features of a target object; the biometric fingerprint recognition algorithm module 102 mainly includes a variety of biometric recognition algorithms. Among them, each biometric recognition algorithm corresponds to a variety of types of biometric features. In the scenario of verifying the collected biometric fingerprint (biometric feature), if the threshold of the biometric fingerprint calculated by the biometric recognition algorithm is greater than the preset threshold, it can be determined that the collected biometric fingerprint verification is passed.
[0133] The authentication system further includes a terminal physical unique identifier collection module 103, which is used to collect terminal physical identifiers such as the terminal device factory id, 4G communication MAC address, wireless communication MAC address, IMEI, uuid, etc. and environmental features in the physical intelligent terminal according to different service scenarios; the homomorphic encryption algorithm module 104 is used to make the biometric fingerprint meet the limited threshold through the homomorphic encryption algorithm, and also meet the limited threshold after adding the terminal identifier; the identity authentication gateway module 105 is used to perform identity authentication through traditional authentication information such as account password collection provided by the user in the initial stage of collecting biometric fingerprints, and verify whether the mixed biometric features input by the user collected during the biometric feature verification stage match the biometric features stored on the server; the cloud computing and data storage module 106 is used to store cloud data.
[0134] Optionally, in combination with Figure 7 , the detailed steps of the present invention in the stage of collecting user features are described in detail:
[0135] Step 201: The user initiates an identity binding request on the client side. This identity binding request may include a login request and a user feature binding request. The identity authentication gateway in the server will authenticate the traditional identity authentication information input by the user through the client. After successful verification, the next step can be entered; otherwise, Step 201 needs to be executed again, or a prompt message indicating the failure of identity binding is output. Among them, the traditional identity authentication information may include username, mobile phone verification code, static password, OTP password, etc.
[0136] Step 202: If the identity authentication gateway determines that the traditional identity authentication information input by the user passes the verification, the identity authentication gateway will instruct the client to provide the user feature (hybrid encryption feature, that is, hybrid biometric value information).
[0137] Step 203: The client will output a biometric value information collection prompt message to prompt the user that the user can provide biometrics through the client. That is to say, the client can collect the user's biometrics through a variety of biometric collection devices. The biometrics may include user iris features, fingerprint features, face image features, voiceprint features, gait features, etc. The client can record the biometrics collected by the collection device as the original biometric x m , where m represents the number of biometric types.
[0138] Step 204: The client calculates x m through the biometric fingerprint recognition algorithm to obtain f(x m ), and stores the obtained calculation result in the local secure execution environment. The local secure execution environment can be TEE (Trusted Execution Environment, trusted execution environment).
[0139] Step 205: The client needs to collect the physical features and environmental features of the terminal device currently used by the user. The physical features include the device id of the terminal factory, the physical address of the current wifi network connection, the physical address of the 4G network connection, the universal unique identifier, the international mobile equipment identification code, etc. The environmental features may include the current connected WIFI status, the geographical location when logging in to the terminal currently, the time period when logging in to the terminal currently, etc. The current connected WIFI status may include encrypted WIFI, trusted WIFI, and frequently used WIFI. The above physical features and environmental features can be denoted as y n , where n represents the number of types of physical features and environmental features.
[0140] Step 206: The client uses the homomorphic encryption algorithm (g(y n )) to add y n to f(x m ) and calculates g(f(xm ) + y n ) value.
[0141] Step 207: The client transmits the encrypted result of the hybrid biometric fingerprint to the cloud data storage module 106 for data storage and synchronizes it to the identity authentication gateway module. The encrypted result of the hybrid biometric fingerprint is the hybrid encrypted feature, which is the user feature that the identity authentication gateway needs to collect.
[0142] Optionally, the embodiments of the present invention can also be combined with Figure 8 , and the specific process of authenticating the user is described as follows:
[0143] Specifically, the terminal can record the input of one biometric fingerprint as x m , and record the input of one terminal physical feature as y n . f(x m ) is a biometric fingerprint recognition algorithm, is the threshold of this algorithm. is a homomorphic encryption algorithm, and this algorithm satisfies
[0144] Step 301: The user uses the terminal biometric for identity authentication. The biometric fingerprint module calculates the biometric x' collected this time m through the biometric fingerprint recognition algorithm and records it as f(x' m ).
[0145] Step 302: Compare f(x' m ) with f(x m ). When the threshold represented by the obtained comparison result is greater than the preset threshold , proceed to Step 303; otherwise, return to Step 301 and continue to collect biometrics. f(x m ) is the biometric pre-stored in the local database.
[0146] Step 303: Collect the terminal features of the current terminal, including physical features and environmental features. The currently collected terminal features are the terminal features to be detected. Physical features include but are not limited to the device id of the terminal at the time of factory, the physical MAC address of the current wifi, 4G, etc. network connection, the universal unique identifier uuid, the international mobile equipment identification code imei, etc., and are recorded as y n , where n represents the number of physical features or environmental features.
[0147] Step 304: The terminal mixes the collected terminal features to be detected y n ' and the biometric to be detected x <http: / / www.w3.org / 1999 / xhtml> m ' to obtain the hybrid feature f(x m') + y n '. The terminal encrypts and calculates the mixed features through a homomorphic encryption algorithm to obtain mixed encrypted features.
[0148] Step 305: The terminal transmits the value of g(f(x m ') + y n ')' (i.e., the mixed encrypted feature), and after encryption, it is transmitted to the cloud server. At the cloud server, the mixed encrypted fingerprint obtained after decrypting the mixed encrypted fingerprint transmitted after encryption is obtained, that is, a set of mixed encrypted fingerprints, g(f(x m ') + y1)', g(f(x m ') + y2)'... g(f(x m ') + y n ')'. Among them, g(f(x m ') + y1)' can represent the mixed encrypted feature obtained after homomorphic encryption of the first feature, and the first feature can be obtained by performing a mixed calculation on the biometric feature and the device id of the terminal at the time of factory; g(f(x m ') + y2)' can represent the mixed encrypted feature obtained after homomorphic encryption of the second feature, and the second feature can be obtained by performing a mixed calculation on the biometric feature and the universally unique identifier uuid; g(f(x m ') + y n ')' can represent the mixed encrypted feature obtained after homomorphic encryption of the nth feature, and the nth feature can be obtained by performing a mixed calculation on the biometric feature and the nth terminal feature.
[0149] In the cloud server, a set of to-be-detected mixed encrypted fingerprints obtained is compared with the mixed encrypted fingerprints pre-stored in the cloud server. If the comparison threshold represented by the obtained comparison result is greater than the preset comparison threshold, it can be determined that the authentication of the to-be-detected mixed encrypted feature passes.
[0150] Step 306: In addition, a Byzantine fault tolerance algorithm can be introduced. For a biometric feature m, when the number of terminal physical features n satisfies 3f(x m ) + 1 ≤ n, it can be considered that the current user's biometric fingerprint has not been stolen, where f(x m ) represents the number of comparison failures. A special example is: when the user's biometric voiceprint mixes id, uuid, imei, and mac parameters, that is, n is equal to 4, and for the mac, this mixed biometric feature does not pass, that is, f(x m ) is equal to 1, and the other three pass. At this time, 3 * 1 + 1 ≤ 4 is satisfied, and it can be determined that the current user is himself / herself, and the biometric fingerprint has not been stolen, and it can be regarded as the user changing the wifi.
[0151] Step 307: When the conditions described in Step 306 are met, the hybrid biometric authentication passes and is synchronized to the identity authentication gateway. Otherwise, the terminal outputs a prompt message, which is used to prompt the customer to use biometric recognition on an unusual terminal or that the current verification environment has changed, etc., and to log in again using traditional methods such as account passwords and mobile verification codes.
[0152] Based on the same inventive concept, an embodiment of the present application further provides a user feature generation device 900 for implementing the method for generating user features involved above. The implementation solutions provided by this device to solve problems are similar to those described in the above method. Therefore, the specific limitations in one or more embodiments of the user feature generation device provided below can refer to the limitations on the method for generating user features in the above text, and will not be elaborated here.
[0153] In one embodiment, as Figure 9 shown, a user feature generation device 900 is provided, including: an acquisition module 901, a mixing module 902, and an encryption calculation module 903, where:
[0154] The acquisition module 901 is used to acquire the target biometric feature of the target object and the terminal feature of the terminal corresponding to the target object. The terminal feature includes one or more physical features or environmental features of the terminal.
[0155] The mixing module 902 is used to mix the target biometric feature and the terminal feature to obtain a mixed feature.
[0156] The encryption calculation module 903 is used to perform encryption calculation on the mixed feature through an encryption algorithm to obtain a mixed encrypted feature, and transmit the mixed encrypted feature to the cloud server.
[0157] In one of the embodiments, the acquisition module includes:
[0158] The collection unit is used to collect the original biometric feature of the target object;
[0159] The calculation unit is used to calculate the confidence corresponding to the original biometric feature through a preset confidence determination algorithm;
[0160] The comparison unit is used to determine the original biometric feature as the target biometric feature if the confidence corresponding to the original biometric feature is greater than the preset confidence threshold.
[0161] In one of the embodiments, the device further includes:
[0162] The binding module is used to obtain the identity authentication information in the identity binding request in response to the identity binding request;
[0163] An output prompt information module, configured to output a collection prompt information of the original biometric feature if it is determined that the identity authentication information passes the verification.
[0164] In one embodiment, the mixing module is specifically configured to:
[0165] Mix the biometric feature with each of the terminal features respectively to obtain a mixed feature.
[0166] In one embodiment, the apparatus further includes:
[0167] A to-be-detected feature acquisition module, configured to acquire a to-be-detected biometric feature and a plurality of to-be-detected terminal features;
[0168] A to-be-detected mixed encryption feature determination module, configured to perform encryption calculation on the to-be-detected biometric feature and the to-be-detected terminal feature for each to-be-detected terminal feature through an encryption algorithm to obtain a to-be-detected mixed encryption feature;
[0169] A comparison result acquisition module, configured to compare a plurality of the to-be-detected mixed encryption features with the mixed encryption features in the cloud server to obtain a plurality of comparison results;
[0170] A verification module, configured to determine that the to-be-detected biometric feature and a plurality of to-be-detected terminal features pass the verification if the plurality of comparison results meet a preset verification passing condition.
[0171] In one embodiment, the verification module includes:
[0172] A target quantity determination unit, configured to determine a target quantity of the comparison results indicating comparison failures among the plurality of comparison results;
[0173] A fault tolerance quantity determination unit, configured to determine a fault tolerance quantity according to a preset fault tolerance algorithm and the target quantity;
[0174] A verification unit, configured to determine that the to-be-detected biometric feature and a plurality of to-be-detected terminal features pass the verification if the fault tolerance quantity is not greater than the quantity of the types of the to-be-detected terminal features.
[0175] Each module in the above user feature generation apparatus can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to the above respective modules.
[0176] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 10As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store relevant data of user characteristics. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements a method for generating user characteristics.
[0177] Those skilled in the art can understand that Figure 10 the structure shown in [the figure] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0178] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the above method embodiments are implemented.
[0179] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0180] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0181] It should be noted that the methods and devices described in the embodiments of the present disclosure can be used in the field of artificial intelligence, can be used in the field of fintech or other related fields. The embodiments of the methods and devices described in the present disclosure do not limit the applied fields.
[0182] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.
[0183] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing related hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAMs), magnetoresistive random access memories (MRAMs), ferroelectric random access memories (FRAMs), phase change memories (PCMs), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.
[0184] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0185] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for generating user characteristics, characterized in that: Applied to a terminal, the method includes: Obtaining target biometric features of a target object and terminal features of a terminal corresponding to the target object; wherein the terminal features include physical features and environmental features of the terminal; the physical features of the terminal include a factory ID of the terminal device, a 4G network MAC address of the terminal device, a wireless network MAC address of the terminal device, an International Mobile Equipment Identity (IMEI) of the terminal device, and a universally unique identifier of the terminal device; the environmental features of the terminal include login location information and login time information of the terminal; Mixing the target biometric feature with each of the terminal features to obtain a mixed feature; The hybrid feature is encrypted and calculated using an encryption algorithm to obtain a hybrid encrypted feature, and the hybrid encrypted feature is used as a user feature, and the user feature and the identity information of the target object are then transmitted to a cloud server; wherein the encryption algorithm is a homomorphic encryption algorithm; Acquire biometric features to be detected and multiple terminal features to be detected; For each terminal feature to be detected, encrypt the biometric feature to be detected and the terminal feature to be detected using the encryption algorithm to obtain a mixed encrypted feature to be detected; Comparing the plurality of hybrid encryption features to be detected with the hybrid encryption features in the cloud server to obtain a plurality of comparison results; If the multiple comparison results meet the preset verification pass conditions, it is determined that the verification of the biometric feature to be detected and the multiple terminal features to be detected are passed.
2. The method according to claim 1, characterized in that The step of acquiring a target biometric feature of a target object includes: Collecting original biometrics of the target object; Calculating the confidence level corresponding to the original biometric feature using a preset confidence level determination algorithm; If the confidence level corresponding to the original biometric feature is greater than a preset confidence threshold, the original biometric feature is determined as a target biometric feature.
3. The method according to claim 2, characterized in that Before the step of collecting the original biometric features of the target object, the method further includes: In response to the identity binding request, obtaining identity authentication information in the identity binding request; If it is determined that the identity authentication information is verified, the collection prompt information of the original biometric feature is output.
4. The method according to claim 1, wherein If the multiple comparison results meet the preset verification pass condition, determining that the biometric feature to be detected and the multiple terminal features to be detected have passed the verification includes: determining, among the plurality of comparison results, a target number of comparison results indicating comparison failures; Determining the fault tolerance quantity according to a preset fault tolerance algorithm and the target quantity; If the error tolerance number is not greater than the number of types of the terminal features to be detected, it is determined that the biometric feature to be detected and the multiple terminal features to be detected have been verified successfully.
5. A user feature generation device, characterized in that: The device comprises: an acquisition module, configured to acquire target biometric features of a target object and terminal features of a terminal corresponding to the target object; wherein the terminal features include physical features and environmental features of the terminal; the physical features of the terminal include a factory ID of the terminal device, a 4G network MAC address of the terminal device, a wireless network MAC address of the terminal device, an International Mobile Equipment Identity (IMI) of the terminal device, and a universally unique identifier of the terminal device; and the environmental features of the terminal include login location information and login time information of the terminal; A mixing module, configured to perform mixed calculations on the target biometric feature and each of the terminal features to obtain mixed features; An encryption calculation module is used to perform encryption calculation on the hybrid feature using an encryption algorithm to obtain a hybrid encrypted feature, and then transmit the user feature and the identity information of the target object to a cloud server; wherein the encryption algorithm is a homomorphic encryption algorithm; A detection feature acquisition module is used to acquire the biometric features to be detected and various terminal features to be detected; a module for determining hybrid encryption features to be detected, configured to perform encryption calculation on each terminal feature to be detected, using the encryption algorithm, on the biometric feature to be detected and the terminal feature to be detected, to obtain the hybrid encryption feature to be detected; a comparison result acquisition module, configured to compare the plurality of hybrid encryption features to be detected with the hybrid encryption features in the cloud server to obtain a plurality of comparison results; The verification module is configured to determine that the verification of the biometric feature to be detected and the multiple terminal features to be detected has been passed if the multiple comparison results meet a preset verification pass condition.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 4 are implemented.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.
8. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Image definition recognition method, identity authentication method and devices
CN106971159A
Identity authentication method, terminal device, authentication server, and electronic device
CN107079034A
Iris information registration and verification method and system and computer readable storage medium
CN110162951A
Terminal unlocking method and system based on biological feature recognition
CN110391909A
Encryption authentication method and system based on power equipment fingerprint
CN113395406A