Authentication method, system and device based on improved cryptographic algorithm
By combining user group identification and biometric information in the password lock for identity authentication, generating a random key and comparing it with the mobile terminal key, the security issues of existing password lock authentication methods are resolved, achieving more efficient and secure permission identification.
Patent Information
- Application Number
- CN202111630398.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-28
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2041-12-28
AI Technical Summary
The authentication method of existing password locks is not secure enough and is easy to crack. It is impossible to accurately determine the authenticity of the identity of the person opening the lock, and there are security risks when the user enters the password.
By receiving the user group identification and biometric information sent by the password lock, the registered biometric information database is queried to obtain the target registered biometric information and perform identity authentication; after the identity authentication is passed, a random key is generated and combined with the key entered by the mobile terminal for permission identification.
The security of permission identification is improved, and the authentication effect of password lock unlocking permission is enhanced through the dual verification method of biometrics and random keys.
Smart Images

Figure CN114297612B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of security technology, and in particular to an authentication method, system, device, computer equipment and storage medium based on an improved cryptographic algorithm. Background Art
[0002] Combination locks are security devices that protect equipment or information, so improving their security is crucial. Currently, many combination locks rely solely on simple passwords for identity authentication and authorization. However, password-based authentication methods are overly simplistic and easily cracked, making it difficult to accurately verify the identity of the unlocking personnel. Furthermore, the user's password entry process can be easily overheard by others, posing a security risk.
[0003] Therefore, the current permission identification method has the defect of insufficient security. Summary of the Invention
[0004] Based on this, it is necessary to provide an authentication method, system, device, computer equipment and storage medium based on an improved cryptographic algorithm that can improve identification security in response to the above technical problems.
[0005] An authentication method based on an improved cryptographic algorithm, applied to a server, comprising:
[0006] Receiving the user group identifier and biometric information corresponding to the user to be identified sent by the password lock, and querying the registered biometric information database according to the user group identifier to obtain the target registered biometric information corresponding to the user group identifier; the registered biometric information database contains the correspondence between the user group identifier and the registered biometric information;
[0007] Obtaining a comparison result between the target registered biometric information and the biometric information, and performing identity authentication on the user to be identified based on the comparison result;
[0008] If the identity authentication is successful, an authentication pass message is sent to the password lock, so that the password lock generates a random key based on the authentication pass message and sends it to the server and the mobile terminal corresponding to the user to be identified respectively; the mobile terminal is used to obtain the key to be identified input by the user to be identified after receiving the random key and send it to the server;
[0009] The random key sent by the password lock and the key to be identified sent by the mobile terminal are obtained, and the password lock unlocking authority of the user to be identified is identified based on a comparison result of the random key and the key to be identified.
[0010] In one embodiment, before obtaining the target registration biometric information corresponding to the user group identifier, the method further includes:
[0011] Get multiple registered user information;
[0012] Grouping the plurality of registered user information according to a preset classification rule to obtain a plurality of user groups;
[0013] For each user group, a user group identifier corresponding to the user group is determined, and the user group identifier is sent to a mobile terminal corresponding to the registered user information in the user group, so that the mobile terminal receives and stores the user group identifier.
[0014] In one embodiment, before obtaining the target registration biometric information corresponding to the user group identifier, the method further includes:
[0015] Obtaining registered biometric information corresponding to the plurality of registered user information;
[0016] The registered biometric information is associated with the user group identifier to which the corresponding registered user information belongs, and the associated registered biometric information is stored to obtain the registered biometric information database.
[0017] In one embodiment, the receiving of the user group identifier and biometric information corresponding to the user to be identified sent by the password lock includes:
[0018] Receive the user group identifier corresponding to the user to be identified and the face information corresponding to the user to be identified sent by the password lock.
[0019] In one embodiment, after receiving the user group identifier and biometric information corresponding to the user to be identified from the password lock, the method further includes:
[0020] Performing rotation correction and scale normalization processing on the face information to be identified so that the face information to be identified is consistent with the target registered biometric information corresponding to the user group identifier, thereby obtaining processed face information to be identified;
[0021] Obtaining a first histogram feature corresponding to the processed face information to be identified by a local ternary pattern algorithm, and obtaining a second histogram feature corresponding to the processed face information to be identified by a local phase quantization algorithm, and fusing the first histogram feature and the second histogram feature to obtain a feature of the face to be identified;
[0022] The face features to be identified are subjected to dimensionality reduction processing by a principal component analysis algorithm, and a face feature vector to be identified is obtained from the face features to be identified after dimensionality reduction processing by a linear discriminant analysis algorithm, so as to compare the face feature vector to be identified with the target registered biometric information.
[0023] In one embodiment, obtaining a comparison result between the target registered biometric information and the biometric information, and authenticating the user to be identified based on the comparison result, includes:
[0024] Obtaining a similarity between the facial feature vector of the person to be identified and a target registered facial feature vector corresponding to the target registered biometric information, and performing identity authentication on the user to be identified based on the similarity;
[0025] If the similarity is greater than a preset similarity threshold, it is determined that the user to be identified has passed the identity authentication.
[0026] An authentication method based on an improved cryptographic algorithm, applied to a mobile terminal, comprising:
[0027] Detecting a detection signal emitted by a password lock, and obtaining a device identification corresponding to the password lock based on the detection signal;
[0028] Obtaining a user group identifier to which the user to be identified belongs, and sending the user group identifier to a password lock corresponding to the device identifier, so that the password lock collects biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to a server; the server is configured to obtain corresponding target registered biometric information based on the user group identifier, perform identity authentication on the user to be identified based on a comparison result of the biometric information with the registered biometric information, and send authentication pass information to the password lock when the authentication is successful, so that the password lock generates a random key based on the authentication pass information and sends it to the server and the mobile terminal respectively;
[0029] Obtain the key to be identified input by the user to be identified based on the random key, and send the key to be identified to the server, so that the server can identify the unlocking authority of the password lock of the user to be identified based on the comparison result of the key to be identified and the random key.
[0030] An authentication system based on an improved cryptographic algorithm includes a mobile terminal and a server; wherein:
[0031] The mobile terminal is configured to detect a detection signal emitted by a password lock, obtain a device identifier corresponding to the password lock based on the detection signal, obtain a user group identifier to which a user to be identified belongs, and send the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to a server;
[0032] The server is configured to query a registered biometric information database based on the user group identifier to obtain target registered biometric information corresponding to the user group identifier; the registered biometric information database contains a correspondence between user group identifiers and registered biometric information; obtain a comparison result between the target registered biometric information and the biometric information, and perform identity authentication on the user to be identified based on the comparison result; if the identity authentication is successful, send authentication pass information to the password lock, so that the password lock generates a random key based on the authentication pass information and sends it to the server and the mobile terminal respectively;
[0033] The mobile terminal is configured to obtain the key to be identified input by the user to be identified after receiving the random key and send the key to the server;
[0034] The server is used to perform authority identification on the password lock unlocking authority of the user to be identified based on the comparison result of the random key and the key to be identified.
[0035] An authentication device based on an improved cryptographic algorithm, applied to a server, comprising:
[0036] A first acquisition module is configured to receive a user group identifier and biometric information corresponding to a user to be identified, sent by the password lock, and query a registered biometric information database based on the user group identifier to obtain target registered biometric information corresponding to the user group identifier; the registered biometric information database contains a correspondence between user group identifiers and registered biometric information;
[0037] An identity authentication module, configured to obtain a comparison result between the target registered biometric information and the biometric information, and perform identity authentication on the user to be identified based on the comparison result;
[0038] A first sending module is configured to send authentication pass information to the password lock if the identity authentication is successful, so that the password lock generates a random key based on the authentication pass information and sends it to the server and the mobile terminal corresponding to the user to be identified; the mobile terminal is configured to obtain the key to be identified input by the user to be identified after receiving the random key and send it to the server;
[0039] The authority identification module is used to obtain the random key sent by the password lock and the key to be identified sent by the mobile terminal, and perform authority identification on the password lock unlocking authority of the user to be identified based on the comparison result of the random key and the key to be identified.
[0040] An authentication device based on an improved cryptographic algorithm, applied to a mobile terminal, comprising:
[0041] A second acquisition module is configured to detect a detection signal emitted by the password lock and acquire a device identification corresponding to the password lock based on the detection signal;
[0042] a second sending module, configured to obtain a user group identifier to which the user to be identified belongs, and to send the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to a server; the server is configured to obtain corresponding target registered biometric information based on the user group identifier, perform identity authentication on the user to be identified based on a comparison result of the biometric information with the registered biometric information, and send authentication pass information to the password lock when the authentication is successful, so that the password lock generates a random key based on the authentication pass information and sends it to the server and the mobile terminal respectively;
[0043] The third sending module is used to obtain the key to be identified input by the user to be identified based on the random key, and send the key to be identified to the server, so that the server can identify the unlocking authority of the password lock of the user to be identified based on the comparison result of the key to be identified and the random key.
[0044] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.
[0045] A computer-readable storage medium stores a computer program, which implements the steps of the above method when executed by a processor.
[0046] The above-mentioned authentication method, system, device, computer equipment and storage medium based on the improved cryptographic algorithm use the user group identifier of the user to be identified sent by the password lock to query the registered biometric information database through the server, obtain the target registered biometric information corresponding to the user group identifier, and identify the identity of the user to be identified based on the comparison result of the target registered biometric information and the biometric information of the user to be identified sent by the password lock. After the identity authentication is passed, the authentication pass information is sent to the password lock. The password lock receives the information and generates a random key and sends it to the server and the mobile terminal of the user to be identified, so that the server can compare the user input key sent by the mobile terminal with the random key to authenticate the password lock unlocking authority of the user to be identified. Compared with the traditional method of verification through passwords, this solution authenticates the user's password lock unlocking authority by verifying the user's biometrics and random keys, thereby improving the security of authority identification. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 FIG1 is an application environment diagram of an authentication method based on an improved cryptographic algorithm in one embodiment;
[0048] Figure 2 1 is a flow chart of an authentication method based on an improved cryptographic algorithm in one embodiment;
[0049] Figure 3 Schematic diagram of the face recognition process in one embodiment;
[0050] Figure 4 1 is a flow chart of an authentication method based on an improved cryptographic algorithm in another embodiment;
[0051] Figure 5 1 is a flow chart of an authentication method based on an improved cryptographic algorithm in another embodiment;
[0052] Figure 6 is a structural block diagram of an authentication device based on an improved cryptographic algorithm in one embodiment;
[0053] Figure 7 is a structural block diagram of an authentication device based on an improved cryptographic algorithm in another embodiment;
[0054] Figure 8 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0056] The authentication method based on the improved cryptographic algorithm provided in this application can be applied to Figure 1 In the application environment shown, the mobile terminal 102 communicates with the server 104 and the password lock 106 via a network. The server 104 can receive the user group identifier and biometric information corresponding to the user to be identified, sent by the password lock 106, and obtain the target registered biometric information corresponding to the user group identifier by querying the registered biometric information database. It then obtains a comparison result between the target registered biometric information and the obtained biometric information to authenticate the user. When the server 104 determines that the identity authentication is successful, it can send an authentication success message to the password lock 106. The password lock 106 can generate a random key and send it to the server 104 and the mobile terminal 102. After receiving the random key, the mobile terminal 102 sends the key entered by the user to the server 104. The server 104 then identifies the user's unlocking authority for the password lock 106 based on the comparison result between the key entered by the user and the random key received by the server 104. The mobile terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablet computers, and portable wearable devices. The server 104 can be implemented as a standalone server or a server cluster consisting of multiple servers.
[0057] In one embodiment, Figure 2 As shown, an authentication method based on an improved cryptographic algorithm is provided, which is applied to Figure 1 The following steps are used as an example to illustrate the server in the example:
[0058] Step S202: Receive the user group identifier and biometric information corresponding to the user to be identified sent by the password lock, and query the registered biometric information database according to the user group identifier to obtain the target registered biometric information corresponding to the user group identifier; the registered biometric information database contains the correspondence between the user group identifier and the registered biometric information.
[0059] The password lock can be a lockable device that can be unlocked in a specific manner. The user to be identified can be the user who wishes to unlock the password lock. When the user wishes to unlock the password lock, the user to be identified can send a corresponding unlock request to the password lock via their mobile terminal 102. The request can include the user group identifier corresponding to the user to be identified. Upon receiving the request, the password lock 106 can obtain the user's biometric information. The biometric information can be obtained via a biometric collection device provided in the password lock. The user group identifier can be the identifier of the group corresponding to the user to be identified, meaning that users can be grouped, for example, according to specific classification rules. The biometric collection device can be any one or more of a fingerprint scanner, palm print scanner, microphone, and camera on the password lock. Different biometric collection devices can collect different biometric information. When the biometric collection device is a camera, the password lock 106 can collect facial information of the user to be identified. For example, in some embodiments, receiving the user group identifier and biometric information corresponding to the user to be identified from the password lock includes receiving the user group identifier and facial information corresponding to the user to be identified from the password lock. In this embodiment, the password lock 106 can collect the facial information of the user to be identified as the biometric information of the user to be identified through the camera set therein, so that the authority of the user to be identified can be identified based on the facial information of the user to be identified.
[0060] After receiving the user group identifier and biometric information of the user to be identified, the combination lock 106 may send the user group identifier and biometric information to the server 104. Server 104 may query the registered biometric information database based on the received user group identifier to obtain the target registered biometric information corresponding to the user group identifier. The registered biometric information database may store multiple user group identifiers and multiple biometric information, as well as corresponding relationships between user group identifiers and biometric information. These multiple corresponding relationships may form corresponding sets. Server 104 may filter out a subset corresponding to the user to be identified from the multiple sets to obtain the corresponding target registered biometric information. For example, based on the received group identifier, server 104 may filter out a subset of registered biometric information corresponding to the group identifier from a pre-stored set of registered biometric information. This means that there is an association between the user group identifier and the biometric information, and each registered biometric information in the registered biometric information database may be biometric information pre-entered by the registered user, who may be a legitimate user.
[0061] Step S204: Obtain the comparison result between the target registered biometric information and the biometric information, and perform identity authentication on the user to be identified based on the comparison result.
[0062] The target registered biometric information may be biometric information associated with a user group identifier in a registered biometric information database, and the biometric information may be biometric information corresponding to the user to be identified, such as facial information, sent by the password lock 106. The server 104 may compare the target registered biometric information with the biometric information to obtain a corresponding comparison result, and the server 104 may perform identity authentication on the user to be identified based on the comparison result, thereby determining whether the identity of the user to be identified is legitimate, such as whether the user is a registered user.
[0063] In step S206, if the identity authentication is successful, the authentication success information is sent to the password lock, so that the password lock generates a random key based on the authentication success information and sends it to the server and the mobile terminal corresponding to the user to be identified respectively; the mobile terminal is used to obtain the key to be identified input by the user to be identified after receiving the random key and send it to the server.
[0064] When the server 104 determines that the identity authentication of the user to be identified has passed based on the above comparison results, the server 104 can send authentication pass information to the password lock 106. After receiving the authentication pass information sent by the server 104, the password lock 106 can generate a random key and send the random key to the server 104 and the mobile terminal 102 used by the user to be identified. The random key can be generated by a preset algorithm. After the server 104 receives the random key sent by the password lock 106, it can store the random key in the order sent by the password lock 106. After receiving the random key, the mobile terminal 102 can display the random key so that the user of the mobile terminal 102 can enter the corresponding key to be identified based on the displayed random key. After the user completes the input, the mobile terminal 102 can send the key to be identified entered by the user to the server 104 for permission identification.
[0065] Step S208: Obtain the random key sent by the password lock and the key to be identified sent by the mobile terminal, and perform authority identification on the password lock unlocking authority of the user to be identified based on the comparison result of the random key and the key to be identified.
[0066] The combination lock 106 may send the same random key to the server 104 and the mobile terminal 102, respectively. The mobile terminal 102 may then send the user-entered key to be identified to the server 104 based on the random key. The server 104 may then obtain the random key sent by the combination lock 106 and the key to be identified sent by the mobile terminal 102. The server 104 may then compare the random key with the key to be identified and, based on the comparison result, perform a permission check on the user to be identified to unlock the combination lock 106. For example, the server 104 may compare the received key with a pre-stored key, such as the random key sent by the combination lock 106. If the key is correct, the server 104 may issue an unlock instruction to the combination lock 106. Otherwise, the server 104 may return a key verification error message to the combination lock 106 and the mobile terminal 102. This allows the server 104 to determine whether the user to be identified is qualified to open the combination lock.
[0067] In the above-mentioned authentication method based on the improved cryptographic algorithm, the server uses the user group identifier of the user to be identified sent by the password lock to query the registered biometric information database, obtain the target registered biometric information corresponding to the user group identifier, and identify the identity of the user to be identified based on the comparison result of the target registered biometric information and the biometric information of the user to be identified sent by the password lock. After the identity authentication is passed, the authentication pass information is sent to the password lock. The password lock receives the information and generates a random key and sends it to the server and the mobile terminal of the user to be identified. The server can then compare the user input key sent by the mobile terminal with the random key to authenticate the password lock unlocking authority of the user to be identified. Compared with the traditional method of verification through passwords, this solution authenticates the user's password lock unlocking authority by verifying the user's biometrics and random keys, thereby improving the security of authority identification.
[0068] In one embodiment, before obtaining the target registered biometric information corresponding to the user group identifier, the method further includes: obtaining multiple registered user information; grouping the multiple registered user information according to preset classification rules to obtain multiple user groups; for each user group, determining the user group identifier corresponding to the user group, and sending the user group identifier to the mobile terminal corresponding to the registered user information in the user group, so that the mobile terminal receives and stores the user group identifier.
[0069] In this embodiment, server 104 may also pre-classify and store registered user information before performing user authorization verification. After user registration is complete, mobile terminal 102 may send user registration-related information to server 104. Server 104 may obtain multiple registered user information and group the multiple registered user information according to preset classification rules to form multiple user groups. Server 104 may also determine a user group identifier for each user group, so that each user group has a corresponding user group identifier. Server 104 may send this user group identifier to the mobile terminal 102 corresponding to the registered user information in the user group. After receiving the user group identifier, mobile terminal 102 may store the user group identifier. For example, after receiving multiple registered user information, server 104 may group the registered users according to preset rules, labeling each user group with a group identifier. The server then sends each user's group identifier to each user's mobile terminal for storage. Each user group contains at least one user. The preset rules of the present invention are user grouping rules, which can be specified according to actual needs, for example, grouping users according to the building floor, building, or neighborhood to which the address in the user registration information belongs.
[0070] Through this embodiment, the server 104 can group users based on their information, so that a subset of registered biometric features corresponding to the group identifier can be filtered out from the pre-stored set of registered biometric features according to the group identifier, which greatly reduces the number of biometric features that need to be compared when performing user identity authentication and improves the efficiency of authority identification.
[0071] In one embodiment, before obtaining the target registered biometric information corresponding to the user group identifier, it also includes: obtaining the registered biometric information corresponding to multiple registered user information; associating the registered biometric information with the user group identifier to which the corresponding registered user information belongs and storing the associated registered biometric information to obtain a registered biometric information database.
[0072] In this embodiment, the registered user information may also include the registered biometric information corresponding to the registered user. That is, the server 104 may pre-collect, classify, and store the registered user's biometric information. The server 104 may obtain the registered biometric information of multiple registered users and associate this registered biometric information with the user group identifier to which the registered user belongs. The server 104 may store the associated registered biometric information, thereby obtaining a registered biometric information database. For example, after the server 104 associates the registered biometric information with the corresponding user group identifier, the registered biometric information for the same user group identifier may be formed into subsets, and all registered biometric information may be formed into a set, which may include multiple subsets. The set formed by the registered biometric information may be stored in the registered biometric database.
[0073] Through this embodiment, the server 104 can filter out a subset of registered biometric features corresponding to the group identifier from the pre-stored registered biometric feature set based on the group identifier, greatly reducing the number of biometric features required for comparison during user identity authentication and improving the efficiency of authority identification.
[0074] In one embodiment, after receiving the user group identifier and biometric information corresponding to the user to be identified sent by the password lock, the method further includes: performing rotation correction and scale normalization processing on the facial information to be identified so that the facial information to be identified is consistent with the specifications of the target registered biometric information corresponding to the user group identifier, thereby obtaining the processed facial information to be identified; obtaining a first histogram feature corresponding to the processed facial information to be identified through a local three-value pattern algorithm, and obtaining a second histogram feature corresponding to the processed facial information to be identified through a local phase quantization algorithm, fusing the first histogram feature and the second histogram feature to obtain the facial feature to be identified; performing dimensionality reduction processing on the facial feature to be identified through a principal component analysis algorithm, and obtaining a facial feature vector to be identified from the facial feature to be identified after the dimensionality reduction processing through a linear discriminant analysis algorithm, so as to compare the facial feature vector to be identified with the target registered biometric information.
[0075] In this embodiment, the biometric information of the user to be identified may be facial information, and the server 104 may perform identity authentication on the facial information of the user to be identified. Before performing identity authentication on the facial information of the user to be identified, the server 104 may first process the received facial image information of the user to be identified. Since the user facial image information obtained by the mobile terminal 102 may not meet the requirements, the server 104 may perform rotation correction and normalization on the facial information to be identified, so that the facial information to be identified is consistent with the target registered biometric information specifications corresponding to the user group identifier, and obtain the processed facial information to be identified. The server 104 may obtain the corresponding first histogram feature of the processed facial information to be identified through a local three-value pattern algorithm, and obtain the second histogram feature corresponding to the processed facial information to be identified through a local phase quantization algorithm. The server 104 may also fuse the first histogram feature and the second histogram feature to obtain the facial feature to be identified, which may be a feature extracted based on the facial image to be identified. The server 104 can also perform dimensionality reduction processing on the facial features to be identified through the principal component analysis algorithm, and obtain the facial feature vector to be identified from the facial features to be identified after dimensionality reduction processing through the linear discriminant analysis algorithm, so that the server 104 can compare the target registered biometric information corresponding to the user group identifier of the user to be identified with the facial feature vector to be identified.
[0076] For example, Figure 3 As shown, Figure 3The figure is a flowchart of the face recognition step in one embodiment. Server 104 receives facial image information and a user group identifier sent by password lock 106. After receiving the user group identifier, server 104 selects a subset of registered biometric features corresponding to the user group identifier from a pre-stored set of registered biometric features. Server 104 can perform rotation correction and scale normalization on the collected facial image information, and use a pre-stored extraction algorithm to extract features from the received facial image information to obtain facial features. Specifically, server 104 processes the facial image information using an LTP (Local Ternary Pattern) algorithm to obtain LTP histogram features, and uses an LPQ (Local Phase Quantization) algorithm to process the received facial image information to obtain LPQ histogram features. The LTP histogram features and the LPQ histogram features are then fused in a predetermined order to obtain facial features. Server 104 can also process the extracted facial features using a pre-stored algorithm to obtain a facial feature vector. Specifically, the facial features are reduced in dimensionality using the PCA (Principal Component Analysis) algorithm, and then the reduced facial features are processed using the LDA (Linear Discriminant Analysis) algorithm to obtain a facial feature vector. The LDA algorithm is a classic pattern recognition algorithm, introduced to the field of pattern recognition and artificial intelligence by Belhumeur in 1996. The basic idea of discriminant analysis is to project high-dimensional pattern samples into an optimal discriminant vector space to extract classification information and compress the dimensionality of the feature space. After projection, the pattern samples are guaranteed to have the maximum inter-class distance and the minimum intra-class distance in the new subspace, that is, the patterns have optimal separability in this space. Therefore, it is an effective feature extraction method. Using this method, the inter-class scatter matrix of the projected pattern samples can be maximized while the intra-class scatter matrix can be minimized. That is, it can ensure that the pattern samples have the smallest intra-class distance and the largest inter-class distance in the new space after projection, that is, the pattern has the best separability in this space.
[0077] Through this embodiment, the server 104 can use the LTP algorithm and the LPQ algorithm to extract and fuse the features of the facial image information respectively, perform dimensionality reduction processing on the fused facial features, and obtain the facial feature vector after processing through the LDA algorithm, which is conducive to making full use of the facial image information and obtaining better recognition results, thereby improving the efficiency and accuracy of authority recognition.
[0078] In one embodiment, a comparison result between target registered biometric information and biometric information is obtained, and identity authentication of the user to be identified is performed based on the comparison result, including: obtaining the similarity between the face feature vector to be identified and the target registered face feature vector corresponding to the target registered biometric information, and identity authentication of the user to be identified based on the similarity; if the similarity is greater than a preset similarity threshold, it is determined that the user to be identified has passed the identity authentication.
[0079] In this embodiment, the biometric information of the user to be identified may be the user's facial image information, and the server 104 may perform permission identification on the user's facial image information. After the server 104 performs the above-mentioned corresponding processing on the facial image information of the user to be identified to obtain the facial feature vector to be identified, the server 104 may obtain the similarity between the facial feature vector to be identified and the target registered facial feature vector corresponding to the target registered biometric information, and perform identity authentication on the user to be identified based on the similarity. When the similarity is greater than the preset similarity threshold, the server 104 may determine that the user to be identified has passed the identity authentication, otherwise, the user to be identified has not passed the identity authentication. For example, Figure 3 As shown, after obtaining the facial feature vector of the user to be identified, the server 104 can calculate the similarity between the obtained facial feature vector and the pre-stored facial feature vector in the pre-stored biometric feature subset to obtain a similarity value, and determine the identification result based on the similarity value. If the similarity value is greater than a preset threshold, a biometric identification success message is sent to the password lock 106. If the similarity value is equal to or less than the preset threshold, a biometric identification failure message is returned to the password lock 106. The target registered biometric information can be the registered biometric information corresponding to the user group identifier stored in the mobile terminal 102 of the user to be identified, and the target facial feature vector of the target registered biometric information can be data pre-stored in the registered biometric information database, or it can be the target facial feature vector obtained by the server 104 after performing the above-mentioned corresponding operation based on the target registered biometric information.
[0080] Through this embodiment, server 104 can authenticate the identity of the user to be identified based on the comparison of the facial feature vector of the user to be identified with the registered facial feature vector corresponding to the user group representation, thereby improving the efficiency of authorization recognition. Furthermore, by comparing the collected biometric features with the biometric features in the registered biometric feature subset to obtain an identification result, and then verifying the identity using the key, this dual authentication method combining biometrics and keys greatly improves the efficiency and reliability of authentication.
[0081] In one embodiment, Figure 4 As shown, an authentication method based on an improved cryptographic algorithm is provided, which is applied to Figure 1 The mobile terminal in the example is used to illustrate, including the following steps:
[0082] Step S302: Detecting a detection signal sent by the combination lock, and obtaining a device identification corresponding to the combination lock based on the detection signal.
[0083] The combination lock 106 can emit a detection signal at preset time intervals or continuously. The detection signal can be a wireless Bluetooth signal. The combination lock 106 can be located in a predetermined area, and the detection signal emitted by the combination lock 106 can also be a signal that is effective within a certain range. The mobile terminal 102 can receive the signal emitted by the combination lock 106 and obtain the device identification corresponding to the combination lock 106 based on the detection signal. For example, after the user's mobile terminal enters the predetermined area, the device identification of the combination lock is extracted from the received wireless signal. Multiple combination locks 106 can be located in the predetermined area.
[0084] Step S304: Obtain the user group identifier to which the user to be identified belongs, and send the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects the biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to the server; the server is used to obtain the corresponding target registered biometric information based on the user group identifier, and authenticate the user to be identified based on the comparison result of the biometric information with the registered biometric information, and send authentication pass information to the password lock when the authentication is passed, so that the password lock generates a random key based on the authentication pass information and sends it to the server and mobile terminal respectively.
[0085] After obtaining the device identifier of password lock 106, mobile terminal 102 can establish communication with password lock 106 and perform the corresponding permission identification process. Mobile terminal 102 can obtain the user group identifier of the user to be identified stored in mobile terminal 102 and send the user group identifier to password lock 106 corresponding to the device identifier. After receiving the user group identifier, password lock 106 can obtain the biometric information corresponding to the user to be identified through the biometric collection device provided in password lock 106, and send the biometric information along with the user group identifier and biometric information to server 104. For example, mobile terminal 102 communicates with password lock 106 based on the device identifier and sends the user's group identifier to password lock 106; password lock 106 collects the user's biometric information through the biometric collection device and sends the collected user biometric information and group identifier to server 104. Server 104 can then authenticate the user to be identified based on the user group identifier and biometric information.
[0086] Step S306: obtaining the key to be identified input by the user to be identified based on the random key, and sending the key to be identified to the server, so that the server can identify the unlocking authority of the password lock of the user to be identified based on the comparison result of the key to be identified and the random key.
[0087] When the server 104 determines that the identity authentication of the user to be identified has passed based on the above comparison results, the server 104 may send an authentication pass message to the password lock 106. After receiving the authentication pass message sent by the server 104, the password lock 106 may generate a random key and send the random key to the server 104 and the mobile terminal 102 used by the user to be identified. The random key may be generated using a preset algorithm. After receiving the random key sent by the password lock 106, the server 104 may store the random key in the order sent by the password lock 106. After receiving the random key, the mobile terminal 102 may display the random key so that the user of the mobile terminal 102 can enter the corresponding key to be identified based on the displayed random key. After the user completes the input, the mobile terminal 102 may send the user-entered key to be identified to the server 104 for permission identification to determine whether the user to be identified has the permission to open the password lock 106.
[0088] In the above-mentioned authentication method based on the improved cryptographic algorithm, the server uses the user group identifier of the user to be identified sent by the password lock to query the registered biometric information database, obtain the target registered biometric information corresponding to the user group identifier, and identify the identity of the user to be identified based on the comparison result of the target registered biometric information and the biometric information of the user to be identified sent by the password lock. After the identity authentication is passed, the authentication pass information is sent to the password lock. The password lock receives the information and generates a random key and sends it to the server and the mobile terminal of the user to be identified. The server can then compare the user input key sent by the mobile terminal with the random key to authenticate the password lock unlocking authority of the user to be identified. Compared with the traditional method of verification through passwords, this solution authenticates the user's password lock unlocking authority by verifying the user's biometrics and random keys, thereby improving the security of authority identification.
[0089] In one embodiment, Figure 5 As shown, Figure 5 The following is a flow chart of an authentication method based on an improved cryptographic algorithm in another embodiment.
[0090] S100: The server groups registered users according to preset rules. Each user group is marked with a group identifier. The server sends each user's group identifier to each user's mobile terminal for storage.
[0091] S200: The password lock broadcasts a wireless signal to a preset area. The password lock is provided with a biometric feature collection device.
[0092] S300: After the user's mobile terminal enters the preset area, the device identification of the password lock is extracted from the received wireless signal;
[0093] S400: The user's mobile terminal communicates with the password lock according to the device identifier and sends the user's group identifier to the password lock;
[0094] S500: The password lock collects user biometric information through a biometric collection device, and sends the collected user biometric information and group ID to a server;
[0095] S600: The server selects a subset of registered biometric features corresponding to the group identifier from a pre-stored set of registered biometric features based on the received group identifier, obtains a similarity value by analyzing and comparing the biometric feature information to be identified with the pre-stored biometric features in the pre-stored biometric feature subset, and determines an identification result based on the similarity value. If the similarity value is greater than a preset threshold, a biometric identification success message is sent to the password lock; if the similarity value is equal to or less than the preset threshold, a biometric identification failure message is returned to the password lock.
[0096] S700: After receiving the biometric identification success information, the password lock randomly generates a key and sends the generated key to the user's mobile terminal and the server at the same time;
[0097] S800: The user mobile terminal sends the key input by the user to the server;
[0098] S900: The server compares the received key with the pre-stored key. If the key is correct, the server sends an unlocking instruction to the combination lock; otherwise, a key verification error message is returned.
[0099] Among them, the above-mentioned biometric feature collection device is selected from any one or more of a fingerprint scanner, a palm print scanner, a microphone, and a camera, and the biometric feature collection device is a camera.
[0100] The above step S600 specifically includes:
[0101] S601: The password lock collects user facial image information through a camera and sends the collected user facial image information and group ID to a server;
[0102] S602: The server selects a subset of registered biometric features corresponding to the group identifier from a pre-stored set of registered biometric features based on the received group identifier;
[0103] S603: On the server side, a pre-stored extraction algorithm is used to perform feature extraction on the received facial image information to obtain facial features;
[0104] S604: On the server side, the extracted facial features are processed using a pre-stored algorithm to obtain a facial feature vector;
[0105] S605: On the server side, the similarity between the calculated facial feature vector and the pre-stored facial feature vector in the pre-stored biometric feature subset is obtained to obtain a similarity value, and the recognition result is determined based on the similarity value. If the similarity value is greater than a preset threshold, a biometric feature recognition success message is sent to the password lock. If the similarity value is equal to or less than the preset threshold, a biometric feature recognition failure message is returned to the password lock.
[0106] Prior to step S603, the method further includes performing rotation correction and scale normalization on the collected facial image information. Step S603 specifically includes processing the received facial image information using the LTP algorithm to obtain LTP histogram features, processing the received facial image information using the LPQ algorithm to obtain LPQ histogram features, and fusing the LTP histogram features and the LPQ histogram features in a predetermined order to obtain facial features. Step S604 specifically includes performing dimensionality reduction processing on the facial features using the PCA algorithm, and then processing the facial features obtained after the dimensionality reduction processing using the LDA algorithm to obtain a facial feature vector.
[0107] Through the above embodiment, the server 104 filters out a subset of registered biometric features corresponding to the group identifier from the pre-stored set of registered biometric features based on the group identifier, thereby greatly reducing the number of biometric features that need to be compared when performing user identity authentication; in addition, the server 104 obtains an identification result by comparing the collected biometric features with the biometric features in the registered biometric feature subset, and then performs identity authentication through the key. This dual authentication method combining biometric features and keys greatly improves the efficiency and reliability of authentication.
[0108] In one embodiment, an authentication system based on an improved cryptographic algorithm is provided, comprising a mobile terminal 102 and a server 104, wherein:
[0109] The mobile terminal is configured to detect a detection signal emitted by the password lock and obtain a device identification corresponding to the password lock based on the detection signal; obtain a user group identification to which the user to be identified belongs, and transmit the user group identification to the password lock corresponding to the device identification, so that the password lock collects biometric information of the user to be identified corresponding to the mobile terminal, and transmits the user group identification and biometric information to the server;
[0110] The server is configured to query a registered biometric information database based on the user group identifier to obtain target registered biometric information corresponding to the user group identifier; the registered biometric information database contains a correspondence between the user group identifier and the registered biometric information; obtain a comparison result between the target registered biometric information and the biometric information, and perform identity authentication on the user to be identified based on the comparison result; if the identity authentication is successful, send an authentication pass message to the password lock, so that the password lock generates a random key based on the authentication pass message and sends it to the server and mobile terminal respectively;
[0111] The mobile terminal is configured to receive the random key and then obtain the key to be identified input by the user to be identified and send it to the server;
[0112] The server is used to identify the unlocking authority of the password lock of the user to be identified based on the comparison result of the random key and the key to be identified.
[0113] The specific definitions of the authentication system based on the improved cryptographic algorithm can be found in the definitions of the authentication method based on the improved cryptographic algorithm above and will not be repeated here. Each module in the authentication system based on the improved cryptographic algorithm can be implemented in whole or in part via hardware. Each of the modules can be embedded in or independent of a processor in a computer device in hardware form, so that the processor can call and execute the operations corresponding to each module.
[0114] It should be understood that although Figure 2-Figure 5 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. In addition, Figure 2-Figure 5 At least part of the steps may include multiple steps or multiple stages. These steps or stages are not necessarily performed at the same time, but can be performed at different times. The order of execution of these steps or stages is not necessarily one by one, but can be performed in turn or alternately with other steps or at least part of the steps or stages in other steps.
[0115] In one embodiment, Figure 6 As shown, an authentication device based on an improved cryptographic algorithm is provided, comprising: a first acquisition module 500, an identity authentication module 502, a first sending module 504 and an authority identification module 506, wherein:
[0116] The first acquisition module 500 is used to receive the user group identifier and biometric information corresponding to the user to be identified sent by the password lock, and query the registered biometric information database based on the user group identifier to obtain the target registered biometric information corresponding to the user group identifier; the registered biometric information database contains the correspondence between the user group identifier and the registered biometric information.
[0117] The identity authentication module 502 is used to obtain the comparison result between the target registered biometric information and the biometric information, and perform identity authentication on the user to be identified based on the comparison result.
[0118] The first sending module 504 is used to send authentication pass information to the password lock if the identity authentication is passed, so that the password lock generates a random key based on the authentication pass information and sends it to the server and the mobile terminal corresponding to the user to be identified respectively; the mobile terminal is used to obtain the key to be identified input by the user to be identified after receiving the random key and send it to the server.
[0119] The authority identification module 506 is used to obtain the random key sent by the password lock and the key to be identified sent by the mobile terminal, and perform authority identification on the password lock unlocking authority of the user to be identified based on the comparison result of the random key and the key to be identified.
[0120] In one embodiment, the above-mentioned device also includes: a registration module, which is used to obtain multiple registered user information; group the multiple registered user information according to preset classification rules to obtain multiple user groups; for each user group, determine the user group identifier corresponding to the user group, and send the user group identifier to the mobile terminal corresponding to the registered user information in the user group, so that the mobile terminal receives the user group identifier and stores it.
[0121] In one embodiment, the above-mentioned device also includes: an association module, which is used to obtain registered biometric information corresponding to multiple registered user information; associate the registered biometric information with the user group identifier to which the corresponding registered user information belongs and store the associated registered biometric information to obtain a registered biometric information database.
[0122] In one embodiment, the first acquisition module 500 is specifically configured to receive a user group identifier corresponding to a user to be identified and facial information corresponding to the user to be identified, which are sent by a password lock.
[0123] In one embodiment, the above-mentioned device also includes: a processing module, which is used to perform rotation correction and scale normalization processing on the facial information to be identified, so that the facial information to be identified is consistent with the specifications of the target registered biometric information corresponding to the user group identifier, and obtain the processed facial information to be identified; obtain the first histogram features corresponding to the processed facial information to be identified through a local three-value pattern algorithm, and obtain the second histogram features corresponding to the processed facial information to be identified through a local phase quantization algorithm, and fuse the first histogram features and the second histogram features to obtain the facial features to be identified; perform dimensionality reduction processing on the facial features to be identified through a principal component analysis algorithm, and obtain the facial feature vector to be identified from the facial features to be identified after dimensionality reduction processing through a linear discriminant analysis algorithm, so as to compare the facial feature vector to be identified with the target registered biometric information.
[0124] In one embodiment, the above-mentioned identity authentication module 502 is specifically used to obtain the similarity between the facial feature vector of the person to be identified and the target registered facial feature vector corresponding to the target registered biometric information, and perform identity authentication on the user to be identified based on the similarity; if the similarity is greater than a preset similarity threshold, it is determined that the user to be identified has passed the identity authentication.
[0125] In one embodiment, Figure 7 As shown, an authentication device based on an improved cryptographic algorithm is provided, comprising: a second acquisition module 600, a second sending module 602 and a third sending module 604, wherein:
[0126] The second acquisition module 600 is configured to detect a detection signal sent by the combination lock, and acquire a device identification corresponding to the combination lock based on the detection signal.
[0127] The second sending module 602 is used to obtain the user group identifier to which the user to be identified belongs, and send the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects the biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to the server; the server is used to obtain the corresponding target registered biometric information based on the user group identifier, and authenticate the user to be identified based on the comparison result of the biometric information with the registered biometric information, and send authentication pass information to the password lock when the authentication is successful, so that the password lock generates a random key based on the authentication pass information and sends it to the server and mobile terminal respectively.
[0128] The third sending module 604 is used to obtain the key to be identified input by the user to be identified based on the random key, and send the key to be identified to the server, so that the server can identify the unlocking authority of the password lock of the user to be identified based on the comparison result of the key to be identified and the random key.
[0129] The specific limitations of the authentication device based on the improved cryptographic algorithm can be found in the limitations of the authentication method based on the improved cryptographic algorithm described above and will not be further elaborated here. Each module in the authentication device based on the improved cryptographic algorithm can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the modules can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0130] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 8 As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data such as biometrics and user information. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements an authentication method based on an improved cryptographic algorithm.
[0131] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0132] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the above-mentioned authentication method based on the improved cryptographic algorithm when executing the computer program.
[0133] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned authentication method based on the improved cryptographic algorithm is implemented.
[0134] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0135] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0136] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. An authentication method based on an improved cryptographic algorithm, characterized in that: Applied to a server, the method includes: Receiving a user group identifier and biometric information corresponding to a user to be identified from a password lock, and querying a registered biometric information database based on the user group identifier to obtain target registered biometric information corresponding to the user group identifier; the registered biometric information database contains a correspondence between the user group identifier and the registered biometric information; the biometric information includes facial information of the person to be identified; Performing rotation correction and scale normalization processing on the facial information to be identified so that the facial information to be identified is consistent with the specifications of the target registered biometric information corresponding to the user group identifier, thereby obtaining processed facial information to be identified; obtaining a first histogram feature corresponding to the processed facial information to be identified through a local three-value pattern algorithm, and obtaining a second histogram feature corresponding to the processed facial information to be identified through a local phase quantization algorithm, fusing the first histogram feature and the second histogram feature to obtain facial features to be identified; performing dimensionality reduction processing on the facial features to be identified through a principal component analysis algorithm, and obtaining a facial feature vector to be identified from the facial features to be identified after the dimensionality reduction processing through a linear discriminant analysis algorithm, and comparing the facial feature vector to be identified with the target registered biometric information; Obtaining a comparison result between the target registered biometric information and a facial feature vector of a person to be identified in the biometric information, and performing identity authentication on the user to be identified based on the comparison result; If the identity authentication is successful, an authentication pass message is sent to the password lock, so that the password lock generates a random key based on the authentication pass message and sends it to the server and the mobile terminal corresponding to the user to be identified respectively; the mobile terminal is configured to display the random key after receiving the random key, obtain the key to be identified input by the user to be identified based on the displayed random key, and send the key to be identified to the server; The random key sent by the password lock and the key to be identified sent by the mobile terminal are obtained, and the password lock unlocking authority of the user to be identified is identified based on a comparison result of the random key and the key to be identified.
2. The method according to claim 1, characterized in that Before acquiring the target registration biometric information corresponding to the user group identifier, the method further includes: Get multiple registered user information; Grouping the plurality of registered user information according to a preset classification rule to obtain a plurality of user groups; For each user group, a user group identifier corresponding to the user group is determined, and the user group identifier is sent to a mobile terminal corresponding to the registered user information in the user group, so that the mobile terminal receives and stores the user group identifier.
3. The method according to claim 2, characterized in that Before acquiring the target registration biometric information corresponding to the user group identifier, the method further includes: Obtaining registered biometric information corresponding to the plurality of registered user information; The registered biometric information is associated with the user group identifier to which the corresponding registered user information belongs, and the associated registered biometric information is stored to obtain the registered biometric information database.
4. The method according to claim 1, wherein The obtaining a comparison result between the target registered biometric information and the biometric information, and performing identity authentication on the user to be identified according to the comparison result, includes: Obtaining a similarity between the facial feature vector of the person to be identified and a target registered facial feature vector corresponding to the target registered biometric information, and performing identity authentication on the user to be identified based on the similarity; If the similarity is greater than a preset similarity threshold, it is determined that the user to be identified has passed the identity authentication.
5. An authentication method based on an improved cryptographic algorithm, characterized in that: Applied to a mobile terminal, the method includes: Detecting a detection signal emitted by a password lock, and obtaining a device identification corresponding to the password lock based on the detection signal; Obtain the user group identifier to which the user to be identified belongs, and send the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects the biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to the server; the biometric information includes facial information to be identified; the server is used to obtain the corresponding target registered biometric information according to the user group identifier, perform rotation correction and scale normalization on the facial information to be identified, so that the facial information to be identified is consistent with the target registered biometric information corresponding to the user group identifier, and obtain the processed facial information to be identified; obtain the first histogram feature corresponding to the processed facial information to be identified by the local three-value pattern algorithm, and obtain the first histogram feature corresponding to the processed facial information to be identified by the local phase quantization algorithm The first histogram feature and the second histogram feature are fused to obtain a facial feature to be identified; the facial feature to be identified is subjected to dimensionality reduction processing by a principal component analysis algorithm, and a facial feature vector to be identified is obtained from the facial feature to be identified after the dimensionality reduction processing by a linear discriminant analysis algorithm, so as to compare the facial feature vector to be identified with the target registered biometric information based on the facial feature vector to be identified; the identity of the user to be identified is authenticated based on the comparison result of the facial feature vector to be identified in the biometric information and the target registered biometric information, and when the authentication is successful, an authentication pass message is sent to the password lock, so that the password lock generates a random key according to the authentication pass message and sends it to the server and the mobile terminal respectively; The random password is displayed, a key to be identified is obtained from the user to be identified based on the displayed random key, and the key to be identified is sent to the server, so that the server identifies the unlocking authority of the password lock of the user to be identified based on the comparison result between the key to be identified and the random key.
6. An authentication system based on an improved cryptographic algorithm, characterized in that: Comprising a mobile terminal and a server; wherein: The mobile terminal is configured to detect a detection signal emitted by a password lock, obtain a device identifier corresponding to the password lock based on the detection signal, obtain a user group identifier to which a user to be identified belongs, and transmit the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects biometric information of the user to be identified corresponding to the mobile terminal, and transmits the user group identifier and the biometric information to a server; the biometric information includes facial information of the person to be identified; The server is used to query the registered biometric information database according to the user group identifier to obtain the target registered biometric information corresponding to the user group identifier; the registered biometric information database contains the corresponding relationship between the user group identifier and the registered biometric information; the face information to be identified is subjected to rotation correction and scale normalization processing to make the face information to be identified consistent with the specifications of the target registered biometric information corresponding to the user group identifier, thereby obtaining the processed face information to be identified; the first histogram feature corresponding to the processed face information to be identified is obtained by a local three-value pattern algorithm, and the second histogram feature corresponding to the processed face information to be identified is obtained by a local phase quantization algorithm, and the first histogram feature is used to obtain the first histogram feature corresponding to the processed face information to be identified. and the second histogram feature fusion to obtain the facial features to be identified; perform dimensionality reduction processing on the facial features to be identified by a principal component analysis algorithm, and obtain the facial feature vector to be identified from the facial features to be identified after the dimensionality reduction processing by a linear discriminant analysis algorithm, and compare the facial feature vector to be identified with the target registered biometric information based on the facial feature vector to be identified; obtain the comparison result of the target registered biometric information and the facial feature vector to be identified in the biometric information, and authenticate the user to be identified based on the comparison result; if the identity authentication is passed, send authentication pass information to the password lock, so that the password lock generates a random key according to the authentication pass information and sends it to the server and the mobile terminal respectively; The mobile terminal is configured to display the random key after receiving the random key, obtain the key to be identified input by the user to be identified based on the displayed random key, and send the key to the server; The server is used to perform authority identification on the password lock unlocking authority of the user to be identified based on the comparison result of the random key and the key to be identified.
7. An authentication device based on an improved cryptographic algorithm, characterized in that: Applied to a server, the device includes: A first acquisition module is configured to receive a user group identifier and biometric information corresponding to a user to be identified, sent by a password lock, and query a registered biometric information database based on the user group identifier to obtain target registered biometric information corresponding to the user group identifier; the registered biometric information database contains a correspondence between user group identifiers and registered biometric information; the biometric information includes facial information of the person to be identified; a processing module configured to perform rotation correction and scale normalization processing on the facial information to be identified so that the facial information to be identified is consistent with the specifications of the target registered biometric information corresponding to the user group identifier, thereby obtaining processed facial information to be identified; obtaining a first histogram feature corresponding to the processed facial information to be identified through a local three-value pattern algorithm, and obtaining a second histogram feature corresponding to the processed facial information to be identified through a local phase quantization algorithm, and fusing the first histogram feature and the second histogram feature to obtain facial features to be identified; performing dimensionality reduction processing on the facial features to be identified through a principal component analysis algorithm, and obtaining a facial feature vector to be identified from the facial features to be identified after the dimensionality reduction processing through a linear discriminant analysis algorithm, for comparison based on the facial feature vector to be identified and the target registered biometric information; An identity authentication module, configured to obtain a comparison result between the target registered biometric information and a facial feature vector of a person to be identified in the biometric information, and perform identity authentication on the user to be identified based on the comparison result; a first sending module configured to send authentication pass information to the password lock if the identity authentication is successful, so that the password lock generates a random key based on the authentication pass information and sends the random key to the server and the mobile terminal corresponding to the user to be identified; the mobile terminal is configured to display the random key after receiving the random key, obtain a key to be identified input by the user to be identified based on the displayed random key, and send the key to be identified to the server; The authority identification module is used to obtain the random key sent by the password lock and the key to be identified sent by the mobile terminal, and perform authority identification on the password lock unlocking authority of the user to be identified based on the comparison result of the random key and the key to be identified.
8. The device according to claim 7, characterized in that The device further includes a registration module, configured to: Get multiple registered user information; Grouping the plurality of registered user information according to a preset classification rule to obtain a plurality of user groups; For each user group, a user group identifier corresponding to the user group is determined, and the user group identifier is sent to a mobile terminal corresponding to the registered user information in the user group, so that the mobile terminal receives and stores the user group identifier.
9. The device according to claim 8, characterized in that The device further includes an association module, configured to: Obtaining registered biometric information corresponding to the plurality of registered user information; The registered biometric information is associated with the user group identifier to which the corresponding registered user information belongs, and the associated registered biometric information is stored to obtain the registered biometric information database.
10. An authentication device based on an improved cryptographic algorithm, characterized in that: Applied to a mobile terminal, the device includes: A second acquisition module is configured to detect a detection signal emitted by the password lock and acquire a device identification corresponding to the password lock based on the detection signal; The second sending module is used to obtain the user group identifier to which the user to be identified belongs, and send the user group identifier to the password lock corresponding to the device identifier, so that the password lock collects the biometric information of the user to be identified corresponding to the mobile terminal, and sends the user group identifier and the biometric information to the server; the biometric information includes the face information to be identified; the server is used to obtain the corresponding target registered biometric information according to the user group identifier, perform rotation correction and scale normalization on the face information to be identified, so that the face information to be identified is consistent with the target registered biometric information corresponding to the user group identifier, and obtain the processed face information to be identified; obtain the first histogram feature corresponding to the processed face information to be identified by the local three-value pattern algorithm, and obtain the first histogram feature corresponding to the processed face information to be identified by the local phase quantity The method further comprises: obtaining a second histogram feature corresponding to the processed facial information to be identified by using a principal component analysis algorithm, fusing the first histogram feature and the second histogram feature to obtain a facial feature to be identified; performing dimensionality reduction processing on the facial feature to be identified by using a principal component analysis algorithm, and obtaining a facial feature vector to be identified from the facial feature to be identified after the dimensionality reduction processing by using a linear discriminant analysis algorithm, so as to compare the facial feature vector to be identified with the target registered biometric information; authenticating the user to be identified based on the comparison result of the facial feature vector to be identified in the biometric information and the target registered biometric information, and sending an authentication pass message to the password lock when the authentication is passed, so that the password lock generates a random key according to the authentication pass message and sends it to the server and the mobile terminal respectively; The third sending module is used to display the random password, obtain the key to be identified input by the user to be identified based on the displayed random key, and send the key to be identified to the server, so that the server can identify the password lock unlocking authority of the user to be identified based on the comparison result of the key to be identified and the random key.
Citation Information
Patent Citations
Authentication method and device, computer equipment and storage medium
CN108900536A
Identity recognition preprocessing method and system and identity recognition method and system
CN112464198A