A security monitoring method and system based on edge computing
Through the edge computing box, multiple encryption and facial feature value comparison are solved, and security risks and manual monitoring omissions in traditional security monitoring systems are improved, achieving the improvement of security and timeliness.
Patent Information
- Application Number
- CN202111453407.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-01
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-12-01
AI Technical Summary
Traditional security monitoring systems require manual monitoring, and data transmission is not encrypted, which poses security risks.
Edge computing box is used for encryption and decryption and facial feature value comparison, and multiple encryption algorithms and authentication mechanisms are used to achieve security and automatic alarms of data transmission.
Improve the security and timeliness of monitoring, avoid the omissions of manual monitoring, and ensure the security of data transmission.
Smart Images

Figure CN114357413B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security monitoring, and particularly to a security monitoring method and system based on edge computing. Background Art
[0002] With the increasing improvement of people's living standards, there are also higher and higher requirements for the security of the living environment. Therefore, many communities have installed cameras for security monitoring. When a stranger is identified entering the community through the camera, an alarm is immediately issued.
[0003] However, traditionally, security monitoring requires security guards to be on duty and view the shooting content of the cameras through monitoring screens. It is impossible to achieve real-time monitoring, and there are often monitoring gaps. Moreover, the data transmitted by the cameras is not encrypted at all, which is easily deleted or tampered with by hackers, posing a great security risk.
[0004] Therefore, how to provide a security monitoring method and system based on edge computing to improve the security of monitoring has become an urgent technical problem to be solved. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a security monitoring method and system based on edge computing to improve the security of monitoring.
[0006] In a first aspect, the present invention provides a security monitoring method based on edge computing, including the following steps:
[0007] Step S10: The edge computing box obtains an encrypted authorized image set from the monitoring server and decrypts it;
[0008] Step S20: The edge computing box obtains a newly captured and encrypted face image set from the FTP server in real time, and decrypts the newly captured face image set;
[0009] Step S30: The edge computing box verifies the newly captured face image set by using the authorized image set based on a face algorithm and generates a verification result;
[0010] Step S40: The edge computing box encrypts the verification result and uploads it to the monitoring server for security alarm.
[0011] Further, the step S10 specifically includes:
[0012] Step S11: The monitoring server presets a first key update period and a first authentication key, creates a pair of first public key and first private key based on the first key update period and the first encryption algorithm, and sends the first public key and the first authentication key to the edge computing box;
[0013] Step S12: The monitoring server randomly generates a first key based on the second encryption algorithm, encrypts the pre-stored authorized image set using the first key, and encrypts the first key using the first private key to obtain a second key;
[0014] Step S13: After receiving the authorized image set acquisition request sent by the edge computing box, the monitoring server sends the encrypted authorized image set and the second key to the edge computing box;
[0015] Step S14: The edge computing box decrypts the second key using the received first public key, determines whether the decryption is successful. If the decryption is successful, the first key is obtained and step S17 is entered; if the decryption fails, it indicates that the first public key has expired and step S15 is entered;
[0016] Step S15: The edge computing box sends a first key acquisition request carrying the first authentication key to the monitoring server. The monitoring server parses the first key acquisition request to obtain the first authentication key, determines whether it matches the first authentication key stored locally in the monitoring server. If it matches, the latest first public key is sent to the edge computing box and step S16 is entered; if it does not match, the process ends;
[0017] Step S16: The edge computing box decrypts the second key using the received first public key to obtain the first key;
[0018] Step S17: The edge computing box decrypts the authorized image set using the first key to obtain a number of authorized face images.
[0019] Further, the specific steps of step S20 include:
[0020] Step S21: Each camera captures the latest face image in real time and uploads each of the latest face images to the FTP server in real time;
[0021] Step S22: The FTP server presets a second key update period and a second authentication key, creates a pair of second public key and second private key based on the second key update period and the first encryption algorithm, and sends the second public key and the second authentication key to the edge computing box;
[0022] Step S23: The FTP server randomly generates a third key based on the second encryption algorithm, encrypts the stored latest face images using the third key to obtain the latest face image set, and encrypts the third key using the second private key to obtain a fourth key;
[0023] Step S24: The edge computing box listens in real time via FTP to check if the number of the latest face images stored on the FTP server has increased. If so, it sends a request to obtain the latest face images to the FTP server and proceeds to Step S25; if not, it continues to listen.
[0024] Step S25: Based on the received request to obtain the latest face images, the FTP server sends the encrypted set of the latest face images and the fourth key to the edge computing box.
[0025] Step S26: The edge computing box decrypts the fourth key using the received second public key and determines whether the decryption is successful. If the decryption is successful, it obtains the third key and proceeds to Step S29; if the decryption fails, indicating that the second public key has expired, it proceeds to Step S27.
[0026] Step S27: The edge computing box sends a request to obtain the second key carrying the second authentication key to the FTP server. The FTP server parses the request to obtain the second authentication key and determines whether it matches the second authentication key stored locally on the FTP server. If it matches, it sends the latest second public key to the edge computing box and proceeds to Step S28; if it does not match, the process ends.
[0027] Step S28: The edge computing box decrypts the fourth key using the received second public key to obtain the third key.
[0028] Step S29: The edge computing box decrypts the set of the latest face images using the third key to obtain a number of the latest face images.
[0029] Further, Step S30 specifically includes:
[0030] Step S31: The edge computing box presets a similarity threshold, extracts the first face feature values of each latest face image in the set of the latest face images using a face algorithm, and extracts the second face feature values of each authorized face image in the set of authorized face images using a face algorithm.
[0031] Step S32: The edge computing box traverses and calculates the similarity between each first face feature value and the second face feature value, and determines whether the similarity is greater than the similarity threshold. If so, it generates a verification result indicating the existence of a stranger; if not, it generates a verification result indicating the non - existence of a stranger.
[0032] Further, Step S40 specifically includes:
[0033] Step S41: The edge computing box parses the verification result. If the verification result indicates the existence of a stranger, it proceeds to Step S42; if the verification result indicates the non - existence of a stranger, the process ends.
[0034] Step S42: The edge computing box randomly generates a fifth key based on the second encryption algorithm, encrypts the verification result and the corresponding latest face image with the fifth key to obtain an encrypted data packet, encrypts the fifth key with the first public key to obtain a sixth key, and uploads the encrypted data packet and the sixth key to the monitoring server;
[0035] Step S43: The monitoring server decrypts the sixth key with the first private key to obtain the fifth key, and then decrypts the encrypted data packet with the fifth key to obtain the verification result and the corresponding latest face image;
[0036] Step S44: The monitoring server pushes security alerts to the associated monitoring terminals in real time based on the verification result and the camera information carried by the latest face image.
[0037] In a second aspect, the present invention provides a security monitoring system based on edge computing, including the following modules:
[0038] An authorized image set acquisition module, configured to enable the edge computing box to obtain the encrypted authorized image set from the monitoring server and decrypt it;
[0039] A latest face image set acquisition module, configured to enable the edge computing box to obtain the real-time captured and encrypted latest face image set from the FTP server and decrypt the latest face image set;
[0040] A latest face image set verification module, configured to enable the edge computing box to verify the latest face image set with the authorized image set based on the face algorithm and generate a verification result;
[0041] A security alert module, configured to enable the edge computing box to encrypt the verification result and upload it to the monitoring server for security alerts.
[0042] Further, the authorized image set acquisition module specifically includes:
[0043] A monitoring server key creation unit, configured to enable the monitoring server to preset a first key update period and a first authentication key, create a pair of first public key and first private key based on the first key update period and the first encryption algorithm, and send the first public key and the first authentication key to the edge computing box;
[0044] An authorized image set encryption unit, configured to enable the monitoring server to randomly generate a first key based on the second encryption algorithm, encrypt the pre-stored authorized image set with the first key, and encrypt the first key with the first private key to obtain a second key;
[0045] The authorized image set and key sending unit is used to send the encrypted authorized image set and the second key to the edge computing box after the monitoring server receives the authorized image set acquisition request sent by the edge computing box;
[0046] The second key decryption unit is used for the edge computing box to decrypt the second key by using the received first public key, determine whether the decryption is successful. If the decryption is successful, the first key is obtained and the authorized image set decryption unit is entered; if the decryption fails, it indicates that the first public key has expired and the first key acquisition request sending unit is entered;
[0047] The first key acquisition request sending unit is used for the edge computing box to send a first key acquisition request carrying the first authentication key to the monitoring server. The monitoring server parses the first key acquisition request to obtain the first authentication key, and determines whether it matches the first authentication key stored locally in the monitoring server. If it matches, the latest first public key is sent to the edge computing box and the second key decryption unit is entered; if it does not match, the process ends;
[0048] The second key decryption unit is used for the edge computing box to decrypt the second key by using the received first public key to obtain the first key;
[0049] The authorized image set decryption unit is used for the edge computing box to decrypt the authorized image set by using the first key to obtain a number of authorized face images.
[0050] Further, the latest face image set acquisition module specifically includes:
[0051] The latest face image capture unit is used for each camera to capture the latest face image in real time and upload each of the latest face images to the FTP server in real time;
[0052] The FTP server key creation unit is used for the FTP server to preset a second key update period and a second authentication key, create a pair of second public key and second private key based on the second key update period and the first encryption algorithm, and send the second public key and the second authentication key to the edge computing box;
[0053] The latest face image encryption unit is used for the FTP server to randomly generate a third key based on the second encryption algorithm, encrypt the stored latest face images by using the third key to obtain the latest face image set, and encrypt the third key by using the second private key to obtain the fourth key;
[0054] The latest face image acquisition request sending unit is used for the edge computing box to monitor in real time whether the number of the latest face images stored in the FTP server increases by reading the FTP method. If so, it sends a latest face image acquisition request to the FTP server and enters the latest face image set and key sending unit; if not, it continues to monitor.
[0055] The latest face image set and key sending unit is used for the FTP server to send the encrypted latest face image set and the fourth key to the edge computing box based on the received latest face image acquisition request.
[0056] The fourth key decryption unit is used for the edge computing box to decrypt the fourth key by using the received second public key, and judge whether the decryption is successful. If the decryption is successful, it obtains the third key and enters the latest face image set decryption unit; if the decryption fails, it indicates that the second public key has expired and enters the second key acquisition request sending unit.
[0057] The second key acquisition request sending unit is used for the edge computing box to send a second key acquisition request carrying the second authentication key to the FTP server. The FTP server parses the second key acquisition request to obtain the second authentication key, and judges whether it matches the second authentication key stored locally in the FTP server. If it matches, it sends the latest second public key to the edge computing box and enters the fourth key secondary decryption unit; if it does not match, the process ends.
[0058] The fourth key secondary decryption unit is used for the edge computing box to decrypt the fourth key by using the received second public key to obtain the third key.
[0059] The latest face image set decryption unit is used for the edge computing box to decrypt the latest face image set by using the third key to obtain a number of the latest face images.
[0060] Further, the latest face image set verification module specifically includes:
[0061] The face feature value calculation unit is used for the edge computing box to preset a similarity threshold, extract the first face feature values of the latest face images in the latest face image set by using the face algorithm, and extract the second face feature values of the authorized face images in the authorized image set by using the face algorithm.
[0062] The face feature value comparison unit is used for the edge computing box to traverse and calculate the similarity between each first face feature value and the second face feature value, and judge whether the similarity is greater than the similarity threshold. If so, it generates a verification result that there are strangers; if not, it generates a verification result that there are no strangers.
[0063] Further, the security warning module specifically includes:
[0064] A verification result analysis unit is used for the edge computing box to analyze the verification result. If the verification result indicates the existence of a stranger, it enters the data encryption and upload unit; if the verification result indicates the non-existence of a stranger, the process ends.
[0065] A verification data encryption and upload unit is used for the edge computing box to randomly generate a fifth key based on a second encryption algorithm, use the fifth key to encrypt the verification result and the corresponding latest face image to obtain an encrypted data packet, use the first public key to encrypt the fifth key to obtain a sixth key, and upload the encrypted data packet and the sixth key to the monitoring server.
[0066] A verification data decryption unit is used for the monitoring server to decrypt the sixth key with the first private key to obtain the fifth key, and then use the fifth key to decrypt the encrypted data packet to obtain the verification result and the corresponding latest face image.
[0067] An alarm push unit is used for the monitoring server to real-time push security alarms to the associated monitoring terminals based on the verification result and the camera information carried by the latest face image.
[0068] The advantages of the present invention are as follows:
[0069] By creating a pair of first public key and first private key on the monitoring server based on the first key update period and the first encryption algorithm, and creating a first authentication key for re-applying the first public key when it expires, using the second encryption algorithm to create a first key, using the first key to encrypt the authorized image set, then using the first private key to encrypt the first key to obtain a second key, and sending the encrypted authorized image set, the second key, the first public key, and the first authentication key to the edge computing box. That is, the transmission of the authorized image set requires quadruple security encryption (1. The first key encrypts the authorized image set; 2. The first private key encrypts the first key; 3. Set the validity period of the first public key and the first private key (the first key update period); 4. Use different first encryption algorithms and second encryption algorithms to randomly generate different keys). For the interaction between the edge computing box and the FTP server, when the edge computing box sends data to the monitoring server, it also uses this quadruple encryption method, thus greatly ensuring the security of data transmission; by the edge computing box automatically comparing the face feature values of the authorized image set and the latest face image set, and sending the relevant data with a similarity greater than the similarity threshold to the monitoring server in real time, and then through the monitoring server to real-time push to the monitoring terminal for security alarms, avoiding the omissions caused by traditional manual monitoring, greatly improving the comprehensiveness and timeliness of monitoring, and ultimately greatly improving the security of monitoring. Description of the Drawings
[0070] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0071] Figure 1 It is a flowchart of a security monitoring method based on edge computing according to the present invention.
[0072] Figure 2 It is a schematic structural diagram of a security monitoring system based on edge computing according to the present invention.
[0073] Figure 3 It is a hardware architecture diagram of the present invention. Specific Embodiments
[0074] The technical solution in the embodiments of the present application has the following general idea: When transmitting data, the data is encrypted by a key randomly generated by a second encryption algorithm, a private key and a public key are randomly generated by a first encryption algorithm and a preset validity period is set, and then the key generated by the second encryption algorithm is encrypted by the private key to perform quadruple security encryption to ensure the security of data transmission; the edge computing box automatically compares the face feature values of the authorized image set and the latest face image set and gives real-time security alerts to improve the comprehensiveness and timeliness of monitoring, and finally realizes the improvement of the security of monitoring.
[0075] Please refer to Figures 1 to 3 As shown, a preferred embodiment of a security monitoring method based on edge computing according to the present invention includes the following steps:
[0076] Step S10: The edge computing box obtains the encrypted authorized image set from the monitoring server and decrypts it; the authorized image set includes several face images of the owners, that is, authorized face images; the edge computing box synchronizes the authorized image set with the monitoring server regularly;
[0077] Step S20: The edge computing box obtains the latest face image set that is real-time collected and encrypted from the FTP server and decrypts the latest face image set;
[0078] Step S30: The edge computing box verifies the latest face image set by using the authorized image set based on the face algorithm and generates a verification result;
[0079] Step S40: The edge computing box encrypts the verification result and uploads it to the monitoring server through the HTTP protocol for security alerts.
[0080] The specific content of step S10 includes:
[0081] Step S11: The monitoring server presets a first key update period and a first authentication key. Based on the first key update period and the first encryption algorithm, a pair of first public key and first private key are randomly created, and the first public key and the first authentication key are sent to the edge computing box; the first key update period is set as needed, for example, set to 5 minutes.
[0082] In specific implementation, the first encryption algorithm and the second encryption algorithm are not limited to any specific encryption algorithm. For example, the first encryption algorithm is set as the RSA encryption algorithm, and the second encryption algorithm is set as the AES encryption algorithm.
[0083] The data encrypted by the first public key can only be decrypted by the first private key, and the data encrypted by the first private key can only be decrypted by the first public key. And based on the first key update period, the validity periods of the first public key and the first private key are set. When the validity period is exceeded, the monitoring server randomly creates a pair of first public key and first private key again using the first encryption algorithm, and the edge computing box needs to use the first authentication key to reapply for the first public key from the monitoring server.
[0084] Step S12: The monitoring server randomly generates a first key based on the second encryption algorithm, uses the first key to encrypt the pre-stored authorized image set, and uses the first private key to encrypt the first key to obtain a second key.
[0085] Step S13: After the monitoring server receives the authorized image set acquisition request sent by the edge computing box through the HTTP protocol, it sends the encrypted authorized image set and the second key to the edge computing box.
[0086] Step S14: The edge computing box uses the received first public key to decrypt the second key, and judges whether the decryption is successful. If the decryption is successful, the first key is obtained and step S17 is entered; if the decryption fails, it means that the first public key has expired, and step S15 is entered.
[0087] Step S15: The edge computing box sends a first key acquisition request carrying the first authentication key to the monitoring server. The monitoring server parses the first key acquisition request to obtain the first authentication key, and judges whether it matches the first authentication key stored locally in the monitoring server. If it matches, it sends the latest first public key to the edge computing box and enters step S16; if it does not match, the process ends.
[0088] Step S16: The edge computing box uses the received first public key to decrypt the second key to obtain the first key.
[0089] Step S17: The edge computing box uses the first key to decrypt the authorized image set to obtain several authorized face images.
[0090] The specific steps of step S20 include:
[0091] Step S21: Each camera captures the latest face image in real time, and uploads each of the latest face images to the FTP server in real time after encrypting them using the third encryption algorithm;
[0092] Step S22: The FTP server presets a second key update period and a second authentication key, creates a pair of second public key and second private key based on the second key update period and the first encryption algorithm, and sends the second public key and the second authentication key to the edge computing box;
[0093] Step S23: The FTP server decrypts the latest face image using the third encryption algorithm, randomly generates a third key based on the second encryption algorithm, encrypts the stored latest face image using the third key to obtain a set of the latest face images, and encrypts the third key using the second private key to obtain a fourth key;
[0094] Step S24: The edge computing box listens in real time through the read FTP method whether the number of the latest face images stored on the FTP server increases. If so, it sends a request for obtaining the latest face image to the FTP server and proceeds to step S25; if not, it continues to listen;
[0095] Step S25: Based on the received request for obtaining the latest face image, the FTP server sends the encrypted set of the latest face images and the fourth key to the edge computing box;
[0096] Step S26: The edge computing box decrypts the fourth key using the received second public key, and judges whether the decryption is successful. If the decryption is successful, it obtains the third key and proceeds to step S29; if the decryption fails, it indicates that the second public key has expired and proceeds to step S27;
[0097] Step S27: The edge computing box sends a second key obtaining request carrying the second authentication key to the FTP server. The FTP server parses the second key obtaining request to obtain the second authentication key, and judges whether it matches the second authentication key stored locally on the FTP server. If they match, it sends the latest second public key to the edge computing box and proceeds to step S28; if they do not match, the process ends;
[0098] Step S28: The edge computing box decrypts the fourth key using the received second public key to obtain the third key;
[0099] Step S29: The edge computing box decrypts the set of the latest face images using the third key to obtain several latest face images.
[0100] Step S30 specifically includes the following:
[0101] Step S31: The edge computing box presets a similarity threshold, extracts the first face feature values of each latest face image set in the latest face image set by using a face algorithm, and extracts the second face feature values of each authorized face image in the authorized image set by using a face algorithm;
[0102] Step S32: The edge computing box traverses and calculates the similarity between each first face feature value and the second face feature value, determines whether the similarity is greater than the similarity threshold. If so, a verification result of the existence of a stranger is generated; if not, a verification result of the non-existence of a stranger is generated.
[0103] Step S40 specifically includes the following:
[0104] Step S41: The edge computing box analyzes the verification result. If the verification result is the existence of a stranger, it proceeds to Step S42; if the verification result is the non-existence of a stranger, the process ends;
[0105] Step S42: The edge computing box randomly generates a fifth key based on a second encryption algorithm, encrypts the verification result and the corresponding latest face image by using the fifth key to obtain an encrypted data packet, encrypts the fifth key by using the first public key to obtain a sixth key, and uploads the encrypted data packet and the sixth key to the monitoring server;
[0106] Step S43: The monitoring server decrypts the sixth key by using the first private key to obtain the fifth key, and then decrypts the encrypted data packet by using the fifth key to obtain the verification result and the corresponding latest face image;
[0107] Step S44: The monitoring server based on the verification result and the camera information carried by the latest face image, pushes a security warning to the associated monitoring terminal in real time. The camera information at least includes the community name, the camera number, and the camera location; the monitoring terminal is a mobile phone, a tablet computer, a smart watch, a smart bracelet, a laptop computer, or a monitoring large screen.
[0108] A preferred embodiment of a security monitoring system based on edge computing according to the present invention includes the following modules:
[0109] An authorized image set acquisition module, configured to enable the edge computing box to obtain an encrypted authorized image set from the monitoring server and decrypt it; the authorized image set includes a plurality of face images of the owners, that is, authorized face images; the edge computing box synchronizes the authorized image set with the monitoring server regularly;
[0110] The latest face image set acquisition module is used for the edge computing box to obtain the latest face image set that is real-time collected and encrypted from the FTP server, and decrypt the latest face image set;
[0111] The latest face image set verification module is used for the edge computing box to verify the latest face image set based on the face algorithm by using the authorized image set, and generate a verification result;
[0112] The security warning module is used for the edge computing box to encrypt the verification result and upload it to the monitoring server through the HTTP protocol for security warning.
[0113] The authorized image set acquisition module specifically includes:
[0114] The monitoring server key creation unit is used for the monitoring server to preset a first key update period and a first authentication key, randomly create a pair of first public key and first private key based on the first key update period and the first encryption algorithm, and send the first public key and the first authentication key to the edge computing box; the first key update period is set as needed, for example, set to 5 minutes;
[0115] In specific implementation, the first encryption algorithm and the second encryption algorithm are not limited to any specific encryption algorithm. For example, the first encryption algorithm is set as the RSA encryption algorithm, and the second encryption algorithm is set as the AES encryption algorithm;
[0116] The data encrypted by the first public key can only be decrypted by the first private key, and the data encrypted by the first private key can only be decrypted by the first public key. And based on the first key update period, the validity periods of the first public key and the first private key are set. When the validity period is exceeded, the monitoring server randomly creates a pair of first public key and first private key again by using the first encryption algorithm, and the edge computing box needs to use the first authentication key to reapply for the first public key from the monitoring server;
[0117] The authorized image set encryption unit is used for the monitoring server to randomly generate a first key based on the second encryption algorithm, encrypt the pre-stored authorized image set by using the first key, and encrypt the first key by using the first private key to obtain a second key;
[0118] The authorized image set and key sending unit is used for the monitoring server to send the encrypted authorized image set and the second key to the edge computing box after receiving the authorized image set acquisition request sent by the edge computing box through the HTTP protocol;
[0119] The second key decryption unit is used for the edge computing box to decrypt the second key by using the received first public key, and determine whether the decryption is successful. If the decryption is successful, the first key is obtained and the authorized image set decryption unit is entered; if the decryption fails, it indicates that the first public key has expired and the first key acquisition request sending unit is entered;
[0120] The first key acquisition request sending unit is used for the edge computing box to send a first key acquisition request carrying the first authentication key to the monitoring server. The monitoring server parses the first key acquisition request to obtain the first authentication key, and determines whether it matches the first authentication key stored locally in the monitoring server. If it matches, the latest first public key is sent to the edge computing box and the second key decryption unit is entered; if it does not match, the process ends;
[0121] The second key decryption unit is used for the edge computing box to decrypt the second key by using the received first public key to obtain the first key;
[0122] The authorized image set decryption unit is used for the edge computing box to decrypt the authorized image set by using the first key to obtain a number of authorized face images.
[0123] The latest face image set acquisition module specifically includes:
[0124] The latest face image capture unit is used for each camera to capture the latest face image in real time, and upload each of the latest face images to the FTP server in real time after encrypting them by using the third encryption algorithm;
[0125] The FTP server key creation unit is used for the FTP server to preset a second key update period and a second authentication key, create a pair of second public key and second private key based on the second key update period and the first encryption algorithm, and send the second public key and the second authentication key to the edge computing box;
[0126] The latest face image encryption unit is used for the FTP server to decrypt the latest face image by using the third encryption algorithm. The FTP server randomly generates a third key based on the second encryption algorithm, encrypts the stored latest face images by using the third key to obtain the latest face image set, and encrypts the third key by using the second private key to obtain the fourth key;
[0127] The latest face image acquisition request sending unit is used for the edge computing box to monitor in real time whether the number of the latest face images stored in the FTP server increases by reading the FTP method. If so, a latest face image acquisition request is sent to the FTP server and the latest face image set and key sending unit is entered; if not, continue to monitor;
[0128] The latest face image set and key sending unit is used for the FTP server to send the encrypted latest face image set and the fourth key to the edge computing box based on the received latest face image acquisition request;
[0129] The fourth key decryption unit is used for the edge computing box to decrypt the fourth key by using the received second public key, determine whether the decryption is successful. If the decryption is successful, the third key is obtained and the latest face image set decryption unit is entered; if the decryption fails, it indicates that the second public key has expired and the second key acquisition request sending unit is entered;
[0130] The second key acquisition request sending unit is used for the edge computing box to send a second key acquisition request carrying the second authentication key to the FTP server. The FTP server parses the second key acquisition request to obtain the second authentication key, and determines whether it matches the second authentication key stored locally in the FTP server. If it matches, the latest second public key is sent to the edge computing box and the fourth key secondary decryption unit is entered; if it does not match, the process ends;
[0131] The fourth key secondary decryption unit is used for the edge computing box to decrypt the fourth key by using the received second public key to obtain the third key;
[0132] The latest face image set decryption unit is used for the edge computing box to decrypt the latest face image set by using the third key to obtain several latest face images.
[0133] The latest face image set verification module specifically includes:
[0134] The face feature value calculation unit is used for the edge computing box to preset a similarity threshold, extract the first face feature values of each latest face image in the latest face image set by using a face algorithm, and extract the second face feature values of each authorized face image in the authorized image set by using a face algorithm;
[0135] The face feature value comparison unit is used for the edge computing box to traverse and calculate the similarity between each first face feature value and the second face feature value, and determine whether the similarity is greater than the similarity threshold. If so, a verification result of the existence of a stranger is generated; if not, a verification result of the non-existence of a stranger is generated.
[0136] The security alarm module specifically includes:
[0137] The verification result parsing unit is used for the edge computing box to parse the verification result. If the verification result is the existence of a stranger, the data encryption and upload unit is entered; if the verification result is the non-existence of a stranger, the process ends;
[0138] The verification data encryption and upload unit is used for the edge computing box to randomly generate a fifth key based on the second encryption algorithm, encrypt the verification result and the corresponding latest face image with the fifth key to obtain an encrypted data packet, encrypt the fifth key with the first public key to obtain a sixth key, and upload the encrypted data packet and the sixth key to the monitoring server;
[0139] The verification data decryption unit is used for the monitoring server to decrypt the sixth key with the first private key to obtain the fifth key, and then decrypt the encrypted data packet with the fifth key to obtain the verification result and the corresponding latest face image;
[0140] The alarm push unit is used for the monitoring server to push security alarms to the associated monitoring terminals in real time based on the verification result and the camera information carried by the latest face image. The camera information at least includes the community name, camera number, and camera location; the monitoring terminals are mobile phones, tablets, smart watches, smart bracelets, laptop computers, or monitoring large screens.
[0141] In summary, the advantages of the present invention are as follows:
[0142] By creating a pair of first public key and first private key on the monitoring server based on the first key update period and the first encryption algorithm, and creating a first authentication key for re-applying the first public key when it expires, creating a first key using the second encryption algorithm, encrypting the authorized image set with the first key, and then encrypting the first key with the first private key to obtain a second key, and sending the encrypted authorized image set, the second key, the first public key, and the first authentication key to the edge computing box. That is, the transmission of the authorized image set requires quadruple security encryption (1. Encrypt the authorized image set with the first key; 2. Encrypt the first key with the first private key; 3. Set the validity period of the first public key and the first private key (the first key update period); 4. Use different first encryption algorithms and second encryption algorithms to generate different keys). For the interaction between the edge computing box and the FTP server, and the edge computing box sending data to the monitoring server, it also based on this quadruple encryption method, thus greatly ensuring the security of data transmission; by the edge computing box automatically comparing the face feature values of the authorized image set and the latest face image set, and sending the relevant data with a similarity greater than the similarity threshold to the monitoring server in real time, and then pushing it to the monitoring terminal by the monitoring server in real time for security alarms, avoiding the omissions caused by traditional manual monitoring, greatly improving the comprehensiveness and timeliness of monitoring, and ultimately greatly improving the security of monitoring.
[0143] Although the specific embodiments of the present invention have been described above, those skilled in the art should understand that the specific embodiments we described are illustrative rather than used to limit the scope of the present invention. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present invention should all be covered by the scope protected by the claims of the present invention.
Claims
1. A security monitoring method based on edge computing, characterized in that: It includes the following steps: Step S10: The edge computing box obtains the encrypted authorized image set from the monitoring server and decrypts it; Step S20: The edge computing box obtains the latest face image set that is real-time captured and encrypted from the FTP server, and decrypts the latest face image set; Step S30: The edge computing box verifies the latest face image set by using the authorized image set based on the face algorithm, and generates a verification result; Step S40: The edge computing box encrypts the verification result and uploads it to the monitoring server for security warning; The specific content of step S10 includes: Step S11: The monitoring server presets a first key update period and a first authentication key, creates a pair of first public key and first private key based on the first key update period and the first encryption algorithm, and sends the first public key and the first authentication key to the edge computing box; Step S12: The monitoring server randomly generates a first key based on the second encryption algorithm, encrypts the pre-stored authorized image set by using the first key, and encrypts the first key by using the first private key to obtain a second key; Step S13: After receiving the authorized image set acquisition request sent by the edge computing box, the monitoring server sends the encrypted authorized image set and the second key to the edge computing box; Step S14: The edge computing box decrypts the second key by using the received first public key, determines whether the decryption is successful. If the decryption is successful, it obtains the first key and enters step S17; if the decryption fails, it indicates that the first public key has expired and enters step S15; Step S15: The edge computing box sends a first key acquisition request carrying the first authentication key to the monitoring server. The monitoring server parses the first key acquisition request to obtain the first authentication key, determines whether it matches the first authentication key stored locally in the monitoring server. If it matches, it sends the latest first public key to the edge computing box and enters step S16; if it does not match, the process ends; Step S16: The edge computing box decrypts the second key by using the received first public key to obtain the first key; Step S17: The edge computing box decrypts the authorized image set by using the first key to obtain several authorized face images.
2. The security monitoring method based on edge computing according to claim 1, characterized in that: The specific content of step S20 includes: Step S21: Each camera captures the latest face image in real time and uploads each latest face image to the FTP server in real time; Step S22: The FTP server presets a second key update period and a second authentication key, creates a pair of second public key and second private key based on the second key update period and the first encryption algorithm, and sends the second public key and the second authentication key to the edge computing box; Step S23: The FTP server randomly generates a third key based on the second encryption algorithm, encrypts the stored latest face image by using the third key to obtain the latest face image set, and encrypts the third key by using the second private key to obtain a fourth key; Step S24: The edge computing box listens in real time through the FTP reading method to check whether the number of the latest face images stored on the FTP server has increased. If so, it sends a request to obtain the latest face images to the FTP server and proceeds to Step S25; if not, it continues to listen. Step S25: Based on the received request to obtain the latest face images, the FTP server sends the encrypted set of the latest face images and the fourth key to the edge computing box. Step S26: The edge computing box decrypts the fourth key using the received second public key and determines whether the decryption is successful. If the decryption is successful, it obtains the third key and proceeds to Step S29; if the decryption fails, indicating that the second public key has expired, it proceeds to Step S27. Step S27: The edge computing box sends a request to obtain the second key carrying the second authentication key to the FTP server. The FTP server parses the request to obtain the second authentication key and determines whether it matches the second authentication key stored locally on the FTP server. If they match, it sends the latest second public key to the edge computing box and proceeds to Step S28; if they do not match, the process ends. Step S28: The edge computing box decrypts the fourth key using the received second public key to obtain the third key. Step S29: The edge computing box decrypts the set of the latest face images using the third key to obtain a number of the latest face images.
3. The security monitoring method based on edge computing according to claim 1, characterized in that: The specific content of Step S30 includes: Step S31: The edge computing box presets a similarity threshold, extracts the first face feature values of each latest face image in the set of the latest face images using a face algorithm, and extracts the second face feature values of each authorized face image in the set of authorized face images using a face algorithm. Step S32: The edge computing box traverses and calculates the similarity between each first face feature value and the second face feature value, and determines whether the similarity is greater than the similarity threshold. If so, it generates a verification result indicating that there are no strangers; if not, it generates a verification result indicating that there are strangers.
4. The security monitoring method based on edge computing according to claim 1, characterized in that: The specific content of Step S40 includes: Step S41: The edge computing box parses the verification result. If the verification result indicates that there are strangers, it proceeds to Step S42; if the verification result indicates that there are no strangers, the process ends. Step S42: The edge computing box randomly generates a fifth key based on a second encryption algorithm, encrypts the verification result and the corresponding latest face image using the fifth key to obtain an encrypted data packet, encrypts the fifth key using the first public key to obtain a sixth key, and uploads the encrypted data packet and the sixth key to the monitoring server. Step S43: The monitoring server decrypts the sixth key using the first private key to obtain the fifth key, and then decrypts the encrypted data packet using the fifth key to obtain the verification result and the corresponding latest face image. Step S44: The monitoring server pushes a security alert to the associated monitoring terminal in real time based on the verification result and the camera information carried by the latest face image.
5. A security monitoring system based on edge computing, characterized in that: It includes the following modules: An authorized image set acquisition module, configured to enable the edge computing box to acquire an encrypted authorized image set from the monitoring server and decrypt it; A latest face image set acquisition module, configured to enable the edge computing box to acquire a real-time captured and encrypted latest face image set from the FTP server, and decrypt the latest face image set; A latest face image set verification module, configured to enable the edge computing box to verify the latest face image set based on a face algorithm by using the authorized image set, and generate a verification result; A security alarm module, configured to enable the edge computing box to encrypt the verification result and upload it to the monitoring server for security alarm; The authorized image set acquisition module specifically includes: A monitoring server key creation unit, configured to enable the monitoring server to preset a first key update period and a first authentication key, create a pair of a first public key and a first private key based on the first key update period and a first encryption algorithm, and send the first public key and the first authentication key to the edge computing box; An authorized image set encryption unit, configured to enable the monitoring server to randomly generate a first key based on a second encryption algorithm, encrypt a pre-stored authorized image set by using the first key, and encrypt the first key by using the first private key to obtain a second key; An authorized image set and key sending unit, configured to enable the monitoring server to send the encrypted authorized image set and the second key to the edge computing box after receiving an authorized image set acquisition request sent by the edge computing box; A second key decryption unit, configured to enable the edge computing box to decrypt the second key by using the received first public key, determine whether the decryption is successful, if the decryption is successful, obtain the first key, and enter an authorized image set decryption unit; if the decryption fails, it indicates that the first public key has expired, and enter a first key acquisition request sending unit; A first key acquisition request sending unit, configured to enable the edge computing box to send a first key acquisition request carrying the first authentication key to the monitoring server, the monitoring server parses the first key acquisition request to obtain the first authentication key, determines whether it matches the first authentication key stored locally in the monitoring server, if it matches, sends the latest first public key to the edge computing box, and enters the second key decryption unit; if it does not match, the process ends; A second key decryption unit, configured to enable the edge computing box to decrypt the second key by using the received first public key to obtain the first key; An authorized image set decryption unit, configured to enable the edge computing box to decrypt the authorized image set by using the first key to obtain a plurality of authorized face images.
6. The security monitoring system based on edge computing according to claim 5, wherein: The latest face image set acquisition module specifically includes: A latest face image capture unit, configured to enable each camera to capture a latest face image in real time, and upload each latest face image to the FTP server in real time; An FTP server key creation unit, configured to enable the FTP server to preset a second key update period and a second authentication key, create a pair of a second public key and a second private key based on the second key update period and a first encryption algorithm, and send the second public key and the second authentication key to the edge computing box; The latest face image encryption unit is used for the FTP server to randomly generate a third key based on the second encryption algorithm, encrypt the stored latest face images with the third key to obtain a set of latest face images, and encrypt the third key with the second private key to obtain a fourth key; The latest face image acquisition request sending unit is used for the edge computing box to monitor in real time whether the number of the latest face images stored in the FTP server increases by reading the FTP method. If so, it sends a latest face image acquisition request to the FTP server and enters the latest face image set and key sending unit; if not, it continues to monitor; The latest face image set and key sending unit is used for the FTP server to send the encrypted latest face image set and the fourth key to the edge computing box based on the received latest face image acquisition request; The fourth key decryption unit is used for the edge computing box to decrypt the fourth key with the received second public key and determine whether the decryption is successful. If the decryption is successful, it obtains the third key and enters the latest face image set decryption unit; if the decryption fails, it indicates that the second public key has expired and enters the second key acquisition request sending unit; The second key acquisition request sending unit is used for the edge computing box to send a second key acquisition request carrying the second authentication key to the FTP server. The FTP server parses the second key acquisition request to obtain the second authentication key, and determines whether it matches the second authentication key stored locally in the FTP server. If it matches, it sends the latest second public key to the edge computing box and enters the fourth key secondary decryption unit; if it does not match, the process ends; The fourth key secondary decryption unit is used for the edge computing box to decrypt the fourth key with the received second public key to obtain the third key; The latest face image set decryption unit is used for the edge computing box to decrypt the latest face image set with the third key to obtain a number of latest face images.
7. The security monitoring system based on edge computing according to claim 5, characterized in that: The latest face image set verification module specifically includes: The face feature value calculation unit is used for the edge computing box to preset a similarity threshold, extract the first face feature values of the latest face images in the latest face image set by using a face algorithm, and extract the second face feature values of the authorized face images in the authorized image set by using a face algorithm; The face feature value comparison unit is used for the edge computing box to traverse and calculate the similarity between each first face feature value and the second face feature value, and determine whether the similarity is greater than the similarity threshold. If so, it generates a verification result that there are no strangers; if not, it generates a verification result that there are strangers.
8. The security monitoring system based on edge computing according to claim 5, wherein: The security warning module specifically includes: The verification result parsing unit is used for the edge computing box to parse the verification result. If the verification result is that there are strangers, it enters the data encryption and upload unit; if the verification result is that there are no strangers, the process ends; The verification data encryption and upload unit is used for the edge computing box to randomly generate a fifth key based on the second encryption algorithm, encrypt the verification result and the corresponding latest face image with the fifth key to obtain an encrypted data packet, encrypt the fifth key with the first public key to obtain a sixth key, and upload the encrypted data packet and the sixth key to the monitoring server; The verification data decryption unit is used for the monitoring server to decrypt the sixth key with the first private key to obtain the fifth key, and then decrypt the encrypted data packet with the fifth key to obtain the verification result and the corresponding latest face image; The alarm push unit is used for the monitoring server to push security alarms to the associated monitoring terminals in real time based on the verification result and the camera information carried by the latest face image.
Citation Information
Patent Citations
Intelligent attendance management and interaction method and system
CN110675518A
Face verification method and face verification system
CN112307875A