Face Recognition Method, System and Medium Based on Security Enhancement
By introducing a security enhancement system into the face recognition system, encrypted communication technology is used to solve the problem of facial data being leaked or tampered during communication, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202210531473.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-13
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-05-13
AI Technical Summary
Existing facial recognition technology is susceptible to attacks during communication, resulting in facial data leakage or tampering.
The security enhancement system is adopted to encrypt communication through the offline communication interface between the main control module and the security enhancement module. The main control module sends identity information and face images to the security enhancement module according to different encryption policies, authenticates and recognizes, and executes the control policy corresponding to the identification results.
It effectively improves the security and reliability of communication, ensures the security of facial data and recognition results during transmission, and prevents leakage or tampering.
Smart Images

Figure CN114786185B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to the field of face recognition technology, and particularly relates to a face recognition method, system and medium based on security enhancement. Background Art
[0002] Face recognition technology is increasingly widely used in various industry scenarios, including precision advertising, attendance checking, access control, mobile payment, etc. Taking face payment as an example, face recognition related algorithms and face image data are easily vulnerable to external malicious attacks in the ordinary operating system of existing payment terminals, resulting in the leakage or tampering of face data. Summary of the Invention
[0003] In view of the above defects or deficiencies in the prior art, it is desirable to provide a face recognition method, system and medium based on security enhancement, which can ensure that data will not be leaked or tampered with during the transmission process by encrypting during the communication process.
[0004] In a first aspect, an embodiment of the present application provides a face recognition method based on a security enhancement system. The security enhancement system includes a main control module and a security enhancement module, and the main control module and the security enhancement module communicate through an offline communication interface. The method includes:
[0005] The main control module sends the identity information to the security enhancement module according to a first encryption policy, so that the security enhancement module authenticates the identity of the main control module;
[0006] After the identity authentication of the main control module is passed, the main control module sends the collected face image to the security enhancement module according to a second encryption policy, so that the security enhancement module recognizes according to the face image and generates a recognition result;
[0007] The main control module receives the recognition result returned by the security enhancement module according to the second encryption policy and executes the control policy corresponding to the recognition result.
[0008] In some embodiments, the first encryption policy includes an asymmetric encryption algorithm.
[0009] In some embodiments, the second encryption policy includes a symmetric encryption algorithm.
[0010] In some embodiments, the main control module sending the identity information to the security enhancement module according to the first encryption policy includes:
[0011] The main control module sends a request to the security enhancement module to obtain the first encryption policy. The security enhancement module generates an asymmetric key pair for the first encryption policy based on the request according to a first preset rule, and sends the asymmetric public key to the main control module;
[0012] The main control module encrypts the identity information using the asymmetric public key and sends the encrypted identity information to the security enhancement module, so that the security enhancement module authenticates the identity of the main control module.
[0013] In some embodiments, after the identity authentication of the main control module is passed, the main control module sends the collected face image to the security enhancement module according to a second encryption policy, including:
[0014] The main control module receives the symmetric key sent by the security enhancement module. The symmetric key is a symmetric key for the second encryption policy generated by the security enhancement module according to a second preset rule after verifying the identity of the main control module;
[0015] The main control module encrypts the collected face image using the symmetric key and sends it to the security enhancement module.
[0016] In some embodiments, the security enhancement module encrypts the symmetric key using the asymmetric private key and sends it to the main control module.
[0017] In some embodiments, the main control module and the security enhancement module communicate using a private protocol, and the main control module and the security enhancement module adopt a question-and-answer communication mode.
[0018] In some embodiments, the security enhancement module is a system-on-chip, and the logic of face recognition for the security enhancement module is defined by FPGA.
[0019] In a second aspect, an embodiment of the present application provides a security enhancement system, including a main control module and a security enhancement module, and the main control module and the security enhancement module communicate through an offline communication interface
[0020] The main control module is used to send the identity information to the security enhancement module according to a first encryption policy, and after the identity authentication of the main control module is passed, send the collected face image to the security enhancement module according to a second encryption policy, and execute the control policy corresponding to the recognition result;
[0021] The security enhancement module is used to authenticate the identity of the main control module and generate a recognition result according to the face image.
[0022] In some embodiments, the security enhancement module is a system-on-chip, and the logic of the security enhancement module for face recognition is defined by an FPGA.
[0023] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in the embodiments of the present application is implemented.
[0024] The face recognition method based on a security enhancement system proposed in the embodiments of the present application effectively improves the security and reliability in the communication process of an offline system by enabling encrypted transmission of the communication between the main control module for collecting face images and the security enhancement module for recognizing face images inside the security enhancement system, and performs encrypted communication of face images after the security enhancement module authenticates the main control module, which can further ensure the security of the face recognition result.
[0025] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Other features, objectives, and advantages of the present application will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings:
[0027] Figure 1 The structural schematic diagram of the security enhancement system provided by the embodiments of the present application is shown;
[0028] Figure 2 The flowchart of the face recognition method based on the security enhancement system provided by an embodiment of the present application is shown;
[0029] Figure 3 The flowchart of the face recognition method based on the security enhancement system provided by another embodiment of the present application is shown
[0030] Figure 4 The signaling interaction diagram of the face recognition method based on the security enhancement system provided by an embodiment of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the sake of description, only the parts related to the invention are shown in the drawings.
[0032] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The information involved in the present application, including but not limited to face information, is information fully authorized by the user, and the collection, use, and processing of the above information need to comply with the relevant laws and standards of the corresponding countries and regions. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0033] For the structure of the security enhancement system proposed in the present application, refer to Figure 1 . Figure 1 Fig. shows a schematic structural diagram of the security enhancement system provided by an embodiment of the present application.
[0034] As Figure 1 shown, the security enhancement system 100 includes: a main control module 101 and a security enhancement module 102, and the main control module 101 and the security enhancement module 102 communicate through an offline communication interface 103.
[0035] Among them, the offline communication interface includes but is not limited to a USB interface, a Type-C interface, a bus interface, etc.
[0036] The main control module 101 is used to collect the face image to be recognized, and transmit the face image to be recognized or receive the recognition result of the face image by the security enhancement module 102 through encrypted communication with the security enhancement module 102.
[0037] The security enhancement module 102 is built with an image feature library 1021 that cannot be directly accessed from the outside. The image feature library is used to store offline face feature data. The security enhancement module 102 is used to provide and store the key for encrypted communication with the main control module 101, and after receiving the face image to be recognized sent by the main control module 101, recognize the face image by accessing the built-in image feature library to obtain the recognition result, and return the recognition result to the main control module 101 according to the second encryption policy, so that the main control module 101 executes the control policy corresponding to the recognition result.
[0038] Among them, the main control module 101 can also be connected to a power supply module 104 and a camera 105. The power supply module 104 is used to supply power to the main control module 101, and the camera 105 is used to collect the face image to be recognized.
[0039] In a feasible embodiment, the security enhancement module 102 can be a System on Chip (SoC). The logic for face recognition in the security enhancement module 102 is defined by a Field Programmable Gate Array (FPGA). The low-latency streaming processing capability of the FPGA is effectively utilized, which effectively improves the efficiency of face recognition. At the same time, the independent computing ability of the FPGA is used to implement security protection for the stored face feature data, reducing the risk of being attacked and leaked.
[0040] Please refer to Figure 2 , Figure 2 which shows a flowchart of a face recognition method based on a security enhancement system provided by an embodiment of the present application.
[0041] As Figure 2 shown, the face recognition method based on the security enhancement system includes the following steps:
[0042] Step 201, the main control module sends the identity information to the security enhancement module according to the first encryption policy, so that the security enhancement module authenticates the main control module.
[0043] Step 202, after the authentication of the main control module is passed, the main control module sends the collected face image to the security enhancement module according to the second encryption policy, so that the security enhancement module performs recognition based on the face image and generates a recognition result.
[0044] Step 203, the main control module receives the recognition result returned by the security enhancement module according to the second encryption policy and executes the control policy corresponding to the recognition result.
[0045] Among them, the first encryption policy and the second encryption policy can be the same or different. Optionally, the confidentiality level of the second encryption policy can be lower than that of the first encryption policy to reduce the parsing time of the face image data and the recognition result, and improve the overall face recognition efficiency of the system.
[0046] In one or more embodiments, the control policy corresponding to the recognition result can be related to the application scenario. For example, when the application scenario is access control, if the recognition result is a match, the main control module controls the access control to open; if the recognition result is a non-match, the main control module controls the access control to close. When the application scenario is mobile payment, if the recognition result is a match, the main control module executes the payment request; if the recognition result is a non-match, the main control module prompts to re-collect the face image or exit the mobile payment, etc.
[0047] Specifically, in the embodiments of the present application, encrypted information is used for data transmission between the main control module and the security enhancement module. That is, the main control module sends an authentication to the security enhancement module according to the first encryption policy to protect the identity information of the main control module through the first encryption policy, preventing the identity information of the main control module from being leaked or tampered with. After the authentication of the main control module is passed, the main control module then sends the collected face image to the security enhancement module according to the second encryption policy to ensure the reliability of the face image transmission process and reduce the possibility of face image data leakage or tampering. Finally, after the security enhancement module completes the recognition of the face image, it also sends the recognition result to the main control module according to the second encryption policy to ensure the security of the recognition result during the transmission process and effectively prevent the recognition result from being leaked or tampered with.
[0048] Thus, the face recognition method based on the security enhancement system proposed in the embodiments of the present application effectively improves the security and reliability in the communication process of the offline system by enabling encrypted transmission of the communication between the main control module for collecting face images and the security enhancement module for recognizing face images within the security enhancement system, and performs encrypted communication of face images after the security enhancement module authenticates the main control module, which can further ensure the security of the face recognition result.
[0049] In one or more embodiments, the first encryption policy includes an asymmetric encryption algorithm. Optionally, the asymmetric encryption algorithm may be RSA-1024.
[0050] In one or more embodiments, the second encryption policy includes a symmetric encryption algorithm. Optionally, the symmetric encryption algorithm may be AES-128.
[0051] Further, as Figure 3 shown, the main control module sending the identity information to the security enhancement module according to the first encryption policy includes:
[0052] Step 2011, the main control module sends a request to obtain the first encryption policy to the security enhancement module, and the security enhancement module generates an asymmetric key pair for the first encryption policy based on the request according to the first preset rule and sends the asymmetric public key to the main control module.
[0053] Among them, the first preset rule may be a random number rule, that is, an asymmetric key pair for the first encryption policy is generated according to a random number.
[0054] It should be noted that the asymmetric key includes a public key and a private key, that is, an asymmetric public key and an asymmetric private key. In the embodiments of the present application, the security enhancement module generates and publishes the asymmetric public key to facilitate the main control module to encrypt the identity information using the asymmetric public key according to the access requirements.
[0055] In step 2012, the main control module encrypts the identity information using an asymmetric public key and sends the encrypted identity information to the security enhancement module so that the security enhancement module can authenticate the main control module.
[0056] It should be understood that after receiving the identity information encrypted by the asymmetric public key, the security enhancement module decrypts it using the asymmetric private key stored in itself to obtain the identity information of the main control module and verifies the identity information of the main control module.
[0057] Thus, in this application, the identity information of the main control module is encrypted using an asymmetric key pair, which can effectively prevent the leakage or tampering of transmitted data during the identity verification process.
[0058] Further, as Figure 3 shown, after the identity verification of the main control module is passed, the main control module sends the captured face image to the security enhancement module according to the second encryption strategy, including:
[0059] In step 2021, the main control module receives the symmetric key sent by the security enhancement module. The symmetric key is the symmetric key for the second encryption strategy generated by the security enhancement module according to the second preset rule after verifying the identity of the main control module.
[0060] Preferably, the security enhancement module encrypts the symmetric key using the asymmetric private key and sends it to the main control module.
[0061] Among them, the symmetric key is the key used to encrypt the face image. That is to say, in order to further improve the key security of the symmetric key, the security enhancement module uses a more complex and difficult-to-decrypt asymmetric key to authenticate the main control module and transmit the symmetric key, thereby effectively improving the key security of the symmetric key used to encrypt the face image. Moreover, using the symmetric key to encrypt the face image can effectively improve the decryption efficiency of the security enhancement module for the face image, and then improve the speed of face recognition of the system, avoiding affecting the user experience due to excessive decryption time.
[0062] In step 2022, the main control module encrypts the captured face image using the symmetric key and sends it to the security enhancement module.
[0063] Thus, in this application, encrypted communication is used during the transmission of the face image, effectively improving the transmission security. At the same time, the cross-use of asymmetric keys and symmetric keys further increases the difficulty of data decryption by attackers and improves the security of face data.
[0064] Specifically, as Figure 4 shown, the face recognition method based on the security enhancement system includes the following steps:
[0065] The S401 main control module sends a key request to the security enhancement module.
[0066] In S402, the security enhancement module randomly generates an asymmetric key pair according to the request.
[0067] In S403, the security enhancement module sends the asymmetric public key to the main control module.
[0068] In S404, the main control module encrypts the identity information according to the asymmetric public key.
[0069] In S405, the main control module sends the encrypted identity information to the security enhancement module.
[0070] In S406, the security enhancement module decrypts the identity information using the asymmetric private key to obtain the identity information of the main control module.
[0071] In S407, the security enhancement module verifies the identity information of the main control module.
[0072] In S408, after the identity verification of the main control module passes, the security enhancement module generates a symmetric key.
[0073] Optionally, after the identity verification of the main control module fails, the security enhancement module exits the program.
[0074] In S409, the security enhancement module encrypts the symmetric key using the asymmetric private key and sends it to the main control module.
[0075] In S410, the main control module receives and decrypts the symmetric key using the asymmetric public key.
[0076] In S411, the main control module captures a face image.
[0077] In S412, the main control module encrypts the face image using the symmetric key and sends it to the security enhancement module.
[0078] In S413, the security enhancement module receives and decrypts the face image using the symmetric key.
[0079] In S414, the security enhancement module recognizes the face image to obtain a recognition result.
[0080] In S415, the security enhancement module encrypts the recognition result using the symmetric key and sends it to the main control module.
[0081] In S416, the main control module receives and decrypts the recognition result using the symmetric key.
[0082] In S417, the main control module executes the control strategy corresponding to the recognition result.
[0083] In one or more embodiments, in step S411, the main control module may further extract features from the face image, and then encrypt and send the face features to the security enhancement module in step S412, thereby effectively reducing the data processing volume of the security enhancement module. That is, the security enhancement module can perform image recognition and judgment only through the FPGA without performing image feature extraction processing, making full use of the fast computing power of the FPGA in the security enhancement module and improving the overall recognition efficiency of the system.
[0084] In one or more embodiments, the main control module and the security enhancement module communicate using a private protocol, and the main control module and the security enhancement module adopt a question-and-answer communication mode.
[0085] Specifically, the protocol format is as follows:
[0086] {
[0087] “sequence”:xxxxxxxxxxx, / * Randomly generated packet sequence number * /
[0088] “deviceid”:xxxxxxxxxxx, / * Edge gateway ID * /
[0089] “command”:”xxxxxxx”, / * Command type * /
[0090] “payload”:{…}
[0091] }
[0092] The payload area of the response frame must have a “response” field to indicate the response result:
[0093] {
[0094] “sequence”:xxxxxxxxxxx, / * Randomly generated packet sequence number * /
[0095] “deviceid”:xxxxxxxxxxx, / * Edge gateway ID * /
[0096] “command”:”xxxxxxx”, / * Command type * /
[0097] “payload”:{
[0098] “response”:”ok” / * Command execution result * /
[0099] }
[0100] }
[0101] It should be understood that the private protocol can be a protocol adapted by the manufacturer for the security enhancement system, so that the manufacturer can communicate with the security enhancement system through the private protocol, and then manage, upgrade, etc. the security enhancement system.
[0102] The face recognition method based on the security enhancement system proposed in the embodiments of the present application effectively improves the security and reliability in the communication process of the offline system by enabling encrypted transmission in the communication between the main control module for collecting face images and the security enhancement module for recognizing face images inside the security enhancement system, and performs encrypted communication of face images after the security enhancement module authenticates the main control module, which can further ensure the security of the face recognition result.
[0103] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operation instructions of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the foregoing module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two connected blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operation instructions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0104] The above description is only for the preferred embodiments of the present application and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in the present application.
Claims
1. A face recognition method based on a security enhancement system, characterized in that, the security enhancement system includes a main control module and a security enhancement module, the main control module and the security enhancement module communicate through an off-line communication interface, and the method includes: the main control module sends the identity information to the security enhancement module according to a first encryption policy, so that the security enhancement module authenticates the identity of the main control module; after the identity authentication of the main control module is passed, the main control module sends the collected face image to the security enhancement module according to a second encryption policy, so that the security enhancement module performs recognition based on the face image and generates a recognition result; the main control module receives the recognition result returned by the security enhancement module according to the second encryption policy and executes the control policy corresponding to the recognition result; the first encryption policy includes an asymmetric encryption algorithm, and the second encryption policy includes a symmetric encryption algorithm. Among them, after the identity authentication of the main control module is passed, the main control module sends the collected face image to the security enhancement module according to the second encryption policy, including: the security enhancement module encrypts the symmetric key with the asymmetric private key and sends it to the main control module; the main control module receives the symmetric key sent by the security enhancement module, and the symmetric key is a symmetric key generated by the security enhancement module according to a second preset rule for the second encryption policy after verifying the identity of the main control module; the main control module encrypts the collected face image with the symmetric key and sends it to the security enhancement module; the main control module sends the identity information to the security enhancement module according to the first encryption policy, including: the main control module sends a request to the security enhancement module to obtain the first encryption policy, and the security enhancement module generates an asymmetric key pair for the first encryption policy according to a first preset rule based on the request and sends the asymmetric public key to the main control module; the main control module encrypts the identity information with the asymmetric public key and sends the encrypted identity information to the security enhancement module, so that the security enhancement module authenticates the identity of the main control module; wherein, the acquisition of the face image and the face image are both fully authorized.
2. The method according to claim 1, characterized in that, the main control module and the security enhancement module communicate using a private protocol, and the main control module and the security enhancement module adopt a question-and-answer communication mode.
3. The method according to claim 1, characterized in that, the security enhancement module is a system-on-chip, and the logic of face recognition by the security enhancement module is defined through an FPGA.
4. A security enhancement system, characterized in that, adopts the face recognition method based on the security enhancement system according to any one of claims 1-3, includes a main control module and a security enhancement module, and the main control module and the security enhancement module communicate through an off-line communication interface; The master control module is used to send the identity information to the security enhancement module according to the first encryption policy, and after the identity authentication of the master control module is passed, send the collected face image to the security enhancement module according to the second encryption policy, and execute the control policy corresponding to the recognition result; The security enhancement module is used to authenticate the master control module and generate a recognition result according to the face image; The master control module sending the identity information to the security enhancement module according to the first encryption policy includes: The master control module sends a request to the security enhancement module to obtain the first encryption policy, and the security enhancement module generates an asymmetric key pair for the first encryption policy based on the request according to a first preset rule, and sends the asymmetric public key to the master control module; The master control module encrypts the identity information using the asymmetric public key and sends the encrypted identity information to the security enhancement module, so that the security enhancement module authenticates the master control module.
5. The system according to claim 4, wherein, The security enhancement module is a system-on-chip, and the logic of face recognition by the security enhancement module is defined through an FPGA.
6. A computer-readable storage medium, on which a computer program is stored, wherein, When the program is executed by a processor, it implements the face recognition method based on a security enhancement system as described in any one of claims 1-3.
Citation Information
Patent Citations
Access control system based on face identification and access control method
CN109903433A