Identity authentication method based on gravity features
By measuring the gravity characteristics of equipment in real time using a quantum gravimeter and comparing them with geographical location, the reliability problem of cross-regional identity authentication is solved, and the security of network access and the monitoring capabilities of equipment transportation are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA
- Filing Date
- 2022-10-10
- Publication Date
- 2026-05-29
AI Technical Summary
Existing informatics and biological identity authentication methods are unreliable in cross-regional authentication, especially when facing AI face-swapping technology and cyberattacks, making it difficult to effectively prevent identity impersonation.
A high-sensitivity quantum gravimeter is used to measure the gravity characteristics of the environment in which the device is located in real time, and the data is uploaded to the network administrator along with the geographical location for comparison. Identity authentication is then performed by establishing a database that corresponds gravity characteristics to geographical locations.
It improves the reliability of remote identity authentication, prevents devices from impersonating others to access the network, enhances the security of communication network access, and provides monitoring and protection for the transportation of important equipment.
Smart Images

Figure CN115694919B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the interdisciplinary field of quantum precision measurement, sensing protection and information security. Specifically, it refers to a method for authenticating devices that only operate in specific areas or locations by measuring gravity characteristics using a quantum gravimeter, analyzing gravity characteristics based on prior data to determine geographical location, and authenticating the identity of devices that only operate in specific areas or locations. Background Technology
[0002] Identity authentication systems are a crucial component of information security systems, primarily employing both informatics (login passwords, account passwords, etc.) and biometrics (facial recognition, iris recognition, fingerprint recognition, etc.). In theory, informatics-based authentication can be completed anytime, anywhere, using any network environment or login platform. Biometrics, on the other hand, require the installation of equipment such as facial recognition cameras or fingerprint scanners at the authentication initiator's location to complete remote, off-site identity verification.
[0003] Currently, the necessary conditions for reliable identity authentication using widely adopted information technology methods are that "the server storing passwords has not been compromised and the user's password has not been known to any third party." If these conditions are not met, attackers can impersonate someone and use the correct password to obtain information that should be exclusively accessible to the person initiating the authentication. A typical application scenario is that an attacker cracks the victim's email account and password, logs into the victim's email from a location abroad, and evades network security software screening through methods such as URL spoofing. While facial recognition can prevent such impersonation to some extent, with the continuous advancement of AI face-swapping technology, remote identity authentication still carries certain risks. Summary of the Invention
[0004] To address the aforementioned shortcomings, the technical problem this invention aims to solve is how to highly integrate a high-sensitivity quantum gravimeter with devices requiring authentication, measure the gravity characteristics of the device's environment in real time, and compile them into complex gravity characteristic signals; when a remote device initiates authentication, it should provide its location coordinates and upload the gravity characteristic signals; the network administrator verifies the location coordinates by checking the gravity characteristic signals against the gravity field database, thus confirming that the authentication initiator is indeed in a controlled, desired area.
[0005] To address the aforementioned shortcomings, the present invention aims to provide an identity authentication method based on gravity characteristics. This method involves precisely measuring the gravity field of a controlled or desired geographical location of a large communication network terminal, establishing a database with a one-to-one correspondence between desired geographical locations and gravity characteristics. A gravimeter is integrated with the device to be authenticated, and the gravity characteristics of the surrounding environment are measured in real time and uploaded along with the declared geographical location. The network administrator or identity authentication verifier extracts the gravity field corresponding to the declared geographical location from the database, matches and compares it with the uploaded gravity characteristic signal, and verifies whether the geographical location declared by the identity authentication initiator is true and accurate, determining whether the initiator is at the correct location.
[0006] Preferably, communication devices with unknown geographical locations request network access, enter a password according to the standard procedure, and pass verification.
[0007] Preferably, the device to be authenticated declares its own geographic coordinates (N, E) and uploads them together with the gravity characteristic signal measured by the quantum gravimeter tightly coupled and integrated with the network access device.
[0008] Preferably, the above method specifically includes the following steps:
[0009] S1. Establish a gravity field database for the controlled area. Collect gravity features from all possible geographical locations of the communication network that the devices may access. Establish a database that corresponds one-to-one between geographical location coordinates and gravity features. The collection process requires the use of a high-precision quantum gravimeter. The collected information should be as rich and comprehensive as possible.
[0010] S2. Devices applying for identity verification provide a geographical location declaration and gravity characteristic signal. When a mobile device applies to access the communication network from a certain location, it needs to submit its geographical location and upload the environmental gravity characteristic signal measured by a quantum gravimeter that is tightly coupled and integrated with the mobile device and whose data is tamper-proof.
[0011] S3. Complete gravity-based identity authentication. Taking a communication network as an example, the network administrator needs to input the geographical location declaration and gravity feature signal into the database for comparison and verification. Successful verification means that the geographical location declaration is true and valid. Then, the geographical location is compared with the communication network management requirements. If the geographical location is within the controlled area, the device's identity verification is passed; otherwise, the device is refused to proceed to the next step.
[0012] Preferably, the data uploaded in S2 can be either locally decoded quantum gravity field distribution data or undecoded quantum gravity field sensing signals.
[0013] Preferably, the above-mentioned tight coupling integration rather than embedding is because quantum gravimeters cannot be miniaturized and integrated at this stage.
[0014] Preferably, the gateway inputs data into the server, which stores gravity field data for different geographical coordinates. The gateway verifies the correctness of the device's geographical location based on the geographical coordinate declaration and gravity characteristic signals.
[0015] Preferably, the server determines the security level of the geographical location of the device. If the location is within the expected range, the verification passes; otherwise, the verification fails.
[0016] This invention provides a transportation protection method based on gravity feature-based identity authentication, comprising:
[0017] Step 1: Place the core equipment into the enclosed transport device and input the gravity field of the target location before starting the transport.
[0018] Step 2: During transportation, the quantum gravimeter continuously measures the gravity characteristics of the environment and compares them with preset gravity characteristics. If the comparison fails, it is determined that the core equipment has not yet been transported to the designated location.
[0019] Step 3: When the gravity characteristics measured by the quantum gravimeter are consistent with the preset values, the enclosed transport device is unlocked. At this time, the transport personnel can open the enclosed transport device and take out the core equipment by entering a password.
[0020] The present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method.
[0021] First, this invention proposes an identity authentication method based on gravity features, which is an important supplement to existing identity authentication methods in the field of information security. It is conducive to building an efficient identity verification system that integrates informatics, physics and biology, and improves the ability of information platforms to resist impersonation attacks.
[0022] Secondly, the gravity feature signal described in this invention will be highly bound to the geographical location as a "gravity field pattern", which can effectively verify the geographical location of the network access device and greatly improve the security of network access and use.
[0023] Finally, this invention can also serve as an important protective measure, providing process monitoring and assurance for the escort and delivery of critical equipment, and has broad application prospects in various fields such as banking, government, and commerce. Attached Figure Description
[0024] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments of the present invention will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 A schematic diagram of an embodiment of the gravity-based identity authentication method of the present invention is shown;
[0026] Figure 2 A schematic flowchart of the gravity-based identity authentication method of the present invention is shown;
[0027] Figure 3 A schematic diagram of another embodiment of the gravity-based identity authentication method of the present invention is shown. Detailed Implementation
[0028] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only configured to explain the present invention and are not configured to limit the present invention. For those skilled in the art, the present invention can be practiced without some of these specific details. The following description of the embodiments is merely intended to provide a better understanding of the present invention by illustrating examples of the invention.
[0029] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0030] like Figure 1 As shown, the present invention provides an embodiment of a non-recognizable identity authentication system based on stress-luminescent thin films, comprising:
[0031] S101. Establishment of a gravity field database: Perform precise gravity field measurements on the controlled (desired) geographical locations of large communication network terminals and establish a database that corresponds one-to-one with the desired geographical location and gravity characteristics.
[0032] S102. Upload of gravity feature signal of identity authentication initiator: Highly integrate the high-sensitivity gravimeter with the device that needs to verify identity, measure the gravity feature of the environment in real time and upload it together with the geographical location declaration;
[0033] S103. Gravity-based identity authentication: The network administrator or identity authentication verifier extracts the gravity field corresponding to the declared geographical location from the database, matches and compares it with the uploaded gravity feature signal, verifies whether the geographical location declared by the identity authentication initiator is true and accurate, and determines whether it appears at the correct point.
[0034] like Figure 2 As shown in the figure, this embodiment illustrates the process of an identity authentication method based on gravity features. The implementation steps are as follows:
[0035] (1) Communication devices with unknown geographical locations request network access. They enter the password according to the standard procedure and pass the verification.
[0036] (2) The device that initiates identity authentication declares its own geographic coordinates (N, E), and at the same time, the quantum gravimeter tightly coupled and integrated with the network access device measures the gravity characteristic signal and uploads it together;
[0037] (3) The gateway inputs the data into the server, which stores gravity field data for different geographical coordinates. The gateway verifies the correct geographical location of the device based on the geographical coordinate declaration and gravity characteristic signal.
[0038] (4) The server assesses the security level of the device's geographical location. If the location is within expectations, the verification passes; otherwise, the verification fails. For example, a device accessing the network should provide gravity characteristic data of an office building in a certain district of a city in northern my country. However, the gravity characteristic data measured by the quantum gravimeter shows that it is located in a farmland in the suburbs of a city in another country. This behavior is judged as an impersonation attack.
[0039] This invention also provides a transportation protection method based on autonomous navigation identity authentication, used for the protection of core equipment during transportation. The implementation steps are as follows:
[0040] (1) Place the core equipment into a closed transport device (tightly coupled with a quantum gravimeter), and input the gravity field of the target location in advance before starting the transport;
[0041] (2) During transportation, the quantum gravimeter constantly measures the gravity characteristics of the environment and compares them with the preset gravity characteristics. If the comparison fails (i.e. the correlation rate between the two is lower than the threshold), it is determined that the core equipment has not been transported to the designated location.
[0042] (3) When the gravity characteristics measured by the quantum gravimeter are consistent with the preset values, the enclosed transport device is in the unlocked state. At this time, the transport personnel can open the enclosed transport device and take out the core equipment by entering a password.
[0043] like Figure 3 As shown, this embodiment also provides an identity authentication method based on gravity features, including:
[0044] S201. Establish a gravity field database for the controlled area. Taking a communication network as an example, gravity features should be collected from all possible geographical locations of all devices in the communication network. A database with one-to-one correspondence between geographical location coordinates and gravity features should be established. A high-precision quantum gravimeter should be used in the collection process, and the collected information should be as rich and comprehensive as possible.
[0045] S202. The device applying for identity verification provides a geographical location declaration and gravity characteristic signal. Taking a communication network as an example, a portable device applying to access a communication network from a certain location needs to submit its geographical location. At the same time, it uploads the environmental gravity characteristic signal measured by a quantum gravimeter that is tightly coupled and integrated with the portable device and whose data cannot be manually modified (the reason for tight coupling and integration rather than embedding is that quantum gravimeters cannot be miniaturized and integrated at present). The uploaded data can be quantum gravity field distribution data that has been locally interpreted or quantum gravity field sensing signal that has not been decoded.
[0046] S203. Complete gravity-based identity authentication. Taking a communication network as an example, the network administrator needs to input the geographical location declaration and gravity feature signal into the database for comparison and verification. Successful verification means that the geographical location declaration is true and valid. Then, the geographical location is compared with the communication network management requirements. If the geographical location is within the controlled area (i.e., the desired location), the device's identity verification is passed; otherwise, the device is refused to proceed to the next step.
[0047] This embodiment also provides a gravity-based identity authentication method. A high-sensitivity quantum gravimeter is embedded in a large device that needs to verify identity. The device measures the gravity characteristics of its environment in real time and compiles them into complex gravity characteristic signals. When a remote device initiates identity authentication, in addition to entering a password, it also needs to upload the gravity characteristic signal. The network administrator or identity verification examiner responsible for identity verification, in addition to verifying the password, also needs to compare and verify the uploaded gravity characteristic signal with an existing gravity field database to confirm the true location of the remote device initiating identity authentication. This prevents devices that steal passwords or are in unexpected locations from impersonating the user to access networks with high security requirements or obtain information with high security levels.
[0048] In some embodiments, the quantum gravimeter accurately measures the magnitude of gravitational acceleration. The measurement mechanism is based on quantum properties. The measurement accuracy and sensitivity can break through the classical bottleneck and have device-level measurement capabilities (i.e., covering whole-machine servo functions such as drift compensation). It can be, but is not limited to, cold atom gravimeters, etc. The composition and parameter indicators of the quantum gravimeter system are not limited, and the tight coupling integration method between the quantum gravimeter and the device to be authenticated is not limited.
[0049] In some embodiments, gravity characteristic signals can be measured and modeled using a quantum gravimeter and an inertial navigation system.
[0050] In some embodiments, the measurement method needs to meet several conditions, including but not limited to moving within a small range to form a gravitational acceleration distribution, being able to overcome the drift effect of the gravitational force of other objects on the measurement of gravitational acceleration, the gravitational acceleration being relatively stable over a long period of time, the absence of various extreme interference conditions such as geological changes, the specific content and data format of the gravity characteristic signal are not limited, and it is not limited whether the uploaded gravity characteristic signal is locally interpreted by the quantum gravimeter.
[0051] In some embodiments, the party being verified uploads a geographical location claim and gravity feature signal. The verifier compares the gravity data of the corresponding geographical location in the database to determine whether the geographical location claim is true and valid, and at the same time verifies whether the claimed geographical location is in a controlled area and whether it meets the usage requirements.
[0052] In some embodiments, during network access authentication in a communication network, the controlled area refers to the desired location for device access, including but not limited to fixed network ports and fixed wireless communication base stations. During the secure transport of core equipment, compliance with usage requirements means that transport personnel and core equipment are always isolated during transport, and transport personnel cannot access or operate the core equipment before it reaches its destination. Any method that uses gravity characteristic signals for geographic location analysis and for identity authentication in the field of information security falls within the scope of this invention.
[0053] Compared with the prior art, the present invention has the following advantages:
[0054] First, this invention proposes an identity authentication method based on gravity features, which is an important supplement to existing identity authentication methods in the field of information security. It is conducive to building an efficient identity verification system that integrates informatics, physics and biology, and improves the ability of information platforms to resist impersonation attacks.
[0055] Secondly, the gravity feature signal described in this invention will be highly bound to the geographical location as a "gravity field pattern", which can effectively verify the geographical location of the network access device and greatly improve the security of network access and use.
[0056] Finally, this invention can also serve as an important protective measure, providing process monitoring and assurance for the escort and delivery of critical equipment, and has broad application prospects in various fields such as banking, government, and commerce.
[0057] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0058] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0059] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0060] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0061] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0062] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1The steps of the function specified in one or more boxes.
[0063] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0064] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0065] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0066] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0067] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0068] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. An identity authentication method based on gravity features, which performs precise gravity field measurement on the controlled or desired geographical location of a large communication network terminal and establishes a database that corresponds one-to-one with the desired geographical location and gravity features; Integrate the gravimeter with the device to be authenticated, measure the gravity characteristics of the environment in real time, and upload them along with the geolocation claim; The network administrator or identity verification verifier extracts the gravity field corresponding to the declared geographical location from the database, matches and compares it with the uploaded gravity feature signal, verifies whether the geographical location declared by the identity verification initiator is true and accurate, and determines whether it appears at the correct point. The device to be verified declares its own geographical coordinates (N, E) and uploads the gravity feature signal measured by the quantum gravimeter tightly coupled and integrated with the network access device. Specifically, the following steps are included: S1. Establish a gravity field database for the controlled area. Collect gravity features from all possible geographical locations of the communication network that the devices may access. Establish a database that corresponds one-to-one between geographical location coordinates and gravity features. The collection process requires the use of a high-precision quantum gravimeter. The collected information should be rich and comprehensive. S2. Devices applying for identity verification provide a geographical location declaration and gravity characteristic signal. When a mobile device applies to access the communication network from a certain location, it needs to submit its geographical location and upload the environmental gravity characteristic signal measured by a quantum gravimeter that is tightly coupled and integrated with the mobile device and whose data is tamper-proof. S3. Complete gravity-based identity authentication. Taking a communication network as an example, the network administrator needs to input the geographical location declaration and gravity feature signal into the database for comparison and verification. Successful verification means that the geographical location declaration is true and valid. Then, the geographical location is compared with the communication network management requirements. If the geographical location is within the controlled area, the device's identity verification is passed; otherwise, the device is refused to proceed to the next step.
2. The identity authentication method based on gravity features according to claim 1, characterized in that, A communication device with an unknown geographical location requests network access. It enters a password according to the standard procedure and passes the verification.
3. The identity authentication method based on gravity features according to claim 1, characterized in that, The data uploaded by S2 is either locally decoded quantum gravity field distribution data or undecoded quantum gravity field sensing signals.
4. The identity authentication method based on gravity features according to claim 1, characterized in that, The gateway inputs data into the server, which stores gravity field data for different geographical coordinates. The gateway verifies the correctness of the device's geographical location based on the geographical coordinate declaration and gravity characteristic signals.
5. The identity authentication method based on gravity features according to claim 1, characterized in that, The server assesses the security level of the device's geographical location. If the location is within the expected range, the verification passes; otherwise, the verification fails.
6. A computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the method of any one of claims 1-5.