Identity registration method, device and system, and identity authentication method, device and system

By utilizing the uniqueness of the scattering medium and combining optical and encoded information, the security of identity registration and authentication is improved, solving the problem that traditional identity authentication information is easily cloned and providing a highly secure identity authentication method.

CN116471027BActive Publication Date: 2026-03-27SHENZHEN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-04
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In traditional identity authentication methods, user authentication information is easily cloned, posing a significant risk to information security.

Method used

By determining the optical information associated with the registered user, coded information is generated and sent to the optical modulator for modulation. Feedback optical information is received, and the uniqueness of the scattering medium is used to match the user's identity. The scattering medium serves as an uncopyable authentication basis.

Benefits of technology

It improves the security of user information, prevents authentication information from being cloned, enhances the security and unforgeability of identity authentication, and does not infringe on personal privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116471027B_ABST
    Figure CN116471027B_ABST
Patent Text Reader

Abstract

The application relates to an identity registration method, an identity registration device, an identity registration system, an identity authentication method, an identity authentication device, an identity authentication system, computer equipment, a storage medium and a computer program product. The identity registration method comprises the following steps: determining optical information associated with a registration user; generating coding information according to the optical information and sending the coding information to a light modulator; receiving feedback optical information; and determining identity information of the registration user based on the coding information if the feedback optical information matches the optical information. The registration method utilizes the feature that the complex internal structure of a scattering medium cannot be cloned, and can make the user information safer. The identity authentication method comprises the following steps: determining coding information according to identity information of a registration user to be authenticated, and sending the coding information to a light modulator; receiving feedback optical information; and performing identity authentication according to the feedback optical information and preset optical information. The identity authentication method does not appear misauthentication, and is safer.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information technology, and in particular, to an identity registration method, an identity registration device, an identity registration system, an identity authentication method, an identity authentication device, an identity authentication system, a computer device, a storage medium, and a computer program product. BACKGROUND

[0002] Identity authentication is the "access control" of a system and is the first line of defense for system security. When a user performs identity registration, authentication information for authenticating user identity information is bound to the user identity information. The authentication information is unique to the user, such as a password, an IC (Integrated Circuit Card) card, or a digital signature. When the user performs identity authentication, the user identity information is authenticated through the authentication information unique to the user to verify the legality of the user accessing system resources.

[0003] However, the user authentication information in the traditional method has the risk of being cloned, and thus the security of the user information still has a large security risk. SUMMARY

[0004] Therefore, it is necessary to provide an identity registration method, an identity registration device, an identity authentication method, an identity authentication device, an identity authentication system, a computer device, a storage medium, and a computer program product that can improve the security of user information.

[0005] In a first aspect, the present application provides an identity registration method. The identity registration method comprises:

[0006] determining optical information associated with a registered user;

[0007] generating encoding information according to the optical information, and sending the encoding information to a light modulator; the light modulator modulates an incident light field according to the encoding information to obtain a target incident wave front;

[0008] receiving feedback optical information; the feedback optical information is information generated on a receiving device after the target incident wave front passes through a scattering medium; the scattering medium is matched one-to-one with the registered user;

[0009] if the feedback optical information matches the optical information, determining identity information of the registered user based on the encoding information.

[0010] In one embodiment, the optical information includes pattern information and / or spectral information.

[0011] In one embodiment, after the feedback optical information is received, the method further comprises:

[0012] updating the coded information according to the optical information and the feedback optical information if the feedback optical information does not match the optical information;

[0013] returning to performing the step of sending the coded information to an optical modulator.

[0014] In a second aspect, the present application provides an identity registration system. The identity registration system comprises a controller, an optical modulator and a receiving device connected to the controller, wherein the controller is configured to perform the identity registration method.

[0015] In one embodiment, the receiving device comprises a beam splitter, an image receiving device and a spectrum detecting device, wherein the image receiving device and the spectrum detecting device are connected to the controller, the beam splitter is configured to split the received optical signal and transmit the optical signal to the image receiving device and the spectrum detecting device respectively, and the optical signal is a signal of the target incident wave front after passing through a scattering medium.

[0016] In a third aspect, the present application provides an identity registration apparatus. The identity registration apparatus comprises:

[0017] an association module configured to determine optical information associated with a registered user;

[0018] an encoding module configured to generate coded information according to the optical information and send the coded information to an optical modulator, wherein the optical modulator modulates an incident light field according to the coded information to obtain a target incident wave front;

[0019] a receiving module configured to receive feedback optical information, wherein the feedback optical information is information generated on a receiving device after the target incident wave front passes through a scattering medium, and the scattering medium is matched with the registered user one by one;

[0020] a registration module configured to determine identity information of the registered user based on the coded information if the feedback optical information matches the optical information.

[0021] In a fourth aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the identity registration method when executing the computer program.

[0022] In a fifth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program implements the steps of the identity registration method when executed by a processor.

[0023] In a sixth aspect, the present application also provides a computer program product. The computer program product comprises a computer program which, when executed by a processor, implements the steps of the identity registration method described above.

[0024] The identity registration method, the identity registration device, the identity registration system, the computer device, the storage medium and the computer program product described above, in the identity registration process, first determine optical information associated with a registered user; generate encoding information according to the optical information, and send the encoding information to an optical modulator; the optical modulator modulates an incident light field according to the encoding information to obtain a target incident wave front; receive feedback optical information; the feedback optical information is information generated on a receiving device after the target incident wave front passes through a scattering medium; the scattering medium is matched with the registered user one by one; if the feedback optical information matches the optical information, determine the identity information of the registered user based on the encoding information. After the registration is completed, the scattering medium matched with the registered user is kept by the user as the authentication basis when the user's identity is authenticated. Since the complex internal structure of the scattering medium cannot be copied, it cannot be cloned, so that the security level of the user information is higher.

[0025] In a seventh aspect, the present application provides an identity authentication method. The identity authentication method comprises:

[0026] determining encoding information according to the identity information of a registered user of the identity to be authenticated, and sending the encoding information to an optical modulator; the optical modulator modulates an incident light field according to the encoding information to obtain a target incident wave front;

[0027] receiving feedback optical information; the feedback optical information is information generated on a receiving device after the target incident wave front passes through a scattering medium; the scattering medium is matched with the registered user one by one;

[0028] performing identity authentication according to the feedback optical information and preset optical information; the preset optical information is optical information associated with the registered user of the identity to be authenticated.

[0029] In one embodiment, the feedback optical information comprises feedback pattern information and feedback spectrum information, the preset optical information comprises preset pattern information and preset spectrum information, and the performing identity authentication according to the feedback optical information and the preset optical information comprises:

[0030] if the feedback pattern information matches the preset pattern information and the feedback spectrum information matches the preset spectrum information, it is determined that the identity authentication of the registered user is successful.

[0031] In an eighth aspect, the present application provides an identity authentication system. The identity authentication system comprises a controller, a light modulator connected to the controller, and a receiving device, wherein the controller is configured to perform identity authentication according to the identity authentication method described above.

[0032] In a ninth aspect, the present application provides an identity authentication device. The identity authentication device comprises:

[0033] a decoding module configured to determine coding information according to identity information of a registered user of a to-be-authenticated identity, and send the coding information to the light modulator; the light modulator is configured to modulate an incident light field according to the coding information to obtain a target incident wave front;

[0034] a feedback module configured to receive feedback optical information; the feedback optical information is information generated on the receiving device after the target incident wave front passes through a scattering medium; the scattering medium is matched with the registered user one by one;

[0035] an authentication module configured to perform identity authentication according to the feedback optical information and preset optical information; the preset optical information is optical information associated with the registered user of the to-be-authenticated identity.

[0036] In a tenth aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the identity authentication method described above when executing the computer program.

[0037] In an eleventh aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program implements the steps of the identity authentication method described above when executed by a processor.

[0038] In a twelfth aspect, the present application further provides a computer program product. The computer program product comprises a computer program, and the computer program implements the steps of the identity authentication method described above when executed by a processor.

[0039] The identity authentication method, the identity authentication device, the identity authentication system, the computer device, the storage medium, and the computer program product have the characteristic that the scattering medium is not reproducible. In the process of identity authentication, only the registered user holding the matched scattering medium can complete the authentication. Therefore, the identity authentication method described above has higher security and improves the security of user information. BRIEF DESCRIPTION OF DRAWINGS

[0040] Figure 1 FIG. 1 is a diagram of an application environment of an identity registration method in an embodiment;

[0041] Figure 2Flowchart of the identity registration method in one embodiment;

[0042] Figure 3 Flowchart of the identity registration method in another embodiment;

[0043] Figure 4 Flowchart of the identity registration process in one embodiment;

[0044] Figure 5 Application environment diagram of the identity authentication method in one embodiment;

[0045] Figure 6 Flowchart of the identity authentication method in one embodiment;

[0046] Figure 7 Module diagram of the identity authentication system in one embodiment;

[0047] Figure 8 Module diagram of the identity authentication system in another embodiment;

[0048] Figure 9 Spectrum distribution and imaging information associated with a registered user in one embodiment;

[0049] Figure 10 Spectrum distribution and imaging information after wavefront shaping in one embodiment;

[0050] Figure 11 Spectrum distribution and imaging information obtained by authentication of an illegal user in one embodiment;

[0051] Figure 12 Structural block diagram of the identity registration device in one embodiment;

[0052] Figure 13 Structural block diagram of the identity registration device in another embodiment;

[0053] Figure 14 Structural block diagram of the identity authentication device in one embodiment;

[0054] Figure 15 Internal structure diagram of the computer device in one embodiment. DETAILED DESCRIPTION

[0055] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.

[0056] Identity authentication is the "access control" of user information system, and is the first line of defense to protect system security. It verifies the legality of user access to system resources through unique characteristic information of the user, such as password, IC card or biological characteristics, etc. The user information system includes a registration process and an authentication process when in use. The registration process is the process of binding the user identity information with the authentication information and storing the authentication information into the database. The authentication process is the process of converting the unknown user's identity information into the authentication information to be authenticated, and then matching it with the existing authentication information in the database to verify the legality of the user's identity. Whether it is a registration process or an authentication process, the core is the mutual authentication of identity information and authentication information. In order to improve the security of the identity authentication system, it is usually necessary to verify two or more authentication information at the same time, which is called double identity authentication or multiple identity authentication. Common double identity authentication strategies include "username + password" or "IC card + password", etc. However, both password and IC card have the risk of being cloned, which makes this identity authentication strategy have security risks. Traditional methods also include: first, the method of using a one-way hash function to construct a message authentication code. In this method, the process of calculating the message authentication code value (MAC value) needs to use a shared key. The shared key, as the legal user identity information, still has the security risk of being lost or cloned. Second, the method of generating a digital signature through RSA (a classic public key cryptography algorithm) to authenticate identity. In this method, the public key (used to verify the signature) can be public, but the private key used to generate the digital signature still has the security risk of being lost or cloned.

[0057] Based on the above technical problems, the present application provides an identity registration method related to user authentication, which cannot be cloned and can improve the security of user information.

[0058] The identity registration method provided by the embodiments of the present application can be applied to an identity registration system. In some embodiments, as shown in Figure 1 The identity registration system includes a controller 110, an optical modulator 120 connected with the controller 110, and a receiving device 130. The controller 110 determines optical information associated with a registered user, generates encoding information according to the optical information, and sends the encoding information to the optical modulator 120. The optical modulator 120 modulates the incident light field according to the encoding information to obtain a target incident wave front. The controller 110 receives feedback optical information, wherein the feedback optical information is information generated on the receiving device 130 after the target incident wave front passes through a scattering medium 200; the scattering medium 200 is matched with the registered user one by one. If the feedback optical information matches the optical information, the controller 110 determines the identity information of the registered user based on the encoding information. The controller 110 can be, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices, etc.

[0059] In one embodiment, as Figure 2As shown, an identity registration method is provided, and the method is applied to Figure 1 The controller in the method is taken as an example for illustration, and the method comprises the following steps 300-600.

[0060] Step 300, determining optical information associated with a registered user.

[0061] The registered user is a user to be registered, and the user to be registered can be a new user who has not been registered or an old user who has been registered and has a registration requirement again.

[0062] The optical information is preset information, which can be determined for each registered user, or all registered users use the same optical information, as long as each registered user corresponds to an optical information at the time of registration.

[0063] Step 400, generating encoding information according to the optical information, and sending the encoding information to a light modulator.

[0064] The light modulator receives the encoding information, modulates the incident light field according to the encoding information, and obtains a target incident wave front. The encoding information can be determined in combination with the type of light modulator selected.

[0065] In one embodiment, the encoding information includes target phase information, and the modulation unit on the spatial light modulator is modulated by the target phase information, the phase of the incident light is changed, and the target incident wave front can be obtained.

[0066] Step 500, receiving feedback optical information.

[0067] The feedback optical information is information generated on a receiving device after the target incident wave front passes through a scattering medium; the scattering medium is matched with the registered user one by one.

[0068] The scattering medium is a substance that can cause light scattering. The scattering medium has the following characteristics: 1. The unpredictability of the interaction process between coherent radiation and the scattering medium makes it difficult to accurately explore the internal structure of the scattering medium. 2. The manufacturing process of the scattering medium is also full of randomness. For example, when zinc oxide is used as raw material to make a scattering medium, the method used is to spray zinc oxide on a glass base, and the scattering medium made is full of randomly distributed micro-nano particles. According to the two characteristics of the scattering medium, it can be determined that it is actually impossible to copy two identical scattering media, so the scattering medium can be regarded as a physical unclonable function (Physical Unclonable Function, PUF).

[0069] Preferably, the scattering medium can comprise a multiple scattering medium, which is a substance capable of causing multiple scattering of light. Further, the number of multiple scattering media can be determined according to actual conditions, which is not limited in the embodiment.

[0070] In actual implementation, after the target incident wave front passes through the scattering medium, the target region is coherently enhanced, the characteristic pattern of the scattered light wave is focused on the receiving device, and the feedback optical signal is generated.

[0071] In one embodiment, the incident light field can be modulated by a wave front shaping technology, such as a global optimization wave front shaping technology based on spatial / frequency dual constraints. Through the optimization algorithm of the dual target constraints, the spatial modulation of the incident spectral signal is realized. Those skilled in the art can also use other methods for modulation, as long as the phase of the incident light can be changed by the modulated light modulator, so that the light waves of different incident channels are coherently enhanced in the target region after passing through the scattering medium, the characteristic pattern of the scattered light wave is focused on the receiving device, and the feedback optical information is formed.

[0072] Due to the uniqueness of the scattering medium, the encoded information generated in the modulation process is one-to-one associated with the scattering medium used in the optical path. Therefore, matching the scattering medium with the registered user can make the registered user and the encoded information obtained at present have a one-to-one association relationship.

[0073] In step 600, if the feedback optical information matches the optical information, the identity information of the registered user is determined based on the encoded information.

[0074] The feedback optical information matching the optical information can be consistent, or can satisfy a certain relationship, which is not limited in the embodiment. For convenience of description, the feedback optical information matching the optical information is described by taking the feedback optical information consistent with the optical information as an example.

[0075] When the feedback optical information is consistent with the optical information, the modulation process is ended, and the identity information of the registered user is determined based on the encoded information. Specifically, the encoded information can be used as a kind of identity information of the registered user, such as the account of the registered user; or the encoded information can be bound with other information of the user, etc., which can be set based on actual needs by those skilled in the art.

[0076] When the feedback optical information is consistent with the optical information, it indicates that the optical information associated with the registered user can be obtained according to the encoded information in the current modulation process and the scattering medium, so as to realize the association among the identity information of the registered user, the scattering medium and the optical information. In order to meet the needs of subsequent identity authentication, the scattering medium can be kept by the user or an authoritative agency for the purpose of ensuring the security of user information.

[0077] Further, the identity registration method and the identity registration system can be adapted by those skilled in the art according to actual needs. For example, the identity registration method can further include the steps of storing the identity information of the registered user, the encoding information and the associated optical information into a database, and giving the registered user corresponding permissions. The controller in the identity registration system can further include a registration request module, and the registration request module receives the registration request of the registered user. Correspondingly, the step 300 can further include the step of receiving the registration request of the registered user. This embodiment does not limit this.

[0078] The identity registration method described above first determines the optical information associated with the registered user, generates the encoding information according to the optical information, and sends the encoding information to the light modulator. The light modulator modulates the incident light field according to the encoding information to obtain the target incident wave front. The feedback optical information is generated on the receiving device after the target incident wave front passes through the scattering medium. The scattering medium is matched with the registered user one by one. If the feedback optical information matches the optical information, the identity information of the registered user is determined based on the encoding information. After the registration is completed, the scattering medium corresponding to the registered user is kept by the user as the authentication basis for user identity authentication. Since the complex internal structure of the scattering medium cannot be copied, it cannot be cloned, so that the security level of the user information is higher, and the user information security is improved. By using the user information obtained by the wave front encoding information on the light modulator and the scattering medium as the identity authentication information, a double identity authentication framework is constructed, and the security strength is further improved. In addition, since the identity registration system is an optoelectronic hybrid system including an optical path and an electrical circuit, the identity registration process is almost at the speed of light, and the registration process can be completed instantly.

[0079] It should be further pointed out that in the related art, in order to improve security, the system generally adopts the form of biometric (such as fingerprint, iris) authentication. Although the biometric greatly reduces the risk of cloning, the form of collecting biometric in the registration process infringes personal privacy, and the collected biometric information is easily misused to cause serious consequences.

[0080] The above embodiments of the present application ensure the information security of the registered user without infringing personal privacy, and due to the characteristics of the scattering medium, the internal structure information cannot be read, let alone misused illegally, which can ensure the information security of the user.

[0081] In actual implementation, the optical information can be set in combination with actual security level requirements. In one embodiment, the optical information includes pattern information, and the feedback optical information includes feedback pattern information. In the registration process, first, preset pattern information corresponding to the registered user is associated, then coding information is generated according to the preset pattern information, and the coding information is sent to the light modulator to modulate the incident light field to obtain a target incident wave front. After the target incident wave front passes through the scattering medium, feedback pattern information is generated on the receiving device. If the feedback pattern information matches the preset pattern information, the modulation is completed, and the identity information of the registered user is determined based on the coding information. Thus, the association among the registered user, the pattern information, the identity information, and the scattering medium is established, and the identity registration process is completed.

[0082] In another embodiment, the optical information includes spectrum information, and the feedback optical information includes feedback spectrum information. In the registration process, first, preset spectrum information corresponding to the registered user is associated, then coding information is generated according to the preset spectrum information, and the coding information is sent to the light modulator to modulate the incident light field to obtain a target incident wave front. After the target incident wave front passes through the scattering medium, feedback spectrum information is generated on the receiving device. If the feedback spectrum information matches the preset spectrum information, the modulation is completed, and the identity information of the registered user is determined based on the coding information.

[0083] In this embodiment, the spectrum information can include spectral line distribution information, such as the center position of a target characteristic spectral line. By establishing the association among the registered user, the spectrum information, the identity information, and the scattering medium, the identity registration process is completed.

[0084] In yet another embodiment, the optical information can include pattern information and spectrum information, and the feedback optical information includes feedback pattern information and feedback spectrum information. In the registration process, first, preset pattern information and spectrum information corresponding to the registered user are associated, then coding information is generated according to the preset pattern information and spectrum information, and the coding information is sent to the light modulator to modulate the incident light field to obtain a target incident wave front. After the target incident wave front passes through the scattering medium, feedback pattern information and feedback spectrum information are generated on the receiving device. If the feedback pattern information matches the preset pattern information and the feedback spectrum information matches the preset spectrum information, the modulation is completed, and the identity information of the registered user is determined based on the coding information.

[0085] Thus, by the dual association of the pattern information and the spectral information with the registered user, the authentication relationship between the scattering medium and the "spectrum information" and the "image information" is established by means of the framework of dual identity authentication. After the relationship is established, the encoding information of the spatial light modulator is saved in the computer, and the scattering medium is saved by the user like a key. The dual authentication process is in a series form, that is, even if the encoding information of the light modulator is illegally stolen by an attacker, the scattering medium held by the legal user can guarantee that the identity is not stolen, and the security strength is further improved.

[0086] In one embodiment, as shown in FIG. 5, after step 500, the identity registration method further includes step 510: judging whether the feedback optical information matches the optical information. Figure 3

[0087] Specifically, when the feedback optical information is consistent with the optical information, it is determined that the feedback optical information matches the optical information. If the optical information includes the pattern information and the spectral information, when the feedback pattern information is consistent with the pattern information and the feedback spectral information is consistent with the spectral information, it is determined that the feedback optical information matches the optical information.

[0088] Further, in one embodiment, if the feedback optical information does not match the optical information, step 520 is performed: updating the encoding information according to the optical information and the feedback optical information.

[0089] After receiving the feedback optical information, the encoding information is updated according to the optical information and the feedback optical information based on the feedback-optimized wavefront shaping technology. After the update, the updated encoding information is sent to the light modulator again, and the light modulator modulates again to obtain the updated target incident wavefront. The updated target incident wavefront passes through the multiple scattering media to generate the updated feedback optical information on the receiving device.

[0090] Specifically, please refer to Figure 4 , in Figure 4 ​In the illustrated embodiment, a broadband illumination field is generated, and the optical modulator is a spatial light modulator. The optical information includes target spectral lines and / or target patterns. The incident light field is modulated by the spatial light modulator to obtain the target incident wavefront. After passing through a multiple scattering medium, the target incident wavefront forms a spectral map and / or speckle pattern on the receiving device. If the spectral map and / or speckle pattern formed on the receiving device does not match the target spectral lines or target pattern in the preset optical information, wavefront shaping technology is used to re-modulate the incident light field to update the encoded information. The target incident wavefront is then updated based on the updated encoded information. If the updated spectral map and / or speckle pattern matches the target spectral lines or target pattern, the modulation process is complete. The optical information is used as the authentication information for the registered user, thereby establishing a connection between the user's identity information, the multiple scattering medium, and the optical information. During subsequent identity authentication, mutual verification of these three elements is required, resulting in a very high level of security.

[0091] In one embodiment, the receiving device may include a spectrometer and a monochrome camera. The NSGA-II multi-objective genetic optimization algorithm, with dual spatial and frequency domain constraints, is employed. Wavefront shaping technology is used to ensure that preset pattern information and target spectra appear on the receiving device at the output surface. Before fitness evaluation, a suitable objective function constraint iterative optimization algorithm needs to be selected. Simultaneously, the broadband spectral line distribution of the incident light field received by the spectrometer and the imaging information from the monochrome camera are used as feedback signals. That is, wavefront shaping needs to be subject to dual constraints in both the frequency and spatial domains, a process achieved using the NSGA-II algorithm. The registration process can use both frequency and spatial domain information as authentication information. The correlation coefficient between the target and the actual spectral distribution, and the ratio of the image plane focus area to the background light intensity of the monochrome camera, are used as objective functions to constrain the algorithm. Based on the above two points, the following two objective evaluation functions can be selected to evaluate the fitness levels of individuals in the pattern information and spectral information populations, respectively:

[0092]

[0093] In equation (1), f1 represents the correlation coefficient between the target and the actual spectral distribution, i represents the ordinal number of the wavelength component detected by the spectrometer, and I(λ) i ) and Ir i ( i The symbols ) represent the actual light intensity and the target light intensity detected by the spectrometer at the i-th wavelength component, respectively. Indicates averaging. and represents the average light intensity of all wavelength components of the authentication information and the target pattern, respectively, and m represents the number of target spectral lines. In equation (2), f2 represents the ratio of the light intensity of the image focal area to the background light intensity, I j and Ibg respectively represent the light intensity and background light intensity of the jth focus point on the image plane, and n represents the number of focus regions.

[0094] In this embodiment, the purpose of refining and improving the algorithm is to provide two authenticatable factors (spectrum, feature map), and through double authentication, the security performance of the system can be further improved.

[0095] In one embodiment, an identity authentication method is provided, which can be applied to an identity authentication system. In some embodiments, the identity authentication system can be as shown in Figure 5 The controller 610 generates coding information according to the identity information of the registered user of the identity to be authenticated, and sends the coding information to the light modulator 620; the light modulator 620 modulates the incident light field according to the coding information to obtain a target incident wave front; the controller 610 receives feedback optical information; the feedback optical information is information generated on the receiving device 630 after the target incident wave front passes through the scattering medium 200; the scattering medium 200 is matched with the registered user one-to-one; the controller 610 performs identity authentication according to the feedback optical information and the preset optical information; the preset optical information is optical information associated with the registered user of the identity to be authenticated.

[0096] It can be understood that in actual implementation, the identity authentication system and the identity registration system can be independently arranged, or can be the same system as shown in Figure 1 or Figure 5 When the identity authentication system and the identity registration system are the same system, the controller can be used to execute the identity registration method or the identity authentication method.

[0097] In one embodiment, as shown in Figure 6 , an identity registration method is provided, and the controller in Figure 5 is taken as an example for description. The identity authentication method includes steps 710-730.

[0098] Step 710, determining coding information according to the identity information of the registered user of the identity to be authenticated, and sending the coding information to the light modulator.

[0099] The light modulator modulates the incident light field according to the encoding information to obtain the target incident wave front. The identity information of the registered user is registered based on the above-mentioned embodiment of the identity registration method, so that when identity authentication is performed, the optical information associated with the identity information of the registered user stored in the database can be read first, and the encoding information can also be determined according to the identity information. The encoding information is the information used to modulate the incident light field in the identity registration process. After the encoding information is sent to the light modulator, the light modulator modulates the incident light field to obtain the same target incident wave front as in the identity registration process.

[0100] Step 720, receiving feedback optical information.

[0101] The feedback optical information is information generated on the receiving device after the target incident wave front passes through the scattering medium; the scattering medium is matched with the registered user one by one.

[0102] In the identity authentication process, the registered user whose identity is to be authenticated also needs to provide the scattering medium associated with the identity information. Due to the uniqueness of the scattering medium, the scattering medium provided by the user must be the scattering medium used in the identity registration process.

[0103] When the scattering medium is placed in the optical path, the target incident wave front passes through the scattering medium to generate feedback optical information on the receiving device.

[0104] Step 730, identity authentication according to the feedback optical information and the preset optical information.

[0105] The preset optical information is the optical information associated with the registered user whose identity is to be authenticated.

[0106] Specifically, it can be verified whether the feedback optical information and the preset optical information match. If the feedback optical information and the preset optical information match, it means that the user information, the scattering medium and the optical information are all associated with the registered user, and then the identity authentication of the registered user is successful. If the feedback optical information and the preset optical information do not match, it means that the user information does not belong to the registered user or the scattering medium does not belong to the registered user, regardless of which case, it is considered that the authentication fails.

[0107] The above identity authentication method, since the scattering medium can be regarded as a physically unclonable function, unlike the password stored in the computer or the key used in life, the scattering medium cannot be cloned even if it is stolen, and therefore the unclonability enhances the security of the identity authentication system. Meanwhile, the user information obtained through the wavefront coding information on the light modulator and the scattering medium are used as the associated basis for identity authentication together, a double identity authentication framework is constructed, and the security of the identity authentication system is further improved. In addition, the scattering medium as the identity authentication basis does not involve biological characteristics and does not infringe on personal privacy. Moreover, since the identity authentication system is an optoelectronic hybrid system, the identity authentication process is carried out at the speed of light, and the authentication process can be completed instantaneously.

[0108] In one embodiment, the feedback optical information includes feedback pattern information and feedback spectrum information, the preset optical information includes preset pattern information and preset spectrum information, and the identity authentication according to the feedback optical information and the preset optical information includes: if the feedback pattern information matches the preset pattern information and the feedback spectrum information matches the preset spectrum information, determining that the identity authentication of the registered user is successful.

[0109] In this embodiment, by simultaneously using the spectral line distribution information and the pattern imaging information of a wide spectrum as the feedback signal, the authentication is further doubly constrained, and the security of the identity authentication system can be further improved.

[0110] Taking the identity authentication system and the identity registration system as the same system as an example, the system shown in Figure 5 is taken as an example for description, and further, reference is made to Figure 7 , the receiving device 630 can include a beam splitter 631, an image receiving device 632 and a spectrum detection device 633. The image receiving device 632 and the spectrum detection device 633 are both connected to the controller 610 Figure 7 (not shown), and the beam splitter 631 is used to split the received optical signal and transmit the optical signal to the image receiving device 632 and the spectrum detection device 633 respectively; the optical signal is the signal of the target incident wavefront after passing through the scattering medium 200.

[0111] In actual implementation, the light modulator 620 can be a liquid crystal spatial light modulator, the image receiving device 632 can be a monochrome CCD (Charge Coupled Device), the spectrum detection device 633 can be a spectrometer, and the beam splitter 631 can be a half mirror. The incident light field can be a wide spectrum light source, such as natural light. According to actual conditions, the system can further include an incident light source, and the incident light field is generated by the incident light source.

[0112] Further, the receiving device 630 can further include an optical diaphragm 634 to form a preset fine bright line, so that the spectrometer can more accurately determine the wavelength of the light, and the preset fine bright line can be set in combination with the selection of the spectrometer.

[0113] It should be noted that the identity registration system can also be used for identity authentication, and the identity authentication process will be described below in combination with Figure 7 Briefly describe the identity registration and authentication process:

[0114] (1) Registration process. First, the user to be registered is randomly assigned or designated a scattering medium, which is placed in the optical path. The spectral line distribution on the spectrometer and the monochromatic CCD image forming information are pre-set as optical information for authentication. Then, the incident wavefront is modulated by the NSGA-II algorithm, so that the scattered light of the incident wavefront passing through the scattering medium presents a specific spectral line distribution on the spectrometer that matches the pre-set spectral line distribution; at the same time, the specific pattern information presented on the monochromatic camera matches the pre-set imaging information. After successfully establishing a corresponding relationship between the identity information obtained based on the encoding information on the spatial light modulator in the modulation stage and the optical information, the identity information and the scattering medium are handed over to the user (or an authoritative agency, etc.), and the registration is completed.

[0115] (2) Authentication process. When authenticating, the user only needs to place the associated scattering medium in the optical path, load the encoding information on the spatial light modulator according to the identity information, record the spectral line distribution of the spectrometer and the imaging information of the monochromatic camera, and compare them with the data in the database. If the two match, the user's identity authentication is passed, and if one of the spectral line distribution and the imaging information does not match, the user's identity will be considered illegal.

[0116] It should be noted that in actual implementation, the optical path structure of the identity authentication system and the identity registration system can also be adjusted based on the embodiments shown in Figure 7 , for example Figure 8 , in the optical path of the light scattered by the target incident wavefront after passing through the scattering medium 200, after being split by the half mirror 1, the light on the optical path where the CCD is located is sequentially provided with an optical diaphragm, a grating, and a converging lens. After passing through the converging lens, two light paths are formed. The first light path is sequentially provided with a mirror 1, a mirror 2, a light modulator 1, and a mirror 3. The second light path is provided with a light modulator 2. After converging by the half mirror 2, the light of the two light paths is incident to the CCD after passing through the scattering medium 210. The scattering medium 210 can also be a multiple scattering medium. In the process of identity registration and authentication, each registered user can be assigned two multiple scattering media (such as the scattering media 200 and 210), to further improve the security of the system.

[0117] It should be noted that when the identity authentication system and the identity registration system are independently set, the identity authentication system and the identity registration system can be set according to the above embodiments.

[0118] It should be further explained that the inventors simulated the dual identity authentication of the scattering medium based on the above embodiments during the research and development process. Specifically, after monochromatic coherent light propagates to the scattering medium, random scattering occurs, forming speckles similar to noise. Under the condition of broadband illumination, the detector receives the superposition of speckles formed by different wavelengths of light independently. Randomly select a point on the image plane to detect its spectrum, and the spectrum will contain each wavelength component, and the intensity value of each component is randomly distributed, which is similar to the distribution properties of speckles in the monochromatic illumination condition.

[0119] The simulation model of the interaction between the wide spectrum light and the scattering medium in wavefront shaping needs to consider two problems. First, the continuous wide spectrum light needs to be discretized into independent spectral components, and the wavelength interval Δλ between each component must be greater than or equal to the spectral correlation bandwidth of the scattering medium λ0, c and Δt are the center wavelength of the light source, the speed of light in vacuum, and the interaction time of light and scattering medium, respectively. Second, the phase modulation effect of the liquid crystal spatial light modulator is related to the wavelength. It is assumed that when the wavelength is λ0, the phase modulation range of the liquid crystal spatial light modulator is 0-2π, which is represented by the following formula:

[0120]

[0121] wherein, represents the phase of the liquid crystal spatial light modulator, d is the thickness of the liquid crystal spatial light modulator, r is the phase modulation level, and n(λ0) is the refractive index of the liquid crystal at a wavelength of λ0. For another wavelength, the modulation effect of the liquid crystal spatial light modulator on the phase will change with the wavelength:

[0122]

[0123] Substituting the Cauchy dispersion formula into the above formula gives:

[0124]

[0125] Since the correlation bandwidth of the scattering medium is usually in the nanometer range, the wavelength interval can be set to 3 nm. At the same time, the parameters in formula (5) are set to a=0.6985, b=8.125×10 4 nm 2 , c=8.292×10 5 nm 4 . Assuming that the authentication information of legal users A and user B is stored in the identity authentication database, the set authentication information (optical information including spectral distribution information and imaging information in the registration process) is as follows: Figure 9The shown (a) (b) is the authentication information of the legal user A, and (c) (d) is the authentication information of the legal user B. The spectral center wavelength of the user A is set to λ A = 530 nm, and the imaging information is a ten-character symbol at the center of the image plane. The spectral center wavelength of the user B is set to λ B = 470 nm, and the imaging information is a square symbol at the upper left region of the image plane. In the next step, the users bind the respective associated scattering media to the authentication information, and this process is realized by simultaneously taking the spectral distribution of the spectrometer and the imaging information on the monochromatic camera as feedback signals through the wavefront shaping technology. The wavefront shaping control result is as shown in Figure 10 Figure 10 The shown (a) (b) is the authentication information of the legal user A, and (c) (d) is the authentication information of the legal user B. The spectral center wavelength of the user A is set to λ

[0126] Further, the inventors also verified whether the user X holding the illegal any scattering medium can pass the identity authentication by using the phase distribution on the spatial light modulator of the user A and the user B, respectively. The result is as shown in Figure 11 The illegal user holds the scattering medium different from the legal user, and even if the spatial light modulator coding phase of the legal user is used, the corresponding spectral distribution and imaging information cannot be obtained, and it is difficult to pass the authentication of the optical identity authentication system. Therefore, this dual authentication mode through the user information and the scattering medium provides certain attack stability and security for the entire authentication system.

[0127] It should be understood that, although each step in the flowchart involved in each of the above-described embodiments is shown in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each of the above-described embodiments can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or stages or steps or stages in other steps.

[0128] Based on the same inventive concept, the embodiments of the present application also provide an identity registration device for implementing the above-mentioned identity registration method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, and therefore the specific limitations in one or more identity registration device embodiments provided below can refer to the limitations of the identity registration method described above, which will not be described here again.

[0129] In one embodiment, as Figure 12 ​As shown, an identity registration device is provided, including: an association module 810, an encoding module 820, a receiving module 830, and a registration module 840, wherein:

[0130] The association module 810 is used to determine the optical information associated with the registered user.

[0131] The encoding module 820 is used to generate encoded information based on optical information and send the encoded information to the optical modulator; the optical modulator modulates the incident light field according to the encoded information to obtain the target incident wavefront.

[0132] The receiving module 830 is used to receive feedback optical information; the feedback optical information is the information generated on the receiving device after the target incident wavefront passes through the scattering medium; the scattering medium is matched one-to-one with the registered user.

[0133] The registration module 840 is used to determine the identity information of the registered user based on the encoded information if the feedback optical information matches the optical information.

[0134] In one embodiment, such as Figure 13 As shown, the identity registration device also includes a feedback module 850, which is used to update the encoded information based on the optical information and the feedback optical information if the feedback optical information does not match the optical information, and then send the encoded information to the optical modulator.

[0135] Based on the same inventive concept, this application also provides an identity authentication device for implementing the aforementioned identity authentication method. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more identity authentication device embodiments provided below can be found in the limitations of the identity authentication method described above, and will not be repeated here.

[0136] In one embodiment, such as Figure 14 As shown, an identity authentication device is provided, including: a decoding module 910, a feedback module 920, and an authentication module 930, wherein:

[0137] The decoding module 910 is used to determine the encoding information based on the identity information of the registered user whose identity is to be authenticated, and send the encoding information to the optical modulator; the optical modulator modulates the incident light field according to the encoding information to obtain the target incident wavefront;

[0138] Feedback module 920 is used to receive feedback optical information; the feedback optical information is the information generated on the receiving device after the target incident wavefront passes through the scattering medium; the scattering medium is matched one-to-one with the registered user;

[0139] The authentication module 930 is configured to perform identity authentication according to the feedback optical information and preset optical information, wherein the preset optical information is optical information associated with a registered user whose identity is to be authenticated.

[0140] In one embodiment, the authentication module 930 is further configured to determine that the identity authentication of the registered user is successful if the feedback pattern information matches the preset pattern information and the feedback spectrum information matches the preset spectrum information.

[0141] The modules in the identity registration apparatus and the identity authentication apparatus described above can be implemented by software, hardware, or a combination thereof, in whole or in part. The modules described above can be embedded in or independent of a processor in a computer device in hardware form, or stored in a memory in a computer device in software form, so as to be invoked and executed by a processor to perform operations corresponding to the modules.

[0142] In one embodiment, a computer device is provided, which can be a server, and an internal structure diagram of the computer device can be as shown in Figure 15 The computer device includes a processor, a memory, an input / output interface (I / O), and a communication interface. The processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for running the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store user information, encoding information, optical information, and other related data. The input / output interface of the computer device is configured to exchange information between the processor and external devices. The communication interface of the computer device is configured to communicate with terminals outside through a network connection. The computer program is executed by the processor to implement an identity registration method or an identity authentication method.

[0143] Those skilled in the art can understand that Figure 15 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. A specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0144] In one embodiment, a computer device is also provided, which includes a memory and a processor. The memory stores a computer program, and the processor implements the steps in each of the identity registration method embodiments or the steps in each of the identity authentication method embodiments when executing the computer program.

[0145] In an embodiment, a computer readable storage medium is provided, and the computer readable storage medium has stored thereon a computer program which, when executed by a processor, implements the steps in each of the identity registration method embodiments or the steps in each of the identity authentication method embodiments.

[0146] In an embodiment, a computer program product is provided, and the computer program product includes a computer program which, when executed by a processor, implements the steps in each of the identity registration method embodiments or the steps in each of the identity authentication method embodiments.

[0147] It should be noted that the user-related information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the related data need to comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0148] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (Read-Only Memory, ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (Magnetoresistive Random Access Memory, MRAM), ferroelectric memory (Ferroelectric Random Access Memory, FRAM), phase change memory (Phase Change Memory, PCM), graphene memory, etc. Volatile memory can include random access memory (Random Access Memory, RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (Static Random Access Memory, SRAM) or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.

[0149] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.

[0150] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. An identity registration method, characterized by, The identity registration method comprises: determining optical information associated with the registered user; the optical information is preset information, and the optical information comprises pattern information and spectrum information; generating coding information according to the optical information, and sending the coding information to a light modulator; the light modulator modulates an incident light field according to the coding information by a double-target constraint optimization algorithm based on a global optimization wavefront shaping technology with double constraints in a spatial domain and a frequency domain, to obtain a target incident wavefront; receiving feedback optical information; the feedback optical information is coherent enhancement in a target region after the target incident wavefront passes through a scattering medium, to realize focusing of a characteristic pattern of scattered light waves on a receiving device, and to generate information on the receiving device for realizing double identity authentication; the scattering medium is matched with the registered user one by one, so that the coding information generated in the modulation process is associated with the scattering medium used in the optical path one by one; and the scattering medium is a physically unclonable function with an internal structure that cannot be replicated; if the feedback optical information matches the optical information, the modulation process is ended, and identity information of the registered user is determined based on the coding information; if the feedback optical information does not match the optical information, the coding information is updated according to the optical information and the feedback optical information based on a feedback-optimized wavefront shaping technology; and the step of sending the coding information to the light modulator is returned.

2. An identity authentication method characterized by, The identity authentication method comprises: determining coding information according to identity information of a registered user of a to-be-authenticated identity, and sending the coding information to a light modulator; the light modulator modulates an incident light field according to the coding information by a double-target constraint optimization algorithm based on a global optimization wavefront shaping technology with double constraints in a spatial domain and a frequency domain, to obtain a target incident wavefront; receiving feedback optical information; the feedback optical information is coherent enhancement in a target region after the target incident wavefront passes through a scattering medium, to realize focusing of a characteristic pattern of scattered light waves on a receiving device, and to generate information on the receiving device for realizing double identity authentication; the scattering medium is matched with the registered user one by one, so that the coding information generated in the modulation process is associated with the scattering medium used in the optical path one by one; and the scattering medium is a physically unclonable function with an internal structure that cannot be replicated; performing identity authentication according to the feedback optical information and preset optical information; the preset optical information is optical information associated with the registered user of the to-be-authenticated identity; and the preset optical information comprises pattern information and spectrum information.

3. The method of claim 2, wherein, The feedback optical information comprises feedback pattern information and feedback spectrum information, the preset optical information comprises preset pattern information and preset spectrum information, and the identity authentication according to the feedback optical information and the preset optical information comprises: if the feedback pattern information matches the preset pattern information, and the feedback spectrum information matches the preset spectrum information, it is determined that the identity authentication of the registered user is successful.

4. An identity registration system characterized by, The system comprises a controller, an optical modulator connected to the controller, and a receiving device, the controller being configured to perform identity registration according to the method of claim 1.

5. The system of claim 4, wherein, The receiving device comprises a beamsplitter, an image receiving device, and a spectrum detecting device, the image receiving device and the spectrum detecting device being connected to the controller, the beamsplitter being configured to split the received optical signal and transmit the split optical signal to the image receiving device and the spectrum detecting device, respectively; the optical signal being a signal of the target incident wavefront after passing through a scattering medium.

6. An identity authentication system characterized by comprising: The system comprises a controller, an optical modulator connected to the controller, and a receiving device, the controller being configured to perform identity authentication according to the method of claim 2 or 3.

7. An identity registration apparatus for implementing the identity registration method according to claim 1, characterized by The device comprises: an association module configured to determine optical information associated with a registered user; an encoding module configured to generate encoding information according to the optical information and send the encoding information to an optical modulator; the optical modulator modulates an incident light field according to the encoding information to obtain a target incident wavefront; a receiving module configured to receive feedback optical information; the feedback optical information being information generated on a receiving device after the target incident wavefront passes through a scattering medium; the scattering medium being matched with the registered user one-to-one; a registration module configured to determine identity information of the registered user based on the encoding information if the feedback optical information matches the optical information.

8. An identity authentication registration apparatus for implementing the identity registration method according to claim 4, characterized in that, The device comprises: a decoding module configured to determine encoding information according to identity information of a registered user whose identity is to be authenticated and send the encoding information to an optical modulator; the optical modulator modulates an incident light field according to the encoding information to obtain a target incident wavefront; a feedback module configured to receive feedback optical information; the feedback optical information being information generated on a receiving device after the target incident wavefront passes through a scattering medium; the scattering medium being matched with the registered user one-to-one; an authentication module configured to perform identity authentication according to the feedback optical information and preset optical information; the preset optical information being optical information associated with the registered user whose identity is to be authenticated.