Computer storage system access method, device, electronic device and storage medium
Verification through facial recognition technology solves the problem of frequent password input by users in computer storage systems, realizes data access without passwords, and improves user experience and data security.
Patent Information
- Application Number
- CN202411168449.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-08-23
AI Technical Summary
When an existing computer storage system accesses encrypted data, it is necessary to frequently enter a password or forget it, which is inconvenient to operate.
Through face recognition technology, the user's first verification image and the second verification image are obtained and the verification is performed. If the verification is passed, the key is obtained from the cloud platform to decrypt the data.
It realizes the operation of accessing encrypted data without the user entering a password, improving user experience and data security.
Smart Images

Figure CN119150376B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technologies, and more particularly to a method and apparatus for accessing a computer storage system, an electronic device, and a storage medium. Background Art
[0002] A computer storage system can store data. The computer storage system can store plaintext data and encrypted data. When a user needs to access the data, the user can verify their identity by entering a password and decrypt the data.
[0003] However, with this method, the user needs to frequently enter the password, or the user may forget the password when not using the encrypted data for a long time, which is very inconvenient to operate. Summary of the Invention
[0004] The present invention provides a method and apparatus for accessing a computer storage system, an electronic device, and a storage medium, which can more conveniently enable a user to access data in the computer storage system.
[0005] To solve the above technical problems, the present invention is implemented as follows:
[0006] In a first aspect, the present application provides a method for accessing a computer storage system, where the computer storage system stores encrypted data. The method includes: obtaining an access request for the encrypted data stored in the computer storage system, and obtaining a first verification image of the accessing user according to the access request. The first verification image includes: a first face image of the accessing user and a first background image corresponding to a camera component of the computer storage system; turning on the camera component corresponding to the computer storage system, and obtaining a second verification image of the accessing user. The second verification image includes a second face image of the accessing user and a second background image; verifying the accessing user according to the first verification image and the second verification image to obtain a first verification result; if it is determined that the verification passes according to the first verification result, obtaining a first key from a cloud platform to decrypt the encrypted data according to the first key.
[0007] Preferably, the method further includes: if it is determined that the verification fails according to the first verification result, outputting a liveness verification prompt, and turning on the camera component corresponding to the computer storage system to obtain a verification video of the accessing user. The liveness verification prompt includes one of opening the mouth, raising the head, lowering the head, and shaking the head left and right; the verification video includes a third face image of the accessing user; determining a second verification result according to whether the third face image of the accessing user in the verification video matches the first face image and whether the liveness verification of the accessing user passes; if it is determined that the verification passes according to the second verification result, obtaining a first key from a cloud platform to decrypt the encrypted data according to the first key.
[0008] Preferably, the method further includes: if the verification fails according to the second verification results, sending a verification instruction to the cloud platform so that the cloud platform sends a verification code to the reserved number of the accessing user; receiving the first hash value of the verification code sent by the cloud platform; obtaining the verification code input by the accessing user and performing hashing to obtain a second hash value; verifying according to the first hash value and the second hash value to determine a third verification result, and if it is determined that the verification passes according to the third verification result, obtaining a first key from the cloud platform to decrypt the encrypted data according to the first key.
[0009] Preferably, the verifying the accessing user according to the first verification image and the second verification image to obtain a first verification result includes: performing matching analysis on the first face image and the second face image to determine a first analysis result; performing matching analysis on the first background image and the second background image to determine a second analysis result; dividing the second background image into a first region corresponding to the face edge and a remaining second region; performing background difference analysis according to the first region and the second region to determine a third analysis result; determining the first verification result according to the first analysis result, the second analysis result, and the third analysis result.
[0010] Preferably, the performing background difference analysis according to the first region and the second region to determine a third analysis result includes: generating a plurality of analysis paths passing through the first region and the second region with the face as the starting direction, obtaining the pixel values of each pixel point in the analysis path, and determining the continuity of the change of the pixel values at the connection of the first region and the second region to determine a third analysis result; determining the background pixel difference according to the pixel values of the pixel points in the first region and the pixel values of the pixel points in the second region to determine a third analysis result; determining the background clarity difference according to the brightness values of the pixel points in the first region and the brightness values of the pixel points in the second region to determine a third analysis result.
[0011] Preferably, the method further includes: after it is determined that the verification passes according to the first verification result, performing background analysis according to the first background image and the second background image to determine background change information, where the background change information includes the addition or reduction of a target object in the background; when the target object is added or reduced in multiple background change information, updating the first background image according to the background change information.
[0012] Preferably, the first key includes a plurality of second keys, and the decrypting the encrypted data according to the first key includes: obtaining the encrypted data and a screening matrix corresponding to the encrypted data, where the screening matrix is used to screen out the target key corresponding to the encrypted data from a plurality of second keys; obtaining a plurality of second keys from the first key and performing screening using the screening matrix to screen out the target key from the second keys; decrypting the encrypted data according to the target key.
[0013] Second aspect, the present application provides a computer storage system access device. The computer storage system stores encrypted data. The device includes: an access request acquisition module, configured to acquire an access request for the encrypted data stored in the computer storage system, and acquire a first verification image of the access user according to the access request. The first verification image includes: a first face image of the access user and a first background image corresponding to the camera component of the computer storage system; a second image acquisition module, configured to activate the camera component corresponding to the computer storage system, and acquire a second verification image of the access user. The second verification image includes a second face image of the access user and a second background image; a second image verification module, configured to verify the access user according to the first verification image and the second verification image, and obtain a first verification result; an encrypted data decryption module, configured to, if it is determined that the verification is passed according to the first verification result, obtain a first key from the cloud platform, and decrypt the encrypted data according to the first key.
[0014] Third aspect, the present application provides an electronic device, including: a memory and at least one processor; the memory is configured to store computer execution instructions; the at least one processor is configured to execute the computer execution instructions stored in the memory, so that the at least one processor executes the method as described in the first aspect.
[0015] Fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method as described in the first aspect is implemented.
[0016] This application can be applied to the data management scenario of a computer storage system. The computer storage system can store encrypted data. Users can verify their identities through face recognition and decrypt the data for access. In addition to matching the user's face, this solution can also match the background of the accessing user's face and the background where the computer storage system is located, so as to determine whether someone else uses the user's photo to access the system, improving data security. Specifically, this solution can pre-enter the face images of authorized accessing users and the background images of the environment where the corresponding camera components of the computer storage system are located into the computer storage system. The background images do not contain faces. When a user accesses, an access request for the encrypted data stored in the computer storage system is obtained, and a first verification image of the accessing user is obtained according to the access request. The first verification image includes: a first face image of the accessing user and a first background image corresponding to the camera component of the computer storage system; the camera component corresponding to the computer storage system is turned on, and a second verification image of the accessing user is obtained. The second verification image includes a second face image of the accessing user and a second background image; then, the accessing user is face-verified and background-verified according to the first verification image and the second verification image to obtain a first verification result; if it is determined that the verification is passed according to the first verification result, a first key is obtained from the cloud platform to decrypt the encrypted data according to the first key. This solution can obtain the second verification image by taking pictures of the accessing user and perform verification according to the first verification image and the second verification image. Compared with the method of collecting multiple images of the accessing user or collecting the live video of the accessing user, this solution has less data processing volume, faster data processing speed, and can analyze the face matching degree and background matching degree, improving data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0018] Figure 1 is a schematic flowchart of a method for accessing a computer storage system according to an embodiment of the present application;
[0019] Figure 2 is a schematic structural diagram of an apparatus for accessing a computer storage system according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0021] This application can be applied to the data management scenario of a computer storage system. The computer storage system can store encrypted data. Users can verify their identities through face recognition and decrypt the data for access. In addition to matching the user's face, this solution can also match the background of the accessing user's face and the background where the computer storage system is located, so as to determine whether someone else uses the user's photo to access the system, improving the security of the data. Specifically, this solution can pre-enter the face images of authorized accessing users and the background images of the environment where the corresponding camera components of the computer storage system are located in the computer storage system. When a user accesses, an access request for the encrypted data stored in the computer storage system is obtained, and a first verification image of the accessing user is obtained according to the access request. The first verification image includes: a first face image of the accessing user and a first background image corresponding to the camera component of the computer storage system; the camera component corresponding to the computer storage system is turned on, and a second verification image of the accessing user is obtained. The second verification image includes a second face image of the accessing user and a second background image; then, the accessing user is verified for face and background based on the first verification image and the second verification image to obtain a first verification result; if it is determined that the verification passes according to the first verification result, a first key is obtained from the cloud platform to decrypt the encrypted data based on the first key. This solution can obtain the second verification image by taking pictures of the accessing user and perform verification based on the first verification image and the second verification image. Compared with the method of collecting multiple images of the accessing user or collecting the live video of the accessing user, this solution has less data processing volume, faster data processing speed, and can analyze the face matching degree and background matching degree, improving the security of the data.
[0022] Specifically, an embodiment of the present application provides a method for accessing a computer storage system. The computer storage system stores encrypted data, as Figure 1 shown, the method includes:
[0023] Step 102, obtain an access request for the encrypted data stored in the computer storage system, and obtain a first verification image of the accessing user according to the access request. The first verification image includes: a first face image of the accessing user and a first background image corresponding to the camera component of the computer storage system.
[0024] Step 104: Activate the camera component corresponding to the computer storage system and obtain a second verification image of the accessing user. The second verification image includes a second face image and a second background image of the accessing user.
[0025] Step 106: Verify the accessing user based on the first verification image and the second verification image to obtain a first verification result.
[0026] Step 108: If it is determined that the verification is passed based on the first verification result, obtain a first key from the cloud platform to decrypt the encrypted data based on the first key.
[0027] This application can be applied to the data management scenario of a computer storage system. The computer storage system can store encrypted data. Users can verify their identities through face recognition and decrypt the data for access. In addition to matching the user's face, this solution can also match the face background of the accessing user and the background where the computer storage system is located, so as to determine whether someone else uses the user's photo to access the system, improving the security of the data. Specifically, this solution can pre-enter the face image of the authorized accessing user and the background image of the environment where the camera component corresponding to the computer storage system is located (the background image does not contain a face) into the computer storage system. When a user accesses, obtain an access request for the encrypted data stored in the computer storage system, and obtain a first verification image of the accessing user based on the access request. The first verification image includes: a first face image of the accessing user and a first background image corresponding to the camera component of the computer storage system; activate the camera component corresponding to the computer storage system and obtain a second verification image of the accessing user. The second verification image includes a second face image and a second background image of the accessing user; then, verify the face and background of the accessing user based on the first verification image and the second verification image to obtain a first verification result; if it is determined that the verification is passed based on the first verification result, obtain a first key from the cloud platform to decrypt the encrypted data based on the first key. This solution can obtain the second verification image by taking pictures of the accessing user and perform verification based on the first verification image and the second verification image. Compared with the method of collecting multiple images of the accessing user or collecting the live video of the accessing user, this solution has less data processing volume, faster data processing speed, and can analyze the face matching degree and background matching degree, improving the security of the data.
[0028] In this solution, the encrypted data of the computer storage system is encrypted with the first key of the cloud platform (or called the key management platform), and the corresponding key can be stored in the cloud platform. When the computer storage system is accessed, obtain it from the cloud platform and decrypt it. Compared with the method of decrypting by the user entering a password, this solution does not require the user to enter a password, which is convenient to operate.
[0029] When the second verification image of the accessing user fails to be verified, the solution can also perform a liveness verification on the accessing user. Specifically, as an optional embodiment, the method further includes: if it is determined that the verification fails according to the first verification result, output a liveness verification prompt and activate the camera component corresponding to the computer storage system to obtain the verification video of the accessing user. The liveness verification prompt includes one of opening the mouth, raising the head, lowering the head, and shaking the head left and right; the verification video includes the third face image of the accessing user; determine the second verification result according to whether the third face image of the accessing user in the verification video matches the first face image and whether the liveness verification of the accessing user passes; if it is determined that the verification passes according to the second verification result, obtain the first key from the cloud platform to decrypt the encrypted data according to the first key.
[0030] If the face liveness verification also fails, the solution can also use the cloud platform to send a verification code to the user, and the user inputs the verification code on the device corresponding to the computer storage system for verification. Specifically, as an optional embodiment, the method further includes: if it is determined that the verification fails according to the second verification result, send a verification instruction to the cloud platform so that the cloud platform sends a verification code to the number reserved for the accessing user; receive the first hash value of the verification code sent by the cloud platform; obtain the verification code input by the accessing user and perform hashing to obtain the second hash value; perform verification according to the first hash value and the second hash value to determine the third verification result. If it is determined that the verification passes according to the third verification result, obtain the first key from the cloud platform to decrypt the encrypted data according to the first key. The cloud platform generates a verification code and sends it to the accessing user, and performs hashing on the verification code and then sends it to the device corresponding to the computer storage system (which can be called a computer, a client, etc.) to perform consistency verification according to the first hash value and the second hash value. The cloud platform interacts with the client with the hash value, not the original verification code, which improves the security of the data.
[0031] In addition to matching the user's face, this solution can also match the background of the face of the accessing user and the background where the computer storage system is located, so as to determine whether someone else uses the user's photo to access the system, improving data security. Specifically, as an optional embodiment, verifying the accessing user based on the first verification image and the second verification image to obtain a first verification result includes: performing a matching analysis on the first face image and the second face image to determine a first analysis result; performing a matching analysis on the first background image and the second background image to determine a second analysis result; dividing the second background image into a first region corresponding to the face edge and a remaining second region; performing a background difference analysis based on the first region and the second region to determine a third analysis result; and determining the first verification result based on the first analysis result, the second analysis result, and the third analysis result. This solution can divide the second background image into two regions. If the user uses a photo to access, there will be a difference between the background of the photo and the background of the client. This solution can divide the first region and the second region to analyze the difference to verify whether a photo is used for verification.
[0032] If a global analysis is performed on the second background image, the amount of data to be analyzed is large. Therefore, this solution can generate multiple analysis paths passing through the first region and the second region starting from the face, obtain the pixel values of each pixel point in the analysis path, and determine the continuity of the change of the pixel values at the connection between the first region and the second region. If the continuity is poor or there is a mutation, it can be determined that a photo is used for verification, and thus it can be determined that the verification fails. It can also be verified based on the pixel value difference and background clarity difference in the two regions. Specifically, as an optional embodiment, performing a background difference analysis based on the first region and the second region to determine a third analysis result includes: generating multiple analysis paths passing through the first region and the second region starting from the face, obtaining the pixel values of each pixel point in the analysis path, and determining the continuity of the change of the pixel values at the connection between the first region and the second region to determine the third analysis result; determining the background pixel difference based on the pixel values of the pixel points in the first region and the pixel values of the pixel points in the second region to determine the third analysis result; and determining the background clarity difference based on the brightness values of the pixel points in the first region and the brightness values of the pixel points in the second region to determine the third analysis result. If the focus of the camera component is on the background near the face (the background of the photo), there will be a large difference in the background clarity between the first region and the second region.
[0033] The background corresponding to the client may change. Therefore, this solution can record background change information and update the first background image when changes occur in multiple identifications. Specifically, as an optional embodiment, the method further includes: after determining that the verification is passed based on the first verification result, performing background analysis based on the first background image and the second background image to determine background change information, where the background change information includes the addition or reduction of a target object in the background; when the target object is added or reduced in multiple pieces of background change information, updating the first background image based on the background change information.
[0034] If only the key of the cloud platform is used to encrypt the data of the computer storage system, the data security is poor. Therefore, the first key requested by the client from the cloud platform may include multiple second keys. This solution can also generate a screening matrix, which can screen out the key corresponding to the data from multiple second keys to avoid data leakage. In addition, the screening matrix can also change the second key and use the changed second key for decryption. Specifically, as an optional embodiment, the first key includes multiple second keys, and decrypting the encrypted data according to the first key includes: obtaining the encrypted data and the screening matrix corresponding to the encrypted data, where the screening matrix is used to screen out the target key corresponding to the encrypted data from multiple second keys; obtaining multiple second keys from the first key and performing screening using the screening matrix to screen out the target key from the second keys; decrypting the encrypted data according to the target key.
[0035] Based on the above embodiments, an embodiment of the present application further provides a computer storage system access device. The computer storage system stores encrypted data, as Figure 2 shown, the device includes:
[0036] An access request acquisition module 202, configured to acquire an access request for the encrypted data stored in the computer storage system and acquire a first verification image of the access user according to the access request. The first verification image includes: a first face image of the access user and a first background image corresponding to the camera component of the computer storage system.
[0037] A second image acquisition module 204, configured to turn on the camera component corresponding to the computer storage system and acquire a second verification image of the access user. The second verification image includes a second face image of the access user and a second background image.
[0038] A second image verification module 206, configured to verify the access user according to the first verification image and the second verification image to obtain a first verification result.
[0039] An encrypted data decryption module 208, which is configured to obtain a first key from a cloud platform if it is determined that the verification is passed according to the first verification result, so as to decrypt the encrypted data according to the first key.
[0040] This application can be applied to the data management scenario of a computer storage system. The computer storage system can store encrypted data. Users can verify their identities by face recognition and decrypt the data for access. In addition to matching the user's face, this solution can also match the face background of the accessing user and the background where the computer storage system is located, so as to determine whether someone else uses the user's photo to access the system, improving the data security. Specifically, this solution can pre-enter the face images of authorized accessing users and the background images of the environment where the corresponding camera component of the computer storage system is located into the computer storage system. The background images do not contain faces. When a user accesses, an access request for the encrypted data stored in the computer storage system is obtained, and a first verification image of the accessing user is obtained according to the access request. The first verification image includes: a first face image of the accessing user and a first background image corresponding to the camera component of the computer storage system; the corresponding camera component of the computer storage system is turned on, and a second verification image of the accessing user is obtained. The second verification image includes a second face image of the accessing user and a second background image; then, the accessing user is verified for face and background according to the first verification image and the second verification image to obtain a first verification result; if it is determined that the verification is passed according to the first verification result, a first key is obtained from the cloud platform, so as to decrypt the encrypted data according to the first key. This solution can obtain the second verification image by taking pictures of the accessing user and perform verification according to the first verification image and the second verification image. Compared with the method of collecting multiple images of the accessing user or collecting the live video of the accessing user, this solution has less data processing volume, faster data processing speed, and can analyze the face matching degree and background matching degree, improving the data security.
[0041] Based on the above embodiments, the present application further provides an electronic device, including: a memory and at least one processor; the memory is used to store computer execution instructions; the at least one processor is used to execute the computer execution instructions stored in the memory, so that the at least one processor executes the method as described in the above embodiments.
[0042] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each process of the above-described method embodiment for processing data and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium includes, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0043] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0044] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0045] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0046] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1Steps of the functions specified in one or more boxes.
[0047] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0048] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0049] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transitory media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0050] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but also other elements not expressly listed, or elements that are inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.
[0051] Those skilled in the art will appreciate that embodiments of the present invention may be provided as a method, system, or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0052] The above are only embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various modifications and variations can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.
Claims
1. A method for accessing a computer storage system, characterized in that: The computer storage system stores encrypted data, and the method includes: Obtaining an access request to the encrypted data stored in the computer storage system, and obtaining a first verification image of the accessing user according to the access request, wherein the first verification image includes: a first face image of the accessing user and a first background image corresponding to the camera component of the computer storage system; Turning on the camera component corresponding to the computer storage system, and taking a picture of the accessing user to obtain a second verification image of the accessing user, the second verification image including a second face image of the accessing user and a second background image; Verifying the access user according to the first verification image and the second verification image to obtain a first verification result includes: Perform matching analysis on the first face image and the second face image to determine a first analysis result, Perform matching analysis on the first background image and the second background image to determine a second analysis result, The second background image is divided into a first area corresponding to the edge of the face and a remaining second area, Perform background difference analysis based on the first area and the second area to determine the third analysis result, Determining a first verification result according to the first analysis result, the second analysis result, and the third analysis result; If the verification is determined to be successful according to the first verification result, the first key is obtained from the cloud platform to decrypt the encrypted data according to the first key; The method further comprises: After the verification is determined to be passed according to the first verification result, background analysis is performed according to the first background image and the second background image to determine background change information, wherein the background change information includes adding or reducing a target object in the background; When the target objects are increased or decreased in multiple background change information, updating the first background image according to the background change information; The performing background difference analysis based on the first area and the second area to determine the third analysis result includes: Generate multiple analysis paths that pass through the first area and the second area with the face as the starting direction, obtain pixel values of each pixel point in the analysis path, and determine the continuity of the change of the pixel value at the connection between the first area and the second area to determine a third analysis result; Determine the background pixel difference according to the pixel value of the pixel point in the first area and the pixel value of the pixel point in the second area to determine the third analysis result; The background definition difference is determined according to the brightness values of the pixels in the first area and the brightness values of the pixels in the second area to determine the third analysis result.
2. The method according to claim 1, characterized in that: The method further comprises: If the verification fails according to the first verification result, a liveness verification prompt is output, and a camera component corresponding to the computer storage system is turned on to obtain a verification video of the accessing user, wherein the liveness verification prompt includes one of opening the mouth, raising the head, lowering the head, and shaking the head left and right; the verification video includes a third face image of the accessing user; Determine a second verification result according to whether the third facial image of the accessing user in the verification video matches the first facial image and whether the liveness verification of the accessing user passes; If the verification is determined to be successful based on the second verification result, the first key is obtained from the cloud platform to decrypt the encrypted data based on the first key.
3. The method according to claim 2, characterized in that The method further comprises: If all verifications fail according to the second verification result, a verification instruction is issued to the cloud platform, so that the cloud platform sends a verification code to the number reserved by the accessing user; Receive the first hash value of the verification code sent by the cloud platform; Obtain the verification code input by the accessing user, and perform hashing to obtain a second hash value; A verification is performed based on the first hash value and the second hash value to determine a third verification result. If the verification is determined to be passed based on the third verification result, the first key is obtained from the cloud platform to decrypt the encrypted data based on the first key.
4. The method according to claim 1, characterized in that The first key includes a plurality of second keys, and the decrypting of the encrypted data according to the first key includes: Obtaining encrypted data and a screening matrix corresponding to the encrypted data, the screening matrix being used to screen out a target key corresponding to the encrypted data from a plurality of second keys; Acquire multiple second keys from the first key, and use a screening matrix to screen the target key from the second keys; Decrypt the encrypted data according to the target key.
5. A computer storage system access device, executing the method according to any one of claims 1 to 4, characterized in that: The computer storage system stores encrypted data, and the device comprises: An access request acquisition module is used to acquire an access request for encrypted data stored in a computer storage system, and acquire a first verification image of an accessing user according to the access request, wherein the first verification image includes: a first face image of the accessing user and a first background image corresponding to a camera component of the computer storage system; A second image acquisition module is used to start the camera component corresponding to the computer storage system and capture a second verification image of the accessing user, where the second verification image includes a second face image and a second background image of the accessing user; A second image verification module, used to verify the accessing user according to the first verification image and the second verification image to obtain a first verification result; The encrypted data decryption module is used to obtain a first key from the cloud platform if the verification is determined to be passed according to the first verification result, so as to decrypt the encrypted data according to the first key.
6. An electronic device, characterized in that include: memory and at least one processor; The memory is used to store computer-executable instructions; The at least one processor is configured to execute computer-executable instructions stored in the memory, so that the at least one processor performs the method according to any one of claims 1 to 4.
7. A storage medium, characterized in that The storage medium stores a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Encryption and decryption method and device based on face features
CN115688076A
Facial recognition-based authentication
US20180096212A1
Identity authentication and processing
US20220277066A1