Electronic passport security sharing and authentication system and method
By using the word2vec model in the electronic certificate system to encode user information and perform homomorphic encryption, the problem of data leakage in the electronic certificate authentication process is solved, and more efficient data security sharing and authentication are achieved.
Patent Information
- Application Number
- CN202411375034.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing technologies have failed to effectively protect against data leakage during the authentication process in the secure sharing of electronic certificate data, leading to risks of identity theft and privacy breaches.
The word2vec model is used to encode user information data, and the encoded vector is encrypted using the homomorphic encryption algorithm. The encrypted data is transmitted to the main device for storage and authentication through the generation device and the authentication device. The constructed word2vec model is used for comparative calculation to ensure the security of the authentication result.
It effectively prevents data leakage caused by man-in-the-middle attacks and improves the security and accuracy of the authentication process.
Smart Images

Figure CN119227109B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic certificates, and in particular to a system and method for securely sharing and authenticating electronic certificates. Background Art
[0002] With the development of electronic certificate informatization, most regions have established electronic certificate platforms, storing and sharing large amounts of electronic certificate data. However, electronic certificate data often contains a large amount of sensitive personal information, such as identity documents, health records, and financial information. If it falls into the hands of unauthorized persons, it can lead to serious losses such as identity theft, fraud, and personal privacy leaks.
[0003] After searching, the existing patent (publication number: CN117676038A) discloses a method and system for secure sharing of electronic certificate data. The present invention analyzes the position distribution and grayscale fluctuation characteristics of the neighborhood pixels of each non-edge pixel of the grayscale image of the electronic certificate to obtain the distribution association value of each non-edge pixel; obtains the grayscale reference value of each non-edge pixel based on the grayscale information of the neighborhood pixels of each non-edge pixel; obtains the corrected grayscale value of each non-edge pixel by combining the distribution association value and the grayscale reference value, and then obtains a valid certificate in combination with the grayscale value of the edge pixel. The present invention analyzes the pixel similarity association characteristics of the pixels in the neighborhood of the non-edge pixel of the electronic certificate, and then corrects the grayscale value of the non-edge pixel, making it easier to distinguish between valid information and invalid information, thereby accurately obtaining a valid certificate and improving the data validity and encryption efficiency of secure sharing of electronic certificate data.
[0004] However, it has its shortcomings. It only improves the data validity and encryption efficiency of the secure sharing of electronic certificate data, but does not protect the data of electronic certificate authentication, which may lead to data leakage during electronic certificate authentication. Summary of the Invention
[0005] In view of the deficiencies of the prior art, the present invention provides a system and method for secure sharing and authentication of electronic certificates, which solves the problems raised by the above-mentioned background technology.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: an electronic certificate security sharing and authentication system and system, including a generation device, an authentication device and a main device, the generation device includes a generation login module, a generation processing module, a generation shooting module and a generation network transmission module, the authentication device includes an authentication login module, an authentication processing module, an authentication shooting module and an authentication network transmission module, and the main device includes a main network transmission module, a comparison module, a main processing module and a storage module.
[0007] Preferably, the login generation module and the authentication login module both include facial recognition login and password login.
[0008] A method for securely sharing and authenticating an electronic certificate comprises the following steps:
[0009] Step 1: The generation device and the authentication device respectively register and log in through the generation login module and the authentication login module, build a word2vec model, and deploy the word2vec model inside the generation device and the authentication device. The generation device and the authentication device use the word2vec model to encode the registered user information data to obtain encoding vectors of different user information data;
[0010] Step 2: The generation device and the authentication device encrypt the user information data encoding vector using a homomorphic encryption algorithm, and transmit the encrypted data to the main device through the generation network transmission module and the authentication network transmission module. The main network transmission module receives the user information encrypted data and transmits it to the storage module for storage;
[0011] Step 3: The generating device takes relevant photos through the generating shooting module and sends the photo data to the generating processing module, and the generating processing module generates electronic certificate data based on the obtained photos;
[0012] Step 4: The generation processing module uses the word2vec model to convert the generated electronic certificate data into a coding vector, homomorphically encrypts the coding vector, and transmits it to the main device through the generation network transmission module. The main network transmission module receives the generated electronic certificate ciphertext and transmits it to the main processing module, and then transmits it to the storage module for storage;
[0013] Step 5: The authentication device takes a photo of the external electronic certificate through the authentication shooting module, and transmits the photographed electronic certificate data to the authentication processing module. The authentication processing module uses the word2vec model to convert the photographed electronic certificate data into a coding vector, homomorphically encrypts the coding vector, and transmits it to the main device through the authentication network transmission module.
[0014] Step 6. The main network transmission module receives the photographed electronic certificate ciphertext and transmits it to the main processing module. The main processing module starts the comparison module and sends the received photographed electronic certificate ciphertext to the comparison module. The comparison module compares and calculates the electronic certificate ciphertext generated inside the storage module and the photographed electronic certificate ciphertext, and then sends the calculation result ciphertext to the main processing module. The main processing module sends the calculation result ciphertext to the authentication device through the main network transmission module. The authentication network transmission device receives the calculation result ciphertext, then decrypts the received calculation result ciphertext, and uses the word2vec model to perform an inverse operation on the decryption result to obtain the calculated authentication result data.
[0015] Preferably, the word2vec model includes an input layer, a hidden layer, and an output layer. The one-hot encoding result X of the user information data is used as the input value of the word2vec model input layer, and the calculation result of the hidden layer of the word2vec model is: The calculation results of the hidden layer are input to the output layer. For the i-th type of user information data, the output result of the output layer is:
[0016] Preferably, the comparison method of the comparison module is the following steps:
[0017] Step 51: Construct an iterative formula for the sample matrix based on the generated electronic certificate ciphertext data stored in the storage module.
[0018]
[0019] The sample matrix is iteratively updated according to the iterative formula to obtain a feature matrix.
[0020] Step 52: Use the feature matrix to obtain the features of the photographed electronic certificate ciphertext and the generated electronic certificate ciphertext. Then, use the cosine algorithm to compare and calculate the features of the generated electronic certificate ciphertext and the photographed electronic certificate ciphertext. The formula is as follows:
[0021] where x1, x2...x n The ciphertext features of the photographed electronic certificate, y1, y2...y n The ciphertext features of the generated electronic certificate.
[0022] Beneficial effects
[0023] The present invention provides a system and method for secure sharing and authentication of electronic certificates. Compared with the existing technology, it has the following advantages:
[0024] 1. The electronic certificate security sharing and authentication system and method are as follows: the present invention sets up a word2vec model and deploys the word2vec model on a generating device (13) and an authentication device (14); encodes the received user information data by the word2vec model to obtain encoding vectors of different user information data; then encrypts the encoding vectors by using a homomorphic encryption algorithm; and transmits the encryption results to a main device; the main device stores the encoding vector ciphertext; the word2vec model converts the generated electronic certificate into an encoding vector, and homomorphically encrypts the encoding vector and transmits the encryption results to the main device for storage; then the word2vec model converts the photographed electronic certificate into an encoding vector, and homomorphically encrypts the encoding vector and transmits the encoding vector to the main device; a comparison module performs comparative calculation authentication and sends the authentication result ciphertext to the authentication device; the authentication device decrypts the received encoding vector ciphertext and uses the word2vec model to perform an inverse operation on the decryption result to obtain authenticated data, thereby preventing data leakage caused by a man-in-the-middle attack during the process of user submitting data to the main device.
[0025] 2. The electronic certificate security sharing and authentication system and method are configured to iteratively update the sample matrix according to the iterative formula to obtain the optimal characteristic matrix and the optimal characteristic vector, thereby improving the accuracy of the comparison calculation. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 Schematic diagram of the structure of the system of the present invention;
[0027] Figure 2 Schematic diagram of the structure of the method of the present invention.
[0028] In the figure: 1. Generate login module; 2. Generate processing module; 3. Generate shooting module; 4. Generate network transmission module; 5. Authentication login module; 6. Authentication processing module; 7. Authentication shooting module; 8. Authentication network transmission module; 9. Main network transmission module; 10. Comparison module; 11. Main processing module; 12. Storage module; 13. Generation device; 14. Authentication device; 15. Main device. DETAILED DESCRIPTION
[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0030] See also Figure 1-2The present invention provides a technical solution: a system for secure sharing and authentication of electronic certificates, comprising a generation device 13, an authentication device 14 and a main device 15. The generation device 13 comprises a generation login module 1, a generation processing module 2, a generation shooting module 3 and a generation network transmission module 4. The authentication device 14 comprises an authentication login module 5, an authentication processing module 6, an authentication shooting module 7 and an authentication network transmission module 8. The main device 15 comprises a main network transmission module 9, a comparison module 10, a main processing module 11 and a storage module 12. The generation login module 1 and the authentication login module 5 both comprise facial recognition login and password login, thereby forming a one-stop operation of generation, storage and authentication of electronic certificates.
[0031] A method for securely sharing and authenticating an electronic certificate comprises the following steps:
[0032] Step 1: The generation device 13 and the authentication device 14 register and log in through the generation login module 1 and the authentication login module 5 respectively, build a word2vec model, and deploy the word2vec model inside the generation device 13 and the authentication device 14. The generation device 13 and the authentication device 14 use the word2vec model to encode the registered user information data to obtain encoding vectors of different user information data;
[0033] Step 2: The generation device 13 and the authentication device 14 encrypt the user information data encoding vector using a homomorphic encryption algorithm and transmit the encrypted data to the main device 15 through the generation network transmission module 4 and the authentication network transmission module 8. The main network transmission module 9 receives the encrypted user information data and transmits it to the storage module 12 for storage;
[0034] Step 3: The generating device 13 takes relevant photos through the generating shooting module 3 and sends the photo data to the generating processing module 2. The generating processing module 2 generates electronic certificate data based on the obtained photos;
[0035] Step 4: The generation processing module 2 uses the word2vec model to convert the generated electronic certificate data into a coding vector, homomorphically encrypts the coding vector, and transmits it to the main device 15 through the generation network transmission module 4. The main network transmission module 9 receives the generated electronic certificate ciphertext and transmits it to the main processing module 11, and then transmits it to the storage module 12 for storage;
[0036] Step 5: The authentication device 14 takes a photo of the external electronic certificate through the authentication shooting module 7 and transmits the photographed electronic certificate data to the authentication processing module 6. The authentication processing module 6 uses the word2vec model to convert the photographed electronic certificate data into a coding vector, homomorphically encrypts the coding vector, and transmits it to the main device 15 through the authentication network transmission module 8.
[0037] Step 6: The main network transmission module 9 receives the photographed electronic certificate ciphertext and transmits it to the main processing module 11. The main processing module 11 starts the comparison module 10 and sends the received photographed electronic certificate ciphertext to the comparison module 10. The comparison module 10 compares and calculates the electronic certificate ciphertext generated in the storage module 12 and the photographed electronic certificate ciphertext, and then sends the calculation result ciphertext to the main processing module 11. The main processing module 11 sends the calculation result ciphertext to the authentication device 14 through the main network transmission module 9. The authentication network transmission device receives the calculation result ciphertext, then decrypts the received calculation result ciphertext, and uses the word2vec model to perform an inverse operation on the decryption result to obtain the calculated authentication result data. The word2vec model is constructed to include an input layer, a hidden layer, and an output layer. The one-hot encoding result X of the user information data is used as the input value of the word2vec model input layer. The calculation result of the hidden layer of the word2vec model is: where X i represents the one-hot encoding result of the i-th category user information data, h i Represents the corresponding hidden layer calculation result; W h represents the weight matrix in the hidden layer, W h The size of is L×H, where L represents the size of the user feature dictionary and H represents the size of the hidden layer. The calculation results of the hidden layer are input to the output layer. For the i-th type of user information data, the output result of the output layer is: where w y represents the weight matrix in the output layer, w y The size is L×H; the resulting encoding vector is y1,y2,y3,y4…y i ;
[0038] By constructing a word2vec model, the received user information data is encoded to obtain encoding vectors of different user information data. The encoding vectors are then encrypted using a homomorphic encryption algorithm, and the encryption results are transmitted to the main device 15. This can protect the user's information. The generated electronic certificate and the photographed electronic certificate are converted into encoding vectors through the word2vec model, and the encoding vectors are homomorphically encrypted and then transmitted to the main device 15. This prevents data leakage caused by man-in-the-middle attacks during the process of users submitting data to the main device 15.
[0039] Furthermore, the comparison method of the comparison module 10 is as follows:
[0040] Step 51: Construct an iterative formula for the sample matrix based on the generated electronic certificate ciphertext data stored in the storage module 12.
[0041]
[0042] The sample matrix is iteratively updated according to the iterative formula to obtain the characteristic matrix, where β0 is a constant. Given a random initial value of β0=1, Y0=H0, it is iteratively updated according to the iterative formula. When the number of iterations reaches the set threshold k, the iteration is terminated and H is obtained. k That is, the characteristic matrix, k represents the product of the matrix, Y is the intermediate parameter, P() represents the projected gradient algorithm, and P(Z) represents projecting all negative numbers in the matrix Z to 0;
[0043] Step 52: Use the feature matrix to obtain the features of the photographed electronic certificate ciphertext and the generated electronic certificate ciphertext. Then, use the cosine algorithm to compare and calculate the features of the generated electronic certificate ciphertext and the photographed electronic certificate ciphertext. The formula is as follows:
[0044] where x1, x2...x n The ciphertext features of the photographed electronic certificate, y1, y2...y n The ciphertext characteristics of the generated electronic certificate;
[0045] The sample matrix is iteratively updated according to the iterative formula to obtain the optimal characteristic matrix and the optimal characteristic vector, thereby improving the accuracy of the comparison calculation and thus improving the accuracy of the authentication.
[0046] Meanwhile, the contents not described in detail in this specification belong to the prior art known to those skilled in the art.
[0047] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include," "comprise," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations. The phrase "includes an element defined by..." does not exclude the presence of other identical elements in the process, method, article, or device that includes the element.
[0048] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A system for secure sharing and authentication of electronic certificates, characterized by: The invention comprises a generating device (13), an authentication device (14) and a main device (15), wherein the generating device (13) comprises a generating login module (1), a generating processing module (2), a generating shooting module (3) and a generating network transmission module (4), the authentication device (14) comprises an authentication login module (5), an authentication processing module (6), an authentication shooting module (7) and an authentication network transmission module (8), the main device (15) comprises a main network transmission module (9), a comparison module (10), a main processing module (11) and a storage module (12), and the generating login module (1) and the authentication login module (5) both comprise facial recognition login and password login; The system includes the following steps: Step 1: the generating device (13) and the authentication device (14) respectively register and log in through the generating login module (1) and the authentication login module (5), construct a word2vec model, and deploy the word2vec model inside the generating device (13) and the authentication device (14), and the generating device (13) and the authentication device (14) use the word2vec model to encode the registered user information data to obtain encoding vectors of different user information data; Step 2: The generating device (13) and the authentication device (14) encrypt the user information data encoding vector using a homomorphic encryption algorithm, and transmit the encrypted data to the main device (15) through the generating network transmission module (4) and the authentication network transmission module (8); the main network transmission module (9) receives the user information encrypted data and transmits it to the storage module (12) for storage; Step 3: The generating device (13) takes relevant photos through the generating shooting module (3) and sends the photo data to the generating processing module (2), and the generating processing module (2) generates electronic certificate data based on the obtained photos; Step 4: The generation processing module (2) uses the word2vec model to convert the generated electronic certificate data into a coding vector, performs homomorphic encryption on the coding vector, and transmits it to the main device (15) through the generation network transmission module (4). The main network transmission module (9) receives the generated electronic certificate ciphertext and transmits it to the main processing module (11), and then transmits it to the storage module (12) for storage; Step 5: The authentication device (14) photographs the external electronic certificate through the authentication photographing module (7), and transmits the photographed electronic certificate data to the authentication processing module (6). The authentication processing module (6) converts the photographed electronic certificate data into a coding vector using the word2vec model, homomorphically encrypts the coding vector, and transmits it to the main device (15) through the authentication network transmission module (8); Step 6. The main network transmission module (9) receives the photographed electronic certificate ciphertext and transmits it to the main processing module (11). The main processing module (11) starts the comparison module (10) and sends the received photographed electronic certificate ciphertext to the comparison module (10). The comparison module (10) performs a comparison calculation between the electronic certificate ciphertext generated inside the storage module (12) and the photographed electronic certificate ciphertext, and then sends the calculation result ciphertext to the main processing module (11). The main processing module (11) sends the calculation result ciphertext to the authentication device (14) through the main network transmission module (9). The authentication network transmission device receives the calculation result ciphertext, then decrypts the received calculation result ciphertext, and uses the word2vec model to perform an inverse operation on the decryption result to obtain the calculated authentication result data.
2. The electronic certificate security sharing and authentication system according to claim 1, characterized in that: The word2vec model includes an input layer, a hidden layer, and an output layer. The one-hot encoding result X of the user information data is used as the input value of the word2vec model input layer. The calculation result of the hidden layer of the word2vec model is: i =W h T X i , where X i represents the one-hot encoding result of the i-th category user information data, h i Represents the corresponding hidden layer calculation result; W h represents the weight matrix in the hidden layer, W h The size of is L×H, where L represents the size of the user feature dictionary and H represents the size of the hidden layer. The calculation results of the hidden layer are input to the output layer. For the i-th type of user information data, the output result of the output layer is: where w y represents the weight matrix in the output layer, w y The size is L×H; the resulting encoding vector is y1,y2,y3,y4…y i .
3. The electronic certificate security sharing and authentication system according to claim 2, characterized in that: The comparison method of the comparison module (10) comprises the following steps: Step 51: Construct an iterative formula for the sample matrix based on the generated electronic certificate ciphertext data stored in the storage module (12). The sample matrix is iteratively updated according to the iterative formula to obtain the characteristic matrix, where β0 is a constant. Given a random initial value of β0=1, Y0=H0, it is iteratively updated according to the iterative formula. When the number of iterations reaches the set threshold k, the iteration is terminated and H is obtained. k That is, the characteristic matrix, k represents the product of the matrix, Y is the intermediate parameter, P() represents the projected gradient algorithm, and P(Z) represents projecting all negative numbers in the matrix Z to 0; Step 52: Use the feature matrix to obtain the features of the photographed electronic certificate ciphertext and the generated electronic certificate ciphertext. Then, use the cosine algorithm to compare and calculate the features of the generated electronic certificate ciphertext and the photographed electronic certificate ciphertext. The formula is as follows: where x1, x2...x n The ciphertext features of the photographed electronic certificate, y1, y2...y n The ciphertext features of the generated electronic certificate.
Citation Information
Patent Citations
Electronic license data security sharing method and system
CN117676038A
Electronic certificate sharing system and usage method thereof
CN107995271A
Electronic academic degree certificate data protection and sharing system based on block chains
CN112749417A