Authentication method, device, electronic device, storage medium and program product
By combining Bloom filters with biometric ciphertext, the problems of high computational overhead and privacy information leakage in identity authentication are solved, and an efficient and secure identity authentication process is achieved.
Patent Information
- Application Number
- CN202411864258.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-12-17
AI Technical Summary
During the user identity authentication process, existing technologies have problems such as high computational overhead, easy authentication failure caused by ciphertext operations, and high risk of privacy information leakage.
A Bloom filter is used for identity authentication. By determining the matching result of the first biometric ciphertext and the object identification ciphertext and combining the feature matching result of the biometric ciphertext, the encrypted transmission of private information and accurate identity authentication are achieved, which reduces the computational overhead and improves the authentication security.
It realizes private intersection query without decrypting private information, reduces computational overhead, improves the accuracy and security of identity authentication, avoids misjudgment, and protects user privacy data from leakage.
Smart Images

Figure CN119671570B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information security technology, and in particular to technical fields such as the Internet of Things and data encryption. Background Art
[0002] In application scenarios such as logging into an internet platform and performing online transactions, the relevant service provider can authenticate the user by obtaining the user's login name and password and other authentication methods. After the identity authentication result is passed, the relevant service provider can safely provide services to the user. Summary of the Invention
[0003] The present disclosure provides an authentication method, device, electronic device, storage medium, and program product.
[0004] According to one aspect of the present disclosure, an authentication method is provided, including: determining a first biometric ciphertext and a first object identifier ciphertext based on an authentication request from a terminal, the first object identifier ciphertext being determined by updating a first Bloom filter based on an object identifier of a target object; determining a target identifier that matches the object identifier from a preset identifier set based on an identifier matching result between the first object identifier ciphertext and a second object identifier ciphertext, wherein the second object identifier ciphertext is determined by updating the first Bloom filter based on a preset identifier in the preset identifier set; and determining an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext related to the target identifier.
[0005] According to another aspect of the present disclosure, an authentication method is provided, comprising: extracting features from biometric attribute data of a target object to obtain a biometric feature of the target object; encrypting the biometric feature of the target object to obtain a first biometric feature ciphertext; determining an authentication request based on the first biometric feature ciphertext and a first object identification ciphertext, wherein the first object identification ciphertext is determined by updating a first Bloom filter based on the object identification of the target object; and sending the authentication request to a server.
[0006] According to another aspect of the present disclosure, an authentication device is provided, including: a first determination module, configured to determine a first biometric ciphertext and a first object identification ciphertext based on an authentication request from a terminal, the first object identification ciphertext being determined by updating a first Bloom filter based on an object identification of the target object; a second determination module, configured to determine a target identification that matches the object identification from a preset identification set based on an identification matching result between the first object identification ciphertext and the second object identification ciphertext, wherein the second object identification ciphertext is determined by updating the first Bloom filter based on a preset identification in the preset identification set; and an authentication module, configured to determine an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext related to the target identification.
[0007] According to another aspect of the present disclosure, an authentication device is provided, comprising: an object biometric characteristic acquisition module, configured to extract characteristics of object biometric attribute data of a target object to obtain a target object biometric characteristic; an encryption module, configured to encrypt the object biometric characteristic to obtain a first biometric characteristic ciphertext; a fourth determination module, configured to determine an authentication request based on the first biometric characteristic ciphertext and a first object identification ciphertext, wherein the first object identification ciphertext is determined by updating a first Bloom filter based on the object identification of the target object; and sending the authentication request to a server.
[0008] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method provided according to an embodiment of the present disclosure.
[0009] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable the computer to execute the method provided according to an embodiment of the present disclosure.
[0010] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, which implements the method provided according to the embodiment of the present disclosure when executed by a processor.
[0011] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.
[0013] Figure 1 Schematically illustrates an exemplary system architecture to which the authentication method and apparatus according to an embodiment of the present disclosure may be applied;
[0014] Figure 2 The following schematically shows a flow chart of an authentication method according to an embodiment of the present disclosure;
[0015] Figure 3 The following schematically shows a flow chart of an authentication method according to another embodiment of the present disclosure;
[0016] Figure 4 Schematically shows a principle diagram of determining a second object identification ciphertext according to an embodiment of the present disclosure;
[0017] Figure 5 Schematically shows a principle diagram of determining a second biometric ciphertext according to an embodiment of the present disclosure;
[0018] Figure 6 The following schematically shows a flow chart of an authentication method according to another embodiment of the present disclosure;
[0019] Figure 7 The following schematically shows a flow chart of an authentication method according to another embodiment of the present disclosure;
[0020] Figure 8 A block diagram schematically shows an authentication processing device according to an embodiment of the present disclosure;
[0021] Figure 9 A block diagram schematically shows an authentication processing device according to another embodiment of the present disclosure; and
[0022] Figure 10 A schematic block diagram of an example electronic device that can be used to implement the authentication method according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0023] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0024] In the technical solution disclosed herein, the acquisition, storage and application of user personal information involved comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good morals.
[0025] The inventors discovered that when users perform interactive operations such as business transactions and information browsing on terminal devices, they can authenticate their biometric data, such as facial images, to confirm their operational permissions. However, the authentication process consumes considerable computational overhead and is prone to errors in biometric data due to ciphertext operations, leading to authentication failures.
[0026] Embodiments of the present disclosure provide an authentication method, apparatus, electronic device, storage medium, and program product. The authentication method includes: determining a first biometric ciphertext and a first object identifier ciphertext based on an authentication request from a terminal, wherein the first object identifier ciphertext is determined by updating a first Bloom filter based on the object identifier of the target object; determining a target identifier that matches the object identifier from a preset identifier set based on an identifier matching result between the first object identifier ciphertext and a second object identifier ciphertext, wherein the second object identifier ciphertext is determined by updating the first Bloom filter based on a preset identifier in the preset identifier set; and determining an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier.
[0027] According to an embodiment of the present disclosure, by acquiring the first object identification ciphertext and the first biometric ciphertext sent by the terminal, the user's private information can be encrypted and transmitted. By matching the first object identification ciphertext obtained by updating the first Bloom filter with the second object identification ciphertext to represent and authenticate the target object, a privacy intersection query can be performed without decrypting the user's private information. The computational overhead generated by the privacy intersection query can be reduced based on the data structure of the Bloom filter, thereby ensuring authentication security and reducing computational overhead. Furthermore, by performing biometric authentication on the target object based on the feature matching result between the first biometric ciphertext and the second biometric ciphertext, the probability of identity authentication errors caused by misjudgment of the matching result due to the query mechanism of the Bloom filter can be avoided, thereby enhancing the accuracy of identity authentication and ensuring that the privacy data of the authenticated object is not leaked.
[0028] Figure 1 An exemplary system architecture to which the authentication method and apparatus according to an embodiment of the present disclosure can be applied is schematically shown.
[0029] It should be noted that Figure 1 The examples shown are merely examples of system architectures to which the embodiments of the present disclosure may be applied, to help those skilled in the art understand the technical content of the present disclosure. This does not mean that the embodiments of the present disclosure cannot be applied to other devices, systems, environments, or scenarios. For example, in another embodiment, an exemplary system architecture to which the authentication method and apparatus may be applied may include a terminal device, but the terminal device may implement the authentication method and apparatus provided by the embodiments of the present disclosure without interacting with a server.
[0030] like Figure 1As shown, the system architecture 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used as a medium for providing communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.
[0031] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as knowledge reading applications, web browser applications, search applications, instant messaging tools, email clients, and / or social platform software (for example only).
[0032] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.
[0033] Server 105 may be a server that provides various services, such as a background management server (for example only) that supports content browsed by users using terminal devices 101, 102, and 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal device.
[0034] It should be noted that the authentication method provided in the embodiment of the present disclosure can generally be executed by the terminal device 101, 102, or 103. Accordingly, the authentication apparatus provided in the embodiment of the present disclosure can also be provided in the terminal device 101, 102, or 103.
[0035] Alternatively, the authentication method provided in the embodiments of the present disclosure may also be generally performed by the server 105. Accordingly, the authentication apparatus provided in the embodiments of the present disclosure may generally be provided in the server 105. The authentication method provided in the embodiments of the present disclosure may also be performed by a server or server cluster that is different from the server 105 and that is capable of communicating with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the authentication apparatus provided in the embodiments of the present disclosure may also be provided in a server or server cluster that is different from the server 105 and that is capable of communicating with the terminal devices 101, 102, 103 and / or the server 105.
[0036] For example, when a user is reading an e-book online, the terminal devices 101, 102, and 103 can obtain the target content in the e-book that the user is looking at, and then send the obtained target content to the server 105. The server 105 analyzes the target content to determine the characteristic information of the target content, predicts the content that the user is interested in based on the characteristic information of the target content, and extracts the content that the user is interested in. Alternatively, a server or server cluster that can communicate with the terminal devices 101, 102, 103 and / or the server 105 can analyze the target content and ultimately extract the content that the user is interested in.
[0037] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0038] Figure 2 The flowchart of the authentication method according to the embodiment of the present disclosure is schematically shown.
[0039] like Figure 2 As shown, the authentication method can be applied to the server, and the authentication method includes operations S210 to S230.
[0040] In operation S210, a first biometric ciphertext and a first object identification ciphertext are determined according to an authentication request from a terminal.
[0041] In operation S220 , based on the identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext, a target identifier that matches the object identifier is determined from a preset identifier set.
[0042] In operation S230 , an identity authentication result of the target object is determined based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier.
[0043] According to an embodiment of the present disclosure, the first object identification ciphertext is determined by updating the first Bloom filter based on the object identification of the target object. The target object may be an object to be authenticated, and the object identification may be data representing the identity of the target object.
[0044] According to an embodiment of the present disclosure, the first Bloom filter may be a preset Bloom filter. The first Bloom filter may include a first hash function and a first initial bit array. The number of the first hash functions may be one or more, and the length of the first initial bit array may be a preset length.
[0045] According to an embodiment of the present disclosure, updating the first Bloom filter based on the object identifier may include processing the object identifier based on a first hash function of the first Bloom filter, mapping the obtained one or more hash values to positions corresponding to the first initial bit array, obtaining the first bit array corresponding to the object identifier, and determining the first bit array as the first object identifier ciphertext.
[0046] According to an embodiment of the present disclosure, the preset identifiers in the preset identifier set may be pre-stored on the server side, and the preset identifiers may be associated with preset objects, which may be any type of user, such as an individual or an organization, for which the server side can provide identity authentication services.
[0047] In one example, the preset identifier may be an identity identifier of a preset object of the user.
[0048] According to an embodiment of the present disclosure, the second object identifier ciphertext is determined by updating the first Bloom filter based on a preset identifier in the preset identifier set. The preset identifier in the preset identifier set can be processed based on a first hash function of the first Bloom filter, and one or more resulting hash values can be mapped to positions corresponding to the first initial bit array to obtain a second bit array corresponding to the preset identifier. The second bit array can then be determined as the second object identifier ciphertext.
[0049] According to an embodiment of the present disclosure, a first object identifier ciphertext can be matched with the second object identifier ciphertext of each of a plurality of preset identifiers to obtain a plurality of identifier matching results. Based on the identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext, a target identifier that matches the object identifier is determined from the preset identifier set. This may include determining a target identifier result representing a match from the plurality of identifier matching results, and determining the preset identifier corresponding to the target identifier matching result as the target identifier. In this way, the identity of the target object can be authenticated by matching different bit arrays based on the data structure of the first Bloom filter, thereby realizing ciphertext interaction and ciphertext authentication in the identity authentication process.
[0050] According to embodiments of the present disclosure, the first biometric ciphertext may represent the biometric attribute data of a target object. For example, feature extraction may be performed on the biometric attribute data of the target object, and the extracted biometric features of the target object may be encrypted to generate the first biometric ciphertext. The second biometric ciphertext may be ciphertext data representing preset biometric attribute data corresponding to the target identifier. The first and second biometric ciphertexts may be determined using the same encryption method, facilitating matching of the first and second biometric ciphertexts to produce a feature matching result.
[0051] According to an embodiment of the present disclosure, matching a first biometric ciphertext with a second biometric ciphertext to obtain a feature matching result may include calculating the similarity between the first biometric ciphertext and the second biometric ciphertext, and using the comparison result between the similarity and a preset similarity threshold as the feature matching result. For example, the cosine similarity between the first biometric ciphertext and the second biometric ciphertext may be calculated, and the comparison result between the cosine similarity and the preset similarity threshold may be used as the feature matching result. If the similarity is greater than the preset similarity threshold, the feature matching result may be determined to indicate a match. However, the present invention is not limited to this. Alternatively, the distance between the first biometric ciphertext and the second biometric ciphertext may be calculated, and the comparison result between the distance and a preset distance threshold may be used as the feature matching result. If the distance is less than the preset distance threshold, the feature matching result may be determined to indicate a match.
[0052] According to an embodiment of the present disclosure, the identity authentication result of the target object is determined based on the feature matching result between the first biometric ciphertext and the second biometric ciphertext related to the target identifier. This may include determining that the identity authentication result indicates that the target object's identity authentication has passed when both the feature matching result and the identifier matching result indicate a match. By using the identifier matching result to determine the target identifier related to the target object that the terminal needs to authenticate from the preset identifier set, and then using the feature matching result between the first biometric ciphertext and the second biometric ciphertext to determine whether the object biometric attribute data of the target object matches the preset biometric attribute data held by the server, dual authentication of the target object's identity attribute information can be achieved under ciphertext interaction conditions. At the same time, by determining the identity authentication result based on the feature matching result indicating a match, it is possible to verify whether there is a mismatch between the first object identifier ciphertext and the second object identifier ciphertext obtained based on the update of the first Bloom filter, thereby avoiding mismatches caused by ciphertext information queries based on the Bloom filter mechanism, thereby improving the accuracy of identity authentication.
[0053] In one example, the server can pre-extract features of the preset biometric attribute data corresponding to each of the multiple preset identifiers, and encrypt the extracted biometric features of the preset objects of each of the multiple preset identifiers to obtain the second biometric ciphertext of each of the multiple preset identifiers, so that the server can store the preset identifiers and the second biometric ciphertext to avoid storing the plaintext data of the preset biometric attribute data, and avoid the server's storage space from being attacked, resulting in the leakage of the biometric attribute data of the preset object, thereby improving the privacy information security of the preset object with the preset identifier.
[0054] According to an embodiment of the present disclosure, the object identifier may include multiple, and the first object identifier ciphertext may also include multiple, and the multiple first object identifier ciphertexts may be represented by one or more bit arrays of the first Bloom filter. Accordingly, the bit array representing the second object identifier ciphertext may also be one or more, and the embodiment of the present disclosure does not limit the number of first object identifier ciphertexts contained in the bit array obtained by updating the first Bloom filter, or the number of second object identifier ciphertexts contained in the bit array obtained by updating the first Bloom filter. The identification matching result representing the matching may represent the intersection between multiple object identifiers and multiple preset identifiers. In the case where the object identifier does not match each preset identifier, the identity authentication result may indicate that the target object identity authentication corresponding to the object identifier fails.
[0055] It should be noted that the information acquisition and processing processes in the above embodiments, such as the first biometric ciphertext or the second biometric ciphertext, are all performed after obtaining authorization from the relevant users or institutions, and the relevant users or institutions are aware of and agree to them, and they all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0056] According to an embodiment of the present disclosure, the first biometric ciphertext is associated with at least one of the following biometric attribute data: facial image data, fingerprint image data, palm print image data, and iris data. However, this is not limited to these data types; biometric attribute data may also include other types of data capable of representing the identity attributes of the target subject, such as voiceprint data. The embodiments of the present disclosure do not limit the specific type of biometric attribute data associated with the first biometric ciphertext; as long as the biometric attribute data can represent the identity attributes of the target subject, is authorized by the target subject with their knowledge, and complies with legal provisions and public order and good morals, it is sufficient.
[0057] According to an embodiment of the present disclosure, the facial image data may include a facial image of the target object, such as a frontal face photo, a side face photo, a facial depth map, etc. of the target object.
[0058] It should be noted that the second biometric ciphertext may represent the same type of biometric attribute data as the first biometric ciphertext.
[0059] Figure 3 The flowchart of an authentication method according to another embodiment of the present disclosure is schematically shown.
[0060] like Figure 3 As shown, the authentication method applied to the server may further include operations S310 to S330.
[0061] In operation S310 , a preset identifier set is hashed to obtain a plurality of identifier subsets.
[0062] In operation S320 , a modular operation is performed on the first object hash value from the terminal based on the number of the identified subsets to obtain a modular operation result.
[0063] In operation S330 , a candidate identification subset is determined from the plurality of identification subsets based on a matching result between the modulo operation result and the partition attribute value.
[0064] According to an embodiment of the present disclosure, the identifier subset has a partition attribute value, and the partition attribute value can represent the partition number of the partition (or small file, hash bucket) storing the identifier subset. Hash segmentation of the preset identifier set can include calculating a hash value for each preset identifier in the preset identifier set to obtain a preset identifier hash value. The partition attribute value for storing the preset identifier is determined based on the preset identifier hash value, and the preset identifier is stored in the partition with the partition attribute value. In this way, each preset identifier in the preset identifier set can be stored in the partition corresponding to the respective preset identifier hash value. The preset identifiers in the same partition can be the identifier subsets obtained after hash segmentation of the preset identifier set, and multiple identifier subsets are stored in the respective corresponding multiple partitions.
[0065] According to an embodiment of the present disclosure, the first object hash value is obtained by performing a hash operation on the object identifier of the target object. The terminal can perform a hash operation on the object representation of the target object to obtain the first object hash value and send the first object hash value to the server.
[0066] According to an embodiment of the present disclosure, a modular operation, also known as a modulo operation, is performed on the first object hash value from the terminal based on the number of identification subsets. For example, when the number of identification subsets is N, the modular operation is performed on the first object hash value H(idc), including an operation represented by the following formula (1), to obtain a modular operation result.
[0067] H(idc) mod N=i (1)
[0068] Where H(idc) is the hash value of the first object, N is the number of identifier subsets, and N is an integer greater than or equal to 1. mod represents a modulo operation, and i is the result of the modulo operation. By matching the modulo operation result i with the partition attribute value i, the identifier subset stored in the partition with partition attribute value i can be determined as a candidate identifier subset. Note that i can be any value.
[0069] According to an embodiment of the present disclosure, the candidate identifier subset includes multiple candidate identifiers, and the identifier matching result is obtained by matching the first object identifier ciphertext with the second candidate object identifier ciphertext corresponding to the candidate identifier.
[0070] According to an embodiment of the present disclosure, after obtaining the first object identifier ciphertext, a modular operation can be performed based on the first object hash value sent by the terminal to obtain a partition attribute value, so as to determine a candidate identifier subset related to the first object identifier ciphertext from multiple candidate subsets. The second candidate object ciphertexts corresponding to the multiple candidate identifiers in the candidate identifier subset are matched with the first object identifier ciphertext respectively to obtain multiple candidate identifier matching results. The candidate identifier corresponding to the candidate identifier matching result that matches the representation is determined as the target identifier. In this way, the first object identifier ciphertext is avoided from being matched with each preset identifier in the preset identifier set, so as to improve the efficiency of obtaining the identifier matching result and save computing overhead.
[0071] According to an embodiment of the present disclosure, the second object identification ciphertext is determined based on the following operations: processing the target identification based on the first hash function of the first Bloom filter to obtain a second identification hash value; determining the first to-be-updated bit corresponding to the second identification hash value from the first initial bit array of the first Bloom filter; and updating the initial bit character of the first to-be-updated bit to the target bit character to obtain the second object identification ciphertext.
[0072] According to an embodiment of the present disclosure, the number of first hash functions may include one or more, and the embodiment of the present disclosure does not limit the number of first hash functions. The initial bit character or the target bit character may be a Boolean value, but is not limited thereto. The initial bit character or the target bit character may also be represented based on other types of characters. The embodiment of the present disclosure does not limit the specific data types of the initial bit character and the target bit character, as long as the initial bit character and the target bit character are different characters.
[0073] Figure 4 The schematic diagram shows a principle diagram of determining the second object identification ciphertext according to an embodiment of the present disclosure.
[0074] like Figure 4 As shown, the first Bloom filter may include a first initial bit array 410 and a first hash function 420. The initial bit character of each bit in the first initial bit array 410 is "0". By processing the target identifier using the first hash function 420, a plurality of hash values may be obtained. The plurality of hash values may be respectively mapped to the three first bits to be updated in the first initial bit array 410. The three first bits to be updated are the first initial bit 411, the second initial bit 412, and the third initial bit 413. The initial bit character "0" of the first initial bit 411, the second initial bit 412, and the third initial bit 413 are all updated to the target bit character "1", and the updated second object identifier ciphertext 430 may be obtained.
[0075] According to an embodiment of the present disclosure, the second biometric ciphertext may be determined by updating the second Bloom filter based on a preset object biometric corresponding to the target identifier.
[0076] According to an embodiment of the present disclosure, the server can update the second Bloom filter based on the biometric characteristics of the preset object corresponding to each preset identifier, thereby obtaining the second biometric ciphertext of each preset identifier. By associating and storing the preset identifiers and the second biometric ciphertext corresponding to each preset identifier, the biometric attribute information of the preset object corresponding to the preset identifier is kept confidential.
[0077] According to an embodiment of the present disclosure, the second Bloom filter may be a preset Bloom filter. The second Bloom filter may include a second hash function and a second initial bit array. The number of the second hash functions may be one or more, and the length of the second initial bit array may be a preset length. Updating the second Bloom filter based on the preset object biometric characteristic corresponding to the target identifier may include: processing the target identifier based on the second hash function of the second Bloom filter, mapping the obtained one or more hash values to positions corresponding to the second initial bit array, obtaining a first bit array corresponding to the preset object biometric characteristic of the target identifier, and determining the first bit array as the second biometric ciphertext.
[0078] According to an embodiment of the present disclosure, the preset subject's biometric features may be obtained by extracting features from preset biometric attribute data corresponding to a preset identifier. The preset biometric attribute data corresponding to the preset identifier may be biometric attribute data of the preset subject obtained under the condition that the preset subject corresponding to the preset identifier has been authorized.
[0079] In one example, the biological attribute data of a preset object can be processed based on a neural network algorithm such as a convolutional neural network algorithm and an attention network algorithm to obtain the biological characteristics of the preset object.
[0080] According to an embodiment of the present disclosure, the first biometric ciphertext may be determined by the terminal updating the second Bloom filter based on a target object biometric characteristic of the target object, where the target object biometric characteristic is determined based on object biometric attribute data of the target object. For example, the target object biometric attribute characteristics of the target object may be obtained by extracting features from the object biometric attribute data of the target object based on a neural network algorithm.
[0081] It should be understood that the second Bloom filter can be updated based on the target object biometrics of the target object to obtain the first biometric ciphertext, with reference to the method of updating the second Bloom filter based on the preset object biometrics corresponding to the target identifier. The embodiments of the present disclosure will not be repeated here.
[0082] According to an embodiment of the present disclosure, the first biometric ciphertext is determined by the terminal updating the second Bloom filter based on the target object biometric of the target object.
[0083] According to an embodiment of the present disclosure, the second biometric ciphertext is determined based on the following operations: feature extraction of preset biometric attribute data corresponding to the target identifier to obtain a preset object biometric feature; processing the preset object biometric feature corresponding to the target identifier based on a second hash function of the second Bloom filter to obtain a second biometric hash value; determining a second to-be-updated bit corresponding to the second biometric hash value from a second initial bit array of the second Bloom filter; and updating the initial bit character of the second to-be-updated bit to the target bit character to obtain the second biometric ciphertext.
[0084] According to embodiments of the present disclosure, the preset biometric attribute data corresponding to a target identifier may include biometric attribute data of the subject with the target identifier, such as a facial image, palm print image, or other biometric attribute data of the subject with the target identifier. The acquisition and processing of the preset biometric attribute data involved in this embodiment is disclosed in advance to the relevant user or organization, and authorized by the relevant user or organization, in compliance with relevant laws and regulations and public order and good morals.
[0085] Figure 5 The figure schematically shows a principle diagram of determining the second biometric ciphertext according to an embodiment of the present disclosure.
[0086] like Figure 5 As shown, the second Bloom filter may include a second initial bit array 510 and a second hash function 520. The initial bit character of each bit in the second initial bit array 510 is "0". By using the second hash function 520 to process the preset object biometric feature 501 corresponding to the target identifier, multiple hash values can be obtained. The multiple hash values can be respectively mapped to the four second bits to be updated in the second initial bit array 510. The 44 second bits to be updated are the first feature initial bit 511, the second feature initial bit 512, the third feature initial bit 513, and the fourth feature initial bit 514. The initial bit character "0" of the first feature initial bit 511, the second feature initial bit 512, the third feature initial bit 513, and the fourth feature initial bit 514 are all updated to the target bit character "1", and the updated second biometric ciphertext 530 can be obtained.
[0087] According to an embodiment of the present disclosure, by updating the second Bloom filter based on the preset object biometrics to obtain the second biometric ciphertext, the storage space occupancy rate of the server can be reduced by the second biometric ciphertext represented by the bit array when storing a large amount of biometric ciphertext. At the same time, the terminal can also update the second Bloom filter based on the target object biometrics to obtain the first biometric ciphertext sent to the server, thereby reducing the space occupied by the communication bandwidth by reducing the data size of the first biometric ciphertext. Furthermore, by sending the first object identification ciphertext and the first biometric ciphertext to the server, the terminal can perform a double Bloom filter query authentication through the server, further reducing the probability of mismatching of the Bloom filter and improving the security and accuracy of identity authentication.
[0088] In one example, the first hash function of the first Bloom filter is different from the second hash function of the second Bloom filter. This allows the first object identification ciphertext and the first biometric ciphertext sent by the terminal device to represent hash values processed by different hash functions. This reduces the probability of simultaneous attacks on the first object identification ciphertext and the first biometric ciphertext, leading to the leakage of both the target object's biometric attribute data and object identification, thereby improving the communication security between the terminal and the server.
[0089] In one example, the first hash function and the second hash function can be determined based on different hash algorithms. For example, the first hash function is determined based on the SHA-3 (Secure Hash Algorithm 3) algorithm, and the second hash function can be determined based on the MD5 (Message-Digest Algorithm 5) algorithm.
[0090] In one example, the data length of the first initial bit array of the first Bloom filter is different from the data length of the second initial bit array of the second Bloom filter. This allows the first object identifier ciphertext and the first biometric ciphertext sent by the terminal device to have different bit array lengths. This allows the server to flexibly set the data lengths of the second object identifier ciphertext and the second biometric ciphertext based on the data characteristics of the preset identifier and preset biometric attribute data, thereby improving storage space utilization on the server.
[0091] In an example, the data length of the first initial bit array may be 128 bits, and the data length of the second initial bit array may be 160 bits.
[0092] In one example, the data length of the first initial bit array of the first Bloom filter is different from the data length of the second initial bit array of the second Bloom filter. Furthermore, the first hash function of the first Bloom filter is different from the second hash function of the second Bloom filter. By processing the preset identifier and the preset object biometric based on different hash functions, and storing the second object identifier ciphertext and the second biometric ciphertext based on different bit array lengths, the probability of simultaneous leakage of the target object's biometric attribute data and object identifier between the terminal and the server can be reduced, and by flexibly setting the data length of the second object identifier ciphertext and the second biometric ciphertext, the storage space utilization of the server can be improved.
[0093] According to an embodiment of the present disclosure, the second biometric ciphertext is determined by encrypting the preset object biometric corresponding to the target identifier based on the public key, and the preset object biometric is determined by feature compression of preset biological attribute data corresponding to the target identifier.
[0094] According to the embodiments of the present disclosure, feature extraction can be performed on the preset biometric attribute data corresponding to the target identifier to obtain initial preset features. Feature compression of the initial preset features corresponding to the target identifier can then be performed using undercomplete autoencoders to obtain preset object biometric features. The public key can be shared between the server and the terminal, and encryption can be performed using the public key without the terminal being able to obtain the private key. This can prevent the terminal from leaking the private key, which could result in the decryption of the first biometric ciphertext.
[0095] According to an embodiment of the present disclosure, the first biometric ciphertext is determined by encrypting the target object's biometric feature based on a public key by the terminal, and the target object's biometric feature is determined by compressing the target object's biometric attribute data by the terminal.
[0096] In one example, the terminal can process the target object's biometric attribute data based on the same feature compression method as the server to obtain a first biometric ciphertext. For example, feature extraction can be performed on the target object's biometric attribute data to obtain initial target object biometric features, and feature compression can be performed on the initial target object biometric features based on an incomplete autoencoder to obtain target object biometric features. By compressing and encrypting the initial target object biometric features to obtain the first biometric ciphertext, the first biometric ciphertext can retain important features in the target object's biometric attribute data. Calculating the similarity between the first biometric ciphertext and the second biometric ciphertext obtained based on feature compression can avoid the defect of homomorphic encryption calculations, where the cumulative error increases with the number of operations, making it difficult to restore the plaintext, thereby improving the recognition accuracy of the target object's biometric attributes.
[0097] According to an embodiment of the present disclosure, the feature matching result is determined based on the following operations: performing similarity calculation on the first biometric ciphertext and the second biometric ciphertext to obtain a similarity ciphertext; decrypting the similarity ciphertext to obtain a similarity plaintext; and determining the feature matching result based on the similarity plaintext.
[0098] According to the embodiments of the present disclosure, a similarity calculation is performed on the first biometric ciphertext and the second biometric ciphertext to obtain a similarity ciphertext, and the feature matching result is determined by decrypting the similarity ciphertext. This allows direct similarity matching without decrypting the first biometric ciphertext and the second biometric ciphertext, thereby avoiding leakage of biometric plaintext data.
[0099] Figure 6 The following schematically shows a flow chart of an authentication method according to another embodiment of the present disclosure.
[0100] like Figure 6 As shown, the authentication method may include operations S601 to S613, the terminal may perform operations S606 to S609, and the server may perform operations S601, S602, S603 to S605, and S610 to S613.
[0101] In operation S601, the server generates a public-private key pair, where the public key is θ e , the private key is θ d .
[0102] In operation S602, the server sends a public key θ to the terminal. e .
[0103] In operation S603, the server performs feature compression on the preset biological attribute data. For example, the server may use a convolutional neural network to extract the preset biological attribute data c j (j=1,2,3…n, n is the number of preset users registered in the base database) feature vector, get the initial preset object biometric feature X of the jth preset user j . Use undercomplete autoencoders to encode the initial preset object biometrics X j Perform feature compression to obtain the preset object biometric feature Enc(X j ). Default default user
[0104] In operation S604, the server uses the public key θ e Encrypt preset object biometrics Enc(X j ). Get the second biometric ciphertext of the jth user [Enc(X j)]. In this way, the second biometric ciphertext corresponding to each preset identifier in the preset identifier set can be obtained. The server can associate the preset identifier with the second biometric ciphertext and store it to avoid leakage of the preset user's facial image data.
[0105] In operation S605, the preset identifiers of the N preset users are used as a preset identifier set, and the preset identifier set is hashed to obtain multiple partition files, wherein the multiple preset identifiers in each partition file can be used as an identifier subset. The i-th partition file f in the multiple partition files i In , multiple preset identifiers corresponding to the partition attribute value i are stored.
[0106] In operation S606, the terminal may update the first Bloom filter according to the object identifier of the target object under the condition of obtaining authorization from the target object to obtain the first object identifier ciphertext. The terminal may also perform a hash calculation on the object identifier of the target object to obtain a first object hash value.
[0107] In operation S607, the terminal performs feature compression on the target object's biometric attribute data to obtain the target object's biometric features. The target object's biometric attribute data may be facial image data of the target object acquired with the target object's knowledge and authorization.
[0108] In operation S608, the terminal uses the public key θ e The target object's biometric feature is encrypted to obtain a first biometric feature ciphertext. The terminal can obtain an authentication request for authenticating the target object by encapsulating the first object identification ciphertext, the first biometric feature ciphertext, and the first object hash value.
[0109] In operation S609 , the terminal sends an authentication request to the server.
[0110] In operation S610, the server determines a candidate identifier subset. The server determines a candidate partition file f that matches the first object hash value from multiple partition files based on the first object hash value carried in the authentication request. i , candidate partition file f i The preset identifiers in are determined as the candidate identifier subset.
[0111] In operation S611, the server processes the candidate partition file f iThe multiple candidate identifiers in the first Bloom filter are inserted into the first Bloom filter, thereby updating the first Bloom filter based on the multiple candidate identifiers. The updated bit array can represent the multiple candidate identifiers. Therefore, the updated bit array can contain the second object identifier ciphertext corresponding to each of the multiple candidate identifiers. The server uses the updated bit array containing the multiple second object identifier ciphertexts to match the first object identifier ciphertext, obtaining multiple identifier matching results. The preset identifier corresponding to the identifier matching result that matches the representation is determined as the target identifier.
[0112] In operation S612, the server authenticates the first biometric ciphertext. The server calculates the similarity between the second biometric ciphertext corresponding to the target identifier and the first biometric ciphertext to obtain a similarity ciphertext. d The similarity ciphertext is decrypted to obtain the similarity plaintext. The similarity plaintext corresponding to each target identifier is compared with a preset similarity threshold. The similarity plaintext greater than or equal to the preset similarity threshold is determined as the target similarity, and the target identifier corresponding to the target similarity is determined as the target identifier that has passed identity authentication. Therefore, based on the identity authentication result, it can be determined that the target object has passed identity authentication.
[0113] In operation S613, the server sends an identity authentication result to the terminal to indicate that the target object identity authentication has passed.
[0114] Figure 7 The following schematically shows a flow chart of an authentication method according to another embodiment of the present disclosure.
[0115] like Figure 7 As shown, the authentication method can be applied to a terminal, and the authentication method includes operations S710 to S740.
[0116] In operation S710 , feature extraction is performed on the biometric attribute data of the target object to obtain a biometric feature of the target object.
[0117] In operation S720, the target object's biometric feature is encrypted to obtain a first biometric feature ciphertext.
[0118] In operation S730 , an authentication request is determined based on the first biometric ciphertext and the first object identification ciphertext, where the first object identification ciphertext is determined by updating a first Bloom filter based on the object identification of the target object.
[0119] In operation S740 , an authentication request is sent to the server.
[0120] The technical terms involved in the authentication method applied to the terminal provided in the embodiment of the present disclosure may have the same or corresponding attributes as the technical terms involved in the authentication method applied to the server provided in the embodiment of the present disclosure, and the embodiments of the present disclosure will not be repeated here.
[0121] The authentication request determined by the authentication method applied to the terminal provided in the embodiment of the present disclosure can be sent to the server, and the server can process the authentication request based on the authentication method provided in the embodiment of the present disclosure to obtain the identity authentication result of the target object.
[0122] According to an embodiment of the present disclosure, the first object identification ciphertext is determined based on the following operations: processing the object identification based on the first hash function of the first Bloom filter to obtain a first identification hash value; determining the third to-be-updated bit corresponding to the first identification hash value from the first initial bit array of the first Bloom filter; and updating the initial bit character of the third to-be-updated bit based on the target bit character to obtain the first object identification ciphertext.
[0123] According to an embodiment of the present disclosure, the third bit to be updated can be the first initial bit in the first initial bit array that has a mapping relationship with the first identification hash value. The target bit character or the initial bit character can be different characters. By updating the third bit to be updated in the first initial bit array to the target bit character, the updated bit array can be used as the first object identification ciphertext.
[0124] According to an embodiment of the present disclosure, updating the initial position character of the third position to be updated based on the target position character to obtain the first object identification ciphertext includes: updating the initial position character of the third position to be updated to the target position character to obtain the first initial object identification ciphertext; and updating the initial position characters of other positions to be updated except the third position to be updated in the first initial object identification ciphertext based on the target position character to obtain the first object identification ciphertext.
[0125] According to an embodiment of the present disclosure, the first initial object identification ciphertext may be an object identification for representing a target object. By updating the initial position characters of the positions to be updated, except for the third position to be updated, in the first initial object identification ciphertext to target position characters, the object identifications of other objects may be obfuscated in the first object identification ciphertext. The server matches the second object identification ciphertext with the first object identification ciphertext, and the identification matching result obtained can represent the object identification of the target object and the object identifications of other objects, thereby preventing the server from determining the true object identification of the target object that the terminal needs to authenticate, thereby improving the privacy security of the terminal's intention to authenticate the target object.
[0126] Figure 8 The block diagram schematically shows an authentication processing device according to an embodiment of the present disclosure.
[0127] like Figure 8 As shown, the authentication device 800 includes: a first determination module 810 , a second determination module 820 and an authentication module 830 .
[0128] The first determining module 810 is configured to determine a first biometric ciphertext and a first object identification ciphertext according to an authentication request from a terminal, wherein the first object identification ciphertext is determined by updating a first Bloom filter based on an object identification of a target object.
[0129] The second determination module 820 is used to determine a target identifier that matches the object identifier from a preset identifier set based on an identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext, wherein the second object identifier ciphertext is determined by updating the first Bloom filter based on a preset identifier in the preset identifier set.
[0130] The authentication module 830 is configured to determine an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier.
[0131] According to an embodiment of the present disclosure, the second object identification ciphertext is determined based on the following operations: processing the target identification based on the first hash function of the first Bloom filter to obtain a second identification hash value; determining the first to-be-updated bit corresponding to the second identification hash value from the first initial bit array of the first Bloom filter; and updating the initial bit character of the first to-be-updated bit to the target bit character to obtain the second object identification ciphertext.
[0132] According to an embodiment of the present disclosure, the second biometric ciphertext is determined by updating the second Bloom filter based on the preset object biometric corresponding to the target identifier; the first biometric ciphertext is determined by the terminal based on updating the second Bloom filter based on the target object biometric, and the target object biometric is determined based on the object biological attribute data of the target object.
[0133] According to an embodiment of the present disclosure, the first biometric ciphertext is determined by the terminal by updating the second Bloom filter based on the target object biometric feature of the target object; wherein the second biometric ciphertext is determined based on the following operations: feature extraction of preset biometric attribute data corresponding to the target identifier to obtain the preset object biometric feature; processing the preset object biometric feature based on the second hash function of the second Bloom filter to obtain a second biometric hash value; determining the second to-be-updated bit corresponding to the second biometric hash value from the second initial bit array of the second Bloom filter; and updating the initial bit character of the second to-be-updated bit to the target bit character to obtain the second biometric ciphertext.
[0134] According to an embodiment of the present disclosure, the second biometric ciphertext is determined by encrypting the preset object biometric corresponding to the target identifier based on the public key, and the preset object biometric is determined by feature compression of the preset biometric attribute data corresponding to the target identifier; the first biometric ciphertext is determined by encrypting the target object biometric based on the public key by the terminal, and the target object biometric is determined by feature compression of the object biometric attribute data of the target object by the terminal.
[0135] According to an embodiment of the present disclosure, the feature matching result is determined based on the following operations: performing similarity calculation on the first biometric ciphertext and the second biometric ciphertext to obtain a similarity ciphertext; decrypting the similarity ciphertext to obtain a similarity plaintext; and determining the feature matching result based on the similarity plaintext.
[0136] According to an embodiment of the present disclosure, the authentication device 800 further includes: an identification subset obtaining module, a modular operation result obtaining module, and a third determination module.
[0137] The identification subset obtaining module is used to perform hash segmentation on the preset identification set to obtain multiple identification subsets, and the identification subsets have partition attribute values.
[0138] The module for obtaining a modular operation result is configured to perform a modular operation on a first object hash value from a terminal based on the number of the identifier subsets to obtain a modular operation result, wherein the first object hash value is obtained by performing a hash operation on the object identifier.
[0139] The third determination module is used to determine a candidate identifier subset from multiple identifier subsets based on the matching result between the modular operation result and the partition attribute value, wherein the candidate identifier subset includes multiple candidate identifiers, and the identifier matching result is obtained by matching the first object identifier ciphertext with the second candidate object identifier ciphertext corresponding to the candidate identifier.
[0140] According to an embodiment of the present disclosure, the first hash function of the first Bloom filter is different from the second hash function of the second Bloom filter.
[0141] According to an embodiment of the present disclosure, the data length of the first initial bit array of the first Bloom filter is different from the data length of the second initial bit array of the second Bloom filter.
[0142] According to an embodiment of the present disclosure, the first biometric ciphertext is related to at least one of the following biometric attribute data: facial image data, fingerprint image data, palm print image data, and iris data.
[0143] Figure 9 The following schematically shows a block diagram of an authentication processing device according to another embodiment of the present disclosure.
[0144] like Figure 9As shown, the authentication device 900 includes: a target object biometric feature acquisition module 910, an encryption module 920, a fourth determination module 930 and a sending module 940.
[0145] The target object biometric feature acquisition module 910 is used to extract features from the target object's biometric attribute data to obtain the target object's biometric features.
[0146] The encryption module 920 is configured to encrypt the biometric feature of the object to obtain a first biometric feature ciphertext.
[0147] a fourth determining module 930, configured to determine an authentication request based on the first biometric ciphertext and the first object identification ciphertext, where the first object identification ciphertext is determined by updating the first Bloom filter based on the object identification of the target object; and
[0148] The sending module 940 is used to send an authentication request to the server.
[0149] According to an embodiment of the present disclosure, the first object identification ciphertext is determined based on the following operations: processing the object identification based on the first hash function of the first Bloom filter to obtain a first identification hash value; determining the third to-be-updated bit corresponding to the first identification hash value from the first initial bit array of the first Bloom filter; and updating the initial bit character of the third to-be-updated bit based on the target bit character to obtain the first object identification ciphertext.
[0150] According to an embodiment of the present disclosure, updating the initial position character of the third position to be updated based on the target position character to obtain the first object identification ciphertext includes: updating the initial position character of the third position to be updated to the target position character to obtain the first initial object identification ciphertext; and updating the initial position characters of other positions to be updated except the third position to be updated in the first initial object identification ciphertext based on the target position character to obtain the first object identification ciphertext.
[0151] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0152] According to an embodiment of the present disclosure, an electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method described above.
[0153] According to an embodiment of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to execute the method described above.
[0154] According to an embodiment of the present disclosure, a computer program product includes a computer program, and when the computer program is executed by a processor, the computer program implements the method described above.
[0155] Figure 10 A schematic block diagram of an example electronic device that can be used to implement the authentication method of an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0156] like Figure 10 As shown, device 1000 includes a computing unit 1001, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 1002 or a computer program loaded from a storage unit 1008 into a random access memory (RAM) 1003. RAM 1003 may also store various programs and data required for the operation of device 1000. Computing unit 1001, ROM 1002, and RAM 1003 are connected to each other via a bus 1004. An input / output (I / O) interface 1005 is also connected to bus 1004.
[0157] Various components in device 1000 are connected to I / O interface 1005, including an input unit 1006, such as a keyboard, mouse, etc.; an output unit 1007, such as various types of displays, speakers, etc.; a storage unit 1008, such as a magnetic disk, optical disk, etc.; and a communication unit 1009, such as a network card, modem, wireless communication transceiver, etc. The communication unit 1009 allows device 1000 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0158] Computing unit 1001 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of computing unit 1001 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Computing unit 1001 performs the various methods and processes described above, such as the authentication method. For example, in some embodiments, the authentication method may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 1008. In some embodiments, part or all of the computer program may be loaded and / or installed onto device 1000 via ROM 1002 and / or communication unit 1009. When the computer program is loaded into RAM 1003 and executed by computing unit 1001, one or more steps of the authentication method described above may be performed. Alternatively, in other embodiments, computing unit 1001 may be configured to perform the authentication method via any other suitable means (e.g., via firmware).
[0159] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0160] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0161] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0162] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0163] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0164] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.
[0165] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.
[0166] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.
Claims
1. An authentication method, comprising: Determining, based on an authentication request from a terminal, a first biometric ciphertext and a first object identifier ciphertext, wherein the first object identifier ciphertext is determined by processing an object identifier of a target object using a first hash function of a first Bloom filter to obtain a hash value, and mapping the hash value to a position in a first initial bit array of the first Bloom filter; Based on an identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext, a target identifier that matches the object identifier is determined from a preset identifier set, and the second object identifier ciphertext is determined based on the following operations: processing the target identifier based on the first hash function to obtain a second identifier hash value; determining a first to-be-updated bit corresponding to the second identifier hash value from a first initial bit array of the first Bloom filter; and updating the initial bit character of the first to-be-updated bit to the target bit character to obtain the second object identifier ciphertext; An identity authentication result of the target object is determined based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier.
2. The method according to claim 1, wherein The second biometric ciphertext is determined by updating a second Bloom filter based on a preset object biometric corresponding to the target identifier; The first biometric ciphertext is determined by the terminal by updating the second Bloom filter based on a biometric characteristic of a target object, where the biometric characteristic of the target object is determined based on object biometric attribute data of the target object.
3. The method according to claim 2, wherein: The first biometric ciphertext is determined by the terminal updating the second Bloom filter based on the target object biometric feature of the target object; The second biometric ciphertext is determined based on the following operations: Extracting features from preset biological attribute data corresponding to the target identifier to obtain preset object biological features; Processing the preset object biometric feature with a second hash function based on the second Bloom filter to obtain a second biometric feature hash value; Determining a second to-be-updated bit corresponding to the second biometric hash value from a second initial bit array of the second Bloom filter; and The initial position character of the second position to be updated is updated to the target position character to obtain the second biometric feature ciphertext.
4. The method according to claim 2, wherein: The first hash function of the first Bloom filter is different from the second hash function of the second Bloom filter; and / or The data length of the first initial bit array of the first Bloom filter is different from the data length of the second initial bit array of the second Bloom filter.
5. The method according to claim 1, wherein The second biometric ciphertext is determined by encrypting a preset object biometric feature corresponding to the target identifier based on a public key, wherein the preset object biometric feature is determined by compressing preset biometric attribute data corresponding to the target identifier; The first biometric ciphertext is determined by the terminal encrypting the biometric of the target object based on the public key, and the biometric of the target object is determined by the terminal performing feature compression on the biometric attribute data of the target object.
6. The method according to claim 1 or 5, wherein: The feature matching result is determined based on the following operations: Calculating similarity between the first biometric ciphertext and the second biometric ciphertext to obtain a similarity ciphertext; Decrypting the similarity ciphertext to obtain similarity plaintext; as well as Based on the similarity plaintext, the feature matching result is determined.
7. The method according to claim 1, wherein The first biometric ciphertext is related to at least one of the following biometric attribute data: Facial image data, fingerprint image data, palm print image data, iris data.
8. The method according to claim 1, further comprising: Performing hash segmentation on the preset identifier set to obtain a plurality of identifier subsets, each of which has a partition attribute value; performing a modulo operation on a first object hash value from the terminal based on the number of the identifier subsets to obtain a modulo operation result, wherein the first object hash value is obtained by performing a hash operation on the object identifier; as well as Based on the matching result between the modular operation result and the partition attribute value, a candidate identifier subset is determined from the multiple identifier subsets, wherein the candidate identifier subset includes multiple candidate identifiers, and the identifier matching result is obtained by matching the first object identifier ciphertext with the second candidate object identifier ciphertext corresponding to the candidate identifier.
9. An authentication method, comprising: Extracting features from the biological attribute data of the target object to obtain biological features of the target object; Encrypting the target object's biometric feature to obtain a first biometric feature ciphertext; determining an authentication request based on the first biometric ciphertext and a first object identifier ciphertext, where the first object identifier ciphertext is determined by processing an object identifier of a target object using a first hash function of a first Bloom filter to obtain a hash value, and mapping the hash value to a position in a first initial bit array of the first Bloom filter; as well as Sending the authentication request to the server; The server determines, based on the authentication request, a first biometric ciphertext and a first object identifier ciphertext; determines, from a preset identifier set, a target identifier that matches the object identifier based on an identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext; and determines an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier; The second object identifier ciphertext is determined based on the following operations: processing the target identifier based on the first hash function to obtain a second identifier hash value; determining a first to-be-updated bit corresponding to the second identifier hash value from a first initial bit array of the first Bloom filter; and updating the initial bit character of the first to-be-updated bit to a target bit character to obtain the second object identifier ciphertext.
10. The method according to claim 9, wherein: The first object identification ciphertext is determined based on the following operations: Processing the object identifier based on a first hash function of the first Bloom filter to obtain a first identifier hash value; Determining a third to-be-updated bit corresponding to the first identification hash value from a first initial bit array of the first Bloom filter; and The initial bit character of the third bit to be updated is updated based on the target bit character to obtain the first object identification ciphertext.
11. The method according to claim 10, wherein: The updating of the initial bit character of the third to-be-updated bit based on the target bit character to obtain the first object identifier ciphertext includes: Updating the initial position character of the third position to be updated to the target position character to obtain a first initial object identification ciphertext; and The initial bit characters of the bits to be updated except the third bit to be updated in the first initial object identification ciphertext are updated based on the target bit character to obtain the first object identification ciphertext.
12. An authentication device comprising: a first determining module, configured to determine, based on an authentication request from a terminal, a first biometric ciphertext and a first object identifier ciphertext, wherein the first object identifier ciphertext is determined by processing an object identifier of a target object using a first hash function of a first Bloom filter to obtain a hash value, and mapping the hash value to a position in a first initial bit array of the first Bloom filter; a second determining module, configured to determine a target identifier that matches the object identifier from a preset identifier set based on an identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext; an authentication module, configured to determine an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier; The second object identifier ciphertext is determined based on the following operations: Processing the target identifier based on a first hash function of the first Bloom filter to obtain a second identifier hash value; Determine a first to-be-updated bit corresponding to the second identification hash value from a first initial bit array of the first Bloom filter; as well as The initial bit character of the first bit to be updated is updated to the target bit character to obtain the second object identifier ciphertext.
13. The device according to claim 12, wherein The second biometric ciphertext is determined by updating a second Bloom filter based on a preset object biometric corresponding to the target identifier; The first biometric ciphertext is determined by the terminal by updating the second Bloom filter based on a biometric characteristic of a target object, where the biometric characteristic of the target object is determined based on object biometric attribute data of the target object.
14. The device according to claim 13, wherein The first biometric ciphertext is determined by the terminal updating the second Bloom filter based on the target object biometric feature of the target object; The second biometric ciphertext is determined based on the following operations: Extracting features from preset biological attribute data corresponding to the target identifier to obtain preset object biological features; Processing the preset object biometric feature with a second hash function based on the second Bloom filter to obtain a second biometric feature hash value; Determining a second to-be-updated bit corresponding to the second biometric hash value from a second initial bit array of the second Bloom filter; and The initial position character of the second position to be updated is updated to the target position character to obtain the second biometric feature ciphertext.
15. The device according to claim 12, wherein The second biometric ciphertext is determined by encrypting a preset object biometric corresponding to the target identifier based on a public key, and the preset object biometric is determined by feature compression of preset biometric attribute data corresponding to the target identifier; The first biometric ciphertext is determined by the terminal encrypting the biometric of the target object based on the public key, and the biometric of the target object is determined by the terminal performing feature compression on the biometric attribute data of the target object.
16. The device according to claim 12 or 15, wherein The feature matching result is determined based on the following operations: Calculating similarity between the first biometric ciphertext and the second biometric ciphertext to obtain a similarity ciphertext; Decrypting the similarity ciphertext to obtain similarity plaintext; as well as Based on the similarity plaintext, the feature matching result is determined.
17. The apparatus according to claim 12, further comprising: An identification subset obtaining module, configured to perform hash segmentation on the preset identification set to obtain a plurality of identification subsets, each of which has a partition attribute value; a modular operation result obtaining module, configured to perform a modular operation on a first object hash value from the terminal based on the number of the identifier subset to obtain a modular operation result, wherein the first object hash value is obtained by performing a hash operation on the object identifier; as well as A third determination module is used to determine a candidate identifier subset from the multiple identifier subsets based on the matching result between the modular operation result and the partition attribute value, wherein the candidate identifier subset includes multiple candidate identifiers, and the identifier matching result is obtained by matching the first object identifier ciphertext with the second candidate object identifier ciphertext corresponding to the candidate identifier.
18. An authentication device comprising: The target object biometric feature acquisition module is used to extract the feature of the target object's biometric attribute data to obtain the target object's biometric features; an encryption module, configured to encrypt the biometric characteristic of the object to obtain a first biometric characteristic ciphertext; a fourth determining module, configured to determine an authentication request based on the first biometric ciphertext and a first object identifier ciphertext, wherein the first object identifier ciphertext is determined by processing an object identifier of a target object using a first hash function of the first Bloom filter to obtain a hash value, and mapping the hash value to a position in a first initial bit array of the first Bloom filter; as well as A sending module, configured to send the authentication request to the server; The server determines, based on the authentication request, a first biometric ciphertext and a first object identifier ciphertext; determines, from a preset identifier set, a target identifier that matches the object identifier based on an identifier matching result between the first object identifier ciphertext and the second object identifier ciphertext; and determines an identity authentication result of the target object based on a feature matching result between the first biometric ciphertext and a second biometric ciphertext associated with the target identifier; The second object identifier ciphertext is determined based on the following operations: processing the target identifier based on the first hash function to obtain a second identifier hash value; determining a first to-be-updated bit corresponding to the second identifier hash value from a first initial bit array of the first Bloom filter; and updating the initial bit character of the first to-be-updated bit to a target bit character to obtain the second object identifier ciphertext.
19. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 11.
20. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 11.
21. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
Identity authentication method and system based on biological identifier
CN110391908A
Privacy-protecting identity information storage method and device and privacy-protecting identity authentication method and device
CN112926092A