Vehicle starting method and system based on face recognition

By using technologies such as non-networked communication verification, face recognition and partial data collaborative signature in the vehicle startup system, the security risks of traditional vehicle startup methods and the single identity verification and data leakage problems of existing facial recognition systems are solved, and higher vehicle startup security and data transmission security are achieved.

CN119734660BActive Publication Date: 2025-05-16杭州乾丰电子有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510253967.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-16
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

Traditional vehicle startup methods have security risks, such as missing keys, stolen or illegally copied, and the existing vehicle startup method based on facial recognition is single, the risk of data leakage during image recognition is high, and it is easy to be forged images or confronted with sample attacks.

Method used

The first paging signal sent by the car owner terminal is communicated with the start control device, establish a non-network connection, and send preset unlock secret questions and face recognition instructions. The car owner terminal performs facial recognition and sends identification information and secret questions to the cloud through some data collaborative signatures. After the cloud is authorized to verify permissions, the cloud is returned to the secret problem solving data, and the start control device is received and matched to unlock, and start the vehicle.

Benefits of technology

Improve the safety of vehicle startup, prevent unauthorized personnel from starting the vehicle remotely, ensure that only authorized owners can start the vehicle, reduce the risk of vehicle theft, and improve the safety and efficiency of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119734660B_ABST
    Figure CN119734660B_ABST
Patent Text Reader

Abstract

The embodiment of this specification discloses a vehicle starting method and system based on face recognition. Among them, the vehicle starting method based on face recognition includes the starting control device communicating with the car owner terminal through the first paging signal sent by the car owner terminal based on the non-networked state; the starting control device sends the preset unlocking secret and face recognition instructions to the car owner terminal; the car owner terminal triggers face recognition according to the face recognition instruction, and sends the identification information and the preset unlocking secret to the cloud based on the partial data collaborative signature; the cloud performs authority verification according to the identification information, and sends the secret solution data to the car owner terminal after the authority verification is passed; the starting control device receives the secret solution data sent by the car owner terminal, and when the secret solution data matches the preset unlocking secret, the vehicle is started. The embodiment of this specification effectively ensures the security and efficiency of data transmission, while improving the security of vehicle startup.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present specification relate to the field of vehicle safety technology, and specifically to a vehicle starting method and system based on face recognition. Background Art

[0002] With the continuous improvement of social economy, cars have become a means of transportation for people's daily use. Traditional vehicle starting methods generally rely on mechanical keys, remote control keys or card keys, but there are still certain safety hazards, such as key loss, theft or illegal copying, etc. Once these problems occur, they may lead to problems such as vehicle theft. Therefore, the traditional vehicle starting method is relatively unsafe, and the driver needs to carry the corresponding key to start the vehicle, which is relatively inconvenient. In addition, the existing vehicle starting method based on face recognition system only sets up a face recognition chip to authenticate the current car user. The authentication of this method is relatively simple. During the image recognition process, personal facial features and behavior data are collected. If there are no strict regulatory measures, these data may be abused or leaked. If the vehicle's remote starting system only relies on image recognition for identity authentication, attackers may bypass identity authentication by forging images or using adversarial sample attacks, and use these vulnerabilities to remotely control the vehicle. Therefore, there is an urgent need for a vehicle starting method based on face recognition that can improve the safety of vehicle startup. Summary of the invention

[0003] The embodiments of this specification provide a vehicle starting method and system based on face recognition, and the technical solution is as follows:

[0004] In a first aspect, an embodiment of the present specification provides a vehicle starting method based on face recognition, including: the vehicle starting control device, based on a non-networked state, communicates with the car owner terminal through a first paging signal sent by the car owner terminal, and establishes a communication connection with the car owner terminal after the communication verification is passed; the starting control device sends a preset unlocking secret and a face recognition instruction to the car owner terminal; the car owner terminal triggers face recognition according to the face recognition instruction, and sends the identification information and the preset unlocking secret to the cloud based on a partial data collaborative signature; the cloud performs authority verification based on the identification information, and sends the secret solution data corresponding to the preset unlocking secret to the car owner terminal after the authority verification is passed; the starting control device receives the secret solution data sent by the car owner terminal, and starts the vehicle when the secret solution data matches the preset unlocking secret.

[0005] On the second aspect, the embodiments of the present specification provide a vehicle starting system based on face recognition, including: a starting control device, which is used to communicate and verify with the car owner terminal through a first paging signal sent by the car owner terminal based on a non-networked state, and establish a communication connection with the car owner terminal after the communication verification is passed; send a preset unlocking secret question and a face recognition instruction to the car owner terminal; receive the secret question solution data sent by the car owner terminal, and start the vehicle when the secret question solution data matches the preset unlocking secret question; the car owner terminal is used to trigger face recognition according to the face recognition instruction, and send the identification information and the preset unlocking secret question to the cloud based on the collaborative signature of partial data; the cloud is used to perform authority verification according to the identification information, and send the secret question solution data corresponding to the preset unlocking secret question to the car owner terminal after the authority verification is passed.

[0006] The beneficial effects brought by the technical solutions provided by some embodiments of this specification include at least:

[0007] The starting control device of the vehicle in the embodiment of the present specification can perform communication verification with the vehicle owner terminal based on the non-networked state through the first paging signal sent by the vehicle owner terminal, and establish a communication connection with the vehicle owner terminal after the communication verification is passed; the starting control device then sends a preset unlocking secret and a face recognition instruction to the vehicle owner terminal; then the vehicle owner terminal triggers face recognition according to the face recognition instruction, and sends the identification information and the preset unlocking secret to the cloud based on the partial data collaborative signature; the cloud then performs authority verification based on the identification information, and sends the secret solution data corresponding to the preset unlocking secret to the vehicle owner terminal after the authority verification is passed; then the starting control device receives the secret solution data sent by the vehicle owner terminal, and starts the vehicle when the secret solution data matches the preset unlocking secret.

[0008] The vehicle startup control device of the embodiment of the present specification is based on a point-to-point communication verification connection with the vehicle owner terminal through the first paging signal sent by the vehicle owner terminal corresponding to the vehicle owner in a non-networked state, thereby avoiding the problem that after the key is lost, stolen or illegally copied, non-vehicle owners can directly remotely start the vehicle through other terminal devices through the network. At the same time, it is determined through the first paging signal that the communication connection can only be made after the communication verification between the vehicle owner terminal and the startup control device is successful, so that only the authorized vehicle owner terminal can establish a connection with the startup control device, eliminating the risk of vehicle theft; in addition, the vehicle owner terminal of the embodiment of the present specification sends the identification information and the preset unlocking secret question to the cloud based on the partial data collaborative signature, which not only ensures that only the authorized vehicle owner terminal can transmit data with the cloud, but also improves the security and efficiency of data transmission; then the cloud of the embodiment of the present specification performs authority verification based on the identification information, and after the authority verification is passed, the secret question solution data corresponding to the preset unlocking secret question is sent to the vehicle owner terminal. The embodiment of the present specification further verifies the vehicle owner information and the vehicle owner terminal information in the cloud, thereby improving the security of vehicle startup and reducing the risk of vehicle theft. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the embodiments of this specification, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0010] Figure 1 This is a schematic diagram of an application scenario of a vehicle starting method based on face recognition provided in this manual.

[0011] Figure 2 This is a flow chart of a vehicle starting method based on face recognition provided in this manual.

[0012] Figure 3 This is a flowchart of establishing a connection between the startup control device and the vehicle owner terminal provided in this manual.

[0013] Figure 4 This manual provides a flowchart of the vehicle owner terminal triggering face recognition according to the face recognition command.

[0014] Figure 5 This is a flowchart of sending identification information and preset unlocking questions to the cloud based on partial data collaborative signature provided in this manual.

[0015] Figure 6 This is a flow chart of the vehicle owner terminal sending the first data to the cloud through collaborative signature provided in this manual.

[0016] Figure 7 This is a flow chart of the vehicle owner terminal encrypting and sending the second data to the cloud provided in this manual.

[0017] Figure 8 This is a structural diagram of a vehicle starting system based on face recognition provided in this manual.

[0018] Fig. 9 This is a structural diagram of an electronic device based on a startup control device provided in this specification. DETAILED DESCRIPTION

[0019] The technical solutions in the embodiments of this specification will be described clearly and completely below in conjunction with the drawings in the embodiments of this specification.

[0020] The terms "first", "second", etc. in the description and claims of this specification and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variation thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device comprising a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices.

[0021] The vehicle starting method based on face recognition provided in multiple embodiments of this specification can be executed by the vehicle starting system based on face recognition provided in an embodiment of the present invention.

[0022] Before elaborating on the vehicle starting method based on face recognition in detail in combination with one or more embodiments, this specification first introduces the application scenarios of the vehicle starting method based on face recognition.

[0023] See also Figure 1 , Figure 1 Schematic diagram of application scenarios of the vehicle startup method based on face recognition provided in an embodiment of the present invention. In this embodiment, the vehicle startup system 100 based on face recognition may include a vehicle startup control device 110, a vehicle owner terminal 120, an image acquisition module 122, a cloud 130, and a certificate issuing authority 140. The vehicle startup control device 110 is connected to the vehicle owner terminal 120 in a non-networked state, the image acquisition module 122 is built in the vehicle owner terminal 120, the vehicle owner terminal 120 is connected to the cloud 130, and the certificate issuing authority 140 is connected to the vehicle owner terminal 120 and the cloud 130 respectively.

[0024] In this embodiment, the vehicle owner terminal 120 can be a mobile phone, a tablet computer, a smart Bluetooth device, a laptop computer, or a personal computer (PC) and the like. The vehicle owner terminal 120 is provided with an image acquisition module 122, and the vehicle owner terminal 120 calls the image acquisition module 122 according to the face recognition instruction. The image acquisition module 122 can acquire an image, locate the face position in the image, mark the face area by the face position; pre-process the face area to obtain a pre-processed face image; extract the key features of the pre-processed face image; encode the key features into a feature vector corresponding to the face image, and the like.

[0025] In this embodiment, the cloud 130 is used to provide various computing resources and services. The cloud 130 may include a cloud platform, etc. The cloud platform is used to provide a variety of services, including computing, storage, network, database, etc.

[0026] In this embodiment, the certificate authority (CA) is a trusted third-party organization that is responsible for issuing, authenticating and managing digital certificates. The certificate contains a public key and identity information, which is used to verify identity and encrypt communication. The vehicle owner terminal 120 of this embodiment can request the certificate authority to issue a digital certificate and send the digital certificate to the cloud 130. After the cloud 130 verifies that the digital certificate is passed, it returns a certificate pass instruction to the vehicle owner terminal 120.

[0027] In this embodiment, the vehicle's startup control device 110 can perform communication verification with the vehicle owner terminal 120 based on a non-networked state through a first paging signal sent by the vehicle owner terminal 120, and establish a communication connection with the vehicle owner terminal 120 after the communication verification is passed; the startup control device 110 then sends a preset unlocking secret and a face recognition instruction to the vehicle owner terminal 120; then the vehicle owner terminal 120 triggers face recognition according to the face recognition instruction, and sends the identification information and the preset unlocking secret to the cloud 130 based on the partial data collaborative signature; the cloud 130 then performs authority verification based on the identification information, and sends the secret solution data corresponding to the preset unlocking secret to the vehicle owner terminal 120 after the authority verification is passed; then the startup control device 110 receives the secret solution data sent by the vehicle owner terminal 120, and when the secret solution data matches the preset unlocking secret, the vehicle is started, etc.

[0028] It should be noted that Figure 1 The scenario diagram of the vehicle starting system based on face recognition shown is merely an example. The vehicle starting system based on face recognition and the scenario described in the embodiment of the present invention are intended to more clearly illustrate the technical solution of the embodiment of the present invention, and do not constitute a limitation on the technical solution provided by the embodiment of the present invention. A person of ordinary skill in the art can know that with the evolution of the vehicle starting system based on face recognition and the emergence of new scenarios, the technical solution provided by the embodiment of the present invention is also applicable to similar technical problems.

[0029] See also Figure 2 , Figure 2 is a flow chart of a vehicle starting method based on face recognition provided by an embodiment of the present invention. The vehicle starting method based on face recognition can be Figure 1 The vehicle starting system 100 based on face recognition is shown. The vehicle starting method based on face recognition may at least include the following steps:

[0030] 200. The vehicle startup control device performs communication verification with the vehicle owner terminal based on a non-networked state through a first paging signal sent by the vehicle owner terminal, and establishes a communication connection with the vehicle owner terminal after the communication verification passes.

[0031] In this embodiment, the vehicle startup control device 110 can be connected to the vehicle's electronic control unit (Electronic Control Unit, ECU). The startup control device 110 of this embodiment does not have an Internet access function, and the startup control device 110 can include a communication module, etc. The communication module can include a Bluetooth module, an NFC module, a ZigBee module, a UWB module, etc. The communication module can also support multiple modules of the Bluetooth module, the NFC module, the ZigBee module, and the UWB module at the same time.

[0032] In this embodiment, the vehicle owner terminal 120 may support a communication module corresponding to the start control device 110. For example, the communication module of the start control device 110 may include a Bluetooth module, and the vehicle owner terminal 120 may support a Bluetooth module corresponding to the start control device 110; the communication module of the start control device 110 may include a Bluetooth module, an NFC module, and a UWB module, and the vehicle owner terminal 120 may support a Bluetooth module, an NFC module, and a UWB module corresponding to the start control device 110.

[0033] In this embodiment, the communication module may include a Bluetooth module, an NFC module, a ZigBee module, and a UWB module. When the owner's terminal is far away from the vehicle, the start-up control device 110 can perform preliminary identity authentication and preliminary positioning through the Bluetooth module. When the owner's terminal is close to the vehicle and is at a preset distance from the vehicle, the start-up control device 110 can switch to the UWB module and perform high-precision real-time ranging and precise positioning through UWB technology; when the Bluetooth module and the UWB module fail to work due to a malfunction, the NFC module and the ZigBee module serve as emergency backup communication modules, and the start-up control device 110 can communicate with the owner's terminal 120 through the NFC module or the ZigBee module.

[0034] In this embodiment, the start control device 110 can receive the first paging signal sent by the vehicle owner terminal 120 in a non-networked state, and perform communication verification with the vehicle owner terminal through the first paging signal, and establish a communication connection with the vehicle owner terminal after the communication verification passes.

[0035] In this embodiment, the startup control device 110 can receive paging signals sent by several different terminals. The paging signals can be broadcast signals sent by several different terminals to the startup control device 110 before establishing a connection. The paging signals are used to notify the startup control device 110 of the existence of the terminal and the preparation for establishing a connection.

[0036] In this embodiment, the first paging signal may be a broadcast signal sent by the vehicle owner terminal corresponding to the vehicle to the start control device 110. In this embodiment, the first paging signal sent by the vehicle owner terminal is received, and communication verification is performed with the vehicle owner terminal through the first paging signal, and a communication connection is established with the vehicle owner terminal after the communication verification is passed.

[0037] The start control device 110 of the embodiment of the present specification performs point-to-point communication verification connection with the vehicle owner terminal 120 through the first paging signal sent by the vehicle owner terminal 120 corresponding to the vehicle owner in a non-networked state. The start control device 110 may not have an Internet access function, thereby avoiding the problem of non-vehicle owners directly remotely starting the vehicle through other terminal devices after the key is lost, stolen or illegally copied. At the same time, the first paging signal is used to determine that a communication connection can only be established after the communication verification between the vehicle owner terminal 120 and the start control device 110 is successful, so that only the authorized vehicle owner terminal can establish a connection with the start control device 110, eliminating the risk of vehicle theft.

[0038] In some embodiments, see Figure 3 , Figure 3 The present invention is a flowchart of establishing a connection between the startup control device 110 and the vehicle owner terminal 120 provided by an embodiment of the present invention. The vehicle startup control device performs communication verification with the vehicle owner terminal through a first paging signal sent by the vehicle owner terminal based on a non-networked state, and establishes a communication connection with the vehicle owner terminal after the communication verification passes, including:

[0039] 300. Start the control device to scan a number of paging signals;

[0040] 310. When the start control device determines that a certain paging signal among the plurality of paging signals contains an identification address corresponding to the start control device and the vehicle owner terminal, the certain paging signal is marked as the first paging signal sent by the vehicle owner terminal, and the communication verification between the start control device and the vehicle owner terminal is passed;

[0041] 320. The startup control device sends response information corresponding to the first paging signal to the vehicle owner terminal, and the vehicle owner terminal establishes a connection with the startup control device according to the response information.

[0042] In this embodiment, the first paging signal may be a broadcast signal sent by the vehicle owner terminal corresponding to the vehicle to the start control device 110, and the first paging signal may include an identification address. The identification address in this embodiment may be an address that can identify both the start control device 110 and the vehicle owner terminal 120.

[0043] In some embodiments, the identification address may include the MAC address of the vehicle owner's terminal and the MAC address of the vehicle's startup control device.

[0044] In this embodiment, the MAC address of the vehicle owner terminal 120 may be a unique hardware identifier corresponding to the vehicle owner terminal 120 , and the MAC address of the startup control device 110 may be a unique hardware identifier corresponding to the startup control device 110 .

[0045] The startup control device 110 of this embodiment can scan a plurality of paging signals and identify a first paging signal sent by the vehicle owner terminal from the plurality of paging signals. For example, when a certain paging signal among the plurality of paging signals is the same as an identification address pre-stored in the startup control device, the certain paging signal is used as the first paging signal. In addition, the startup control device 110 of this embodiment can send a response message corresponding to the first paging signal to the vehicle owner terminal, and the vehicle owner terminal then establishes a connection with the startup control device according to the response message.

[0046] The startup control device of this embodiment can determine through the first paging signal that only the authorized vehicle owner terminal (i.e., the vehicle owner terminal with the identification address) can successfully communicate with the startup control device, and a communication connection can be established only after the communication verification is successful, so that only the vehicle owner terminal corresponding to the vehicle can establish a connection with the startup control device, reducing the risk of vehicle theft.

[0047] In some embodiments, the vehicle startup control device is based on a non-networked state, and before the vehicle owner terminal is communicated and verified through a first paging signal sent by the vehicle owner terminal, the vehicle owner terminal and the startup control device respectively store identification addresses.

[0048] In this embodiment, the user can first store the identification address that can simultaneously identify the start control device 110 and the car owner terminal 120 into the start control device 110 and the car owner terminal 120 respectively. When the start control device 110 and the car owner terminal 120 perform communication verification, the start control device 110 can receive the first paging signal containing the identification address sent by the car owner terminal 120, and compare the identification address pre-stored in the start control device 110 with the first paging signal to determine whether the communication verification is successful.

[0049] In this embodiment, the identification address can be stored in advance in the start control device 110 and the vehicle owner terminal 120, respectively, to prevent other unauthorized terminals from illegally establishing a communication connection with the start control device 110, thereby reducing the occurrence of vehicle theft.

[0050] 210. The start control device sends a preset unlocking secret question and a face recognition command to the vehicle owner terminal.

[0051] In this embodiment, the preset unlocking secret question may be a vehicle unlocking secret question that is pre-stored in the start control device by the user. For example, the vehicle unlocking secret question may be one or more combination questions about numbers, graphics, special characters or text, etc.; the vehicle unlocking secret question may also be a biometric question, that is, unlocking using biometric features such as fingerprint, facial recognition, iris recognition, etc.

[0052] In this embodiment, the face recognition instruction may be an instruction sent by the startup control device to the vehicle owner terminal, which is capable of calling an image acquisition module in the vehicle owner terminal to trigger face recognition.

[0053] 220. The vehicle owner terminal triggers face recognition according to the face recognition command, and sends the recognition information and the preset unlocking secret to the cloud based on the partial data collaborative signature.

[0054] In some embodiments, see Figure 4 , Figure 4 The embodiment of the present invention provides a flow chart of the vehicle owner terminal triggering face recognition according to the face recognition instruction. The vehicle owner terminal 120 triggers face recognition according to the face recognition instruction and obtains recognition information, including:

[0055] 400. The vehicle owner terminal calls the image acquisition module according to the face recognition instruction;

[0056] The image acquisition module is used to:

[0057] 410. Collect an image, locate a face position in the image, and mark a face area according to the face position;

[0058] 420. Preprocess the face region to obtain a preprocessed face image;

[0059] 430. Extract key features of the preprocessed face image;

[0060] 440. Encode the key features into feature vectors corresponding to the face image.

[0061] In this embodiment, the identification information may include a feature vector corresponding to the face image, an identification address, and a vehicle owner terminal ID, etc. The image acquisition module 122 of this embodiment may be built into the vehicle owner terminal 120. After the vehicle owner terminal 120 receives the face recognition instruction sent by the start control device 110, the image acquisition module 122 may be called according to the face recognition instruction.

[0062] The image acquisition module 122 of the present embodiment can acquire images in real time through a camera until a face that meets the requirements is detected; then the face position is located in the image, the face area is marked by the face position, and then the acquired face image is preprocessed, including grayscale, normalization, contrast enhancement and other operations to improve the image quality; then the key features of the face, such as the geometric features and texture features of the facial features and other parts, are extracted through a deep learning algorithm (such as a convolutional neural network); then the key features of the preprocessed face image are extracted, and then the key features are encoded into a feature vector corresponding to the face image for subsequent uploading to the cloud 130 for comparison of identification information.

[0063] In some embodiments, see Figure 5 , Figure 5 The embodiment of the present invention provides a flowchart of sending identification information and preset unlocking secret questions to the cloud 130 based on partial data collaborative signature. The vehicle owner terminal triggers face recognition according to the face recognition instruction, and sends the identification information and preset unlocking secret questions to the cloud based on the partial data collaborative signature, including:

[0064] 500. The vehicle owner terminal requests the certificate authority to issue a digital certificate and sends the digital certificate to the cloud. After the cloud verifies the digital certificate, it returns a certificate approval instruction to the vehicle owner terminal.

[0065] 510. After receiving the certificate approval instruction, the vehicle owner terminal divides the vehicle verification data into first data and second data;

[0066] 520. The vehicle owner terminal performs collaborative signing with the cloud, and sends the first data after signature verification to the cloud;

[0067] 530. After the first data is sent, the vehicle owner terminal generates a first key pair to encrypt the second data and send it to the cloud.

[0068] In this embodiment, the vehicle verification data includes identification information and a preset unlocking question.

[0069] The partial data collaborative signature of this embodiment can be for the car owner terminal 120 to split the vehicle verification data into two parts, namely the first data and the second data. The car owner terminal 120 can collaboratively sign with the cloud 130 and send the first data after the signature verification to the cloud 130. After the first data is sent, the car owner terminal 120 generates a first key pair and encrypts the second data and sends it to the cloud 130.

[0070] Before the car owner terminal 120 and the cloud 130 of the embodiment of this specification perform collaborative signing of partial data, the mobile terminal 120 and the cloud 130 need to perform identity authentication, that is, the car owner terminal 120 sends the digital certificate issued by the certificate authority to the cloud 130, and the cloud 130 authenticates the identity of the mobile terminal 120 through the digital certificate to ensure that the identities of both parties are legitimate, thereby ensuring the authenticity of the identities of both parties and the confidentiality of the data between the car owner terminal 120 and the cloud 130.

[0071] The car owner terminal 120 of the embodiment of this specification sends the identification information and the preset unlocking secret to the cloud 130 based on the partial data collaborative signature, which not only ensures that only the authorized car owner terminal 120 and the cloud 130 can transmit data, but also improves the security and efficiency of data transmission. The car owner terminal 120 of the embodiment of this specification performs a collaborative signature with the cloud 130, and sends the first data after the signature verification to the cloud 130, which improves the security of data transmission and ensures that the communication between the car owner terminal 120 and the cloud 130 is encrypted. Then, after the first data is sent, the car owner terminal 120 generates a first key pair and encrypts the second data and sends it to the cloud 130, thereby further improving the efficiency of data transmission on the basis of ensuring the security of data transmission.

[0072] In some embodiments, the certificate authority is used to generate a second key pair, split the private key in the second key pair into a first private key fragment and a second private key fragment through a key splitting algorithm, and send the public key in the second key pair to the cloud; the first private key fragment is stored in the car owner terminal, and the second private key fragment is stored in the cloud.

[0073] In this embodiment, the second key pair is a private key generated by a certificate authority and a public key corresponding to the private key. The certificate authority in this embodiment of the specification is a third-party organization that is not only responsible for issuing, authenticating and managing digital certificates, but also can generate the second key pair.

[0074] The certificate issuing authority of the embodiment of the present specification can split the private key in the second key pair into two parts through a secure key splitting algorithm (such as Shamir key splitting algorithm), one part is stored in the vehicle owner terminal 120, and the other part is stored in the cloud 130. The embodiment of the present specification stores the split private key fragments (i.e., the first private key fragment and the second private key fragment) in the vehicle owner terminal 120 and the cloud 130 respectively, ensuring that only the authorized vehicle owner terminal and the cloud service can access these fragments. Even if the private key of one party is stolen, the attacker cannot complete the signing or decryption operation, thereby improving the security of the private key fragments during storage and transmission, ensuring the security of data transmission, and further improving the security of vehicle startup.

[0075] In some embodiments, see Figure 6 , Figure 6 The embodiment of the present invention provides a flow chart of a vehicle owner terminal sending first data to the cloud through collaborative signature. The vehicle owner terminal performs collaborative signature with the cloud and sends the first data after signature verification to the cloud, including:

[0076] 600. The vehicle owner terminal obtains a first hash value;

[0077] 610. The vehicle owner terminal sends the first hash value to the cloud;

[0078] 620. The cloud signs the first hash value using the second private key fragment to obtain a first partial signature, and sends the first partial signature to the vehicle owner terminal;

[0079] 630. The vehicle owner terminal signs the first hash value using the first private key fragment to obtain a second partial signature.

[0080] 640. The vehicle owner terminal combines the first signature with the second signature to generate a combined signature, and sends the combined signature and the first data to the cloud;

[0081] 650. The cloud verifies the combined signature using the public key in the second key pair. After the signature verification is successful, the cloud obtains the first data after the signature verification is successful.

[0082] In this embodiment, the first hash value may be a hash value corresponding to the first data, and the first hash value may be a string of fixed length that can uniquely identify the first data. The first data may be one of the two parts of the vehicle verification data divided by the vehicle owner terminal 120 .

[0083] When the car owner terminal 120 and the cloud 130 of the embodiment of the present specification perform collaborative signing, the car owner terminal 120 can first obtain the hash value corresponding to the first data, that is, the first hash value; the mobile terminal 120 then sends the first hash value to the cloud 130, and the cloud 130 can sign the first hash value through the second private key fragment, and return the first part of the signature to the mobile terminal 120; after the car owner terminal 120 receives the first part of the signature from the cloud 130, it uses the locally stored private key fragment (that is, the first private key fragment) to further process the data, and the car owner terminal 120 combines the first part of the signature of the cloud 130 with the second part of the signature of the car owner terminal 120 to generate a final signature; then the combined signature and the first data are sent to the cloud 130, and the cloud 130 uses the public key to verify the validity of the signature. After the signature verification is passed, the cloud obtains the first data after the signature verification is passed. The vehicle owner terminal 120 and the cloud 130 of the embodiment of this specification can collaborate to complete the signing operation while ensuring the security of the private key fragment, thereby improving the security of the private key fragment during storage and transmission, ensuring the security of data transmission, and further improving the security of vehicle startup.

[0084] In some embodiments, see Figure 7 , Figure 7 The embodiment of the present invention provides a flow chart of the vehicle owner terminal encrypting and sending the second data to the cloud. After the first data is sent, the vehicle owner terminal generates a first key pair to encrypt and send the second data to the cloud, including:

[0085] 700. The vehicle owner terminal generates a first key pair and sends the public key in the first key pair to the cloud;

[0086] 710. The vehicle owner terminal encrypts the second data using the private key in the first key pair to obtain encrypted second data;

[0087] 720. The vehicle owner terminal sends the encrypted second data to the cloud, and the cloud decrypts the encrypted second data using the public key in the first key pair to obtain the decrypted second data.

[0088] In this embodiment, the first key pair may be a private key and a public key corresponding to the private key generated by the vehicle owner terminal 120. The second data may be another part of the data obtained by dividing the vehicle verification data into two parts by the vehicle owner terminal 120.

[0089] In the embodiment of the present specification, after the car owner terminal 120 and the cloud 130 complete the signature operation in collaboration and successfully send the first data to the cloud 130, the car owner terminal 120 can first generate a first key pair, and send the public key in the first key pair to the cloud. The car owner terminal 120 encrypts the second data with the private key in the first key pair, and then sends it to the cloud 130 to decrypt the second data with the public key in the pre-stored first key pair. In the data transmission process, the embodiment of the present specification divides the identification information and the preset unlocking secret into the first data and the second data, and the car owner terminal 120 and the cloud 130 complete the signature in collaboration to transmit the first data, which ensures the authenticity of the data source, ensures the security of data transmission, and further improves the security of vehicle startup; in addition, after the first data is sent, the car owner terminal generates the first key pair to encrypt the second data and send it to the cloud, which further ensures the integrity of the data uploaded to the cloud 130, and improves the efficiency of data transmission and the security of vehicle startup on the basis of ensuring the security of data transmission.

[0090] 230. The cloud performs authority verification based on the identification information. After the authority verification is passed, the solution data of the preset unlocking secret question is sent to the vehicle owner terminal.

[0091] In this embodiment, the cloud 130 may pre-store data such as secret problem solution data corresponding to a preset unlocking secret problem, identification address, vehicle owner image information, and vehicle owner terminal information. When the identification information uploaded by the vehicle owner terminal 120 is consistent with the data pre-stored in the cloud 130, the cloud 130 passes the authority verification of the vehicle owner terminal 120, and then the cloud 130 may send the secret problem solution data corresponding to the preset unlocking secret problem to the vehicle owner terminal 120.

[0092] In some embodiments, the cloud performs authority verification based on the identification information, and after the authority verification is passed, the cloud sends the secret question solution data corresponding to the preset unlocking secret question to the car owner terminal, including: when the identification address and the car owner terminal ID are respectively the same as the identification address and the pre-stored car owner terminal ID in the cloud, and the feature vector corresponding to the face image is the same as the feature vector pre-stored in the cloud, the cloud determines that the car owner terminal authority verification is passed; after the car owner terminal authority verification is passed, the cloud decrypts the preset unlocking secret question, obtains the secret question solution data, and sends the secret question solution data to the car owner terminal.

[0093] In this embodiment, the identification information may include a feature vector corresponding to the face image, an identification address, and the vehicle owner's terminal ID, etc. When the identification information is the same as the data pre-stored in the cloud 130, the cloud 130 may determine that the vehicle owner's terminal authority verification has passed; after the vehicle owner's terminal authority verification has passed, the cloud may decrypt the preset unlocking secret question, obtain the secret question solution data, and send the secret question solution data to the vehicle owner's terminal.

[0094] In this embodiment, the car owner can store a preset unlocking secret question in the start control device 110 in advance, and store the secret question solution data corresponding to the preset unlocking secret question in the cloud 130. After the cloud 130 passes the authority verification, the preset unlocking secret question is decrypted, that is, the secret question solution data corresponding to the pre-stored preset unlocking secret question is obtained, and then the secret question solution data is sent to the car owner terminal 120.

[0095] In this embodiment, a preset unlocking question can be set in the starting control device 110, and the cloud 130 decrypts the preset unlocking question, sends the question solution data to the car owner terminal 120, and then sends the question solution data to the starting control device 110 through the car owner terminal 120; and, in this embodiment, the security of vehicle startup can be further enhanced through collaborative verification among the starting control device 110, the car owner terminal 120 and the cloud 130, that is, including communication verification between the starting control device 110 and the car owner terminal 120, and also including data verification such as identification address, car owner image information and car owner terminal information between the starting control device 110, the car owner terminal 120 and the cloud 130.

[0096] 240. The start control device receives the secret question solution data sent by the vehicle owner terminal, and starts the vehicle when the secret question solution data matches the preset unlocking secret question.

[0097] The starting control device 110 of the vehicle in the embodiment of the present specification is based on a non-networked state, and a first paging signal is sent by the vehicle owner terminal 120 corresponding to the vehicle owner to perform a point-to-point communication verification connection with the vehicle owner terminal 120. The starting control device 110 does not have an Internet access function, which avoids the problem of non-vehicle owners directly remotely starting the vehicle through other terminal devices after the key is lost, stolen or illegally copied. At the same time, the first paging signal is used to determine that a communication connection can only be made after the communication verification between the vehicle owner terminal 120 and the starting control device 110 is successful, so that only the authorized vehicle owner terminal can establish a connection with the starting control device, eliminating the risk of vehicle theft.

[0098] The vehicle owner terminal 120 of the embodiment of the present specification sends the identification information and the preset unlocking secret to the cloud 130 based on the collaborative signature of partial data, which not only ensures that data can be transmitted only between the authorized vehicle owner terminal 120 and the cloud 130, and ensures the security of the private key fragment, thereby improving the security of the private key fragment during storage and transmission, but also improves the security and efficiency of data transmission, ensures the security of data transmission, and thus improves the security of vehicle startup.

[0099] The cloud 130 of the embodiment of the present specification can perform authority verification based on the identification information. After the authority verification is passed, the solution data of the preset unlocking question corresponding to the preset unlocking question is sent to the owner terminal 120. The embodiment of the present specification further verifies the owner information and the owner terminal information in the cloud 130, which improves the security of vehicle startup and reduces the risk of vehicle theft.

[0100] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0101] See also Figure 8 , Figure 8 A schematic diagram of the structure of a vehicle starting system based on face recognition provided in an embodiment of this specification.

[0102] like Figure 8 As shown, the vehicle starting system based on face recognition may include at least a starting control device 800, a vehicle owner terminal 810, and a cloud 820, wherein:

[0103] The start control device 800 is used to perform communication verification with the vehicle owner terminal through the first paging signal sent by the vehicle owner terminal based on the non-networked state, and establish a communication connection with the vehicle owner terminal after the communication verification is passed; send a preset unlocking secret question and a face recognition instruction to the vehicle owner terminal; receive the secret question solution data sent by the vehicle owner terminal, and start the vehicle when the secret question solution data matches the preset unlocking secret question;

[0104] The vehicle owner terminal 810 is used to trigger face recognition according to the face recognition instruction, and send the recognition information and the preset unlocking secret to the cloud based on the partial data collaborative signature;

[0105] The cloud 820 is used to perform authority verification according to the identification information, and after the authority verification is passed, the secret problem solution data corresponding to the preset unlocking secret problem is sent to the car owner terminal.

[0106] In some embodiments, the start control device 800 also includes a communication verification module, which includes a scanning module, an address determination module and a response module, wherein the scanning module is used to: scan a number of paging signals; the address determination module is used to: when it is determined that a certain paging signal among the plurality of paging signals contains an identification address corresponding to the start control device and the vehicle owner terminal, mark a certain paging signal as the first paging signal sent by the vehicle owner terminal, and determine that the communication verification between the start control device and the vehicle owner terminal is passed; the response module is used to: send a response message corresponding to the first paging signal to the vehicle owner terminal; the vehicle owner terminal 810 also includes a communication connection module, which is used to: establish a connection with the start control device 800 according to the response message.

[0107] In some embodiments, the identification address includes the MAC address of the vehicle owner's terminal and the MAC address of the vehicle's startup control device.

[0108] In some embodiments, the vehicle owner terminal 810 includes a first storage module, the startup control device 800 includes a second storage module, and the first storage module and the second storage module respectively store identification addresses.

[0109] In some embodiments, the vehicle owner terminal 810 also includes a certificate module, a data segmentation module, a collaborative signature module and a data encryption module. The certificate module is used to: request the certificate issuing authority to issue a digital certificate and send the digital certificate to the cloud; the data segmentation module is used to: after receiving the certificate approval instruction, split the vehicle verification data into first data and second data; the vehicle verification data includes identification information and a preset unlocking secret; the collaborative signature module is used to: collaboratively sign with the cloud, and send the first data after the signature verification is passed to the cloud; the data encryption module is used to: after the first data is sent, encrypt the second data and send it to the cloud 820 by generating a first key pair; the cloud 820 also includes a certificate verification module, a signature module and a second data module. The certificate verification module is used to: receive the digital certificate sent by the vehicle owner terminal 810, and after verifying the digital certificate, return the certificate approval instruction to the vehicle owner terminal; the signature module is used to: collaboratively sign with the vehicle owner terminal 810, and receive the first data after the signature verification is passed; the second data module is used to: receive the second data encrypted and sent by the vehicle owner terminal 810 by generating a first key pair after the first data is sent.

[0110] In some embodiments, the certificate authority 830 is used to: generate a second key pair, split the private key in the second key pair into a first private key fragment and a second private key fragment by a key splitting algorithm, and send the public key in the second key pair to the cloud; the first private key fragment is stored in the vehicle owner terminal, and the second private key fragment is stored in the cloud;

[0111] In some embodiments, the collaborative signature module includes a hash value acquisition module, a hash value sending module, a second signature module and a signature merging module. The hash value acquisition module is used to: obtain a first hash value, the first hash value is the hash value corresponding to the first data; the hash value sending module is used to: send the first hash value to the cloud; the second signature module is used to: sign the first hash value through the first private key fragment to obtain the second part of the signature; the signature merging module is used to: merge the first part of the signature with the second part of the signature to generate a merged signature, and send the merged signature and the first data to the cloud; the signature module includes a hash value receiving module, a first signature module and a signature verification module. The hash value receiving module is used to: receive the first hash value sent by the hash value sending module; the first signature module is used to: sign the first hash value through the second private key fragment to obtain the first part of the signature, and send the first part of the signature to the car owner terminal; the signature verification module is used to: verify the merged signature through the public key in the second key pair. After the signature verification is passed, the cloud obtains the first data after the signature verification.

[0112] In some embodiments, the data encryption module also includes a key pair generation module and an encryption sub-module. The key pair generation module is used to: generate a first key pair and send the public key in the first key pair to the cloud; the encryption sub-module is used to: encrypt the second data using the private key in the first key pair to obtain the encrypted second data; and send the encrypted second data to the cloud; the second data module also includes a decryption module, and the decryption module is used to: decrypt the encrypted second data using the public key in the first key pair to obtain the decrypted second data.

[0113] In some implementation examples, the recognition information includes a feature vector corresponding to a facial image, and the vehicle owner terminal 810 also includes a calling module and an image acquisition module. The calling module is used to: call the image acquisition module according to a facial recognition instruction; the image acquisition module is used to: acquire an image, locate the face position in the image, and mark the face area by the face position; preprocess the face area to obtain a preprocessed face image; extract key features of the preprocessed face image; and encode the key features into a feature vector corresponding to the face image.

[0114] In some implementation examples, the identification information also includes an identification address and a vehicle owner terminal ID. The cloud 820 also includes an authority verification module and a secret question decryption module. The authority verification module is used to: when the identification address and the vehicle owner terminal ID are respectively the same as the identification address and the vehicle owner terminal ID pre-stored in the cloud, and the feature vector corresponding to the face image is the same as the feature vector pre-stored in the cloud, determine that the vehicle owner terminal authority verification is passed; the secret question decryption module is used to: after the vehicle owner terminal authority verification is passed, decrypt the preset unlock secret question, obtain the secret question solution data, and send the secret question solution data to the vehicle owner terminal.

[0115] Based on the content of the vehicle starting system based on face recognition in multiple embodiments of this specification, it can be known that the starting control device of the vehicle in the embodiment of this specification can be based on a non-networked state, and can communicate with the car owner terminal through the first paging signal sent by the car owner terminal, and establish a communication connection with the car owner terminal after the communication verification is passed; the starting control device then sends the preset unlocking secret and the face recognition instruction to the car owner terminal; then the car owner terminal triggers face recognition according to the face recognition instruction, and sends the identification information and the preset unlocking secret to the cloud based on the partial data collaborative signature; the cloud then performs authority verification based on the identification information, and sends the secret solution data corresponding to the preset unlocking secret to the car owner terminal after the authority verification is passed; then the starting control device receives the secret solution data sent by the car owner terminal, and when the secret solution data matches the preset unlocking secret, the vehicle is started.

[0116] The vehicle startup control device of the embodiment of the present specification is based on a point-to-point communication verification connection with the vehicle owner terminal through a first paging signal sent by the vehicle owner terminal corresponding to the vehicle owner in a non-networked state. The startup control device does not have an Internet access function, which avoids the problem that non-vehicle owners can directly remotely start the vehicle through other terminal devices after the key is lost, stolen or illegally copied. At the same time, it is determined through the first paging signal that the communication connection can only be made after the communication verification between the vehicle owner terminal and the startup control device is successful, so that only the authorized vehicle owner terminal can establish a connection with the startup control device, eliminating the risk of vehicle theft; in addition, the vehicle owner terminal of the embodiment of the present specification sends the identification information and the preset unlocking secret question to the cloud based on the partial data collaborative signature, which not only ensures that only the authorized vehicle owner terminal can transmit data with the cloud, but also improves the security and efficiency of data transmission; then the cloud of the embodiment of the present specification performs authority verification based on the identification information, and after the authority verification is passed, the secret question solution data corresponding to the preset unlocking secret question is sent to the vehicle owner terminal. The embodiment of the present specification further verifies the vehicle owner information and the vehicle owner terminal information in the cloud, improves the security of vehicle startup, and reduces the risk of vehicle theft.

[0117] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the vehicle starting system embodiment based on face recognition, since it is basically similar to the vehicle starting method embodiment based on face recognition, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0118] See also Fig. 9 A schematic diagram of the structure of an electronic device based on a vehicle startup control device provided in an embodiment of this specification is shown.

[0119] like Fig. 9 As shown, the electronic device 900 may include: at least one processor 910 , at least one network interface 940 , a user interface 930 , a memory 950 , and at least one communication bus 920 .

[0120] The communication bus 920 may be used to realize the connection and communication among the above-mentioned components.

[0121] The user interface 930 may include buttons, and the optional user interface may also include a standard wired interface or a wireless interface.

[0122] The network interface 940 may include, but is not limited to, a Bluetooth module, an NFC module, a ZigBee module, and a UWB module.

[0123] Among them, the processor 910 may include one or more processing cores. The processor 910 uses various interfaces and lines to connect various parts within the entire electronic device 900, and executes various functions and processes data of the electronic device 900 by running or executing instructions, programs, code sets or instruction sets stored in the memory 950, and calling data stored in the memory 950. Optionally, the processor 910 can be implemented in at least one hardware form of DSP, FPGA, and PLA. The processor 910 can integrate one or a combination of CPU and GPU. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content that needs to be displayed on the display screen.

[0124] Among them, the memory 950 may include RAM or ROM. Optionally, the memory 950 includes a non-transitory computer-readable medium. The memory 950 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 950 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 950 may also be at least one storage device located away from the aforementioned processor 910. The memory 950 as a computer storage medium may include an operating system, a communication module, a user interface module, and a vehicle startup application based on face recognition. The processor 910 may be used to call the vehicle startup application based on face recognition stored in the memory 950 regarding the vehicle startup control device, and execute the vehicle startup and formulation steps based on face recognition regarding the vehicle startup control device mentioned in the aforementioned embodiment.

[0125] The embodiment of the present specification also provides a computer-readable storage medium, in which instructions are stored. When the instructions are executed on a computer or a processor, the computer or the processor executes the above Figure 2 to Figure 7 One or more steps in the illustrated embodiment. If the components of the electronic device described above are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.

[0126] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, the process or function according to the embodiment of this specification is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that can be accessed by the computer or a data storage device such as a server or data center that contains one or more available media integrations. Available media may be magnetic media (eg, floppy disks, hard disks, tapes), optical media (eg, digital versatile discs (DVD)), or semiconductor media (eg, solid state drives (SSD)).

[0127] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk and other media that can store program codes. In the absence of conflict, the technical features in this embodiment and the implementation scheme can be combined arbitrarily.

[0128] The embodiments described above are merely preferred embodiments of this specification and are not intended to limit the scope of this specification. Without departing from the design spirit of this specification, various modifications and improvements made to the technical solutions of this specification by ordinary technicians in this field should fall within the scope of protection determined by the claims of this specification.

Claims

1. A vehicle starting method based on face recognition, characterized in that: include: The vehicle startup control device performs communication verification with the vehicle owner terminal through a first paging signal sent by the vehicle owner terminal based on the non-networked state, and establishes a communication connection with the vehicle owner terminal after the communication verification is passed; The start control device sends a preset unlocking secret question and a face recognition instruction to the vehicle owner terminal; The vehicle owner terminal triggers face recognition according to the face recognition instruction, and sends the recognition information and the preset unlocking secret to the cloud based on the partial data collaborative signature; The cloud performs authority verification according to the identification information, and after the authority verification is passed, sends the secret problem solution data corresponding to the preset unlocking secret problem to the vehicle owner terminal; The start control device receives the secret question solution data sent by the vehicle owner terminal, and starts the vehicle when the secret question solution data matches the preset unlocking secret question.

2. The vehicle starting method based on face recognition according to claim 1, characterized in that: The vehicle startup control device performs communication verification with the vehicle owner terminal through a first paging signal sent by the vehicle owner terminal based on a non-networked state, and establishes a communication connection with the vehicle owner terminal after the communication verification passes, including: The startup control device scans a number of paging signals; When the startup control device determines that a certain paging signal among the plurality of paging signals contains an identification address corresponding to the startup control device and the vehicle owner terminal, the certain paging signal is marked as a first paging signal sent by the vehicle owner terminal, and the communication verification between the startup control device and the vehicle owner terminal is passed; The startup control device sends response information corresponding to the first paging signal to the vehicle owner terminal, and the vehicle owner terminal establishes a connection with the startup control device according to the response information.

3. The vehicle starting method based on face recognition according to claim 2, characterized in that: The identification address includes the MAC address of the vehicle owner terminal and the MAC address of the vehicle startup control device.

4. The vehicle starting method based on face recognition according to claim 2 or 3, characterized in that: The vehicle startup control device is based on a non-networked state, and before the vehicle owner terminal performs communication verification through a first paging signal sent by the vehicle owner terminal, the vehicle owner terminal and the startup control device respectively store the identification address.

5. The vehicle starting method based on face recognition according to claim 1, characterized in that: The vehicle owner terminal triggers face recognition according to the face recognition instruction, and sends the recognition information and the preset unlocking secret to the cloud based on the partial data collaborative signature, including: The vehicle owner terminal requests a certificate issuing authority to issue a digital certificate, and sends the digital certificate to the cloud. After the cloud verifies the digital certificate, it returns a certificate passing instruction to the vehicle owner terminal. After receiving the certificate passing instruction, the vehicle owner terminal divides the vehicle verification data into first data and second data; the vehicle verification data includes the identification information and the preset unlocking secret question; The vehicle owner terminal performs collaborative signing with the cloud, and sends the first data after signature verification to the cloud; After the first data is sent, the vehicle owner terminal generates a first key pair to encrypt the second data and send it to the cloud.

6. The vehicle starting method based on face recognition according to claim 5, characterized in that: The certificate authority is used to generate a second key pair, split the private key in the second key pair into a first private key fragment and a second private key fragment by a key splitting algorithm, and send the public key in the second key pair to the cloud; the first private key fragment is stored in the vehicle owner terminal, and the second private key fragment is stored in the cloud; The vehicle owner terminal performs collaborative signing with the cloud, and sends the first data after signature verification to the cloud, including: The vehicle owner terminal obtains a first hash value, where the first hash value is a hash value corresponding to the first data; The vehicle owner terminal sends the first hash value to the cloud; The cloud performs a signature process on the first hash value by using the second private key fragment to obtain a first partial signature, and sends the first partial signature to the vehicle owner terminal; The vehicle owner terminal signs the first hash value using the first private key fragment to obtain a second partial signature; The vehicle owner terminal combines the first partial signature with the second partial signature to generate a combined signature, and sends the combined signature and the first data to the cloud; The cloud verifies the combined signature using the public key in the second key pair. After the signature verification is successful, the cloud obtains the first data after the signature verification is successful.

7. The vehicle starting method based on face recognition according to claim 5, characterized in that: After the first data is sent, the vehicle owner terminal generates a first key pair to encrypt and send the second data to the cloud, including: The vehicle owner terminal generates the first key pair, and sends the public key in the first key pair to the cloud; The vehicle owner terminal encrypts the second data by using the private key in the first key pair to obtain encrypted second data; The vehicle owner terminal sends the encrypted second data to the cloud, and the cloud decrypts the encrypted second data using the public key in the first key pair to obtain the decrypted second data.

8. The vehicle starting method based on face recognition according to claim 1, characterized in that: The vehicle owner terminal triggers face recognition according to the face recognition instruction to obtain recognition information, wherein the recognition information includes a feature vector corresponding to the face image. The above steps include: The vehicle owner terminal calls the image acquisition module according to the face recognition instruction; The image acquisition module is used to acquire images, locate the face position in the image, and mark the face area through the face position; preprocess the face area to obtain a preprocessed face image; extract key features of the preprocessed face image; and encode the key features into a feature vector corresponding to the face image.

9. The vehicle starting method based on face recognition according to claim 8, characterized in that: The cloud performs authority verification according to the identification information, and after the authority verification is passed, sends the secret problem solution data corresponding to the preset unlocking secret problem to the vehicle owner terminal, wherein the identification information also includes an identification address and a vehicle owner terminal ID, including: When the identification address and the vehicle owner terminal ID are respectively the same as the identification address and the vehicle owner terminal ID pre-stored in the cloud, and the feature vector corresponding to the face image is the same as the feature vector pre-stored in the cloud, the cloud determines that the vehicle owner terminal authority verification is passed; After the car owner terminal passes the authority verification, the cloud decrypts the preset unlocking secret question, obtains the secret question solution data, and sends the secret question solution data to the car owner terminal.

10. The vehicle starting system based on face recognition is characterized in that: include: The start control device is used to perform communication verification with the vehicle owner terminal through a first paging signal sent by the vehicle owner terminal based on a non-networked state, and establish a communication connection with the vehicle owner terminal after the communication verification is passed; send a preset unlocking secret question and a face recognition instruction to the vehicle owner terminal; receive secret question solution data sent by the vehicle owner terminal, and start the vehicle when the secret question solution data matches the preset unlocking secret question; The vehicle owner terminal is used to trigger face recognition according to the face recognition instruction, and send the recognition information and the preset unlocking secret to the cloud based on the partial data collaborative signature; The cloud is used to perform authority verification according to the identification information, and after the authority verification is passed, the secret problem solution data corresponding to the preset unlocking secret problem is sent to the vehicle owner terminal.

Citation Information

Patent Citations

  • Vehicle-based safety control method

    CN111194028A

  • Dual security control method for vehicle, and device and system using the same

    KR102241775B1