Biological characteristic protection method and equipment based on KZG commitment
By using KZG promise value and bilinear mapping verification technology in biometric data verification, the problem of privacy leakage and data tampering risks during the storage and verification process of biometric data is solved, and efficient privacy protection and verification are achieved.
Patent Information
- Application Number
- CN202510103213.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-16
AI Technical Summary
In the prior art, there is a risk of privacy leakage and data tampering during storage and verification of biometric data, and there is a lack of effective solutions to sampling differences.
By generating and storing the user's KZG commitment value as the unique binding identifier of the biometric feature, new biometric data is obtained during verification, processing to generate KZG proofs, and the matching of the KZG commitment value to the KZG proof is verified through bilinear mapping.
It realizes privacy protection and efficient verification of biometric data, avoids the leakage of original data, improves the matching efficiency of verification, and solves the sampling difference problem.
Smart Images

Figure CN120012157A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a biometric protection method and device based on KZG commitment. Background Art
[0002] In the existing technology, biometric technology: biometrics such as fingerprints and irises have been widely used in identity authentication, but due to the sensitivity of biometric data, its privacy needs to be specially protected. The KZG commitment in the KZG commitment technology is a zero-knowledge proof scheme that allows the generation of a fixed-size commitment value for data while supporting efficient verification.
[0003] In traditional biometric authentication schemes, feature vectors are generated using fingerprint images or iris images, and stored encrypted; during verification, feature vectors are directly compared with pre-stored feature vectors, but there is a risk of data leakage during the storage process, and direct comparison requires the original feature vector, which lacks privacy protection. Traditional KZG commitment applications are mainly used in blockchain storage or multi-party computing for efficient verification of data sets, but the existing technology does not combine the characteristics of biometric data and does not solve the problem of consistency of multiple sampling.
[0004] Existing biometric data is easily affected by external interference (such as sampling angle, light, etc.), which leads to inconsistency in the feature points of multiple samples, thus affecting the matching accuracy; traditional biometric authentication schemes lack protection for data privacy, and feature vectors are directly stored, which poses a risk of leakage; although KZG's commitment technology can provide data integrity verification, it does not combine the characteristics of biometric data and cannot solve the problem of sampling differences. Summary of the invention
[0005] One purpose of the present application is to provide a biometric protection method and device based on KZG commitment, which solves the problems of privacy leakage and data tampering risks in the storage and verification process of biometric data in the prior art, combines biometric data with KZG commitment technology, realizes privacy protection and efficient verification of biometrics, and eliminates the need to leak original data during the verification process.
[0006] According to one aspect of the present application, a biometric protection method based on the KZG commitment is provided, wherein the method comprises:
[0007] Generate and store the user's KZG commitment value as a unique binding identifier of the user's biometric features;
[0008] During verification, obtaining biometric data re-collected and submitted by the user;
[0009] Processing the new biometric data to generate a KZG certificate for the new biometric data;
[0010] Verify the matching of the KZG commitment value and the KZG proof through bilinear mapping;
[0011] If the verification is successful, it indicates that the submitted new biometric data matches the KZG commitment value and the user identity verification is successful.
[0012] Furthermore, in the above method, the generating and storing of the user's KZG commitment value as a unique binding identifier of the user's biometric feature includes:
[0013] Collecting a biometric image of the user;
[0014] Sequentially performing feature extraction and feature preprocessing on the biometric image of the user to obtain a preprocessed feature vector;
[0015] Based on the KZG commitment technology, the preprocessed feature vector is processed to generate and store the KZG commitment value of the biometric image as a unique binding identifier of the user's biometric feature.
[0016] Furthermore, in the above method, collecting the biometric image of the user includes:
[0017] The user collects a biometric image of the user through a fingerprint scanner or an iris recognition device.
[0018] Furthermore, in the above method, the step of sequentially extracting and preprocessing the biometric image of the user to obtain a preprocessed feature vector includes:
[0019] The collected biometric image of the user is input into the image processing algorithm, and the feature points are extracted and converted into a digital feature vector v = [υ1, υ2, ..., υ n ]; wherein there are n feature points in the biometric image;
[0020] Normalizing each feature point in the digital feature vector to adjust the feature points to a consistent length and range, and calibrating the difference between each feature point by a tolerance algorithm to obtain a preprocessed feature vector;
[0021] Among them, the formula for calibrating the difference of each feature point is:
[0022] υ′ i =f(υ i )+△
[0023] Among them, f(υ i ) is the normalization function, Δ is the tolerance parameter, V iis the i-th feature point in the digital feature vector.
[0024] Furthermore, in the above method, the preprocessed feature vector is processed based on the KZG commitment technology to generate and store the KZG commitment value of the biometric image as the unique binding identifier of the user's biometric, including:
[0025] The preprocessed feature vector is converted into a polynomial P(x) = v0+v1x+v2x 2 +...+υ n x n ;
[0026] The polynomial P(x) is calculated using the privacy parameter α in the KZG commitment technology to generate a KZG commitment value C of the biometric image;
[0027] The calculation formula of the KZG commitment value C of the biometric image is:
[0028] C=g P(α)
[0029] Among them, g is the generator, and α is the privacy parameter set through trust;
[0030] The KZG commitment value of the biometric image is stored in a database as a unique binding identifier of the user's biometric.
[0031] Furthermore, in the above method, the processing of the new biometric data to generate a KZG certificate of the new biometric data includes:
[0032] The new biometric data is subjected to feature extraction and feature preprocessing in sequence to obtain a new preprocessed feature vector v′=[υ′1,υ′2,...,υ′ n ], wherein the new preprocessed feature vector has n feature points;
[0033] Construct a verification point (x) for the new preprocessed feature vector i ,y i ), generate a KZG certificate π of the new biometric data;
[0034] The calculation formula of the KZG proof π of the new biometric data is:
[0035] π=g Q(α)
[0036] in, is the intermediate polynomial used for verification.
[0037] Furthermore, in the above method, verifying the matching of the KZG commitment value and the KZG proof by bilinear mapping includes:
[0038] The verifier verifies the matching of the KZG commitment value and the KZG proof through the bilinear mapping e, where the verification formula is:
[0039]
[0040] Among them, h is the result output of the verification formula.
[0041] According to another aspect of the present application, a non-volatile storage medium is also provided, on which computer-readable instructions are stored. When the computer-readable instructions can be executed by a processor, the processor implements the biometric protection method based on the KZG commitment as described above.
[0042] According to another aspect of the present application, a biometric protection device based on the KZG commitment is also provided, wherein the device includes:
[0043] one or more processors;
[0044] A computer readable medium for storing one or more computer readable instructions,
[0045] When the one or more computer-readable instructions are executed by the one or more processors, the one or more processors implement the biometric protection method based on the KZG commitment as described above.
[0046] Compared with the prior art, this application generates and stores the user's KZG commitment value as the unique binding identifier of the user's biometrics; during verification, obtains the biometric data re-collected and submitted by the user; processes the new biometric data to generate a KZG certificate for the new biometric data; verifies the matching of the KZG commitment value and the KZG certificate through bilinear mapping; if the verification passes, it indicates that the submitted new biometric data matches the KZG commitment value, and the user identity verification is successful. In this application, the KZG commitment value is combined with biometric authentication to propose a biometric protection solution based on the KZG commitment value, which not only protects the privacy of user data, but also improves the efficiency of verification and matching. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings:
[0048] Figure 1 A schematic flow chart of a biometric protection method based on KZG commitment according to one aspect of the present application is shown.
[0049] The same or similar reference numerals in the drawings represent the same or similar components. DETAILED DESCRIPTION
[0050] The present application is described in further detail below in conjunction with the accompanying drawings.
[0051] In a typical configuration of the present application, the terminal, the device of the service network and the trusted party all include one or more processors (CPU), input / output interfaces, network interfaces and memories.
[0052] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0053] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include non-transitory media such as modulated data signals and carrier waves.
[0054] In order to solve the problems of privacy leakage and data tampering risks in the storage and verification process of biometric data in the existing technology, such as Figure 1 As shown, Figure 1 A flow chart of a biometric protection method based on KZG commitment proposed in one aspect of the present application, which can be implemented in software by combining biometric acquisition software (such as OpenCV library) with cryptographic libraries (such as libsnark or Go-KZG), and at the same time, an encryption chip or module that supports elliptic curve operations (such as Intel SGX) is used to meet hardware implementation. The method includes steps S11, S12, S13, S14 and S15, specifically including the following steps:
[0055] Step S11, generate and store the user's KZG commitment value as the unique binding identifier of the user's biometrics, so as to implement the privacy protection of the user's biometrics through the user's KZG commitment value; here, calculating and generating the user's KZG commitment value requires processing large-scale data, and parallel computing can be used to optimize the subsequent polynomial calculation process.
[0056] In the step S11, the present application can not only generate and store the user's KZG commitment value, but also use other zero-knowledge proof schemes, such as Groth16 or PLONK, to replace the KZG commitment value to ensure the privacy of the user's biometrics.
[0057] Step S12, during verification, obtaining the biometric data re-collected and submitted by the user;
[0058] Step S13, processing the new biometric data to generate a KZG certificate for the new biometric data;
[0059] Step S14, verifying the matching of the KZG commitment value and the KZG certificate through bilinear mapping to ensure data integrity and authenticity;
[0060] Step S15: If the verification is successful, it indicates that the submitted new biometric data matches the KZG commitment value and the user identity verification is successful.
[0061] Through the above steps S11 to S15, not only the problems of privacy leakage and data tampering risks in the storage and verification process of biometric data in the prior art are solved, but also the biometric data is combined with the KZG commitment technology to achieve privacy protection and efficient verification of biometrics, so that the verification process does not need to leak the original data.
[0062] Following the above embodiment of the present application, the step S11 generates and stores the user's KZG commitment value as the unique binding identifier of the user's biometric feature, specifically including:
[0063] First, the biometric image of the user is collected; wherein the biometric image of the user includes but is not limited to multiple biometric features of the user, such as fingerprint, iris, facial features, etc., so as to subsequently generate a joint feature commitment value with better adaptability and better versatility.
[0064] Then, feature extraction and feature preprocessing are performed on the biometric image of the user in sequence to obtain a preprocessed feature vector;
[0065] Finally, based on the KZG commitment technology, the preprocessed feature vector is processed to generate and store the KZG commitment value of the biometric image as the unique binding identifier of the user's biometric feature. This not only realizes the preprocessing of the user's biometric image, but also generates the KZG commitment value as the unique binding identifier of the user's biometric feature.
[0066] Following the above embodiment of the present application, the step S11 of collecting the biometric image of the user specifically includes:
[0067] The user collects the user's biometric image through a fingerprint scanner or an iris recognition device to collect the user's biometric features such as fingerprints, irises, facial features, etc.
[0068] Following the above embodiment of the present application, the step S11 sequentially extracts and preprocesses the biometric image of the user to obtain a preprocessed feature vector, specifically including:
[0069] The collected biometric image of the user is input into the image processing algorithm, and the feature points are extracted and converted into a digital feature vector v = [υ1, υ2, ..., υ n ], the feature extraction of the collected biometric image of the user is realized by an image processing algorithm to extract a digital feature vector, wherein the biometric image has n feature points, v1, v2, v3, ... v n They represent the first, second, third, ... nth feature points in sequence; for example, a fingerprint image is subjected to a Minutiae extraction algorithm to generate a vector composed of feature points (position, direction, etc.). In a preferred embodiment of the present application, a deep learning algorithm (such as a convolutional neural network) can also be used to extract features from the collected biometric image of the user to enhance the consistency of feature extraction.
[0070] Each feature point in the digital feature vector is normalized and adjusted to a consistent length and range, and the difference of each feature point is calibrated by a tolerance algorithm to obtain a preprocessed feature vector to eliminate the influence of acquisition conditions (such as lighting, angle, etc.) on the result, and at the same time, reduce the deviation introduced by different devices, light, sampling angle, etc.;
[0071] Among them, the formula for calibrating the difference of each feature point is:
[0072] υ′ i =f(υ i )+△
[0073] Among them, f(υ i) is the normalization function; Δ is the tolerance parameter used to adapt to slight errors; V i is the i-th feature point in the digital feature vector.
[0074] Here, due to different devices and different environments, the collected biometrics may vary greatly. In order to ensure the consistency of the collected biometrics, a multiple sampling calibration algorithm and a tolerance matching mechanism are introduced to overcome the subtle differences caused by the biometric adoption conditions. It has strong resistance to differences and can also solve the problem of slight differences in feature points caused by multiple sampling.
[0075] Following the above embodiment of the present application, the pre-processed feature vector is processed based on the KZG commitment technology in step S11 to generate and store the KZG commitment value of the biometric image as the unique binding identifier of the user's biometric feature, specifically including:
[0076] The preprocessed feature vector is converted into a polynomial P(x) = v0+v1x+v2x 2 +...+υ n x n , so that the KZG commitment value can be generated according to the polynomial later;
[0077] The polynomial P(x) is calculated using the privacy parameter α in the KZG commitment technology to generate a KZG commitment value C of the biometric image, where the KZG commitment value is a fixed size and serves as a privacy binding value of the user's biometric image;
[0078] The calculation formula of the KZG commitment value C of the biometric image is:
[0079] C=g P(α)
[0080] Among them, g is the generator, and α is the privacy parameter set through trust;
[0081] The KZG commitment value of the biometric image is stored in the database as the unique binding identifier of the user's biometric feature, avoiding the direct storage of the original biometric data. It not only hides the original biometric data of the user, but also protects the user's privacy, effectively prevents data leakage, and improves privacy.
[0082] Following the above embodiment of the present application, during the verification process, the step S13 processes the new biometric data to generate a KZG certificate for the new biometric data, specifically including:
[0083] The newly collected biometric data is subjected to feature extraction and feature preprocessing in sequence to obtain a new preprocessed feature vector v′=[υ′1, υ′2, ..., υ′ n ], wherein the new preprocessed feature vector has n feature points;
[0084] Construct a verification point (x) for the new preprocessed feature vector i ,y i ), generate a KZG certificate π of the new biometric data;
[0085] The calculation formula of the KZG proof π of the new biometric data is:
[0086] π=g Q(α)
[0087] in, is the intermediate polynomial used for verification.
[0088] Following the above embodiment of the present application, when verifying, the step S14 verifies the matching of the KZG commitment value and the KZG proof through bilinear mapping, specifically including:
[0089] The verifier verifies the matching of the KZG commitment value and the KZG proof through the bilinear mapping e, where the verification formula is:
[0090]
[0091] Among them, h is the result output of the verification formula;
[0092] If the verification is successful, it means that the new biometric data of the user that was re-collected and submitted matches the stored KZG commitment value, and the user identity verification is successful.
[0093] Here, the generation and verification process of the KZG commitment value only involves a finite number of exponential operations and bilinear mappings, with low computational complexity, suitable for real-time verification scenarios, and better efficiency.
[0094] According to another aspect of the present application, a non-volatile storage medium is provided, on which computer-readable instructions are stored. When the computer-readable instructions can be executed by a processor, the processor implements the biometric protection method based on the KZG commitment as described above.
[0095] According to another aspect of the present application, a biometric protection device based on the KZG commitment is also provided, wherein the device includes:
[0096] one or more processors;
[0097] A computer readable medium for storing one or more computer readable instructions,
[0098] When the one or more computer-readable instructions are executed by the one or more processors, the one or more processors implement the biometric protection method based on the KZG commitment as described above.
[0099] Here, for the detailed contents of each embodiment of the biometric protection device based on the KZG commitment, please refer to the corresponding part of the above-mentioned biometric protection method embodiment based on the KZG commitment, which will not be repeated here.
[0100] In summary, this application generates and stores the user's KZG commitment value as the unique binding identifier of the user's biometrics; during verification, obtains the biometric data re-collected and submitted by the user; processes the new biometric data to generate a KZG certificate for the new biometric data; verifies the matching of the KZG commitment value and the KZG certificate through bilinear mapping; if the verification passes, it indicates that the submitted new biometric data matches the KZG commitment value, and the user identity verification is successful. In this application, the KZG commitment value is combined with biometric authentication to propose a biometric protection solution based on the KZG commitment value, which not only protects the privacy of user data, but also improves the efficiency of verification and matching.
[0101] It should be noted that the present application can be implemented in software and / or a combination of software and hardware, for example, can be implemented using an application specific integrated circuit (ASIC), a general purpose computer or any other similar hardware device. In one embodiment, the software program of the present application can be executed by a processor to implement the steps or functions described above. Similarly, the software program of the present application (including relevant data structures) can be stored in a computer-readable recording medium, for example, a RAM memory, a magnetic or optical drive or a floppy disk and similar devices. In addition, some steps or functions of the present application can be implemented using hardware, for example, as a circuit that cooperates with a processor to perform each step or function.
[0102] In addition, a part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present application through the operation of the computer. The program instruction for calling the method of the present application may be stored in a fixed or removable recording medium, and / or transmitted through a data stream in a broadcast or other signal-bearing medium, and / or stored in a working memory of a computer device that runs according to the program instruction. Here, according to an embodiment of the present application, a device is included, the device including a memory for storing computer program instructions and a processor for executing program instructions, wherein, when the computer program instruction is executed by the processor, the device is triggered to run the method and / or technical solution based on the aforementioned multiple embodiments according to the present application.
[0103] It is obvious to those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and that the present application can be implemented in other specific forms without departing from the spirit or basic features of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive, and the scope of the present application is limited by the attached claims rather than the above description, so it is intended to include all changes that fall within the meaning and scope of the equivalent elements of the claims in the present application. Any figure mark in the claims should not be regarded as limiting the claims involved. In addition, it is obvious that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the device claim can also be implemented by one unit or device through software or hardware. The words first, second, etc. are used to indicate names, and do not indicate any particular order.
Claims
1. A biometric protection method based on KZG commitment, wherein: The method includes: Generate and store the user's KZG commitment value as a unique binding identifier of the user's biometric features; During verification, obtaining biometric data re-collected and submitted by the user; Processing the new biometric data to generate a KZG certificate for the new biometric data; Verify the matching of the KZG commitment value and the KZG proof through bilinear mapping; If the verification is successful, it indicates that the submitted new biometric data matches the KZG commitment value and the user identity verification is successful.
2. The method according to claim 1, wherein: The generating and storing of the user's KZG commitment value as a unique binding identifier of the user's biometric feature includes: Collecting a biometric image of the user; Sequentially performing feature extraction and feature preprocessing on the biometric image of the user to obtain a preprocessed feature vector; Based on the KZG commitment technology, the preprocessed feature vector is processed to generate and store the KZG commitment value of the biometric image as a unique binding identifier of the user's biometric feature.
3. The method according to claim 2, wherein: The collecting of the biometric image of the user includes: The user collects a biometric image of the user through a fingerprint scanner or an iris recognition device.
4. The method according to claim 2, wherein: The step of sequentially extracting and preprocessing the biometric image of the user to obtain a preprocessed feature vector includes: The collected biometric image of the user is input into the image processing algorithm, feature points are extracted and converted into a digital feature vector v = [v1, v2, ..., v n ]; wherein, there are n feature points in the biometric image; Normalizing each feature point in the digital feature vector to adjust the feature points to a consistent length and range, and calibrating the difference between each feature point by a tolerance algorithm to obtain a preprocessed feature vector; Among them, the formula for calibrating the difference of each feature point is: v′ i =f(v i )+Δ Among them, f(v i ) is the normalization function, Δ is the tolerance parameter, V i is the i-th feature point in the digital feature vector.
5. The method according to claim 2, wherein: The method of processing the preprocessed feature vector based on the KZG commitment technology to generate and store the KZG commitment value of the biometric image as a unique binding identifier of the user's biometric feature includes: The preprocessed feature vector is converted into a polynomial P(x)=v0+v1x+v2x 2 +...+v n x n ; The polynomial P(x) is calculated using the privacy parameter α in the KZG commitment technology to generate a KZG commitment value C of the biometric image; The calculation formula of the KZG commitment value C of the biometric image is: C=G P(α) Among them, g is the generator, and α is the privacy parameter set through trust; The KZG commitment value of the biometric image is stored in a database as a unique binding identifier of the user's biometric.
6. The method according to claim 5, wherein: The processing of the new biometric data to generate a KZG certificate for the new biometric data includes: The new biometric data is subjected to feature extraction and feature preprocessing in sequence to obtain a new preprocessed feature vector v′=[v′1, v′2, ..., v′ n ], wherein the new preprocessed feature vector has n feature points; Construct a verification point (x) for the new preprocessed feature vector i ,y i ), generate a KZG certificate π of the new biometric data; The calculation formula of the KZG proof π of the new biometric data is: π=g Q(α) in, is the intermediate polynomial used for verification.
7. The method according to claim 6, wherein: Verifying the matching of the KZG commitment value and the KZG proof through bilinear mapping includes: The verifier verifies the matching of the KZG commitment value and the KZG proof through the bilinear mapping E, where the verification formula is: Among them, h is the result output of the verification formula.
8. A non-volatile storage medium having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executable by a processor, the processor is enabled to implement the method according to any one of claims 1 to 7.
9. A biometric protection device based on KZG commitment, wherein: The equipment includes: one or more processors; A computer readable medium for storing one or more computer readable instructions, When the one or more computer-readable instructions are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7.