Identity authentication method and system based on identity basic database
By extracting and matching user authentication information in the identity authentication system, building an authentication prediction model, comprehensively calculating biological verification information and verification environment information, the problem of difficult security in the identity authentication process is solved, and higher authentication accuracy and security are achieved.
Patent Information
- Application Number
- CN202411945809.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing identity authentication systems based on basic identity databases are difficult to ensure security during user authentication, especially in the fine-grained access control of resources and services.
By extracting the characteristics of user authentication information during user authentication and matching with the user identity storage information in the basic database, bio verification information and verification environment information are extracted after success. This information is used to build an identity verification prediction model, comprehensively calculate the fingerprint recognition time deviation value, verification frequency fluctuation value and verification execution efficiency to judge the security of the identity verification process and issue an early warning.
Improve the accuracy and security of the user authentication process, reduce the possibility of misjudgment and deception, and improve the flexibility and adaptability of the system through customized security strategies.
Smart Images

Figure CN120068038A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity management, and particularly to an identity authentication method and system based on an identity basic database. Background Art
[0002] The identity authentication method based on an identity basic database involves a user providing identity information, and the system queries records stored in the database for verification. After successful identity verification, the user is granted corresponding permissions. This system focuses on database design, encryption security, identity authentication algorithms, and access control to ensure efficient and secure management of user identities. It may include technologies such as multi-factor authentication and biometric recognition, and comprehensively applies multiple background technologies to ensure the security of user identities and the effectiveness of access authorization. However, due to the need for fine-grained access control of resources and services during the identity authentication process, it is difficult to guarantee the security of the verification process when users perform identity authentication. Summary of the Invention
[0003] The purpose of the present invention is to provide an identity authentication method and system based on an identity basic database to solve the deficiencies in the background art.
[0004] To achieve the above purpose, the present invention provides the following technical solution: An identity authentication method based on an identity basic database, comprising the following steps:
[0005] S1: When a user performs identity verification, extract the feature of the user identity verification information, and match the extracted user identity verification information with the user identity storage information in the basic database;
[0006] S2: After the user identity verification information is successfully matched, extract the biometric verification information and verification environment information during the user identity verification process. The biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency;
[0007] S3: Construct an identity verification prediction model, comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the verification execution efficiency, judge the security of the user's identity verification process, and give an early warning of the risk situation.
[0008] In a preferred embodiment, in S2, after the user identity verification information is successfully matched, extract the biometric verification information and verification environment information during the user identity verification process. The biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency, including the following content:
[0009] The method for obtaining the fingerprint recognition time deviation value is as follows: When a user performs fingerprint authentication, collect the user's fingerprint image. While collecting the fingerprint image, obtain the fingerprint collection time t within the s time period; process the collected fingerprint image, extract features related to timing information, compare the extracted timing information with the user template stored in the database in advance, and calculate the fingerprint recognition time deviation value by comparing the similarity of the timing information;
[0010] The method for obtaining the calibration frequency fluctuation value is as follows: Obtain the number of identity recognition features, the feature recognition time, and the number of feature comparisons performed by the identity verification system when the user performs identity verification. Obtain the preset number of identity recognition features, the feature recognition time, and the number of feature comparisons, and calculate the deviation value eg of the number of identity recognition features, the deviation value dk of the feature recognition time, and the deviation value sk of the number of feature comparisons. Calculate the calibration frequency fluctuation value, and the calculation expression is: In the formula, dy m is the calibration frequency fluctuation value, and n is the number of identity recognition times;
[0011] The method for obtaining the verification execution efficiency is as follows: Real-time obtain the start time and end time of the user's identity information verification, and obtain the execution time T of each user's identity verification z and the standard time t for each identity verification system to perform identity verification r , calculate the average execution time, and the calculation expression is: In the formula, ds v is the average execution time, g is the number of executions, calculate the verification execution efficiency, and the calculation expression is: In the formula, mh x is the verification execution efficiency.
[0012] In a preferred embodiment, in S3, construct an identity verification prediction model, comprehensively calculate the fingerprint recognition time deviation value, the calibration frequency fluctuation value, and the verification execution efficiency, and judge the security of the user's identity verification process, including the following content;
[0013] After comprehensively calculating the fingerprint recognition time deviation value, the calibration frequency fluctuation value, and the verification execution efficiency, construct a data evaluation model, and the model calculation expression is: In the formula, ts k is the security coefficient, mn g is the fingerprint recognition time deviation value, dy m is the calibration frequency fluctuation value, mh x is the verification execution efficiency, a 1 、a 2 、a 3 are the proportionality coefficients of the fingerprint recognition time deviation value, the calibration frequency fluctuation value, and the verification execution efficiency, and a 2 >a3 >a 1 >0;
[0014] Compare the security coefficient of the user during the identity verification process with the standard threshold. If the security coefficient is greater than the standard threshold, no warning signal is issued at this time; if the security coefficient is less than or equal to the standard threshold, a warning signal is issued at this time.
[0015] The present invention also provides an identity authentication system based on an identity basic database, including an identity recognition module, a data acquisition module, and a warning module;
[0016] Identity recognition module: When a user performs identity verification, extract the characteristics of the user identity verification information, and match the extracted user identity verification information with the user identity storage information in the basic database;
[0017] Data acquisition module: After the user identity verification information is successfully matched, extract the biometric verification information and verification environment information during the user identity verification process. The biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency;
[0018] Warning module: Construct an identity verification prediction model, comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the verification execution efficiency, judge the security of the user during the identity verification process, and give an early warning of the risk situation.
[0019] In the above technical solution, the technical effects and advantages provided by the present invention:
[0020] 1. When the user performs identity verification, the present invention extracts the characteristics of the user identity verification information, and matches the extracted user identity verification information with the user identity storage information in the basic database. After the user identity verification information is successfully matched, the biometric verification information and verification environment information during the user identity verification process are extracted. The biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency. By comprehensively calculating and analyzing the information in multiple aspects, the accuracy of the user identity verification process is improved. Comprehensive analysis helps to more comprehensively evaluate the authenticity of the user identity and reduce the possibility of misjudgment and deception.
[0021] 2. By constructing an identity verification prediction model, the present invention comprehensively calculates the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the verification execution efficiency, judges the security of the user during the identity verification process, and gives an early warning of the risk situation. By establishing an identity verification prediction model, the system can customize security policies according to the actual situation, improving the flexibility and adaptability of the system. Description of the Drawings
[0022] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.
[0023] Figure 1 It is a flowchart of the method of the present invention.
[0024] Figure 2 It is a system module diagram of the present invention. Detailed implementation manners
[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0026] Embodiment 1. Please refer to Figure 1 and Figure 2 As shown, a method for identity authentication based on an identity-based database in this embodiment includes the following steps:
[0027] S1: When a user performs identity authentication, extract the features of the user identity authentication information, and match the extracted user identity authentication information with the user identity storage information in the basic database;
[0028] S2: After the user identity authentication information matches successfully, extract the biometric authentication information and the authentication environment information during the user identity authentication process. The biometric authentication information includes the fingerprint recognition time deviation value, and the authentication environment information includes the verification frequency fluctuation value and the verification execution efficiency;
[0029] S3: Construct an identity authentication prediction model, comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the verification execution efficiency, judge the security of the user's identity authentication process, and give an early warning of the risk situation.
[0030] Among them, in S1, when a user performs identity authentication, extract the features of the user identity authentication information, and match the extracted user identity authentication information with the user identity storage information in the basic database. Specifically;
[0031] User identity authentication information: The user identity authentication information may include a user name, a password, biometric features, etc.
[0032] Feature extraction: The process of extracting features from user authentication information. For example, if biometric features are involved, it may include fingerprint images, iris scans, or facial features. For passwords, it may involve encryption algorithms such as hash functions.
[0033] User identity information in the basic database: In the basic database, the identity information of registered users is stored. This includes preprocessed and stored user authentication information, such as encrypted passwords, biometric templates, etc.
[0034] Information matching: The extracted user authentication information is matched with the corresponding records in the basic database. This may involve decrypting passwords or comparing biometric features. If the match is successful, the user is authenticated as a legitimate user.
[0035] Error handling: During the information matching process, the system needs to consider mechanisms for handling error situations, such as incorrect passwords, unmatched biometric features, etc. Provide appropriate error messages and handling measures to ensure that users receive clear feedback.
[0036] Among them, the information matching process includes: Obtaining the identity information provided by the user. When the user conducts identity authentication, first obtain the identity information provided by the user, which may include username, password, biometric features, etc.
[0037] Feature extraction is performed on the identity information provided by the user. Convert the original information into comparable features, such as hashing the password or extracting specific templates from biometric features.
[0038] Compare the extracted features with the records of the corresponding users in the basic database. Note whether the information stored in the database is properly encrypted and protected to ensure the security of users' sensitive information.
[0039] Password matching: If the identity authentication involves a password, perform password matching. Usually, passwords are stored in the database in hashed form, so the password entered by the user needs to be hashed in the same way and then compared with the hash value in the database.
[0040] Biometric comparison: If the identity authentication involves biometric features, perform biometric comparison. This may include fingerprint comparison, iris scan, or facial recognition, etc., to ensure that the biometric features provided by the user match the corresponding features in the database.
[0041] Processing of matching results: Based on the comparison results, determine whether the match is successful. If the match is successful, the user is authenticated as a legitimate user; otherwise, the authentication fails. In this step, error handling mechanisms usually also need to be considered, such as providing error messages or recording failed attempts.
[0042] Among them, in S2, after the user authentication information matches successfully, the biometric authentication information and the verification environment information in the user authentication process are extracted. The biometric authentication information includes the fingerprint recognition time deviation value, and the verification environment information includes the calibration frequency fluctuation value and the verification execution efficiency;
[0043] The main function of obtaining the fingerprint recognition time deviation value is to enhance the security of the authentication process. It can be achieved through the following methods:
[0044] The fingerprint recognition time deviation value can be used to detect possible spoofing attacks. An attacker may attempt to use a captured fingerprint image or template for authentication. By comparing the provided fingerprint information with the actual collected fingerprint timing information, the system can detect such spoofing attempts.
[0045] The time deviation value reflects the timing information of the fingerprint, including the speed of fingerprint formation, pressure changes, etc. It is difficult for an attacker to simulate or replicate these timing characteristics. Therefore, obtaining the time deviation value can improve the anti-counterfeiting property of biometrics and increase the difficulty of attacks.
[0046] Introducing the time deviation value into the authentication process makes the system have multi-level security. It not only depends on static fingerprint image matching but also considers the matching of timing information, thus increasing the difficulty for an attacker to deceive the system.
[0047] Generally speaking, obtaining the fingerprint recognition time deviation value is to introduce more biometric timing information, thereby improving the security of the authentication system, increasing the difficulty for an attacker to deceive the system, and strengthening the ability to prevent various attack means.
[0048] The method for obtaining the fingerprint recognition time deviation value is as follows: When the user conducts fingerprint authentication, the fingerprint image of the user is collected, which can be completed by a fingerprint sensor or other biometric collection devices. While collecting the fingerprint image, the fingerprint collection time t within the s time period is obtained; the collected fingerprint image is processed to extract the features related to the timing information, and the extracted timing information is compared with the user template stored in the database in advance. By comparing the similarity of the timing information, the fingerprint recognition time deviation value is calculated.
[0049] The increase in the fingerprint recognition time deviation value makes the system more difficult to be threatened by spoofing attacks. It is usually difficult for an attacker to simulate or replicate the timing characteristics of a normal user's fingerprint. Therefore, a larger time deviation value improves the system's ability to resist spoofing attacks.
[0050] The increase in the fingerprint recognition time deviation value means that the system pays more attention to the timing changes of the fingerprint rather than just the static fingerprint image. This improves the anti-counterfeiting property of biometrics and increases the difficulty for an attacker to deceive the system.
[0051] The introduction of the fingerprint recognition time deviation value increases the complexity of the authentication system, giving it more security levels. It not only relies on static fingerprint image matching but also takes into account the matching of temporal information, thus increasing the difficulty for attackers to succeed in an attack.
[0052] Generally speaking, the larger the fingerprint recognition time deviation value, the more capable the system is of resisting attacks and enhancing security. However, at the same time, it is also necessary to balance the user experience to ensure that the practicality of the system is not affected while increasing security.
[0053] Obtaining the verification frequency fluctuation value has several benefits for evaluating the security of the user's authentication process:
[0054] The calculation of the verification frequency fluctuation value can help the system detect abnormal activities. By monitoring changes in the verification frequency, the system can identify situations that may be brute-force attacks, malicious attempts, or other abnormal behaviors. This helps to detect and prevent potential security threats in a timely manner.
[0055] Changes in the frequency fluctuation value reflect changes in the environment or user behavior. The system can utilize this information for dynamic risk assessment. For example, a significant change in frequency may indicate that the user's identity may be threatened and stronger authentication is required.
[0056] The calculation of the verification frequency fluctuation value enables the system to respond to changing situations in real time. This real-time nature allows the system to adapt more quickly to new security threats, increasing the overall security of the system.
[0057] By comprehensively utilizing the verification frequency fluctuation value, the system can establish a more comprehensive and intelligent security protection mechanism, thereby improving the security level of the overall authentication system.
[0058] The method for obtaining the verification frequency fluctuation value is as follows: Obtain the number of identity recognition features, the feature recognition time, and the number of feature comparisons when the authentication system performs identity recognition during user authentication. Obtain the preset number of identity recognition features, the feature recognition time, and the number of feature comparisons. Calculate the identity recognition feature quantity deviation value eg, the feature recognition time deviation value dk, and the feature comparison number deviation value sk. Calculate the verification frequency fluctuation value, and the calculation expression is: In the formula, dy m is the verification frequency fluctuation value, and n is the number of identity recognition times;
[0059] A larger verification frequency fluctuation value means that the system more sensitively monitors changes in the verification request frequency. This improves the system's ability to detect abnormal activities (such as brute-force attacks, multiple failed authentication attempts, etc.), making it easier to identify potential security threats.
[0060] Larger frequency fluctuation values enable the system to be more capable of dynamically adjusting the authentication strategy. The system can adjust the verification level or introduce additional security layers according to the frequently changing situations to ensure that the system responds quickly and flexibly to new threats.
[0061] Large frequency fluctuation values enable the system to respond more in real time to changing situations. This is crucial for timely addressing potential threats in environments with high real-time requirements.
[0062] High frequency fluctuation values can provide the system with richer user behavior data, enabling it to analyze users' patterns and habits more deeply. This helps to establish a more accurate user behavior model and improve the system's ability to distinguish between normal and abnormal behaviors.
[0063] Generally speaking, larger verification frequency fluctuation values help the system to more comprehensively and flexibly evaluate the security of the user authentication process and improve the system's ability to respond to various security threats.
[0064] The benefits of obtaining verification execution efficiency for evaluating the security of the user authentication process include:
[0065] Efficient verification execution can quickly detect and respond to potential threats, reduce the window period for malicious activities to occur, and improve the system's response speed to immediate security issues.
[0066] A fast and accurate authentication process reduces the opportunity for attackers to exploit vulnerabilities and decreases the likelihood of the system being exploited, thus enhancing the overall security.
[0067] Efficient authentication reduces the likelihood of impersonation, making it more difficult for attackers to use stolen credentials or malicious means to impersonate legitimate users, thus enhancing the security of authentication.
[0068] An efficient authentication process helps to smoothly integrate multi-factor authentication, provides a stronger security layer, and increases the security of overall authentication.
[0069] The method for obtaining verification execution efficiency is: obtain the start time and end time of the user's identity information verification in real time, obtain the execution time T for each user authentication z , and the standard time t for the system to perform authentication for each authentication r , calculate the average execution time, and the calculation expression is: In the formula, ds v is the average execution time, g is the number of executions, calculate the verification execution efficiency, and the calculation expression is: In the formula, mh x is the verification execution efficiency;
[0070] A larger verification execution efficiency value indicates that the system can complete the authentication task more quickly, making it more real-time, helping to quickly detect and respond to potential threats, and improving the system's response speed to immediate security issues.
[0071] Fast and efficient authentication reduces the time window for attackers to exploit vulnerabilities, thereby reducing the likelihood of the system being exploited and enhancing overall security.
[0072] Efficient verification can quickly identify and abort malicious activities, shortening the duration of attacks and helping to reduce potential security threats.
[0073] After comprehensively calculating the fingerprint recognition time deviation value, calibration frequency fluctuation value, and verification execution efficiency, a data evaluation model is constructed. The model calculation expression is: In the formula, ts k is the security coefficient, mn g is the fingerprint recognition time deviation value, dy m is the calibration frequency fluctuation value, mh x is the verification execution efficiency, a 1 、a 2 、a 3 are the proportionality coefficients of the fingerprint recognition time deviation value, calibration frequency fluctuation value, and verification execution efficiency, and a 2 > a 3 > a 1 > 0;
[0074] Compare the security coefficient obtained during the user authentication process with the standard threshold. If the security coefficient is greater than the standard threshold, it indicates that the security of the user authentication process is higher, and no warning signal is issued at this time; if the security coefficient is less than or equal to the standard threshold, it indicates that the security of the user authentication process is lower, and a warning signal is issued at this time; when the staff receives the warning signal, the staff may need to take appropriate solutions according to the actual situation.
[0075] In this embodiment, when a user performs identity authentication, feature extraction is performed on the user identity authentication information, and the extracted user identity authentication information is matched with the user identity storage information in the basic database. After the user identity authentication information is successfully matched, biometric authentication information and authentication environment information during the user identity authentication process are extracted. The biometric authentication information includes a fingerprint recognition time deviation value, and the authentication environment information includes a verification frequency fluctuation value and a verification execution efficiency. An identity authentication prediction model is constructed to comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the verification execution efficiency, determine the security of the user's identity authentication process, and give an early warning of the risk situation. By establishing an identity authentication prediction model, the system can customize security policies according to the actual situation, improving the flexibility and adaptability of the system.
[0076] Embodiment 2. The data content confidentiality inspection system described in this embodiment includes an identity recognition module, a data acquisition module, and a warning module;
[0077] Among them,
[0078] Identity recognition module: When a user performs identity authentication, feature extraction is performed on the user identity authentication information, and the extracted user identity authentication information is matched with the user identity storage information in the basic database;
[0079] Data acquisition module: After the user identity authentication information is successfully matched, biometric authentication information and authentication environment information during the user identity authentication process are extracted. The biometric authentication information includes a fingerprint recognition time deviation value, and the authentication environment information includes a verification frequency fluctuation value and a verification execution efficiency;
[0080] Warning module: Construct an identity authentication prediction model to comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the verification execution efficiency, determine the security of the user's identity authentication process, and give an early warning of the risk situation.
[0081] The above formulas are all dimensionless and take their numerical calculations. The formula is obtained by collecting a large amount of data for software simulation to obtain a formula that is closest to the actual situation. The preset parameters in the formula are set by those skilled in the art according to the actual situation.
[0082] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0083] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context.
[0084] In this application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0085] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0086] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans may use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0087] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0088] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0089] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0090] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0091] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0092] As described above, the above are only specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. An identity authentication method based on an identity basic database, characterized in that: The steps include: S1: When the user authenticates the user, feature extraction is performed on the user authentication information, and the extracted user authentication information is matched with the user identity storage information in the basic database; S2: after the user identity verification information is successfully matched, extracting the biometric verification information and verification environment information in the user identity verification process, wherein the biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency; S3: Construct an identity authentication prediction model, comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value and the verification execution efficiency, judge the security of the user's identity authentication process, and issue early warning of risk conditions.
2. The identity authentication method based on the identity basic database according to claim 1 is characterized in that: In S2, after the user identity verification information is successfully matched, the biometric verification information and verification environment information in the user identity verification process are extracted, the biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency, including the following contents: The method for obtaining the fingerprint recognition time deviation value is as follows: when the user performs fingerprint authentication, the user's fingerprint image is collected, and at the same time as the fingerprint image is collected, the fingerprint collection time t within the time period s is obtained; the collected fingerprint image is processed, and features related to the time sequence information are extracted, and the extracted time sequence information is compared with the user template stored in the database in advance, and the fingerprint recognition time deviation value is calculated by comparing the similarity of the time sequence information; The method for obtaining the verification frequency fluctuation value is as follows: obtain the number of identity recognition features, feature recognition time, and feature comparison times performed by the identity recognition system when the user performs identity authentication, obtain the preset number of identity recognition features, feature recognition time, and feature comparison times, calculate the identity recognition feature number deviation value eg, feature recognition time deviation value dk, feature comparison times deviation value sk, calculate the verification frequency fluctuation value, and the calculation expression is: In the formula, dy m is the verification frequency fluctuation value, n is the number of identity recognition times; The method for obtaining the verification execution efficiency is: obtaining the start time and end time of the user's identity information verification in real time, and obtaining the execution time T of each user's identity verification. z And the standard time t for each authentication system to perform authentication r , calculate the average execution time, the calculation expression is: Where, ds v is the average execution time, g is the number of executions, and the execution efficiency is calculated and verified. The calculation expression is: In the formula, mh x To verify the execution efficiency.
3. The identity authentication method based on the identity basic database according to claim 2 is characterized in that: In S3, an identity authentication prediction model is constructed to comprehensively calculate the fingerprint recognition time deviation value, the verification frequency fluctuation value and the verification execution efficiency to determine the security of the user's identity authentication process, including the following contents; The fingerprint recognition time deviation value and the verification frequency fluctuation value are calculated comprehensively, and the data evaluation model is constructed after the execution efficiency is verified. The model calculation expression is: In the formula, ts k is the security factor, mng is the fingerprint recognition time deviation value, dy m is the verification frequency fluctuation value, mhx is the verification execution efficiency, a1, a2, a3 are the fingerprint recognition time deviation value, the verification frequency fluctuation value, and the proportional coefficient of the verification execution efficiency, and a2>a3>a1>0; The obtained security factor of the user's identity authentication process is compared with the standard threshold. If the security factor is greater than the standard threshold, no warning signal is issued; If the safety factor is less than or equal to the standard threshold, a warning signal is issued.
4. An identity authentication system based on an identity basic database, used to implement an identity authentication method based on an identity basic database according to any one of claims 1 to 3, characterized in that: Including identity recognition module, data acquisition module and early warning module; Identity recognition module: when the user authenticates the user, it extracts the features of the user's identity authentication information and matches the extracted user identity authentication information with the user identity storage information in the basic database; Data acquisition module: after the user identity verification information is successfully matched, extract the biometric verification information and verification environment information in the user identity verification process, the biometric verification information includes the fingerprint recognition time deviation value, and the verification environment information includes the verification frequency fluctuation value and the verification execution efficiency; Early warning module: Build an identity authentication prediction model, comprehensively calculate the fingerprint recognition time deviation value, verification frequency fluctuation value and verification execution efficiency, judge the security of the user's identity authentication process, and issue early warning of risk conditions.