Face data privacy protection method and device

By using blockchain and smart contract technical means in the face recognition system, the problems of data security and privacy protection in traditional systems are solved, decentralized management of feature data and traceability of the entire process are realized, and a secure and trustworthy technical solution is provided.

CN120074802AActive Publication Date: 2025-05-30UNIVERSAL UBIQUITOUS TECH CO LTD

Patent Information

Application Number
CN202510551609.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-05-30
Estimated Expiration
2045-04-29

AI Technical Summary

Technical Problem

Traditional facial recognition systems have data security risks and hidden dangers of privacy leakage, lack a full life cycle security protection mechanism, and feature extraction and encrypted storage solutions are difficult to meet high security requirements.

Method used

By establishing a blockchain distributed network and smart contract, building permission management module, collecting face image data and extracting key point coordinates, building geometric feature vectors and texture feature vectors, performing data sharding and homomorphic encryption, realizing decentralized management of feature data and traceability of the entire process.

Benefits of technology

It effectively solves the data security and privacy protection problems in traditional facial recognition systems, realizes secure and trustworthy storage and controllable access of feature data, and provides a secure and trustworthy technical solution for the field of biometric recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074802A_ABST
    Figure CN120074802A_ABST
Patent Text Reader

Abstract

According to the face data privacy protection method and device provided by the embodiment of the invention, a credible authority management mechanism is constructed through a distributed network and a smart contract, and a multi-dimensional feature extraction scheme fusing geometric features and texture features is innovatively designed. The system adopts data fragmentation and homomorphic encryption technologies to carry out security processing on feature vectors, and dispersedly stores encrypted data in a block chain network, so that decentralized management of the feature data is realized. According to the method, feature comparison and identity verification are carried out in a ciphertext domain, the whole process is traceable in combination with a timestamp and an operation record, the problems of data security and privacy protection in a traditional face recognition system are effectively solved, and a safe and credible technical solution is provided for the field of biological feature recognition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and particularly to a method and device for protecting the privacy of face data. Background Art

[0002] Traditional face recognition systems mostly adopt a centralized storage and management mode, which has data security risks and potential privacy leaks. Existing technologies have obvious deficiencies in data protection and access control, and lack a full-life-cycle security protection mechanism for users' biometric data. Users' privacy data is vulnerable to unauthorized access and malicious attacks.

[0003] At the same time, existing systems also have limitations in feature extraction and data encryption. Traditional methods often adopt a single feature representation method, failing to fully utilize the multi-dimensional feature information of face images, and the encryption storage scheme is relatively simple, making it difficult to meet high-security requirements. The system lacks an effective decentralized mechanism in data distribution and storage.

[0004] In addition, existing technologies also need to be improved in terms of identity authentication and data traceability. There is a lack of reliable data access control strategies and operation audit mechanisms, and the whole process supervision of the use of feature data cannot be achieved. The verification process is usually carried out in a plaintext environment, with a risk of data leakage.

[0005] In terms of data sharing and interoperability, existing systems generally have problems such as data islands and the lack of a mutual trust mechanism. There is a lack of unified data exchange standards and a trustworthy consensus mechanism, making it difficult to achieve secure data sharing between different institutions. Solving these problems is of great significance for building a secure and trustworthy face recognition system. Summary of the Invention

[0006] In view of the problems in the prior art, this application provides a method and device for protecting the privacy of face data, which can solve the data security and privacy protection problems in traditional face recognition systems and provide a secure and trustworthy technical solution for the field of biometric recognition.

[0007] To solve at least one of the above problems, this application provides the following technical solutions: In a first aspect, this application provides a method for protecting the privacy of face data, including: Establishing a blockchain distributed network, configuring multiple nodes in the network and connecting them through a peer-to-peer communication protocol, constructing a permission management module based on a smart contract, and controlling the data access of nodes through the permission management module; Collect face image data, extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain target feature vectors, perform sharding and homomorphic encryption on the target feature vectors, and package the encrypted feature shards and related operation information into blocks and store them in the blockchain distributed network; Receive a face verification request, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, perform shard recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and related information and write it into the blockchain distributed network.

[0008] Further, it includes: Establish a blockchain distributed network, configure multiple nodes in the blockchain distributed network, connect the multiple nodes through a peer-to-peer communication protocol, generate a unique identity identifier and access key in the multiple nodes, write the unique identity identifier and access key into a smart contract, and construct a permission management module based on the smart contract to control the data access of the multiple nodes through the permission management module; Collect face image data, extract the key point coordinates in the face image data, construct geometric feature vectors based on the key point coordinates, calculate the texture feature vectors of the face image data, fuse the geometric feature vectors and the texture feature vectors to obtain a fused feature vector, perform a dimensionality reduction transformation on the fused feature vector to obtain a target feature vector, divide the target feature vector into multiple data shards, perform homomorphic encryption on the multiple data shards respectively to obtain encrypted feature shards, package the encrypted feature shards, operation timestamps, and operation records into blocks, disperse the blocks and store them in multiple nodes in the blockchain distributed network, record the access operations of the encrypted feature shards based on the smart contract, and perform the access operations after passing the verification by the permission management module; Receive a face verification request, obtain the face image to be verified, repeat the feature extraction and encryption sharding process to obtain the encrypted feature shards to be verified, retrieve the encrypted feature shards from the blockchain distributed network, perform shard recombination and feature comparison on the encrypted feature shards to be verified and the encrypted feature shards in the ciphertext domain, generate a comparison result, determine the verification conclusion according to the comparison result, generate a new block with the verification conclusion, verification timestamp, and verification operation record, and write the new block into the blockchain distributed network.

[0009] In a second aspect, the present application provides a face data privacy protection device, including: A network construction module, which is used to establish a blockchain distributed network, configure multiple nodes in the network and connect them through a peer-to-peer communication protocol, construct a permission management module based on a smart contract, and control the data access of nodes through the permission management module; An image processing module, which is used to collect face image data, extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and dimension-reduce the feature vectors to obtain target feature vectors, perform sharding and homomorphic encryption on the target feature vectors, and package the encrypted feature shards and related operation information into blocks and store them in the blockchain distributed network; A privacy protection module, which is used to receive a face verification request, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, perform shard recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and related information and write it into the blockchain distributed network.

[0010] In a third aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the face data privacy protection method are implemented.

[0011] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the face data privacy protection method are implemented.

[0012] In a fifth aspect, the present application provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the face data privacy protection method are implemented.

[0013] As can be seen from the above technical solutions, the present application provides a face data privacy protection method and device, constructs a trusted permission management mechanism through a distributed network and a smart contract, and innovatively designs a multi-dimensional feature extraction scheme that combines geometric features and texture features. The system uses data sharding and homomorphic encryption technologies to securely process feature vectors, and dispersedly stores the encrypted data in the blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are performed in the ciphertext domain, and the whole process is traceable in combination with time stamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems, and providing a secure and trusted technical solution for the field of biometric recognition. Description of the Drawings

[0014] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0015] Figure 1 One of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 2 Two of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 3 Three of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 4 Four of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 5 Five of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 6 Six of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 7 Seven of the schematic flowcharts of the face data privacy protection method in the embodiments of the present application; Figure 8 The structural diagram of the face data privacy protection device in the embodiments of the present application; Figure 9 The structural schematic diagram of the electronic device in the embodiments of the present application.

[0016] Reference numerals: Electronic device 9600, central processing unit 9100, memory 9140, communication module 9110, input unit 9120, audio processor 9130, display 9160, power supply 9170, buffer memory 9141, application / function storage unit 9142, data storage unit 9143, driver program storage unit 9144, antenna 9111, speaker 9131, microphone 9132. Detailed implementation manners

[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.

[0018] In the technical solution of this application, the acquisition, storage, use, processing, etc. of data all comply with the relevant provisions of national laws and regulations.

[0019] Considering the problems existing in the prior art, this application provides a method and device for protecting the privacy of face data. A trusted permission management mechanism is constructed through a distributed network and smart contracts, and a multi-dimensional feature extraction scheme that combines geometric features and texture features is innovatively designed. The system uses data sharding and homomorphic encryption technologies to securely process feature vectors, and dispersedly stores the encrypted data in a blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are carried out in the ciphertext domain, and the whole process can be traced by combining timestamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems, and providing a secure and trusted technical solution for the field of biometric recognition.

[0020] In order to solve the data security and privacy protection problems in traditional face recognition systems and provide a secure and trusted technical solution for the field of biometric recognition, this application provides an embodiment of a method for protecting the privacy of face data. Refer to Figure 1 , the method for protecting the privacy of face data specifically includes the following content: Step S101: Establish a blockchain distributed network, configure multiple nodes in the network and connect them through a peer-to-peer communication protocol, construct a permission management module based on a smart contract, and control the data access of the nodes through the permission management module; Specifically, it includes: establishing a blockchain distributed network, configuring multiple nodes in the blockchain distributed network, connecting the multiple nodes through a peer-to-peer communication protocol, generating a unique identity identifier and an access key in the multiple nodes, writing the unique identity identifier and the access key into the smart contract, constructing a permission management module based on the smart contract, and controlling the data access of the multiple nodes through the permission management module; Optionally, this embodiment uses a consortium chain architecture to construct a distributed network. The network topology adopts a full connection structure, and each node establishes a direct peer-to-peer connection with other nodes. Node communication is based on the libp2p protocol framework, realizing multiplexing, flow control, and congestion control mechanisms. To optimize network performance, a persistent connection pool is established between nodes, and a stable communication channel is maintained through TCP long connections. During the node discovery process, a new node obtains network topology information through a bootstrap node, and then builds a neighbor node list based on the ping-pong mechanism, and regularly updates the node status and routing table.

[0021] This embodiment adopts a multi-layer cryptographic mechanism in node identity generation. First, the hardware fingerprint collection module collects characteristic information such as the CPU ID, MAC address, and hard disk serial number of the device, and calculates the unique device identifier through the SHA3-256 algorithm. Then, an asymmetric key pair is generated based on the secp256k1 elliptic curve algorithm. The private key is used for signature operations, and the public key generates the node address through the Keccak-256 hash algorithm. Finally, the device identifier and the node address are combined, and the access key is generated through the PBKDF2 key derivation function to achieve identity authentication and data encryption.

[0022] This embodiment implements a complete permission management system at the smart contract level. The contract adopts a hierarchical design. The bottom-layer contract is responsible for identity registration and key management. The middle layer implements permission rules and policy configuration. The top layer provides permission verification and access control interfaces. The contract state uses a mapping data structure to store node information, including attributes such as node type, permission level, and expiration date. The permission rules are described by a state machine model, supporting complex condition combinations and state transitions.

[0023] This embodiment designs a permission management architecture based on the RBAC (Role-Based Access Control) model. First, the role hierarchy is defined, including super administrators, regional administrators, ordinary nodes, and read-only nodes. Each role is associated with a set of permission collections, and the permission granularity is refined to the specific data operation level. The role assignment adopts a multi-signature mechanism, and the co-signature of administrator nodes reaching the preset threshold is required to take effect. The permission inheritance relationship is represented by a directed acyclic graph, supporting flexible permission transfer and delegation.

[0024] This embodiment implements a dynamic access control policy in permission control. The policy rules include multiple dimensions: the time dimension controls the access period, the space dimension restricts the access geographical location, and the frequency dimension constrains the number of operations. The rule engine adopts a forward reasoning mechanism to evaluate in real time whether the access request meets the policy requirements. The policy configuration supports dynamic updates, and the management node can modify the rule parameters through the smart contract interface, and the changes take effect immediately.

[0025] This embodiment adopts a hierarchical encryption scheme for communication between nodes. The network layer uses the TLS1.3 protocol to establish a secure channel, supporting perfect forward secrecy. The transport layer adopts the ChaCha20-Poly1305 authenticated encryption algorithm to provide high-performance encryption and authentication services. The application layer encrypts messages based on the access key shared between nodes and generates a session key through ECDH key agreement. The message contains a digital signature and an incrementing nonce value to prevent replay attacks.

[0026] In this embodiment, a distributed audit system is constructed. Each node maintains a local audit log, recording detailed operation information, including the requester, operation type, timestamp, accessed resource, execution result, etc. The log entries are organized by Merkle Patricia Trie to ensure data immutability. The audit data is periodically synchronized to the blockchain network to form a globally consistent audit history. The contract provides multi-dimensional query interfaces to support complex audit analysis.

[0027] In this embodiment, a complete fault tolerance mechanism is implemented. The node status monitoring uses the Gossip protocol for propagation, and the node liveness is detected through heartbeat messages. When a node failure is detected, an automatic failover process is triggered: first, isolate the failed node and update the network topology; then activate the backup node and reconstruct the connection relationship; finally, synchronize the permission data and restore the service state. The entire process ensures network consistency through the consensus mechanism.

[0028] In this embodiment, fine-grained control is achieved in terms of permission delegation. The delegation operation is executed through a smart contract, supporting partial delegation of permissions and time limits. The delegation chain is maintained in a tree structure to control the delegation depth and prevent permission diffusion. The delegation status is updated to the blockchain in real time to ensure that all nodes obtain the latest permission information. This solution realizes secure and controllable permission management, providing a trusted data access environment for the face recognition system.

[0029] Step S102: Collect face image data and extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain target feature vectors, slice and homomorphically encrypt the target feature vectors, and package the encrypted feature slices and related operation information into a block and store it in the blockchain distributed network; Specifically, it includes: collecting face image data, extracting the key point coordinates in the face image data, constructing geometric feature vectors based on the key point coordinates, calculating the texture feature vectors of the face image data, fusing the geometric feature vectors and the texture feature vectors to obtain a fused feature vector, performing a dimensionality reduction transformation on the fused feature vector to obtain target feature vectors, dividing the target feature vectors into multiple data slices, homomorphically encrypting the multiple data slices respectively to obtain encrypted feature slices, packaging the encrypted feature slices, operation timestamps, and operation records into a block, dispersedly storing the block in multiple nodes in the blockchain distributed network, recording the access operations of the encrypted feature slices based on the smart contract, and executing the access operations after passing the verification in the permission management module; Optionally, in this embodiment, a multi-spectral image acquisition scheme is adopted, and a dual camera array of visible light and near-infrared is configured to achieve all-weather face image acquisition. The camera array is spatially aligned through precise calibration, and real-time exposure control and white balance adjustment are performed during the acquisition process. The image preprocessing module first performs light compensation, enhances the image contrast using the adaptive histogram equalization algorithm, and then performs multi-scale decomposition through the Gaussian pyramid to construct an image pyramid model to support feature extraction at different resolutions.

[0030] In this embodiment, an improved cascaded shape regression algorithm is adopted in key point localization. First, the face region is located through the Haar feature detector, and then the multi-level cascaded regressor is used to gradually optimize the key point positions. The regressor adopts the gradient boosting tree structure, each layer contains multiple weak classifiers, and the localization accuracy is improved through combined learning. The model training uses an objective function with constraint terms to ensure that the key point distribution conforms to the facial anatomical features. Finally, the coordinates of 68 standard face key points are output.

[0031] In this embodiment, multi-dimensional geometric features are constructed based on the key point coordinates. First, the Euclidean distance matrix between key points is calculated to capture the relative position relationship of facial organs. Then, triangle features are extracted, key points are selected to form a Delaunay triangulation, and the area ratio and angle ratio of the triangles are calculated. These features have strong robustness to face pose changes. At the same time, the curvature features of the key points are calculated to describe the local geometric characteristics of the facial contour.

[0032] In this embodiment, a multi-scale Gabor filter bank is adopted in texture feature extraction. The filter parameters cover 8 directions and 5 scales, forming 40 filter kernels. After performing convolution operations on the image, the amplitude and phase information are extracted to construct a feature map. The local binary pattern (LBP) features are calculated on the feature map to capture the local change patterns of the texture. Then, histogram features are generated through block statistics, and finally, the texture feature vector is obtained through principal component analysis for dimensionality reduction.

[0033] In this embodiment, an adaptive feature fusion algorithm is designed. First, the geometric features and texture features are standardized to eliminate the dimensional difference. Then, based on the Fisher criterion, the feature discriminant ability is calculated, and the feature weight coefficients are designed. The two types of features are combined into a high-dimensional feature vector in a weighted concatenation manner. To improve the expression ability of the features, a kernel function is introduced to map the features to a high-dimensional space to enhance the non-linear expression ability of the features.

[0034] In this embodiment, feature dimensionality reduction is achieved through local preserving projection. First, a neighbor graph is constructed to describe the local structure between samples, and the edge weights are calculated based on the heat kernel function. Then, the generalized eigenvalue problem is solved to obtain the optimal projection matrix. The projection process preserves the local geometric structure of the samples while achieving dimensionality reduction. Finally, a target feature vector with a fixed dimension is obtained, which is convenient for subsequent patch processing and encrypted storage.

[0035] In this embodiment, a threshold secret sharing scheme is adopted for feature fragmentation. First, the target feature vector is divided into multiple fragments according to a fixed length, and each fragment is independently encrypted. The Shamir threshold scheme is used to disperse the secret to multiple holders, and a sufficient number of fragments are required to reconstruct the original data. Random perturbations are introduced during the fragmentation process to enhance data security.

[0036] In this embodiment, an improved homomorphic encryption algorithm is adopted for feature encryption. A homomorphic encryption system is constructed based on the BGV scheme, which supports addition and multiplication operations in the ciphertext domain. The key generation uses the ring learning with errors problem to ensure the encryption strength. Noise terms are introduced during the encryption process to prevent statistical analysis attacks. Each feature fragment is independently encrypted to generate corresponding ciphertext data.

[0037] In this embodiment, a complete block packaging mechanism is designed. The encrypted feature fragments, timestamps, and operation records are organized as transaction data, and the Merkle root hash of the data is calculated as the block identifier. The block header also contains fields such as the version number and difficulty target. The block body adopts a compact encoding format to optimize the storage space. Finally, the block is synchronized to multiple nodes in the distributed network through a consensus algorithm.

[0038] In this embodiment, access control is implemented through a smart contract. The contract defines the access rules for feature fragments, including read permissions, usage times, and timeliness restrictions. Access requests need to pass permission verification, and the contract records the access logs and updates the usage count. This scheme realizes the secure storage and controllable access of face feature data, providing an effective guarantee for privacy protection.

[0039] Step S103: Receive a face verification request, perform feature extraction and encryption fragmentation on the face image to be verified, retrieve the corresponding encrypted feature fragments from the blockchain distributed network, perform fragmentation recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and related information and write it into the blockchain distributed network.

[0040] Specifically, it includes: receiving a face verification request, obtaining the face image to be verified, repeatedly performing the feature extraction and encryption fragmentation process to obtain the encrypted feature fragments to be verified, retrieving the encrypted feature fragments from the blockchain distributed network, performing fragmentation recombination and feature comparison on the encrypted feature fragments to be verified and the encrypted feature fragments in the ciphertext domain to generate a comparison result, determining the verification conclusion according to the comparison result, generating a new block with the verification conclusion, verification timestamp, and verification operation record, and writing the new block into the blockchain distributed network.

[0041] Optionally, in this embodiment, a multi-queue priority scheduling mechanism is adopted in the verification request processing. The request queue is divided into high priority and normal priority according to the urgency level, and the token bucket algorithm is used to control the request processing rate. The verification request includes a timestamp, location information, and access credentials, and the identity of the requester is verified through zero-knowledge proof. The request parsing module extracts verification parameters, including the target identity identifier and the verification scenario type, to ensure the integrity of the request.

[0042] In this embodiment, an adaptive image acquisition controller is designed. The camera parameters, including the exposure time, gain, and aperture size, are dynamically adjusted based on the environmental light intensity. The motion detection algorithm is used to identify the stable state of the face area, and the image acquisition is triggered at the best time. The quality of the acquired image sequence is evaluated, and the image with the best clarity and pose is selected as the sample to be verified. The image enhancement module improves the image quality through adaptive gamma correction and denoising processing.

[0043] In this embodiment, parallel processing of computing tasks is implemented during the feature extraction process. First, the face image is divided into multiple overlapping local regions, and feature extraction is performed independently for each region. Geometric feature extraction and texture feature extraction are executed in parallel on different processing units, and the processing efficiency is optimized through a data pipeline. The attention mechanism is adopted in the feature fusion stage to dynamically adjust the feature weights according to the discriminative ability of different regions.

[0044] In this embodiment, an improved data sharding strategy is adopted. Based on the correlation analysis of feature vectors, highly correlated feature elements are assigned to the same shard to reduce the information redundancy between shards. A check code is added to each shard to support data integrity verification. The random permutation is introduced during the sharding process to increase the uniformity of data distribution. Finally, each shard is independently homomorphically encrypted to generate the encrypted feature shards to be verified.

[0045] In this embodiment, a distributed caching mechanism is adopted in the blockchain data retrieval. A multi-level caching structure is constructed, including memory caching and persistent storage. The caching policy is based on the access frequency and temporal locality, and the LRU algorithm is used to manage the cache content. The retrieval request is first searched in the local cache, and when it misses, the data is obtained from the blockchain network. The network request adopts an asynchronous manner to avoid blocking the verification process.

[0046] In this embodiment, a ciphertext domain feature comparison algorithm is implemented. First, based on the properties of homomorphic encryption, the Euclidean distance between encrypted feature shards is calculated. The comparison result of the distance value is obtained through partial homomorphic decryption without fully decrypting the original data. The secure multi-party computation protocol is adopted in the feature recombination process to ensure that the intermediate results do not disclose the original information. Finally, the similarity score is restored through threshold decryption.

[0047] This embodiment designs an adaptive threshold decision mechanism. The basic threshold is set based on the security level of the verification scenario, and the dynamic threshold is updated through exponential moving average. Multiple metrics are considered in the decision-making process, including feature similarity, confidence level, and quality score. A fuzzy inference system is used to fuse multiple metrics to generate the final verification conclusion. The system supports multi-level verification results, including confirmed match, suspected match, and non-match.

[0048] This embodiment realizes efficient data organization during the block generation process. The verification conclusion is packaged together with detailed verification process information, including feature comparison scores, threshold settings, and decision-making bases. Compression encoding is used to reduce the block volume while retaining key audit information. The block header contains a timestamp, the hash of the parent block, and the Merkle tree root to ensure the timeliness and integrity of the data.

[0049] This embodiment uses an improved consensus mechanism to implement block writing. A consensus protocol is constructed based on the Practical Byzantine Fault Tolerance algorithm to support consistency achievement in an asynchronous network environment. The consensus process is divided into three stages: pre-prepare, prepare, and commit. Multiple rounds of voting are used to ensure the validity of the block. After the block is committed, it is synchronized to all network nodes through a broadcast mechanism to ensure data consistency. This solution realizes the full-process security protection of face verification and supports large-scale distributed deployment scenarios.

[0050] As can be seen from the above description, the face data privacy protection method provided by the embodiments of the present application can construct a trusted permission management mechanism through a distributed network and smart contracts, and innovatively designs a multi-dimensional feature extraction scheme that combines geometric features and texture features. The system uses data sharding and homomorphic encryption technologies to securely process feature vectors and dispersedly stores the encrypted data in the blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are performed in the ciphertext domain, and the whole process is traceable by combining timestamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems and providing a secure and trusted technical solution for the field of biometric recognition.

[0051] In an embodiment of the face data privacy protection method of the present application, refer to Figure 2 , it may also specifically include the following content: Step S201: Perform multi-scale decomposition on the face image data using Gabor wavelet transform, extract the texture information of the image in different directions and frequencies, map the texture information to the feature space to construct a texture feature matrix, perform dimensionality reduction processing on the texture feature matrix through principal component analysis to obtain a texture feature vector, use a deep convolutional neural network to locate the facial key point coordinates in the face image data, and calculate the distances and angle values between facial organs based on the facial key point coordinates to construct a geometric feature vector; Step S202: Normalize the texture feature vector and the geometric feature vector, and use a weighted fusion algorithm to combine the normalized texture feature vector and geometric feature vector into a high-dimensional feature matrix. Then, select discriminative feature components from the high-dimensional feature matrix through an adaptive feature selection algorithm, and construct the selected feature components into a fused feature vector.

[0052] Optionally, in this embodiment, an adaptive parameter configuration strategy is adopted in the Gabor wavelet transform. The filter bank includes 5 scales and 8 directions. The scale parameter is dynamically adjusted based on the image resolution, and the direction parameter evenly covers the interval from 0 to π. The center frequency and bandwidth of each filter kernel are optimized through grid search to maximize the discriminability of texture features. The convolution operation is accelerated by the fast Fourier transform, and the image boundary is processed by the overlap-add method to ensure the continuity of feature extraction.

[0053] This embodiment designs a multi-level texture feature extraction framework. First, local statistical features, including mean, variance, skewness, and kurtosis, are calculated on the Gabor response map. Then, a spatial pyramid structure is constructed, and the histogram of oriented gradients is extracted at different resolutions. The feature mapping uses a kernel function to project non-linear features into a high-dimensional feature space to enhance the expression ability of features. Finally, features at different levels are cascaded to form a texture feature matrix.

[0054] This embodiment implements an incremental learning mechanism in principal component analysis. The feature matrix is first zero-centered and whitened to improve the statistical characteristics of the data. The principal eigenvector is calculated by the modified power iteration method, and the eigenvalue energy threshold is adaptively determined. In the dimensionality reduction process, the principal components with a cumulative contribution rate reaching a preset threshold are retained to ensure controllable information loss. The dimensionality-reduced feature vector maintains the geometric structure of the feature space through orthogonal transformation.

[0055] This embodiment constructs a hierarchical deep convolutional neural network. The backbone of the network adopts a residual structure, and the gradient vanishing problem is alleviated through skip connections. The feature extraction layer uses dilated convolution to expand the receptive field, and the multi-scale feature fusion adopts a feature pyramid network. The key point detection head designs a multi-task learning framework to predict the key point heat map and displacement vector simultaneously. The network training adopts a hard and soft example mining strategy to dynamically adjust the sample weights.

[0056] This embodiment designs a geometric feature extraction module based on anatomical features. First, the centroid positions of facial organs are calculated to construct a standardized coordinate system. Then, multiple groups of geometric metrics are extracted, including absolute distances such as inter-ocular distance, nose length, and mouth width, and angular features such as eye angle, nasal bridge angle, and mandibular angle. The feature calculation considers the changes in face pose, and pose normalization is achieved through projective transformation. At the same time, contour curvature features are extracted to describe the geometric characteristics of the facial contour.

[0057] In this embodiment, a robust standardization method is adopted in feature normalization. For texture features, improved Z-score standardization is used, where the median and interquartile distance are used to replace the mean and standard deviation to reduce the influence of outliers. For geometric features, min-max normalization is adopted, and the interval boundaries are determined by kernel density estimation. The standardization parameters are updated through a sliding window to adapt to the dynamic changes in the feature distribution.

[0058] This embodiment implements an adaptive feature weighted fusion algorithm. First, the discrimination ability of each feature component is evaluated through the Fisher discriminant criterion, and the between-class scatter and within-class aggregation are calculated. The weight coefficients are optimized by the Lagrange multiplier method to maximize the discrimination ability of the features. The fusion process adopts a weighted concatenation method to generate a high-dimensional feature matrix. The matrix structure contains local and global feature information and supports multi-scale feature representation.

[0059] This embodiment designs a dynamic feature selection mechanism. A feature importance score is constructed based on the mutual information criterion, and a sequential forward selection strategy is used to iteratively screen the feature subsets. The redundancy between features is considered during the selection process, and the minimum redundancy maximum correlation criterion is used to balance the discriminability and independence of the features. The feature selection results are dynamically updated with the sample distribution to maintain the optimality of the feature components.

[0060] This embodiment generates a fused feature vector through feature component reconstruction. The spatio-temporal structure of the features is maintained during the reconstruction process, and the contributions of different feature domains are adjusted through an attention mechanism. The vector dimension is determined through cross-validation to balance the feature expression ability and computational efficiency. This scheme realizes the efficient extraction and optimized expression of face features, providing a reliable basis for subsequent feature encryption and comparison.

[0061] In an embodiment of the face data privacy protection method of this application, refer to Figure 3 , it may also specifically include the following content: Step S301: Use the locally linear embedding algorithm to perform non-linear dimensionality reduction on the fused feature vector, construct a local linear relationship matrix between feature points, calculate the optimal projection direction based on the local linear relationship matrix, project the fused feature vector into a low-dimensional space to obtain a target feature vector, segment the target feature vector according to a preset segmentation length to generate a data segment sequence of fixed length, assign a unique identifier to each data segment and record the segment position information; Step S302: Generate a public key pair and a private key pair based on the homomorphic encryption algorithm, perform an encryption operation on each data segment in the data segment sequence using the public key, combine the encrypted data segment with the corresponding segment identifier and position information to form an encrypted feature segment, construct a segment index table to record the association relationship between the encrypted feature segments, and write the segment index table into the smart contract.

[0062] Optionally, in this embodiment, an adaptive neighborhood construction strategy is adopted in the locally linear embedding algorithm. First, the local neighborhood of each feature point is determined through fast nearest neighbor search, and the neighborhood size is dynamically adjusted based on the local data density. The neighborhood relationship is described by a heat kernel weight function, and the weight coefficient decays exponentially with distance. Threshold pruning is used when constructing the sparse weight matrix to retain significant local connection relationships and improve computational efficiency and robustness.

[0063] This embodiment realizes an improved locally linear relationship modeling. For each feature point, the reconstruction weights are obtained by solving a constrained least squares problem. The constraint conditions include that the sum of weights is 1 and local geometry preservation. The optimization process adopts the augmented Lagrangian method, and the optimal weights are obtained through iterative convergence. The reconstruction error is used as a regularization term to balance local preservation and global structure. The sparsification of the weight matrix is achieved through a soft threshold strategy to improve storage efficiency.

[0064] This embodiment designs an efficient feature projection optimization framework. Based on the reconstruction weight matrix, a global covariance structure is constructed, and the optimal projection direction is solved through generalized eigenvalue decomposition. The eigenvalue decomposition adopts the Lanczos iteration method, which significantly improves the efficiency of large-scale data processing. The projection dimension is determined by the cumulative reconstruction error to ensure that the features after dimensionality reduction retain sufficient discriminant information. The orthogonality of the projection matrix ensures the orthogonality of the feature space.

[0065] This embodiment adopts a hierarchical data sharding strategy. First, the target feature vectors are normalized to ensure uniform numerical distribution. The shard length is determined through feature correlation analysis, and strongly correlated feature elements are assigned to the same shard. Redundant check codes are added to each shard to support data integrity verification. A random permutation is introduced during the sharding process to increase the uniformity of data distribution.

[0066] This embodiment realizes a traceable shard identification mechanism. The identifier is generated by combining a timestamp and a random number to ensure global uniqueness. The location information includes the starting position and length of the shard in the original vector, and compressed coding is used to reduce storage overhead. The identification information constructs an association structure through hash links to support shard traceability and integrity verification.

[0067] This embodiment adopts an improved BGV scheme in homomorphic encryption. The key generation is based on the ring learning with errors problem, and the public and private key pairs are constructed through random polynomials. The public key contains multiple components to support batch encryption. The private key is stored in shards and distributed to multiple authorized nodes through a threshold scheme. The key update is achieved through a blinding factor, and regular rotation enhances security.

[0068] This embodiment designs a shard-level parallel encryption mechanism. Each data shard is encrypted independently, supporting multi-threaded parallel execution. The encryption process introduces random noise to prevent statistical analysis attacks. Ciphertext compression is achieved through modulus switching to optimize storage space. The encrypted feature shard contains ciphertext data, shard identifier and location information, using a unified serialization format.

[0069] This embodiment builds an efficient shard index structure. The index table adopts a skip list organization to support fast range query and insertion operations. The index item contains the shard identifier, location information and association relationship, which are stored in a prefix tree compression. The index update adopts optimistic concurrency control to improve the efficiency of concurrent access.

[0070] This embodiment implements index management through smart contracts. The contract defines the index add, delete, modify and query interface, and access rights are controlled by roles. Index operations generate event logs that record the operation type and execution results. The contract status is synchronized to the blockchain network to ensure the consistency of index data. This solution implements secure sharding storage of feature data and supports efficient data retrieval and access control.

[0071] The technical solution of this embodiment maintains the essential structure of the feature through nonlinear dimensionality reduction, shard storage and homomorphic encryption ensure data security, and smart contracts implement reliable index management. The overall design meets the efficiency and security requirements of the face recognition system for feature processing.

[0072] In one embodiment of the face data privacy protection method of the present application, see Figure 4 , and can also include the following: Step S401: Combine the encrypted feature fragment and the operation timestamp to form a data block, calculate the hash value of the data block as the block header, write the operation record information into the block body, build the association structure of the block header and the block body based on the Merkle tree algorithm, use the consensus algorithm to verify the block between multiple nodes, generate block link information, write the verified block into the blockchain distributed network, and store the block in different nodes according to the preset distribution strategy; Step S402: Set access control rules in the smart contract, build an access operation log structure to record data access request information, verify the legitimacy of the access request based on the zero-knowledge proof algorithm, match the access request information with the authorization information of the corresponding node, generate access credentials and set the validity period of the access rights, and send the access credentials to the node that initiated the access request.

[0073] Optionally, this embodiment adopts a hierarchical data block organizational structure. The data block header includes a version number, a timestamp, the hash of the previous block, and a difficulty target. The timestamp is accurate to the millisecond level and is synchronized through the Network Time Protocol. The data block adopts a compact serialization format to optimize storage efficiency. The block body contains the indexes of multiple encrypted feature shards and operation records, recording the detailed data processing history.

[0074] This embodiment implements an improved Merkle tree algorithm in block construction. First, the block data is hashed hierarchically. The leaf nodes store the hash values of the original data, and the intermediate nodes are calculated from the hashes of the child nodes. The hash function uses SHA3-256 to provide stronger collision resistance. The tree structure is optimized for balance, and the tree height balance is maintained through rotation operations. The root node hash serves as the unique identifier of the block, supporting fast data verification.

[0075] This embodiment designs an efficient consensus mechanism. A consensus framework is built based on the Practical Byzantine Fault Tolerance algorithm, supporting an asynchronous network environment. The consensus process is divided into three stages: pre-prepare, prepare, and commit. Nodes confirm the validity of the block through voting, and more than two-thirds of the nodes need to reach an agreement. Byzantine fault tolerance ensures that the system can still operate normally in the case of partial node failures or malicious behavior.

[0076] This embodiment adopts a dynamic block distribution strategy. Based on the consistent hashing algorithm, the blocks are mapped to the node ring to ensure uniform data distribution. Each block sets a replication factor according to its importance, determining the number of backups. Node selection considers geographical location and network latency to optimize access performance. The data synchronization uses the gossip protocol to ensure eventual consistency of the network.

[0077] This embodiment implements fine-grained access control in smart contracts. The contract defines a multi-level permission model, including administrator permissions, operation permissions, and read-only permissions. The permission rules support time limits and operation count limits. The access policy is described by a state machine, supporting complex condition combinations. Contract state changes are notified to relevant nodes through an event mechanism.

[0078] This embodiment constructs a complete access log system. The log structure includes the request time, the identity of the requester, the operation type, and the accessed resource. The log entries are organized in a chained structure to ensure the immutability of the records. Log queries support multi-dimensional filtering for easy auditing and analysis. The logs are synchronized to the blockchain network to form a distributed audit Trail.

[0079] This embodiment adopts an improved Schnorr protocol in zero-knowledge proof. First, an identity commitment of the prover is constructed, including the public key and a random challenge. The verification process is completed through an interactive proof without revealing the original credentials. The proof structure adopts a compressed format to reduce communication overhead. The zero-knowledge property ensures that sensitive information is not revealed during the verification process.

[0080] This embodiment designs a secure authorization mechanism. The authorization information includes the node public key, permission level, and expiration date. The authorization process adopts a multi-signature scheme, and a sufficient number of authorized node signatures are required to take effect. The authorization status is managed by a smart contract, which supports the revocation and update of authorization. The state change triggers an event notification to ensure the timely synchronization of authorization information.

[0081] This embodiment realizes efficient access credential management. The credentials are in the JSON Web Token format, including permission claims and signature information. A random factor is added to the credential generation process to prevent replay attacks. The validity period setting adopts a sliding window mechanism to support automatic renewal. The credential revocation is implemented through a blacklist to ensure security.

[0082] This embodiment realizes the secure storage and access control of data through a distributed network. Blockchain technology ensures the immutability of data, smart contracts realize flexible permission management, and zero-knowledge proofs ensure the security of identity authentication. This solution provides a reliable data protection mechanism for the face recognition system.

[0083] In an embodiment of the face data privacy protection method of this application, refer to Figure 5 , and it may specifically include the following content: Step S501: Receive the face verification request sent by the node, parse the target identity information and access credential in the verification request, verify the validity of the access credential, call the image acquisition module to obtain the face image to be verified, perform light compensation and pose correction on the face image to be verified, and standardize the corrected face image according to a preset resolution; Step S502: Perform feature extraction operations on the standardized face image to be verified, extract texture feature vectors and geometric feature vectors using the same algorithm configuration as the original feature extraction, fuse the feature vectors and then perform dimensionality reduction transformation to obtain the target feature vector, segment the target feature vector based on a preset sharding strategy, and perform encryption operations on the segmented data shards using the public key to obtain the encrypted feature shards to be verified.

[0084] Optionally, this embodiment adopts a hierarchical authentication mechanism in the verification request processing. First, extract the identity identifier and access credential in the verification request through a Token parser. The credential format adopts the JWT standard, including permission claims and digital signatures. The authentication process is divided into two stages: identity authentication and permission verification. The signature validity is verified through asymmetric encryption to ensure the credibility of the request source. The permission verification is based on the RBAC model, and the timeliness of the access permission is checked in combination with the timestamp.

[0085] In this embodiment, an adaptive image acquisition controller is designed. The acquisition module is configured with a multi-spectral camera array, including visible light and near-infrared sensors, to support image acquisition under different lighting conditions. The camera parameters are adjusted through real-time feedback, including exposure time, gain, and aperture size. The image quality evaluation module screens the optimal image frames based on indicators such as sharpness, contrast, and face pose.

[0086] In this embodiment, a multi-stage illumination compensation algorithm is implemented. First, the image contrast is enhanced by adaptive histogram equalization, and the weight coefficients are dynamically adjusted according to the local brightness distribution. Then, an improved Retinex algorithm is used to separate the illumination component and the reflection component, and the illumination estimation is optimized through multi-scale decomposition. Finally, the image dynamic range is adjusted by gamma correction to ensure that facial details are clearly visible.

[0087] In this embodiment, a three-dimensional model-assisted method is adopted in pose correction. First, a deep learning model is used to estimate the three-dimensional pose parameters of the face, including Euler angles and translation vectors. Then, a facial mesh in the standard pose is generated based on the 3D deformation model, and the correspondence between the two-dimensional image and the three-dimensional model is established through perspective projection. Finally, image reprojection is achieved through thin plate spline interpolation to generate a frontal view of the face image.

[0088] In this embodiment, an adaptive image normalization processing flow is designed. The image scaling adopts the bicubic interpolation algorithm to maintain a smooth transition of edge details. The resolution normalization considers the requirements of subsequent feature extraction to ensure the consistency of feature description. The image alignment is based on the corner landmarks, and geometric normalization is achieved through affine transformation. The preprocessed image meets the input requirements of the feature extraction module.

[0089] In this embodiment, a parallel computing framework is implemented in feature extraction. The extraction processes of texture features and geometric features are executed in parallel on independent processing units. The texture features are extracted using a Gabor filter bank to obtain multi-scale features, and the filter parameters are consistent with the original feature extraction. The geometric features are calculated based on facial key points, including distance ratios and angle ratios, to ensure the pose invariance of the features.

[0090] In this embodiment, a dynamic feature fusion strategy is adopted. The feature vectors are first normalized to eliminate the scale differences in different feature domains. The fusion weights are dynamically adjusted according to the feature discriminability, considering the characteristics of the current verification scenario. The feature combination adopts a weighted concatenation method to maintain the structural integrity of the features. The fused feature vectors are dimensionally reduced through local preserving projection to maintain the local geometric structure of the samples.

[0091] This embodiment implements a consistent feature sharding mechanism. The sharding strategy is consistent with the original feature processing to ensure the comparability of encrypted features. The sharding process considers feature correlation, and feature elements with high correlation are assigned to the same shard. Check information is added to each shard to support integrity verification. A random perturbation is introduced during the sharding process to enhance security.

[0092] This embodiment adopts an optimized homomorphic encryption implementation in feature encryption. The public key of the system is used in the encryption process to support feature comparison in the ciphertext domain. The encryption operation adopts a parallel processing architecture to improve processing efficiency. Ciphertext compression is achieved through modulus switching to optimize storage overhead. The format of the encrypted feature shards is consistent with the original encrypted features, facilitating subsequent feature comparison.

[0093] This embodiment realizes the feature preparation for face verification through a standardized processing flow. The entire process from image acquisition to feature encryption is consistent with the registration stage to ensure the comparability of features. This solution supports efficient face recognition verification while protecting the security of feature data.

[0094] In an embodiment of the face data privacy protection method of this application, refer to Figure 6 , and it may specifically include the following content: Step S601: Retrieve the encrypted feature shards from the blockchain distributed network according to the shard index information recorded in the smart contract, verify the integrity and validity of the encrypted feature shards, sort the retrieved encrypted feature shards based on the shard identifier and location information, recombine the sorted encrypted feature shards according to a preset rule, and calculate the Euclidean distance between the encrypted feature shards to be verified and the recombined encrypted feature shards in the ciphertext domain using the homomorphic encryption algorithm; Step S602: Set a feature matching threshold in the ciphertext domain, compare the calculated Euclidean distance value with the feature matching threshold, calculate the similarity score between feature vectors based on the addition and multiplication operations of the homomorphic encryption algorithm, perform normalization processing on the similarity score, generate a feature comparison result after interval mapping, and combine the feature comparison result with the corresponding confidence value to form verification result data.

[0095] Optionally, this embodiment adopts a distributed caching mechanism in shard retrieval. First, query the shard index table through the smart contract to obtain the shard distribution information of the target feature. The index query uses a Bloom filter for pre-screening to reduce invalid queries. The retrieval request is routed to the storage node through the DHT network to support parallel retrieval of multiple shards. The caching strategy is based on access frequency and temporal locality, and the cache content is managed through the LRU algorithm.

[0096] This embodiment realizes multi-level integrity verification. The shard verification first checks the validity of the digital signature and timestamp to ensure that the data has not been tampered with. Then, the existence of the shard in the blockchain is verified through the Merkle proof, and the proof process is constructed based on the hash chain. The integrity check uses erasure code technology to support data recovery for partially damaged shards. The shards that fail the verification are retrieved again through the backup nodes.

[0097] This embodiment designs an adaptive shard recombination algorithm. First, an ordered sequence is constructed based on the shard identifier, and the relative order of the shards is determined through the position information. The sliding window mechanism is adopted in the recombination process to dynamically adjust the processing batch size. The data alignment is achieved through the synchronization mark to ensure the accuracy of shard splicing. The recombination result is verified through the checksum to ensure data consistency.

[0098] This embodiment adopts optimized homomorphic operations in the ciphertext domain calculation. For the Euclidean distance calculation, the feature vector is first converted into the inner product form, and the vector inner product is calculated using the multiplicative homomorphic property of homomorphic encryption. The Montgomery algorithm is adopted in the calculation process to accelerate the modular exponentiation operation and improve the calculation efficiency. The noise management is achieved through modulus switching to control the growth of the ciphertext.

[0099] This embodiment realizes a dynamic threshold management mechanism. The threshold setting considers the security requirements of the verification scenario, and the reference value is determined through historical data analysis. The exponential moving average is adopted for threshold update to adapt to the dynamic changes of the feature distribution. The comparison operation is completed in the ciphertext domain and is realized through the comparison circuit of homomorphic encryption. The threshold adjustment supports multi-level security policies to meet the requirements of different application scenarios.

[0100] This embodiment adopts a multi-feature fusion strategy in the similarity calculation. First, the similarity scores of different feature components are calculated, and the score weights are dynamically adjusted according to the feature importance. The reliability of the features is considered in the fusion process and is weighted by the confidence level. The calculation process is completely carried out in the ciphertext domain to protect the original feature information.

[0101] This embodiment designs an adaptive normalization processing mechanism. First, the statistical characteristics of the similarity distribution are estimated, and a probability model is constructed through kernel density estimation. The normalization adopts piecewise linear mapping to ensure the uniform distribution of the scores. The mapping parameters are optimized through cross-validation to balance the recognition rate and the false recognition rate. The normalization result is limited within a preset interval for subsequent decision-making.

[0102] This embodiment realizes a complete confidence evaluation framework. The confidence calculation considers multiple factors, including feature quality, matching degree, and environmental conditions. The evaluation model adopts a fuzzy inference system, and the association relationship between factors is described through the rule base. The inference process supports uncertainty processing and outputs an interpretable confidence value.

[0103] This embodiment constructs a standardized verification result format. The result data includes comparison scores, confidence levels, and timestamp information. The data organization adopts a hierarchical structure, supporting the traceability and auditing of results. The format design takes into account subsequent processing requirements, facilitating the storage and analysis of results.

[0104] This embodiment realizes face verification through a secure feature comparison mechanism. The entire process from shard retrieval to result generation is completed in the ciphertext domain, ensuring the security of feature data. The multi-level verification mechanism and dynamic threshold management provide reliable verification results. This solution achieves efficient face feature comparison while protecting privacy.

[0105] In an embodiment of the face data privacy protection method of this application, refer to Figure 7 , and it may specifically include the following content: Step S701: Parse the feature comparison result based on a preset scoring rule, compare the similarity score of the feature comparison result with a confidence threshold, generate a verification conclusion including verification status, verification timestamp, and scoring details, digitally sign the verification conclusion, combine the signed verification conclusion with the verification operation record to form transaction data, and calculate the hash value of the transaction data to construct a block header; Step S702: Combine the block header with the transaction data to generate a new block, use the proof-of-work mechanism to broadcast the block in the blockchain network, verify the new block through a distributed consensus algorithm, generate block link information, append the verified block to the end of the existing blockchain structure, update the verification status information in the smart contract, and synchronize the block to other nodes in the blockchain distributed network.

[0106] Optionally, this embodiment adopts a hierarchical scoring mechanism in result parsing. First, construct a scoring rule tree, which includes evaluation indicators in multiple dimensions, such as similarity scores, feature quality, and environmental factors. The rule parsing adopts a recursive method to calculate the scores of each layer from bottom to top. The scoring weights are determined through expert knowledge and data analysis, supporting dynamic adjustment. The rule engine adopts a forward reasoning strategy to ensure the interpretability of the scoring process.

[0107] This embodiment realizes an adaptive confidence comparison strategy. The confidence threshold is dynamically set based on the security level of the verification scenario, and a more stringent threshold is adopted for high security levels. The comparison process considers the confidence interval and processes uncertainties through fuzzy logic. The threshold update adopts a feedback mechanism and automatically adjusts according to the verification accuracy. The comparison results are analyzed in association with historical data to identify abnormal patterns.

[0108] This embodiment designs a standardized verification conclusion format. The conclusion data includes a verification status code, a timestamp, scoring details, and environmental parameters. The status code defines multiple levels to refine the description of the verification result. The timestamp is in UTC format to support cross-timezone synchronization. The scoring details record the scores and weights of each dimension for subsequent analysis. The environmental parameters include hardware configuration and algorithm version information.

[0109] This embodiment adopts a multi-signature mechanism in digital signatures. In the signature process, first, the digest of the verification conclusion is calculated through a hash function, and then a signature is generated using the node's private key. The signature algorithm uses EdDSA to provide an efficient verification speed. Multi-signature requires multiple authorized nodes to participate, enhancing the credibility of the result. Signature verification supports batch processing mode to improve processing efficiency.

[0110] This embodiment constructs a complete transaction data structure. The transaction data includes verification conclusions, operation records, and signature information. The operation records detail the key steps of the verification process to support post-event auditing. Data serialization uses a compact format to optimize storage space. A random factor is added during the transaction construction process to prevent replay attacks.

[0111] This embodiment implements optimized hash calculation in block construction. The block header includes a version number, a timestamp, the hash of the previous block, and a difficulty target. The hash algorithm uses SHA3 to provide stronger security. The difficulty target maintains a stable block production time through a dynamic adjustment mechanism. The block structure adopts a hierarchical design to support fast verification.

[0112] This embodiment designs an efficient block broadcast mechanism. The broadcast adopts a hierarchical network architecture to optimize the propagation path through relay nodes. Node discovery is based on the Kademlia protocol to support dynamic node management. Compressed transmission is used during the broadcast process to reduce network load. New block verification uses pipeline processing to improve concurrent performance.

[0113] This embodiment adopts an improved proof-of-work mechanism in the consensus algorithm. First, the calculation difficulty target is adjusted through a random number to balance the network computing power distribution. The verification process supports parallel computing to improve verification efficiency. Consensus requires meeting the minimum confirmation number requirement to ensure transaction security. Fork handling adopts the longest chain principle to maintain network consistency.

[0114] This embodiment implements a reliable block linking mechanism. The linking information includes block hashes and serial numbers, and the block relationship is maintained through a doubly linked list. Block appending uses atomic operations to ensure state consistency. The chain structure supports fast traversal and retrieval to optimize query performance. Fork detection is implemented through a hash tree to detect anomalies in a timely manner.

[0115] In this embodiment, the verification status is managed through smart contracts. The status update adopts a transaction processing mechanism to ensure data consistency. The contract defines the state transition rules and supports complex business logics. The status synchronization adopts an incremental update strategy to improve the synchronization efficiency. Event logs are generated during the contract execution process, facilitating monitoring and analysis.

[0116] The technical solution of this embodiment realizes the trustworthy storage and synchronization of verification results. The whole process from result evaluation to blockchain synchronization ensures the integrity and traceability of data. The distributed architecture and consensus mechanism ensure the reliability and security of the system. This solution provides a complete verification result management solution for the face recognition system.

[0117] In order to solve the data security and privacy protection problems in traditional face recognition systems and provide a secure and trustworthy technical solution for the biometric recognition field, this application provides an embodiment of a face data privacy protection device for implementing all or part of the content of the face data privacy protection method. Refer to Figure 8 , the face data privacy protection device specifically includes the following content: A network construction module 10, used to establish a blockchain distributed network, configure multiple nodes in the network and connect them through a peer-to-peer communication protocol, construct a permission management module based on smart contracts, and control the data access of nodes through the permission management module; An image processing module 20, used to collect face image data and extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain target feature vectors, slice and homomorphically encrypt the target feature vectors, and package the encrypted feature slices and related operation information into blocks and store them in the blockchain distributed network; A privacy protection module 30, used to receive a face verification request, perform feature extraction and encryption slicing on the face image to be verified, retrieve the corresponding encrypted feature slices from the blockchain distributed network, perform slice recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and related information and write it into the blockchain distributed network.

[0118] As can be seen from the above description, the face data privacy protection device provided by the embodiment of this application can construct a trustworthy permission management mechanism through a distributed network and smart contracts, and innovatively designs a multi-dimensional feature extraction scheme that integrates geometric features and texture features. The system uses data slicing and homomorphic encryption technologies to securely process feature vectors, and dispersedly stores the encrypted data in the blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are performed in the ciphertext domain, and the whole process is traceable in combination with timestamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems and providing a secure and trustworthy technical solution for the biometric recognition field.

[0119] At the hardware level, in order to solve the data security and privacy protection problems in traditional face recognition systems and provide a secure and trustworthy technical solution for the field of biometric recognition, this application provides an embodiment of an electronic device for implementing all or part of the face data privacy protection method. The electronic device specifically includes the following: A processor, a memory, a communications interface, and a bus; wherein, the processor, the memory, and the communications interface complete communication with each other through the bus; the communications interface is used to implement information transmission between the face data privacy protection device and related devices such as the core business system, the user terminal, and the relevant database, etc. This logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., and this embodiment is not limited thereto. In this embodiment, this logic controller can be implemented with reference to the embodiments of the face data privacy protection method and the embodiments of the face data privacy protection device in the embodiments, and the content is incorporated herein, and the repeated parts will not be elaborated again.

[0120] It can be understood that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.

[0121] In practical applications, part of the face data privacy protection method can be executed on the electronic device side as described above, or all operations can be completed in the client device. Specifically, it can be selected according to the processing capacity of the client device and the limitations of the user usage scenario, etc. This application does not make any limitations in this regard. If all operations are completed in the client device, the client device may further include a processor.

[0122] The above-mentioned client device may have a communication module (i.e., a communication unit), and can be communicatively connected to a remote server to achieve data transmission with the server. The server may include a server on the task scheduling center side, and may also include a server on an intermediate platform in other implementation scenarios, such as a server on a third-party server platform communicatively linked to the task scheduling center server. The server may include a single computer device, or may include a server cluster composed of multiple servers, or a server structure of a distributed device.

[0123] Figure 9 It is a schematic block diagram of the system composition of the electronic device 9600 according to the embodiment of this application. As Figure 9As shown, the electronic device 9600 may include a central processor 9100 and a memory 9140; the memory 9140 is coupled to the central processor 9100. It should be noted that this Figure 9 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0124] In one embodiment, the function of the face data privacy protection method may be integrated into the central processor 9100. Among them, the central processor 9100 may be configured to perform the following controls: Step S101: Establish a blockchain distributed network, configure multiple nodes in the network and connect them through a peer-to-peer communication protocol, build a permission management module based on a smart contract, and control the data access of the nodes through the permission management module; Step S102: Collect face image data and extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain target feature vectors, perform sharding and homomorphic encryption on the target feature vectors, and package the encrypted feature shards and related operation information into a block and store it in the blockchain distributed network; Step S103: Receive a face verification request, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, perform shard recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and related information and write it into the blockchain distributed network.

[0125] As can be seen from the above description, the electronic device provided by the embodiment of the present application constructs a trusted permission management mechanism through a distributed network and a smart contract, and innovatively designs a multi-dimensional feature extraction scheme that combines geometric features and texture features. The system uses data sharding and homomorphic encryption technologies to securely process feature vectors, and dispersedly stores the encrypted data in the blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are performed in the ciphertext domain, and the whole process is traceable in combination with timestamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems, and providing a secure and trusted technical solution for the field of biometric recognition.

[0126] In another embodiment, the face data privacy protection device may be separately configured from the central processor 9100. For example, the face data privacy protection device may be configured as a chip connected to the central processor 9100, and the function of the face data privacy protection method is realized through the control of the central processor.

[0127] Such as Figure 9As shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include Figure 9 all the components shown in Figure 9 ; in addition, the electronic device 9600 may further include

[0128] As Figure 9 shown, the central processing unit 9100, sometimes also referred to as a controller or operation control, may include a microprocessor or other processor devices and / or logic devices. The central processing unit 9100 receives inputs and controls the operations of the various components of the electronic device 9600.

[0129] Among them, the memory 9140, for example, may be one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. It can store the above information related to failures, and can also store programs for executing relevant information. And the central processing unit 9100 can execute the programs stored in the memory 9140 to implement information storage or processing, etc.

[0130] The input unit 9120 provides inputs to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.

[0131] The memory 9140 may be a solid-state memory. For example, a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be such a memory that stores information even when powered off, can be selectively erased and has more data. Examples of such a memory are sometimes referred to as EPROM, etc. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142, and the application / function storage unit 9142 is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.

[0132] The memory 9140 may further include a data storage unit 9143 for storing data such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers of the electronic device for communication functions and / or for performing other functions of the electronic device (such as a messaging application, an address book application, etc.).

[0133] The communication module 9110 is a transmitter / receiver that transmits and receives signals via the antenna 9111. The communication module 9110 (transmitter / receiver) is coupled to the central processing unit 9100 to provide input signals and receive output signals, which may be the same as in the case of a conventional mobile communication terminal.

[0134] Based on different communication technologies, multiple communication modules 9110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module 9110 (transmitter / receiver) is also coupled to the speaker 9131 and the microphone 9132 via the audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby implementing normal telecommunication functions. The audio processor 9130 may include any suitable buffers, decoders, amplifiers, etc. In addition, the audio processor 9130 is also coupled to the central processing unit 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.

[0135] Embodiments of the present application also provide a computer-readable storage medium capable of implementing all steps of the face data privacy protection method in which the execution subject in the above embodiments is a server or a client. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, all steps of the face data privacy protection method in which the execution subject in the above embodiments is a server or a client are implemented. For example, when the processor executes the computer program, the following steps are implemented: Step S101: Establish a blockchain distributed network, configure multiple nodes in the network and connect them through a peer-to-peer communication protocol, construct a permission management module based on a smart contract, and control the data access of the nodes through the permission management module; Step S102: Collect face image data, extract key point coordinates, construct a geometric feature vector and a texture feature vector, fuse and reduce the dimension of the feature vectors to obtain a target feature vector, perform sharding and homomorphic encryption on the target feature vector, and package the encrypted feature shards and related operation information into a block and store it in the blockchain distributed network; Step S103: Receive a face verification request, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, perform shard recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and relevant information and write it into the blockchain distributed network.

[0136] As can be seen from the above description, the computer-readable storage medium provided by the embodiments of the present application constructs a trusted permission management mechanism through a distributed network and a smart contract, and innovatively designs a multi-dimensional feature extraction scheme that combines geometric features and texture features. The system uses data sharding and homomorphic encryption technologies to securely process feature vectors and dispersedly stores the encrypted data in the blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are performed in the ciphertext domain, and the whole process can be traced by combining timestamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems and providing a secure and trusted technical solution for the field of biometric recognition.

[0137] The embodiments of the present application also provide a computer program product capable of implementing all the steps in the face data privacy protection method whose execution subject in the above embodiments is a server or a client. When the computer program / instructions are executed by a processor, the steps of the face data privacy protection method are implemented. For example, the computer program / instructions implement the following steps: Step S101: Establish a blockchain distributed network, configure multiple nodes in the network and connect them through a peer-to-peer communication protocol, construct a permission management module based on a smart contract, and control the data access of the nodes through the permission management module; Step S102: Collect face image data and extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain target feature vectors, perform sharding and homomorphic encryption on the target feature vectors, and package the encrypted feature shards and relevant operation information into a block and store it in the blockchain distributed network; Step S103: Receive a face verification request, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, perform shard recombination and feature comparison in the ciphertext domain, and generate a new block with the verification conclusion and relevant information and write it into the blockchain distributed network.

[0138] As can be seen from the above description, the computer program product provided by the embodiments of the present application constructs a trusted permission management mechanism through a distributed network and smart contracts, and innovatively designs a multi-dimensional feature extraction scheme that integrates geometric features and texture features. The system uses data sharding and homomorphic encryption technologies to securely process feature vectors, and dispersedly stores the encrypted data in the blockchain network, realizing the decentralized management of feature data. Feature comparison and identity verification are performed in the ciphertext domain, and the whole process can be traced by combining timestamps and operation records, effectively solving the data security and privacy protection problems in traditional face recognition systems, and providing a secure and trusted technical solution for the field of biometric recognition.

[0139] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, apparatus, or computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0140] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0141] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0142] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for realizing the functions in Figure 1One process or multiple processes and / or boxes Figure 1 Steps of functions specified in one box or multiple boxes.

[0143] In the present invention, specific embodiments are used to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A method for protecting face data privacy, characterized in that: The method comprises: Establish a distributed blockchain network, configure multiple nodes in the network and connect them through a point-to-point communication protocol, build a rights management module based on smart contracts, and control data access to the nodes through the rights management module; Collect facial image data and extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain a target feature vector, slice and homomorphically encrypt the target feature vector, package the encrypted feature slices and related operation information to generate blocks and store them in the blockchain distributed network; Receive face verification requests, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, reorganize the shards and compare the features in the ciphertext domain, generate a new block with the verification conclusion and related information, and write it into the blockchain distributed network.

2. The method for protecting face data privacy according to claim 1, characterized in that: The establishment of a distributed blockchain network, in which multiple nodes are configured and connected via a point-to-point communication protocol, includes: Establishing a blockchain distributed network, configuring a plurality of nodes in the blockchain distributed network, and connecting the plurality of nodes through a point-to-point communication protocol; Generate unique identities and access keys in the multiple nodes, and write the unique identities and access keys into the smart contract.

3. The method for protecting face data privacy according to claim 1, characterized in that: The method of collecting face image data and extracting key point coordinates, constructing geometric feature vectors and texture feature vectors, fusing the feature vectors and reducing their dimensions to obtain a target feature vector includes: Collecting facial image data, extracting key point coordinates in the facial image data, and constructing a geometric feature vector based on the key point coordinates; The texture feature vector of the face image data is calculated, the geometric feature vector and the texture feature vector are fused to obtain a fused feature vector, and a dimensionality reduction transformation is performed on the fused feature vector to obtain a target feature vector.

4. The method for protecting face data privacy according to claim 1, characterized in that: The sharding and homomorphic encryption of the target feature vector includes: Dividing the target feature vector into multiple data slices, and performing homomorphic encryption on the multiple data slices to obtain encrypted feature slices; The encrypted feature fragments, operation timestamps, and operation records are packaged to generate blocks.

5. The method for protecting face data privacy according to claim 1, characterized in that: The step of packaging the encrypted feature fragments and related operation information to generate blocks and storing them in the blockchain distributed network includes: Distribute and store the blocks to multiple nodes in the blockchain distributed network; The access operation of the encrypted feature shard is recorded based on the smart contract, and the access operation is executed after verification by the authority management module.

6. The method for protecting face data privacy according to claim 1, characterized in that: The receiving of the face verification request and performing feature extraction and encryption slicing on the face image to be verified include: Receive a face verification request and obtain the face image to be verified; Repeat the feature extraction and encryption sharding process to obtain the encrypted feature shard to be verified, and retrieve the encrypted feature shard from the blockchain distributed network.

7. The method for protecting face data privacy according to claim 1, characterized in that: The method of retrieving the corresponding encrypted feature shards from the blockchain distributed network, reorganizing the shards and comparing the features in the ciphertext domain, and generating a new block with the verification conclusion and related information and writing it into the blockchain distributed network includes: Reorganize the encrypted feature fragments to be verified and perform feature comparison on the encrypted feature fragments in the ciphertext domain to generate a comparison result; A verification conclusion is determined according to the comparison result, a new block is generated by recording the verification conclusion, verification timestamp and verification operation, and the new block is written into the blockchain distributed network.

8. A face data privacy protection device, characterized in that: The device comprises: A network construction module is used to establish a distributed blockchain network, configure multiple nodes in the network and connect them through a point-to-point communication protocol, build a rights management module based on smart contracts, and control data access to nodes through the rights management module; An image processing module is used to collect face image data and extract key point coordinates, construct geometric feature vectors and texture feature vectors, fuse and reduce the dimension of the feature vectors to obtain a target feature vector, slice and homomorphically encrypt the target feature vector, package the encrypted feature slices and related operation information to generate blocks and store them in a blockchain distributed network; The privacy protection module is used to receive face verification requests, perform feature extraction and encryption sharding on the face image to be verified, retrieve the corresponding encrypted feature shards from the blockchain distributed network, reorganize the shards and compare the features in the ciphertext domain, and generate a new block with the verification conclusion and related information and write it into the blockchain distributed network.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the facial data privacy protection method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the facial data privacy protection method described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Image generation method, mouth shape driving model training method, device and equipment

    CN118521682A

  • Access control system based on 3D face recognition technology

    CN118840773A

  • Data security gateway method and system based on edge privacy calculation

    CN118921161A

  • Data security sharing method and system

    CN119483909A

  • Method and apparatus for creating encoded data and use of same for identity verification

    US20240348603A1

Cited By

  • Cleaning and spraying data management system based on block chain

    CN120336432A

  • Cleaning and spraying data management system based on blockchain

    CN120336432B

  • Face image enhancement and recognition method in low-light environment

    CN120452048A

  • Face image enhancement and recognition method in low-light environment

    CN120452048B

  • Cross-system collaborative protection system and method based on face data

    CN120710702A