Security authentication method based on secure computer

By building a security certification center on a secure computer, collecting and evaluating user's face images and behavioral data, the security risks and lack of dynamics of traditional authentication methods are solved, and higher authentication security and flexibility are achieved.

CN120074939APending Publication Date: 2025-05-30QINGDAO HOTEL MANAGEMENT VOCATIONAL & TECH COLLEGE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510278692.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Traditional username and password authentication methods have security risks such as easy to be stolen and cracked, which cannot meet the high security needs of modern network applications, and lack dynamics and flexibility, making it difficult to adapt to user behavior characteristics and changing security needs.

Method used

A security authentication method based on a secure computer is adopted, and a security authentication center is built through a client and a security computing organization, the user's face image and behavior data are collected, the face authentication evaluation and dynamic behavior evaluation are carried out, and the face authentication index and behavior evaluation index are generated to determine whether the user meets the authentication needs.

Benefits of technology

It realizes a safer and reliable authentication environment, enhances the flexibility and adaptability of authentication, dynamically adjusts user authentication levels, and improves the security, accuracy and efficiency of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074939A_ABST
    Figure CN120074939A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computer authentication, and discloses a security authentication method based on a secure computer, which comprises the following steps: constructing a security authentication center taking a client and the secure computer as a basic framework; initiating an authentication request based on the client, and performing request verification on the corresponding authentication request; if the request passes verification; performing data acquisition on related information of a corresponding user authentication process based on the client to obtain corresponding authentication information; the authentication information comprises a user face image and user behavior data; performing data processing on the user face image and the user behavior data in the uploaded authentication information to obtain a corresponding face authentication index and a behavior evaluation index; based on the obtained face authentication index and the behavior evaluation index, judging whether the corresponding user meets the authentication requirement or not; if yes, authentication succeeds; the method has the beneficial effects of improving the authentication safety, enhancing the authentication accuracy, improving the authentication efficiency, enhancing the authentication process and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer authentication, and more specifically, to a security authentication method based on a secure computer. Background Art

[0002] With the rapid development of information technology, network security issues have become increasingly prominent. Ensuring the authenticity and security of user identities has become a key issue in network applications. Traditional authentication methods, such as username and password authentication, have security risks such as being easily stolen and cracked, and are no longer able to meet the high security requirements of modern network applications. To address these challenges, people have started to explore more secure and reliable authentication methods. Among them, authentication methods based on biometric and behavioral data have received extensive attention due to their uniqueness and difficulty in replication. For example, how to efficiently collect and process users' face images and behavioral data, how to accurately evaluate users' authentication information and make decisions, and how to ensure the security and stability of the entire authentication process.

[0003] Compared with the prior art, traditional authentication methods, such as authentication based on usernames and passwords, have security risks such as being easily stolen and cracked, and cannot meet the requirements of an environment with high security needs. At the same time, traditional authentication methods are too single, and the authentication process lacks dynamics, that is, the same verification information is used for each authentication, without considering users' behavioral characteristics. With the increase in the number of users and the diversification of authentication requirements, traditional authentication systems are often difficult to expand flexibly and cannot meet the changing security needs.

[0004] In view of this, the present invention proposes a security authentication method based on a secure computer to solve the above problems. Summary of the Invention

[0005] To overcome the above-mentioned defects of the prior art and to achieve the above object, the present invention provides the following technical solution: A security authentication method based on a secure computer, including:

[0006] Step 1: Construct a security authentication center with a client and a secure computer as the basic framework;

[0007] Step 2: Based on the client, initiate an authentication request and perform request verification on the corresponding authentication request. If the request verification passes, proceed to Step 3;

[0008] Step 3: Based on the client, collect data on relevant information during the corresponding user authentication process to obtain the corresponding authentication information; the authentication information includes the user's face image and the user's behavioral data;

[0009] Step 4: Respectively conduct face authentication evaluation and dynamic behavior evaluation on the user's face image and user behavior data in the uploaded authentication information to obtain the corresponding face authentication index and behavior evaluation index;

[0010] Step 5: Based on the obtained face authentication index and behavior evaluation index, determine whether the corresponding user meets the authentication requirements; if so, the authentication is successful.

[0011] Furthermore, the client is used for the user to initiate an authentication request, and is also used for collecting and uploading the authentication information related to the user; the security computer is used to execute the corresponding authentication process and store the data involved in the corresponding authentication process.

[0012] Furthermore, the process of initiating an authentication request based on the client and verifying the corresponding authentication request includes:

[0013] A permission verification unit is set in the client. The user to be authenticated inputs the corresponding login account and login password into the permission verification unit to complete the login of the client. After the login is completed; the user to be authenticated can initiate an authentication request based on the client and send it to the corresponding security computer;

[0014] After the security computer receives the corresponding authentication request, it randomly selects an integer k and sends it back to the client; at the same time, the security computer retrieves the user key stored based on the authentication request to obtain the user key corresponding to the corresponding user to be authenticated; where k ∈ (1, n - 1); n > 1 and n is an integer;

[0015] After the client receives the integer k, it constructs the corresponding signature authentication information YZ yh =(r, s); in the formula, r = x × mod × n; r represents the signature parameter; mod represents the modulo operation; x represents the abscissa obtained after multiplying the integer k by the generator in cryptography;

[0016] s = (h1(ID yh ||T yh ) + r × SK yh ) × k -1 × mod × n; in the formula, h1() represents the hash operation, ID yh represents the client number of the corresponding user to be authenticated; T yh represents the request time when the user to be authenticated initiates an authentication request; ∥ represents the concatenation operation; SK yh represents the user key to which the corresponding user to be authenticated belongs;

[0017] Furthermore, the client sends the corresponding signature authentication information to the secure computer. After receiving the corresponding signature authentication information, the secure computer verifies the request time in the corresponding signature authentication information. After the verification passes, it parses the received signature authentication information based on the retrieved user key to obtain the integer corresponding to the parsed signature authentication information, and records it as k`; compares the obtained integer k` with the randomly selected original integer k; and determines whether the request verification passes based on the comparison result. If the request verification passes, the corresponding client is connected to the secure computer; if the request verification fails, an authentication failure notice is returned to the corresponding client.

[0018] Furthermore, the process of obtaining the login account and login password includes:

[0019] A registration unit for user identity registration verification is set up for the user to register identity information. The user's personal basic information is input through the registration unit, and the secure computer audits the input personal basic information and outputs an audit result.

[0020] After the audit passes, the corresponding login account and login password are generated based on the input personal basic information and fed back to the corresponding user. At the same time, a corresponding client number and user key are constructed based on the personal basic information and sent to the corresponding client for storage, and the client number and user key are stored in the secure computer.

[0021] Furthermore, the process of collecting data on relevant information in the authentication process of the corresponding user to be authenticated by the client to obtain the corresponding authentication information includes:

[0022] When the client recognizes that it has been connected to the secure computer, it collects data on the authentication process of the corresponding user to be authenticated, obtains the corresponding authentication information, and uploads the collected authentication information to the secure computer; the authentication information includes the user's face image and user behavior data.

[0023] Furthermore, the process of performing face authentication evaluation on the user's face image in the uploaded authentication information includes:

[0024] Obtain the user's face image in the authentication information, and decompose the user's face image to obtain the corresponding blurred image and high-frequency image;

[0025] Perform image segmentation on the obtained blurred image and construct a corresponding set of blurred subgraphs, which consists of several blurred image blocks;

[0026] Obtain the similarity between adjacent blurred image patches respectively, construct a corresponding similarity sequence based on it, obtain the adjacent blurred image patches with the highest similarity based on the similarity sequence; and merge them in blocks to obtain corresponding initial image patches, and update them into the blurred sub-image set; and remove the blurred image patches involved in the corresponding initial image patches.

[0027] Furthermore, obtain the similarity between the corresponding initial image patches and other blurred image patches, and so on until the preset removal stop condition is met, to obtain a corresponding initial image set, and the initial image set is composed of several initial image patches.

[0028] Number the initial image patches in the corresponding initial image set, denoted as i, i = 1, 2 ……, N, where N > 0 and N is an integer; N represents the total number of initial image patches.

[0029] Obtain the corresponding initial image patch i and perform adaptive local image optimization on it to obtain a corresponding optimized image patch.

[0030] The formula for the corresponding adaptive local image optimization is: In the formula, TK i represents the i-th initial image patch in the initial image set; TK` i represents the optimized image patch corresponding to the i-th initial image patch after adaptive local image optimization; α represents the fusion weight; TK (i,j) represents the j-th face image patch within the local range centered on the image patch TK i ; w (i,j) represents the block weight corresponding to the j-th face image patch within the local range centered on the image patch x i ; where In the formula, h represents the control weight value. M > 0 and M is an integer, and M represents the total number of face image patches within the corresponding local range.

[0031] Furthermore, merge the obtained optimized image patches in blocks to obtain a corresponding optimized image, and perform global optimization on the corresponding optimized image; and mark the optimized image after global optimization as the first image; and determine whether it meets the preset image stop condition. If it meets, mark the corresponding first image as the enhanced face image and output it; if it does not meet, perform secondary processing on the corresponding first image based on the face authentication evaluation process of the user's face image to obtain a new first image, and so on; until it meets the preset image stop condition.

[0032] Read the obtained enhanced face image and input it into a pre-constructed improved identity recognition model to obtain the corresponding model output result. The model data result is the face features and corresponding feature vectors corresponding to the input enhanced face image;

[0033] Obtain the client number of the corresponding user to be authenticated, and based on it, obtain the user's face image pre-stored in the security computer. And based on the acquisition process of the above model output result, obtain the face features and corresponding feature vectors corresponding to the user's face image;

[0034] Based on the obtained model output result, mark and intercept the corresponding user's face image to obtain several face feature regions; at the same time, obtain the face feature regions corresponding to the user's face image;

[0035] Compare the corresponding face feature regions with the face feature regions at the corresponding positions respectively, and obtain the corresponding face authentication index based on it.

[0036] Further, the process of constructing the identity authentication model includes:

[0037] Define the network architecture of the identity authentication model as an improved DCNN network; the basic framework of the DCNN network is an input layer, a convolutional layer, an attention layer, and an output layer;

[0038] The input layer is used to receive the input face image and perform image mapping on the input face image to meet the requirements of the identity authentication model;

[0039] The convolutional layer is used to perform convolutional processing on the input face image and output the corresponding feature map;

[0040] The attention layer is used to weight the obtained feature map and perform self-attention learning on the corresponding feature map based on the weighted result;

[0041] The output layer is used to receive the feature map after attention learning and perform image mapping on it to output the corresponding face features and face feature vectors;

[0042] Define the parameter optimizer of the identity authentication model as SGD; obtain several user face images; based on them, construct the corresponding training data set, divide the training data set into batches, and train the identity authentication model. By passing the training data set batches into the identity authentication model and calculating the gradient based on the loss function, use the backpropagation algorithm to update the weights of the model, and record the value of the loss function for each batch. When the value of the loss function no longer decreases or changes in consecutive P1 batches, stop training and save the parameters of the identity authentication model at this time, that is, complete the training of the identity authentication model; P1 is a fixed constant;

[0043] Furthermore, define the formula for convolution processing as:

[0044] In the formula, f 1 , f 2 and f 3 respectively represent different pre-selected activation functions; * represents the convolution operation; Q l represents the output feature map of the l-th layer of convolution; Q l-1 is the output feature map of the (l - 1)-th layer of convolution, which is the previous layer of the l-th layer of convolution; Both are bias terms;

[0045] The process of weighting the obtained feature map includes:

[0046] Obtain the feature map output by each channel in the convolution layer, and perform global average pooling operation on it to obtain the global perception value corresponding to the corresponding channel; and use it as the feature weight corresponding to the corresponding channel; that is, the weighting of the feature map is completed;

[0047] The formula for the corresponding global average pooling operation is: In the formula, H and W respectively represent the length and width of the output feature map of channel td; u and v respectively represent the horizontal and vertical coordinates of the pixel points in the feature map; O td represents the output result of the global average pooling operation in channel td;

[0048] Define the formula for self-attention learning as: Y` = g(μ × G td + ρ × T td , V td ); In the formula, Y` represents the feature map after self-attention learning, g() represents the transformation function; μ and ρ respectively represent the image weights of the input feature map and the output feature map in channel td; G td represents the result of the global average pooling operation of channel td; V td represents the feature weight assigned to the feature map; T td represents the input feature map in channel td;

[0049] Define the loss function of the identity authentication model as LOSS = loss jc + loss face ; where, loss jc represents the cross-entropy loss function and the angular margin loss function;

[0050] In the formula, E represents the total number of training samples in the training data set; y is the index of the training sample; represents the weight vector corresponding to the feature map output by the attention layer; b_y and b t_0denotes the bias term; sr y is the output feature vector after global average pooling operation; T0 and t_0 respectively denote the total number of known face feature categories and the feature index; denotes the feature vector of the t_0-th known face feature of the input; sr t_0 denotes the t_0-th known face feature of the input;

[0051] In the formula, ε y denotes the class weight to which the y-th training sample belongs; θ y denotes the vector angle between the predicted value and the corresponding feature vector of the actual value; φ(d) represents the adaptive function of the vector angle; denotes the coefficient of regularization; λ represents the feature scale.

[0052] Furthermore, the process of dynamically evaluating the user behavior data in the uploaded authentication information includes:

[0053] Read the user behavior data in the collected authentication information and perform data preprocessing on it to obtain the corresponding initial user data; after the preprocessing is completed, construct the corresponding first user behavior pattern baseline based on the obtained initial user data;

[0054] Obtain the client number of the corresponding client of the user to be authenticated, and based on it, read the historical user behavior data of the corresponding user to be authenticated in the corresponding security computer and record it as personal behavior data; at the same time, read the historical user behavior data corresponding to several other users during the historical authentication process and mark it as reference behavior data;

[0055] Construct the corresponding second user behavior pattern baseline and reference behavior pattern baseline based on the personal behavior data and reference behavior data respectively;

[0056] Compare the obtained first user behavior pattern baseline with the corresponding reference behavior pattern baseline and second user behavior pattern baseline respectively; and assign scores based on the comparison results to obtain the corresponding user baseline score and reference baseline score;

[0057] Furthermore, perform weighted summation on the obtained user baseline score and reference baseline data to obtain the corresponding behavior evaluation index.

[0058] Furthermore, the process of determining whether the corresponding user to be authenticated meets the authentication requirements based on the obtained face authentication index and behavior evaluation index includes:

[0059] Set an authentication threshold, compare the obtained face authentication index with the corresponding authentication threshold. If the corresponding face authentication index is less than the authentication threshold, feedback an authentication failure notice and the reason for failure to the corresponding client; if the corresponding face authentication index is not less than the authentication threshold, obtain the behavior evaluation index of the corresponding user to be authenticated during the authentication process, and assign a level to the authentication process of the corresponding user to be authenticated based on it to obtain the corresponding authentication level;

[0060] If the authentication level of the corresponding user to be authenticated is less than the pre-set level requirement, feedback an authentication failure notice; if the authentication level of the corresponding user to be authenticated is not less than the pre-set level requirement, feedback an authentication success notice and allow the corresponding user to be authenticated to access the secure computer.

[0061] The technical effects and advantages of a security authentication method based on a secure computer according to the present invention:

[0062] 1. By constructing a security authentication center with the client and the secure computer as the basic framework, centralized management and secure processing of user authentication requests are realized, effectively preventing illegal access and malicious attacks;

[0063] 2. Through face recognition and combined with the analysis of user behavior data in the present invention, the authentication process becomes more flexible and adaptable to the authentication requirements in different scenarios; and the authentication level will be updated in real time according to the behavior evaluation index of the user. The higher the user authentication level, the longer the allowed access time. The dynamic adjustment mechanism enhances the flexibility and adaptability of the authentication; therefore, the present invention has significant beneficial effects in improving authentication security, accuracy, flexibility, efficiency, and ensuring data security and privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is a schematic flowchart of a security authentication method based on a secure computer according to the present invention;

[0065] Figure 2 It is a schematic diagram of the invention of a security authentication system based on a secure computer according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0066] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0067] Embodiment 1

[0068] Please refer to Figure 1As shown in the figure, a security authentication method based on a security computer in this embodiment includes:

[0069] Step 1: Construct a security authentication center with the client and the security computer as the basic framework;

[0070] Step 2: Initiate an authentication request based on the client and verify the corresponding authentication request; if the request verification passes, proceed to Step 3;

[0071] Step 3: Collect data on relevant information during the corresponding user authentication process based on the client to obtain the corresponding authentication information; the authentication information includes the user's face image and the user's behavior data;

[0072] Step 4: Conduct face authentication evaluation and dynamic behavior evaluation on the user's face image and the user's behavior data in the uploaded authentication information respectively to obtain the corresponding face authentication index and behavior evaluation index;

[0073] Step 5: Determine whether the corresponding user meets the authentication requirements based on the obtained face authentication index and behavior evaluation index; if so, the authentication is successful;

[0074] It should be further noted that in the specific implementation process, a security authentication center is constructed with the client and the security computer as the basic framework; the client is used for the user to initiate an authentication request, and is also used for collecting and uploading authentication information related to the user; the security computer is used to execute the corresponding authentication process and store the relevant data involved in the corresponding authentication process;

[0075] It should be further noted that in the specific implementation process, the process of initiating an authentication request based on the client and verifying the corresponding authentication request includes:

[0076] A permission verification unit is set in the client. The user to be authenticated inputs the corresponding login account and login password into the permission verification unit to complete the client login. After the login is completed, the user to be authenticated can initiate an authentication request based on the client and send it to the corresponding security computer;

[0077] After the security computer receives the corresponding authentication request, it randomly selects an integer k and sends it back to the client; at the same time, the security computer retrieves the stored user key based on the authentication request to obtain the user key corresponding to the user to be authenticated; where k ∈ (1, n - 1); n > 1 and n is an integer;

[0078] After the client receives the integer k, it constructs the corresponding signature authentication information YZ based on the integer k yh=(r, s); where r = x × mod × n; r represents the signature parameter, which is used to ensure the uniqueness of the signature and the consistency during the verification process; mod represents the modulo operation; n represents a constant; x represents the abscissa obtained after multiplying the integer k by the generator in cryptography; wherein, the cryptography intended to be used in the present invention is elliptic curve cryptography;

[0079] s = (h1(ID yh ||T yh ) + r × SK yh ) × k -1 × mod × n; where h1() represents the hashing operation, ID yh represents the client number of the corresponding user to be authenticated; T yh represents the request time when the user to be authenticated initiates an authentication request; ∥ represents the concatenation operation; SK yh represents the user key to which the corresponding user to be authenticated belongs;

[0080] Furthermore, the client sends the corresponding signature authentication information to the security computer. After receiving the corresponding signature authentication information, the security computer verifies the request time in the corresponding signature authentication information. After the verification passes, it parses the received signature authentication information based on the retrieved user key to obtain the integer corresponding to the parsed signature authentication information, and records it as k`; compares the obtained integer k` with the randomly selected original integer k; if k` = k, it indicates that the authentication request of the corresponding client is verified, and then the corresponding client is connected to the security computer to complete the subsequent authentication process; if k` ≠ k, it indicates that the authentication request of the corresponding client fails, and then an authentication failure notice and the reason for the authentication failure are returned to the corresponding client; at the same time, the corresponding authentication request is recorded as a failed authentication; wherein, the method for verifying the request time T yh is as follows: calculate the time error between the received request time T yh and the current time, and compare it with the preset error range. If it exceeds the error range, the verification fails; if it is within the error range, the verification passes;

[0081] It should be further noted that, in the specific implementation process, the process of obtaining the login account and login password includes:

[0082] Set a registration unit for the user to perform identity registration verification, for the user to perform identity information registration, input the user's personal basic information through the registration unit, and the security computer audits the input personal basic information and outputs the audit result; wherein, the personal basic information includes name, gender, age, ID number, and real-name authenticated mobile phone number;

[0083] After passing the review, the corresponding login account and login password are generated according to the input personal basic information and feedback to the corresponding user. At the same time, the corresponding client number and user key are constructed based on the personal basic information and sent to the corresponding client for storage, and the client number and user key are stored in a secure computer.

[0084] It should be further noted that in the specific implementation process, the process of collecting data on relevant information of the corresponding user to be authenticated by the client to obtain the corresponding authentication information includes:

[0085] When the client recognizes that it has been connected to the secure computer, it collects data on the authentication process of the corresponding user to be authenticated, obtains the corresponding authentication information, and uploads the collected authentication information to the secure computer; the authentication information includes the user's face image and user behavior data.

[0086] It should be further noted that in the specific implementation process, the process of performing face authentication evaluation on the user's face image in the uploaded authentication information includes:

[0087] Obtain the user's face image in the authentication information, and perform image decomposition on the user's face image to obtain the corresponding blurred image and high-frequency image; the blurred image and high-frequency image respectively represent the sub-images corresponding to the user's face image at low resolution and high resolution;

[0088] Perform image segmentation on the obtained blurred image and construct the corresponding set of blurred sub-images, and the set of blurred sub-images is composed of several blurred image blocks;

[0089] Obtain the similarity between adjacent blurred image blocks respectively, and construct the corresponding similarity sequence based on it. Obtain the adjacent blurred image blocks with the highest similarity based on the similarity sequence; and perform block merging on them to obtain the corresponding initial image block, and update it to the set of blurred sub-images; and remove the blurred image blocks involved in the corresponding initial image block;

[0090] Furthermore, obtain the similarity between the corresponding initial image block and other blurred image blocks, and so on, until the pre-set removal stop condition is met, and obtain the corresponding initial image set, and the initial image set is composed of several initial image blocks; where the removal stop condition is that the highest similarity between adjacent image blocks is less than the pre-set similarity threshold, or the constructed similarity sequence is empty;

[0091] Number the initial image blocks in the corresponding initial image set, denoted as i, i = 1, 2..., N, N > 0 and N is an integer; N represents the total number of initial image blocks;

[0092] Obtain the corresponding initial image block i and perform adaptive local image optimization on it to obtain the corresponding optimized image block; wherein, the purpose of the adaptive local image optimization is to optimize the irregular parts of the image contour within the corresponding initial image block.

[0093] The formula for the corresponding adaptive local image optimization is: In the formula, TK i represents the i-th initial image block in the initial image set; TK` i represents the optimized image block corresponding to the i-th initial image block after adaptive local image optimization; α represents the fusion weight; is a fixed constant; TK (i,j) represents the j-th face image block within the local range centered on the image block TK i ; wherein, the specific size of the local range is determined according to actual needs; w (i,j) represents the block weight corresponding to the j-th face image block within the local range centered on the image block x i ; wherein, In the formula, h represents the control weight, which is related to the Euclidean distance between the face image block TK i and the face image block TK (i,j) . M > 0 and M is an integer, M represents the total number of face image blocks within the corresponding local range;

[0094] Furthermore, merge the obtained optimized image blocks to obtain the corresponding optimized image. Since the corresponding adaptive local image optimization process does not consider the overall effect of the image, it is necessary to perform global optimization on the corresponding optimized image. The formula for the corresponding global optimization is: TX` = argmin TX ||TX - TX 0 ||; In the formula, TX` represents the optimized image after global optimization; TX represents the obtained high-frequency image, TX0 represents the obtained optimized image; argmin is used to represent the value required to find the minimum value of the function.

[0095] Mark the optimized image after global optimization as the first image; and determine whether it meets the pre-set image stop condition. If it meets, mark the corresponding first image as the enhanced face image and output it; if it does not meet, perform secondary processing on the corresponding first image based on the face authentication evaluation process of the user's face image to obtain a new first image, and so on; until it meets the pre-set image stop condition.

[0096] Among them, the formula for the image stop condition is: TX m+1 = TX m + T BP (TX - TX m)); where, TX m+1 represents the image obtained after the (m + 1)-th global optimization process; TX m represents the image obtained after the m-th global optimization process; T BP represents the back-projection matrix;

[0097] Read the obtained enhanced face image and input it into a pre-constructed improved identity recognition model to obtain a corresponding model output result, where the model data result is the face feature and the corresponding feature vector corresponding to the input enhanced face image;

[0098] Obtain the client number of the corresponding user to be authenticated, and based on it, obtain the user's face image pre-stored in the security computer for the user to be authenticated. And based on the acquisition process of the above model output result, obtain the face feature and the corresponding feature vector corresponding to the user's face image;

[0099] Based on the obtained model output result, mark and intercept the corresponding user's face image to obtain a number of face feature regions; at the same time, obtain the face feature region corresponding to the corresponding user's face image;

[0100] Compare the corresponding face feature regions with the face feature regions at the corresponding positions respectively, and obtain the corresponding face authentication index based on it where; PC a represents the pixel deviation between the a-th pixel point in the face feature region and the pixel point at the corresponding position in the face feature region; a = 1, 2,..., A, A > 0 and A is an integer, and A represents the total number of pixel points in the face feature region; tz` c and tz c represent the feature vectors of the c-th face feature region and the face feature region at the corresponding position respectively; c = 1, 2,..., P; P > 0 and P is an integer, and P represents the total number of face feature regions;

[0101] It should be further noted that in the specific implementation process, the process of constructing the identity authentication model includes:

[0102] Define the network architecture of the identity authentication model as an improved DCNN network; where, the basic framework of the DCNN network is an input layer, a convolutional layer, an attention layer, and an output layer;

[0103] The input layer is used to receive the input face image and perform image mapping on the input face image to meet the requirements of the identity authentication model;

[0104] The convolutional layer is used to perform convolutional processing on the input face image and output the corresponding feature map;

[0105] The attention layer is used to weight the obtained feature maps and perform self-attention learning on the corresponding feature maps based on the weighting results;

[0106] The output layer is used to receive the feature maps after attention learning and map them to images to output the corresponding face features and face feature vectors;

[0107] The formula for convolutional processing is defined as:

[0108] In the formula, f 1 , f 2 and f 3 respectively represent different activation functions selected in advance; * represents the convolutional operation; Q l represents the output feature map of the l-th layer of convolution; Q l-1 is the output feature map of the (l - 1)-th layer of convolution, which is the previous layer of the l-th layer of convolution. It should be noted that each convolutional layer will perform a convolutional operation on the output feature map of the previous layer; represents the weight of the convolutional kernel in the l-th layer under different activation functions, which is determined by the convolutional scale of the corresponding convolutional kernel; are both bias terms; con means connecting or combining vectors along the specified dimension;

[0109] Among them, the process of weighting the obtained feature maps includes:

[0110] Obtain the feature maps output by each channel in the convolutional layer, perform global average pooling operation on them, and obtain the global perception values corresponding to the corresponding channels; its role is to compress the feature maps from three dimensions to one dimension; and use them as the feature weights corresponding to the corresponding channels; that is, the weighting of the feature maps is completed;

[0111] The formula for the corresponding global average pooling operation is: In the formula, H and W respectively represent the length and width of the output feature map of channel td; u and v respectively represent the horizontal and vertical coordinates of the pixel points in the feature map; O td represents the output result of the global average pooling operation in channel td;

[0112] Among them, the present invention uses two fully connected layers for global average pooling operation; the first fully connected layer is used to reduce the number of channels, and then the ReLU activation function is used to increase the nonlinearity; the second fully connected layer restores the number of channels to the original quantity; furthermore, the output of the second fully connected layer is normalized to obtain the weight value of each channel;

[0113] The formula for self-attention learning is defined as: Y` = g(μ × G td + ρ × T td , V td);Wherein, Y` represents the feature map after self-attention learning, and g() represents a transformation function for performing form conversion or processing on the corresponding feature map based on a preset form; μ and ρ respectively represent the image weights of the input feature map and the output feature map within channel td; used to adjust the contribution degrees of the global average pooling result and the input feature map within channel td; G td represents the result of the global average pooling operation for channel td; V td represents the feature weight assigned to the feature map; T td represents the input feature map within channel td;

[0114] Define the loss function of the identity authentication model as LOSS = loss jc + loss face ; Among them, loss jc represents the cross-entropy loss function and the angular margin loss function;

[0115] In the formula, E represents the total number of training samples in the training data set; y is the index of the training sample; represents the weight vector corresponding to the feature map output by the attention layer; b_y and b t_0 represent the bias term; sr y is the output feature vector after the global average pooling operation; T0 and t_0 respectively represent the total number of known face feature categories and the feature index; represents the feature vector of the t_0-th known face feature input; sr t_0 represents the t_0-th known face feature input;

[0116] In the formula, ε y represents the class weight to which the y-th training sample belongs; θ y represents the vector angle between the predicted value and the actual value corresponding feature vectors; φ(d) represents the adaptive function of the vector angle; represents the coefficient of regularization; λ represents the feature scale;

[0117] Define the parameter optimizer of the identity authentication model as SGD; obtain several user face images; construct a corresponding training data set based on them, perform batch division on the training data set, and train the identity authentication model. By passing the training data set batches into the identity authentication model and calculating the gradient based on the loss function, use the backpropagation algorithm to update the weights of the model, and record the value of the loss function for each batch. Stop training when the value of the loss function no longer decreases or changes for consecutive P1 batches, and save the parameters of the identity authentication model at this time, that is, complete the training of the identity authentication model; P1 is a fixed constant;

[0118] It should be further noted that in the specific implementation process, the process of dynamically evaluating the user behavior data in the uploaded authentication information includes:

[0119] Read the user behavior data in the collected authentication information and perform data preprocessing on it to obtain corresponding initial user data; the data preprocessing is used to eliminate invalid or abnormal behavior data in the user behavior data;

[0120] After the preprocessing is completed, construct a corresponding first user behavior pattern baseline based on the obtained initial user data. The first user behavior pattern baseline is used to characterize the authentication behavior characteristics of the user to be authenticated in the corresponding authentication process. The authentication behavior characteristics include multiple characteristics such as authentication time, authentication client, authentication times, authentication location, etc.;

[0121] Obtain the client number of the corresponding client of the user to be authenticated, and read the historical user behavior data of the corresponding user to be authenticated in the corresponding security computer and record it as personal behavior data; at the same time, read the historical user behavior data corresponding to several other users in the historical authentication process and mark it as reference behavior data; among them, both the personal behavior data and the reference behavior data are the user behavior data corresponding to the user after completing the corresponding authentication process and until the access to the security computer ends (i.e., the access data in the normal authentication state);

[0122] Construct a corresponding second user behavior pattern baseline and reference behavior pattern baseline based on the personal behavior data and reference behavior data respectively;

[0123] Compare the obtained first user behavior pattern baseline with the corresponding reference behavior pattern baseline and second user behavior pattern baseline respectively; and assign scores based on the comparison results to obtain corresponding user baseline scores and reference baseline scores; among them, the higher the consistency between the corresponding first user behavior pattern baseline and the corresponding reference behavior pattern baseline and second user behavior pattern baseline, the higher the corresponding user baseline score and reference baseline score;

[0124] Furthermore, perform weighted summation on the obtained user baseline score and reference baseline data to obtain a corresponding behavior evaluation index;

[0125] It should be further noted that in the specific implementation process, since the historical user behavior data of other users stored in the security computer may be huge; to ensure the timeliness of data calculation volume, in the actual application process, data clustering will first be performed based on the historical user behavior data of the currently to-be-authenticated user to obtain the corresponding behavior clustering set; the behavior clustering set includes several historical user behavior data of the same category as the personal behavior data of the corresponding to-be-authenticated user; and randomly select several historical user behavior data from the corresponding clustering set as the required reference behavior data;

[0126] It should be further noted that in the specific implementation process, the process of judging whether the corresponding to-be-authenticated user meets the authentication requirements based on the obtained face authentication index and behavior evaluation index includes:

[0127] Set an authentication threshold, compare the obtained face authentication index with the corresponding authentication threshold. If the corresponding face authentication index is less than the authentication threshold, it indicates that the corresponding to-be-authenticated user does not meet the authentication requirements, and an authentication failure notice and the reason for failure will be fed back to the corresponding client; at the same time, record the corresponding authentication process as a failed authentication request; if the corresponding face authentication index is not less than the authentication threshold, obtain the behavior evaluation index of the corresponding to-be-authenticated user during the authentication process, and assign a level to the authentication process of the corresponding to-be-authenticated user based on it to obtain the corresponding authentication level;

[0128] If the authentication level of the corresponding to-be-authenticated user is less than the pre-set level requirement, still record the authentication request of the corresponding to-be-authenticated user as a failed authentication; feed back an authentication failure notice; if the authentication level of the corresponding to-be-authenticated user is not less than the pre-set level requirement; feed back an authentication success notice to the client corresponding to the to-be-authenticated user and allow the corresponding to-be-authenticated user to access the security computer;

[0129] It should be further noted that in the specific implementation process, the behavior evaluation index will be updated in real time as the authentication process of the to-be-authenticated user progresses, and when the to-be-authenticated user passes the authentication, the behavior evaluation index will be updated based on the access behavior of the corresponding to-be-authenticated user and the authentication level will be updated in real time based on it; and the higher the authentication level of the to-be-authenticated user, the longer the access time allowed for the corresponding to-be-authenticated user; if the authentication level of the to-be-authenticated user is less than the pre-set level requirement during the corresponding access process, the security computer will immediately disconnect the access status with the client of the to-be-authenticated user and clear all data read by the client during the access process.

[0130] The present invention can provide a more secure and reliable authentication environment by constructing a security authentication center based on a client and a security computer. The client is used for the user to initiate an authentication request and collect and upload data of relevant authentication information, while the security computer is responsible for executing the authentication process and storing relevant data. Such a design effectively isolates different links in the authentication process and reduces the risk of information leakage.

[0131] Embodiment 2

[0132] Please refer to Figure 2 As shown, for the parts not described in detail in this embodiment, refer to the description content of Embodiment 1. A security authentication system based on a security computer is provided, including:

[0133] A data collection module, which is used to obtain the user's authentication and verify the corresponding authentication request. If the request verification passes, it collects data on relevant information in the user authentication process to obtain the corresponding authentication information. The authentication information includes the user's face image and user behavior data.

[0134] A data processing module, which is used to perform face authentication evaluation and dynamic behavior evaluation on the user's face image and user behavior data in the obtained authentication information respectively, to obtain the corresponding face authentication index and behavior evaluation index.

[0135] A data authentication module, which determines whether the corresponding user meets the authentication requirements based on the obtained face authentication index and behavior evaluation index. If it meets the requirements, the authentication is successful.

[0136] Each module is connected by wired and / or wireless means to realize data transmission between modules.

[0137] Embodiment 3

[0138] This embodiment publicly provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it realizes the operation mode of the above-provided security authentication method based on a security computer.

[0139] Since the electronic device introduced in this embodiment is the electronic device adopted for implementing a security authentication method based on a security computer in an embodiment of the present application, based on the security authentication method based on a security computer introduced in an embodiment of the present application, those skilled in the art can understand the specific implementation manner and various variations of the electronic device in this embodiment. Therefore, the specific implementation of how this electronic device realizes the method in an embodiment of the present application will not be described in detail here. As long as those skilled in the art implement the electronic device adopted for a security authentication method based on a security computer in an embodiment of the present application, it falls within the scope of protection of the present application.

[0140] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data and performing software simulation to get a formula closest to the actual situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.

[0141] The above is only the preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for ordinary users in the technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. A security authentication method based on a secure computer, characterized in that: include: Step 1: Build a security authentication center based on the client and secure computer framework; Step 2: Initiate an authentication request based on the client and verify the corresponding authentication request; If the request verification is successful, proceed to step 3; Step 3: Based on the client, data is collected on the relevant information of the corresponding user authentication process to obtain corresponding authentication information; the authentication information includes the user's face image and user behavior data; Step 4: Perform face authentication evaluation and dynamic behavior evaluation on the user face image and user behavior data in the uploaded authentication information, respectively, to obtain the corresponding face authentication index and behavior evaluation index; Step 5: Based on the obtained face recognition index and behavior evaluation index, determine whether the corresponding user meets the authentication requirements; if yes, the authentication is successful.

2. A security authentication method based on a secure computer according to claim 1, characterized in that: The client is used for the user to initiate an authentication request, and is also used to collect and upload authentication information related to the user; the secure computer is used to execute the corresponding authentication process and store the data involved in the corresponding authentication process.

3. A security authentication method based on a secure computer according to claim 2, characterized in that: The process of initiating an authentication request based on the client and verifying the corresponding authentication request includes: The client is provided with an authority verification unit, and the user to be authenticated enters the corresponding login account and login password into the authority verification unit to complete the client login, and the login is completed; the user to be authenticated can initiate an authentication request based on the client and send it to the corresponding security computer; After the security computer receives the corresponding authentication request, it randomly selects an integer k and sends it back to the client; at the same time, the security computer retrieves the stored user key based on the authentication request to obtain the user key corresponding to the corresponding user to be authenticated; where k∈(1,n-1); n>1 and n is an integer; After the client receives the integer k, it constructs the corresponding signature authentication information YZ based on the integer k yh =(r,s); where r = x×mod×n; r represents the signature parameter; mod represents the modulo operation; x represents the horizontal coordinate obtained by multiplying the integer k by the generator; s=(h1(ID yh ||T yh )+r×SK yh )×k -1 ×mod×n; where h1() represents hash operation, ID yh Indicates the client ID of the corresponding user to be authenticated; T yh Indicates the time when the user to be authenticated initiates the authentication request; ∥ indicates a concatenation operation; SK yh Indicates the user key to which the corresponding user to be authenticated belongs; The client sends the corresponding signature authentication information to the security computer, and performs time verification on the request time in the corresponding signature authentication information. After the verification is passed, the received signature authentication information is parsed based on the retrieved user key to obtain an integer corresponding to the parsed signature authentication information, and record it as k`; the obtained integer k` is compared with the randomly selected original integer k; and based on the comparison result, it is determined whether the request verification is passed; if the request verification is passed, the corresponding client is connected to the security computer; if the request verification fails, an authentication failure notification is returned to the corresponding client.

4. A security authentication method based on a secure computer according to claim 3, characterized in that: The process of obtaining the login account and password includes: A registration unit is provided for user identity registration and verification, and the user registers identity information, inputs the user's basic personal information through the registration unit, and the security computer reviews the input basic personal information and outputs the review result; After the review is passed, the corresponding login account and login password are generated based on the personal basic information entered, and they are fed back to the corresponding user. At the same time, the corresponding client number and user key are constructed based on the personal basic information, and they are sent to the corresponding client for storage. At the same time, the client number and user key are stored in a secure computer.

5. A security authentication method based on a secure computer according to claim 3, characterized in that: Based on the client, data is collected on the authentication process of the corresponding user to be authenticated, and the process of obtaining the corresponding authentication information includes: When the client recognizes that it has access to a secure computer, it collects data on the authentication process of the corresponding user to be authenticated, obtains corresponding authentication information, and uploads the collected authentication information to the secure computer; the authentication information includes the user's facial image and user behavior data.

6. A secure computer-based security authentication method according to claim 5, characterized in that: The process of face authentication evaluation of the user's face image in the uploaded authentication information includes: Obtaining a user face image in the authentication information, and performing image decomposition on the user face image to obtain a corresponding blurred image and a high-frequency image; Performing image segmentation on the obtained fuzzy image and constructing a corresponding fuzzy sub-image set, wherein the fuzzy sub-image set is composed of a plurality of fuzzy image blocks; The similarities between adjacent blurred image blocks are respectively obtained, and a corresponding similarity sequence is constructed based on the similarity sequence, and adjacent blurred image blocks with the highest similarity are obtained based on the similarity sequence; the blocks are merged to obtain the corresponding initial image blocks, and the blocks are updated to the blurred sub-image set; and the blurred image blocks involved in the corresponding initial image blocks are eliminated; Obtaining the similarity between the corresponding initial image block and other blurred image blocks, and so on, until a preset elimination stop condition is met, to obtain a corresponding initial image set, wherein the initial image set is composed of a plurality of initial image blocks; The initial image blocks in the corresponding initial image set are numbered as i, i=1, 2, ..., N, N>0 and N is an integer; N represents the total number of initial image blocks; Obtain a corresponding initial image block i, and perform adaptive local image optimization on it to obtain a corresponding optimized image block; The corresponding formula for adaptive local image optimization is: Where, TK i represents the i-th initial image block in the initial image set; TK` i represents the optimized image block corresponding to the i-th initial image block after adaptive local image optimization; α represents the fusion weight; TK (i,j) Represented by image block TK i The jth face image patch in the local area is centered; w (i,j) Represents an image block x i The block weight corresponding to the j-th face image block in the local range is centered; In the formula, h represents the control weight; M>0 and M is an integer, M represents the total number of face image blocks in the corresponding local range; Merge the obtained optimized image blocks to obtain a corresponding optimized image, and globally optimize the corresponding optimized image; mark the globally optimized optimized image as a first image; and determine whether it meets a preset image stop condition. If so, mark the corresponding first image as an enhanced face image and output it; if not, perform secondary processing on the corresponding first image based on a face authentication evaluation process of a user face image to obtain a new first image, and so on; until it meets the preset image stop condition; Reading the obtained enhanced face image and inputting it into a pre-built improved identity recognition model to obtain a corresponding model output result, wherein the model data result is the face features and corresponding feature vectors corresponding to the input enhanced face image; Obtain the client ID of the corresponding user to be authenticated, and based on the client ID, obtain the user facial image of the user to be authenticated pre-stored in the security computer, and based on the acquisition process of the above model output result, obtain the facial features and corresponding feature vectors corresponding to the facial image of the corresponding user; Based on the obtained model output results, the corresponding user's face image is marked and the image is intercepted to obtain a number of facial feature areas; at the same time, the facial feature areas corresponding to the corresponding user's face image are obtained; The corresponding facial feature areas are compared with the facial feature areas at the corresponding positions, and the corresponding face authentication index is obtained based on them.

7. A secure computer-based security authentication method according to claim 6, characterized in that: The process of building an authentication model includes: The network architecture of the identity authentication model is defined as an improved DCNN network; the basic framework of the DCNN network is an input layer, a convolution layer, an attention layer and an output layer; The input layer is used to receive the input face image and perform image mapping on the input face image to meet the requirements of the identity authentication model; The convolution layer is used to perform convolution processing on the input face image and output the corresponding feature map; The attention layer is used to weight the obtained feature map, and perform self-attention learning on the corresponding feature map based on the weighted result; The output layer is used to receive the feature map after attention learning and perform image mapping on it to output corresponding facial features and facial feature vectors; Define the parameter optimizer of the identity authentication model as SGD; obtain several user face images; build the corresponding training data set based on them, divide the training data set into batches, and train the identity authentication model. By passing the training data set batches into the identity authentication model and calculating the gradient based on the loss function, use the back propagation algorithm to update the model weights, and record the value of the loss function of each batch. Stop training when the value of the loss function no longer decreases or changes for P1 consecutive batches, save the parameters of the identity authentication model at this time, and complete the training of the identity authentication model; P1 is a fixed constant.

8. A security authentication method based on a secure computer according to claim 7, characterized in that: The formula defining the convolution process is: Where f1, f2 and f3 represent different pre-selected activation functions; * represents convolution operation; Q l Represents the output feature map of the l-th layer convolution; Q l-1 It is the output feature map of the previous l-1 layer of convolution of the lth layer of convolution; All are bias terms; Represents the weight of the convolution kernel in the lth layer under different activation functions; con means connecting or combining vectors along the specified dimension; The process of weighting the obtained feature map includes: Get the feature map output by each channel in the convolution layer, perform global average pooling on it, and obtain the global perception value corresponding to the corresponding channel; and use it as the feature weight corresponding to the corresponding channel; that is, the feature map is weighted; The formula for the corresponding global average pooling operation is: Where H and W represent the length and width of the output feature map of channel td, respectively; u and v represent the horizontal and vertical coordinates of the pixel points in the feature map of channel td, respectively; td Represents the output result of the global average pooling operation within channel td; The formula for self-attention learning is defined as: Y`=g(μ×G td +ρ×T td , V td ), where Y` represents the feature map after self-attention learning, g() represents the transformation function, μ and ρ represent the image weights of the input feature map and the output feature map in the channel td, respectively; G td Represents the global average pooling operation result of channel td; V td Represents the feature weight assigned by the feature map; T td Represents the feature map of the input in channel td; Define the loss function of the identity authentication model as LOSS = loss jc +loss face Among them, loss jc represents the cross entropy loss function and the angular margin loss function; Where E represents the total number of training samples in the training data set; y is the index of the training sample; The feature map corresponding to the output of the attention layer represents the weight vector; b_y and b t_0 represents the bias term; sr y is the output feature vector after the global average pooling operation; T0 and t_0 represent the total number of known face feature categories and feature index respectively; The feature vector representing the t_0th known face feature of the input; sr t_0 Represents the t_0th known face feature of the input; In the formula, ε y Indicates the category weight to which the y-th training sample belongs; θ y represents the vector angle between the eigenvectors corresponding to the predicted value and the actual value; φ(d) represents the adaptive function of the vector angle; represents the regularization coefficient; λ represents the feature scale.

9. A security authentication method based on a secure computer according to claim 5, characterized in that: The process of dynamic behavior evaluation of the user behavior data in the uploaded authentication information includes: Read the user behavior data in the collected authentication information, and perform data preprocessing on the data to obtain corresponding initial user data; after the preprocessing is completed, construct a corresponding first user behavior pattern baseline based on the obtained initial user data; Obtain the client ID of the client corresponding to the corresponding user to be authenticated, and read the historical user behavior data of the corresponding user to be authenticated in the corresponding secure computer based on the client ID, and record it as personal behavior data; at the same time, read the historical user behavior data corresponding to several other users in the historical authentication process, and mark it as reference behavior data; Constructing a corresponding second user behavior pattern baseline and a reference behavior pattern baseline based on the personal behavior data and the reference behavior data respectively; The obtained first user behavior pattern baseline is compared with the corresponding reference behavior pattern baseline and the second user behavior pattern baseline respectively; and scores are assigned based on the comparison results to obtain corresponding user benchmark scores and reference benchmark scores; The obtained user benchmark score and reference benchmark data are weighted and summed to obtain the corresponding behavior evaluation index.

10. A security authentication method based on a secure computer according to claim 9, characterized in that: The process of judging whether the corresponding user to be authenticated meets the authentication requirements based on the obtained face authentication index and behavior evaluation index includes: Set an authentication threshold, compare the obtained face authentication index with the corresponding authentication threshold, and if the corresponding face authentication index is less than the authentication threshold, feedback the authentication failure notification and the failure reason to the corresponding client; if the corresponding face authentication index is not less than the authentication threshold, obtain the behavior evaluation index of the corresponding user to be authenticated during the authentication process, and assign a grade to the authentication process of the corresponding user to be authenticated based on it to obtain the corresponding authentication grade; If the authentication level of the corresponding user to be authenticated is lower than the preset level requirement, an authentication failure notification is fed back; if the authentication level of the corresponding user to be authenticated is not lower than the preset level requirement, an authentication success notification is fed back, and the corresponding user to be authenticated is allowed to access the secure computer.