Identity authentication method, device, equipment and medium
By using identity information and biometric information for authentication in 5G millimeter wave communication network and combining live detection, the security and management complexity issues in the existing RADIUS protocol authentication process are solved, and higher authentication security and reliability are achieved.
Patent Information
- Application Number
- CN202510321467.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-03
AI Technical Summary
The existing authentication process based on the RADIUS protocol has security dependence on the hash value derived from the MD5 algorithm, which poses a risk of collision attacks. The configuration and management of the RADIUS server are relatively complex, which increases the risk of security vulnerabilities and authentication failures.
Data transmission is carried out using 5G millimeter wave communication method. By obtaining the user's identity information and biometric information, a target authentication request is generated, and an authentication request is sent to the ground authentication server through the on-board millimeter wave radio. The live detection is performed in combination with fingerprint and facial recognition algorithms, enhancing the security of authentication.
Improve the security of on-board communication radio network authentication, reduce the risk of collision attacks, and reduce the possibility of security vulnerabilities and authentication failures by simplifying the configuration and management of RADIUS servers.
Smart Images

Figure CN120091308A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rail transit, and in particular, to an identity authentication method, apparatus, device, and medium. Background Art
[0002] Currently, in the wireless network systems of high-speed railways or heavy-haul railways, the authentication algorithm for on-vehicle GSM-R communication radios to access the network is mainly the authentication algorithm based on 802.1X. 802.1X is a port-based network access control protocol that authenticates users or devices to determine whether to allow them to access the network. In the high-speed railway wireless network system, the 802.1X authentication algorithm is usually combined with a Remote Authentication Dial-In User Service (RADIUS) server to implement the access authentication of users or devices. When a user or device attempts to access the network, the 802.1X authentication algorithm will require it to provide authentication information (such as a username and password). Then, this information will be sent to the RADIUS server for verification. If the verification is successful, the user or device will be allowed to access the network; if the verification fails, access will be denied.
[0003] There are some problems in the existing authentication process based on the RADIUS protocol. One is that the security of authentication depends on the hash value derived using the MD5 algorithm. The MD5 algorithm has the risk of collision attacks, which means that an attacker may find two different inputs that will produce the same MD5 hash value. Such collision attacks enable the attacker to forge a valid authentication response, thus bypassing the RADIUS authentication mechanism. The high-speed railway train control service belongs to a security service, and there are security risks when wireless devices access the network. The other is that the configuration and management of the RADIUS server are relatively complex and require professional knowledge. This increases the risk of configuration errors and improper management, which may lead to security vulnerabilities or authentication failure problems. Summary of the Invention
[0004] The present invention provides an identity authentication method, apparatus, device, and medium to improve the security of the on-vehicle communication radio network access authentication.
[0005] According to one aspect of the present invention, there is provided an identity authentication method, including:
[0006] Obtain the identity information and biometric information of a user;
[0007] Generate a target authentication request according to the identity information and the biometric information;
[0008] Send the target authentication request to a ground authentication server through an on-vehicle millimeter-wave radio to instruct the ground authentication server to verify the target authentication request.
[0009] According to another aspect of the present invention, there is provided an identity authentication apparatus, including:
[0010] An acquisition module, configured to acquire the identity information and biometric information of a user;
[0011] A generation module, configured to generate a target authentication request according to the identity information and the biometric information;
[0012] A sending module, configured to send the target authentication request to a ground authentication server via an in-vehicle millimeter-wave radio, for instructing the ground authentication server to verify the target authentication request.
[0013] According to another aspect of the present invention, there is provided a computer program product, including a computer program, where the computer program, when executed by a processor, implements the identity authentication method according to any embodiment of the present invention.
[0014] According to another aspect of the present invention, there is provided an electronic device, where the electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the identity authentication method according to any embodiment of the present invention.
[0015] According to another aspect of the present invention, there is provided a computer-readable storage medium, where the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the identity authentication method according to any embodiment of the present invention when executed by a processor.
[0016] The embodiment of the present invention uses a 5G millimeter-wave communication method for data transmission. 5G millimeter-wave has characteristics such as large bandwidth, low air interface delay, high anti-interference ability, and large capacity. When the radio accesses, more complex algorithms can be used, such as access in multiple ways such as identity information + biometric information, etc., to ensure the secure and reliable transmission of communication data of more vehicles, and increase the security of communication.
[0017] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0019] Figure 1A It is a flowchart of an identity authentication method provided according to an embodiment of the present invention;
[0020] Figure 1B It is a schematic diagram of a millimeter-wave communication network provided according to an embodiment of the present invention;
[0021] Figure 2A It is a flowchart of an identity authentication method provided according to another embodiment of the present invention;
[0022] Figure 2B It is a schematic diagram of an authentication process provided according to another embodiment of the present invention;
[0023] Figure 3 It is a schematic structural diagram of an identity authentication device provided according to another embodiment of the present invention;
[0024] Figure 4 It is a schematic structural diagram of an electronic device implementing the embodiment of the present invention. Detailed implementation manners
[0025] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0026] It should be noted that the terms "first", "second", etc. in the present invention are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0027] Figure 1AThe flowchart of an identity authentication method provided by an embodiment of the present invention. This embodiment is applicable to the situation of upgrading the existing GSM-R system to a 5G millimeter-wave network and performing network access authentication through the 5G millimeter-wave network. This method can be executed by an identity authentication device, which can be implemented in the form of hardware and / or software, and can be configured in an electronic device with corresponding data processing capabilities, such as a vehicle-mounted system. As Figure 1A shown, the method includes:
[0028] S110. Obtain the identity information and biometric information of the user.
[0029] S120. Generate a target authentication request according to the identity information and the biometric information.
[0030] S130. Send the target authentication request to the ground authentication server through the vehicle-mounted millimeter-wave radio, for instructing the ground authentication server to verify the target authentication request.
[0031] Among them, the identity information usually includes the personal account number and password input by the user. The ground authentication server receives the target authentication request through the core network and the ground millimeter-wave base station. The millimeter-wave communication network is composed of vehicle-mounted millimeter-waves, ground millimeter-wave base stations, ground core networks, and ground RADIUS authentication servers. The vehicle-mounted millimeter-wave radio conducts service interactions with ground core devices through the millimeter-wave communication network. When the radio terminal performs network registration and terminal sessions, the core network SMF device forwards the authentication request to the RADIUS ground authentication server.
[0032] Specifically, as Figure 1B shown, before authentication, it is necessary to deploy a millimeter-wave radio on the train and deploy a corresponding millimeter-wave base station on the station side, so that the vehicle-mounted system of the train can communicate with the ground authentication server on the station side through 5G millimeter-waves.
[0033] In the past, in the GSM-R system, when a radio accesses the network, it needs to undergo authentication to ensure that only legitimate devices can access the network and communicate. 1. Authentication request: When a radio attempts to access the GSM-R network, it sends an authentication request to the authentication server (such as a RADIUS server) in the network. This request usually contains the unique identifier of the radio (such as IMSI or IMEI, etc.), device type, location information, etc. 2. Authentication verification: After receiving the authentication request, the authentication server first verifies the legitimacy of the request, including checking the format, signature, etc. of the request. Then, the authentication server queries the unique identifier of the radio in the database to confirm whether the device has been registered and is allowed to access the network. If the device has been registered and the information matches, the authentication server will conduct further verification, such as checking the device's certificate, key, etc. 3. Authentication response: If the authentication server passes the verification, it will send an authentication acceptance message to the radio, allowing it to access the network. This message may contain information such as the device's network access permissions, communication parameters, etc. If the authentication fails, the authentication server will send an authentication rejection message to the radio and may include the reason for the failure. 4. Secure data transmission: After successful authentication, the communication between the radio and the network will be protected to ensure the secure transmission of data, which is usually achieved through means such as encryption and integrity verification. Compared with the GSM-R network, millimeter-wave communication itself has the properties of high frequency and large bandwidth, so the network has strong anti-interference ability and can adopt more advanced authentication algorithms to make up for the deficiencies of RADIUS.
[0034] After the millimeter-wave radio is powered on, it initializes the device parameters. The user re-enters their identity information in the system and presents their biometric information to the system. The system processes the collected identity information and biometric information, compresses and packages them to obtain a target authentication request.
[0035] Since the vehicle-mounted millimeter-wave radio is deployed in advance on the train, the system can send the target authentication request to the ground authentication server in the form of millimeter-wave signals through the vehicle-mounted millimeter-wave radio. The ground authentication server receives the target authentication request through the connected millimeter-wave base station and verifies the target authentication request. If the verification passes, the ground authentication server can feedback the legitimate network access IP to the system through the millimeter-wave base station. The system receives the network access IP through the vehicle-mounted millimeter-wave radio and conducts subsequent service transmissions based on this. If the authentication fails, the ground authentication server can feedback the authentication failure information to the system through the millimeter-wave base station. The system receives the authentication failure information through the vehicle-mounted millimeter-wave radio, displays it to the user, and attempts to authenticate again.
[0036] The embodiments of the present invention use 5G millimeter-wave communication for data transmission. 5G millimeter-wave has the characteristics of large bandwidth, low air interface delay, high anti-interference ability, and large capacity. When the radio station accesses, more complex algorithms can be used, such as access in multiple ways such as identity information + biometric information, etc., to ensure the safe and reliable transmission of communication data of more vehicles, and increase the security of communication.
[0037] Figure 2A The flowchart of an identity authentication method provided by another embodiment of the present invention. This embodiment is optimized and improved on the basis of the above embodiment. As Figure 2A shown, the method includes:
[0038] S210. Obtain the identity information and biometric information of the user.
[0039] S220. Use the fingerprint algorithm to extract the fingerprint features to obtain the target fingerprint feature vector; use the face recognition algorithm to extract the face features to obtain the target face feature vector.
[0040] S230. Generate a target authentication request according to the target fingerprint feature vector, the target face feature vector and the identity information.
[0041] Specifically, use a mature fingerprint algorithm to extract the fingerprint features to obtain the target fingerprint feature vector. At the same time, use a mature face recognition algorithm to extract the face features to obtain the target face feature vector. Compared with the fingerprint information and face information, the data volume of the target fingerprint feature vector and the target face feature vector is smaller, which can effectively reduce the data size of the subsequent authentication information. Compress and package the obtained target fingerprint feature vector, target face feature vector, identity information and other necessary auxiliary information according to the predetermined template format to obtain the target authentication request.
[0042] S240. Send the target authentication request to the ground authentication server through the vehicle-mounted millimeter-wave radio station, for instructing the ground authentication server to verify the target authentication request.
[0043] S250. Receive the expression instruction sent by the ground authentication server through the vehicle-mounted millimeter-wave radio station; collect the action video made by the user according to the expression instruction, and send the action video to the ground authentication server through the vehicle-mounted millimeter-wave radio station, for instructing the ground authentication server to perform a liveness detection according to the action video.
[0044] Specifically, as Figure 2BAs shown in the figure, to further improve the authentication security, after authentication is passed, a liveness detection of the user can be further performed based on the 5G millimeter-wave network. The vehicle-mounted system receives specific expression instructions from the ground authentication server through the millimeter-wave radio station. These instructions may require the user to perform a series of predetermined actions, such as blinking, opening the mouth, shaking the head, etc. After receiving the instructions, the image acquisition device of the vehicle-mounted system will be activated and start recording the actions made by the user according to the instructions. This process may have a time limit to ensure the immediacy of the response and prevent the use of pre-recorded videos. Once the actions are successfully recorded, the action video will be transmitted back to the ground authentication server through the 5G millimeter-wave network again. After receiving the action video, the ground authentication server will use image processing and machine learning algorithms to analyze the video content, check whether the user's actions meet the expectations, and determine whether a real person is executing the command or trying to deceive the system, and obtain the liveness detection result. After the liveness detection passes, a legal network access IP will be fed back to the system through the millimeter-wave base station.
[0045] Based on the above embodiments, optionally, the obtaining of the user's identity information and biometric information includes:
[0046] Capturing the fingerprint pattern on the surface of the user's finger through a fingerprint sensor deployed in the cab to obtain fingerprint information; capturing the user's face image through an image acquisition device deployed in the cab to obtain face information.
[0047] Specifically, a fingerprint sensor and an image acquisition device are pre-deployed inside the cab. When authentication is required, the fingerprint pattern on the surface of the user's finger is captured through the fingerprint sensor, and the fingerprint pattern is pre-processed (such as image enhancement, denoising, orientation field estimation) to obtain available fingerprint information. The user's face image is captured through a camera or other device to obtain face image information.
[0048] Based on the above embodiments, optionally, the verification process of the target authentication information is as follows:
[0049] Parsing the target authentication information to obtain identity information, a target fingerprint feature vector, and a target face feature vector; if the identity information, the target fingerprint feature vector, and the target face feature vector all pass the verification, it is determined that the target authentication information passes the verification; if the identity information, the target fingerprint feature vector, and the target face feature vector do not all pass the verification, it is determined that the target authentication information does not pass the verification.
[0050] Specifically, the user registers their identity information in the ground authentication server in advance, and inputs their fingerprint information and face information. The ground authentication server extracts features from the fingerprint information and face information input by the user, and saves them locally in the form of vectors. After receiving an authentication request subsequently, the authentication information is parsed to obtain the identity information, target fingerprint feature vector, and target face feature vector therein. The server first checks the identity information. If the check fails, it is determined that the target authentication information fails the verification. If the check passes, the pre-stored face feature vector and pre-stored fingerprint feature vector that match the identity information are obtained locally. The pre-stored fingerprint feature vector is compared with the target fingerprint feature vector, and the pre-stored face feature vector is compared with the target face feature vector. If the comparison results are all consistent, it is determined that the target authentication information passes the verification. If there is an inconsistent comparison result, it is determined that the target authentication information fails the verification.
[0051] The embodiment of the present invention introduces liveness detection in the train network access authentication process, further improving the security of the authentication process.
[0052] Figure 3 It is a schematic structural diagram of an identity authentication device provided by another embodiment of the present invention. As Figure 3 shown, the device includes:
[0053] An acquisition module 310, configured to acquire the identity information and biometric information of the user;
[0054] A generation module 320, configured to generate a target authentication request according to the identity information and the biometric information;
[0055] A sending module 330, configured to send the target authentication request to the ground authentication server through the vehicle-mounted millimeter-wave radio, for instructing the ground authentication server to verify the target authentication request.
[0056] The identity authentication device provided by the embodiment of the present invention can execute the identity authentication method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0057] Optionally, the biometric information includes fingerprint information and face information, and the generation module 320 includes:
[0058] Extract features from the fingerprint information using a fingerprint algorithm to obtain a target fingerprint feature vector;
[0059] Extract features from the face information using a face recognition algorithm to obtain a target face feature vector;
[0060] Generate a target authentication request according to the target fingerprint feature vector, target face feature vector, and identity information.
[0061] Optionally, the obtaining module 310 includes:
[0062] A fingerprint obtaining unit, configured to capture a fingerprint pattern on the surface of a user's finger through a fingerprint sensor deployed in the cab to obtain fingerprint information;
[0063] A face obtaining unit, configured to capture a user's face image through an image acquisition device deployed in the cab to obtain face information.
[0064] Optionally, the verification process of the target authentication information is as follows:
[0065] Parse the target authentication information to obtain identity information, a target fingerprint feature vector, and a target face feature vector;
[0066] If the identity information, the target fingerprint feature vector, and the target face feature vector all pass the verification, it is determined that the target authentication information passes the verification;
[0067] If the identity information, the target fingerprint feature vector, and the target face feature vector do not all pass the verification, it is determined that the target authentication information fails the verification.
[0068] Optionally, the apparatus further includes:
[0069] An instruction receiving module, configured to receive an expression instruction sent by the ground authentication server through the vehicle-mounted millimeter-wave radio;
[0070] An instruction response module, configured to collect an action video made by the user according to the expression instruction, and send the action video to the ground authentication server through the vehicle-mounted millimeter-wave radio, for instructing the ground authentication server to perform a liveness detection according to the action video.
[0071] Optionally, the ground authentication server receives a target authentication request through a core network and a ground millimeter-wave base station.
[0072] The further described identity authentication apparatus can also execute the identity authentication method provided in any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0073] Figure 4The structural schematic diagram of an electronic device 40 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0074] As Figure 4 shown, the electronic device 40 includes at least one processor 41 and a memory communicatively connected to the at least one processor 41, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc. The memory stores a computer program executable by the at least one processor. The processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. In the RAM 43, various programs and data required for the operation of the electronic device 40 can also be stored. The processor 41, the ROM 42, and the RAM 43 are connected to each other through a bus 44. The input / output (I / O) interface 45 is also connected to the bus 44.
[0075] Multiple components in the electronic device 40 are connected to the I / O interface 45, including: an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a disk, an optical disc, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0076] The processor 41 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 executes the various methods and processes described above, such as the authentication method.
[0077] In some embodiments, the identity authentication method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the identity authentication method described above may be performed. Alternatively, in other embodiments, the processor 41 may be configured to execute the identity authentication method by any other suitable means (e.g., by means of firmware).
[0078] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0079] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0080] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0081] For providing interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used for providing interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0082] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of the communication network include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0083] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0084] It should be understood that various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0085] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. An identity authentication method, characterized in that: The method comprises: Obtain the user's identity information and biometric information; generating a target authentication request according to the identity information and the biometric information; A target authentication request is sent to a ground authentication server via the vehicle-mounted millimeter wave radio station, so as to instruct the ground authentication server to verify the target authentication request.
2. The method according to claim 1, characterized in that The biometric information includes fingerprint information and face information, and generating a target authentication request according to the identity information and the biometric information includes: Use fingerprint algorithm to extract features from fingerprint information and obtain target fingerprint feature vector; Use facial recognition algorithm to extract features from facial information and obtain the target facial feature vector; A target authentication request is generated according to the target fingerprint feature vector, the target face feature vector and the identity information.
3. The method according to claim 2, characterized in that The obtaining of the user's identity information and biometric information includes: The fingerprint sensor deployed in the cab captures the fingerprint pattern on the surface of the user's finger to obtain fingerprint information; The user's face image is captured by an image acquisition device deployed in the cab to obtain face information.
4. The method according to claim 2, characterized in that: The verification process of the target authentication information is as follows: Parsing the target authentication information to obtain identity information, a target fingerprint feature vector and a target face feature vector; If the identity information, the target fingerprint feature vector, and the target face feature vector are all verified, then it is determined that the target authentication information is verified; If the identity information, the target fingerprint feature vector, and the target face feature vector all fail to pass verification, it is determined that the target authentication information fails to pass verification.
5. The method according to claim 1, characterized in that: After sending the target authentication request to the ground authentication server through the vehicle-mounted millimeter wave radio, the method further includes: Receiving the expression command sent by the ground authentication server through the vehicle-mounted millimeter wave radio; The action video performed by the user according to the expression instruction is collected, and the action video is sent to the ground authentication server through the vehicle-mounted millimeter wave radio station to instruct the ground authentication server to perform liveness detection according to the action video.
6. The method according to claim 1, characterized in that The ground authentication server receives a target authentication request through a core network and a ground millimeter wave base station.
7. An identity authentication device, characterized in that: The device comprises: An acquisition module, used to obtain the user's identity information and biometric information; A generating module, used for generating a target authentication request according to the identity information and the biometric information; The sending module is used to send a target authentication request to a ground authentication server through the vehicle-mounted millimeter wave radio station, and is used to instruct the ground authentication server to verify the target authentication request.
8. The device according to claim 7, characterized in that The generation module comprises: A first extraction unit, used to extract features from fingerprint information using a fingerprint algorithm to obtain a target fingerprint feature vector; A second extraction unit is used to extract features from face information using a face recognition algorithm to obtain a target face feature vector; A generating unit is used to generate a target authentication request according to the target fingerprint feature vector, the target face feature vector and the identity information.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the identity authentication method described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the identity authentication method according to any one of claims 1 to 6 when executed.
Citation Information
Patent Citations
Identity authentication method and system, electronic equipment and computer readable storage medium
CN109815665A
Vehicle-mounted identity recognition method and system
CN110717355A
Method and vehicle-mounted device for authenticating identity of vehicle user
CN118487880A
Systems and methods for liveness-verified identity authentication
US11288530B1