Campus ID card multi-scene identity authentication system based on edge computing

By introducing the identity authentication request scheduling module and the biometric matching optimization module in the identity authentication system, combined with the dynamic resource allocation and matching calculation optimization of the distributed matching calculation module, the problems of uneven allocation of computing resources and large matching errors in the high-concurrency environment in the existing technology are solved, and efficient and accurate identity authentication is achieved.

CN120108076AActive Publication Date: 2025-06-06NANJING AUDIT UNIV

Patent Information

Application Number
CN202510304000.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-06
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

The prior art is difficult to prioritize the classification of the frequency characteristics of identity authentication requests in a high concurrency environment, resulting in uneven allocation of computing resources, large response delays and matching errors, affecting the efficiency and accuracy of identity authentication.

Method used

The time interval of the identity authentication request is calculated through the identity authentication request scheduling module, classifies it according to the access frequency, and adjusts the task priority in combination with the computing resource load status. The biometric matching optimization module classifies stability according to the amplitude of the characteristic area, and the distributed matching calculation module dynamically adjusts the calculation resource allocation ratio and matching calculation parameters to ensure the response speed of high-frequency identity authentication requests and the accuracy of matching results.

Benefits of technology

It realizes efficient allocation of computing resources in a high-concurrency environment, improves the response speed and accuracy of identity authentication, reduces the risk of misidentification, and improves the security and stability of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120108076A_ABST
    Figure CN120108076A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of identity authentication, in particular to a campus ID card multi-scene identity authentication system based on edge computing, which comprises an identity authentication request scheduling module, a biological feature matching optimization module, an authentication task priority adjustment sub-module, a distributed matching calculation module and a matching result decision module. According to the method, the response speed of the high-frequency identity authentication request is ensured by calculating the time interval of the identity authentication request, classifying according to the access frequency and adjusting the task priority in combination with the calculation of the resource load state, and the accuracy of identity recognition is improved by analyzing the variation amplitude of the feature region and classifying the region stability according to the threshold value. The distribution proportion of the computing resources is dynamically adjusted, the task distribution proportion of the computing nodes is adjusted according to the computing priority of the identity authentication task, the matching confidence is calculated in combination with the biological feature matching result, the reliability of the identity matching result is improved, and the safety and stability of identity authentication are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of identity authentication technology, and in particular to a campus ID card multi-scenario identity authentication system based on edge computing. Background Art

[0002] The field of identity authentication technology includes various technical methods for verifying and confirming user identities. The core content of this technical field is to achieve unique identification of individual identities through biometrics, passwords, smart cards and other means, and ensure that authorized users can access specific resources or services. Identity authentication technology as a whole covers biometrics, encryption authentication, smart card authentication and multi-factor authentication, and is widely used in multiple scenarios such as finance, security, and campus management. With the development of computing technology, identity authentication systems are gradually evolving towards a more efficient and secure direction, and are combined with edge computing, artificial intelligence and other technologies to improve the real-time and reliability of authentication.

[0003] Among them, the campus ID card multi-scenario identity authentication system based on edge computing refers to the use of edge computing technology to manage various identity authentication needs in the campus environment. The system covers contactless identity authentication methods based on radio frequency identification technology, identity comparison methods based on biometric matching, and remote identity confirmation mechanisms based on encrypted communication protocols. The system adopts an edge computing architecture to perform identity data analysis, feature matching, and permission management at local campus nodes, reducing dependence on central servers and improving the real-time performance of data processing. At the same time, the encrypted authentication protocol is combined to protect identity data and ensure the security of the identity authentication process.

[0004] In the process of identity authentication, the existing technology usually relies on a single authentication method, and it is difficult to classify the priority according to the frequency characteristics of the identity authentication request, resulting in uneven distribution of computing resources in a high-concurrency environment, which easily causes response delays for high-priority identity authentication requests. Due to the lack of classification of the stability of different regions in the biometric matching process, all feature points participate in the matching calculation with the same weight, resulting in a large matching error, which affects the accuracy of identity authentication. The allocation method of computing resources is usually based on a fixed strategy, and the allocation ratio of computing resources cannot be dynamically adjusted according to the task priority, resulting in waste of computing resources or unreasonable allocation, affecting the overall computing efficiency of the system. The task scheduling of computing nodes often adopts a fixed strategy, lacks adaptive adjustment of matching confidence, and easily leads to low-confidence matching results affecting the final authentication results, increasing the risk of misidentification. The determination method of identity authentication matching results is usually based on a fixed matching threshold, and fails to combine the matching confidence of multiple computing nodes for dynamic evaluation, which is easy to cause misjudgment in boundary cases, reducing the accuracy and security of identity authentication. Summary of the invention

[0005] The purpose of the present invention is to solve the shortcomings existing in the prior art and propose a campus ID card multi-scenario identity authentication system based on edge computing.

[0006] In order to achieve the above purpose, the present invention adopts the following technical solution: The campus ID card multi-scenario identity authentication system based on edge computing includes:

[0007] The authentication request scheduling module obtains the authentication request data, extracts the timestamp, calculates the time interval between the current authentication request and the last access, classifies the identity access type according to the identity access frequency threshold, synchronously determines the computing resource load status, adjusts the authentication task execution priority, and generates the authentication task priority list;

[0008] The biometric matching optimization module obtains biometric data according to the identity authentication task priority list, calculates the biometric region change amplitude, classifies the region stability according to the feature change threshold, and generates the biometric region matching result;

[0009] The authentication task priority adjustment submodule adjusts the computing resource allocation ratio of the campus edge computing server task queue based on the identity authentication task priority list and generates an identity authentication task computing sequence;

[0010] The distributed matching calculation module adjusts the task allocation ratio of the computing nodes based on the identity authentication task calculation sequence, calculates the matching confidence in combination with the biometric feature area matching weight, and generates an identity matching confidence calculation result;

[0011] The matching result decision module determines that the match is successful based on the identity matching confidence calculation result and generates an identity authentication matching determination result if the matching confidence of all computing nodes is higher than the identity matching confidence threshold.

[0012] As a further solution of the present invention, the identity authentication task priority list includes high-frequency access identities, medium-frequency access identities, and low-frequency access identities; the biometric area matching results include stable areas, sub-stable areas, and unstable areas; the identity authentication task calculation sequence includes a computing resource allocation ratio and a task calculation priority; the identity matching confidence calculation result includes a matching confidence calculation value and a computing node matching parameter; the identity authentication matching judgment result includes an identity matching success record, an identity matching failure record, and an identity matching re-evaluation result.

[0013] As a further solution of the present invention, the identity authentication request scheduling module includes:

[0014] The identity authentication classification submodule obtains the identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, and compares the identity high-frequency access threshold with the identity medium-frequency access threshold for classification. If the time interval is less than the identity high-frequency access threshold, it is marked as a high-frequency access identity. If the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as a medium-frequency access identity. If the time interval is greater than the identity medium-frequency access threshold, it is marked as a low-frequency access identity, and the identity access frequency classification result is generated;

[0015] The computing load monitoring submodule uses the formula based on the identity access frequency classification results and the load monitoring data of the campus edge computing server:

[0016]

[0017] Calculate the load adjustment value L adj , determine whether the calculation load adjustment value exceeds the calculation resource allocation threshold, and generate the calculation load status result, where L cur Represents the current load value, F i represents the identity access frequency weight, W i Represents the identity type calculation weight, T avg represents the mean of the historical access time interval, T cur Represents the timestamp of the current authentication request, T prev Represents the timestamp of the last authentication request, and n represents the total number of identity types;

[0018] The task priority adjustment submodule is based on the computing load status result. If the computing resource load exceeds the computing resource allocation threshold, the execution priority of low-frequency access identity requests is reduced, and the execution priority of high-frequency access identity requests is increased simultaneously, and the identity authentication task priority list is generated in order.

[0019] As a further solution of the present invention, the biometric matching optimization module includes:

[0020] The high-priority identity authentication data collection submodule collects the biometric data corresponding to the high-priority identity authentication request according to the identity authentication task priority list, extracts the biometric area information, and obtains the biometric basic data set;

[0021] The historical matching data retrieval submodule retrieves the historical matching data of the target identity based on the biometric basic data set, compares the current biometric data with the corresponding feature point set in the historical matching data, calculates the matching error of each feature point, and obtains the feature matching error value;

[0022] The biometric stability classification submodule uses the formula according to the feature matching error value:

[0023]

[0024] Calculate the characteristic variation range S of the i-th biometric region i , set the biometric stability threshold T 1 and the medium stability threshold T 2 , if S i <T 1 , marked as a stable region, if T 1 ≤S i <T 2 , marked as the substable region, if S i ≥T 2 , marked as unstable areas, and feature denoising is performed on the unstable areas to remove abnormal feature points and obtain the biometric region matching results, where N represents the number of samples in the historical matching records of the area, and E ij represents the matching error value of the i-th biometric region in the j-th matching record, represents the average value of the matching error of the i-th biometric region, w i Represents the weight coefficient of the i-th biometric region.

[0025] As a further solution of the present invention, the authentication task priority adjustment submodule includes:

[0026] The task priority parsing submodule parses the priority weight of each identity authentication task based on the identity authentication task priority list, extracts the identity information, task type and historical processing record corresponding to the task request, and calculates the task priority adjustment parameter;

[0027] The computing resource allocation submodule adjusts the parameters based on the task priority, calculates the computing resource allocation ratio of the identity authentication task, sets the total amount of computing resources, and increases its computing resource allocation ratio if the task priority is high; if the task priority is low, reduces the computing resource allocation ratio, using the formula:

[0028]

[0029] Calculate the computing resource allocation R of the i-th task i , construct the computing resource allocation matrix, where Q i represents the priority adjustment parameter of the i-th task, R represents the total amount of computing resources, K represents the total number of tasks, and T h represents the historical average processing time of the i-th task, represents the average processing time of all tasks, and C represents the computing resource adjustment coefficient;

[0030] The identity authentication task calculation sequence generation submodule sorts the identity authentication tasks according to the computing resource allocation matrix, task priorities and computing resource allocation amounts, adjusts the task execution order, eliminates tasks whose computing resource allocation amounts are lower than a threshold, and obtains the identity authentication task calculation sequence.

[0031] As a further solution of the present invention, the distributed matching calculation module includes:

[0032] The task calculation allocation submodule extracts the calculation priority of the task based on the identity authentication task calculation sequence, allocates tasks to the campus edge computing nodes according to the task calculation priority, calculates the task load ratio of each computing node, sets the task allocation parameters, calls the task allocation parameters to adjust the computing tasks of the edge computing nodes, and generates the task allocation ratio of the computing nodes;

[0033] The calculation parameter optimization submodule analyzes the adaptability of each calculation node in the matching calculation based on the task allocation ratio of the calculation node and the matching result of the biometric feature area, adjusts the matching calculation parameters, sets the matching parameter adjustment ratio, and adopts the formula:

[0034]

[0035] Calculate the matching calculation adjustment parameter P′ for each computing node ij , update the adjusted matching calculation parameters, where P ij Represents the initial matching calculation parameters, M ik represents the matching adaptability of computing node i to feature region k, B k represents the benchmark matching value of feature region k, L represents the total number of matching regions, and a represents the matching parameter adjustment coefficient;

[0036] The matching confidence calculation submodule calculates the matching confidence of each computing node according to the adjusted matching calculation parameters, calculates the identity matching confidence weight according to the matching confidence of each node, adjusts the matching confidence weight distribution ratio, and generates the identity matching confidence calculation result.

[0037] As a further solution of the present invention, the matching result decision module includes:

[0038] The confidence threshold determination submodule obtains the matching confidence data of each computing node based on the identity matching confidence calculation result, sets the identity matching confidence threshold, calls the matching confidence threshold to compare with the matching confidence of each computing node, determines whether the matching confidence of each computing node exceeds the identity matching confidence threshold, screens the computing nodes whose matching confidence does not reach the threshold, and generates a matching confidence determination result;

[0039] The matching result re-evaluation submodule selects computing nodes whose matching confidence does not reach the threshold according to the matching confidence judgment result, re-evaluates their matching confidence, adjusts the matching confidence according to the matching task volume, computing load and computing error of the computing node, sets the adjustment ratio, and adopts the formula:

[0040]

[0041] Calculate the new matching confidence Z′ i , update to get the adjusted matching confidence, where Z i represents the initial matching confidence, J ij represents the computation error of computing node i in matching task j, Y ij represents the allowable error of computing task j, and X represents the total number of computing tasks;

[0042] The identity matching determination submodule determines whether the matching confidence of all computing nodes exceeds the identity matching confidence threshold based on the adjusted matching confidence. If all matching confidences exceed the threshold, the identity matching is marked as successful. If there are still some computing nodes whose matching confidences are lower than the threshold, the identity matching result is re-evaluated based on the matching confidences of all computing nodes to generate an identity authentication matching determination result.

[0043] Compared with the prior art, the advantages and positive effects of the present invention are:

[0044] In the present invention, by calculating the time interval of identity authentication requests, classifying them according to the access frequency, and adjusting the task priority in combination with the computing resource load status, the response speed of high-frequency identity authentication requests is ensured, the accuracy of identity recognition is improved by analyzing the variation range of feature regions and classifying the regional stability according to the threshold, the allocation ratio of computing resources is dynamically adjusted, so that computing tasks can reasonably allocate edge computing resources according to demand, the task allocation ratio of computing nodes is adjusted according to the computing priority of the identity authentication task, and the matching confidence is calculated in combination with the biometric matching result, so that the computing resources are optimally configured among different nodes, the reliability of the identity matching result is improved, the misidentification situation is reduced, and the security and stability of identity authentication are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is a system flow chart of the present invention;

[0046] Figure 2 This is a flow chart of the identity authentication request scheduling module of the present invention;

[0047] Figure 3 This is a flow chart of the biometric matching optimization module of the present invention;

[0048] Figure 4This is a flow chart of the authentication task priority adjustment submodule of the present invention;

[0049] Figure 5 This is a flow chart of the distributed matching calculation module of the present invention;

[0050] Figure 6 This is a flow chart of the matching result decision module of the present invention. DETAILED DESCRIPTION

[0051] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0052] In the description of the present invention, it should be understood that the terms "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside" and the like indicate positions or positional relationships based on the positions or positional relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, in the description of the present invention, "multiple" means two or more, unless otherwise clearly and specifically defined.

[0053] See also Figure 1 , the campus ID card multi-scenario identity authentication system based on edge computing includes:

[0054] The identity authentication request scheduling module obtains the identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, and classifies it according to the time interval threshold. If the time interval is less than the identity high-frequency access threshold, it is marked as a high-frequency access identity. If the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as a medium-frequency access identity. If the time interval is greater than the identity medium-frequency access threshold, it is marked as a low-frequency access identity. According to the campus edge computing server load monitoring data, it is determined whether the current computing load exceeds the computing resource allocation threshold. If the computing resource load exceeds the allocation threshold, the execution priority of the low-frequency access identity request is reduced, and the execution priority of the high-frequency access identity request is increased, and the identity authentication task priority list is output;

[0055] The biometric matching optimization module collects biometric data corresponding to high-priority authentication requests according to the priority list of identity authentication tasks, retrieves historical matching data of the target identity, calculates the feature change amplitude of the biometric region in the difference matching record, and classifies it according to the feature change amplitude threshold. If the feature change amplitude is less than the biometric stability threshold, it is marked as a stable region. If the feature change amplitude is between the biometric stability threshold and the medium stability threshold, it is marked as a sub-stable region. If the feature change amplitude is greater than the medium stability threshold, it is marked as an unstable region, and feature denoising is performed on the unstable region to remove abnormal feature points and generate biometric region matching results.

[0056] The authentication task priority adjustment submodule adjusts the computing resource allocation ratio based on the identity authentication task priority list according to the task priority. If the task priority is high, its computing resource allocation ratio is increased; if the task priority is low, its computing resource allocation ratio is reduced to generate the identity authentication task calculation sequence.

[0057] The distributed matching calculation module allocates the identity authentication calculation tasks to the campus edge computing nodes based on the identity authentication task calculation sequence, adjusts the task allocation ratio of the computing nodes according to the task calculation priority, adjusts the edge computing node matching calculation parameters based on the biometric area matching results, calculates the matching confidence of each computing node, and generates the identity matching confidence calculation results;

[0058] The matching result decision module determines whether the matching confidence of each computing node exceeds the identity matching confidence threshold based on the identity matching confidence calculation result. If all matching confidences exceed the identity matching confidence threshold, the identity matching is marked as successful. If some matching confidences are lower than the identity matching confidence threshold, the identity matching result is re-evaluated to generate an identity authentication matching judgment result.

[0059] The identity authentication task priority list includes high-frequency access identities, medium-frequency access identities, and low-frequency access identities. The biometric area matching results include stable areas, sub-stable areas, and unstable areas. The identity authentication task calculation sequence includes the computing resource allocation ratio and task calculation priority. The identity matching confidence calculation results include the matching confidence calculation value and the computing node matching parameters. The identity authentication matching judgment results include identity matching success records, identity matching failure records, and identity matching re-evaluation results.

[0060] See also Figure 2 , the authentication request scheduling module includes:

[0061] The identity authentication classification submodule obtains the identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, and compares the identity high-frequency access threshold with the identity medium-frequency access threshold for classification. If the time interval is less than the identity high-frequency access threshold, it is marked as a high-frequency access identity. If the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as a medium-frequency access identity. If the time interval is greater than the identity medium-frequency access threshold, it is marked as a low-frequency access identity, and the identity access frequency classification result is generated;

[0062] Get the authentication request data, collect the authentication records of the campus ID card reader, including the card swiping timestamp and user identity, store them in the database, call the database records to calculate the time interval between the current authentication request and the last access, and set the authentication timestamp format to:

[0063] YYYY-MM-DDHH:MM:SS

[0064] And calculate the time interval based on the time difference. If a user last swiped his card at:

[0065] 2025-02-18 08:00:00

[0066] The card swiping time is:

[0067] 2025-02-18 08:05:00

[0068] The time interval is calculated as 5 minutes. Based on the set identity high-frequency access threshold and identity medium-frequency access threshold, the identity high-frequency access threshold is set to 3 minutes, and the identity medium-frequency access threshold is set to 10 minutes.

[0069] The setting is based on the analysis of the historical access distribution of different identity groups in campus scenarios. In the card swiping data statistics of a certain teaching building, the frequency of repeated card swiping by faculty and staff in a short period of time is low, while the frequency of continuous card swiping by students in scenarios such as class breaks and laboratories is high. Data statistics show that more than 80% of the groups with continuous card swiping intervals of less than 3 minutes are students, and their average access intervals are distributed between 1.5 minutes and 2.8 minutes. Therefore, 3 minutes is selected as the identity high-frequency access threshold, and the medium-frequency access threshold of 10 minutes is set based on the cross-regional office characteristics of faculty and staff. Data analysis shows that their average card swiping intervals are concentrated between 7 and 12 minutes. 10 minutes is the representative value of this distribution and is classified as the identity medium-frequency access threshold.

[0070] The frequency level of the current access is determined according to the threshold. If the time interval is less than 3 minutes, it is marked as a high-frequency access identity. If the time interval is between 3-10 minutes, it is marked as a medium-frequency access identity. If the time interval is greater than 10 minutes, it is marked as a low-frequency access identity. The classified identity data is stored in the access frequency database, and the identity access frequency classification result is generated.

[0071] The computing load monitoring submodule uses the formula based on the identity access frequency classification results and the load monitoring data of the campus edge computing server:

[0072]

[0073] Calculate the load adjustment value L adj , determine whether the calculation load adjustment value exceeds the calculation resource allocation threshold, and generate the calculation load status result, where L cur Represents the current load value, F i represents the identity access frequency weight, W i Represents the identity type calculation weight, T avg represents the mean of the historical access time interval, T cur Represents the timestamp of the current authentication request, T prev Represents the timestamp of the last authentication request, and n represents the total number of identity types;

[0074] Based on the identity access frequency classification results, the load monitoring data of the campus edge computing server is called to calculate the current load value. The current CPU utilization of the server is 85%, and the memory occupancy is 75%. The computing resource allocation threshold is set to 80%. If the CPU or memory utilization exceeds 80%, the computing resources are in a high load state, otherwise they are in a normal load state. The computing consumption of the identity authentication request is calculated, and the computing weights of identities with different frequencies are set. The weight of high-frequency access identities is set to 2.0, the medium-frequency access identities are set to 1.5, and the low-frequency access identities are set to 1.0.

[0075] The calculation weight is set based on the computing resource usage of different identity frequencies. According to actual server operation data statistics, during the peak period, the system needs to process an average of 200 authentication requests per second, of which the computing resource usage of high-frequency identities is between 45% and 50%, the usage of medium-frequency identities is between 30% and 35%, and the usage of low-frequency identities is between 15% and 20%. Therefore, the calculation weight of high-frequency identities is set to 2.0 to reflect the multiplier effect of their usage of computing resources, while the medium-frequency identity is set to 1.5 and the low-frequency identity is set to 1.0 to match the computing resource allocation strategy.

[0076] In a certain time period, there are three identity requests, namely high-frequency, medium-frequency, and low-frequency identities. The calculation amount is:

[0077]

[0078] in,

[0079]

[0080] T avg =5 minutes, |T cur -T prev | = 5 minutes, then:

[0081]

[0082] If the load adjustment value L is calculated adj If the computing resource allocation threshold exceeds 80%, the computing load is determined to be too high and a computing load status result is generated. This result indicates that the current computing load has exceeded the threshold and the task priority needs to be adjusted.

[0083] The task priority adjustment submodule is based on the computing load status result. If the computing resource load exceeds the computing resource allocation threshold, the execution priority of low-frequency access identity requests is reduced, and the execution priority of high-frequency access identity requests is increased simultaneously, and the identity authentication task priority list is generated in order;

[0084] Based on the computing load status results, if the computing resource load exceeds the computing resource allocation threshold, the task priority is adjusted to reduce the execution priority of low-frequency access identity requests and increase the execution priority of high-frequency access identity requests. The identity authentication requests are sorted by priority. Assuming that there are currently 5 identity requests, namely high frequency (2), medium frequency (2), and low frequency (1), they are sorted by priority as shown in Table 1.1:

[0085]

[0086] As shown in Table 1.1, the task priority is sorted according to the frequency of identity access. High-frequency identity requests are executed first, followed by medium-frequency identity requests, and finally low-frequency identity requests to generate an identity authentication task priority list.

[0087] See also Figure 3 , the biometric matching optimization module includes:

[0088] The high-priority authentication data collection submodule collects the biometric data corresponding to the high-priority authentication request according to the authentication task priority list, extracts the biometric area information, and obtains the biometric basic data set;

[0089] In the campus ID card authentication system, some scenarios require priority processing of authentication requests for specific identities, such as authentication of teachers entering laboratories, dormitory access, or access rights to the finance office. First, the authentication request of the campus ID card is received, and high-priority identity requests are screened out according to the preset permission rules. For example, the identity authentication priority of faculty and administrative personnel is higher than that of ordinary students. Subsequently, the biometric acquisition device (such as a face recognition camera, fingerprint reader, or iris scanner) is called to collect the biometric data of the current user. Assuming that face recognition is used, the camera captures the front image of the current user and extracts 68 facial key point information, including the two-dimensional coordinate information of the corners of the eyes, the tip of the nose, the corners of the mouth, etc. For example, some facial key point data of a user are as follows:

[0090] Table 2.1 Example of key point coordinates of campus faces

[0091]

[0092] As shown in Table 2.1, facial key point data is used for subsequent identity matching. It is normalized and the feature coordinate values ​​are mapped to the interval [0, 1] to eliminate the impact of different camera resolutions and ensure the accuracy of cross-device matching. Finally, a basic biometric data set is generated.

[0093] The historical matching data retrieval submodule retrieves the historical matching data of the target identity based on the biometric basic data set, compares the current biometric data with the corresponding feature point set in the historical matching data, calculates the matching error of each feature point, and obtains the feature matching error value;

[0094] Based on the basic biometric data set, the system retrieves the user's historical matching data, for example, the user's campus access records in the past week, including the identity authentication data of dormitory doors, libraries, and study rooms. The historical matching data is stored in the school server, including the user's biometric matching template and the coordinates of the feature points at each authentication. For example, a user on different dates (t 1 , t 2 , t 3 ) is stored as the matrix M 1 , M 2 , M 3 , calculate the error value between the current matching data and the historical data, and assume that the current feature point set is P c ={(x i ,y i )}, historical data is P h ={(x′ i , y′ i )}, the matching error is calculated as follows:

[0095]

[0096] Calculate the Euclidean distance E between the current authentication data and the historical matching data i , to measure the matching error. For example, the error of some key points of a user is as follows:

[0097] Table 2.2 Campus identity authentication feature matching error

[0098]

[0099] As shown in Table 2.1, some feature points with large errors are affected by lighting, shooting angle or expression. This data will be used for subsequent stability analysis.

[0100] The biometric stability classification submodule uses the formula based on the feature matching error value:

[0101]

[0102] Calculate the characteristic variation range S of the i-th biometric region i , set the biometric stability threshold T 1 and the medium stability threshold T 2 , if S i <T 1 , marked as a stable region, if T 1 ≤S i <T 2 , marked as the substable region, if S i ≥T 2 , marked as unstable areas, and feature denoising is performed on the unstable areas to remove abnormal feature points and obtain the biometric region matching results, where N represents the number of samples in the historical matching records of the area, and E ij represents the matching error value of the i-th biometric region in the j-th matching record, represents the average value of the matching error of the i-th biometric region, w i represents the weight coefficient of the i-th biometric region;

[0103] According to the feature matching error value, the feature change range of the biometric feature area in multiple matching records is calculated, and the stability threshold T is set. 1 and the medium stability threshold T 2 Perform regional classification. In the campus identity authentication scenario, stable areas (such as the corners of the eyes and the tip of the nose) are usually not affected by changes in expression or lighting, while unstable areas (such as the corners of the mouth and the jaw) may cause feature shifts due to actions such as smiling and lowering the head. The formula is used to calculate the amplitude of feature changes.

[0104] In the campus access control system, the eye area is more stable, so w i=0.8, the mouth area is greatly affected by factors such as speaking and smiling, so w i =0.5.

[0105] Stability threshold T 1 and the medium stability threshold T 2 The basis for setting is as follows: First, analyze the distribution of biometric matching errors in different identity authentication scenarios in the campus access control system, extract matching error data of different user groups (such as teachers, students, and staff) in multiple authentications, select no less than 1,000 groups of identity authentication records, compare the mean and standard deviation of feature matching errors, and set the threshold reference standard. In the specific calculation, first calculate the mean error of all users and standard deviation σ E , calculated based on historical data:

[0106]

[0107] σ E =1.2

[0108] Threshold T 1 Set to Right now:

[0109] T 1 =2.5-0.5×1.2=1.9

[0110] Threshold T 2 Set to Right now:

[0111] T 2 =2.5+1.25×1.2=4.0

[0112] This setting method ensures that the stability threshold can cover the matching error range of most users, while avoiding abnormal data with large errors that affect the classification accuracy, making T 1 The corresponding stable region covers the feature points with smaller errors, while T 2 The corresponding medium stable area covers the normal error range of most users, while the error range exceeding T 2 The region can be considered as an unstable region.

[0113] The calculation example is as follows: Assume that the matching error value of a user's mouth corner area is:

[0114] [2.5, 3.0, 3.6, 4.1, 3.2], mean Weight w i =0.5.

[0115] but:

[0116]

[0117] If S i <T 1 , then the region is marked as a stable region; if T 1 ≤S i <T 2 , marked as the substable region; if S i ≥T 2 , it is marked as an unstable area, and feature denoising is performed on the unstable area to remove abnormal feature points, and finally obtain the biometric region matching result. The result shows that the stability value S of the mouth corner area i =0.228 below the threshold T 1 =1.9, so it can be marked as a stable area, which is suitable for long-term identity authentication matching in campus access control systems.

[0118] See also Figure 4 , the authentication task priority adjustment submodule includes:

[0119] The task priority parsing submodule parses the priority weight of each identity authentication task based on the identity authentication task priority list, extracts the identity information, task type and historical processing records corresponding to the task request, and calculates the task priority adjustment parameters;

[0120] In the campus identity authentication system, the priority of different identity authentication tasks has a direct impact on the allocation of computing resources. Therefore, it is necessary to first parse the priority weights of each identity authentication task. The specific process is as follows: First, the system calls the identity authentication task priority list to extract the identity information, task type and historical processing records of the task to be processed. For example, the tasks in a university's identity authentication system may include faculty and staff laboratory access control authentication, student dormitory access control authentication, visitor registration and review, etc. The priority of different tasks needs to be determined in combination with the importance of the task and historical data analysis. The system classifies the task types and calculates the priority adjustment coefficient of the task based on factors such as task execution frequency, average waiting time, and authentication failure rate. For example, for faculty and staff laboratory access control, a higher priority is set because it involves scientific research safety, while visitor registration and review is set at a lower priority because of relatively less demand. In order to quantify the priority adjustment coefficient, the task weight calculation formula is set:

[0121] Q i =αFz i +βTp i +γEs i

[0122] Among them, Fz i represents the execution frequency of task i, Tp i Represents the average waiting time of the task, Es iThe authentication failure rate represents the task, α, β, γ are weight coefficients, and combined with the historical data statistics of the campus identity authentication system, the weight coefficients are set to α = 0.4, β = 0.3, γ = 0.3. The execution frequency of a laboratory access control authentication task is 50 times a day, the average waiting time is 2.5 seconds, and the authentication failure rate is 5%. The task weight is calculated as follows:

[0123] Q lab =0.4×50+0.3×2.5+0.3×5=20+0.75+1.5=22.25

[0124] Similarly, assuming that the visitor registration task is executed 10 times a day, the average waiting time is 6 seconds, and the authentication failure rate is 15%, calculate its task weight:

[0125] Q visitor =0.4×10+0.3×6+0.3×15=4+1.8+4.5=10.3

[0126] As shown in the calculation, the priority of the laboratory access authentication task is significantly higher than that of the visitor registration task. The system uses this priority weight for subsequent calculation resource allocation and obtains the task priority adjustment parameters.

[0127] The computing resource allocation submodule adjusts parameters based on task priority, calculates the computing resource allocation ratio of the identity authentication task, sets the total amount of computing resources, and increases its computing resource allocation ratio if the task priority is high; if the task priority is low, reduces the computing resource allocation ratio using the formula:

[0128]

[0129] Calculate the computing resource allocation R of the i-th task i , construct the computing resource allocation matrix, where Q i represents the priority adjustment parameter of the i-th task, R represents the total amount of computing resources, K represents the total number of tasks, and T h represents the historical average processing time of the i-th task, represents the average processing time of all tasks, and C represents the computing resource adjustment coefficient;

[0130] Based on the task priority adjustment parameters, calculate the computing resource allocation ratio of the identity authentication task, set the total computing resource R = 100 (in CPU computing units), and calculate the resource allocation R for each task i If the task priority is higher, then increase its computing resource allocation ratio; if the task priority is lower, then reduce the computing resource allocation ratio. The specific calculation is as follows: Assuming that there are K=3 tasks to be processed, namely, laboratory access control authentication, student dormitory access control authentication and visitor registration, calculate the resource allocation amount for each task.

[0131] Set C = 2. The reason for setting is as follows: In the campus identity authentication system, the processing time of different tasks fluctuates to a certain extent, and the dynamic allocation of computing resources needs to take into account the stability of task execution and the balance of computing load. In order to ensure the rationality of computing resource allocation, it is necessary to make appropriate resource compensation or reduction for tasks whose processing time deviates from the overall mean. The value of C should be able to balance the deviation of task execution time while avoiding excessive resource fluctuations affecting task scheduling. In the process of setting C, firstly, the historical processing time distribution of various tasks in the campus identity authentication system is counted, and the standard deviation σ of the task processing time is calculated. T , and adjust based on the task execution frequency and computing resource usage. After data analysis, the standard deviation of task processing time is usually between 1.5 and 2.5 seconds. If C is too small, the dynamic adjustment range of computing resources is insufficient, and it is difficult to effectively compensate for tasks with large computing resource requirements. If C is too large, it will lead to excessive tilt of computing resources, affecting the balance of the overall computing load. Considering the stability of computing resource allocation and the fluctuation range of different task processing times, C=2 is finally set. This value can appropriately adjust the allocation of computing resources so that the increase or decrease of resources is in a reasonable range, thereby ensuring the balance of task scheduling and the stability of system computing efficiency.

[0132] The priority weights of the tasks are:

[0133] Laboratory access control certification: Q 1 =22.25

[0134] Dormitory access authentication: Q 2 =15.8

[0135] Visitor registration authentication: Q 3 =10.3

[0136] First, calculate the total weight:

[0137]

[0138] Then, calculate the initial allocation of resources:

[0139]

[0140] Set the historical average processing time T of the task h1 = 2.5 seconds, T h2 = 3.0 seconds, T h3 = 6.0 seconds, calculate the average processing time of all tasks:

[0141]

[0142] Calculate resource adjustment amount:

[0143]

[0144] Final computing resource allocation:

[0145] R 1 =46.0+2.31=48.31

[0146] R 2 =32.7+1.82=34.52

[0147] R 3 =21.3+2.94=24.24

[0148] As shown in Table 3.1, the dynamic adjustment of computing resources effectively allocates computing units, and finally obtains the computing resource allocation matrix.

[0149] Table 3.1 Computational resource allocation matrix

[0150]

[0151] As shown in Table 3.1, the laboratory access control authentication task has a higher priority and occupies the largest proportion of computing resources, while the visitor registration authentication task has relatively lower computing requirements and the amount of computing resources allocated is relatively reduced. A computing resource allocation matrix is ​​constructed.

[0152] The identity authentication task calculation sequence generation submodule sorts the identity authentication tasks according to the computing resource allocation matrix, task priority and computing resource allocation, adjusts the task execution order, removes tasks whose computing resource allocation is lower than the threshold, and obtains the identity authentication task calculation sequence;

[0153] According to the computing resource allocation matrix, the system sorts the authentication tasks according to the task priority and computing resource allocation, adjusts the task execution order, and removes the tasks whose computing resource allocation is lower than the threshold. Assuming that the minimum computing resource allocation threshold R min =20.0.

[0154] The setting basis is as follows: In the campus identity authentication system, each identity authentication task requires a certain amount of computing resources to ensure the normal execution of the task. If the computing resources are allocated too low, it may cause the task execution time to be too long, affect the efficiency of identity authentication, and even cause the task to fail. Therefore, the system needs to set a reasonable minimum computing resource allocation threshold to ensure that all tasks can at least obtain basic computing power.

[0155] In setting R minWhen performing identity authentication, we first analyze the computing resource requirements of different types of identity authentication tasks, such as laboratory access authentication, dormitory access authentication, and visitor registration authentication. Laboratory access authentication tasks generally involve high-security identity verification and require higher computing resources, usually allocated between 30-40 units; dormitory access authentication tasks involve a large number of students and have moderate computing resource requirements, usually between 20-30 units; and visitor registration authentication tasks have the lowest computing requirements, usually allocated between 10-20 units.

[0156] In order to ensure the rationality of task scheduling, the system counts the computing resource requirements of each task and calculates the average computing resource allocation value required for the task, while taking into account the standard deviation of task execution to measure the fluctuation of task computing resources. After statistics, the system found that the average computing resource requirement of the identity authentication task was about 28.0 units, while the standard deviation of the task computing resource requirement was about 8.0 units. In order to avoid task failure due to insufficient computing resources and at the same time not excessively increase the minimum threshold of computing resources, the system uses the average computing resource value minus the standard deviation to set the minimum computing resource allocation threshold, which is 20.

[0157] The system checks the computing resource allocation of each task. As shown in Table 1, all tasks meet the minimum computing resource allocation requirements, so there is no need to eliminate tasks. The task execution order is sorted according to the computing resource allocation as follows:

[0158] Laboratory access control certification (48.31)

[0159] Dormitory access control authentication (34.52)

[0160] Visitor registration and authentication (24.24)

[0161] Finally, an authentication task calculation sequence is generated, which is used for scheduling actual authentication tasks to ensure reasonable allocation of computing resources and improve task execution efficiency.

[0162] See also Figure 5 , the distributed matching calculation module includes:

[0163] The task computing allocation submodule extracts the computing priority of the task based on the identity authentication task computing sequence, allocates tasks to the campus edge computing nodes according to the task computing priority, calculates the task load ratio of each computing node, sets the task allocation parameters, calls the task allocation parameters to adjust the computing tasks of the edge computing nodes, and generates the computing node task allocation ratio;

[0164] In the campus ID card authentication system, daily authentication tasks come from multiple different scenarios, including campus access control, library borrowing, canteen payment, and laboratory access control. The computing requirements of authentication tasks in different scenarios are different. For example, access control authentication tasks require high real-time performance, while library borrowing authentication tasks have relatively low timeliness requirements. Therefore, it is necessary to set computing priorities for authentication tasks in different scenarios. For example, access control sets a priority of 3, laboratory access control sets a priority of 2, library borrowing sets a priority of 1, and canteen payment sets a priority of 2. According to the computing priority, adjust the task allocation ratio and set the computing node task allocation ratio. Assume that the campus edge computing network contains 5 computing nodes, and the computing power of each node is 10, 8, 6, 5, and 4 units respectively. By calculating the computing power ratio of each node, the task allocation ratio is determined:

[0165] The computing power data of the current computing nodes are as follows:

[0166] Table 4.1 Computing node computing capacity table

[0167]

[0168] Calculate the task allocation ratio based on the above data:

[0169]

[0170] Based on the calculation results, the tasks are allocated to different computing nodes in proportion to ensure that the identity authentication tasks are reasonably distributed in the campus edge computing environment, and finally the task allocation ratio of the computing nodes is obtained.

[0171] The calculation parameter optimization submodule analyzes the adaptability of each calculation node in the matching calculation based on the task allocation ratio of the calculation node and the matching results of the biometric region, adjusts the matching calculation parameters, and sets the matching parameter adjustment ratio using the formula:

[0172]

[0173] Calculate the matching calculation adjustment parameter P′ for each computing node ij , update the adjusted matching calculation parameters, where P ij Represents the initial matching calculation parameters, M ik represents the matching adaptability of computing node i to feature region k, B k represents the benchmark matching value of feature region k, L represents the total number of matching regions, and a represents the matching parameter adjustment coefficient;

[0174] Based on the task allocation ratio of computing nodes, the historical matching computing data of each computing node is called to extract the key biometric matching parameters in the campus ID card authentication process, including face recognition similarity, fingerprint matching rate, identity information consistency, etc. Assuming that in the historical matching data of a computing node in a certain period of time, the average face recognition similarity is 0.87, the average fingerprint matching rate is 0.75, and the average identity information consistency is 0.81, it is set as the benchmark matching value:

[0175] B k =[0.87, 0.75, 0.81]

[0176] Assume that the feature matching data of computing node 2 is:

[0177] M 2k =[0.84, 0.73, 0.79]

[0178] a represents the matching calculation adjustment coefficient, which is set based on the matching deviation amplitude of the computing node. The matching deviation amplitude is defined as the average error between the computing node and the benchmark matching value during the feature matching process. If the error amplitude is large, the matching calculation adjustment coefficient should be appropriately increased to amplify the adjustment amplitude. If the error amplitude is small, the matching calculation adjustment coefficient should be small to ensure that the matching parameters are not over-corrected. Calculate the matching deviation amplitude:

[0179]

[0180] Substitute the data and calculate:

[0181]

[0182] The matching calculation adjustment coefficient a is set as the correction coefficient of the error amplitude. According to the feature matching data of the campus ID card identity authentication system, the empirical interval is [1.05, 1.15]. When the matching deviation amplitude δ i When the matching deviation amplitude δ is less than 0.02, set a = 1.05. i When it is greater than 0.03, set a=1.15, and when 0.02≤δ i ≤0.03, linear interpolation is used to calculate a, and the calculation method is as follows:

[0183]

[0184] Bring in data:

[0185]

[0186] Calculate the adjusted matching calculation parameters:

[0187] P′ 2j =P2j ×(1+0.0233) 1.083

[0188] Assume that the initial matching calculation parameter P of computing node 2 is 2j =0.85, then:

[0189] P′ 2j =0.85×(1+0.0233) 1.083

[0190] P′ 2j ≈0.85×1.0256=0.8718

[0191] Update the matching parameters of the computing nodes, optimize the computing configuration of the identity authentication task, and finally obtain the adjusted matching computing parameters P′ 2j =0.8718.

[0192] The matching confidence calculation submodule calculates the matching confidence of each computing node according to the adjusted matching calculation parameters, calculates the identity matching confidence weight according to the matching confidence of each node, adjusts the matching confidence weight distribution ratio, and generates the identity matching confidence calculation result;

[0193] According to the adjusted matching calculation parameters, the matching confidence of each computing node in the campus ID card authentication task is calculated. The matching confidence measures the matching degree of the computing node to the current authentication task. For example, the adjusted matching calculation parameter calculation value of computing node 2 is P′ 2j =0.8718, calculate the matching confidence

[0194] The adjusted matching calculation parameters of the compute nodes are as follows:

[0195] Table 4.2 Computation node matching calculation parameter table after adjustment

[0196]

[0197]

[0198] Calculate the match confidence:

[0199]

[0200] The matching confidence indicates the matching reliability of the computing node in the campus ID card authentication task. The matching confidence of computing node 1 is the highest, which is 0.2156, and the matching confidence of computing node 5 is the lowest, which is 0.1810. According to the calculation results, the matching confidence is used as the basis for the identity matching confidence weight allocation, and the matching confidence weight allocation ratio is adjusted to finally generate the identity matching confidence calculation result.

[0201] See also Figure 6 , the matching result decision module includes:

[0202] The confidence threshold determination submodule obtains the matching confidence data of each computing node based on the identity matching confidence calculation result, sets the identity matching confidence threshold, calls the matching confidence threshold to compare with the matching confidence of each computing node, determines whether the matching confidence of each computing node exceeds the identity matching confidence threshold, screens the computing nodes whose matching confidence does not reach the threshold, and generates the matching confidence determination result;

[0203] Based on the identity matching confidence calculation results, first obtain the matching confidence data of each computing node. The matching confidence reflects the matching reliability of the computing node to the input identity data. For example, in a system containing five computing nodes, the matching confidence of each node may be 0.82, 0.76, 0.91, 0.67 and 0.88 respectively. Then set the identity matching confidence threshold. The identity matching confidence threshold is usually determined by the security level of the system. If the system requires high security, the threshold can be set to 0.80. If the security requirement is high, the threshold can be set to 0.81. To find a moderate value, the threshold value can be set to 0.70. In this embodiment, the identity matching confidence threshold value is set to 0.75. Subsequently, the matching confidence threshold value is called to compare with the matching confidence of each computing node. The matching confidences of the five computing nodes are compared one by one, and it is found that the matching confidence of the fourth computing node, 0.67, is lower than the threshold value 0.75, and the matching confidences of the remaining computing nodes are all higher than the threshold value. Therefore, the computing node whose matching confidence does not reach the threshold value, that is, node 4, is screened out, and its matching confidence value is recorded, and finally the matching confidence judgment result is generated.

[0204] The matching result re-evaluation submodule selects computing nodes whose matching confidence does not reach the threshold according to the matching confidence judgment result, re-evaluates their matching confidence, adjusts the matching confidence according to the matching task volume, computing load and computing error of the computing node, sets the adjustment ratio, and uses the formula:

[0205]

[0206] Calculate the new matching confidence Z′ i , update to get the adjusted matching confidence, where Z i represents the initial matching confidence, J ij represents the computation error of computing node i in matching task j, Y ij represents the allowable error of computing task j, and X represents the total number of computing tasks;

[0207] Based on the matching confidence judgment result, the computing nodes whose matching confidence does not reach the threshold are screened. In this example, only node 4 does not reach the threshold, so node 4 is re-evaluated. The matching task volume, computing load and computing error of the computing node are considered during the evaluation. The current computing task volume of node 4 is 30 matching tasks, accounting for 25% of the total number of tasks, and the computing load is 75%. The computing error reflects the deviation that may occur in the node during the matching process. The computing error can be measured by the error mean of the matching data. Assuming that the error mean of node 4 in 30 matching tasks is 0.08, and the allowable error is set to 0.05, the computing error exceeds the allowable error range. Based on these data, the formula is used for calculation:

[0208]

[0209] The adjusted matching confidence is 0.70, and the matching confidence data of the computing node is updated to obtain the adjusted matching confidence.

[0210] The identity matching determination submodule determines whether the matching confidence of all computing nodes exceeds the identity matching confidence threshold based on the adjusted matching confidence. If all matching confidences exceed the threshold, the identity matching is marked as successful. If there are still some computing nodes whose matching confidences are lower than the threshold, the identity matching result is re-evaluated based on the matching confidences of all computing nodes to generate an identity authentication matching determination result.

[0211] According to the adjusted matching confidence, determine whether the matching confidence of all computing nodes exceeds the identity matching confidence threshold. In this example, the matching confidence of node 4 is 0.70 after adjustment, which is still lower than the identity matching confidence threshold of 0.75. Therefore, the matching confidence of some computing nodes is still lower than the threshold. At this time, the system re-evaluates the identity matching result based on the matching confidence of all computing nodes and calculates the average matching confidence of all computing nodes:

[0212]

[0213] The mean match confidence is 0.814, which is higher than the identity match confidence threshold of 0.75. Therefore, the identity match is determined to be successful, and an identity authentication match determination result is generated.

[0214] Table 5.1 Computational node matching confidence

[0215]

[0216] As shown in Table 5.1, the average matching confidence of all computing nodes reaches 0.814, which exceeds the identity matching confidence threshold of 0.75. Therefore, the identity match is judged to be successful and the identity authentication matching judgment result is generated.

[0217] The above are only preferred embodiments of the present invention and are not intended to limit the present invention in other forms. Any technician familiar with the profession may use the technical contents disclosed above to change or modify them into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution of the present invention still falls within the protection scope of the technical solution of the present invention.

Claims

1. The campus ID card multi-scenario identity authentication system based on edge computing is characterized by: The system comprises: The authentication request scheduling module obtains the authentication request data, extracts the timestamp, calculates the time interval between the current authentication request and the last access, classifies the identity access type according to the identity access frequency threshold, synchronously determines the computing resource load status, adjusts the authentication task execution priority, and generates the authentication task priority list; The biometric matching optimization module obtains biometric data according to the identity authentication task priority list, calculates the biometric region change amplitude, classifies the region stability according to the feature change threshold, and generates the biometric region matching result; The authentication task priority adjustment submodule adjusts the computing resource allocation ratio of the campus edge computing server task queue based on the identity authentication task priority list and generates an identity authentication task computing sequence; The distributed matching calculation module adjusts the task allocation ratio of the computing nodes based on the identity authentication task calculation sequence, calculates the matching confidence in combination with the biometric feature area matching weight, and generates an identity matching confidence calculation result; The matching result decision module determines that the match is successful based on the identity matching confidence calculation result and generates an identity authentication matching determination result if the matching confidence of all computing nodes is higher than the identity matching confidence threshold.

2. According to the edge computing-based campus ID card multi-scenario identity authentication system of claim 1, it is characterized in that: The identity authentication task priority list includes high-frequency access identities, medium-frequency access identities, and low-frequency access identities. The biometric feature area matching results include stable areas, sub-stable areas, and unstable areas. The identity authentication task calculation sequence includes a computing resource allocation ratio and a task calculation priority. The identity matching confidence calculation result includes a matching confidence calculation value and a computing node matching parameter. The identity authentication matching judgment result includes an identity matching success record, an identity matching failure record, and an identity matching re-evaluation result.

3. According to the edge computing-based campus ID card multi-scenario identity authentication system of claim 1, it is characterized in that: The identity authentication request scheduling module includes: The identity authentication classification submodule obtains the identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, and compares the identity high-frequency access threshold with the identity medium-frequency access threshold for classification. If the time interval is less than the identity high-frequency access threshold, it is marked as a high-frequency access identity. If the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as a medium-frequency access identity. If the time interval is greater than the identity medium-frequency access threshold, it is marked as a low-frequency access identity, and the identity access frequency classification result is generated; The computing load monitoring submodule uses the formula based on the identity access frequency classification results and the load monitoring data of the campus edge computing server: Calculate the load adjustment value L adj , determine whether the calculation load adjustment value exceeds the calculation resource allocation threshold, and generate the calculation load status result, where L cur Represents the current load value, F i represents the identity access frequency weight, W i Represents the identity type calculation weight, T avg represents the mean of the historical access time interval, T cur Represents the timestamp of the current authentication request, T prev Represents the timestamp of the last authentication request, and n represents the total number of identity types; The task priority adjustment submodule is based on the computing load status result. If the computing resource load exceeds the computing resource allocation threshold, the execution priority of low-frequency access identity requests is reduced, and the execution priority of high-frequency access identity requests is increased simultaneously, and the identity authentication task priority list is generated in order.

4. According to the edge computing-based campus ID card multi-scenario identity authentication system of claim 1, it is characterized in that: The biometric matching optimization module includes: The high-priority identity authentication data collection submodule collects the biometric data corresponding to the high-priority identity authentication request according to the identity authentication task priority list, extracts the biometric area information, and obtains the biometric basic data set; The historical matching data retrieval submodule retrieves the historical matching data of the target identity based on the biometric basic data set, compares the current biometric data with the corresponding feature point set in the historical matching data, calculates the matching error of each feature point, and obtains the feature matching error value; The biometric stability classification submodule uses the formula according to the feature matching error value: Calculate the feature variation amplitude S of the i-th biometric region i , set the biometric stability threshold T1 and the medium stability threshold T2. If S i < T1, mark it as a stable region. If T1 ≤ S i < T2, mark it as a sub-stable region. If S i ≥ T2, mark it as an unstable region, and perform feature denoising processing on the unstable region to eliminate abnormal feature points to obtain the biometric region matching result. Among them, N represents the number of samples in the historical matching record of this region, and E ij represents the matching error value of the i-th biometric region in the j-th matching record. represents the average value of the matching error values of the i-th biometric region, and w i represents the weight coefficient of the i-th biometric region.

5. According to the edge computing-based campus ID card multi-scenario identity authentication system of claim 1, it is characterized in that: The authentication task priority adjustment submodule includes: The task priority parsing submodule parses the priority weight of each identity authentication task based on the identity authentication task priority list, extracts the identity information, task type and historical processing record corresponding to the task request, and calculates the task priority adjustment parameter; The computing resource allocation submodule adjusts the parameters based on the task priority, calculates the computing resource allocation ratio of the identity authentication task, sets the total amount of computing resources, and increases its computing resource allocation ratio if the task priority is high; if the task priority is low, reduces the computing resource allocation ratio, using the formula: Calculate the computing resource allocation R of the i-th task i , construct the computing resource allocation matrix, where Q i represents the priority adjustment parameter of the i-th task, R represents the total amount of computing resources, K represents the total number of tasks, and T h represents the historical average processing time of the i-th task, represents the average processing time of all tasks, and C represents the computing resource adjustment coefficient; The identity authentication task calculation sequence generation submodule sorts the identity authentication tasks according to the computing resource allocation matrix, task priorities and computing resource allocation amounts, adjusts the task execution order, eliminates tasks whose computing resource allocation amounts are lower than a threshold, and obtains the identity authentication task calculation sequence.

6. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The distributed matching calculation module includes: The task calculation allocation submodule extracts the calculation priority of the task based on the identity authentication task calculation sequence, allocates tasks to the campus edge computing nodes according to the task calculation priority, calculates the task load ratio of each computing node, sets the task allocation parameters, calls the task allocation parameters to adjust the computing tasks of the edge computing nodes, and generates the task allocation ratio of the computing nodes; The calculation parameter optimization submodule analyzes the adaptability of each calculation node in the matching calculation based on the task allocation ratio of the calculation node and the matching result of the biometric feature area, adjusts the matching calculation parameters, sets the matching parameter adjustment ratio, and adopts the formula: Calculate the matching calculation adjustment parameter P′ for each computing node ij , update the adjusted matching calculation parameters, where P ij Represents the initial matching calculation parameters, M ik represents the matching adaptability of computing node i to feature region k, B k represents the benchmark matching value of feature region k, L represents the total number of matching regions, and a represents the matching parameter adjustment coefficient; The matching confidence calculation submodule calculates the matching confidence of each computing node according to the adjusted matching calculation parameters, calculates the identity matching confidence weight according to the matching confidence of each node, adjusts the matching confidence weight distribution ratio, and generates the identity matching confidence calculation result.

7. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The matching result decision module includes: The confidence threshold determination submodule obtains the matching confidence data of each computing node based on the identity matching confidence calculation result, sets the identity matching confidence threshold, calls the matching confidence threshold to compare with the matching confidence of each computing node, determines whether the matching confidence of each computing node exceeds the identity matching confidence threshold, screens the computing nodes whose matching confidence does not reach the threshold, and generates a matching confidence determination result; The matching result re-evaluation submodule selects computing nodes whose matching confidence does not reach the threshold according to the matching confidence judgment result, re-evaluates their matching confidence, adjusts the matching confidence according to the matching task volume, computing load and computing error of the computing node, sets the adjustment ratio, and adopts the formula: Calculate the new matching confidence Z′ i , update to get the adjusted matching confidence, where Z i represents the initial matching confidence, J ij represents the computation error of computing node i in matching task j, Y ij represents the allowable error of computing task j, and X represents the total number of computing tasks; The identity matching determination submodule determines whether the matching confidence of all computing nodes exceeds the identity matching confidence threshold based on the adjusted matching confidence. If all matching confidences exceed the threshold, the identity matching is marked as successful. If there are still some computing nodes whose matching confidences are lower than the threshold, the identity matching result is re-evaluated based on the matching confidences of all computing nodes to generate an identity authentication matching determination result.

Citation Information

Patent Citations

  • Intelligent device computing resource allocation method, device and system

    CN110417831A

  • Load-aware cloud computing resource elastic distribution system and method

    CN111491006A

  • Face feature base library management method, controller and system

    CN114155583A

  • Gate control method, device and equipment and computer readable storage medium

    CN114613056A

  • Whole-house multi-defense-area door lock control system based on Internet of Things

    CN116434391A

Cited By

  • Entrance guard abnormal behavior detection and linkage early warning method and system based on edge calculation

    CN120894852A