Campus id card multi-scene identity authentication system based on edge computing
By classifying identity access frequency and biometric stability, and dynamically adjusting the allocation of computing resources and tasks, the problem of uneven resource allocation and large errors in identity authentication in existing technologies is solved, thus achieving efficient and secure identity authentication.
Patent Information
- Application Number
- CN202510304000.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-03-14
AI Technical Summary
Existing technologies fail to prioritize authentication requests based on frequency characteristics during the authentication process, resulting in uneven allocation of computing resources. This affects the response speed and authentication accuracy of high-priority requests. Furthermore, the lack of stable classification during biometric matching leads to significant errors, impacting the security and accuracy of authentication.
The identity authentication request scheduling module categorizes identity access types and adjusts task priorities based on the computing resource load status. The biometric matching module classifies stability based on the variation of feature regions and dynamically adjusts the computing resource allocation ratio and node task allocation. The matching reliability is calculated based on the matching results to generate the identity authentication judgment result.
It improves the response speed of high-frequency identity authentication requests, enhances the accuracy and security of identity recognition, ensures the reasonable allocation of computing resources, reduces false recognition, and strengthens the stability and reliability of identity authentication.
Smart Images

Figure CN120108076B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of identity authentication, and particularly relates to a campus ID card multi-scene identity authentication system based on edge computing. BACKGROUND
[0002] The technical field of identity authentication includes various technical methods for verifying and confirming the identity of users. The core content of this technical field is to achieve unique identification of individual identity through means such as biometric features, passwords, and smart cards, and to ensure that authorized users can access specific resources or services. Identity authentication technology as a whole covers biometric recognition, encryption authentication, smart card authentication, and multi-factor authentication, and is widely used in finance, security, campus management, and other scenarios. With the development of computing technology, identity authentication systems are gradually evolving towards higher efficiency and security, and combining edge computing, artificial intelligence, and other technologies to improve the real-time and reliability of authentication.
[0003] Among them, the campus ID card multi-scene identity authentication system based on edge computing refers to the use of edge computing technology to manage various identity authentication needs within the campus environment. The system covers contactless identity verification methods based on radio frequency identification technology, identity comparison methods based on biometric feature matching, and remote identity confirmation mechanisms based on encryption communication protocols. The system uses an edge computing architecture to perform identity data analysis, feature matching, and permission management at local nodes on campus, reducing dependence on central servers and improving the real-time nature of data processing. At the same time, encryption authentication protocols are used to protect identity data, ensuring the security of the identity authentication process.
[0004] In the prior art, identity authentication processes typically rely on a single authentication method, making it difficult to prioritize based on the frequency characteristics of identity authentication requests, resulting in uneven allocation of computing resources in high-concurrency environments, which can cause delays in responding to high-priority identity authentication requests. Due to the lack of classification of the stability of different regions in the biometric feature matching process, all feature points participate in matching calculations with the same weight, resulting in large matching errors and affecting the accuracy of identity authentication. The allocation of computing resources is usually based on fixed strategies, and the allocation proportion of computing resources cannot be dynamically adjusted according to task priority, resulting in waste of computing resources or unreasonable allocation, affecting the overall computing efficiency of the system. The task scheduling of computing nodes often uses fixed strategies, and lacks adaptive adjustment of matching confidence, which can easily lead to low-confidence matching results affecting the final authentication result, increasing the risk of misidentification. The determination of identity authentication matching results is usually based on a fixed matching threshold, and cannot be dynamically evaluated in combination with the confidence of multiple computing nodes, which can easily produce false positives in boundary cases, reducing the accuracy and security of identity authentication. SUMMARY
[0005] The application aims to solve the problems in the prior art and provides a campus ID card multi-scene identity authentication system based on edge computing.
[0006] To achieve the above-mentioned purpose, the application adopts the following technical scheme: the campus ID card multi-scene identity authentication system based on edge computing comprises:
[0007] The identity authentication request scheduling module obtains identity authentication request data, extracts a timestamp, calculates the time interval between the current identity authentication request and the last access, classifies the identity access type according to the identity access frequency threshold, synchronously judges the computing resource load state, adjusts the identity authentication task execution priority, and generates an identity authentication task priority list.
[0008] The biological feature matching optimization module obtains biological feature data according to the identity authentication task priority list, calculates the biological feature region variation amplitude, classifies the region stability according to the feature variation threshold, and generates a biological feature region matching result.
[0009] The authentication task priority adjustment submodule adjusts the computing resource allocation proportion of the campus edge computing server task queue based on the identity authentication task priority list, and generates an identity authentication task computing sequence.
[0010] The distributed matching computing module adjusts the computing node task allocation proportion based on the identity authentication task computing sequence, combines the biological feature region matching weight to calculate the identity matching confidence, and generates an identity matching confidence calculation result.
[0011] The matching result decision module determines that the matching is successful according to the identity matching confidence calculation result, and generates an identity authentication matching decision result if the matching confidence of all computing nodes is higher than the identity matching confidence threshold.
[0012] As a further scheme of the application, the identity authentication task priority list comprises high-frequency access identity, medium-frequency access identity and low-frequency access identity, the biological feature region matching result comprises stable region, sub-stable region and unstable region, the identity authentication task computing sequence comprises computing resource allocation proportion and task computing priority, the identity matching confidence calculation result comprises matching confidence calculation value and computing node matching parameter, and the identity authentication matching decision result comprises identity matching success record, identity matching failure record and identity matching re-evaluation result.
[0013] As a further scheme of the application, the identity authentication request scheduling module comprises:
[0014] The identity authentication classification submodule obtains identity authentication request data through a campus ID card swiping machine, extracts a timestamp of the identity authentication request, calculates a time interval between the current identity authentication request and the last access, compares the identity high-frequency access threshold and the identity medium-frequency access threshold for classification, if the time interval is less than the identity high-frequency access threshold, marks as a high-frequency access identity, if the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, marks as a medium-frequency access identity, if the time interval is greater than the identity medium-frequency access threshold, marks as a low-frequency access identity, and generates an identity access frequency classification result;
[0015] The computing load monitoring submodule generates a computing load state result based on the identity access frequency classification result and in combination with load monitoring data of the campus edge computing server, adopts a formula:
[0016]
[0017] The computing load adjustment value L is calculated and obtained adj , and it is judged whether the computing load adjustment value exceeds a computing resource allocation threshold, to generate a computing load state result, wherein L cur represents a current load value, F i represents an identity access frequency weight, W i represents an identity type calculation weight, T avg represents a historical access time interval mean value, T cur represents a current identity authentication request timestamp, T prev represents a last identity authentication request timestamp, and n represents a total number of identity types.
[0018] The task priority adjustment submodule generates an identity authentication task priority list based on the computing load state result, if the computing resource load exceeds the computing resource allocation threshold, reduces the execution priority of a low-frequency access identity request, synchronously improves the execution priority of a high-frequency access identity request, and sorts.
[0019] As a further scheme of the application, the biological feature matching optimization module comprises:
[0020] The high-priority identity authentication data acquisition submodule acquires biological feature data corresponding to a high-priority identity authentication request according to the identity authentication task priority list, extracts biological feature region information, and obtains a biological feature basic data set.
[0021] The historical matching data retrieval submodule retrieves historical matching data of a target identity based on the biological feature basic data set, compares corresponding feature point sets in the current biological feature data and the historical matching data, calculates matching errors of each feature point, and obtains a feature matching error value.
[0022] The biometric feature stability classification submodule adopts a formula according to the feature matching error value:
[0023]
[0024] Calculate the feature variation range S of the i-th biometric feature region i Set a biometric feature stability threshold T1 and a medium stability threshold T2, if S i <T1, mark as a stable region, if T1≤S i <T2, mark as a sub-stable region, if S i ≥T2, mark as an unstable region, and perform feature denoising processing on the unstable region to eliminate abnormal feature points, and obtain a biometric feature region matching result, wherein N represents the number of samples in the historical matching record of the region, E ij represents the matching error value of the i-th biometric feature region in the j-th matching record, represents the average value of the i-th biometric feature region matching error value, w i represents the weight coefficient of the i-th biometric feature region.
[0025] As a further scheme of the present application, the authentication task priority adjustment submodule comprises:
[0026] The task priority analysis submodule analyzes the priority weight of each identity authentication task based on the identity authentication task priority list, extracts the identity information, task type and historical processing record corresponding to the task request, and calculates the task priority adjustment parameter;
[0027] The computing resource allocation submodule calculates the computing resource allocation proportion of the identity authentication task based on the task priority adjustment parameter, sets the total amount of computing resources, increases the computing resource allocation proportion if the task priority is high, and reduces the computing resource allocation proportion if the task priority is low, and adopts a formula:
[0028]
[0029] Calculate the computing resource allocation amount R of the i-th task i , and construct a computing resource allocation matrix, wherein Q i represents the i-th task priority adjustment parameter, R represents the total amount of computing resources, K represents the total number of tasks, T h represents the historical average processing time of the i-th task, represents the average processing time of all tasks, and C represents the computing resource adjustment coefficient;
[0030] The identity authentication task computing sequence generation submodule sorts the identity authentication tasks according to the task priority and the computing resource allocation amount based on the computing resource allocation matrix, adjusts the task execution order, eliminates the tasks with the computing resource allocation amount lower than a threshold, and obtains an identity authentication task computing sequence.
[0031] As a further scheme of the present application, the distributed matching computing module comprises:
[0032] The task computing allocation submodule extracts the computing priority of the tasks based on the identity authentication task computing sequence, performs task allocation on the campus edge computing nodes according to the task computing priority, calculates the task load proportion of each computing node, sets task allocation parameters, performs computing task adjustment on the edge computing nodes by calling the task allocation parameters, and generates a computing node task allocation proportion;
[0033] The computing parameter optimization submodule analyzes the adaptability of each computing node in the matching computation based on the computing node task allocation proportion in combination with the biological feature region matching result, adjusts the matching computation parameters, sets a matching parameter adjustment ratio, and adopts the formula:
[0034]
[0035] The matching computation adjustment parameter P' of each computing node is calculated ij , and the adjusted matching computation parameter is obtained by updating, wherein P ij represents the initial matching computation parameter, M ik represents the matching adaptability degree of the computing node i to the feature region k, B k represents the reference matching value of the feature region k, L represents the total number of matching regions, and a represents the matching parameter adjustment coefficient;
[0036] The matching confidence calculation submodule calculates the matching confidence of each computing node according to the adjusted matching computation parameter, calculates the identity matching confidence weight according to the matching confidence of each node, adjusts the matching confidence weight allocation proportion, and generates an identity matching confidence calculation result.
[0037] As a further scheme of the present application, the matching result decision module comprises:
[0038] The confidence threshold determination submodule obtains the matching confidence data of each computing node based on the identity matching confidence calculation result, sets an identity matching confidence threshold, calls the identity matching confidence threshold to compare with the matching confidence of each computing node, judges whether the matching confidence of each computing node exceeds the identity matching confidence threshold, screens the computing nodes with the matching confidence not reaching the threshold, and generates a matching confidence determination result.
[0039] The matching result re-evaluation sub-module re-evaluates the matching confidence of the computing nodes whose matching confidence does not reach the threshold value according to the matching confidence determination result, adjusts the matching confidence according to the matching task amount, the computing load and the computing error of the computing nodes, sets an adjustment ratio, and uses the formula:
[0040]
[0041] The new matching confidence Z' is calculated i , and the adjusted matching confidence is obtained by updating, wherein Z i represents the initial matching confidence, J ij represents the computing error of the computing node i in the matching task j, Y ij represents the allowed error of the computing task j, and X represents the total number of computing tasks.
[0042] The identity matching determination sub-module determines whether all the matching confidences of the computing nodes exceed the identity matching confidence threshold value based on the adjusted matching confidence, marks the identity matching as successful if all the matching confidences exceed the threshold value, and re-evaluates the identity matching result and generates an identity authentication matching determination result if some of the matching confidences of the computing nodes are lower than the threshold value.
[0043] Compared with the prior art, the advantages and positive effects of the present application are that:
[0044] In the present application, the time interval of the identity authentication request is calculated, the access frequency is classified, the task priority is adjusted in combination with the computing resource load state, the response speed of the high-frequency identity authentication request is ensured, the feature region variation amplitude is analyzed, the region stability is classified according to the threshold value, the accuracy of identity recognition is improved, the allocation proportion of the computing resource is dynamically adjusted, the computing task can be reasonably allocated to the edge computing resource according to the demand, the task allocation proportion of the computing node is adjusted according to the computing priority of the identity authentication task, the matching confidence is calculated in combination with the biological feature matching result, the computing resource is optimally allocated among different nodes, the reliability of the identity matching result is improved, the misrecognition condition is reduced, and the security and stability of the identity authentication are improved. BRIEF DESCRIPTION OF DRAWINGS
[0045] Figure 1 The system flowchart of the present application is shown in the figure;
[0046] Figure 2 The identity authentication request scheduling module flowchart of the present application is shown in the figure;
[0047] Figure 3 The biological feature matching optimization module flowchart of the present application is shown in the figure;
[0048] Figure 4The flow chart of the priority adjustment submodule for the authentication task of the present application;
[0049] Figure 5 The flow chart of the distributed matching calculation module of the present application;
[0050] Figure 6 The flow chart of the matching result decision module of the present application. DETAILED DESCRIPTION
[0051] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0052] In the description of the present application, it should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the present application and simplify the description, and therefore cannot be understood as indicating or implying that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application. In addition, in the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.
[0053] Please refer to Figure 1 The campus ID card multi-scene identity authentication system based on edge computing comprises:
[0054] The identity authentication request scheduling module obtains identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, classifies according to the time interval threshold, if the time interval is less than the identity high-frequency access threshold, it is marked as a high-frequency access identity, if the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as a medium-frequency access identity, if the time interval is greater than the identity medium-frequency access threshold, it is marked as a low-frequency access identity, according to the campus edge computing server load monitoring data, it is judged whether the current computing load exceeds the computing resource allocation threshold, if the computing resource load exceeds the allocation threshold, the execution priority of the low-frequency access identity request is reduced, the execution priority of the high-frequency access identity request is increased, and an identity authentication task priority list is outputted;
[0055] The biometric feature matching optimization module collects biometric feature data corresponding to high-priority identity authentication requests according to the identity authentication task priority list, retrieves historical matching data of the target identity, calculates the feature variation amplitude of the biometric feature region in the difference matching record, classifies according to the feature variation amplitude threshold, if the feature variation amplitude is less than the biometric feature stability threshold, it is marked as a stable region, if the feature variation amplitude is between the biometric feature stability threshold and the medium stability threshold, it is marked as a sub-stable region, if the feature variation amplitude is greater than the medium stability threshold, it is marked as an unstable region, and the feature denoising processing is performed on the unstable region, the abnormal feature points are removed, and the biometric feature region matching result is generated;
[0056] The authentication task priority adjustment submodule adjusts the computing resource allocation proportion based on the identity authentication task priority list according to the task priority, increases the computing resource allocation proportion if the task priority is high, reduces the computing resource allocation proportion if the task priority is low, and generates an identity authentication task computing sequence;
[0057] The distributed matching computing module distributes identity authentication computing tasks to campus edge computing nodes based on the identity authentication task computing sequence, adjusts the computing node task allocation proportion according to the task computing priority, adjusts the edge computing node matching computing parameters combined with the biometric feature region matching result, calculates the matching confidence of each computing node, and generates an identity matching confidence calculation result;
[0058] The matching result decision module judges whether the matching confidence of each computing node exceeds the identity matching confidence threshold based on the identity matching confidence calculation result, marks the identity matching as successful if all matching confidences exceed the identity matching confidence threshold, re-evaluates the identity matching result if part of the matching confidences is lower than the identity matching confidence threshold, and generates an identity authentication matching decision result.
[0059] The identity authentication task priority list includes high-frequency access identity, medium-frequency access identity, and low-frequency access identity, the biometric feature region matching result includes stable region, sub-stable region, and unstable region, the identity authentication task computing sequence includes computing resource allocation proportion and task computing priority, the identity matching confidence calculation result includes matching confidence calculation value and computing node matching parameter, and the identity authentication matching decision result includes identity matching success record, identity matching failure record, and identity matching re-evaluation result.
[0060] Please refer to Figure 2 , the identity authentication request scheduling module includes:
[0061] The identity authentication classification submodule obtains identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, compares the identity high-frequency access threshold and the identity medium-frequency access threshold for classification, if the time interval is less than the identity high-frequency access threshold, it is marked as high-frequency access identity, if the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as medium-frequency access identity, if the time interval is greater than the identity medium-frequency access threshold, it is marked as low-frequency access identity, and an identity access frequency classification result is generated;
[0062] Identity authentication request data is obtained, identity authentication records of the campus ID card reader are collected, including card swiping timestamp and user identity identifier, and stored in a database. The database records are called to calculate the time interval between the current identity authentication request and the last access. The identity authentication timestamp format is set as:
[0063] YYYY-MM-DD HH:MM:SS
[0064] And based on the time difference, the time interval is calculated. If the last card swiping time of a user is:
[0065] 2025-02-18 08:00:00
[0066] And the current card swiping time is:
[0067] 2025-02-18 08:05:00
[0068] The time interval is calculated as 5 minutes. Based on the set identity high-frequency access threshold and identity medium-frequency access threshold, the identity high-frequency access threshold is set to 3 minutes, and the identity medium-frequency access threshold is set to 10 minutes.
[0069] The setting is based on the analysis of the historical access distribution of different identity groups in the campus scene. In the card swiping data statistics of a certain teaching building, the frequency of repeated card swiping of faculty and staff in a short period of time is low, while the frequency of continuous card swiping of students in the scene of between classes and laboratories is high. Data statistics show that more than 80% of the groups with continuous card swiping interval less than 3 minutes are students, and their average access interval is distributed between 1.5 minutes and 2.8 minutes. Therefore, 3 minutes is selected as the identity high-frequency access threshold. The setting of the medium-frequency access threshold of 10 minutes is derived from the cross-regional office characteristics of faculty and staff. Data analysis shows that their average card swiping interval is concentrated between 7 and 12 minutes, and 10 minutes is a representative value of this distribution, which is divided into the identity medium-frequency access threshold;
[0070] According to the threshold value, the frequency level of the current access is judged. If the time interval is less than 3 minutes, it is marked as a high-frequency access identity. If the time interval is between 3-10 minutes, it is marked as a medium-frequency access identity. If the time interval is greater than 10 minutes, it is marked as a low-frequency access identity. The classified identity data is stored in the access frequency database, and the identity access frequency classification result is generated.
[0071] The computing load monitoring submodule is based on the identity access frequency classification result, combined with the load monitoring data of the campus edge computing server, and uses the formula:
[0072]
[0073] The computing load adjustment value L is calculated adj , and it is judged whether the computing load adjustment value exceeds the computing resource allocation threshold. The computing load state result is generated, where L cur represents the current load value, F i represents the identity access frequency weight, W i represents the identity type calculation weight, T avg represents the average of the historical access time interval, T cur represents the current identity authentication request timestamp, T prev represents the last identity authentication request timestamp, and n represents the total number of identity types.
[0074] Based on the identity access frequency classification result, the load monitoring data of the campus edge computing server is called, the current load value is calculated, the current CPU utilization of the server is 85%, the memory occupancy rate is 75%, the computing resource allocation threshold is set to 80%, if the CPU or memory utilization exceeds 80%, the computing resource is in a high load state, otherwise it is in a normal load state, the computing consumption of the identity authentication request is calculated, and the computing weight of different frequency identities is set. The weight of high-frequency access identity is set to 2.0, the weight of medium-frequency access identity is set to 1.5, and the weight of low-frequency access identity is set to 1.0.
[0075] The setting of the computing weight is based on the computing resource occupancy of different identity frequencies. Through actual server running data statistics, in the peak time period, the system needs to process 200 authentication requests per second on average, among which the computing resource occupancy proportion of high-frequency identity is between 45%-50%, the occupancy proportion of medium-frequency identity is between 30%-35%, and the occupancy proportion of low-frequency identity is between 15%-20%. Therefore, the computing weight of high-frequency identity is set to 2.0 to reflect the multiple effect of computing resource occupancy, and the computing weight of medium-frequency identity is set to 1.5, and the computing weight of low-frequency identity is set to 1.0 to match the computing resource allocation strategy.
[0076] There are 3 identity requests in a certain time period, which are high-frequency, medium-frequency, and low-frequency identities, respectively, and their computing amount is:
[0077]
[0078] wherein,
[0079]
[0080] T avg = 5 minutes, |T cur - T prev | = 5 minutes, then:
[0081]
[0082] If the calculation load adjustment value L adj If the calculation resource load exceeds the calculation resource allocation threshold 80%, it is determined that the calculation load is too high, and a calculation load state result is generated. The result shows that the current calculation load has exceeded the threshold, and the task priority needs to be adjusted.
[0083] The task priority adjustment submodule is based on the calculation load state result. If the calculation resource load exceeds the calculation resource allocation threshold, the execution priority of the low-frequency access identity request is reduced, the execution priority of the high-frequency access identity request is simultaneously increased, and the identity authentication task priority list is sorted.
[0084] Based on the calculation load state result, if the calculation resource load exceeds the calculation resource allocation threshold, the task priority is adjusted, the execution priority of the low-frequency access identity request is reduced, the execution priority of the high-frequency access identity request is increased, and the identity authentication request is sorted by priority. Assuming that there are currently 5 identity requests, which are high frequency (2), medium frequency (2), and low frequency (1), the priority sorting is as shown in Table 1.1:
[0085]
[0086] According to Table 1.1, the task priority is sorted according to the identity access frequency, and the high-frequency identity request is executed first, followed by the medium-frequency identity request, and finally the low-frequency identity request, generating an identity authentication task priority list.
[0087] Please refer to Figure 3 , the biometric feature matching optimization module includes:
[0088] The high-priority identity authentication data acquisition submodule acquires the biometric feature data corresponding to the high-priority identity authentication request according to the identity authentication task priority list, extracts the biometric feature region information, and obtains the biometric feature basic data set.
[0089] In the campus ID card identity authentication system, some scenarios need to prioritize the authentication request of a specific identity, for example, teachers entering the laboratory, dormitory access control or financial room access authentication. First, the authentication request of the campus ID card is received, and high-priority identity requests are filtered out according to the preset permission rules, for example, the identity verification priority of teachers and administrative staff is higher than that of ordinary students. Then, the biological feature collection device (such as a face recognition camera, a fingerprint identifier or an iris scanner) is called to collect the biological feature data of the current user. Assuming that face recognition is used, the camera captures the front image of the current user and extracts 68 face key point information, including the two-dimensional coordinate information of the eye corner, nose tip and mouth corner, etc. For example, the face key point data of a certain user is as follows:
[0090] Table 2.1: Example of campus face key point coordinates
[0091]
[0092] As shown in Table 2.1, the face key point data is used for subsequent identity matching. Normalization is performed on it to map the feature coordinate values to the [0, 1] interval to eliminate the influence of different camera resolutions and ensure the accuracy of cross-device matching. Finally, a biological feature base data set is generated.
[0093] The historical matching data retrieval submodule retrieves the historical matching data of the target identity based on the biological feature base data set, compares the current biological feature data with the corresponding feature point set in the historical matching data, calculates the matching error of each feature point, and obtains the feature matching error value.
[0094] Based on the biological feature base data set, the system retrieves the historical matching data of the user, for example, the user's campus access control records in the past week, including dormitory door, library, study room identity verification data. The historical matching data is stored in the school server, including the user's biological feature matching template and the feature point coordinates at each authentication time. For example, the face recognition key point data of a certain user on different dates (t1, t2, t3) is stored as matrices M1, M2, M3. The error value between the current matching data and the historical data is calculated. Let the current collected feature point set be P c ={(x i , y i )}, and the historical data be P h ={(x′ i , y′ i )}, the matching error is calculated as follows:
[0095]
[0096] The Euclidean distance E i, measure the matching error, for example, part of the key point error of a user is as follows:
[0097] Table 2.2 Campus identity authentication feature matching error
[0098]
[0099] As shown in Table 2.1, the feature points with larger partial error are affected by light, shooting angle or expression, and this data will be used for subsequent stability analysis.
[0100] The biometric feature stability classification submodule uses the formula:
[0101]
[0102] Calculate the feature variation range S of the ith biometric feature area i , set the biometric feature stability threshold T1 and the medium stability threshold T2, if S i <T1, marked as stable area, if T1≤S i <T2, marked as sub-stable area, if S i ≥T2, marked as unstable area, and the unstable area is denoised to remove abnormal feature points, and the biometric feature area matching result is obtained, wherein N represents the number of samples in the historical matching record of the area, E ij represents the matching error value of the ith biometric feature area in the jth matching record, represents the average value of the matching error value of the ith biometric feature area, w i represents the weight coefficient of the ith biometric feature area.
[0103] According to the feature matching error value, the feature variation range of the biometric feature area in multiple matching records is calculated, and the area is classified according to the set stability threshold T1 and medium stability threshold T2. In the campus identity authentication scene, the stable area (such as the eye corner and nose tip) is usually not affected by expression changes or light, while the unstable area (such as the mouth corner and lower jaw) may be caused by smiling, bowing and other actions. The feature variation range is calculated using the formula.
[0104] In the campus access control system, the eye area is more stable, so w i =0.8, the mouth area is greatly affected by factors such as speaking and smiling, so w i =0.5.
[0105] The setting of the stability threshold T1 and the medium stability threshold T2 is based on the following: first, analyze the biometric feature matching error distribution in different identity authentication scenarios in the campus access control system, extract the matching error data of different user groups (such as teachers, students, and staff) in multiple authentications, select no less than 1000 identity authentication records, compare the mean and standard deviation of the feature matching error, and set the threshold reference standard. In the specific calculation, first calculate the error mean and standard deviation σ of all users E , based on the historical data calculation:
[0106]
[0107] σ E = 1.2
[0108] The threshold T1 is set to , that is:
[0109] T1 = 2.5 - 0.5 x 1.2 = 1.9
[0110] The threshold T2 is set to , that is:
[0111] T2 = 2.5 + 1.25 x 1.2 = 4.0
[0112] This setting ensures that the stability threshold covers the matching error range of most users, while avoiding the influence of abnormal data with large errors on classification accuracy, so that the stable region corresponding to T1 covers feature points with small errors, and the medium stable region corresponding to T2 covers the normal error range of most users, and the region exceeding T2 can be considered as an unstable region.
[0113] The calculation example is as follows: assuming that the matching error value of the mouth corner region of a user is:
[0114] [2.5, 3.0, 3.6, 4.1, 3.2], mean weight w i = 0.5.
[0115] Then:
[0116]
[0117] If S i < T1, the region is marked as a stable region; if T1 ≤ S i < T2, it is marked as a sub-stable region; if S i ≥ T2, it is marked as an unstable region, and the unstable region is subjected to feature denoising processing to eliminate abnormal feature points, and finally the biometric feature region matching result is obtained. The result shows that the stability value S i = 0.228 below threshold T1 = 1.9, thus can be marked as stable region, suitable for long-term identity authentication matching of campus access control system.
[0118] Please refer to Figure 4 , the authentication task priority adjustment submodule includes:
[0119] The task priority analysis submodule analyzes the priority weight of each identity authentication task based on the identity authentication task priority list, extracts the identity information, task type and historical processing record corresponding to the task request, and calculates the task priority adjustment parameter;
[0120] In the campus identity authentication system, the priority of different identity authentication tasks has a direct impact on the allocation of computing resources, therefore, the priority weight of each identity authentication task needs to be analyzed first, the specific process is as follows, first, the system calls the identity authentication task priority list, extracts the identity information, task type and historical processing record of the to-be-processed task, for example, the tasks in a certain university identity authentication system may include faculty laboratory access authentication, student dormitory access authentication, visitor registration audit, etc., the priority of different tasks needs to be determined in combination with the importance of the task and historical data analysis, the system classifies the task type, and calculates the priority adjustment coefficient of the task according to the task execution frequency, average waiting time, authentication failure rate and other factors, for example, for faculty laboratory access, a higher priority is set because it involves scientific research safety, while visitor registration audit is set to a lower priority because the demand is relatively small, in order to quantify the priority adjustment coefficient, the task weight calculation formula is set as follows:
[0121] Q i = αFz i + βTp i + γEs i
[0122] Wherein, Fz i represents the execution frequency of task i, Tp i represents the average waiting time of the task, Es i represents the authentication failure rate of the task, α, β, γ are weight coefficients, according to the historical data statistics of the campus identity authentication system, the weight coefficients are set as α = 0.4, β = 0.3, γ = 0.3, the execution frequency of a certain laboratory access authentication task is 50 times per day, the average waiting time is 2.5 seconds, and the authentication failure rate is 5%, then the task weight is calculated as follows:
[0123] Q lab = 0.4 × 50 + 0.3 × 2.5 + 0.3 × 5 = 20 + 0.75 + 1.5 = 22.25
[0124] Similarly, assuming that the execution frequency of the visitor registration task is 10 times per day, the average waiting time is 6 seconds, and the authentication failure rate is 15%, the task weight is calculated as follows:
[0125] Q visitor = 0.4 x 10 + 0.3 x 6 + 0.3 x 15 = 4 + 1.8 + 4.5 = 10.3
[0126] As the calculation shows, the priority of the laboratory access authentication task is significantly higher than that of the visitor registration task, and the system uses this priority weight for subsequent calculation resource allocation to obtain the task priority adjustment parameter.
[0127] Based on the task priority adjustment parameter, the calculation resource allocation submodule calculates the calculation resource allocation proportion of the identity authentication task. If the task priority is high, the calculation resource allocation proportion is increased, and if the task priority is low, the calculation resource allocation proportion is reduced. The formula is as follows:
[0128]
[0129] The calculation resource allocation amount R i of the i-th task is calculated, and a calculation resource allocation matrix is constructed, where Q i represents the i-th task priority adjustment parameter, R represents the total amount of calculation resources, K represents the total number of tasks, T h represents the historical average processing time of the i-th task, represents the average processing time of all tasks, and C represents the calculation resource adjustment coefficient.
[0130] Based on the task priority adjustment parameter, the calculation resource allocation proportion of the identity authentication task is calculated, and the total amount of calculation resources R is set to 100 (unit: CPU computing unit). The resource allocation amount R i of each task is calculated. If the task priority is high, the calculation resource allocation proportion is increased, and if the task priority is low, the calculation resource allocation proportion is reduced. The specific calculation is as follows: assuming that there are K = 3 tasks to be processed, which are laboratory access authentication, student dormitory access authentication, and visitor registration, the resource allocation amount of each task is calculated.
[0131] Set C = 2, and set the following: in the campus identity authentication system, the processing time of different tasks has certain volatility, and the dynamic allocation of calculation resources needs to consider the stability of task execution and the balance of calculation load. In order to ensure the rationality of calculation resource allocation, appropriate resource compensation or reduction needs to be made for tasks whose processing time deviates from the overall mean. The value of C should be able to balance the deviation of task execution time, while avoiding excessive resource fluctuation affecting task scheduling. In the process of setting C, first, the historical processing time distribution of various tasks in the campus identity authentication system is counted, and the standard deviation σT Based on the task execution frequency and the calculation resource occupation, the standard deviation of the task processing time is usually between 1.5-2.5 seconds after data analysis. If the value of C is too small, the dynamic adjustment range of the calculation resource is insufficient, and it is difficult to effectively compensate for the tasks with large calculation resource requirements. If the value of C is too large, it will lead to excessive tilt of the calculation resource, affecting the balance of the overall calculation load. Considering the stability of the allocation of calculation resources and the fluctuation range of the processing time of different tasks, C = 2 is finally set. This value can appropriately adjust the allocation of calculation resources, so that the increase and decrease range of resources is in a reasonable interval, thereby ensuring the balance of task scheduling and the stability of system calculation efficiency.
[0132] The priority weights of the tasks are as follows:
[0133] Laboratory access authentication: Q1 = 22.25
[0134] Dormitory access authentication: Q2 = 15.8
[0135] Visitor registration authentication: Q3 = 10.3
[0136] First, calculate the total weight:
[0137]
[0138] Then, calculate the initial allocation of resources:
[0139]
[0140] Set the historical average processing time T h1 = 2.5 seconds, T h2 = 3.0 seconds, T h3 = 6.0 seconds, calculate the average processing time of all tasks:
[0141]
[0142] Calculate the adjustment amount of the calculation resource:
[0143]
[0144] Final calculation resource allocation:
[0145] R1 = 46.0 + 2.31 = 48.31
[0146] R2 = 32.7 + 1.82 = 34.52
[0147] R3 = 21.3 + 2.94 = 24.24
[0148] As shown in Table 3.1, the dynamic adjustment of the calculation resource effectively allocates the calculation units, and finally obtains the calculation resource allocation matrix.
[0149] Table 3.1. Computing resource allocation matrix
[0150]
[0151] As shown in Table 3.1, the laboratory access authentication task has the highest priority and the largest proportion of computing resources, while the visitor registration authentication task has relatively low computing requirements and a relatively reduced allocation of computing resources. The computing resource allocation matrix is constructed.
[0152] The identity authentication task computing sequence generation submodule sorts the identity authentication tasks according to the task priority and the computing resource allocation amount based on the computing resource allocation matrix, adjusts the task execution order, eliminates tasks with a computing resource allocation amount below the threshold, and obtains the identity authentication task computing sequence.
[0153] According to the computing resource allocation matrix, the system sorts the identity authentication tasks according to the task priority and the computing resource allocation amount, adjusts the task execution order, eliminates tasks with a computing resource allocation amount below the threshold, and assumes that the minimum computing resource allocation threshold R min = 20.0.
[0154] The following settings are made: In the campus identity authentication system, each identity authentication task needs to occupy a certain amount of computing resources to ensure the normal execution of the task. If the computing resource allocation is too low, it may lead to a long task execution time, affecting the efficiency of identity authentication, or even causing the task to fail. Therefore, the system needs to set a reasonable minimum computing resource allocation threshold to ensure that all tasks can at least obtain basic computing power.
[0155] When R min is set, the computing resource requirements of different types of identity authentication tasks are first analyzed, such as laboratory access authentication, dormitory access authentication, and visitor registration authentication. The laboratory access authentication task generally involves high-security level identity verification and requires higher computing resources, usually allocated between 30-40 units; the dormitory access authentication task involves a large number of students and has moderate computing resource requirements, usually between 20-30 units; and the visitor registration authentication task has the lowest computing requirements, usually allocated between 10-20 units.
[0156] To ensure the rationality of task scheduling, the system counts the computing resource requirements of each task and calculates the average computing resource allocation required for each task. It also takes into account the standard deviation of task execution to measure the fluctuation of task computing resources. The system found that the average computing resource requirement for identity authentication tasks was approximately 28.0 units, while the standard deviation of task computing resource requirements was approximately 8.0 units. To prevent task failures due to insufficient computing resources while not excessively raising the minimum computing resource threshold, the system uses the average computing resource value minus the standard deviation to set the minimum computing resource allocation threshold, which is 20.
[0157] The system checks the computing resource allocation for each task. As shown in Table 1, all tasks meet the minimum computing resource allocation requirements, so there is no need to eliminate tasks. The task execution order is sorted by computing resource allocation as follows:
[0158] Laboratory access control certification (48.31)
[0159] Dormitory access control authentication (34.52)
[0160] Visitor registration and authentication (24.24)
[0161] Finally, an authentication task calculation sequence is generated, which is used for scheduling actual authentication tasks to ensure reasonable allocation of computing resources and improve task execution efficiency.
[0162] See also Figure 5 , the distributed matching calculation module includes:
[0163] The task computing allocation submodule extracts the computing priority of the task based on the identity authentication task computing sequence, allocates tasks to the campus edge computing nodes according to the task computing priority, calculates the task load ratio of each computing node, sets the task allocation parameters, calls the task allocation parameters to adjust the computing tasks of the edge computing nodes, and generates the task allocation ratio of the computing nodes;
[0164] In the campus ID card identity authentication system, the identity authentication tasks of each day come from multiple different scenarios, including campus access, library borrowing, canteen payment, and laboratory access, and the identity authentication task calculation requirements in different scenarios are different. For example, the access authentication task requires high real-time performance, while the library borrowing authentication task has relatively low time efficiency requirements, so it is necessary to set the calculation priority for identity authentication tasks in different scenarios, such as setting the priority of access to 3, setting the priority of laboratory access to 2, setting the priority of library borrowing to 1, and setting the priority of canteen payment to 2. According to the calculation priority, the task allocation ratio is adjusted, and the calculation node task allocation ratio is set. Assuming that the campus edge computing network contains 5 calculation nodes, the calculation capabilities of each node are 10, 8, 6, 5, and 4 units respectively, the task allocation ratio is determined by calculating the proportion of the calculation capabilities of each node:
[0165] The current calculation node capability data is as follows:
[0166] Table 4.1 Calculation node calculation capability table
[0167]
[0168] According to the above data, the task allocation ratio is calculated as follows:
[0169]
[0170] According to the calculation result, the tasks are allocated to different calculation nodes in proportion to ensure that the identity authentication tasks are reasonably allocated in the campus edge computing environment, and finally the calculation node task allocation ratio is obtained.
[0171] The calculation parameter optimization submodule adjusts the matching calculation parameters based on the calculation node task allocation ratio and the biological feature region matching result, analyzes the adaptability of each calculation node in matching calculation, and adjusts the matching calculation parameters. The matching parameter adjustment ratio is set, and the formula is as follows:
[0172]
[0173] The matching calculation adjustment parameter P' of each calculation node is calculated ij , and the updated matching calculation parameter is obtained, wherein P ij represents the initial matching calculation parameter, M ik represents the matching adaptability of the calculation node i to the feature region k, B k represents the reference matching value of the feature region k, L represents the total number of matching regions, and a represents the matching parameter adjustment coefficient.
[0174] Based on the proportion of task allocation of the computing node, the historical matching calculation data of each computing node is called, and the key biometric feature matching parameters in the campus ID card authentication process are extracted, including face recognition similarity, fingerprint matching rate, identity information consistency, etc. Assuming that the historical matching data of a certain computing node in a certain time period has an average face recognition similarity of 0.87, an average fingerprint matching rate of 0.75, and an average identity information consistency of 0.81, set it as the reference matching value:
[0175] B k =[0.87, 0.75, 0.81]
[0176] Assuming that the feature matching data of computing node 2 is:
[0177] M 2k =[0.84, 0.73, 0.79]
[0178] a represents the matching calculation adjustment coefficient, which is set according to the matching deviation amplitude of the computing node. The matching deviation amplitude is defined as the average error size between the computing node in the feature matching process and the reference matching value. If the error amplitude is large, the matching calculation adjustment coefficient should be appropriately increased to enlarge the adjustment amplitude. If the error amplitude is small, the matching calculation adjustment coefficient should be small to ensure that the matching parameters will not be overcorrected. The matching deviation amplitude is calculated as follows:
[0179]
[0180] Substitute the data to calculate:
[0181]
[0182] The matching calculation adjustment coefficient a is set as the correction coefficient of the error amplitude. According to the feature matching data of the campus ID card identity authentication system, the experience interval is [1.05, 1.15]. When the matching deviation amplitude δ i is less than 0.02, set a = 1.05. When the matching deviation amplitude δ i is greater than 0.03, set a = 1.15. When 0.02 ≤ δ i ≤ 0.03, use linear interpolation to calculate a, and the calculation method is as follows:
[0183]
[0184] Substitute the data:
[0185]
[0186] Calculate the adjusted matching calculation parameters:
[0187] P′ 2j =P2j x (1 + 0.0233) 1.083
[0188] Assume the initial matching calculation parameter P of the computing node 2 is 0.85 2j = 0.85, then:
[0189] P' 2j = 0.85 x (1 + 0.0233) 1.083
[0190] P' 2j ≈ 0.85 x 1.0256 = 0.8718
[0191] The matching calculation parameter of the computing node is updated, the calculation configuration of the identity authentication task is optimized, and the adjusted matching calculation parameter P' is finally obtained 2j = 0.8718.
[0192] The matching confidence of each computing node is calculated according to the adjusted matching calculation parameter, the identity matching confidence weight is calculated according to the matching confidence of each node, the matching confidence weight distribution ratio is adjusted, and the identity matching confidence calculation result is generated;
[0193] According to the adjusted matching calculation parameter, the matching confidence of each computing node in the campus ID card identity authentication task is calculated, the matching confidence measures the matching degree of the computing node to the current identity authentication task, for example, the adjusted matching calculation parameter calculation value of the computing node 2 is P' 2j = 0.8718, the matching confidence is calculated
[0194] The adjusted matching calculation parameter of the computing node is as follows:
[0195] Table 4.2 Adjusted matching calculation parameter table of computing node
[0196]
[0197]
[0198] The matching confidence is calculated:
[0199]
[0200] The matching confidence indicates the matching reliability of the computing node in the campus ID card identity authentication task, wherein the matching confidence of the computing node 1 is the highest, which is 0.2156, and the matching confidence of the computing node 5 is the lowest, which is 0.1810. According to the calculation result, the matching confidence is taken as the identity matching confidence weight distribution basis, the matching confidence weight distribution ratio is adjusted, and the identity matching confidence calculation result is finally generated.
[0201] Please refer to Figure 6 , the matching result decision module comprises:
[0202] The confidence threshold determination sub-module obtains the matching confidence data of each computing node based on the identity matching confidence calculation result, sets an identity matching confidence threshold, calls the identity matching confidence threshold and the matching confidence of each computing node for comparison, judges whether the matching confidence of each computing node exceeds the identity matching confidence threshold, screens the computing nodes whose matching confidence does not reach the threshold, and generates a matching confidence determination result.
[0203] Based on the identity matching confidence calculation result, first, the matching confidence data of each computing node is obtained. The matching confidence reflects the matching confidence degree of the computing node to the input identity data. For example, in a system comprising five computing nodes, the matching confidence of each node may be 0.82, 0.76, 0.91, 0.67 and 0.88 respectively. Then, the identity matching confidence threshold is set. The identity matching confidence threshold is usually determined by the security level of the system. If the system requires high security, the threshold can be set to 0.80. If the security requirement is moderate, the threshold can be set to 0.70. In this embodiment, the identity matching confidence threshold is set to 0.75. Subsequently, the identity matching confidence threshold is called for comparison with the matching confidence of each computing node. The matching confidence of the five computing nodes is compared one by one. It is found that the matching confidence 0.67 of the fourth computing node is lower than the threshold 0.75, and the matching confidence of the remaining computing nodes is higher than the threshold. Therefore, the computing node whose matching confidence does not reach the threshold, i.e., node 4, is screened out, and its matching confidence value is recorded. Finally, the matching confidence determination result is generated.
[0204] The matching result re-evaluation sub-module screens the computing nodes whose matching confidence does not reach the threshold according to the matching confidence determination result, re-evaluates the matching confidence of the computing nodes, adjusts the matching confidence according to the matching task amount, computing load and computing error of the computing node, sets an adjustment ratio, and uses the formula:
[0205]
[0206] The new matching confidence Z' is calculated i , and the adjusted matching confidence is updated, wherein Z i represents the initial matching confidence, J ij represents the computing error of the computing node i in the matching task j, Y ij represents the allowed error of the computing task j, and X represents the total number of computing tasks.
[0207] Based on the matching confidence judgment result, the computing nodes whose matching confidence does not reach the threshold are filtered. In this example, only node 4 does not reach the threshold, so node 4 is re-evaluated. The matching task volume, computing load and computing error of the computing node are considered during the evaluation. The current computing task volume of node 4 is 30 matching tasks, accounting for 25% of the total number of tasks, and the computing load is 75%. The computing error reflects the deviation that may occur in the node during the matching process. The computing error can be measured by the mean error of the matching data. Assuming that the mean error of node 4 in 30 matching tasks is 0.08, and the allowable error is set to 0.05, the computing error exceeds the allowable error range. Based on these data, the formula is used for calculation:
[0208]
[0209] The adjusted matching confidence is 0.70, and the matching confidence data of the computing node is updated to obtain the adjusted matching confidence.
[0210] The identity matching determination submodule determines whether the matching confidence of all computing nodes exceeds the identity matching confidence threshold based on the adjusted matching confidence. If all matching confidences exceed the threshold, the identity matching is marked as successful. If the matching confidence of some computing nodes is still lower than the threshold, the identity matching result is re-evaluated based on the matching confidence of all computing nodes to generate the identity authentication matching determination result.
[0211] Based on the adjusted match confidence, the system determines whether the match confidence of all computing nodes exceeds the identity match confidence threshold. In this example, the match confidence of node 4 is 0.70 after adjustment, which is still lower than the identity match confidence threshold of 0.75. Therefore, some computing nodes still have match confidences below the threshold. In this case, the system re-evaluates the identity match result based on the match confidence of all computing nodes and calculates the average match confidence of all computing nodes:
[0212]
[0213] The mean match confidence value is 0.814, which is higher than the identity match confidence threshold of 0.75. Therefore, the identity match is determined to be successful, and an identity authentication match determination result is generated.
[0214] Table 5.1 Computing node matching confidence
[0215]
[0216] As shown in Table 5.1, the average matching confidence of all computing nodes reaches 0.814, which exceeds the identity matching confidence threshold of 0.75. Therefore, the identity matching is judged to be successful and the identity authentication matching judgment result is generated.
[0217] The above merely describes the preferred embodiments of the present application, and is not intended to limit the present application in other forms. Any skilled person in the art can modify or change the disclosed technical content into equivalent embodiments with equivalent changes, and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present application, without departing from the technical solution content of the present application, still falls within the protection scope of the present application.
Claims
1. Campus ID card multi-scenario identity authentication system based on edge computing, characterized by: The system comprises: The authentication request scheduling module obtains authentication request data, extracts timestamps, calculates the time interval between the current authentication request and the last access, classifies the authentication access type according to the access frequency threshold, simultaneously determines the computing resource load status, adjusts the authentication task execution priority, and generates an authentication task priority list; The biometric matching optimization module obtains biometric data according to the identity authentication task priority list, calculates the biometric region change amplitude, classifies the region stability according to the feature change threshold, and generates a biometric region matching result; The authentication task priority adjustment submodule adjusts the computing resource allocation ratio of the campus edge computing server task queue based on the identity authentication task priority list and generates an identity authentication task calculation sequence; The distributed matching calculation module adjusts the task allocation ratio of the computing nodes based on the identity authentication task calculation sequence, calculates the matching confidence in combination with the biometric feature area matching weight, and generates an identity matching confidence calculation result; The matching result decision module calculates the identity matching confidence result according to the identity matching confidence. If the matching confidence of all computing nodes is higher than the identity matching confidence threshold, it determines that the match is successful and generates an identity authentication matching determination result. The identity authentication request scheduling module includes: The identity authentication classification submodule obtains identity authentication request data through the campus ID card reader, extracts the timestamp of the identity authentication request, calculates the time interval between the current identity authentication request and the last access, and compares the identity high-frequency access threshold with the identity medium-frequency access threshold for classification. If the time interval is less than the identity high-frequency access threshold, it is marked as a high-frequency access identity. If the time interval is between the identity high-frequency access threshold and the identity medium-frequency access threshold, it is marked as a medium-frequency access identity. If the time interval is greater than the identity medium-frequency access threshold, it is marked as a low-frequency access identity, and the identity access frequency classification result is generated; The computing load monitoring submodule uses the formula based on the identity access frequency classification results and the load monitoring data of the campus edge computing server: ; Calculate the load adjustment value , determine whether the calculation load adjustment value exceeds the calculation resource allocation threshold, and generate a calculation load status result, where, Represents the current load value, Represents the identity access frequency weight, Represents the identity type to calculate the weight, represents the mean of the historical access time interval, Represents the timestamp of the current authentication request. Represents the timestamp of the last authentication request. The total number of representative identity types; The task priority adjustment submodule is based on the computing load status result. If the computing resource load exceeds the computing resource allocation threshold, the execution priority of low-frequency access identity requests is lowered, and the execution priority of high-frequency access identity requests is increased simultaneously, and the identity authentication task priority list is generated in order.
2. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The identity authentication task priority list includes high-frequency access identities, medium-frequency access identities, and low-frequency access identities; the biometric feature area matching results include stable areas, sub-stable areas, and unstable areas; the identity authentication task calculation sequence includes the computing resource allocation ratio and the task calculation priority; the identity matching confidence calculation result includes the matching confidence calculation value and the computing node matching parameters; the identity authentication matching judgment result includes the identity matching success record, the identity matching failure record, and the identity matching re-evaluation result.
3. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The biometric matching optimization module includes: The high-priority identity authentication data collection submodule collects biometric data corresponding to the high-priority identity authentication request according to the identity authentication task priority list, extracts biometric area information, and obtains a biometric basic data set; The historical matching data retrieval submodule retrieves the historical matching data of the target identity based on the biometric basic data set, compares the current biometric data with the corresponding feature point set in the historical matching data, calculates the matching error of each feature point, and obtains the feature matching error value; The biometric stability classification submodule uses the formula: ; Calculate the The characteristic variation range of the biometric area , set the biometric stability threshold and medium stability threshold ,like , marked as a stable region, if , marked as the substable region, if , marked as unstable areas, and feature denoising is performed on the unstable areas to remove abnormal feature points and obtain the biometric region matching results, where Represents the number of samples in the historical matching records of this area, Representative The biometric area in The matching error value in the matching records, Representative The average value of the matching error of the biometric regions, Representative The weight coefficient of each biometric region.
4. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The authentication task priority adjustment submodule includes: The task priority parsing submodule parses the priority weight of each identity authentication task based on the identity authentication task priority list, extracts the identity information, task type and historical processing records corresponding to the task request, and calculates the task priority adjustment parameter; The computing resource allocation submodule adjusts the parameters based on the task priority, calculates the computing resource allocation ratio of the identity authentication task, sets the total amount of computing resources, and increases the computing resource allocation ratio if the task priority is high, and decreases the computing resource allocation ratio if the task priority is low, using the formula: ; Calculate the Computing resource allocation for each task , construct the computing resource allocation matrix, where Representative Task priority adjustment parameters, Represents the total amount of computing resources, Represents the total number of tasks, Representative The historical average processing time of tasks, represents the average processing time of all tasks, Represents the computing resource adjustment coefficient; The identity authentication task calculation sequence generation submodule sorts the identity authentication tasks according to the computing resource allocation matrix, task priority and computing resource allocation amount, adjusts the task execution order, eliminates tasks with computing resource allocation amounts below a threshold, and obtains the identity authentication task calculation sequence.
5. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The distributed matching calculation module includes: The task calculation allocation submodule extracts the calculation priority of the task based on the identity authentication task calculation sequence, allocates tasks to the campus edge computing nodes according to the task calculation priority, calculates the task load ratio of each computing node, sets the task allocation parameters, calls the task allocation parameters to adjust the computing tasks of the edge computing nodes, and generates the task allocation ratio of the computing nodes; The calculation parameter optimization submodule analyzes the adaptability of each calculation node in the matching calculation based on the task allocation ratio of the calculation node and the matching results of the biometric feature area, adjusts the matching calculation parameters, and sets the matching parameter adjustment ratio using the formula: ; Calculate the matching calculation adjustment parameters for each computing node , update to obtain the adjusted matching calculation parameters, where Represents the initial matching calculation parameters, Represents a compute node For feature areas The matching adaptability of Representative feature areas The benchmark matching value, Represents the total number of matching regions, Represents the matching parameter adjustment coefficient; The matching confidence calculation submodule calculates the matching confidence of each computing node according to the adjusted matching calculation parameters, calculates the identity matching confidence weight based on the matching confidence of each node, adjusts the matching confidence weight distribution ratio, and generates the identity matching confidence calculation result.
6. The campus ID card multi-scenario identity authentication system based on edge computing according to claim 1 is characterized in that: The matching result decision module includes: The confidence threshold determination submodule obtains the matching confidence data of each computing node based on the identity matching confidence calculation result, sets the identity matching confidence threshold, calls the matching confidence threshold and compares it with the matching confidence of each computing node, determines whether the matching confidence of each computing node exceeds the identity matching confidence threshold, filters out computing nodes whose matching confidence does not reach the threshold, and generates a matching confidence determination result; The matching result re-evaluation submodule selects computing nodes whose matching confidence does not reach the threshold according to the matching confidence judgment result, re-evaluates their matching confidence, adjusts the matching confidence according to the matching task volume, computing load and computing error of the computing node, and sets the adjustment ratio using the formula: ; Calculate new matching confidence , update to get the adjusted matching confidence, where represents the initial matching confidence, Represents a compute node In matching tasks The calculation error in Represents a computing task The allowable error, Represents the total number of computing tasks; The identity matching determination submodule determines whether the matching confidence of all computing nodes exceeds the identity matching confidence threshold based on the adjusted matching confidence. If all matching confidences exceed the threshold, the identity matching is marked as successful. If there are still some computing nodes whose matching confidences are lower than the threshold, the identity matching result is re-evaluated based on the matching confidences of all computing nodes to generate an identity authentication matching determination result.
Citation Information
Patent Citations
Face feature base library management method, controller and system
CN114155583A
Real-time object recognition system and method based on GPU acceleration
CN118781547A