Cloud face authentication method and device based on RNS-CKKS encryption and cosine similarity, and storage medium

By adopting RNS-CKKS encryption and cosine similarity calculation in cloud face authentication, combined with differential privacy and Plonk protocol, the problem of secure storage and transmission of face feature template libraries in cloud environments is solved, and the recognition accuracy and privacy protection capabilities are improved.

CN120200800APending Publication Date: 2025-06-24JIANGSU UNIV
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510342002.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing facial recognition technology has problems with the secure storage and transmission of face feature template libraries in the cloud environment, and the calculation efficiency is low and the calculation complexity is high, especially in high-dimensional feature vector calculation.

Method used

The cloud face authentication method based on RNS-CKKS encryption and cosine similarity is adopted, and differential privacy noise injection and Hadamama product calculation are performed through the client, the features are homomorphically encrypted using the RNS-CKKS scheme, and the cosine similarity is calculated in the cloud server, and the Plonk protocol is used to ensure the correctness of the calculation results.

Benefits of technology

It improves the accuracy of facial recognition, effectively prevents user information leakage, enhances the system's privacy protection capabilities and computing efficiency, and is particularly suitable for encrypted computing of high-dimensional data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200800A_ABST
    Figure CN120200800A_ABST
Patent Text Reader

Abstract

The invention discloses a cloud face authentication method and device based on RNS-CKKS encryption and cosine similarity and a storage medium. A user initiates an authentication request, a client obtains and preprocesses a face image, extracts a feature vector and performs modular length normalization; the cloud server generates a random number and sends the random number to the client, and the client adds noise to a feature value by adopting a differential privacy technology, carries out Hadamard product operation, carries out homomorphic encryption on the feature by using an RNS-CKKS scheme and sends a ciphertext to the cloud server; the cloud server receives the ciphertext, encrypts the face feature template by using an RNS-CKKS scheme, calculates cosine similarity, ensures the correctness of a calculation result by using a Plonk protocol, and transmits a similarity ciphertext back to the client; and the client decrypts the similarity ciphertext and compares the similarity ciphertext with a set threshold value to obtain a user identity authentication result. According to the scheme, by combining differential privacy, zero-knowledge proof and homomorphic encryption technologies, privacy protection is enhanced, the recognition accuracy is improved, and user information leakage is effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of face recognition, and in particular to a cloud-based face authentication method, device and storage medium based on RNS-CKKS encryption and cosine similarity. Background Art

[0002] With the rapid development of information technology, face recognition technology has become an important means in the field of identity authentication and security monitoring. This technology has promoted the innovation and development of many industries with its convenience, efficiency and security. However, face recognition technology faces major challenges in processing personal privacy data. Especially in the cloud environment, the secure storage and transmission of the face feature template library has become a prominent issue. Traditional face recognition methods usually rely on storing the user's face feature template in the cloud server. These feature data are usually stored in plain text or encrypted form, and there is a risk of being stolen, leaked or abused. In order to solve this problem, homomorphic encryption technology came into being. It can directly operate on the ciphertext to avoid the risk of user data exposure. However, the existing homomorphic encryption methods generally have the problems of low computational efficiency and high computational complexity, especially in the calculation of high-dimensional feature vectors. This defect is more prominent. In addition, the face feature value is usually high-dimensional data. The traditional Euclidean distance measurement method is affected by the data scale. When processing face data with different angles, illumination changes or facial expression changes, the recognition accuracy and robustness have certain limitations. In order to solve the above problems, it is necessary to provide a new encryption method. Summary of the invention

[0003] The purpose of the present invention is to provide a cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity, which can effectively prevent user information leakage while improving the accuracy of face recognition.

[0004] To achieve the above object, the present invention provides the following technical solution: a cloud-based face recognition method based on RNS-CKKS encryption and cosine similarity, comprising the following steps:

[0005] Step 1: The user initiates an authentication request on the client, and the client obtains and preprocesses the face image, extracts the feature vector and performs modulus normalization;

[0006] Step 2: The cloud server generates a random number and sends it to the client. The client uses differential privacy technology to add noise to the feature value, uses the Plonk protocol to ensure the correctness of the noise addition result, performs Hadamard product operation, uses the RNS-CKKS scheme to homomorphically encrypt the feature and sends the ciphertext to the cloud server.

[0007] Step 3: The cloud server receives the ciphertext, encrypts the face feature template, calculates the cosine similarity, uses the Plonk protocol to ensure the correctness of the cosine similarity calculation, and sends the similarity ciphertext back to the client.

[0008] Step 4: The client decrypts the similarity ciphertext, compares it with the set threshold, and completes the identity authentication.

[0009] Furthermore, Step 1 specifically includes the following steps:

[0010] (1) The client uses the camera to obtain a face image and adjusts the image through geometric transformation.

[0011] (2) Eliminate random interference in the image and remove noise.

[0012] (3) Perform face detection and locate the position of the face in the image.

[0013] (4) Adjust the format of the image data to meet the input requirements of the model, extract the face feature value F, normalize it, and store it.

[0014] Furthermore, in Step 2, the differential privacy noise injection process is executed by the client. By adding Laplace noise to the face feature value, it prevents malicious users from stealing the original feature value through reverse engineering or replay attacks, enhancing the privacy protection ability of the system. The standard deviation of the noise is jointly determined by the privacy budget epsilon and the failure probability delta. The privacy budget epsilon controls the intensity of the noise, and the failure probability delta controls the failure probability of differential privacy. The generated noise vector has the same dimension as the face feature value, and each noise value comes from the Laplace distribution.

[0015] Furthermore, in Step 2, the differential privacy noise injection process includes the following steps:

[0016] (1) Select differential privacy parameters. The privacy budget ∈ selects the default value of 1.0, and the failure probability δ selects the default value of 1e -5 ;

[0017] (2) Generate noise values for each element of the feature value using the Laplace distribution. The Laplace noise probability density function P(x) is:

[0018]

[0019] where x represents the noise value, μ is the mean of the Laplace distribution, set to 0, indicating that the probability density function is symmetric around 0, and b is the scale parameter, controlling the distribution range of the noise, calculated from the privacy budget ∈ and the sensitivity Δ:

[0020]

[0021] Generate a random number \(u\) uniformly distributed between \([0, 1]\), and convert \(u\) into noise \(noise\) that conforms to the Laplace distribution through the inverse transformation method:

[0022] \(noise=-b\cdot sgn(u - 0.5)\cdot\ln(1 - 2|u - 0.5|)\)

[0023] \(u - 0.5\) maps the random number \(u\) from \([0, 1]\) to \([-0.5, 0.5]\), ensuring the symmetry of the noise value distribution. \(sgn(u - 0.5)\) is the sign function, ensuring that the sign of the noise value is random and symmetric. \(\ln(1 - 2|u - 0.5|)\) transforms the uniformly distributed random number, making the generated noise conform to the Laplace distribution characteristics. Each eigenvalue element generates an independent Laplace distribution noise value to obtain the noise value vector \(N\);

[0024] (3) Add the corresponding noise value to each eigenvalue to disrupt the original data and obtain the noisy face eigenvalue \(F\) N ;

[0025] Furthermore, in step 2, the random number vector \(R\) is generated by the cloud server and passed to the client for use, preventing malicious users on the client from forging the authentication process, further confusing the eigenvalues, preventing replay attacks, and reducing the risk of the system being attacked; this random number vector has the same dimension as the noisy face eigenvalue, and each element is a floating-point number between \([0, 1]\). Perform the Hadamard product calculation on the noisy face eigenvalue vector and the random number vector:

[0026] \(V = F\) N \(\odot R\)

[0027] For the vector \(V\) obtained by the Hadamard product operation, each element is obtained by multiplying the corresponding elements in the noisy face eigenvalue \(F\) N and the random number vector \(R\);

[0028] Furthermore, in step 2, the specific steps to ensure the correctness of the noise addition result using the Plonk protocol include:

[0029] (1) After the client performs the noise addition operation, use the Plonk protocol to initialize the proof generator, generate a zero-knowledge proof about the noise addition step, and send the noisy data and the zero-knowledge proof to the cloud server for verification;

[0030] (2) After receiving the noisy data, the cloud server uses the Plonk protocol to initialize the proof verifier, verify the generated zero-knowledge proof, ensure that the client has correctly performed the noise addition operation, and verify the correctness of the calculation;

[0031] Furthermore, in step 3, the proof generation steps of the Plonk protocol include:

[0032] (1) Convert the calculation process into constraints, and use the polynomial a(X) to represent the constraints of the noise addition operation:

[0033] a(X) = F·N - F N

[0034] where F is the initial face feature vector, N is the noise vector, and F N is the noisy face feature vector. If the polynomial a(X) holds, it proves that the noise addition process is correct and prevents the generation of incorrect noise;

[0035] (2) Prove that the generation process has three main stages: the commitment stage, the challenge stage, and the response stage; in the commitment stage, the client generates a commitment value according to the polynomial a(X) constructed in the first stage. In the challenge stage, a random challenge factor α is generated through the Fiat-Shamir challenge mechanism. In the response stage, the challenge factor is used to calculate the zero-knowledge proof:

[0036] ∏1 = {a(α), z1(α)}

[0037] ∏1 is the zero-knowledge proof set of the client's noise addition operation. a(α) is the commitment value of the client's noise addition operation, and z1(α) is the response value of the client's noise addition operation, based on the challenge factor α;

[0038] (3) The cloud server uses the elliptic curve pairing technology to verify whether the equation holds, pairs the commitment value generated by the client with the calculation result, checks whether the calculation process meets the predetermined constraints, and confirms whether the noise addition result provided by the client is correct;

[0039] Furthermore, in step 2, the client uses the RNS-CKKS fully homomorphic encryption algorithm to encrypt the face feature values after the Hadamard product operation to generate face feature value ciphertext. The specific steps and their optimization operations include:

[0040] (1) The client initializes the encryption system, generates RNS-CKKS encryption parameters, and selects a polynomial ring:

[0041]

[0042] R q is the polynomial ring under the modulus q, where q is an element in the modulus chain, Z[X] is the polynomial ring over integers, where Z is the set of integers and X is the symbol used to represent the polynomial variable in the polynomial ring, and N is a power of 2;

[0043] (2) Adopt a segmented encoding method to divide the feature vector v = [v1, v2,..., v n after the Hadamard product into k sub-vectors v1, v2,..., v k, according to the precision requirements of the face feature vector, dynamically adjust the scaling factor S and the modulus chain length L for each sub-vector to generate a modulus chain, and simultaneously generate a set of keys such as a private key, a public key, and a relinearization key;

[0044] Select the scaling factor for each sub-vector by the adaptive scaling method, that is, calculate the maximum value of each segment of the sub-vector, and use the logarithmic function to estimate the scaling factor S:

[0045]

[0046] where max_value is the maximum value of the sub-vector, take the larger value between 40 and the ceiling of log2(max_value) to ensure that the scaling factor is at least 2 40 , when the maximum value of the sub-vector exceeds 2 40 , the scaling factor will increase accordingly to ensure sufficient numerical precision in subsequent calculations;

[0047] Synchronously adjust the modulus chain length L according to the scaling factor S:

[0048]

[0049] Take the larger value between 4 and the ceiling of log2(S) to ensure that the modulus chain length L is at least 4, balance the calculation efficiency and the ciphertext security, and control the noise growth;

[0050] Map the sub-vector to the polynomial m(x), and the coefficients of m(x) are the elements x0, x1, x2, …, x n , where n is the number of elements of the sub-vector and also serves as the highest degree of the polynomial:

[0051] m(x) = x0 + x1x + x2x 2 + … + x n x n

[0052] Perform residue numbering. For the moduli p1, p2, p3, …, p k in the modulus chain, where k is the number of moduli in the modulus chain, take the modulus of each coefficient of m(x) with the moduli respectively. Each element of the sub-vector will be mapped to different moduli to obtain residues:

[0053]

[0054] where, is the residue of the coefficient x i under the modulus p j , x i is the coefficient in the polynomial m(x), i is the index starting from 0 to n ending, and n is the number of elements of the sub-vector, pj is the j-th modulus in the modulus chain, where j ranges from 1 to k;

[0055] For each modulus, generate a polynomial:

[0056]

[0057] where m j (x) is the polynomial corresponding to the j-th modulus chain, a total of k polynomials are generated, where j ranges from 1 to k, and i is an index ranging from 0 to n, and n is the number of elements in the sub-vector;

[0058] (3) Use the public key to encrypt each polynomial m j (x), encrypt it into a ciphertext in RNS-CKKS format, and send the ciphertext C generated by the encryption, along with the public key and encryption parameters, to the cloud server for subsequent calculations;

[0059] Furthermore, in step 3, the cloud server receives the ciphertext transmitted by the client and its related encryption parameters, constructs a homomorphic encryption framework using the RNS-CKKS scheme, performs segmented encoding and encryption on all vectors in the face feature template to generate a template ciphertext M, and then performs element-by-element operations on the template ciphertext and the face feature ciphertext transmitted by the client to complete the homomorphic calculation of the cosine similarity. The cosine similarity calculation formula is as follows:

[0060]

[0061] Substitute the face feature ciphertext C and the template ciphertext M to calculate the cosine similarity. Since the feature vectors have been normalized during extraction, the calculation formula is simplified to:

[0062]

[0063] where n is the dimension of vector C and vector M, and the calculated cosine similarity ciphertext group is sent to the client for further calculation;

[0064] Furthermore, in step 3, the specific steps to ensure the correct calculation of the cosine similarity using the Plonk protocol include:

[0065] (1) The cloud server initializes a proof generator using the Plonk protocol. When calculating the cosine similarity ciphertext, generate a zero-knowledge proof, and send the calculated cosine similarity ciphertext and the zero-knowledge proof to the client together;

[0066] (2) After the client receives the cosine similarity ciphertext and zero - knowledge proof sent by the cloud server, it initializes a proof verifier using the Plonk protocol. The verification function checks whether the zero - knowledge proof generated by the cloud server is valid. After successful verification, the client confirms that the cloud server's calculation is correct and no data has been tampered with during the calculation process;

[0067] (3) If the zero - knowledge proof verification is successful, the client continues with the authentication.

[0068] Furthermore, in step (3), the Plonk protocol proof generation steps include:

[0069] (1) Convert the calculation process into constraint conditions, and use the polynomial b(X) to represent the constraint conditions of the cosine similarity calculation process:

[0070] b(X) = C·M - cos(C,M)

[0071] where C is the face feature ciphertext, M is the template ciphertext, and cos(C,M) is the cosine similarity ciphertext. If the polynomial b(X) holds, it proves that the cloud server's cosine similarity calculation is correct;

[0072] (2) The proof generation has three main stages: the commitment stage, the challenge stage, and the response stage; in the commitment stage, the cloud server generates a commitment value according to the polynomial b(X) constructed in the first stage. In the challenge stage, a random challenge factor β is generated through the Fiat - Shamir challenge mechanism. In the response stage, the challenge factor is used to calculate the zero - knowledge proof:

[0073] ∏2 = {b(β),z2(β)}

[0074] ∏2 is the set of zero - knowledge proofs for the cloud server's cosine similarity calculation. b(β) is the commitment value of the cloud server's cosine similarity calculation operation, and z2(β) is the response value of the cloud server's cosine similarity calculation operation, based on the challenge factor β;

[0075] (3) The verifier uses the elliptic curve pairing technology to verify whether the equation holds, pairs the commitment value generated by the cloud server with the calculation result, checks whether the calculation process meets the predetermined constraint conditions, and confirms whether the cosine similarity calculation result provided by the cloud server is correct;

[0076] Furthermore, in step (4), after the client receives the cosine similarity ciphertext and completes the zero - knowledge proof verification, it decrypts the ciphertext using the previously stored private key to obtain the plaintext result of the cosine similarity; then, the client compares the decrypted cosine similarity value with a pre - set threshold. If the cosine similarity value is greater than or equal to the threshold, it is considered that the authentication is successful and the user is allowed to access the corresponding service; if the cosine similarity value is less than the threshold, it is considered that the authentication fails and the user's access request is rejected.

[0077] Based on the above authentication method, the present invention also proposes a device for implementing a cloud face authentication method based on RNS-CKKS encryption and cosine similarity, including a client device and a cloud server device. The client device can perform the content related to the client in the above method, and the cloud server device can execute the content related to the cloud server in the above method.

[0078] Based on the above authentication method, the present invention also proposes a storage medium, and the program code stored in the storage medium can implement the above authentication method when executed.

[0079] Advantages of the present invention:

[0080] 1. In this method, a random number is introduced into the face feature value to accompany the entire authentication process, effectively protecting the security of the face feature value during transmission and resisting replay attacks at the same time.

[0081] 2. This method uses differential privacy technology to add noise to the face feature value, shielding personal data in each authentication, ensuring that even in multiple authentication processes, attackers cannot obtain any user's private information, greatly improving privacy protection.

[0082] 3. The RNS-CKKS fully homomorphic encryption technology designed in this method ensures that when calculating in the cloud server, the data itself is always in an encrypted state, effectively preventing potential data leakage risks of the cloud computing platform. Compared with traditional homomorphic encryption schemes, the RNS-CKKS scheme has higher computing efficiency and better scalability, and is particularly suitable for encrypted computing of high-dimensional data. When calculating cosine similarity, the multi-modulus support of RNS-CKKS can effectively improve the processing speed and accuracy of encrypted data, and has stronger data scalability and privacy protection capabilities, especially suitable for applications such as face recognition that need to process a large number of feature vectors.

[0083] 4. This method introduces the Plonk zero-knowledge proof protocol to ensure the correctness of the similarity result calculated by the cloud server without revealing the intermediate data of the calculation and without public parameters, greatly enhancing the transparency and credibility of the system. This method uses cosine similarity to measure face feature values. Compared with Euclidean distance measurement, cosine similarity can better adapt to high-dimensional data and is not affected by the data scale. By measuring the angle between vectors to evaluate similarity, it is not affected by the modulus length of the vectors, enabling it to maintain good recognition performance when processing facial features with different scales. When the face involves pose changes, using cosine similarity can provide a more stable and robust similarity measurement, having great advantages in high-dimensional face recognition. Description of the Drawings

[0084] Figure 1Schematic flowchart of an embodiment of the authentication method of the present invention;

[0085] Figure 2 Schematic diagram of the system architecture of an embodiment of the present invention; Detailed implementation manners

[0086] The present invention proposes a cloud face authentication method, device and storage medium based on RNS-CKKS encryption and cosine similarity. The user initiates an authentication request, and the client acquires and preprocesses the face image, extracts the feature vector and normalizes the modulus length. The cloud server generates a random number and sends it to the client. The client uses differential privacy technology to add noise to the eigenvalue, performs Hadamard product operation, uses the RNS-CKKS scheme to homomorphically encrypt the feature and sends the ciphertext to the cloud server. The cloud server receives the ciphertext, encrypts the face feature template using the RNS-CKKS scheme, calculates the cosine similarity, uses the Plonk protocol to ensure the correctness of the calculation result, and sends the similarity ciphertext back to the client. The client decrypts the similarity ciphertext, compares it with the set threshold, and obtains the user identity authentication result. This solution strengthens privacy protection, improves recognition accuracy, and effectively prevents user information leakage by combining differential privacy, zero-knowledge proof and homomorphic encryption technologies.

[0087] The present invention will be further described below with reference to the accompanying drawings.

[0088] As Figure 1 、 2 shown, the present invention provides a cloud face authentication method based on RNS-CKKS encryption and cosine similarity. By combining differential privacy, zero-knowledge proof and homomorphic encryption technologies, it strengthens privacy protection, improves recognition accuracy, and effectively prevents user information leakage. The specific implementation of this authentication method includes the following steps:

[0089] Step 1: The user initiates an authentication request, and the client acquires and preprocesses the face image, extracts the feature vector and normalizes the modulus length. The specific implementation method is as follows:

[0090] The client initializes the camera, reads the face image frame, and uses the OpenCV library of Python (all embodiments of the present invention are implemented in a python environment);

[0091] video_capture = cv2.VideoCapture(0)

[0092] ret, image = video_capture.read()

[0093] Correct the lens distortion (the internal parameters mtx and distortion coefficients dist of the camera are obtained through the calibration process);

[0094] image = cv2.undistort(image, mtx, dist)

[0095] Eliminate random interference in the image, perform Gaussian blur using a 5×5 Gaussian kernel to remove noise, and the standard deviation of the Gaussian kernel is automatically calculated by the function;

[0096] image = cv2.GaussianBlur(image, (5, 5), 0)

[0097] Perform face detection, use the dlib library to detect faces in the image, and locate the positions of the faces;

[0098] face_detector = dlib.get_frontal_face_detector()

[0099] faces = face_detector(image)

[0100] Resize the image to 112x112 pixel size, convert it to the RGB color space, and extract the face feature value vector using the sphereface model;

[0101] face_img = cv2.resize(face_img, (112, 112))

[0102] face_img = cv2.cvtColor(face_img, cv2.COLOR_BGR2RGB)

[0103] face_features = sphereface_model(face_img)

[0104] Calculate the modulus of the feature vector and perform modulus normalization;

[0105] face_encoding_norm = np.linalg.norm(face_features)

[0106] normalized_face_features = face_features / face_encoding_norm

[0107] Step 2: The cloud server generates a random number and sends it to the client. The client uses differential privacy technology to add noise to the eigenvalue, performs Hadamard product operation, and uses the RNS-CKKS scheme to homomorphically encrypt the feature and send the ciphertext to the cloud server;

[0108] First, the cloud server generates a 128-dimensional random number vector, creates a TCP server using the socket library, and sends it to the client via a TCP connection (in subsequent steps, the client communicates with the cloud server using TCP connections). The client uses differential privacy technology to add noise to the eigenvalue;

[0109] Define a function to add noise to the face eigenvalue. The return value of this function is the original face eigenvalue plus the noise. The privacy budget epsilon controls the magnitude of the noise and is set to the default value of 1.0. The failure probability parameter delta controls the magnitude of the failure probability and is set to 1e -5 ;

[0110] def add_dp_noise(face_features, epsilon = 1.0, delta = 1e -5 )

[0111] Calculate the scale parameter sale of the Laplace noise, generate the noise noise from the Laplace distribution, and the face feature vector is normalized by the norm. The sensitivity is set to 1;

[0112] scale = sensitivity / epsilon

[0113] noise = np.random.laplace(0, scale, face_features.shape)

[0114] noisy_face_features = face_features + noise

[0115] The client performs a Hadamard product operation on the noisy face eigenvalue vector and the random number vector;

[0116] hadamard_product = noisy_face_features * random_vector

[0117] The client uses the RNS-CKKS fully homomorphic encryption scheme to encrypt the face eigenvalue after the Hadamard product operation to generate the ciphertext of the face eigenvalue. The specific implementation method is as follows:

[0118] The number of sub-vectors k_segments is 4, and the input feature vector is segmented according to k_segments;

[0119] segment_length = len(hadamard_product) / / k_segments

[0120] segment = features[i * segment_length:(i + 1) * segment_length]

[0121] Initialize the encryption parameters. The degree of the polynomial ring poly_modules_degree is 4096, the initial value of the modulus chain length is set to 4, and the initial value of the scaling factor is 2 40 , and set multiple modulus chains;

[0122] Dynamically calculate the scaling factor and modulus chain length according to the maximum value of the segments, and assign the corresponding scaling factor to each segment;

[0123] scaling_factor = 2 ** max(40, math.ceil(math.log2(max_value)))

[0124] L = max(4, math.ceil(math.log2(scaling_factor)))

[0125] segment_scaling = scaling_factors[i] if scaling_factors else 2 ** 40

[0126] Dynamically generate the modulus chain, with larger prime digit widths at the beginning and end and smaller in the middle;

[0127] coeff_modulus = CoeffModulus.Create(poly_modulus_degree,

[60] +

[40] * (L - 2) +

[60] )

[0128] Import the Python interface library ssealpy of the SEAL encryption library, import and create an EncryptionParameters object and specify the CKKS encryption scheme type, set the degree of the polynomial modulus poly_modulus_degree and the coefficient modulus coeff_modulus to define the encryption parameters, and use these parameters to create a SEALContext instance;

[0129] Generate a set of keys through the KeyGenerator class and pass in the context, including the public key public_key, the private key secret_key, and the relinearization key relin_keys;

[0130] Generate an encryptor according to the public key, a decryptor according to the private key, and an evaluator;

[0131] encryptor = Encryptor(context, public_key)

[0132] decryptor = Decryptor(context, secret_key)

[0133] evaluator = Evaluator(context)

[0134] Create an encoder encoder to encode each sub-vector into a polynomial representation supported by RNS-CKKS. During the encoding process, the precision is adjusted according to the scaling factor of each sub-vector;

[0135] CKKSEncoder encoder(context)

[0136] encoded_poly = encoder.encode(segment, segment_scaling)

[0137] encoded_polys.append(encoded_poly)

[0138] Create an empty ciphertext object ciphertext, encrypt each segmented vector. Each ciphertext in encrypted_segments corresponds to the encrypted data of a segment;

[0139] encryptor.encrypt(poly, ciphertext)

[0140] encrypted_segments.append(ciphertext)

[0141] Serialize the encrypted data into a format that can be transmitted, and transmit it to the cloud server together with the encryption parameter set and the public key;

[0142] Step 3: The cloud server receives the ciphertext, encrypts the face feature template, calculates the cosine similarity, uses zero-knowledge proof to ensure the correctness of the calculation result, and transmits the similarity ciphertext back to the client;

[0143] First, the cloud server receives the public key and parameters, creates an instance of SEALContext using the same encryption parameters as the client. The private key is only retained on the client, and the cloud server only needs to generate an encryptor encryptor and an evaluator calculator;

[0144] The cloud server uploads the face feature value template M{Q1, Q2,..., Q nAll the face feature vectors are homomorphically encrypted using the received public key by RNS-CKKS, which is consistent with the encryption method of the client. Each vector is segmented, encoded, and encrypted to generate the corresponding ciphertext, and the encrypted template face feature value M is obtained. enc {Q 1_enc , Q 2_enc , …, Q n_enc}; Receive the encrypted face feature value ciphertext, read the encrypted template face feature value ciphertext, and calculate the cosine similarity between the encrypted face feature value ciphertext uploaded by the client and the encrypted template face feature value ciphertext. The formula for the cosine similarity after vector normalization is:

[0145]

[0146] Perform element-wise operations on the encrypted template encrypted_template and the encrypted face feature ciphertext encrypted_segments transmitted by the client, and use homomorphic encryption operations to add multiple ciphertexts to obtain the encrypted cosine similarity sum_ciphertext;

[0147] encrypted_dot_product = Ciphertext()

[0148] evaluator.multiply(encrypted_segments, encrypted_y, encrypted_dot_product)

[0149] encrypted_sim_cos = Ciphertext()

[0150] evaluator.add_many(encrypted_dot_product, sum_ciphertext)

[0151] Compile and implement the proof generation and verification code of the Plonk protocol, install the zkp-plonk open-source library to create a Python module plonk_zkp, and initialize the proof generator Prover and verifier Verifier for the module;

[0152] Use the generate_proof() method to accept the calculation data parameters, and the proof generator Prover calculates a zero-knowledge proof proof based on the input data;

[0153] Use the verify_proof() method to accept two parameters: the zero-knowledge proof proof and the calculation data. The proof verifier Verifier checks whether the proof and the calculation data conform to the verification rules in the Plonk protocol and returns a boolean value;

[0154] The client imports the plonk_zkp module, creates a Plonk proof generator, generates a zero-knowledge proof for the noise-added data, and sends the noise-added data and the zero-knowledge proof to the cloud server;

[0155] zkp_generator = plonk_zkp.PlonkZKGenerator()

[0156] proof = zkp_generator.generate_proof(noisy_face_features)

[0157] The cloud server imports the plonk_zkp module, creates a Plonk proof generator, receives the noise-added data and the proof, and verifies the noise-added step;

[0158] zkp_verifier = plonk_zkp.PlonkZKVerifier()

[0159] is_valid = zkp_verifier.verify_proof(proof, noisy_face_features)

[0160] The cloud server creates a Plonk proof generator, generates a zero-knowledge proof based on the cosine similarity ciphertext, and passes it and the similarity ciphertext to the client;

[0161] zkp_generator = plonk_zkp.PlonkZKGenerator()

[0162] similarity_proof = zkp_generator.generate_proof(sum_ciphertext)

[0163] The client receives the similarity ciphertext and the zero-knowledge proof, creates a Plonk verifier, and if similarity_valid is valid, the verification is successful;

[0164] zkp_verifier = plonk_zkp.PlonkZKVerifier()

[0165] similarity_valid = zkp_verifier.verify_proof(similarity_proof, sum_ciphertext)

[0166] Step 4: The client decrypts the similarity ciphertext and compares it with the set threshold to complete the identity authentication. The specific implementation method is as follows:

[0167] The client uses a decryptor to decrypt to obtain the cosine similarity;

[0168] decrypted_result = Plaintext()

[0169] decryptor.decrypt(sum_ciphertext, decrypted_result)

[0170] Convert the decrypted plaintext to a floating point number and find the maximum value among a set of n cosine similarities;

[0171] similarity = float(rns_ckks_encoder.decode_real(decrypted_result))

[0172] decrypted_similarities.append(similarity)

[0173] max_similarity = np.max(decrypted_similarities)

[0174] Compare the maximum value of the cosine similarity max_similarity with the pre-set threshold τ obtained from experiments. If max_similarity > τ, the face authentication is successful; otherwise, the authentication fails.

[0175] The series of detailed descriptions listed above are only specific descriptions of the feasible implementation manners of the present invention, and they are not intended to limit the protection scope of the present invention. Any equivalent manners or modifications that do not depart from the technology created by the present invention should be included in the protection scope of the present invention.

Claims

1. A cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity, characterized in that: These include: Step 1: The user initiates an authentication request on the client, and the client obtains and preprocesses the face image, extracts the feature vector and performs modulus normalization; Step 2: The cloud server generates a random number vector and sends it to the client. The client uses differential privacy to add noise to the feature value, uses the Plonk protocol to ensure the correctness of the noise addition result, performs Hadamard product operation, uses the RNS-CKKS scheme to homomorphically encrypt the feature and sends the ciphertext to the cloud server. Step 3: The cloud server receives the ciphertext and encrypts the facial feature template, calculates the cosine similarity, uses the Plonk protocol to ensure that the cosine similarity calculation is correct, and transmits the similarity ciphertext back to the client; Step 4: The client decrypts the similarity ciphertext and compares it with the set threshold to complete identity authentication.

2. According to claim 1, a cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity is characterized in that: The step 1 specifically includes the following: Step 1.1 The client uses a camera to obtain a face image and performs geometric transformation adjustment on the image; Step 1.2: Eliminate random interference in the image and remove noise; Step 1.3 performs face detection to locate the position of the face in the image; Step 1.4 adjusts the format of the image data to meet the input requirements of the model, extracts facial feature values, normalizes and stores them.

3. According to claim 1, a cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity is characterized in that: The client in step 2 uses differential privacy to add noise to the eigenvalues. This is done by adding Laplace noise to the face eigenvalues ​​to prevent malicious users from stealing the original eigenvalues ​​through reverse engineering or replay attacks, thereby enhancing the privacy protection capability of the system. The standard deviation of the noise is determined by the privacy budget epsilon and the error probability delta. The privacy budget epsilon controls the intensity of the noise, and the error probability delta controls the failure probability of differential privacy. The generated noise vector has the same dimension as the face eigenvalue, and each noise value comes from a Laplace distribution.

4. According to claim 3, a cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity is characterized in that: The specific process in step 2 includes: Step 2.1 Select the differential privacy parameters, the privacy budget ∈ is set to the default value 1.0, and the error probability δ is set to the default value 1e -5 ; Step 2.2 generates a noise value for each element of the eigenvalue using Laplace distribution. The Laplace noise probability density function P(x) is: Where x represents the noise value, μ is the mean of the Laplace distribution, which is set to 0, indicating that the probability density function is symmetric around 0, and b is the scale parameter that controls the distribution range of the noise, which is calculated by the privacy budget ∈ and the sensitivity Δ: Generate a random number u uniformly distributed between [0,1], and convert u into noise noise that conforms to the Laplace distribution through the inverse transformation method: noise=-b·sgn(u-0.5)·ln(1-2∣u-0.5∣) u-0.5 maps the random number u from [0,1] to [-0.5,0.5] to ensure that the noise value distribution is symmetrical. sgn(u-0.5) is a sign function to ensure that the sign of the noise value is random and symmetrical. ln(1-2|u-0.5|) transforms the uniformly distributed random number so that the generated noise conforms to the Laplace distribution characteristics. Each eigenvalue element generates an independent Laplace distribution noise value to obtain the noise value vector N. Step 2.3: Add the corresponding noise value to each eigenvalue to disturb the original data and obtain the noisy face eigenvalue F. N ; Step 2.4 The random number vector has the same dimension as the noisy face feature value, and each element is a floating point number between [0,1]. The Hadamard product of the noisy face feature value vector and the random number vector is calculated: V=F N ⊙R The vector V obtained by the Hadamard product operation, each element of which is composed of the noisy face feature value F N It is obtained by multiplying the element at the corresponding position in the random number vector R; Step 2.5 The client uses the RNS-CKKS algorithm to homomorphically encrypt the facial feature values ​​after the Hadamard product operation to generate facial feature value ciphertext. The specific steps and their optimization process include: Step 2.5.1 The client initializes the encryption system, generates RNS-CKKS encryption parameters, and selects the polynomial ring: R q =Z[X] / (X N +1) R q is a polynomial ring under modulus q, q is an element in the modulus chain, Z[X] is a polynomial ring over integers, where Z is the set of integers, X is the symbol used to represent the polynomial variable in the polynomial ring, and N is a power of 2; Step 2.5.2 adopts the segmented coding method to convert the feature vector v after the Hadamard product into [v1, v2, …, v n ] is divided into k sub-vectors v1, v2, …, v k , according to the accuracy requirements of the facial feature vector, dynamically adjust the scaling factor S and the modulus chain length L for each sub-vector, generate the modulus chain, and at the same time generate a key set including the private key, public key and relinearization key; The scaling factor is selected for each sub-vector by adaptive scaling, that is, the maximum value of each sub-vector segment is calculated, and the scaling factor S is estimated using a logarithmic function: Where max_value is the maximum value of the subvector, which is the larger value between 40 and log2(max_value) rounded up, ensuring that the scaling factor is at least 2 40 , when the maximum value of the subvector exceeds 2 40 When , the scaling factor will be increased accordingly to ensure sufficient numerical accuracy in subsequent calculations; The modulus chain length L is adjusted synchronously according to the scaling factor S: Take the larger value between 4 and log2(S) rounded up to ensure that the modulus chain length L is at least 4, balance computational efficiency and ciphertext security, and control noise growth; Map the subvector to a polynomial m(x), where the coefficients of m(x) are the elements x0,x1,x2,…,x in the subvector. n , n is the number of elements in the subvector and also the highest degree of the polynomial: m(x)=x0+x1x+x2x 2 +…+x n x n Perform residual digitization, for the moduli p1, p2, p3, ..., p in the modulus chain k , k is the number of moduli in the modulus chain, each coefficient of m(x) is modulo the modulus, each element of the subvector will be mapped to a different modulus, and the residual number is obtained: in, is the coefficient x i In modulus p j The residual number under i are the coefficients in the polynomial m(x), i is the index starting from 0 and ending at n, n is the number of elements in the subvector, and p j is the jth modulus in the modulus chain, where j starts at 1 and ends at k; For each modulus, generate a polynomial: Among them, m j (x) is the polynomial corresponding to the jth modulus chain, and a total of k polynomials are generated, j starts from 1 and ends at k, i is the index from 0 to n, and n is the number of elements in the subvector; Step 2.5.3 Use the public key to encode each polynomial m j (x) is encrypted and converted into RNS-CKKS format ciphertext, and the generated ciphertext C together with the public key and encryption parameters are sent to the cloud server for subsequent calculations.

5. A cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity according to claim 4, characterized in that: The specific process of step 3 includes: Step 3.1 The cloud server receives the ciphertext and its related encryption parameters transmitted by the client, uses the RNS-CKKS scheme to build a homomorphic encryption framework, segment-encodes and encrypts all vectors in the facial feature template, generates the template ciphertext M, and then performs element-by-element operations on the template ciphertext and the facial feature ciphertext transmitted by the client to complete the homomorphic calculation of cosine similarity; the calculated cosine similarity ciphertext group is sent to the client for further calculation; Step 3.2 The cloud server uses the Plonk protocol to initialize the proof generator, generates a zero-knowledge proof when calculating the cosine similarity ciphertext, and sends the calculated cosine similarity ciphertext and the zero-knowledge proof to the client; Step 3.3 After the client receives the cosine similarity ciphertext and zero-knowledge proof sent by the cloud server, it uses the Plonk protocol to initialize the proof verifier. The verification function checks whether the zero-knowledge proof generated by the cloud server is valid. After successful verification, the client confirms that the calculation of the cloud server is correct and that the data has not been tampered with during the calculation process. Step 3.4: Zero-knowledge proof verification succeeds and the client proceeds to identity authentication.

6. A cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity according to claim 5, characterized in that: The cosine similarity calculation formula of step 3.1 is as follows: Where n is the dimension of vector C and vector M.

7. A cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity according to claim 5, characterized in that: The method for generating the zero-knowledge proof in step 3.2 includes: Step 3.2.1 converts the calculation process into constraints, and uses the polynomial b(X) to represent the constraints of the cosine similarity calculation process: b(X)=C·M-cos(C,M) Where C is the face feature ciphertext, M is the template ciphertext, and cos(C,M) is the cosine similarity ciphertext. If the polynomial b(X) holds, it proves that the cloud server cosine similarity calculation is correct. Polynomials are used in the Plonk protocol to express the constraints in the above calculation process and verify the correctness of the calculation process; Step 3.2.2 Proof generation has three main stages: commitment stage, challenge stage and response stage; in the commitment stage, the cloud server generates a commitment value based on the polynomial b(X) constructed in the first stage, the challenge stage generates a random challenge factor β through the Fiat-Shamir challenge mechanism, and the response stage uses the challenge factor to calculate the zero-knowledge proof: ∏2={b(β),z2(β)} ∏2 is the zero-knowledge proof set of the cloud server cosine similarity calculation, b(β) is the commitment value of the cloud server cosine similarity calculation operation, z2(β) is the response value of the cloud server cosine similarity calculation operation, based on the challenge factor β; Step 3.2.3 uses elliptic curve pairing to verify whether the equation holds, pairs the commitment value generated by the cloud server with the calculation result, checks whether the calculation process meets the predetermined constraints, and confirms whether the cosine similarity calculation result provided by the cloud server is correct.

8. A cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity according to claim 1, characterized in that: The specific process of step 4 includes: Step 4.1 After the client receives the cosine similarity ciphertext and completes the zero-knowledge proof verification, it uses the stored private key to decrypt the ciphertext to obtain the plaintext result of the cosine similarity; Step 4.2 The client compares the decrypted cosine similarity value with a preset threshold. If the cosine similarity value is greater than or equal to the threshold, the authentication is considered successful and the user is allowed to access the corresponding service. If the cosine similarity value is less than the threshold, the authentication is considered failed and the user's access request is denied.

9. A device for implementing a cloud-based face authentication method based on RNS-CKKS encryption and cosine similarity, characterized in that: The invention comprises a client device and a cloud server device, wherein the client device can execute the content of the client in any one of claims 1-8, and the cloud server device can execute the content of the cloud server in any one of claims 1-8.

10. A storage medium, characterized in that: The program code stored in the storage medium can implement the authentication method of any one of claims 1-8 when executed.

Citation Information

Cited By

  • Face feature encryption matching method and system for privacy protection

    CN121392944A

  • High-dimensional vector similarity retrieval method and system supporting hierarchical fully homomorphic encryption

    CN121764986A

  • A high-dimensional vector similarity retrieval method and system supporting hierarchical homomorphic encryption

    CN121764986B