Multi-person identity recognition system with access permission allocation and without storage

Through iris feature extraction and secret sharing algorithms, combined with symmetric encryption technology, multi-person identity authentication without storage is realized, the security and expansion problems of existing systems are solved, and flexible permission sharing and group authentication functions are provided.

CN120296718APending Publication Date: 2025-07-11NAT UNIV OF DEFENSE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510165925.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing identity authentication system cannot achieve multi-person identity authentication, there is a risk of database leakage, and biometric information is prone to forgery and theft, and insufficient security and expansion.

Method used

Iris feature extraction and secret sharing algorithms are used to encode iris features and permission information on the card using symmetric encryption technology to realize multi-person identity authentication without storage, authenticate through QR code decoding and iris feature comparison, and group permission authentication is used using secret recovery algorithm.

Benefits of technology

It realizes multi-person identity authentication without database storage, avoids the risk of database leakage, improves the security and flexibility of identity authentication, and supports permission sharing and group authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296718A_ABST
    Figure CN120296718A_ABST
Patent Text Reader

Abstract

The invention provides a storage-free multi-person identity recognition system with access permission allocation, and belongs to the technical field of secret sharing. The system comprises a front end and a rear end. Wherein the front end comprises an interface design process and an event response process, the interface design is used for realizing user access and management operation, and the event response comes from an algorithm of the rear end; the rear end comprises a card making module and an authentication module; the card making module is used for realizing iris acquisition and basic information acquisition of a user, group permission input, symmetric encryption, two-dimensional code coding and printing and card printing; and the authentication module is used for realizing iris feature comparison, basic information comparison, group authority authentication, symmetric decryption and two-dimensional code decoding. According to the invention, the authority information is generated through the secret sharing algorithm, and the authority information is shared, so that a group authentication (group identification) function is realized. Meanwhile, the method does not depend on a database to store the privacy information of the user, and the problem of secret leakage does not exist.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of secret sharing, and particularly relates to a multi-person identity recognition system with access right sharing and no storage. Background Art

[0002] Secret Sharing (SS) encrypts secret information into multiple shadow images (shadow, shadow image or share) and distributes them to multiple participating parties. Only a subset of authorized participating parties can decrypt together, while unauthorized subsets cannot decrypt.

[0003] In terms of human identity authentication, it is mainly achieved through one or a combination of the following three basic ways: what you know, knowledge known or mastered by an individual, such as a password; what you have, things owned by an individual, such as an ID card, passport, credit card, key or certificate, etc.; personal characteristics (what you are), biological characteristics of an individual, such as fingerprints, palm prints, voiceprints, face shapes, DNA, retina, etc. Among them, biometric-based recognition technology has many advantages over traditional identity authentication, such as confidentiality, convenience, not easy to forget, good anti-counterfeiting performance, not easy to forge or be stolen, easy to carry and use anytime and anywhere. It is also because of these advantages that many countries have embedded the biometric information of the holder in personal identity documents, such as embedding fingerprint information. However, there are still problems to be solved and common concerns regarding identity authentication currently.

[0004] For example: Currently, most systems can only achieve single-person identity authentication, without the function of multi-person identity authentication (group identity recognition), and there is no group identity recognition system that can avoid collusion attacks, making it impossible to achieve right sharing and flexible control in many special application scenarios.

[0005] Currently, traditional identity recognition schemes require the support of a local database. Once the system administrator leaks secrets or is attacked by an attacker, private biometric features face the risk of being centrally leaked, which is a common concern currently.

[0006] In addition, currently, the more popular and widely used identity recognition method is based on deep learning models. This method is vulnerable to new types of intelligent attacks, such as model backdoor attacks and adversarial samples, which will make biometric recognition technologies such as face recognition and iris recognition no longer reliable.

[0007] The human iris has stability. A person's iris forms when they are 10 months old and remains unchanged throughout their life. The probability of two identical iris features occurring is almost zero. The iris is hidden in the human eye and is not easily stolen or lost.

[0008] Currently, most of the biometric-based identity authentication methods are fingerprint recognition and face recognition technologies, etc., which are related prior arts of the present invention. The core is to input the user's fingerprint or face information into the backend database for storage. When performing identity authentication, the biometric information collected on-site is compared and judged with the biometric information in the backend database, and it is determined whether it is the same person after calculation. However, with the continuous development of attack technologies, it is no longer difficult to forge and modify easily modifiable biometric information such as fingerprints and faces, which is also a great challenge for identity authentication. Secondly, storing unique biometric privacy information in the hands of a third party poses risks such as theft, forgery, and trading, and the security of users' personal privacy cannot be guaranteed.

[0009] The following gives the principle flowchart of common biometric recognition (as Figure 1 shown). This technology is one of the most common implementations of biometric identity recognition and authentication. Its technical implementation is basically divided into a registration stage and an authentication stage. In the registration stage, the user's biometric image information is obtained and feature extraction is performed, and after completion, the data is stored in the local database. In the authentication stage, the collected image to be measured is subjected to feature extraction and then placed in the matcher for comparison with the biometric information in the local database. If there is the same feature information in the local database, the authentication is passed; otherwise, the authentication fails.

[0010] This implementation method has been accepted and recognized by the majority of developers and users, but it still has defects in scalability and security. First, it cannot achieve permission sharing and flexible switching; second, the security risks of the local database still exist and cannot be solved. Summary of the Invention

[0011] In view of the above technical problems, the present invention starts from the actual needs and applications, and proposes a multi-person identity recognition system with access permission sharing and no storage; the present invention can realize the group discrimination function and can completely solve the user's concern about the problem of database leakage.

[0012] The present invention proposes a multi-person identity recognition system with access permission sharing and no storage, and the system includes a front end and a back end; wherein:

[0013] The front end includes two processes: interface design and event response. The interface design is used to implement user access and management operations, and the event response comes from the algorithm of the back end;

[0014] The back end includes a card making module and an authentication module; wherein:

[0015] The card making module is used to implement: iris collection and basic information collection of users, group permission entry, symmetric encryption, QR code encoding, printing and card making;

[0016] Among them, an iris camera is used for iris collection, a thermal printer is used for printing and card making, an iris feature extraction algorithm is used for iris feature extraction, a secret sharing algorithm is used for group permission setting, and a symmetric encryption algorithm is used for symmetric encryption;

[0017] The authentication module is used to implement: iris feature comparison, basic information comparison, group permission authentication, symmetric decryption, and QR code decoding;

[0018] Among them, a QR code scanner is used for QR code decoding, an iris feature comparison algorithm is used for iris feature comparison, a secret recovery algorithm is used for group permission authentication, and a symmetric decryption algorithm is used for symmetric decryption.

[0019] According to the system proposed by the present invention, at the backend of the system:

[0020] When making a card, the card making module collects information about the user group, including the user's basic information, permission information, and iris information. The permission information includes the threshold, group, and shadow value. The iris information refers to the iris features obtained by extracting the features of the collected user iris image. Various types of information collected are encrypted using symmetric encryption technology, encoded into a QR code, and the QR code and basic information are printed on the card to complete card making;

[0021] When authenticating, the authentication module performs the following operations on all users in the group to be authenticated in sequence: scans the QR code on the card they hold, decrypts the QR code using the symmetric key, and respectively performs iris feature comparison, basic information comparison, and group permission authentication on the information therein. When performing iris feature comparison, one of the iris features comes from the iris features after feature extraction of the iris information collected on-site from the users in the group to be authenticated.

[0022] According to the system proposed by the present invention, an iris feature extraction algorithm is used for iris feature extraction; specifically including:

[0023] Read the iris image and convert the iris image into a grayscale image;

[0024] Perform image preprocessing, including median filtering operation, Gaussian blur, and histogram equalization, to remove noise interference;

[0025] Use the Hough transform to detect the inner circle and outer circle in the iris image, and obtain the center coordinates and radius size to further determine the position and size of the iris;

[0026] Perform normalization processing, convert the polar coordinate graph into a rectangular coordinate graph, and adjust the size and position of the iris;

[0027] Using wavelet transform or stationary wavelet transform, extract the high-frequency coefficients, calculate the average value of each coefficient block, binarize the average value of the high-frequency coefficients to obtain the feature vector.

[0028] Remove noise through morphological opening operation and output the feature vector.

[0029] According to the system proposed by the present invention, use the iris feature comparison algorithm to compare iris features; specifically including:

[0030] Compare the iris information extracted in the verification stage with the iris information saved on the card;

[0031] Calculate the number of non-zero elements between the two feature vectors through the np.count_nonzero function as the Hamming distance, and this distance is used to measure the similarity degree of the two feature vectors;

[0032] The smaller the distance, the higher the similarity degree. If it is within a certain threshold, it is judged as the same person, otherwise the verification fails.

[0033] According to the system proposed by the present invention, use the secret sharing algorithm to set group permissions; specifically including:

[0034] The group discrimination function is realized based on the polynomial-based secret sharing technology. Secret sharing means encrypting the secret information into multiple share values and distributing them to multiple participants. Only a subset of the authorized participants can decrypt, and the unauthorized set cannot decrypt;

[0035] In (k,n) threshold secret sharing, encrypt the secret information into n shadow images. If no less than k shadows are obtained, the original secret can be reconstructed; if less than k shadow images are obtained, no secret can be obtained, where k ≤ n;

[0036] Embed the secret into a random polynomial of degree k - 1. Given the secret information s, share it into n share values sc1, sc2, …, sc n :

[0037] Select a large prime number p such that p > n and p > s. Let GF(p) be a finite field, all elements are elements of GF(p), and all operations are carried out in the finite field GF(p);

[0038] In the sharing stage, encrypt s into the shadow value sc i , randomly generate a polynomial f(x) = a0 + a1x + … + a of degree k - 1 in the finite field GF(p) k-1 x k-1 ;

[0039] Embed the secret s into the first coefficient of the polynomial, a0 = s, and the remaining coefficients a1, …, a k-1Randomly select in the finite field GF(p), and calculate sc1 = f(1), …, sc k = f(k), …, sc n = f(n);

[0040] Take (i, sc i ) as a shadow pair, where i is used as an information tag or serial number tag, and sc i is used as a shadow pixel value. Distribute the n shadow shares to n participants respectively to complete the secret sharing.

[0041] According to the system proposed by the present invention, use the secret recovery algorithm for group permission authentication; specifically include:

[0042] In the secret recovery stage, obtain any k secret pairs among the n participants Construct a system of linear equations:

[0043]

[0044] where, i l (1 ≤ l ≤ k) are all different, and construct a polynomial by Lagrange interpolation formula:

[0045]

[0046] Obtain the secret s = f(0);

[0047] Among them, if k - 1 participants obtain the secret, then construct k - 1 equations to form a system of linear equations, where the k coefficients of the sharing polynomial are unknowns; and because the label i l is different, each shadow share corresponds to a unique polynomial that satisfies the formula system of linear equations. Knowing k - 1 shadows cannot solve the system of linear equations with k unknowns, so no information about the secret can be obtained;

[0048] Among them, for a legal group (P1, P2, …, P k , …, P n ), the (k, n) threshold group discrimination function means that when any k or more users in the legal group come to authenticate their identities at the same time, the authentication is passed; and when any less than k users in the legal group come to authenticate their identities at the same time, the authentication fails. In addition, when an illegal user P outside the legal group * comes to participate in the authentication, the authentication also fails.

[0049] According to the system proposed by the present invention, use the symmetric encryption algorithm for symmetric encryption; specifically include:

[0050] The encryption algorithm AES-256-CBC is adopted, with a key length of 256 bits, a block length of 128 bits, and the padding method is PKCS7Padding;

[0051] During encryption, the key and the initialization vector IV are set. The key length is 256 bits. The key is obtained from the string using the UTF8 character set encoding method, and the IV uses a byte array with a fixed length of 16 as the initialization vector;

[0052] Create a decryptor object through the createDecryptor() function and pass it into the TransformFinalBlock() function for decryption operation.

[0053] According to the system proposed by the present invention, symmetric decryption is performed using a symmetric decryption algorithm; specifically including:

[0054] For decryption, the AES algorithm is also used. The ciphertext string is converted into a byte array. An AES decryptor object is created by using Aes.Create(), and the key length and block length are set to 256 bits and 128 bits respectively. The key and the initialization vector (IV) are set, where the key and the IV are respectively obtained by retrieving from a UTF-8 encoded string;

[0055] Create a decryptor object through the AES.CreateDecryptor() function, use the decryptr.TransformFinalBlock() function to decrypt the ciphertext, obtain the byte array of the plaintext, convert the byte array of the plaintext into a string and display it in the text box.

[0056] In summary, the present invention mainly generates permission information through a secret sharing algorithm and apportions the permission information to implement the group authentication (group discrimination) function. At the same time, this system does not rely on a database to store user privacy information, and there is no problem of information leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0058] Figure 1 It is a flowchart of common biometric recognition in the prior art.

[0059] Figure 2Schematic diagram of a multi-person identity recognition system with access right sharing and no storage according to an embodiment of the present invention.

[0060] Figure 3 Schematic diagram of a multi-person identity recognition process with access right sharing and no storage according to an embodiment of the present invention.

[0061] Figure 4 Schematic diagram of the system interface according to an embodiment of the present invention.

[0062] Figure 5 Schematic diagram of the iris feature extraction process according to an embodiment of the present invention.

[0063] Figure 6 Schematic diagram of the iris feature comparison process according to an embodiment of the present invention.

[0064] Figure 7 Schematic diagram of the permission information entry form according to an embodiment of the present invention.

[0065] Figure 8 Schematic diagram of information collection, encryption, and QR code generation according to an embodiment of the present invention.

[0066] Figure 9 Schematic diagram of the authentication form according to an embodiment of the present invention. Detailed implementation manners

[0067] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0068] The present invention provides a multi-person identity recognition system with access right sharing and no storage. As Figure 2 shown, the system is divided into a front end and a back end. The front end includes interface design and event response for user access and system administrator operations, where the response to events comes from the back-end algorithms; the back end mainly includes a card-making module and an authentication module. The card-making module is mainly responsible for user information collection, encryption, QR code encoding, and finally typesetting the layout of the card; the authentication module is mainly responsible for QR code decoding, decrypting, and comparing user information. The main algorithms involved in the entire system include iris feature and comparison algorithms, secret sharing and recovery algorithms, and symmetric encryption and decryption algorithms. In addition, the peripheral hardware devices of the system include an iris camera, a thermal printer, and a QR code scanner.

[0069] As Figure 3As shown in the figure, when making a card, first, information of user groups is collected, including basic information, permission information, and iris information of users. Here, the permission information is pre-thresholded, including threshold, group, and shadow value for user selection. Iris information refers to the iris features obtained by extracting features from the collected iris images of users. Then, the user information obtained by using symmetric encryption technology is encrypted and encoded into a QR code. Finally, the QR code and basic information are printed on the card, and thus the card making is completed.

[0070] As Figure 3 shown in the figure, during authentication, the following operations are performed on all users in the group to be authenticated in sequence. First, the QR code on the card they hold is scanned. Then, the QR code is decrypted with the symmetric key, and iris feature comparison, basic information comparison, and group permission authentication are respectively performed on the information therein. When performing iris feature comparison, one of the iris features is the iris feature after feature extraction from the iris information collected on-site from the users in the group to be authenticated.

[0071] The above system is used in identity recognition scenarios, such as access control systems, attendance systems, confidential places, etc., and is widely used in management systems, as Figure 4 shown in the figure.

[0072] I. Implementation Principle of Permission Sharing

[0073] The group discrimination function is realized based on the polynomial-based secret sharing technology. The basic idea of secret sharing is to encrypt the secret information into multiple share values and distribute them to multiple participating parties. Only the subset of authorized participating parties can decrypt together, while the non-authorized subset cannot decrypt. A secret sharing algorithm generally includes two stages: secret sharing and recovery. The (k,n) threshold secret sharing scheme encrypts the secret information into k shadow images. Only when k or more shadow images are obtained can the original secret be reconstructed; when less than k shadow images are obtained, no secret can be obtained. In the scheme, k ≤ n.

[0074] This work uses the classic polynomial-based secret sharing algorithm to implement the group discrimination function. The polynomial secret sharing scheme embeds the secret into a random polynomial of degree k - 1. During decryption, this polynomial can be reconstructed by Lagrange interpolation method to obtain the secret information embedded in the polynomial. Given the secret information s, it is shared into n share values sc 1, sc 2, … , sc n , and the specific scheme is as follows:

[0075] (1) In the initialization phase, determine the values of the threshold (k, n), where k ≤ n. Select a large prime number p such that p > n and p > s. Let GF(p) be a finite field, all elements are elements of GF(p), and all operations are performed in the finite field GF(p).

[0076] (2) In the sharing phase, to encrypt s into shadow values sc i , randomly generate a polynomial of degree k - 1 in the finite field GF(p): f(x) = a0 + a1x + … + a k-1 x k-1 .

[0077] Embed the secret s into the first coefficient of the polynomial, i.e., a0 = s, and the remaining coefficients a1, …, a k-1 are randomly selected in the finite field GF(p). Then calculate sc1 = f(1), …, sc k = f(k), …, sc n = f(n).

[0078] Take (i, sc i ) as a shadow pair, where i is used as an information label or serial number label, and sc i is used as a shadow pixel value. Distribute the n shadow shares to n participants respectively to complete the secret sharing.

[0079] (3) In the recovery phase, obtain any k secret pairs held by the n participants Among them, a linear equation system can be constructed as follows:

[0080]

[0081] Since i l (1 ≤ l ≤ k) are all different, the following polynomial can be constructed by the Lagrange interpolation formula:

[0082]

[0083] Thus, the secret s = f(0) can be obtained. If k - 1 participants want to obtain the secret, k - 1 equations can be constructed to form a linear equation system, where the k coefficients of the sharing polynomial are unknowns. Since the label i l is different, each shadow share corresponds to a unique polynomial that satisfies the formula linear equation system. Therefore, knowing k - 1 shadows cannot solve the linear equation system with k unknowns, and no information about the secret can be obtained. Thus, this scheme is perfect.

[0084] For a legal group (P1, P2, …, P k , …, Pn ) The (k,n) threshold group authentication function means that when any k or more users in the legitimate group come to authenticate their identities simultaneously, they can pass the authentication together. When any fewer than k users in the legitimate group come to authenticate their identities simultaneously, they cannot pass the authentication. Additionally, when an illegal user P outside the legitimate group * participates in the authentication, the authentication cannot pass.

[0085] Moreover, this work generates a group permission information book in advance (see Table 1 below), that is, it generates a list of secret values and corresponding sharing values in advance. When k or more users provide the sharing values they hold, the polynomial can be successfully solved to obtain the unique secret value a0. When fewer than k users provide the sharing values they hold, there are p choices for the secret value a0, and the unique secret value cannot be solved. The secret value recovery fails. Lagrange interpolation is used when recovering the authentication group permissions. It belongs to lossless recovery. If the secret value can be successfully recovered, the group authentication passes; if the secret value recovery fails, the group authentication fails.

[0086] Table 1 is the permission information book preset in this system, and only 5 groups are shown for each threshold. The following tips are given for this table:

[0087] The meaning of the (k,n) threshold: Among n sharing values, collecting k or more sharing values can recover the secret value.

[0088] The parameter range here is set to 2 ≤ k ≤ n ≤ 6.

[0089] Here, only 5 groups are shown for each threshold. The secret value is set as the threshold plus the group number. With this setting method, there can be 100 sharing values for each threshold, and there are up to 100 groups to choose from for each threshold. (It can be amplified according to the actual application situation).

[0090] Among four-digit numbers, the largest prime number is 9973. We choose p = 9973 as the prime number for the secret sharing algorithm. The value of p can be adjusted, and the higher the value of p, the higher the security level.

[0091] Table 1: Permission Information Book

[0092]

[0093]

[0094]

[0095]

[0096]

[0097] II. Implementation Principle without Database Dependence

[0098] The iris features, basic information, and group permission information are all encrypted and encoded in the QR code, which is printed on the card held by the individual. Therefore, there is no need to design a database to store this information in the entire card system. All personal information, including personal biometric information, is held and preserved by the individual and not stored by any other second party, effectively protecting personal privacy.

[0099] For the collected iris information, according to the Figure 5 process shown below, OpenCV and PyWavelets in the Python environment are used to implement iris feature extraction. Among them, OpenCV is an open-source computer vision library widely used in the fields of computer vision and image processing. And PyWavelets is a wavelet transform library based on the Python language. The steps of iris feature extraction are described as follows:

[0100] 1. Read the iris image and convert the image file to a grayscale image. In iris recognition, a grayscale image can reduce the amount of data in the image and retain the main information of the image.

[0101] 2. Perform image preprocessing, including operations such as median filtering, to remove noise interference. There may be some noise and interference in the iris image, which will affect both iris feature extraction and recognition. Therefore, in this step, some image preprocessing operations, such as median filtering, Gaussian blur, histogram equalization, etc., are required to remove the noise interference in the image.

[0102] 3. Use the Hough transform to detect the inner circle and outer circle in the iris image, and obtain the center coordinates and radius size. In iris recognition, it is necessary to determine the position and size of the iris by detecting the inner circle and outer circle of the iris. This algorithm uses the Hough transform for circle detection to obtain the center coordinates and radius size of the iris.

[0103] 4. Perform normalization processing on the image, and convert the polar coordinate map to a rectangular coordinate map. The iris image has the characteristics of strong rotation and scale invariance. Therefore, in this step, normalization processing is required to convert the original image to a rectangular coordinate map and adjust the size and position of the iris.

[0104] 5. Using wavelet transform or stationary wavelet transform, extract the high-frequency coefficients, calculate the average value of each coefficient block, binarize the average value of the high-frequency coefficients to obtain the feature vector. Wavelet transform is a tool for decomposing a signal into different frequency components. It can process images and separate the detail information at different levels and scales. Using wavelet transform, the iris image can be divided into two parts: low frequency and high frequency, and then the high-frequency coefficients of the iris image can be extracted. Then calculate the average value of these coefficients to obtain the average value of each coefficient block (also called the feature vector). Subsequently, perform a binarization operation on it, converting the average value to 0 or 1 to obtain a string of binary codes as the feature vector of the iris.

[0105] 6. Remove noise through morphological opening operation. There may be some noise points or unnecessary information in the binarized feature vector, which will affect the subsequent feature matching and recognition accuracy. Therefore, in this step, use morphological opening operation (morphologyEx function) to remove noise. Morphological opening operation can remove the structural elements smaller than a certain specific size, thereby removing the noise points in the feature vector.

[0106] 7. Finally, output the feature vector.

[0107] Iris feature comparison is to compare the iris information extracted in the verification stage with the iris information stored on the ID card. Specifically, first calculate the number of non-zero elements between these two feature vectors through the np.count_nonzero function, that is, their Hamming distance. This distance can be used to measure the similarity of the two feature vectors. The smaller the distance, the higher their similarity. Within a certain threshold, it is judged as the same person, otherwise the verification fails. The iris feature comparison flow chart is shown in Figure 6.

[0108] III. Symmetric Encryption and Decryption Algorithm

[0109] Adopt the efficient and reliable encryption algorithm AES-256-CBC, with a key length of 256 bits, a block length of 128 bits, and a padding method of PKCS7Padding. When encrypting, it is necessary to set the key and IV (initialization vector). Among them, the key length is 256 bits, and the key is obtained from the string using the UTF8 character set encoding method. The IV uses a fixed byte array with a length of 16 as the initialization vector. When decrypting, the same key and IV are also required for decryption operations. In addition, this work creates a decryptor object through the createDecryptor() function and passes it into the TransformFinalBlock() function for decryption operations, ensuring the accuracy and reliability of encryption and decryption.

[0110] Decryption also uses the AES algorithm. During the decryption process, first convert the ciphertext string into a byte array, then create an AES decryptor object by using the Aes.Create() method, set the key length and block length to 256 bits and 128 bits, and set the key and initialization vector (IV), where the key and IV are obtained from a UTF-8 encoded string respectively. Then, create a decryptor object through the AES.CreateDecryptor() function, and then use the decryptr.TransformFinalBlock() function to decrypt the ciphertext to obtain the byte array of the plaintext. Finally, convert the byte array of the plaintext into a string and display it in the text box.

[0111] The First Embodiment

[0112] The card system can be applied to access control systems or other security devices. It is applicable to occasions where access control and access sharing are required. During (k,n) threshold group authentication, the legal user group is represented as (P1, P2, …, P k , …, P n ), and P * represents an illegal user. And this card system is applicable to the following application scenarios:

[0113] Example 1: When (P1, P2, …, P k-1 ) authenticate together, the authentication fails. When less than k users in the legal group come to authenticate, the authentication fails.

[0114] Example 2: When (P1, P2, …, P k-1 ) collude with an illegal user P * and authenticate together, the authentication fails. Additionally, when P * impersonates any user in the legal group to deceive other legal users into authenticating together, the authentication fails.

[0115] Example 3: When any k or more users in (P1, P2, …, P k , …, P n ) come to authenticate, the authentication is successful.

[0116] The Second Embodiment

[0117] Operating System: Windows 11.

[0118] Development Tools and Versions: Visual Studio 2022.

[0119] Programming Languages and Versions: C# 10.0, Python 3.7.0.

[0120] Dependency libraries and frameworks:.NET Framework 4.7.2,.NET Core 6.0, Opencv-python4.5.3.56, numpy 1.21.6, pytz 2023.3.

[0121] For the above group identification function, the implementation of the (2,3) threshold scheme is shown.

[0122] Table 2: (2,3) Threshold Scheme

[0123]

[0124]

[0125] The form for entering group permission information is as Figure 7 shown. According to the number of people entered, the threshold value is selected. Each threshold value provides five threshold features, and each threshold feature contains several underlying permission values. The underlying permission values are ultimately assigned to users. When the number of users meeting the threshold value jointly verifies, they provide their respective underlying permissions, thus generating a common permission feature. By comparing the permission features, we can determine whether the verification is successful.

[0126] The interface for encrypting basic information and generating a QR code is as Figure 8 shown. Click the encryption button to execute the program that integrates the entered name, gender, age, selected permissions, and extracted iris information into one segment and performs AES encryption. Click the generate QR code button to execute the program that encodes the AES information code into a QR code.

[0127] The interface for scanning the QR code, decrypting, and distributing information is as Figure 9 shown. After scanning the QR code on the identification card, the AES information code result will be displayed in the text box. At this time, enter the iris information and click the feature extraction button, and the iris feature value will be displayed in the text box. After clicking the decrypt button, the system will decrypt the AES information code and disassemble the information of name, gender, age, permissions, and iris feature value.

[0128] In summary, the present invention proposes a multi-person identity recognition system with access permission sharing and no storage; this system is a new type of identification card system based on iris feature comparison, with group identity recognition (group identification) function and without relying on database storage. Due to the security and scalability problems commonly existing in current identity authentication, the present invention proposes the group identification function according to actual needs and solves the security problem of storing private biological information in the database, which has important value for improving the security in the field of identity authentication.

[0129] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification. The above embodiments only represent several implementation manners of the present application, and the description is relatively specific and detailed, but it should not be understood as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A multi-person identity recognition system with access right sharing and no storage, characterized in that The system includes a front end and a back end; where: The front end includes two processes: interface design and event response. The interface design is used to implement user access and management operations, and the event response comes from the algorithms in the back end; The back end includes a card-making module and an authentication module; where: The card-making module is used to implement: iris collection and basic information collection of users, group permission entry, symmetric encryption, QR code encoding, and printing and card-making; Among them, iris collection is performed using an iris camera, printing and card-making are performed using a thermal printer, iris feature extraction is performed using an iris feature extraction algorithm, group permission setting is performed using a secret sharing algorithm, and symmetric encryption is performed using a symmetric encryption algorithm; The authentication module is used to implement: iris feature comparison, basic information comparison, group permission authentication, symmetric decryption, and QR code decoding; Among them, QR code decoding is performed using a QR code scanner, iris feature comparison is performed using an iris feature comparison algorithm, group permission authentication is performed using a secret recovery algorithm, and symmetric decryption is performed using a symmetric decryption algorithm.

2. The multi-person identity recognition system with access right sharing and no storage according to claim 1, characterized in that, In the back end of the system: When making a card, the card-making module collects information about the user group, including the basic information, permission information, and iris information of the user. The permission information includes the threshold, group, and shadow value. The iris information refers to the iris features obtained by extracting features from the collected user iris images. Various types of information collected are encrypted using symmetric encryption technology, encoded into a QR code, and the QR code and basic information are printed on the card to complete card-making; When authenticating, the authentication module performs the following operations on all users in the group to be authenticated in sequence: scans the QR code on the card they hold, decrypts the QR code using the symmetric key, and performs iris feature comparison, basic information comparison, and group permission authentication on the information therein respectively. When performing iris feature comparison, one of the iris features comes from the iris features after feature extraction of the iris information collected on-site from the users in the group to be authenticated.

3. A multi-person identity recognition system with access right sharing and no storage according to claim 2, characterized in that, Use an iris feature extraction algorithm to perform iris feature extraction; Specifically include: Read the iris image and convert the iris image into a grayscale image; Perform image preprocessing, including median filtering operation, Gaussian blur, and histogram equalization, to remove noise interference; Use the Hough transform to detect the inner circle and outer circle in the iris image, obtain the center coordinates and radius size, so as to further determine the position and size of the iris; Perform normalization processing, convert the polar coordinate diagram into a rectangular coordinate diagram, and adjust the size and position of the iris; Use wavelet transform or stationary wavelet transform to extract high-frequency coefficients, calculate the average value of each coefficient block, and binarize the average value of the high-frequency coefficients to obtain a feature vector. Remove noise points through morphological opening operation and output the feature vector.

4. A multi-person identity recognition system with access right sharing and no storage according to claim 3, characterized in that, Use an iris feature comparison algorithm to perform iris feature comparison; Specifically include: Compare the iris information extracted in the verification stage with the iris information saved on the card; Calculate the number of non-zero elements between the two feature vectors as the Hamming distance through the np.count_nonzero function, and this distance is used to measure the similarity degree of the two feature vectors; The smaller the distance, the higher the degree of similarity. If it is within a certain threshold, it is judged as the same person; otherwise, the verification fails.

5. A multi-person identity recognition system with access right sharing and no storage according to claim 2, characterized in that, Use the secret sharing algorithm to set group permissions; specifically including: The group identification function is implemented based on the polynomial-based secret sharing technology. Secret sharing means encrypting the secret information into multiple share values and distributing them to multiple participating parties. Only a subset of the authorized participating parties can decrypt, and the unauthorized set cannot decrypt; In (k,n) threshold secret sharing, the secret information is encrypted into n shadow images. If no less than k shadows are obtained, the original secret can be reconstructed; if less than k shadow images are obtained, no secret can be obtained, where k ≤ n; Embed the secret into a random polynomial of degree k - 1. Given the secret information s, share it into n share values sc1, sc2, …, sc n : Select a large prime number p such that p > n and p > s. Let GF(p) be a finite field, all elements are elements of GF(p), and all operations are performed in the finite field GF(p); In the sharing phase, s is encrypted into a shadow value sc i , a polynomial f(x) = a0 + a1x + … + a k-1 x k-1 ; Embed the secret s into the first coefficient of the polynomial, a0 = s, and the remaining coefficients a1, …, a k-1 Randomly select in the finite field GF(p), and calculate sc1 = f(1), …, sc k = f(k), …, sc n = f(n); Take (i, sc i ) as a shadow pair, where i is used as an information label or a serial number label, and sc i is used as a shadow pixel value. Distribute n shadow shares to n participants respectively to complete the secret sharing.

6. The multi-person identity recognition system with access right sharing and no storage according to claim 5, characterized in that, Use the secret recovery algorithm to perform group permission authentication; specifically including: In the secret recovery phase, obtain any k secret pairs among n participants Construct a system of linear equations: where i l (1 ≤ l ≤ k) are all different, and construct a polynomial by Lagrange interpolation formula: Obtain the secret s = f(0); Among them, if k - 1 participants obtain the secret, k - 1 equations are constructed to form a system of linear equations, where the k coefficients of the sharing polynomial are unknowns; and due to the different labels i l are different, each shadow share corresponds to a unique polynomial that satisfies the system of linear equations. Given k - 1 shadows, it is impossible to solve the system of linear equations with k unknowns, and thus no information about the secret can be obtained; Among them, for a legal group (P1, P2, …, P k , …, P n ), the (k, n) threshold group identification function means that when any k or more users in the legal group come to authenticate their identities simultaneously, the authentication is passed; when any fewer than k users in the legal group come to authenticate their identities simultaneously, the authentication fails. Additionally, when an illegal user P * outside the legal group participates in the authentication, the authentication also fails.

7. The multi-person identity recognition system with access right sharing and no storage according to claim 2, characterized in that Use the symmetric encryption algorithm for symmetric encryption; specifically including: Adopt the encryption algorithm AES-256-CBC, with a key length of 256 bits, a block length of 128 bits, and a padding method of PKCS7Padding; During encryption, set the key and the initialization vector IV. The key length is 256 bits. The key is obtained from the string using the UTF8 character set encoding method. The IV uses a byte array with a fixed length of 16 as the initialization vector; Create a decryptor object through the createDecryptor() function and pass it into the TransformFinalBlock() function for decryption operations.

8. A multi-person identity recognition system with access right sharing and no storage according to claim 7, characterized in that, Use the symmetric decryption algorithm for symmetric decryption; specifically including: The decryption also uses the AES algorithm. Convert the ciphertext string into a byte array. Create an AES decryptor object by using Aes.Create(). Set the key length and block length to 256 bits and 128 bits respectively. Set the key and the initialization vector (IV), where the key and IV are obtained by getting them from the UTF-8 encoded string respectively; Create a decryptor object through the AES.CreateDecryptor() function. Use the decryptr.TransformFinalBlock() function to decrypt the ciphertext to obtain the byte array of the plaintext. Convert the byte array of the plaintext into a string and display it in the text box.