A blockchain-based identity authentication method and system
By using multi-factor cross-validation that verifies biometrics and facial optical flow analysis on the user login page, combined with blockchain's hash encryption and dynamic security assessment, the problem of lagging risk assessment and misuse of user information in existing identity authentication methods is solved, thereby improving the security and accuracy of identity authentication and enabling proactive management of server information security.
Patent Information
- Application Number
- CN202510457094.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-13
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2045-04-13
AI Technical Summary
Existing identity authentication methods lack continuous monitoring of user behavior and device status, making it impossible to identify abnormal operations after authentication. This leads to delayed risk assessments, and the lack of effective oversight when user information is repeatedly submitted to different platforms makes it easy for the information to be abused.
By verifying the credibility of biometrics on the user login page, detecting facial video streams using optical flow analysis, calculating optical flow cosine similarity, and performing hash encryption on the blockchain, combined with multi-factor cross-validation and dynamic security assessment data, the system monitors the risks of the authentication server in real time, triggering abnormal risk alarms and security measures.
It improves the security and accuracy of identity authentication, enhances the protection of user information, monitors risk changes in real time by dynamically tracking server status, prevents security incidents, and improves the efficiency of server information security management.
Smart Images

Figure CN120342624B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of identity authentication security, more particularly, the present application relates to a blockchain-based identity authentication method and system. BACKGROUND
[0002] The blockchain adopts a distributed ledger structure, and data is stored in multiple nodes rather than a single centralized server. Once data is recorded on the blockchain, it is difficult to tamper with. This tamper-proof feature ensures the authenticity and integrity of user identity information, and through the traceability function, the source and change record of the information can be clearly understood.
[0003] With the acceleration of digitalization, various online businesses and services are booming, from social networks, online finance to government services, supply chain management, almost covering all aspects of people's lives. In this process, identity authentication, as a key link to ensure the security of information systems and confirm the legal identity of users, has become increasingly important.
[0004] However, in actual use, there are still some shortcomings, such as the existing identity authentication method mostly uses one-time verification, such as password login, lacks continuous monitoring of user behavior and device status, and cannot identify abnormal operations after authentication, resulting in lagging risk assessment.
[0005] In the existing identity authentication method, the user needs to repeatedly submit personal identity information when registering on different platforms. These information is independently stored and managed by each platform, and there is a lack of effective supervision mechanism, which leads to the user information being easily misused without authorization. SUMMARY
[0006] In order to overcome the above-mentioned defects of the prior art, the embodiments of the present application provide a blockchain-based identity authentication method and system to solve the problems raised in the background art.
[0007] To achieve the above-mentioned purpose, the present application provides the following technical scheme: a blockchain-based identity authentication method, comprising the following steps:
[0008] Step S01: User login request verification: used to verify the biological feature credibility of the user on the user login page, hash encrypt the biological feature credibility, and send it to the authentication server.
[0009] Step S02: User identity detection enhanced verification: based on optical flow analysis to detect user face video stream, extract the optical flow change matrix of continuous frames, calculate the face optical flow cosine similarity of the user, hash encrypt the face optical flow cosine similarity, and send it to the authentication server.
[0010] Step S03: User identity authentication anomaly control: used to verify user identity compliance through the authentication server, and trigger user identity authentication anomaly risk alarm.
[0011] Step S04: User access security assessment data collection: used to collect security assessment data of the authentication server in the blockchain network every j time period, and transmit the security assessment data to step S05.
[0012] Step S05: User access security analysis: used to receive the security assessment data transmitted by the user access security assessment data collection step, and calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period.
[0013] Step S06: User access security assessment: used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the server authentication access risk.
[0014] Preferably, the step S01: user login request verification specifically comprises:
[0015] Step S11: Collect the face recognition confidence and iris matching degree of the user login device when the user logs in the page, and mark them as , wherein i=1, 2,...n, i represents the number of the ith user login device;
[0016] Step S12: the calculation formula of the biological feature credibility is:
[0017]
[0018] wherein, represents the biological feature credibility of the ith user login device, represents the face recognition confidence of the ith user login device, represents the iris matching degree of the ith user login device, and e represents a natural constant;
[0019] Step S13: obtain the biological feature credibility of the user login device, and generate a new hash value to update to the blockchain.
[0020] Preferably, the step S02: user identity detection enhanced verification specifically comprises:
[0021] Step S21: collect the user face video stream of the user login device through the camera, extract the displacement vector between the continuous frames, and generate the optical flow change matrix of the continuous frames ;
[0022] Step S22: converting the optical flow change matrix of the continuous frames into an optical flow change vector ;
[0023] Step S23: the calculation formula of the face optical flow cosine similarity is:
[0024]
[0025] Wherein, represents the face optical flow cosine similarity of the i-th user login device, represents the optical flow change vector of the i-th user login device, represents the preset optical flow change vector;
[0026] Step S23: obtaining the face optical flow cosine similarity of the user login device, and generating a new hash value and updating to the blockchain.
[0027] Preferably, the step S03: user identity authentication exception control is specifically:
[0028] Step S31: extracting the biological feature credibility hash value of the user login device, Wherein t=1, 2,... m, t represents the number of the t-th hash value;
[0029] Step S32: extracting the face optical flow cosine similarity hash value of the user login device, ;
[0030] Step S33: verifying the user identity compliance by calculating the user identity compliance score index:
[0031]
[0032] Wherein, represents the user identity compliance score index of the t-th hash value of the i-th user login device, represents the biological feature credibility hash value of the t-th hash value of the i-th user login device, represents the biological feature credibility hash value of the t-1-th hash value of the i-th user login device, represents the face optical flow cosine similarity hash value of the t-th hash value of the i-th user login device, represents the face optical flow cosine similarity hash value of the t-1-th hash value of the i-th user login device;
[0033] Step S34: Obtain the latest user identity compliance score index of the authentication server, and compare it with the preset user identity compliance score index. If the latest user identity compliance score index is greater than the preset user identity compliance score index, it indicates that the user login identity authentication fails, and the user login page request is rejected. Otherwise, it indicates that the user login identity authentication succeeds, and step S04 is performed.
[0034] Preferably, the security evaluation data includes the number of users with failed identity authentication, the user identity authentication frequency, the number of user information tampering events, and the total number of user information query and modification.
[0035] Preferably, the calculation formula of the user authentication access risk assessment coefficient is:
[0036]
[0037] wherein, represents the user authentication access risk assessment coefficient of the u-th time period, represents the authentication server risk indicator of the u-th time period, represents the user information tampering risk rate of the u-th time period, represents the mean value of the authentication server risk indicator, represents the mean value of the user information tampering risk rate, , respectively represent the standard deviation of the authentication server risk indicator and the user information tampering risk rate;
[0038] Specifically, , , , wherein q represents the number of time periods.
[0039] Preferably, the user authentication access risk assessment coefficient is specifically:
[0040] Step S51: Calculate the authentication server risk indicator of each time period by the number of users with failed identity authentication and the user identity authentication frequency:
[0041]
[0042] wherein, represents the authentication server risk indicator of the u-th time period, represents the number of users with failed identity authentication of the u-th time period, represents the maximum value of the user identity authentication frequency, represents the maximum value of the number of users with failed identity authentication, j represents the interval time, and e represents the natural constant;
[0043] Step S52: Calculate the user information tampering risk rate of each time period by the number of user information tampering events, the total number of user information queries and modifications:
[0044]
[0045] wherein, represents the user information tampering risk rate of the u-th time period, represents the number of user information tampering events in the u-th time period, represents the total number of user information queries and modifications in the u-th time period.
[0046] Preferably, the step S06: user access security assessment is specifically:
[0047] Obtain the user authentication access risk assessment coefficient of the authentication server in the j-th time period of the blockchain network, and compare it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient of a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there is a security risk in the server authentication access of that time period, and the authentication server has weak protection ability for user information. Inform the management personnel to enhance the security protection measures of the authentication server and improve the user information protection ability. On the contrary, if the user authentication access risk assessment coefficient of a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access security of that time period is high, and the authentication server has strong protection ability for user information. It can continue to maintain the current security protection measures.
[0048] Preferably, a blockchain-based identity authentication system comprises:
[0049] A user login request verification module is used to verify the biological feature credibility of the user on the user login page, hash encrypt the biological feature credibility, and send it to the authentication server.
[0050] A user identity detection enhancement verification module is used to detect the user's face video stream based on optical flow analysis, extract the optical flow change matrix of consecutive frames, calculate the face optical flow cosine similarity of the user, hash encrypt the face optical flow cosine similarity, and send it to the authentication server.
[0051] A user identity authentication anomaly control module is used to verify the user identity compliance through the authentication server, and trigger the user identity authentication anomaly risk alarm.
[0052] A user access security assessment data collection module is used to collect the security assessment data of the authentication server in the blockchain network every j time periods, and transmit the security assessment data to the user access security analysis module.
[0053] User access security analysis module: used for calculating the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period through security evaluation data;
[0054] User access security evaluation module: used for obtaining the user authentication access risk assessment coefficient of the authentication server in the blockchain network in the jth time period, comparing with the preset user authentication access risk assessment coefficient, and monitoring the server authentication access risk.
[0055] Technical effects and advantages of the present application:
[0056] 1. The identity authentication method and system based on the blockchain provided by the present application, by collecting the face recognition confidence and the iris matching degree of the user login device when the user logs in, verifying the biological feature credibility of the user, hashing and encrypting the biological feature credibility, and sending it to the authentication server, through the camera to collect the user face video stream of the user login device, extract the displacement vector between the continuous frames, generate the optical flow change matrix of the continuous frames, convert the optical flow change matrix of the continuous frames into the optical flow change vector, calculate the face optical flow cosine similarity of the user, hash and encrypt the face optical flow cosine similarity, and send it to the authentication server, and then calculate the user identity compliance score index, verify the user identity compliance, and trigger the user identity authentication abnormal risk alarm, which is beneficial to improve the security of user identity verification through multi-factor cross verification, improve the authentication accuracy, is beneficial to the transmission through the hash encryption, so that the attacker is difficult to restore the original information from the encrypted data, provides reliable protection for the security of data transmission, and further enhances the security of identity authentication;
[0057] 2、The application provides a kind of based on blockchain's identity authentication method and system, the security evaluation data of authentication server in blockchain network is collected every j Time period, and the user authentication access risk assessment coefficient of authentication server in the j Time period of blockchain network is calculated, compared with the preset user authentication access risk assessment coefficient, if the user authentication access risk assessment coefficient of a time period is greater than the preset user authentication access risk assessment coefficient, it indicates that the server authentication access in this time period has security risk, the protection ability of authentication server to user information is weak, notify management personnel to enhance the security protection measures of authentication server, improve user information protection ability, otherwise, if the user authentication access risk assessment coefficient of a time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the security of the server authentication access in this time period is higher, the protection ability of authentication server to user information is strong, can continue to maintain the current security protection measures, it is favorable to the dynamic tracking of the running state of authentication server, the change of server authentication access risk is monitored in real time, so as to take targeted measures to solve the problem, effectively prevent the occurrence of security event, through the active monitoring of server authentication access risk, improve the efficiency of server authentication access risk management, enhance the initiative of server user information security management, protect user information security, promote the wide application of blockchain technology. BRIEF DESCRIPTION OF DRAWINGS
[0058] Figure 1 It is the flowchart of the application based on blockchain's identity authentication method.
[0059] Figure 2 It is the structure diagram of the application based on blockchain's identity authentication system. DETAILED DESCRIPTION
[0060] The technical solutions in the embodiments of the application will be described clearly and completely below with the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, not all. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the application.
[0061] Please refer to Figure 1 The application provides a kind of based on blockchain's identity authentication method, including the following steps:
[0062] The step S01: user login request verification: for verifying the biological characteristic credibility of user in user login page, the biological characteristic credibility is hashed and encrypted, and sent to authentication server.
[0063] In a possible design, the step S01: user login request verification is specifically:
[0064] Step S11: Collect the face recognition confidence and the iris matching degree of the user login device when the user logs in the page, and mark them as and respectively 、 , wherein i = 1, 2,... n, i represents the number of the i-th user login device;
[0065] Step S12: The calculation formula of the biometric credibility is:
[0066]
[0067] , wherein, represents the biometric credibility of the i-th user login device, represents the face recognition confidence of the i-th user login device, represents the iris matching degree of the i-th user login device, and e represents a natural constant;
[0068] Step S13: Obtain the biometric credibility of the user login device, and generate a new hash value and update it to the blockchain.
[0069] The step S02: user identity detection enhanced verification: detecting the user's face video stream based on optical flow analysis, extracting the optical flow change matrix of consecutive frames, calculating the face optical flow cosine similarity of the user, hashing the face optical flow cosine similarity, and sending it to the authentication server.
[0070] In a possible design, the step S02: user identity detection enhanced verification is specifically:
[0071] Step S21: Collect the user's face video stream of the user login device through the camera, extract the displacement vector between consecutive frames, and generate the optical flow change matrix of consecutive frames ;
[0072] Step S22: Convert the optical flow change matrix of consecutive frames into an optical flow change vector ;
[0073] Step S23: The calculation formula of the face optical flow cosine similarity is:
[0074]
[0075] , wherein, represents the face optical flow cosine similarity of the i-th user login device, represents the optical flow change vector of the i-th user login device, represents a preset optical flow change vector;
[0076] Step S23: obtaining the face optical flow cosine similarity of the user login device, and generating a new hash value and updating to the blockchain.
[0077] The step S03: user identity authentication anomaly control is used to verify the user identity compliance through the authentication server, and trigger the user identity authentication anomaly risk alarm.
[0078] In a possible design, the step S03: user identity authentication anomaly control is specifically:
[0079] Step S31: extracting the biometric feature credibility hash value of the user login device, Wherein t=1, 2,...m, t represents the number of the tth hash value;
[0080] Step S32: extracting the face optical flow cosine similarity hash value of the user login device, ;
[0081] Step S33: verifying the user identity compliance by calculating the user identity compliance score index:
[0082]
[0083] Wherein, The user identity compliance score index of the tth hash value of the ith user login device, The biometric feature credibility hash value of the tth hash value of the ith user login device, The biometric feature credibility hash value of the t-1th hash value of the ith user login device, The face optical flow cosine similarity hash value of the tth hash value of the ith user login device, The face optical flow cosine similarity hash value of the t-1th hash value of the ith user login device;
[0084] Step S34: obtaining the latest user identity compliance score index of the authentication server, and comparing it with the preset user identity compliance score index, if the latest user identity compliance score index is greater than the preset user identity compliance score index, it indicates that the user login identity verification fails, then the user login page request is rejected, otherwise, it indicates that the user login identity verification is successful, then step S04 is executed.
[0085] The present application provides another specific embodiment, specifically as follows:
[0086] The user identity compliance score index reflects the dynamic change degree of the user biometric feature and the face optical flow data, the higher the index, the greater the possibility of user identity authentication anomaly;
[0087] Step S1: The current face optical flow cosine similarity hash value of a user logging into a device is 120, and the last face optical flow cosine similarity hash value is 100;
[0088] Step S2: The current face optical flow cosine similarity hash value of a user logging into a device is 70, and the last face optical flow cosine similarity hash value is 80;
[0089] Step S3: Calculate the user identity compliance score index:
[0090]
[0091] Step S4: Set the preset user identity compliance score index to 1.0. Since 1.34>1.0, it indicates that the user login identity verification fails, and the user login page request is rejected.
[0092] The step S04: User access security assessment data collection: used for collecting security assessment data of the authentication server in the blockchain network every j time period, and transmitting the security assessment data to the step S05.
[0093] In a possible design, the security assessment data includes the number of identity verification failed users, the user identity verification frequency, the number of user information tampering events, and the total number of user information query and modification.
[0094] The step S05: User access security analysis: used for receiving the security assessment data transmitted by the user access security assessment data collection step, and calculating the user authentication access risk assessment coefficient of the authentication server in the jth time period of the blockchain network.
[0095] In a possible design, the step S05: user access security analysis is specifically:
[0096] Step S51: Calculate the authentication server risk index of each time period by the number of identity verification failed users and the user identity verification frequency:
[0097]
[0098] Wherein, represents the authentication server risk index of the u th time period, represents the number of identity verification failed users in the u th time period, represents the maximum value of the user identity verification frequency, represents the maximum value of the number of identity verification failed users, j represents the interval time, and e represents the natural constant;
[0099] Step S52: Calculate the user information tampering risk rate of each time period by the number of user information tampering events, the total number of user information queries and modifications:
[0100]
[0101] wherein, represents the user information tampering risk rate of the u-th time period, represents the number of user information tampering events in the u-th time period, represents the total number of user information queries and modifications in the u-th time period;
[0102] Step S53: The calculation formula of the user authentication access risk assessment coefficient is:
[0103]
[0104] wherein, represents the user authentication access risk assessment coefficient of the u-th time period, represents the mean value of the authentication server risk index, represents the mean value of the user information tampering risk rate, , respectively represent the standard deviation of the authentication server risk index and the user information tampering risk rate;
[0105] Step S54: , , , wherein, q represents the number of time periods;
[0106] The step S06: user access security assessment is used to obtain the user authentication access risk assessment coefficient of the authentication server in the j-th time period of the blockchain network, compare it with the preset user authentication access risk assessment coefficient, and monitor the server authentication access risk.
[0107] In one possible design, the step S06: user access security assessment is specifically:
[0108] The user authentication access risk evaluation coefficient of the authentication server in the blockchain network in the jth time period is obtained, and is compared with the preset user authentication access risk evaluation coefficient. If the user authentication access risk evaluation coefficient of a time period is greater than the preset user authentication access risk evaluation coefficient, it indicates that the server authentication access in the time period has a security risk, the protection ability of the authentication server for user information is weak, the management personnel is notified to enhance the security protection measures of the authentication server, and the user information protection ability is improved. Otherwise, if the user authentication access risk evaluation coefficient of a time period is less than or equal to the preset user authentication access risk evaluation coefficient, it indicates that the security of the server authentication access in the time period is high, the protection ability of the authentication server for user information is strong, and the current security protection measures can be maintained.
[0109] Referring to Figure 2 The identity authentication system based on the blockchain provided by the application comprises:
[0110] The user login request verification module is used for verifying the biological feature credibility of the user on a user login page, performing hash encryption on the biological feature credibility, and sending the biological feature credibility to the authentication server.
[0111] The user identity detection enhancement verification module is used for detecting a user face video stream based on optical flow analysis, extracting an optical flow change matrix of continuous frames, calculating a face optical flow cosine similarity of the user, performing hash encryption on the face optical flow cosine similarity, and sending the face optical flow cosine similarity to the authentication server.
[0112] The user identity authentication abnormality control module is used for verifying the user identity compliance through the authentication server, and triggering a user identity authentication abnormality risk alarm.
[0113] The user access security evaluation data collection module is used for collecting security evaluation data of the authentication server in the blockchain network every j time periods, and transmitting the security evaluation data to the user access security analysis module.
[0114] The user access security analysis module is used for calculating the user authentication access risk evaluation coefficient of the authentication server in the blockchain network in the jth time period through the security evaluation data.
[0115] The user access security evaluation module is used for obtaining the user authentication access risk evaluation coefficient of the authentication server in the blockchain network in the jth time period, comparing the user authentication access risk evaluation coefficient with the preset user authentication access risk evaluation coefficient, and monitoring the server authentication access risk.
[0116] In the embodiment, it is particularly pointed out that the application collects the face recognition confidence and the iris matching degree of the user login device when the user logs in the page, verifies the biological feature credibility of the user, performs hash encryption on the biological feature credibility, and sends it to the authentication server, collects the user face video stream of the user login device through the camera, extracts the displacement vector between the continuous frames, generates the optical flow change matrix of the continuous frames, converts the optical flow change matrix of the continuous frames into an optical flow change vector, calculates the face optical flow cosine similarity of the user, performs hash encryption on the face optical flow cosine similarity, and sends it to the authentication server, and then verifies the user identity compliance by calculating the user identity compliance score index, and triggers the user identity authentication abnormal risk alarm, which is beneficial to improve the security of user identity authentication through multi-factor cross verification, improve the authentication accuracy, is beneficial to the transmission through the hash encryption, so that the attacker is difficult to restore the original information from the encrypted data, provides reliable protection for data transmission security, and further enhances the security of identity authentication;
[0117] The application collects the security evaluation data of the authentication server in the blockchain network every j time period, calculates the user authentication access risk evaluation coefficient of the authentication server in the j time period of the blockchain network, compares it with the preset user authentication access risk evaluation coefficient, if the user authentication access risk evaluation coefficient of a certain time period is greater than the preset user authentication access risk evaluation coefficient, it indicates that the server authentication access in the time period has security risks, the protection ability of the authentication server for user information is weak, the management personnel is informed to enhance the security protection measures of the authentication server, improve the user information protection ability, otherwise, if the user authentication access risk evaluation coefficient of a certain time period is less than or equal to the preset user authentication access risk evaluation coefficient, it indicates that the server authentication access in the time period is safe, the protection ability of the authentication server for user information is strong, the current security protection measures can be continued, which is beneficial to dynamically track the running state of the authentication server, monitor the change of the server authentication access risk in real time, so as to take targeted measures to solve the problem, effectively prevent the occurrence of security events, through the active monitoring of the server authentication access risk, improve the server authentication access risk management efficiency, enhance the initiative of server user information security management, protect the security of user information, and promote the wide application of blockchain technology.
[0118] Finally: the above only describes the preferred embodiments of the application and is not used to limit the application, any modification, equivalent replacement, improvement, etc. within the spirit and principles of the application should be included in the protection scope of the application.
Claims
1. A blockchain-based identity authentication method, characterized in that, Includes the following steps: Step S01: User login request verification: This step verifies the credibility of the user's biometrics on the user login page, hashes and encrypts the biometrics, and sends it to the authentication server. Step S02: Enhanced verification of user identity detection: Based on optical flow analysis, detect the user's facial video stream, extract the optical flow change matrix of consecutive frames, calculate the cosine similarity of the user's facial optical flow, hash and encrypt the facial optical flow cosine similarity, and send it to the authentication server. Step S03: User identity authentication anomaly control: used to verify the compliance of user identity through the authentication server and trigger a user identity authentication anomaly risk alarm; Step S04: User access security assessment data collection: This step collects security assessment data from the authentication server in the blockchain network every j time intervals and transmits the security assessment data to step S05. Step S05: User Access Security Analysis: This step receives the security assessment data transmitted from the user access security assessment data collection step and calculates the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period. Step S06: User Access Security Assessment: This step is used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the server authentication access risk.
2. The blockchain-based identity authentication method according to claim 1, characterized in that: Step S01: User login request verification specifically includes: Step S11: When logging into the user's login page, collect the face recognition confidence score and iris matching score of the user's login device, and label them as follows: , , where i = 1, 2, ..., n, and i represents the number of the i-th user's login device; Step S12: The formula for calculating the reliability of the biometrics is as follows: in, Let represent the biometric credibility of the device logged in by the i-th user. Let represent the confidence score of the face recognition on the device logged in by the i-th user. Let represent the iris matching score of the i-th user's login device, and e represent the natural constant. Step S13: Obtain the biometric credibility of the user's login device and generate a new hash value to update the blockchain.
3. The blockchain-based identity authentication method according to claim 1, characterized in that: Step S02: Enhanced verification of user identity detection specifically includes: Step S21: Capture the user's facial video stream from the camera, extract the displacement vectors between consecutive frames, and generate the optical flow variation matrix for consecutive frames. ; Step S22: Convert the optical flow variation matrix of consecutive frames into optical flow variation vectors. ; Step S23: The formula for calculating the facial optical flow cosine similarity is: in, Let be the facial optical flow cosine similarity of the i-th user's logged-in device. Let the optical flow change vector of the i-th user's logged-in device be represented as . Represented as a preset optical flow variation vector; Step S23: Obtain the facial optical flow cosine similarity of the user's login device and generate a new hash value to update the blockchain.
4. The blockchain-based identity authentication method according to claim 3, characterized in that: Step S03: User authentication anomaly control specifically includes: Step S31: Extract the biometric credibility hash value of the user's login device. , where t=1,2,...m, and t represents the number of the t-th hash value; Step S32: Extract the facial optical flow cosine similarity hash value of the user's logged-in device. ; Step S33: Verify user identity compliance by calculating the user identity compliance score index. in, The user identity compliance score index is represented by the hash value of the t-th device logged in by the i-th user. This represents the biometric credibility hash value of the t-th hash value of the ith user's login device. The biometric credibility hash value is represented by the (t-1)th hash value of the device logged in by the i-th user. The facial optical flow cosine similarity hash value is represented by the hash value of the t-th hash value of the ith user's login device. The facial optical flow cosine similarity hash value is represented by the hash value of the (t-1)th hash value of the device logged in by the i-th user. Step S34: Obtain the latest user identity compliance score index from the authentication server and compare it with the preset user identity compliance score index. If the latest user identity compliance score index is greater than the preset user identity compliance score index, it indicates that the user login authentication has failed, and the user login page request is rejected. Otherwise, it indicates that the user login authentication has succeeded, and step S04 is executed.
5. The blockchain-based identity authentication method according to claim 1, characterized in that: The security assessment data includes the number of users whose authentication failed, the frequency of user authentication, the number of user information tampering events, and the total number of user information queries and modifications.
6. The blockchain-based identity authentication method according to claim 1, characterized in that: The formula for calculating the user authentication access risk assessment coefficient is as follows: in, This represents the user authentication access risk assessment coefficient for the u-th time period. This represents the authentication server risk index for the u-th time period. This represents the user information tampering risk rate in the u-th time period. This represents the average risk index of the authentication server. This represents the average risk rate of user information tampering. , These are the standard deviations of the authentication server risk index and the user information tampering risk rate, respectively. Specifically, , , , , where q represents the number of time periods.
7. The blockchain-based identity authentication method according to claim 6, characterized in that: The user authentication access risk assessment coefficient is specifically as follows: Step S51: Calculate the authentication server risk indicators for each time period based on the number of users with failed authentication and the frequency of user authentication. in, This represents the authentication server risk index for the u-th time period. This represents the number of users whose authentication failed during the u-th time period. This represents the maximum frequency of user authentication. This represents the maximum number of users whose authentication failed, j represents the interval time, and e represents the natural constant. Step S52: Calculate the user information tampering risk rate for each time period based on the number of user information tampering events and the total number of user information queries and modifications. in, This represents the user information tampering risk rate in the u-th time period. This represents the number of user information tampering events that occurred in the u-th time period. This represents the total number of user information queries and modifications during the u-th time period.
8. The blockchain-based identity authentication method according to claim 1, characterized in that: Step S06: User access security assessment specifically includes: Obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period, and compare it with the preset user authentication access risk assessment coefficient. If the user authentication access risk assessment coefficient for a certain time period is greater than the preset user authentication access risk assessment coefficient, it indicates that there is a security risk in server authentication access during that time period, and the authentication server's ability to protect user information is weak. The administrator is notified to strengthen the security protection measures of the authentication server and improve the user information protection capability. Conversely, if the user authentication access risk assessment coefficient for a certain time period is less than or equal to the preset user authentication access risk assessment coefficient, it indicates that the server authentication access security during that time period is high, and the authentication server's ability to protect user information is strong. The current security protection measures can be maintained.
9. A blockchain-based identity authentication system, using a blockchain-based identity authentication method as described in any one of claims 1-8, characterized in that: include: User login request verification module: used to verify the credibility of the user's biometric features on the user login page, hash and encrypt the biometric feature credibility, and send it to the authentication server; The enhanced verification module for user identity detection detects user facial video streams based on optical flow analysis, extracts the optical flow change matrix of consecutive frames, calculates the cosine similarity of the user's facial optical flow, hashes and encrypts the facial optical flow cosine similarity, and sends it to the authentication server. User authentication anomaly control module: used to verify user identity compliance through the authentication server and trigger user authentication anomaly risk alarm; User access security assessment data collection module: used to collect security assessment data of the authentication server in the blockchain network every j time intervals, and transmit the security assessment data to the user access security analysis module; User access security analysis module: used to calculate the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period using security assessment data; User access security assessment module: used to obtain the user authentication access risk assessment coefficient of the authentication server in the blockchain network during the j-th time period, compare it with the preset user authentication access risk assessment coefficient, and monitor the server authentication access risk.
Citation Information
Patent Citations
Science and technology service platform cross-domain identity authentication scheme based on a block chain
CN113676447A
Zero-trust network access control method and system based on time window dynamic switching
CN116545731A