Security authentication method and device based on biological recognition and data synchronization

Through the multimodal biometrics and distributed authentication network combined with blockchain technology, the security authentication and data synchronization problems of distributed devices are solved, efficient and secure authentication and data synchronization are achieved, and security and data consistency between devices are improved.

CN120358104AActive Publication Date: 2025-07-22WEAPON EQUIP RES INST OF CHINA NAT WEAPON EQUIP GRP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510864950.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-07-22
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

In the prior art, the security authentication method of distributed devices is easily cracked, the accuracy of a single biometric technology is unstable, and data synchronization depends on the central server to have the risk of privacy leakage and single point of failure, and synchronization is inefficient.

Method used

Multimodal biometric fusion technology is adopted, combined with distributed authentication network and blockchain technology, through multi-level recognition of facial features, iris features and voice features, and using consensus algorithms and blockchain network to verify data synchronization to ensure the security of authentication and the consistency of data.

Benefits of technology

Improve the accuracy and security of certification, reduce the risk of single point of failure, realize efficient data synchronization, and ensure the consistency and reliability of data between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358104A_ABST
    Figure CN120358104A_ABST
Patent Text Reader

Abstract

The invention discloses a security authentication method and device based on biological recognition and data synchronization, and belongs to the technical field of information security. The method comprises the following steps: performing multi-level identification on user characteristics; after the identification is passed, the distributed device opens an access permission to the user, but does not open all permissions to the user; the distributed device sends authentication information to all authentication nodes in the distributed authentication network; each authentication node verifies the authentication information based on verification information and verification rules stored in the authentication node; and the verification result of each authentication node is calculated by a consensus algorithm to obtain a verification result of the distributed authentication network, and when the verification result of the distributed authentication network is that the verification is passed, the distributed device opens all permissions to the user. According to the method, multi-mode biological recognition fusion is adopted, operation is more convenient, and user data and equipment safety are effectively protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a security authentication method and device based on biometric recognition and data synchronization. Background Art

[0002] With the wide application of distributed devices, how to ensure secure authentication and efficient data synchronization between these devices has become an urgent problem to be solved. In the prior art, secure authentication of distributed devices mostly uses single password authentication, digital certificate authentication or single biometric technology for secure authentication. Data synchronization usually relies on a central server for centralized management, or is manually or periodically synchronized through specific synchronization software. Common ones include centralized synchronization based on cloud servers or simple peer-to-peer synchronization.

[0003] Single password authentication is easy to be guessed or cracked; digital certificate management is complex and may be forged, with insufficient security; single biometric technology may have a high authentication failure rate due to environmental factors or individual differences. For example, fingerprint recognition authentication may be affected by fingerprint wear, stains, etc., resulting in unstable recognition accuracy.

[0004] Centralized synchronization based on cloud servers has the risk of data privacy leakage and strong dependence on the server. Centralized server synchronization has the risk of single point of failure, and when the server fails or the network is congested, data synchronization will be seriously affected. Manual or periodic synchronization methods are inefficient, and are prone to omissions and errors, unable to ensure the real-time and accuracy of data, and have high requirements for user operations. Peer-to-peer synchronization may have synchronization interruptions or data inconsistencies.

[0005] It can be seen that traditional authentication methods may have problems such as being maliciously attacked, identity theft, and cumbersome operations. At the same time, data synchronization also faces challenges such as low efficiency and error-proneness. Summary of the Invention

[0006] The present invention proposes a security authentication method and device based on biometric recognition and data synchronization to solve the technical problems existing in traditional authentication methods such as being maliciously attacked, identity theft, and cumbersome operations, and at the same time, the technical problems of low efficiency and error-proneness faced by data synchronization.

[0007] The first aspect of the present invention proposes a security authentication method based on biometric recognition and data synchronization, and the method includes: Recognition stage: When a user uses a distributed device, the distributed device collects the user's facial features, iris features and voice features; The first model is used to recognize the facial features; In response to the successful recognition of facial features by the first model, the second model recognizes the first fused feature after fusing the facial features and iris features; In response to the successful recognition of the first fused feature by the second model, the third model recognizes the second fused feature after fusing the facial features, iris features and voice features; In response to the successful recognition of the second fused feature by the third model, the distributed device grants the access permission among all permissions to the user and retains other permissions; Authentication stage: The distributed device sends authentication information to all authentication nodes in the distributed authentication network. The authentication information includes the identifier of the distributed device, the facial features, iris features and voice features of the user; Each authentication node verifies the authentication information based on the verification information and verification rules stored in itself; the consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network; In response to the verification result of the distributed authentication network being verified successfully, the distributed device grants all permissions to the user; Send the updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the successful verification by the blockchain network, other distributed devices in the blockchain network update their locally stored data based on the updated data.

[0008] Preferably, each authentication node verifies the authentication information based on the verification information and verification rules stored in itself, where The verification information includes: user information, distributed device information, biometric data, distributed device trust graph, environmental parameters; The user information includes the username and user identifier; The distributed device information includes the device identification code, the registration time of the distributed device and the registration location of the distributed device; The biometric data includes the facial feature template, iris feature template, voice feature template, dynamic change model of the user's biometrics and the behavior pattern of the user operating the distributed device. The dynamic change model of the user's biometrics includes the facial micro-expression time series data, the iris texture change prediction model with age and the adaptive offset curve of the voice frequency with environmental noise; The distributed device trust graph is constructed based on the login period of the distributed device, the geographical location trajectory, the connection records between multiple distributed devices and the connection strength at the time of connection; The environmental parameters include a geographical fence and an environmental fingerprint. The geographical fence is the geographical area where the distributed device is allowed to be located, and the environmental fingerprint is the environmental characteristics of the environment where the distributed device is allowed to be located, the time entropy value table of the distributed device, and the time entropy value table is a record table storing the time rules of the user operating the distributed device.

[0009] Preferably, each authentication node verifies the authentication information based on the verification information and verification rules stored in itself, wherein the verification rules include: Rule 1: The facial features, iris features, and voice features of the user are collected within the same time window, and the time stamp difference of the collection of the facial features, iris features, and voice features is less than a preset threshold; when the distributed device is in an unfamiliar geographical location and / or during a non-prescribed access time period, secondary confirmation of the iris features is enabled, or the user is required to speak a dynamically generated random verification code through voice; Rule 2: When the distributed device has changed its IP address and / or logged in across regions within a time period less than a first preset time period from the current access time, gesture password verification is added or other verified distributed devices perform linkage verification on this distributed device; Rule 3: When the deviation between the current environmental parameters and the environmental parameters corresponding to the distributed device at the time of successful verification exceeds a second preset threshold, SMS verification code verification is triggered; when the deviation between the current access time and the record in the time entropy value table is greater than a third preset threshold, user liveness detection and iris feature recognition of the user are performed.

[0010] Preferably, a consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network. In response to the verification result of the distributed authentication network being verified successfully, all permissions of the distributed device are opened to the user, including: Step S21: The verification results corresponding to each authentication node are recorded and propagated through a distributed ledger, and a consensus algorithm is used to generate the verification result of the distributed authentication network; the consensus algorithm is PBFT or PoS; Step S22: In response to the verification result of the distributed authentication network being verified successfully, all permissions of the distributed device are opened to the user; in response to the verification result of the distributed authentication network being verified unsuccessfully, the method ends.

[0011] Preferably, the updated data in the distributed device is sent to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; in response to the blockchain network verifying successfully, other distributed devices in the blockchain network update their locally stored data based on the updated data, including: Step S23: After the user's access is completed, determine the data that has been updated in the distributed device; the distributed device sends a data update request to the blockchain network to which the distributed device belongs, and the data update request includes the updated data, the identifier of the distributed device, and the timestamp when the updated data is generated; Step S24: The smart contract in the blockchain network verifies the data update request according to preset data synchronization rules and data consistency verification rules. The verification content includes the data format of the updated data, whether the distributed device deploying the updated data is legal, and whether the updated data conflicts with the data stored in other distributed devices; in response to the smart contract verification passing, proceed to Step S25, otherwise, the method ends; Step S25: Broadcast the data update request to each other distributed device in the blockchain network, and other distributed devices update their locally stored data based on the updated data.

[0012] A second aspect of the present invention proposes a security authentication device based on biometric recognition and data synchronization, and the device includes: Recognition module: configured to collect the user's facial features, iris features, and voice features by the distributed device when the user uses the distributed device; Recognize the facial features by the first model; In response to the recognition of the facial features by the first model passing, recognize the first fusion feature after fusing the facial features and iris features by the second model; In response to the recognition of the first fusion feature by the second model passing, recognize the second fusion feature after fusing the facial features, iris features, and voice features by the third model; In response to the recognition of the second fusion feature by the third model passing, the distributed device grants the access permission in all permissions to the user and retains other permissions; Authentication module: configured to send authentication information to all authentication nodes in the distributed authentication network by the distributed device, and the authentication information includes the identifier of the distributed device, the user's facial features, iris features, and voice features; Each authentication node verifies the authentication information based on the verification information and verification rules stored in itself; calculate the verification results of each authentication node by the consensus algorithm to obtain the verification result of the distributed authentication network; In response to the verification result of the distributed authentication network being verified and passed, the distributed device grants all permissions to the user; Send the data updated in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the successful verification by the blockchain network, other distributed devices in the blockchain network update the data stored locally based on the updated data.

[0013] The third aspect of the present invention provides an electronic device, which includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method as described above.

[0014] The fourth aspect of the present invention provides a non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to cause the computer to execute the method as described above.

[0015] The present invention has the following technical effects: (1) The present invention adopts the fusion of multi-modal biometric recognition, and users do not need to remember complex passwords, making the operation more convenient; since biometric authentication methods are difficult to crack and forge, it effectively protects the security of user data and devices.

[0016] (2) The distributed security authentication architecture of the present invention improves the reliability and availability of data, avoiding the risk of single-point failure; the construction of an encrypted P2P network and the design of a communication protocol improve the security authentication level of distributed devices and reduce the risk of being attacked and misused.

[0017] (3) The data synchronization mechanism based on the blockchain in the present invention realizes efficient data synchronization, and the real-time synchronization technology ensures that the data between devices is always consistent, improving work efficiency. Description of the Drawings

[0018] Figure 1 It is a schematic flowchart of the security authentication method based on biometric recognition and data synchronization of the present invention; Figure 2 It is a schematic structural diagram of the security authentication device based on biometric recognition and data synchronization of the present invention. Detailed Embodiments

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts shall fall within the scope of protection of the present disclosure.

[0020] As shown in Figure 1 the figure, the present invention provides a security authentication method based on biometric recognition and data synchronization, and the method includes: Recognition stage: When a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features; The first model is used to recognize the facial features; In response to the recognition of the facial features by the first model passing, the second model is used to recognize the first fusion feature after fusing the facial features and the iris features; In response to the recognition of the first fusion feature by the second model passing, the third model is used to recognize the second fusion feature after fusing the facial features, iris features, and voice features; In response to the recognition of the second fusion feature by the third model passing, the distributed device grants the user access rights among all permissions and retains other permissions; Authentication stage: The distributed device sends authentication information to all authentication nodes in the distributed authentication network, and the authentication information includes the identifier of the distributed device, the user's facial features, iris features, and voice features; Each authentication node verifies the authentication information based on the verification information and verification rules stored in itself; a consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network; In response to the verification result of the distributed authentication network being verified successfully, the distributed device grants all permissions to the user; Send the updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verifying successfully, other distributed devices in the blockchain network update their locally stored data based on the updated data.

[0021] Regularly update and optimize the first model, the second model, and the third model to adapt to environmental changes and changes in user characteristics.

[0022] In the present invention, the first model, the second model, and the third model are all conventional neural network models in the art. Sensors are provided on the distributed device to collect the user's facial features, iris features, and voice features. When the recognition by the first model fails, the method ends; when the verification by the second model fails, the method ends; when the recognition by the third model fails, the method ends.

[0023] Further, each authentication node verifies the authentication information based on the verification information and verification rules stored in itself, wherein, The verification information includes: user information, distributed device information, biometric data, distributed device trust graph, and environmental parameters; User information includes username and user identification; Distributed device information includes device identification code, distributed device registration time, and distributed device registration location; Biometric data includes facial feature template, iris feature template, voice feature template, dynamic change model of user biometrics, and behavior pattern of the user operating the distributed device. The dynamic change model of user biometrics includes facial micro-expression time series data, iris texture change prediction model with age, and adaptive offset curve of voice frequency with environmental noise; The distributed device trust graph is constructed based on the login period, geographical location trajectory, connection records between multiple distributed devices, and connection strength at the time of connection; Environmental parameters include geographical fence and environmental fingerprint. The geographical fence is the geographical area where the distributed device is allowed to be located, and the environmental fingerprint is the environmental characteristics of the environment where the distributed device is allowed to be located, the time entropy value table of the distributed device. The time entropy value table is a record table storing the time pattern of the user operating the distributed device.

[0024] In the present invention, the user information includes username, user identification, and personal information filled in by the user during registration, such as name, contact information, etc., which is used to assist in verifying the authenticity of the user identity.

[0025] Distributed device information includes device identification code, distributed device registration time, and distributed device registration location. The device identification code is the unique identification code of the distributed device, such as IMEI, MAC address, etc. The distributed device registration time and distributed registration location are used as the basis for verifying whether the distributed device is normally registered and used.

[0026] Biometric data includes facial feature template, iris feature template, voice feature template, dynamic change model of user biometrics, and behavior pattern of the user operating the distributed device. The dynamic change model of user biometrics includes facial micro-expression time series data, iris texture change prediction model with age, and adaptive offset curve of voice frequency with environmental noise; The behavior pattern of the user operating the distributed device, such as touch screen pressure distribution, typing rhythm, is used as the cross-verification basis for the behavior and physiological characteristics of the user operating the distributed device.

[0027] The distributed device trust graph is constructed based on the login time period of distributed devices, geographical location trajectories, connection records between multiple distributed devices, and connection strength during connection. For example, it is constructed based on the user's common login time period, geographical location trajectory, software installation records, and historical security events (intrusion records, abnormal login records), the distributed device groups bound to the distributed device, the collaborative operation history between multiple distributed devices, and the connection strength between multiple distributed devices during connection (such as data interaction frequency, duration, and encrypted transmission success rate).

[0028] The environmental parameters include geographical fences and environmental fingerprints, including the geographical areas and environmental characteristics where the distributed device is allowed to be located, and the time entropy value table, which is a record table storing the time rules of the user's operation of the distributed device. The content stored in the time entropy value table is, for example, the distribution of usage time periods on weekdays and / or weekends, and the time interval threshold for high-frequency operations.

[0029] Each of the authentication nodes verifies the authentication information based on the verification information and verification rules stored by itself, where the verification rules include: Rule 1: The facial features, iris features, and voice features of the user are collected within the same time window, and the time stamp difference of the collection of facial features, iris features, and voice features is less than a preset threshold; when the distributed device is in an unfamiliar geographical location and / or during a non-prescribed access time period, secondary confirmation of iris features is enabled, or the user is required to speak a dynamically generated random verification code through voice. Rule 2: When the distributed device has changed its IP address and / or logged in across regions within a time period less than the first preset time period from the current access time, gesture password verification is added or the distributed device is verified in a linked manner by other distributed devices that have passed the verification. Rule 3: When the deviation between the current environmental parameters and the environmental parameters corresponding to the distributed device at the time of successful verification exceeds the second preset threshold, SMS verification code verification is triggered; when the deviation between the current access time and the records in the time entropy value table is greater than the third preset threshold, user liveness detection and iris feature recognition of the user are performed.

[0030] In the present invention, the verification rules deeply couple biometric features, device behaviors, environmental contexts, and dynamic security policies, taking into account the flexibility of the user experience while enhancing security.

[0031] When a specific event occurs, the authentication node conducts weighted voting based on the local verification results, and determines the final verification result based on the voting result of the weighted voting and the verification result of the distributed authentication network. When the final verification result is passed, all permissions are opened to the user for this distributed device.

[0032] Furthermore, the present invention continuously learns the natural variation range of the user's biometric features (such as the change of facial features under different illuminations), and determines the features exceeding the normal variation threshold (such as an overly blurred iris image) as an attack attempt. Periodically inject simulated attack samples (such as deepfake videos, voice synthesis data) into the authentication nodes; dynamically update the first model, the second model, and the third model to enhance security.

[0033] Furthermore, the verification results of each authentication node are calculated by the consensus algorithm to obtain the verification result of the distributed authentication network. In response to the verification result of the distributed authentication network being verified as passed, the distributed device opens all permissions to the user, including: Step S21: The verification results corresponding to each authentication node are recorded and propagated through the distributed ledger, and the consensus algorithm is used to generate the verification result of the distributed authentication network; the consensus algorithm is PBFT or PoS; Step S22: In response to the verification result of the distributed authentication network being verified as passed, the distributed device opens all permissions to the user; in response to the verification result of the distributed authentication network being verified as failed, the method ends.

[0034] The distributed devices are connected through an encrypted P2P network, and a secure channel is established between the distributed devices; after the distributed device opens all permissions to the user, the user can access the distributed device information, contact information, and application information of the distributed device.

[0035] The present invention adopts the distributed ledger technology to record the modification history and synchronization status of the data, ensuring the consistency and traceability of the data. And the data is transmitted through the secure channel. The data is encrypted during the transmission process to ensure the security of the data.

[0036] The distributed ledger is divided into 6 layers, from bottom to top are: the data layer, the network layer, the consensus layer, the smart contract layer, the incentive layer, and the application layer. The data layer includes block data, chain structure, digital signature, hash function, Merkle tree, asymmetric encryption, etc.; the network layer includes peer-to-peer (P2P) communication, propagation mechanism, verification mechanism; the consensus layer includes protocols such as PBFT, Pos, DPoS, PoW, paxos, etc.; the smart contract layer is mainly the specific implementation of the contract, including smart contract code, contract interface, contract template and library; the incentive layer includes economic incentive mechanism, non-economic incentive mechanism; the application layer mainly has financial, supply chain management, social DApps, etc.

[0037] Sending the updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network validates the updated data; in response to the successful validation by the blockchain network, other distributed devices in the blockchain network update their locally stored data based on the updated data, including: Step S23: After the user finishes accessing, determine the updated data in the distributed device; the distributed device sends a data update request to the blockchain network to which the distributed device belongs, and the data update request includes the updated data, the identifier of the distributed device, and the timestamp when the updated data is generated; Step S24: The smart contract in the blockchain network validates the data update request according to preset data synchronization rules and data consistency verification rules. The verification content includes the data format of the updated data, whether the distributed device deploying the updated data is legal, and whether the updated data conflicts with the data stored in other distributed devices; in response to the successful validation by the smart contract, proceed to Step S25, otherwise, the method ends; Step S25: Broadcast the data update request to each other distributed device in the blockchain network, and other distributed devices update their locally stored data based on the updated data.

[0038] Optionally, the distributed device can also collect the user's voiceprint, palmprint or other biometric features, such as electroencephalogram recognition. The distributed authentication network can use different network topologies and communication protocols.

[0039] In the present invention, multi-modal biometric fusion authentication greatly improves the accuracy and security of authentication. Compared with single biometric technology, it can effectively reduce the false recognition rate and rejection rate. The distributed authentication network adopts a decentralized design concept, and the distributed ledger records authentication information to ensure the immutability and traceability of authentication data, significantly improving the reliability and anti-attack ability of the distributed authentication network. Using the distributed ledger and smart contract technology of the blockchain network to achieve data synchronization improves the efficiency and security of data synchronization, and reduces the occurrence of data conflicts and errors.

[0040] As Figure 2 shown, the present invention provides a security authentication device based on biometric recognition and data synchronization. The device 100 includes: Recognition module 101: configured to collect the user's facial features, iris features and voice features by the distributed device when the user uses the distributed device; Identify the facial features by the first model; In response to the successful recognition of the facial features by the first model, identify the first fusion feature after fusing the facial features and iris features by the second model; In response to the successful recognition of the first fused feature by the second model, the third model recognizes the second fused feature after fusing the facial feature, iris feature, and voice feature; In response to the successful recognition of the second fused feature by the third model, the distributed device grants the access permission among all the permissions to the user and retains other permissions; Authentication module 102: Configured to send authentication information to all authentication nodes in the distributed authentication network by the distributed device. The authentication information includes the identifier of the distributed device, the facial feature, iris feature, and voice feature of the user; Each authentication node verifies the authentication information based on the verification information and verification rules stored in itself; The consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network; In response to the verification result of the distributed authentication network being verified successfully, the distributed device grants all permissions to the user; Send the updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the successful verification by the blockchain network, other distributed devices in the blockchain network update their locally stored data based on the updated data.

[0041] The above modules can be one or more integrated circuits configured to implement the above methods. For example: one or more application specific integrated circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), etc. Again, when a certain module above is implemented in the form of a processing element scheduling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code. Again, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0042] The above-mentioned modules can be connected or communicate with each other via wired connections or wireless connections. Wired connections can include metal cables, optical cables, hybrid cables, etc., or any combination thereof. Wireless connections can include connections in the form of LAN, WAN, Bluetooth, ZigBee, or NFC, etc., or any combination thereof. Two or more modules can be combined into a single module, and any one module can be divided into two or more units. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the method embodiments, and will not be elaborated herein.

[0043] It should be noted that the above-mentioned modules can be one or more integrated circuits configured to implement the above methods, such as: one or more application specific integrated circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), etc. Again, when a certain module above is implemented in the form of a processing element dispatching program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code. Again, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0044] The electronic device includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the electronic device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, carrier networks, near field communication (NFC), or other technologies. The display screen of the electronic device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the electronic device can be a touch layer covering the display screen, or a button, trackball, or touchpad provided on the housing of the electronic device, or an external keyboard, touchpad, or mouse, etc.

[0045] The present invention also provides a program product, such as a computer-readable storage medium, including a program that is used to execute the above method embodiments when executed by a processor.

[0046] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical or other forms.

[0047] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0048] In addition, each functional unit in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.

[0049] The above-mentioned integrated units implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units stored in a storage medium include several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute some steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (English: Read-Only Memory, abbreviated as: ROM), random access memories (English: Random Access Memory, abbreviated as: RAM), magnetic disks or optical discs that can store program codes.

Claims

1. A security authentication method based on biometric recognition and data synchronization, characterized in that, The method includes: Recognition stage: When the user uses the distributed device, the distributed device collects the user's facial features, iris features, and voice features; The first model recognizes the facial features; In response to the recognition of the facial features by the first model passing, the second model recognizes the first fusion feature after fusing the facial features and the iris features; In response to the recognition of the first fusion feature by the second model passing, the third model recognizes the second fusion feature after fusing the facial features, iris features, and voice features; In response to the recognition of the second fusion feature by the third model passing, the distributed device grants the access permission among all the permissions to the user and retains other permissions; Authentication stage: The distributed device sends authentication information to all the authentication nodes in the distributed authentication network. The authentication information includes the identifier of the distributed device, the user's facial features, iris features, and voice features; Each authentication node verifies the authentication information based on the verification information and verification rules stored in itself; the consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network; In response to the verification result of the distributed authentication network being verification passed, the distributed device grants all the permissions to the user; Send the updated data that occurs in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verifying passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.

2. The method according to claim 1, characterized in that, Each of the authentication nodes verifies the authentication information based on the verification information and verification rules stored in itself, where The verification information includes: user information, distributed device information, biometric data, distributed device trust graph, environmental parameters; The user information includes the user name and user identifier; The distributed device information includes the device identification code, the registration time of the distributed device, and the registration location of the distributed device; The biometric data includes the facial feature template, iris feature template, voice feature template, dynamic change model of the user's biometrics, and the behavior pattern of the user operating the distributed device. The dynamic change model of the user's biometrics includes the facial micro-expression time series data, the iris texture change prediction model with age, and the adaptive offset curve of the voice frequency with environmental noise; The distributed device trust graph is constructed based on the login time period of the distributed device, the geographical location trajectory, the connection records between multiple distributed devices, and the connection strength during connection; The environmental parameters include the geographical fence and environmental fingerprint. The geographical fence is the geographical area where the distributed device is allowed to be located, and the environmental fingerprint is the environmental characteristics of the environment where the distributed device is allowed to be located, the time entropy value table of the distributed device. The time entropy value table is a record table storing the time rules of the user operating the distributed device.

3. The method according to claim 2, wherein Each of the authentication nodes verifies the authentication information based on the verification information and verification rules stored in itself, where the verification rules include: Rule 1: The facial features, iris features, and voice features of the user are collected within the same time window, and the difference in the timestamps of the collection of the facial features, iris features, and voice features is less than a preset threshold; when the distributed device is in an unfamiliar geographical location and / or during a non-prescribed access time period, secondary iris feature confirmation is enabled, or the user is required to speak a dynamically generated random verification code through voice. Rule 2: When the distributed device has changed its IP address and / or logged in across regions within a time period less than the first preset time period from the current access time, gesture password verification is added or other verified distributed devices perform linkage verification on this distributed device. Rule 3: When the deviation of the current environmental parameters from the environmental parameters corresponding to the distributed device at the time of verification passes exceeds the second preset threshold, SMS verification code verification is triggered; when the deviation between the current access time and the record in the time entropy value table is greater than the third preset threshold, user liveness detection and iris feature recognition of the user are performed.

4. The method according to claim 1, wherein The verification results of each authentication node are calculated by the consensus algorithm to obtain the verification result of the distributed authentication network. In response to the verification result of the distributed authentication network being verified as passed, this distributed device opens all permissions to the user, including: Step S21: The verification results corresponding to each authentication node are recorded and propagated through the distributed ledger, and the consensus algorithm is used to generate the verification result of the distributed authentication network; the consensus algorithm is PBFT or PoS. Step S22: In response to the verification result of the distributed authentication network being verified as passed, this distributed device opens all permissions to the user; in response to the verification result of the distributed authentication network being verified as not passed, the method ends.

5. The method according to claim 4, wherein Sending the updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verifying and passing, other distributed devices in the blockchain network update their locally stored data based on the updated data, including: Step S23: After the user finishes accessing, determine the updated data in the distributed device; the distributed device sends a data update request to the blockchain network to which the distributed device belongs, and the data update request includes the updated data, the identifier of the distributed device, and the timestamp of generating the updated data. Step S24: The smart contract in the blockchain network verifies the data update request according to the preset data synchronization rules and data consistency verification rules, and the verification content includes the data format of the updated data, whether the distributed device deploying the updated data is legal, and whether the updated data conflicts with the data stored in other distributed devices; in response to the smart contract verifying and passing, enter Step S25, otherwise, the method ends; Step S25: The data update request is broadcast to each other distributed device in the blockchain network, and other distributed devices update their locally stored data based on the updated data.

6. A security authentication device based on biometric recognition and data synchronization, characterized in that, The device includes: Recognition module: configured to collect the facial features, iris features, and voice features of the user by the distributed device when the user uses the distributed device; The facial features are recognized by the first model; In response to the recognition of facial features by the first model being passed, the second model recognizes the first fused feature after fusing the facial features and iris features; In response to the recognition of the first fused feature by the second model being passed, the third model recognizes the second fused feature after fusing the facial features, iris features, and voice features; In response to the recognition of the second fused feature by the third model being passed, the distributed device grants the access permission among all permissions to the user and retains other permissions; Authentication module: configured to send authentication information including the identifier of the distributed device, the facial features, iris features, and voice features of the user to all authentication nodes in the distributed authentication network; Each authentication node verifies the authentication information based on the verification information and verification rules stored in itself; the consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network; In response to the verification result of the distributed authentication network being verified successfully, the distributed device grants all permissions to the user; Send the updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.

7. An electronic device, characterized in that, The device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-5.

8. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • The invention discloses a mMulti-mode biological feature fusion method and device

    CN109614880A

  • Identity authentication method and device based on fusion features, equipment and storage medium

    CN111814128A

  • Data processing method and device

    CN113312106A

  • Password generation method and device and storage medium

    CN114679264A

  • Blockchain-based authentication system

    DE202025100776U1