A security authentication method and device based on biometric identification and data synchronization
Through the combination of multimodal biometrics, distributed authentication and blockchain network, the security authentication and data synchronization problems of distributed devices are solved, and efficient and secure authentication and data synchronization are achieved.
Patent Information
- Application Number
- CN202510864950.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-06-26
AI Technical Summary
In the existing technology, the security authentication method of distributed devices has problems such as being vulnerable to malicious attacks and cumbersome operations. At the same time, data synchronization faces the challenges of low efficiency and prone to errors.
It adopts multimodal biometric fusion technology, through multi-level recognition of facial features, iris features and voice features, combined with distributed authentication network and blockchain network, to achieve secure authentication and efficient data synchronization.
It improves the security and convenience of authentication, reduces the risk of attacks and impersonation, ensures the real-time consistency and reliability of data, and avoids the risk of single point failure.
Smart Images

Figure CN120358104B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a security authentication method and device based on biometric identification and data synchronization. Background Art
[0002] With the widespread use of distributed devices, ensuring secure authentication and efficient data synchronization between them has become a pressing issue. Existing technologies often rely on single password authentication, digital certificate authentication, or biometric authentication for distributed device security. Data synchronization typically relies on centralized management from a central server or manual or scheduled synchronization using specialized synchronization software. Common methods include centralized synchronization based on cloud servers or simple point-to-point synchronization.
[0003] Single password authentication is easy to guess or crack; digital certificate management is complex and may be forged, which is not secure enough; single biometric technology may lead to a high authentication failure rate due to environmental factors or individual differences. For example, fingerprint recognition authentication may be affected by fingerprint wear and stains, resulting in unstable recognition accuracy.
[0004] Centralized synchronization based on cloud servers carries the risk of data privacy leaks and is highly dependent on servers. Centralized server synchronization presents a single point of failure, and data synchronization can be severely impacted by server failures or network congestion. Manual or scheduled synchronization methods are inefficient and prone to omissions and errors. They cannot guarantee the real-time and accuracy of data and require high user input. Peer-to-peer synchronization can result in synchronization interruptions or data inconsistencies.
[0005] It can be seen that traditional authentication methods may be subject to malicious attacks, identity theft, cumbersome operations and other problems. At the same time, data synchronization also faces challenges such as low efficiency and prone to errors. Summary of the Invention
[0006] The present invention proposes a security authentication method and device based on biometric identification and data synchronization, which is used to solve the technical problems of traditional authentication methods such as malicious attacks, identity fraud, and cumbersome operations. At the same time, data synchronization faces the technical problems of low efficiency and easy errors.
[0007] A first aspect of the present invention provides a security authentication method based on biometric identification and data synchronization, the method comprising:
[0008] Identification phase:
[0009] When a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features;
[0010] Recognizing facial features by the first model;
[0011] In response to the first model successfully recognizing the facial features, the second model recognizes a first fused feature formed by fusing the facial features with the iris features;
[0012] In response to the second model successfully identifying the first fused feature, the third model identifies the second fused feature formed by fusing the facial feature, the iris feature, and the voice feature;
[0013] In response to the third model successfully identifying the second fusion feature, the distributed device opens access rights in all permissions to the user and reserves other permissions;
[0014] Certification stage:
[0015] The distributed device sends authentication information to all authentication nodes in the distributed authentication network. The authentication information includes the identifier of the distributed device, the user's facial features, iris features, and voice features.
[0016] Each authentication node verifies the authentication information based on its own stored authentication information and verification rules; the consensus algorithm calculates the verification results of each authentication node to obtain the verification results of the distributed authentication network;
[0017] In response to the distributed authentication network's verification result being a passed verification, the distributed device opens all permissions to the user;
[0018] Sending updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data;
[0019] In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.
[0020] Preferably, each authentication node verifies the authentication information based on its own stored authentication information and verification rules, wherein:
[0021] Verification information includes: user information, distributed device information, biometric data, distributed device trust map, and environmental parameters;
[0022] User information includes user name and user ID;
[0023] Distributed device information includes device identification code, distributed device registration time, and distributed device registration location;
[0024] The biometric data includes facial feature templates, iris feature templates, voice feature templates, a dynamic change model of the user's biometrics, and the user's behavior pattern in operating distributed devices. The dynamic change model of the user's biometrics includes facial micro-expression time series data, a prediction model of iris texture changes with age, and an adaptive offset curve of voice frequency with environmental noise.
[0025] The distributed device trust graph is constructed based on the distributed device's login period, geographical location trajectory, connection records between multiple distributed devices, and connection strength during connection;
[0026] Environmental parameters include geographic fences and environmental fingerprints. Geographic fences are the geographical areas where distributed devices are allowed to be located. Environmental fingerprints are the environmental characteristics of the environment where distributed devices are allowed to be located, and the time entropy value table of distributed devices. The time entropy value table is a record table that stores the time patterns of user operations on distributed devices.
[0027] Preferably, each authentication node verifies the authentication information based on its own stored verification information and verification rules, wherein the verification rules include:
[0028] Rule 1: The user's facial features, iris features, and voice features must be collected within the same time window, and the difference in the collection timestamps of the facial features, iris features, and voice features must be less than a preset threshold. If the distributed device is in an unfamiliar location and / or outside the specified access time period, iris feature secondary confirmation is enabled, or the user is required to speak a dynamically generated random verification code.
[0029] Rule 2: If a distributed device has changed its IP address and / or logged in from a different region within a period of time less than the first preset time since the current access time, gesture password verification is added or a distributed device that has passed verification is used to perform joint verification on the distributed device.
[0030] Rule 3: When the deviation between the current environmental parameters and the corresponding environmental parameters of the distributed device when the verification is passed exceeds the second preset threshold, the SMS verification code verification is triggered; when the deviation between the current access time and the record in the time entropy value table is greater than the third preset threshold, user liveness detection and iris feature recognition of the user are performed.
[0031] Preferably, the consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network. In response to the verification result of the distributed authentication network being verification passed, the distributed device opens all permissions to the user, including:
[0032] Step S21: Each authentication node records and disseminates its corresponding verification results through a distributed ledger, and uses a consensus algorithm to generate the verification results of the distributed authentication network; the consensus algorithm is PBFT or PoS;
[0033] Step S22: In response to the distributed authentication network's verification result being a successful verification, the distributed device opens all permissions to the user; in response to the distributed authentication network's verification result being a failed verification, the method ends.
[0034] Preferably, the updated data in the distributed device is sent to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; in response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data, including:
[0035] Step S23: After the user completes the access, the updated data in the distributed device is determined; the distributed device sends a data update request to the blockchain network to which the distributed device belongs, and the data update request includes the updated data, the identifier of the distributed device, and the timestamp of generating the updated data;
[0036] Step S24: The smart contract in the blockchain network verifies the data update request according to preset data synchronization rules and data consistency verification rules. The verification content includes the data format of the updated data, whether the distributed device deploying the updated data is legal, and whether the updated data conflicts with data stored in other distributed devices. In response to the smart contract verification passing, the process proceeds to step S25; otherwise, the method ends.
[0037] Step S25: The data update request is broadcast to other distributed devices in the blockchain network, and other distributed devices update their locally stored data based on the updated data.
[0038] A second aspect of the present invention provides a security authentication device based on biometric identification and data synchronization, the device comprising:
[0039] Identification module: When a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features;
[0040] Recognizing facial features by the first model;
[0041] In response to the first model successfully recognizing the facial features, the second model recognizes a first fused feature formed by fusing the facial features with the iris features;
[0042] In response to the second model successfully identifying the first fused feature, the third model identifies the second fused feature formed by fusing the facial feature, the iris feature, and the voice feature;
[0043] In response to the third model successfully identifying the second fusion feature, the distributed device opens access rights in all permissions to the user and reserves other permissions;
[0044] Authentication module: configured as a distributed device to send authentication information to all authentication nodes in the distributed authentication network. The authentication information includes the identification of the distributed device, the user's facial features, iris features, and voice features;
[0045] Each authentication node verifies the authentication information based on its own stored authentication information and verification rules; the consensus algorithm calculates the verification results of each authentication node to obtain the verification results of the distributed authentication network;
[0046] In response to the distributed authentication network's verification result being a passed verification, the distributed device opens all permissions to the user;
[0047] Sending updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data;
[0048] In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.
[0049] A third aspect of the present invention provides an electronic device, comprising:
[0050] at least one processor; and
[0051] a memory communicatively connected to the at least one processor; wherein,
[0052] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method described above.
[0053] A fourth aspect of the present invention provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method as described above.
[0054] The present invention has the following technical effects:
[0055] (1) The present invention adopts the fusion of multimodal biometrics, so users do not need to remember complex passwords, making operation more convenient; because the biometric authentication method is difficult to crack and forge, it effectively protects user data and device security.
[0056] (2) The distributed security authentication architecture of the present invention improves the reliability and availability of data and avoids the risk of single point failure; the encrypted P2P network construction and communication protocol design improve the security authentication level of distributed devices and reduce the risk of attack and impersonation.
[0057] (3) The data synchronization mechanism based on blockchain in this invention realizes efficient data synchronization. The real-time synchronization technology ensures that the data between devices are always consistent, thereby improving work efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 Schematic diagram of the process of the security authentication method based on biometric identification and data synchronization of the present invention;
[0059] Figure 2 It is a structural diagram of the security authentication device based on biometric identification and data synchronization of the present invention. DETAILED DESCRIPTION
[0060] To make the purpose, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present disclosure.
[0061] like Figure 1 As shown, the present invention provides a security authentication method based on biometric identification and data synchronization, the method comprising:
[0062] Identification phase:
[0063] When a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features;
[0064] Recognizing facial features by the first model;
[0065] In response to the first model successfully recognizing the facial features, the second model recognizes a first fused feature formed by fusing the facial features with the iris features;
[0066] In response to the second model successfully identifying the first fused feature, the third model identifies the second fused feature formed by fusing the facial feature, the iris feature, and the voice feature;
[0067] In response to the third model successfully identifying the second fusion feature, the distributed device opens access rights in all permissions to the user and reserves other permissions;
[0068] Certification stage:
[0069] The distributed device sends authentication information to all authentication nodes in the distributed authentication network. The authentication information includes the identifier of the distributed device, the user's facial features, iris features, and voice features.
[0070] Each authentication node verifies the authentication information based on its own stored authentication information and verification rules; the consensus algorithm calculates the verification results of each authentication node to obtain the verification results of the distributed authentication network;
[0071] In response to the distributed authentication network's verification result being a passed verification, the distributed device opens all permissions to the user;
[0072] Sending updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data;
[0073] In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.
[0074] The first model, the second model and the third model are updated and optimized regularly to adapt to changes in the environment and user characteristics.
[0075] In the present invention, the first, second, and third models are all conventional neural network models in the art. Sensors are provided on the distributed devices to collect the user's facial features, iris features, and voice features. The method terminates if the first model fails recognition; if the second model fails verification; and if the third model fails recognition.
[0076] Furthermore, each authentication node verifies the authentication information based on its own stored verification information and verification rules, wherein:
[0077] Verification information includes: user information, distributed device information, biometric data, distributed device trust map, and environmental parameters;
[0078] User information includes user name and user ID;
[0079] Distributed device information includes device identification code, distributed device registration time, and distributed device registration location;
[0080] The biometric data includes facial feature templates, iris feature templates, voice feature templates, a dynamic change model of the user's biometrics, and the user's behavior pattern in operating distributed devices. The dynamic change model of the user's biometrics includes facial micro-expression time series data, a prediction model of iris texture changes with age, and an adaptive offset curve of voice frequency with environmental noise.
[0081] The distributed device trust graph is constructed based on the distributed device's login period, geographical location trajectory, connection records between multiple distributed devices, and connection strength during connection;
[0082] Environmental parameters include geographic fences and environmental fingerprints. Geographic fences are the geographical areas where distributed devices are allowed to be located. Environmental fingerprints are the environmental characteristics of the environment where distributed devices are allowed to be located, and the time entropy value table of distributed devices. The time entropy value table is a record table that stores the time patterns of user operations on distributed devices.
[0083] In the present invention, user information includes user name, user ID, and personal information filled in by the user when registering, such as name, contact information, etc., which are used to assist in verifying the authenticity of the user's identity.
[0084] Distributed device information includes device identification code, distributed device registration time, and distributed device registration location. The device identification code is the unique identification code of the distributed device, such as IMEI, MAC address, etc. The distributed device registration time and distributed registration location serve as the basis for verifying whether the distributed device is registered and used normally.
[0085] Biometric data includes facial feature templates, iris feature templates, voice feature templates, dynamic change models of user biometrics and behavioral patterns of users operating distributed devices. The dynamic change models of user biometrics include facial micro-expression time series data, iris texture change prediction model with age and adaptive offset curve of voice frequency with environmental noise; behavioral patterns of users operating distributed devices, such as touch screen pressure distribution and typing rhythm, serve as the basis for cross-validation of user behavior and physiological characteristics in operating distributed devices.
[0086] The distributed device trust map is constructed based on the distributed device's login time period, geographic location trajectory, connection records between multiple distributed devices, and connection strength when connected. For example, the distributed device trust map is constructed based on the user's common login time period, geographic location trajectory, software installation records and historical security events (intrusion records, abnormal login records), the distributed device group to which the distributed device has been bound, the collaborative operation history between multiple distributed devices, and the connection strength when multiple distributed devices are connected (such as data interaction frequency, duration, and encryption transmission success rate).
[0087] Environmental parameters include geofencing and environmental fingerprints, which include the geographic areas and environmental characteristics of the distributed devices, and a time entropy table, which records the temporal patterns of user operations on distributed devices. The time entropy table contains information such as weekday and / or weekend usage distribution and time interval thresholds for high-frequency operations.
[0088] Each authentication node verifies the authentication information based on its own stored verification information and verification rules, wherein the verification rules include:
[0089] Rule 1: The user's facial features, iris features, and voice features must be collected within the same time window, and the difference in the collection timestamps of the facial features, iris features, and voice features must be less than a preset threshold. If the distributed device is in an unfamiliar location and / or outside the specified access time period, iris feature secondary confirmation is enabled, or the user is required to speak a dynamically generated random verification code.
[0090] Rule 2: If a distributed device has changed its IP address and / or logged in from a different region within a period of time less than the first preset time since the current access time, gesture password verification is added or a distributed device that has passed verification is used to perform joint verification on the distributed device.
[0091] Rule 3: When the deviation between the current environmental parameters and the corresponding environmental parameters of the distributed device when the verification is passed exceeds the second preset threshold, the SMS verification code verification is triggered; when the deviation between the current access time and the record in the time entropy value table is greater than the third preset threshold, user liveness detection and iris feature recognition of the user are performed.
[0092] In the present invention, the verification rules deeply couple biometrics, device behavior, environmental context and dynamic security policies, improving security while taking into account the flexibility of user experience.
[0093] When a specific event occurs, the authentication node performs weighted voting based on the local verification results, and determines the final verification result based on the voting results of the weighted voting and the verification results of the distributed authentication network. When the final verification result is passed, the distributed device opens all permissions to the user.
[0094] Furthermore, the present invention continuously learns the natural variation range of user biometrics (such as how facial features change under different lighting conditions) and identifies features that exceed the normal variation threshold (such as excessively blurred iris images) as attack attempts. Simulated attack samples (such as deepfake videos and voice synthesis data) are regularly injected into the authentication node, and the first, second, and third models are dynamically updated to enhance security.
[0095] Furthermore, the consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network. In response to the verification result of the distributed authentication network being verification passed, the distributed device opens all permissions to the user, including:
[0096] Step S21: Each authentication node records and disseminates its corresponding verification results through a distributed ledger, and uses a consensus algorithm to generate the verification results of the distributed authentication network; the consensus algorithm is PBFT or PoS;
[0097] Step S22: In response to the distributed authentication network's verification result being a successful verification, the distributed device opens all permissions to the user; in response to the distributed authentication network's verification result being a failed verification, the method ends.
[0098] Distributed devices are connected through an encrypted P2P network, and a secure channel is established between distributed devices; after the distributed device opens all permissions to the user, the user can access the distributed device information, contact information and application information of the distributed device.
[0099] This invention uses distributed ledger technology to record data modification history and synchronization status, ensuring data consistency and traceability. Data is transmitted through secure channels. Data is encrypted during transmission to ensure data security.
[0100] Distributed ledgers are divided into six layers: data layer, network layer, consensus layer, smart contract layer, incentive layer, and application layer. The data layer includes block data, chain structure, digital signatures, hash functions, Merkle trees, asymmetric encryption, etc.; the network layer includes peer-to-peer (P2P) communication, propagation mechanisms, and verification mechanisms; the consensus layer includes protocols such as PBFT, Pos, DPoS, PoW, and Paxos; the smart contract layer mainly implements contracts, including smart contract code, contract interfaces, contract templates, and libraries; the incentive layer includes economic and non-economic incentive mechanisms; and the application layer mainly includes financial, supply chain management, and social DApps.
[0101] The updated data in the distributed device is sent to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; in response to the blockchain network verification, other distributed devices in the blockchain network update their locally stored data based on the updated data, including:
[0102] Step S23: After the user completes the access, the updated data in the distributed device is determined; the distributed device sends a data update request to the blockchain network to which the distributed device belongs, and the data update request includes the updated data, the identifier of the distributed device, and the timestamp of generating the updated data;
[0103] Step S24: The smart contract in the blockchain network verifies the data update request according to preset data synchronization rules and data consistency verification rules. The verification content includes the data format of the updated data, whether the distributed device deploying the updated data is legal, and whether the updated data conflicts with data stored in other distributed devices. In response to the smart contract verification passing, the process proceeds to step S25; otherwise, the method ends.
[0104] Step S25: The data update request is broadcast to other distributed devices in the blockchain network, and other distributed devices update their locally stored data based on the updated data.
[0105] Optionally, the distributed devices can also collect the user's voiceprint, palmprint or other biometric features, such as brain wave recognition. The distributed authentication network can use different network topologies and communication protocols.
[0106] In this invention, multimodal biometric fusion authentication significantly improves authentication accuracy and security, effectively reducing false positives and rejections compared to single biometric technologies. The distributed authentication network adopts a decentralized design concept, with a distributed ledger recording authentication information, ensuring the immutability and traceability of authentication data, significantly enhancing the reliability and attack resistance of the distributed authentication network. Data synchronization is achieved using the blockchain network's distributed ledger and smart contract technology, improving its efficiency and security while reducing data conflicts and errors.
[0107] like Figure 2 As shown, the present invention provides a security authentication device based on biometric identification and data synchronization, the device 100 includes:
[0108] Identification module 101: configured so that when a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features;
[0109] Recognizing facial features by the first model;
[0110] In response to the first model successfully recognizing the facial features, the second model recognizes a first fused feature formed by fusing the facial features with the iris features;
[0111] In response to the second model successfully identifying the first fused feature, the third model identifies the second fused feature formed by fusing the facial feature, the iris feature, and the voice feature;
[0112] In response to the third model successfully identifying the second fusion feature, the distributed device opens access rights in all permissions to the user and reserves other permissions;
[0113] Authentication module 102: configured as a distributed device to send authentication information to all authentication nodes in the distributed authentication network, the authentication information including the identifier of the distributed device, the user's facial features, iris features and voice features;
[0114] Each authentication node verifies the authentication information based on its own stored authentication information and verification rules; the consensus algorithm calculates the verification results of each authentication node to obtain the verification results of the distributed authentication network;
[0115] In response to the distributed authentication network's verification result being a passed verification, the distributed device opens all permissions to the user;
[0116] Sending updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data;
[0117] In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.
[0118] The above modules can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital singular processors (DSPs), or one or more field programmable gate arrays (FPGAs). For example, when a module is implemented by scheduling program code through a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0119] The above modules can be connected or communicate with each other via a wired connection or a wireless connection. The wired connection may include a metal cable, an optical cable, a hybrid cable, etc., or any combination thereof. The wireless connection may include a connection in the form of a LAN, a WAN, Bluetooth, ZigBee, or NFC, or any combination thereof. Two or more modules can be combined into a single module, and any module can be divided into two or more units. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in the present invention.
[0120] It should be noted that the above modules can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs). For example, when a module is implemented by scheduling program code through a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0121] An electronic device includes a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor of the electronic device provides computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the electronic device is used to communicate with an external terminal via wired or wireless communication, where wireless communication can be achieved via Wi-Fi, a carrier network, near-field communication (NFC), or other technologies. The display of the electronic device can be a liquid crystal display or an electronic ink display. The input device of the electronic device can be a touchscreen covering the display, buttons, a trackball, or a touchpad provided on the electronic device housing, or an external keyboard, touchpad, or mouse.
[0122] The present invention also provides a program product, such as a computer-readable storage medium, comprising a program, which is used to perform the above method embodiments when executed by a processor.
[0123] In the several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0124] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0125] In addition, the functional units in various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional units.
[0126] The aforementioned integrated unit implemented as a software functional unit can be stored in a computer-readable storage medium. The software functional unit, stored in a storage medium, includes instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) or a processor to execute portions of the method steps described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a removable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
Claims
1. A security authentication method based on biometric identification and data synchronization, characterized in that: The method comprises: Identification phase: When a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features; Recognizing facial features by the first model; In response to the first model successfully recognizing the facial features, the second model recognizes a first fused feature formed by fusing the facial features with the iris features; In response to the second model successfully identifying the first fused feature, the third model identifies the second fused feature formed by fusing the facial feature, the iris feature, and the voice feature; In response to the third model successfully identifying the second fusion feature, the distributed device opens access rights in all permissions to the user and reserves other permissions; Certification stage: The distributed device sends authentication information to all authentication nodes in the distributed authentication network. The authentication information includes the identifier of the distributed device, the user's facial features, iris features, and voice features. Each authentication node verifies the authentication information based on its own stored authentication information and verification rules; the consensus algorithm calculates the verification results of each authentication node to obtain the verification results of the distributed authentication network; In response to the distributed authentication network's verification result being a passed verification, the distributed device opens all permissions to the user; Sending updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.
2. The method according to claim 1, wherein Each authentication node verifies the authentication information based on its own stored authentication information and verification rules, wherein: Verification information includes: user information, distributed device information, biometric data, distributed device trust map, and environmental parameters; User information includes user name and user ID; Distributed device information includes device identification code, distributed device registration time, and distributed device registration location; The biometric data includes facial feature templates, iris feature templates, voice feature templates, a dynamic change model of the user's biometrics, and the user's behavior pattern in operating distributed devices. The dynamic change model of the user's biometrics includes facial micro-expression time series data, a prediction model of iris texture changes with age, and an adaptive offset curve of voice frequency with environmental noise. The distributed device trust graph is constructed based on the distributed device's login period, geographical location trajectory, connection records between multiple distributed devices, and connection strength during connection; Environmental parameters include geographic fences and environmental fingerprints. Geographic fences are the geographical areas where distributed devices are allowed to be located. Environmental fingerprints are the environmental characteristics of the environment where distributed devices are allowed to be located, and the time entropy value table of distributed devices. The time entropy value table is a record table that stores the time patterns of user operations on distributed devices.
3. The method according to claim 2, wherein Each authentication node verifies the authentication information based on its own stored verification information and verification rules, wherein the verification rules include: Rule 1: The user's facial features, iris features, and voice features must be collected within the same time window, and the difference in the collection timestamps of the facial features, iris features, and voice features must be less than a preset threshold. If the distributed device is in an unfamiliar location and / or outside the specified access time period, iris feature secondary confirmation is enabled, or the user is required to speak a dynamically generated random verification code. Rule 2: If a distributed device has changed its IP address and / or logged in from a different region within a period of time less than the first preset time since the current access time, gesture password verification is added or a distributed device that has passed verification is used to perform joint verification on the distributed device. Rule 3: When the deviation between the current environmental parameters and the corresponding environmental parameters of the distributed device when the verification is passed exceeds the second preset threshold, the SMS verification code verification is triggered; when the deviation between the current access time and the record in the time entropy value table is greater than the third preset threshold, user liveness detection and iris feature recognition of the user are performed.
4. The method according to claim 1, wherein The consensus algorithm calculates the verification results of each authentication node to obtain the verification result of the distributed authentication network. In response to the verification result of the distributed authentication network being verification passed, the distributed device opens all permissions to the user, including: Step S21: Each authentication node records and disseminates its corresponding verification results through a distributed ledger, and uses a consensus algorithm to generate the verification results of the distributed authentication network; the consensus algorithm is PBFT or PoS; Step S22: In response to the distributed authentication network's verification result being a successful verification, the distributed device opens all permissions to the user; in response to the distributed authentication network's verification result being a failed verification, the method ends.
5. The method according to claim 4, wherein The updated data in the distributed device is sent to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data, including: Step S23: After the user completes the access, the updated data in the distributed device is determined; the distributed device sends a data update request to the blockchain network to which the distributed device belongs, and the data update request includes the updated data, the identifier of the distributed device, and the timestamp of generating the updated data; Step S24: The smart contract in the blockchain network verifies the data update request according to preset data synchronization rules and data consistency verification rules. The verification content includes the data format of the updated data, whether the distributed device deploying the updated data is legal, and whether the updated data conflicts with data stored in other distributed devices. In response to the smart contract verification passing, the process proceeds to step S25; otherwise, the method ends. Step S25: The data update request is broadcast to other distributed devices in the blockchain network, and other distributed devices update their locally stored data based on the updated data.
6. A security authentication device based on biometric identification and data synchronization, characterized in that: The device comprises: Identification module: When a user uses a distributed device, the distributed device collects the user's facial features, iris features, and voice features; Recognizing facial features by the first model; In response to the first model successfully recognizing the facial features, the second model recognizes a first fused feature formed by fusing the facial features with the iris features; In response to the second model successfully identifying the first fused feature, the third model identifies the second fused feature formed by fusing the facial feature, the iris feature, and the voice feature; In response to the third model successfully identifying the second fusion feature, the distributed device opens access rights in all permissions to the user and reserves other permissions; Authentication module: configured as a distributed device to send authentication information to all authentication nodes in the distributed authentication network. The authentication information includes the identification of the distributed device, the user's facial features, iris features, and voice features; Each authentication node verifies the authentication information based on its own stored authentication information and verification rules; the consensus algorithm calculates the verification results of each authentication node to obtain the verification results of the distributed authentication network; In response to the distributed authentication network's verification result being a passed verification, the distributed device opens all permissions to the user; Sending updated data in the distributed device to the blockchain network to which the distributed device belongs, and the blockchain network verifies the updated data; In response to the blockchain network verification being passed, other distributed devices in the blockchain network update their locally stored data based on the updated data.
7. An electronic device, characterized in that: The device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 5.
8. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
The invention discloses a mMulti-mode biological feature fusion method and device
CN109614880A
Identity authentication method and device based on fusion features, equipment and storage medium
CN111814128A