Revocable color vein identity authentication method for user security and privacy

Through interactive coloring scheme, grayscale venous images are converted into color venous images, which solves the problems of insufficient information and safety in venous biometric recognition, achieves efficient revocability and unlinkability, and improves recognition performance and security.

CN120387157APending Publication Date: 2025-07-29SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510463385.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

Existing venous biometric recognition technologies mainly rely on grayscale images, with limited information and susceptible to image transformation, and lack of reversibility and unlinkability, resulting in insufficient recognition performance and security.

Method used

Through an interactive coloring scheme, grayscale venous images are converted into color venous images, and venous segmentation networks, coloring networks and feature extraction networks are used to generate revocable color venous features, and optimize feature extraction with the security center loss function to achieve user-controllable pseudo-random color space.

Benefits of technology

Significantly enhances the information density of venous images, provides flexible revocable template generation, improves recognition performance and security, prevents cross-database links, and ensures irreversibility and unlinkability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387157A_ABST
    Figure CN120387157A_ABST
Patent Text Reader

Abstract

The invention provides a user security and privacy-oriented revocable color vein identity authentication method. The implementation of the scheme mainly comprises the following three steps of: 1, extracting a binary vein texture image from an original vein image by using a vein segmentation network; and 2, defining a unique pseudo-random color prompt corresponding to the identity, and transmitting a prompt point as input to the vein coloring network to generate a unique colored vein image. And step 3, inputting the generated color vein image into a feature extraction network, and generating a vein feature vector for identity matching for identity authentication. According to the scheme, a plurality of safe and reliable revocable identities can be published by using one vein feature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a revocable color vein authentication method for user security and privacy, belonging to the field of secure biometric technologies. Background Art

[0002] Vein biometric recognition is an advanced identity recognition technology based on the inherent physiological characteristics of the human body. When near-infrared light irradiates human tissues, hemoglobin in vein blood vessels absorbs more near-infrared light than the surrounding tissues, thus forming a unique shadow pattern during the imaging process and presenting vein textures in the image. Usually, infrared images (grayscale images) are obtained, and these images mainly contain feature information such as textures, brightness, and contrast. These features are extracted and used for subsequent processing and analysis, forming the basis for identity matching. Color images are everywhere. The human visual system is naturally capable of recognizing thousands of colors, but has relatively limited ability to distinguish gray levels. Obviously, color images can carry more abundant information than grayscale images. Similar to general image classification tasks, color is also crucial in the field of biometric recognition, such as in face, iris, and gait recognition. However, vein recognition faces unique challenges: different from face, iris, or gait where infrared grayscale images or natural color images can be selectively acquired, due to its inherent imaging principle, conventional vein features can only be collected in the form of infrared grayscale images.

[0003] Vein recognition is essentially a fine-grained classification task. Since grayscale images can only provide limited feature information, the differences between vein images are mainly reflected in texture features, and these differences are further weakened by other unstable factors in the images (such as translation, rotation, or contrast changes). Inspired by color biometric recognition technologies and image coloring algorithms, it is hoped to try coloring vein images to inject stable and information-rich color features. It is hoped that this significantly enhances the information density of vein images, expands the original single grayscale channel into a multi-dimensional RGB three-channel representation, expands the information space available for feature extraction, helps the feature extractor or recognition and authentication model capture more refined inter-class differences, and thus comprehensively improves the recognition performance and robustness of the system.

[0004] On the other hand, the color space is editable and can be achieved through an interactive coloring scheme. By introducing an interactive coloring scheme, static grayscale information can be transformed into a dynamically controllable color representation. The uniqueness of this method lies in that it allows users or system administrators to define a controllable pseudo-random color space for grayscale vein images by editing the position, quantity, and color of color cue points. This interactive coloring scheme can essentially solve three key problems: "Where to color?", that is, through controlling the position of color cue points, selective coloring of specific regions of the vein image can be achieved. "What color to use?", that is, by customizing the color of each cue point, a unique color mapping scheme can be created. And "How rich is the color?", that is, by adjusting the quantity and distribution of cue points, the complexity and diversity of the coloring result can be controlled.

[0005] It perfectly meets the core requirements of the CB system: by simply changing the color mapping scheme, new revocable templates can be easily generated to achieve revocability. There is no special mapping relationship between the colored vein feature templates used for matching and the original biometric features, so the original biometric features cannot be reconstructed from the protected templates, ensuring irreversibility. Different applications can use different color mapping schemes to prevent cross-database linking, which can meet unlinkability. Finally, appropriately designed color mapping can retain or even enhance the recognition performance of the original vein features. To address the issue caused by the uniqueness of biometric features, when biometric features are stolen, the present invention provides a revocable biometric generation scheme specific to hand veins - ColorVein, which enables the release of multiple revocable identities using the same biometric feature. Summary of the Invention

[0006] The problem of biometric information leakage may still pose a serious threat to user privacy and anonymity. Current template protection schemes usually damage the original biometric features, such as textures and minutiae, resulting in the loss of feature information for recognition and an inability to obtain ideal recognition performance. In addition, there is currently no revocable biometric generation scheme designed for vein biometrics.

[0007] To achieve the above object, the solution of the present invention is as follows: A revocable color vein authentication method for user security and privacy. ColorVein is an interactive infrared vein image coloring scheme that converts static grayscale information into dynamically controllable color representations, allowing users / system administrators to define a controllable pseudo-random color space for grayscale vein images by editing the position, quantity, and color of color hint points, and generating protected revocable biometric features. The implementation of this scheme is mainly divided into three steps: Step 1, use a vein segmentation network to extract a binary vein texture image from the original vein image. Step 2, define a unique pseudo-random color hint corresponding to the identity, and pass the hint points as input to the vein coloring network to generate a unique color vein image. Step 3, input the generated color vein image into a feature extraction network to generate a vein feature vector for identity matching for identity authentication. This scheme can realize the release of multiple secure and reliable revocable identities using one vein feature. The implementation steps are as follows:

[0008] Step 1: Train a vein texture segmentation network using texture labels to achieve automatic annotation of vein pixels. Input the original vein image into the trained vein texture segmentation network to automatically and accurately extract the vein pattern.

[0009] Step 2: Train the colored vein network. The coloring model uses pre-training on large-scale data to learn the prior knowledge of natural color images, and at the same time combines user control in the traditional edit propagation framework to directly map the grayscale image and sparse user input hint hint(I X ) to the output color.

[0010] Step 3: Train the feature extraction network. Further extract features from the color vein to obtain a fixed-length feature vector for registration / verification.

[0011] Furthermore, in the above Step 1, according to the majority voting strategy described in claim 3, it is characterized in that:

[0012] Use the majority voting strategy to make vein texture labels, and fuse the segmentation results of five classic baseline methods (maximum curvature method, principal curvature method, repeated line tracking method, Gabor filter, and isotropic non-subsampled wavelet transform). As shown in formula 1, if a pixel is marked as a vein by four or more methods, then the pixel is classified as a vein pixel (value is 1), otherwise it is regarded as a background pixel (value is 0). The binary texture map L generated by this method is used as a supervision signal for training the segmentation model.

[0013]

[0014] Furthermore, in the above Step 2, according to the vein coloring network described in claim 4, it is characterized in that:

[0015] The training of the coloring network is carried out on a large-scale color image dataset (ImageNet) with the goal of learning the coloring ability based on grayscale images and hints. The input of the model is the luminance L ∈ R of the grayscale image H×W×1 (the L channel in the LAB color space) and the user hint H, and the output is Y ∈ R H×W×2 , that is, the color estimation value (the ab channels in the LAB color space).

[0016] The structure of the model consists of 10 convolutional blocks (conv1-10), forming a deeper encoder-decoder structure. In the encoder part (conv1-4), each block contains 2-3 convolutional-ReLU pairs, and the feature map size is gradually halved while the feature dimension is doubled. In the bottleneck part (conv5-6), dilated convolutions are used to retain more detailed information while maintaining the receptive field. The decoder part (conv7-10) gradually restores the spatial resolution and reduces the feature dimension. A batch normalization layer is added after each convolutional block to improve the training stability. At the end of the network, 1×1 convolutions and a tanh activation function are used to adapt to the bounded ab color space. In addition, the conv1-8 layers are fine-tuned using pre-trained weights. The objective function used to supervise the learning of the coloring model is defined as:

[0017]

[0018] where δ is a threshold used to control the boundary of the error size. When the error is less than δ, the loss is the mean squared error MSE; otherwise, the loss is the mean absolute error MAE, and δ is set to 1. Here, 1 condition represents taking the value of 1 when the condition is true and 0 when the condition is false.

[0019] The coloring model also has a local hint branch network that reuses the features of the main branch, connects the features of multiple layers of the main branch through the hypercolumn method, and learns a two-layer classifier at the top to predict the probability distribution of the output color where Q is the number of quantization color bins. This branch is supervised using cross-entropy loss:

[0020]

[0021] Furthermore, in step 2, for the revocable identity definition and vein image coloring, assume that G is the model trained on the ImageNet dataset, and the vein image coloring is inferred on G. The input includes L ∈ R H×W×1 which is the luminance channel of the input image in the LAB color space and the defined revocable identity I X , which includes a set of hint points hint(I X uniquely corresponding to IX )). The output is the final estimated distribution of vein color \(Y\in\mathbb{R}\) H×W×2 . By combining the grayscale \(L\) and \(Y\), the final colored vein can be obtained. When defining the pseudo-random color space, in addition to using the set of hint points, a mask can also be used. The setting of the vein area and \(I\) X uniquely correspond to the pseudo-random brightness and the vein background color. This depends on the special grayscale image type - binary image of the input coloring model (which can be regarded as a mask for the vein area) to achieve.

[0022] Furthermore, in step 3, the security center loss function, different from general biometric recognition, in addition to considering the inherent variability of natural biometric features, revocable biometrics also need to additionally consider the cancellability, irreversibility, and unlinkability of templates. The feature extraction network hopes to learn a secure extraction function. Specifically, the security center loss is a five-tuple loss. The five-tuple consists of the class center, registered user samples (positive), imposter samples (negative), cross-registered samples (negative), and samples generated using stolen tokens (negative). There are four comparison pairs, including one positive comparison pair and three negative comparison pairs. The positive comparison pair is the class center and the registered positive sample, and the negative comparison pairs are the sample center and the other three negative samples respectively. For a good biometric recognition system, the score distributions of true matches and imposters should be clearly separable. To meet the revocability requirement, for a revocable biometric recognition system, it is required that the score distribution generated by cross-application matching of users should be consistent with the distribution of imposters. At the same time, to avoid the catastrophic impact on the recognition system when the token is stolen (the adversary can access the system only using the token and any biometric reference), the revocable biometric recognition system also requires that the matching score distribution generated by such samples should be consistent with the distribution of imposters. The SC Loss simultaneously considers maximizing the distance between the sample center and the four negative samples, making the matching score distributions of the four negative samples consistent and clearly separable from the true matching scores. In addition, the loss function used to supervise the feature extraction network also includes a softmax loss. Thus, the total loss is defined as:

[0023]

[0024] where \(L\) S is the softmax loss, and \(L\) sc is the security center loss. \(N\) represents the number of samples in a mini-batch, and \(K\) represents the number of classes. represents the difference between the distances of the positive and negative samples to the corresponding class centers, where represents the within-class distance, where \(j\) takes values from 1 to 3, representing the between-class distances of registered users. The negative samples \(\{I\) C , B X \} and \(y\)i The distance between and the negative sample {I X , B N} and y i The distance between. M is the margin difference. The corresponding λ takes 1, 0.001, and 0.001 respectively.

[0025] Furthermore, in step 3, for protected vein feature extraction, after coloring, the colored veins will undergo further feature extraction to obtain a fixed-length feature vector for registration / verification. ResNet50 is used as the backbone of the deep feature extraction network. On this basis, a fully connected layer is added after layer4 to extract a deep feature vector with a fixed length of 128. This network uses the secure center loss function for supervised learning.

[0026] All ColorVein biometrics for registration / authentication need to use the trained feature extraction network to extract fixed-length feature vector templates for storage or matching.

[0027] Compared with the prior art, the advantages of the present invention are as follows: This is the first revocable template generation scheme designed for vein biometrics. By converting static grayscale information into dynamically controllable color representations, ColorVein not only significantly enhances the information density of vein images but also provides a flexible revocable template generation mechanism. The scheme provided by the present invention allows users / administrators to define a controllable pseudo-random color space for grayscale vein images by editing the position, quantity, and color of the hint points, thereby generating protected revocable templates. In addition, the secure center loss provided by the present invention further optimizes the training process of the protected feature extraction model, effectively maintaining the feature distance between legitimate users and potential impostors. The superior performance of this scheme in terms of recognition performance, unlinkability, irreversibility, and revocability. Compared with the existing state-of-the-art revocable biometric schemes, ColorVein demonstrates highly competitive performance. ColorVein provides a new idea for revocable vein biometric generation. Brief Description of the Drawings

[0028] To more clearly introduce the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required in the implementation cases. Obviously, the drawings shown below are only individual cases of the present invention. For researchers in the field, this method can be applied to finger vein images of different qualities through simple reproduction of the present invention.

[0029] Figure 1 is the registration / verification flowchart of ColorVein described in the present invention,

[0030] Figure 2 is the schematic diagram of the feature extraction network described in the present invention,

[0031] Figure 3 This is a radar chart comparing the performance of the present invention with representative methods.

[0032] Figure 4 This is a two-dimensional feature distribution diagram of the protected biometric feature vectors obtained from the simulation test of the present invention.

[0033] Figure 5 This is a distribution diagram of brute-force attack matching scores obtained from the simulation test of the present invention.

[0034] Figure 6 This is a schematic diagram of global unlinkability obtained from the simulation experiment of the present invention.

[0035] Figure 7 This is a distribution diagram of matching scores in the stolen scenario obtained from the simulation test of the present invention.

[0036] Figure 8 This is a distribution diagram of matching scores for the wrong acceptance attack obtained from the simulation test of the present invention. Detailed implementation manners

[0037] To make the above objects, features, and advantages of the present invention more obvious and understandable, the technical solutions of the present invention will be described in detail below with reference to the accompanying drawings and specific implementation cases. It should be noted that this implementation case is only a part of the examples of the present invention, rather than all examples. All other examples obtained without making innovative work belong to the protection scope of the present invention. Example: A revocable color vein identity authentication method for user security and privacy, whose overall structure is as Figure 1 shown. The implementation of this solution is mainly divided into three steps: First, use a vein segmentation network to extract a binary vein texture image from the original vein image. Then, define a unique pseudo-random color hint corresponding to the identity, and use the hint points as inputs to the vein coloring network to generate a unique color vein image. Finally, input the generated color vein image into the feature extraction network to generate a vein feature vector for identity matching for identity authentication. The implementation steps are as follows:

[0038] First, use the provided majority voting strategy to make vein texture labels, and fuse the segmentation results of five classic baseline methods (maximum curvature method, principal curvature method, repeated line tracking method, Gabor filter, and isotropic non-subsampled wavelet transform). As shown in Equation 1, if a pixel is marked as a vein by four or more methods, then the pixel is classified as a vein pixel (value 1), otherwise it is regarded as a background pixel (value 0).

[0039]

[0040] The binary texture map L generated by this method is used as a supervision signal.

[0041] Then, the vein texture segmentation network is trained using texture labels to achieve automatic annotation of vein pixels. The original vein image is input into the trained vein texture segmentation network to automatically and precisely extract the vein pattern.

[0042] Next, the colored vein network G is trained.

[0043] The training of the coloring network is carried out on a large-scale color image dataset (ImageNet) with the goal of learning the coloring ability based on grayscale images and hints. The input to the model is the luminance L ∈ R H×W×1 (the L channel in the LAB color space) and the user hint H, and the output is Y ∈ R H×W×2 , that is, the color estimation value (the ab channels in the LAB color space).

[0044] The structure of the model consists of 10 convolutional blocks (conv1 - 10), forming a deeper encoder-decoder structure. In the encoder part (conv1 - 4), each block contains 2 - 3 convolutional-ReLU pairs, and the feature map size is gradually halved while the feature dimension is doubled. In the bottleneck part (conv5 - 6), dilated convolutions are used to retain more detailed information while maintaining the receptive field. The decoder part (conv7 - 10) gradually restores the spatial resolution and reduces the feature dimension. A batch normalization layer is added after each convolutional block to improve the training stability. At the end of the network, 1×1 convolutions and the tanh activation function are used to adapt to the bounded ab color space. In addition, the conv1 - 8 layers are fine-tuned using pre-trained weights. The objective function for supervising the learning of the coloring model is defined as:

[0045]

[0046] where δ is a threshold used to control the boundary of the error size. When the error is less than δ, the loss is the mean squared error MSE; otherwise, the loss is the mean absolute error MAE, and δ is set to 1. Here, 1 condition represents taking the value 1 when the condition is true and 0 when the condition is false.

[0047] The coloring model also has a local hint branch network that reuses the features of the main branch, connects the features of multiple layers of the main branch through the hypercolumn method, and learns a two-layer classifier at the top to predict the probability distribution of the output color where Q is the number of quantization color bins. This branch is supervised using cross-entropy loss:

[0048]

[0049] Then, vein image coloring is performed. Inferencing on G is used to color the vein image. The input includes L ∈ R H×W×1is the sum of the luminance channels of the input image in the LAB color space, defining the revocable identity I X , which includes a set of hint points hint(I X ) that corresponds uniquely to I X . The output is the final venous color estimation distribution Y ∈ R H×W×2 . By combining the grayscale L and Y, the final color veins can be obtained.

[0050] When defining the pseudo-random color space, in addition to using the set of hint points, a mask can also be used to set the pseudo-random luminance and the venous background color that corresponds uniquely to I X . This depends on the implementation of a special grayscale image type - binary image - of the input coloring model.

[0051] Finally, a feature extraction network is trained, as shown in Figure 2 . The color veins will be further feature-extracted to obtain a fixed-length feature vector for registration / verification. Extracting the fixed-length feature vector uses ResNet50 as the backbone of the deep feature extraction network. On this basis, a fully connected layer is added after layer4 to extract a deep feature vector with a fixed length of 128. This network uses a secure center loss function for supervised learning. The secure center loss function, in addition to considering the inherent variability of natural biometrics, the revocable biometrics also need to additionally consider the cancellability, irreversibility, and unlinkability of the template. The feature extraction network hopes to learn a secure extraction function. Specifically, the secure center loss is a five-tuple loss. The five-tuple consists of a class center, a registered user sample (positive), an imposter sample (negative), a cross-registered sample (negative), and a sample generated using a stolen token (negative). There are four comparison pairs, including one positive comparison pair and three negative comparison pairs. The positive comparison pair is the class center and the registered positive sample, and the negative comparison pairs are the sample center and the other three negative samples. For a good biometric recognition system, the score distributions of true matches and imposters should be clearly separable. To meet the requirement of revocability, for a revocable biometric recognition system, it is required that the score distribution generated by cross-application matching of users should be consistent with the distribution of imposters. At the same time, to avoid the catastrophic impact on the recognition system when the token is stolen (an adversary can access the system using only the token and any biometric reference), the revocable biometric recognition system also requires that the matching score distribution generated by such samples should be consistent with the distribution of imposters. SC Loss simultaneously considers maximizing the distances between the sample center and the four negative samples, making the matching score distributions of the four negative samples consistent and clearly separable from the true matching scores. In addition, the loss function used to supervise the feature extraction network also includes a softmax loss. Thus, the total loss is defined as:

[0052]

[0053] Among them, L S is the softmax loss, and L sc is the security center loss. N represents the number of samples in a mini-batch, and K represents the number of classes. represents the difference between the distances of positive and negative samples to the corresponding class centers, where represents the within-class distance, where j takes values from 1 to 3, representing the inter-class distances of registered users. The distances between the negative samples {I C , B X} and y i , and the distances between the negative samples {I X , B N} and y i . M is the margin difference. The corresponding λ values are 1, 0.001, and 0.001 respectively.

[0054] The finally extracted feature vectors can be stored or used for user identity authentication.

[0055] Test Example 1: Comparison of the ColorVein Scheme with Existing Representative Revocable Schemes

[0056] As Figure 3 shown, among all revocable schemes, ColorVein has the highest recognition ability and can ensure security in the case of stolen tokens. Next is Biohashing, which has good recognition performance under normal circumstances but is not ideal for stolen cases. On the contrary, the Bloom filter can hardly perform the recognition task under normal circumstances but can completely distinguish templates generated using stolen tokens. The block remapping and grid warping are relatively low. For irreversibility, first of all, Biohashing and the Bloom Filter show high irreversibility, which helps them project vein features onto a discrete binary space. The irreversibility of ColorVein is almost the same as theirs without losing information. By using smaller blocks or grids, block remapping and grid warping can enhance irreversibility. The Bloom filter, ColoVein, and Biohashing all have high unlinkability and revocability, indicating that these schemes can generate more diverse cancellable templates. Similarly, block remapping and grid warping can use smaller blocks or grids to increase the diversity of the generated templates. All in all, ColorVein has more comprehensive performance and is a cancellable biometric template generation solution specifically designed for vein biometric technology. In addition, from the perspective of vein pattern features, ColorVein creatively uses color as the key to designing cancellable templates and enriches the feature information of vein images to improve recognition performance.

[0057] Test Case 2: Visualization of ColorVein Features

[0058] The present invention provides the feature distribution of ColorVein visualized in a representative finger vein dataset, the HKPU-FV dataset. As Figure 4 shown, it shows 10 randomly selected users, and the number of test samples for each class is increased to 600 through traditional data augmentation methods. The results show that the differences between samples are obvious, while the veins of the same user tend to be concentrated in the center of their respective classes with small gaps.

[0059] Test Case 6: Effect of the Cancelable Recognition System Based on the ColorVein Scheme against Brute-Force Attacks This test case generates legitimate biometric templates to access the recognition system by exhaustively listing or guessing possible biometric data. The features generated by ColorVein range from [-10, 10] with a fixed precision of four decimal places, which means that each feature component requires 200,000 (≈2 17 ) attempts. Therefore, fully inferring a 64-dimensional feature vector requires 2 17×64 = 21088 attempts, which is computationally infeasible. 10,000 templates are randomly generated to attack the recognition system, and the distribution of brute-force attack matching scores is plotted. Figure 5 Shows the distribution of match scores for brute-force attacks and genuine / impostor match distributions under normal conditions. The results show that the distribution of match scores generated by brute-force attacks either overlaps with the impostor distribution or shows a leftward trend, indicating lower match scores. The EER on all datasets is 0, indicating that the distribution of brute-force attack match scores is completely different from the genuine match scores and can be completely distinguished by the system. This proves that ColorVein can effectively defend against brute-force attacks.

[0060] Test Case 4: Unlinkability Performance of the Cancelable Recognition System Based on the ColorVein Scheme

[0061] Unlinkability is a key property of cancelable biometric technologies, which requires no link between protected templates generated using different tokens. This property ensures that users can generate protected templates that are unlinked in different color spaces when registering for different applications / databases. Therefore, an attacker cannot launch an attack by analyzing the links between protected templates of a user in different applications. Specifically, this test case calculates paired and unpaired scores by setting different user tokens for users to cross-match and calculates the global link metric. Figure 6Shows the distribution of paired and unpaired scores on each dataset. The results show that the two distributions overlap highly in most parts, indicating that the revocable recognition system based on the present invention exhibits only extremely low global linkability and has good unlinkability.

[0062] Test Case 5: Revocability Performance of the Revocable Recognition System Based on the ColorVein Scheme

[0063] Revocability means that in a recognition system, the original (stolen) and new (re-released) templates are generated from the same finger vein template, but the two templates are not linked. This test case empirically studies revocability by generating an imposter distribution. Revocability can be empirically verified if (1) the imposter and pseudo-imposter distributions overlap, and (2) the genuine and pseudo-imposter distributions are clearly separable. Figure 7 Shows the genuine, imposter, and pseudo-imposter distributions on each dataset. There is a large overlap between the imposter and pseudo-imposter, while the genuine and pseudo-imposter distribution scores are clearly distinguishable. The separability or overlap between the two distributions can be quantitatively estimated by a qualitative index. The following table shows the separability index between the three distributions on each dataset. It can be observed that the separability index between the imposter and pseudo-imposter distributions on each dataset is very low. These show that the revocable finger vein recognition system provided by the present invention has good revocability.

[0064]

[0065] Test Case 6: Effect of the Revocable Recognition System Based on the ColorVein Scheme in Resisting False Acceptance Attacks False acceptance attacks are different from brute-force attacks because they may require fewer attempts to access. In this test case, it is assumed that the attacker knows exactly the template protection process of the recognition system, thus increasing the possibility of forging legitimate templates. In a threshold-based decision scheme, the matching score of the transformed template only needs to exceed a predetermined threshold to successfully access the system. To evaluate this attack, it is assumed that the attacker successfully guesses N% of the bits in ColorVein and attempts to access the recognition system. Figure 8 Shows the distribution of false acceptance attack and imposter matching scores. It can be observed that as more bits are guessed, the false attack matching scores gradually approach the true matching score distribution. The results show that the attacker has a very small chance of entry only when N is greater than 60%. This means that at least 38 feature vectors need to be successfully inferred, which is equivalent to 2 17×38 = 2646 attempts. Therefore, the false acceptance attack is still computationally infeasible. The revocable recognition system based on the ColorVein scheme can well resist false acceptance attacks.

[0066] The embodiments described above merely represent some embodiments of the present invention. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those skilled in the art, without departing from the concept of the present invention, several modifications and improvements can be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the invention patent shall be subject to the appended claims.

Claims

1. A revocable color vein authentication method for user security and privacy, characterized in that: The method includes the following steps: Step 1: Use a vein segmentation network to extract a binarized vein texture image from the original vein image. Step 2: Define a unique pseudo-random color hint corresponding to the identity, and pass the hint points as input to the vein coloring network to generate a unique colored vein image. Step 3: Input the generated colored vein image into a feature extraction network to generate a vein feature vector for identity matching for identity authentication.

2. The revocable color vein authentication method for user security and privacy according to claim 1, wherein The binarized vein texture segmentation in Step 1 is as follows: Use a deep learning model (ResU-Net) F with an encoder-decoder structure to extract the binarized vein pattern, realize the automatic annotation of vein pixels, and the learning model makes labels through a majority voting strategy to supervise the model learning.

3. The revocable colored vein identity authentication method for user security and privacy according to claim 2, wherein The majority voting strategy integrates the segmentation results of five classic baseline methods, namely the maximum curvature method, the principal curvature method, the repeated line tracking method, the Gabor filter, and the isotropic non-subsampled wavelet transform. As shown in Formula 1, if a pixel is marked as a vein by four or more methods, then the pixel is classified as a vein pixel (value 1), otherwise it is regarded as a background pixel (value 0). The binary texture map L generated by this method is used as a supervision signal for training the segmentation model. Among them, L(p) is the binary label of vein texture, and V i (p) is the binary texture map of different classical baseline methods.

4. The revocable color vein authentication method for user security and privacy according to claim 3, characterized in that In Step 2, Coloring network: The user interactive deep learning model serves as the coloring network G of ColorVein. The model spreads the user-edited color by integrating low-level hints and high-level semantic information learned from large-scale data. Specifically, the coloring model uses the pre-training of large-scale data to learn the prior knowledge of natural color images, and at the same time combines the user control in the traditional editing propagation framework. Using DCNN, it directly maps the grayscale image and sparse user input hints to the output color. The training of the coloring network is carried out on a large-scale color image dataset (ImageNet). The goal is to learn the coloring ability based on grayscale images and hints. The input of the model is the luminance L ∈ R of the grayscale image H×W×1 (the L channel of the LAB color space) and the user hint H, and the output is Y ∈ R H×W×2 , that is, the color estimation value (the ab channels in the LAB color space). The structure of the model consists of 10 convolutional blocks (conv1 - 10), forming a deeper encoder-decoder structure. In the encoder part (conv1 - 4), each block contains 2 - 3 convolutional-ReLU pairs, and the feature map size is halved step by step while the feature dimension is doubled. In the bottleneck part (conv5 - 6), dilated convolutions are used to retain more detailed information while maintaining the receptive field. The decoder part (conv7 - 10) gradually restores the spatial resolution and reduces the feature dimension. A batch normalization layer is added after each convolutional block to improve training stability. At the end of the network, 1×1 convolutions and a tanh activation function are used to adapt to the bounded ab color space. The conv1 - 8 layers are fine-tuned using pre-trained weights. The objective function used to supervise the learning of the coloring model is defined as: Among them, δ is a threshold used to control the boundary of the error magnitude. When the error is less than δ, the loss is the mean squared error MSE; otherwise, the loss is the mean absolute error MAE, and δ is set to 1, 1 condition represents taking the value of 1 when the condition is true and 0 when the condition is false, X i,j represents the predicted pixel value, Y i,j represents the corresponding labeled pixel value. The coloring model also has a local hint branch network, which reuses the features of the main branch, jumps to connect the features of multiple layers of the main branch, and learns a two-layer classifier at the top to predict the probability distribution of the output color where Q is the number of quantization color bins, and this branch uses the cross-entropy loss L CE for supervision: where H and W are the dimensions of the image, and Z is the label of the color.

5. The revocable color vein authentication method for user security and privacy according to claim 4, characterized in that, Revocable identity generation and vein coloring Let G be the model trained on the ImageNet dataset. Inferring on G to colorize vein images, the input includes L ∈ R H ×W×1 which is the sum of the luminance channels of the input image in the LAB color space. The defined revocable identity I X includes a set of hint points hint(I X ) that corresponds uniquely to I X . The output is the final vein color estimation distribution Y ∈ R H×W×2 . Combining the grayscale L and Y gives the final colored vein. When defining the pseudo-random color space, in addition to using the set of hint points, a mask can also be used. The pseudo-random luminance and vein background color corresponding uniquely to the vein region are set according to I X . This is achieved by relying on a special grayscale image type - binary image - of the input colorization model.

6. The revocable color vein authentication method for user security and privacy according to claim 4, wherein Protected revocable feature extraction in Step 3 After coloring, the colored vein will be further feature-extracted to obtain a fixed-length feature vector for registration / verification. Use ResNet50 as the backbone of the deep feature extraction network. On this basis, a fully connected layer is added after layer 4 to extract a deep feature vector with a fixed length of 128. This network uses a safety center loss function for supervised learning.

7. The revocable color vein authentication method for user security and privacy according to claim 6, characterized in that Safety center loss function Specifically, the safety center loss is a five-tuple loss. The five-tuple consists of a class center, a registered user sample (positive), an imposter sample (negative), a cross-registered sample (negative), and a sample generated using a stolen token (negative). There are four comparison pairs, including one positive comparison pair and three negative comparison pairs. The positive comparison pair is the class center and the registered positive sample, and the negative comparison pairs are the sample center and the other three negative samples. For a good biometric recognition system, the score distributions of true matches and imposters should be clearly separable. The total loss is defined as: Among them, L S is the softmax loss, and L sc is the security center loss. N represents the number of samples in a mini-batch, K represents the number of classes, represents the difference in distances from positive and negative samples to the corresponding class centers, where represents the within-class distance, where j takes values from 1 to 3 respectively representing the between-class distances of registered users, the distances between the negative samples {I C , B X} and y i and the distances between the negative samples {I X , B N} and y i . M is the margin difference, and the corresponding λ takes values of 1, 0.001, and 0.001 respectively.

8. A terminal, characterized in that: It includes a processor, a memory, and a revocable finger vein detector algorithm program for high-security identity recognition stored in the memory. When the revocable finger vein detector program for high-security identity recognition is run by the processor, it implements the revocable color vein identity authentication method for user security and privacy as described in any one of claims 1-7.

9. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instruction is executed by the processor, it implements the revocable color vein identity authentication method for user security and privacy as described in any one of claims 1-7.