Identity binding verification method and system

Through the communication network between the encryptor and the decryptor, multi-dimensional identity information and hybrid encryption algorithms are used, combined with similarity calculation and multiple verification modes, the problem of poor security and accuracy in identity binding verification is solved, and the efficient and secure verification of identity information is achieved.

CN120498868APending Publication Date: 2025-08-15SHENZHEN POWER SUPPLY BUREAU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510857684.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The problems of poor security and poor accuracy in existing identity binding verification are especially difficult to deal with complex security challenges when facing the diversity of user information and high privacy protection requirements.

Method used

A communication network that is interconnected by an encryptor and a decryptor is used to generate multi-dimensional identity information by collecting multiple identity information, and a hybrid encryption algorithm and feature vector extraction generate encryption keys, combining similarity calculation and multiple verification modes for identity binding verification, including simple verification mode and multiple verification mode.

Benefits of technology

It improves the security and accuracy of identity binding verification, dynamically adjusts the verification strength, reduces the risks of forgery and tampering, ensures reasonable verification in different scenarios, and enhances the security and reliability of the encryption process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498868A_ABST
    Figure CN120498868A_ABST
Patent Text Reader

Abstract

The invention provides an identity binding verification method, which comprises the following steps that: an encryptor collects various identity information of a user to form multi-dimensional identity information, extracts a feature vector of each identity information to combine and generate an encryption key, and further adopts a hybrid encryption algorithm to combine the multi-dimensional identity information with the encryption key, so that the identity binding verification is realized. Generating encrypted data; wherein the identity information comprises a password, a verification code and at least one biological characteristic; the decryptor decrypts the encrypted data and extracts feature vectors of the identity information, the similarity is further calculated in combination with preset user identity binding information so as to judge whether the identity information is successfully matched, and if the matching is successful, a corresponding verification mode is selected for identity binding verification so as to judge whether the identity information is successfully bound; wherein the check mode comprises a simple check mode and a multi-check mode. By implementing the identity binding verification method and device, the technical problems of relatively poor security and relatively poor accuracy in the existing identity binding verification can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of computer technology and digital identity technology, and in particular to an identity binding verification method and system. Background Art

[0002] With the widespread adoption of the internet and mobile devices, identity verification technology has become a critical means of safeguarding user information security and privacy. Traditional identity verification often relies on static information such as passwords and PIN codes, making it vulnerable to hacker attacks, password leaks, and social engineering attacks. This makes it difficult to address complex security challenges, especially given the diverse nature of user information and the high level of privacy protection required. Its limitations are particularly evident.

[0003] In recent years, with the rapid development of biometric recognition technology, biometrics such as fingerprints, facial recognition, and iris recognition have been widely used in identity verification due to their uniqueness and difficulty in forging, becoming an effective means of enhancing identity verification security. However, single-biometric verification also has some issues, such as significant environmental impact, limited recognition accuracy, and compatibility issues across different devices. Furthermore, the use of biometrics for identity binding verification also presents technical issues such as poor security and accuracy.

[0004] Therefore, there is an urgent need for a new identity authentication method that can solve the technical problems of poor security and poor accuracy in existing identity binding verification. Summary of the Invention

[0005] The technical problem to be solved by the embodiments of the present invention is to provide an identity binding verification method and system, which can solve the technical problems of poor security and poor accuracy in existing identity binding verification.

[0006] To solve the above technical problems, an embodiment of the present invention provides an identity binding verification method for use on a communication network interconnected by an encryptor and a decryptor, the method comprising the following steps:

[0007] The encryptor collects multiple identity information of the user to form multi-dimensional identity information, extracts feature vectors of each identity information to combine and generate an encryption key, and further uses a preset hybrid encryption algorithm to combine the multi-dimensional identity information with the encryption key to generate encrypted data; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0008] If the decryptor receives the encrypted data sent by the encryptor, it decrypts the multi-dimensional identity information and extracts the feature vector, and further combines the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is bound successfully; wherein, the verification mode includes a simple verification mode and a multiple verification mode; the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

[0009] The encryptor collects multiple identity information of the user to form multi-dimensional identity information, extracts feature vectors of each identity information to combine and generate an encryption key, and further uses a preset hybrid encryption algorithm to combine the multi-dimensional identity information with the encryption key to generate encrypted data. The specific steps include:

[0010] The encryptor collects multiple identity information of the user to form multi-dimensional identity information M, and performs feature extraction on each identity information in the multi-dimensional identity information M; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0011] The encryptor is implemented by the formula Generate encryption key K key ; Among them, w i is the weight coefficient of the i-th identity information, and its value is a constant between [0,1]; n is the number of identity information types contained in the multi-dimensional identity information M; I i is the feature vector of the i-th identity information; is an XOR operator; C is the timestamp carried by the encryptor; h(C) is the encryption processing function of the timestamp;

[0012] The encryptor determines a hybrid encryption algorithm composed of an asymmetric encryption algorithm RSA and a symmetric encryption algorithm AES, and combines the encryption key K key , encrypt the multi-dimensional identity information to obtain encrypted data D enc ;in, is the key obtained by encrypting with the asymmetric encryption algorithm RSA, and E pub is the public key when using the asymmetric encryption algorithm RSA; M enc is the identity information obtained by encrypting with the symmetric encryption algorithm AES, and M enc =AES(M,Kkey ).

[0013] The specific steps of extracting features from each type of identity information in the multi-dimensional identity information M by the encryptor include:

[0014] The encryptor uses the scale-invariant feature transform algorithm SIFT or ORB to extract the feature points of each biometric feature and forms a corresponding feature vector through the feature points;

[0015] The encryptor uses a preset hash function SHA-256 to convert the password into a hash value of fixed length to form a corresponding feature vector;

[0016] The encryptor uses a character recognition algorithm to extract numbers or letters in the verification code and then converts them into numerical values to form a corresponding feature vector.

[0017] Wherein, if the decryptor receives the encrypted data sent by the encryptor, it decrypts the multi-dimensional identity information and extracts the feature vector, and further combines the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is successfully bound. The specific steps of determining whether the identity information is successfully bound include:

[0018] If the decryptor receives the encrypted data D sent by the encryptor enc , then the inverse algorithm of the hybrid encryption algorithm decrypts the encrypted key, and then uses the decrypted key to decrypt the encrypted multi-dimensional identity information to obtain the decrypted multi-dimensional identity information

[0019] The decryptor decrypts the multi-dimensional identity information Perform feature extraction;

[0020] The decryptor is implemented by the formula Calculate the decrypted multi-dimensional identity information The similarity between the user identity binding information in, Its with I existing,j The maximum similarity between them; Decrypted multi-dimensional identity information The feature vector of the i-th identity information in existing,j is the comparison feature corresponding to the j-th identity information in the preset user identity binding information; is the inner product; is the weight coefficient of the ith contrast feature in the identity information comparison, and its value is a constant between [0,1]; n is the decrypted multidimensional identity information The number of types of identity information contained in is equal to the number of types of identity information contained in the multi-dimensional identity information M; Decrypted multi-dimensional identity information The square of the eigenvector of the i-th identity information; I existing,i is the comparison feature corresponding to the i-th identity information in the preset user identity binding information; is the square of the comparison feature corresponding to the i-th identity information in the preset user identity binding information;

[0021] If the decryptor determines that the calculated similarity If the calculated similarity is greater than the first preset threshold, the identity match is deemed successful; otherwise, If the value is less than or equal to the first preset threshold, the identity matching is deemed to have failed;

[0022] After the decryptor determines that the identity match is successful, if the calculated similarity is determined is greater than a second preset threshold, the simple verification mode and the algorithm contained therein are selected; or, if the calculated similarity is determined to be If the value of the simple verification mode is less than or equal to the second preset threshold, a multiple verification mode and the algorithms contained therein are selected; wherein the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash check algorithm and an anomaly detection algorithm based on machine learning;

[0023] The decryptor uses the formula Calculate the final verification score C final ; Wherein, m is the total number of algorithms contained in the simple verification mode or the multiple verification mode; α k The weight coefficients pre-assigned to each algorithm in the simple verification mode or the multiple verification mode are constants; is the verification output of the kth algorithm in the simple verification mode or the multiple verification mode, and takes a value of 1 or 0, where a value of 1 indicates that the current algorithm verification has passed, and a value of 0 indicates that the current algorithm verification has failed; λ(·) is a dynamic adjustment function; and λ0 are both preset constants; θ1 and θ2 are both thresholds pre-set between [0, 1];

[0024] If the decryptor determines the final verification score C finalIf the final verification score C is greater than the third preset threshold, the identity binding is deemed successful; otherwise, final If the value is less than or equal to the third preset threshold, it is determined that the identity binding has failed.

[0025] The embodiment of the present invention further provides an identity binding verification system, comprising: an encryptor and a decryptor; wherein,

[0026] The encryptor is configured to collect multiple identity information of a user to form multi-dimensional identity information, extract feature vectors of each identity information to combine and generate an encryption key, and further combine the multi-dimensional identity information with the encryption key using a preset hybrid encryption algorithm to generate encrypted data; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0027] The decryptor is used to decrypt the multi-dimensional identity information and extract the feature vector when receiving the encrypted data sent by the encryptor, and further combine the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is bound successfully; wherein, the verification mode includes a simple verification mode and a multiple verification mode; the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

[0028] Wherein, the encryptor includes:

[0029] An information collection and feature extraction unit, configured to collect multiple identity information of a user to form multi-dimensional identity information M, and perform feature extraction on each type of identity information in the multi-dimensional identity information M; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0030] Encryption key generation unit, used to generate the encryption key through the formula Generate encryption key K key ; Among them, w i is the weight coefficient of the i-th identity information, and its value is a constant between [0,1]; n is the number of identity information types contained in the multi-dimensional identity information M; I i is the feature vector of the i-th identity information; is an XOR operator; C is the timestamp carried by the encryptor; h(C) is the encryption processing function of the timestamp;

[0031] The hybrid encryption unit is used to determine the hybrid encryption algorithm composed of the asymmetric encryption algorithm RSA and the symmetric encryption algorithm AES, and combines the encryption key K key , encrypt the multi-dimensional identity information to obtain encrypted data D enc ;in, is the key obtained by encrypting with the asymmetric encryption algorithm RSA, and E pub is the public key when using the asymmetric encryption algorithm RSA; M enc is the identity information obtained by encrypting with the symmetric encryption algorithm AES, and M enc =AES(M,K key ).

[0032] Wherein, the decryptor includes:

[0033] The identity information decryption unit is used to decrypt the encrypted data D sent by the encryptor. enc , then the inverse algorithm of the hybrid encryption algorithm decrypts the encrypted key, and then uses the decrypted key to decrypt the encrypted multi-dimensional identity information to obtain the decrypted multi-dimensional identity information

[0034] Decryption information feature extraction unit, used to extract the decrypted multi-dimensional identity information Perform feature extraction;

[0035] Similarity calculation unit, used to calculate the similarity through the formula Calculate the decrypted multi-dimensional identity information The similarity between the user identity binding information in, Its with I existing,j The maximum similarity between them; Decrypted multi-dimensional identity information The feature vector of the i-th identity information in existing,j is the comparison feature corresponding to the j-th identity information in the preset user identity binding information; is the inner product; is the weight coefficient of the ith contrast feature in the identity information comparison, and its value is a constant between [0,1]; n is the decrypted multidimensional identity information The number of types of identity information contained in is equal to the number of types of identity information contained in the multi-dimensional identity information M; Decrypted multi-dimensional identity information The square of the eigenvector of the i-th identity information; I existing,iis the comparison feature corresponding to the i-th identity information in the preset user identity binding information; is the square of the comparison feature corresponding to the i-th identity information in the preset user identity binding information;

[0036] The identity matching judgment unit is used to determine if the calculated similarity If the calculated similarity is greater than the first preset threshold, the identity match is deemed successful; otherwise, If the value is less than or equal to the first preset threshold, the identity matching is deemed to have failed;

[0037] Verification mode selection unit, used to determine the calculated similarity after the identity match is successful is greater than a second preset threshold, the simple verification mode and the algorithm contained therein are selected; or, if the calculated similarity is determined to be If the value of the simple verification mode is less than or equal to the second preset threshold, a multiple verification mode and the algorithms contained therein are selected; wherein the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash check algorithm and an anomaly detection algorithm based on machine learning;

[0038] The verification score unit is used to calculate the verification score based on the selected verification mode and its included algorithms through the formula Calculate the final verification score C final ; Wherein, m is the total number of algorithms contained in the simple verification mode or the multiple verification mode; α k The weight coefficients pre-assigned to each algorithm in the simple verification mode or the multiple verification mode are constants; is the verification output of the kth algorithm in the simple verification mode or the multiple verification mode, and takes a value of 1 or 0, where a value of 1 indicates that the current algorithm verification has passed, and a value of 0 indicates that the current algorithm verification has failed; λ(·) is a dynamic adjustment function; and λ0 are both preset constants; θ1 and θ2 are both thresholds pre-set between [0, 1];

[0039] The identity binding judgment unit is used to determine the final verification score C final If the final verification score C is greater than the third preset threshold, the identity binding is deemed successful; otherwise, final If the value is less than or equal to the third preset threshold, it is determined that the identity binding has failed.

[0040] The implementation of the embodiments of the present invention has the following beneficial effects:

[0041] 1. The present invention uses similarity calculation to compare identity information in the decryptor. After the comparison is successful, different verification modes are selected (for example, simple verification mode uses loose verification, while multiple verification mode uses strict verification using multiple algorithms). This not only dynamically adjusts the verification strength and strategy, but also allows for flexible response to different scenarios, thereby ensuring the authenticity of identity information. It also reduces the risk of forgery and tampering, ensuring reasonable and effective verification in different scenarios (such as high and low similarity), thereby solving the technical problems of poor security and poor accuracy in existing identity binding verification.

[0042] 2. The present invention uses a hybrid encryption algorithm in the encryptor to ensure that the encryption process of identity information can not only provide efficient encryption performance, but also ensure the security of data during transmission and storage. In particular, encryption is performed by dynamically generating encryption keys and introducing factors such as timestamps to ensure the uniqueness and non-repetitiveness of the keys, thereby preventing the leakage of keys and the forgery of identity information, and enhancing the security and reliability of the encryption process. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, without paying any creative work, other drawings obtained based on these drawings still fall within the scope of the present invention.

[0044] Figure 1 A flowchart of an identity binding verification method provided by an embodiment of the present invention;

[0045] Figure 2 A schematic diagram of the structure of an identity binding verification system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0046] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention will be described in further detail below with reference to the accompanying drawings.

[0047] like Figure 1 FIG. 1 is a diagram showing an identity binding verification method provided in an embodiment of the present invention, which is used on a communication network formed by interconnecting an encryptor and a decryptor. The method includes the following steps:

[0048] Step S1: The encryptor collects multiple identity information of the user to form multi-dimensional identity information, extracts feature vectors of each identity information to combine and generate an encryption key, and further uses a preset hybrid encryption algorithm to combine the multi-dimensional identity information with the encryption key to generate encrypted data; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0049] The specific process is as follows: First, the encryptor collects multiple identity information of the user through sensor devices such as fingerprint sensors, facial recognition cameras, eye recognition devices, and password authentication devices to form multi-dimensional identity information M. In this case, the identity information includes but is not limited to passwords, verification codes, and at least one biometric feature (such as fingerprint features, facial features, iris features, etc.).

[0050] Next, the encryptor extracts features from each type of identity information in the multi-dimensional identity information M. For example, the encryptor uses the scale-invariant feature transform (SIFT) or ORB algorithm to extract feature points for each biometric feature and forms a corresponding feature vector from the feature points. Alternatively, the encryptor uses the preset hash function SHA-256 to convert the password into a fixed-length hash value to form a corresponding feature vector. Alternatively, the encryptor uses a character recognition algorithm to extract numbers or letters from the verification code and then converts them into numerical form to form a corresponding feature vector.

[0051] Then, the encryptor generates the encryption key K based on the eigenvector of the identity information using formula (1): key ;

[0052]

[0053] Among them, w i is the weight coefficient of the i-th identity information, which is a constant between [0,1]; n is the number of identity information types contained in the multi-dimensional identity information M; I i is the feature vector of the i-th identity information; is the XOR operator; C is the timestamp carried by the encryptor, which can be the current system time (for example, UTC time) to ensure that the generated key changes over time and is associated with the specific operation; h(C) is the encryption processing function of the timestamp.

[0054] It should be noted that the encryption key K key The encryption and decryption process used for subsequent identity information is unique and dynamic and closely related to the user's identity information, so it can be adjusted as the user's identity information changes, enhancing the security and uniqueness of the encryption process; iIndicates the relative importance of each identity information in the process of generating the final key, which is determined based on security requirements or the reliability of the identity information according to expert experience; It represents the unpredictable result of generating an encryption key through bit-level comparison. The XOR operation can effectively mix information and increase the complexity of the key. C can also represent a unique identifier of device information (such as a serial number). For example, if the same user performs authentication on different devices, the device information (such as the device serial number) ensures that the key generated for each device is different. h(C) is used to ensure the uniqueness and security of the key. The key part related to the device and time is generated through existing encryption or hash algorithms to ensure the uniqueness of the key.

[0055] Finally, the encryptor determines the hybrid encryption algorithm composed of the asymmetric encryption algorithm RSA and the symmetric encryption algorithm AES, and combines the encryption key K key , encrypt the multi-dimensional identity information and obtain the encrypted data D enc ;in, is the key obtained by encrypting with the asymmetric encryption algorithm RSA, and E pub is the public key when using the asymmetric encryption algorithm RSA; M enc is the identity information obtained by encrypting with the symmetric encryption algorithm AES, and M enc =AES(M,k key ).

[0056] It should be noted that the key k is encrypted by the asymmetric encryption algorithm RSA. key Encryption is performed to ensure that the key itself will not be leaked during transmission. And, through the symmetric encryption algorithm AES encryption, it can efficiently handle the encryption task of large amounts of data. At this time, the encrypted data D enc It contains the key encrypted by the asymmetric encryption algorithm RSA and the identity information encrypted by the symmetric encryption algorithm AES, ensuring the security of the information during transmission. Only the recipient with the correct private key can decrypt the key. Then use this key to decrypt the identity information M enc , thereby restoring the original identity data.

[0057] It is understandable that the technical goal of the above encryption process is to ensure that multi-dimensional identity information will not be leaked or tampered with during storage and transmission. Therefore, through the combination of dynamically generated keys and symmetric and asymmetric encryption algorithms in hybrid encryption algorithms, not only the encryption strength is improved, but also the computing efficiency is optimized, which is suitable for various authentication scenarios requiring high security.

[0058] Step S2: If the decryptor receives the encrypted data sent by the encryptor, it decrypts the multi-dimensional identity information and extracts the feature vector, and further combines the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is bound successfully; wherein, the verification mode includes a simple verification mode and a multiple verification mode; the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

[0059] The specific process is as follows: First, if the decryptor receives the encrypted data D sent by the encryptor enc , then the inverse algorithm of the hybrid encryption algorithm decrypts the encrypted key, and then uses the decrypted key to decrypt the encrypted multi-dimensional identity information to obtain the decrypted multi-dimensional identity information

[0060] Secondly, the decryptor decrypts the multi-dimensional identity information Perform feature extraction. At this time, the feature extraction method of the decryptor is the same as that of the encryptor in step S1. For details, please refer to the above content and will not be repeated here. That is, the decrypted multi-dimensional identity information The feature vector is obtained by using the feature extraction method in step S1

[0061] Then, the decryptor calculates the decrypted multi-dimensional identity information through formula (2) The similarity between the user identity binding information

[0062]

[0063] in, Its with I existing,j The maximum similarity between them is calculated by traversing the feature vectors of all preset user identity binding information. The similarity of the two and the largest similarity value are selected, aiming to select the registered identity feature that best matches the decrypted identity information feature; Decrypted multi-dimensional identity information The feature vector of the i-th identity information in existing,j is the comparison feature corresponding to the j-th identity information in the preset user identity binding information; is the inner product; is the weight coefficient of the i-th contrast feature in the identity information comparison, and the value is a constant between [0,1]. This reflects the importance of each feature in the final similarity calculation and can be determined based on expert experience. n is the decrypted multidimensional identity information. The number of types of identity information contained in is equal to the number of types of identity information contained in the multi-dimensional identity information M; Decrypted multi-dimensional identity information The square of the eigenvector of the i-th identity information represents the square of the modulus of the eigenvector; I existing,i is the comparison feature corresponding to the i-th identity information in the preset user identity binding information, that is, stored in the existing database; is the square of the comparison feature corresponding to the i-th identity information in the preset user identity binding information, indicating the square of the modulus of the comparison feature.

[0064] Then, if the decryptor determines that the calculated similarity If the calculated similarity is greater than the first preset threshold, the identity match is deemed successful; otherwise, If the value is less than or equal to the first preset threshold, it is determined that the identity matching fails.

[0065] Then, after the decryptor determines that the identity match is successful, if the calculated similarity is determined is greater than a second preset threshold, the simple verification mode and the algorithm contained therein are selected; or, if the calculated similarity is determined to be If the value is less than or equal to the second preset threshold, a multiple verification mode and the algorithms contained therein are selected; wherein the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

[0066] It is understandable that after the identity is matched, multiple verification phases are entered to further verify the authenticity of the identity information to prevent forgery or tampering. In order to improve the flexibility of verification, an adaptive verification algorithm is introduced to dynamically adjust the strength and strategy of the verification according to the similarity of the comparison. When the similarity is high, the simple verification mode is used, and when the similarity is high When lower, it switches to a stricter multi-check mode.

[0067] Then, the decryptor calculates the final verification score C according to the selected verification mode and the algorithm it contains through formula (3): final ;

[0068]

[0069] Where m is the total number of algorithms contained in the simple verification mode or the multiple verification mode, which is determined according to the specific verification mode; α k The weight coefficients pre-assigned to each algorithm in the simple verification mode or the multiple verification mode are constants; is the verification output of the kth algorithm in simple verification mode or multiple verification mode, and takes the value of 1 or 0, where a value of 1 indicates that the current algorithm verification has passed, and a value of 0 indicates that the current algorithm verification has failed. λ(·) is a dynamic adjustment function used to adjust the strength of the verification rules based on the similarity of the identity information. Its function is to adjust the strictness of the verification based on the similarity to prevent potential forgery or tampering. and λ0 are both preset constants; θ1 and θ2 are both thresholds pre-set between [0, 1].

[0070] It should be noted that It is the weight coefficient of the high similarity interval, which controls the strength of the verification rule under high similarity conditions. It is determined according to the expert experience method and is used to control whether loose verification is allowed when the identity information is highly matched. It is a non-negative number; β is the strength of the verification rule when the identity information is highly similar. When β is the exponent of the change of verification strength, it controls the nonlinear degree of verification strength as the similarity changes. A larger β will make the verification looser when the similarity is higher. It is a positive number with a value range of [0,10]. γ is the value of the identity information similarity. When the weight coefficient of the verification strength adjustment is , it controls the strictness of the verification when the similarity is at a medium level. It is determined according to the expert experience method and is a positive number less than δ is the identity information similarity When the similarity changes within this interval, the index of the change in verification strength determines the degree of change in verification strength. It is a positive number with a value range of [0,10]. λ0 is the value of the identity information similarity. The verification strength indicates that when the similarity is extremely low, the strictness of the verification reaches the maximum. This value ensures strict identity authentication to prevent identity information from being tampered with or forged. It is a fixed value set during design to ensure that the strictness of the verification does not decrease when the similarity is low, avoiding incorrect verification. θ1 is the threshold of the high similarity interval, which defines that when the similarity is greater than or equal to this value, the verification rules will be more relaxed. It is determined based on expert experience and has a value range of [0,1]. It is set to a higher value, close to 1, so that relaxed verification is only used when the identity information is extremely similar. θ2 is the threshold of the low similarity interval, which defines that when the similarity is lower than this value, the verification rules will be very strict. It is determined based on expert experience and has a value range of [0,1]. It is set to a lower value, close to 0, indicating that strict verification is only started when the identity information is significantly different.

[0071] Finally, if the decryptor determines the final verification score C final If the final verification score C is greater than the third preset threshold, the identity binding is deemed successful; otherwise, final If the value is less than or equal to the third preset threshold, it is determined that the identity binding has failed.

[0072] It should be noted that the first to third preset thresholds and the constants or constants in the formula can be flexibly adjusted according to actual conditions and will not be elaborated here.

[0073] like Figure 2 As shown in FIG, an embodiment of the present invention provides an identity binding verification system, including: an encryptor 1 and a decryptor 2; wherein,

[0074] The encryptor 1 is configured to collect multiple identity information of a user to form multi-dimensional identity information, extract feature vectors of each identity information to combine and generate an encryption key, and further combine the multi-dimensional identity information with the encryption key using a preset hybrid encryption algorithm to generate encrypted data; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0075] The decryptor 2 is used to decrypt the multi-dimensional identity information and extract the feature vector when receiving the encrypted data sent by the encryptor 1, and further combine the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is bound successfully; wherein, the verification mode includes a simple verification mode and a multiple verification mode; the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

[0076] Wherein, the encryptor 1 includes:

[0077] An information collection and feature extraction unit, configured to collect multiple identity information of a user to form multi-dimensional identity information M, and perform feature extraction on each type of identity information in the multi-dimensional identity information M; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature;

[0078] Encryption key generation unit, used to generate the encryption key through the formula Generate encryption key K key ; Among them, w iis the weight coefficient of the i-th identity information, and its value is a constant between [0,1]; n is the number of identity information types contained in the multi-dimensional identity information M; I i is the feature vector of the i-th identity information; is an XOR operator; C is the timestamp carried by the encryptor; h(C) is the encryption processing function of the timestamp;

[0079] The hybrid encryption unit is used to determine the hybrid encryption algorithm composed of the asymmetric encryption algorithm RSA and the symmetric encryption algorithm AES, and combines the encryption key K key , encrypt the multi-dimensional identity information to obtain encrypted data D enc ;in, is the key obtained by encrypting with the asymmetric encryption algorithm RSA, and E pub is the public key when using the asymmetric encryption algorithm RSA; M enc is the identity information obtained by encrypting with the symmetric encryption algorithm AES, and M enc =AES(M,K key ).

[0080] Wherein, the decryptor 2 includes:

[0081] The identity information decryption unit is used to decrypt the encrypted data D sent by the encryptor. enc , then the inverse algorithm of the hybrid encryption algorithm decrypts the encrypted key, and then uses the decrypted key to decrypt the encrypted multi-dimensional identity information to obtain the decrypted multi-dimensional identity information

[0082] Decryption information feature extraction unit, used to extract the decrypted multi-dimensional identity information Perform feature extraction;

[0083] Similarity calculation unit, used to calculate the similarity through the formula Calculate the decrypted multi-dimensional identity information The similarity between the user identity binding information in, Its with I existing,j The maximum similarity between them; Decrypted multi-dimensional identity information The feature vector of the i-th identity information in existing,j is the comparison feature corresponding to the j-th identity information in the preset user identity binding information; is the inner product; is the weight coefficient of the ith contrast feature in the identity information comparison, and its value is a constant between [0,1]; n is the decrypted multidimensional identity information The number of types of identity information contained in is equal to the number of types of identity information contained in the multi-dimensional identity information M; Decrypted multi-dimensional identity information The square of the eigenvector of the i-th identity information; I existing,i is the comparison feature corresponding to the i-th identity information in the preset user identity binding information; is the square of the comparison feature corresponding to the i-th identity information in the preset user identity binding information;

[0084] The identity matching judgment unit is used to determine if the calculated similarity If the calculated similarity is greater than the first preset threshold, the identity match is deemed successful; otherwise, If the value is less than or equal to the first preset threshold, the identity matching is deemed to have failed;

[0085] Verification mode selection unit, used to determine the calculated similarity after the identity match is successful is greater than a second preset threshold, the simple verification mode and the algorithm contained therein are selected; or, if the calculated similarity is determined to be If the value of the simple verification mode is less than or equal to the second preset threshold, a multiple verification mode and the algorithms contained therein are selected; wherein the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash check algorithm and an anomaly detection algorithm based on machine learning;

[0086] The verification score unit is used to calculate the verification score based on the selected verification mode and its included algorithms through the formula Calculate the final verification score C final ; Wherein, m is the total number of algorithms contained in the simple verification mode or the multiple verification mode; α k The weight coefficients pre-assigned to each algorithm in the simple verification mode or the multiple verification mode are constants; is the verification output of the kth algorithm in the simple verification mode or the multiple verification mode, and takes a value of 1 or 0, where a value of 1 indicates that the current algorithm verification has passed, and a value of 0 indicates that the current algorithm verification has failed; λ(·) is a dynamic adjustment function; and λ0 are both preset constants; θ1 and θ2 are both thresholds pre-set between [0, 1];

[0087] The identity binding judgment unit is used to determine the final verification score C finalIf the final verification score C is greater than the third preset threshold, the identity binding is deemed successful; otherwise, final If the value is less than or equal to the third preset threshold, it is determined that the identity binding has failed.

[0088] The implementation of the embodiments of the present invention has the following beneficial effects:

[0089] 1. The present invention uses similarity calculation to compare identity information in the decryptor. After the comparison is successful, different verification modes are selected (for example, simple verification mode uses loose verification, while multiple verification mode uses strict verification using multiple algorithms). This not only dynamically adjusts the verification strength and strategy, but also allows for flexible response to different scenarios, thereby ensuring the authenticity of identity information. It also reduces the risk of forgery and tampering, ensuring reasonable and effective verification in different scenarios (such as high and low similarity), thereby solving the technical problems of poor security and poor accuracy in existing identity binding verification.

[0090] 2. The present invention uses a hybrid encryption algorithm in the encryptor to ensure that the encryption process of identity information can not only provide efficient encryption performance, but also ensure the security of data during transmission and storage. In particular, encryption is performed by dynamically generating encryption keys and introducing factors such as timestamps to ensure the uniqueness and non-repetitiveness of the keys, thereby preventing the leakage of keys and the forgery of identity information, and enhancing the security and reliability of the encryption process.

[0091] Those skilled in the art will understand that all or part of the steps in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a program, and the program can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc.

[0092] The above disclosure is merely a preferred embodiment of the present invention and certainly cannot be used to limit the scope of the present invention. Therefore, equivalent changes made according to the claims of the present invention are still within the scope of the present invention.

Claims

1. A method for verifying identity binding, characterized in that: Used on a communication network formed by interconnecting an encryptor and a decryptor, the method comprises the following steps: The encryptor collects multiple identity information of the user to form multi-dimensional identity information, extracts feature vectors of each identity information to combine and generate an encryption key, and further uses a preset hybrid encryption algorithm to combine the multi-dimensional identity information with the encryption key to generate encrypted data; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature; If the decryptor receives the encrypted data sent by the encryptor, it decrypts the multi-dimensional identity information and extracts the feature vector, and further combines the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is bound successfully; wherein, the verification mode includes a simple verification mode and a multiple verification mode; the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

2. The identity binding verification method according to claim 1, characterized in that: The encryptor collects multiple identity information of the user to form multi-dimensional identity information, extracts feature vectors of each identity information to combine and generate an encryption key, and further uses a preset hybrid encryption algorithm to combine the multi-dimensional identity information with the encryption key to generate encrypted data. The specific steps include: The encryptor collects multiple identity information of the user to form multi-dimensional identity information M, and performs feature extraction on each identity information in the multi-dimensional identity information M; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature; The encryptor is implemented by the formula Generate encryption key K key ; Among them, w i is the weight coefficient of the i-th identity information, and its value is a constant between [0,1]; n is the number of identity information types contained in the multi-dimensional identity information M; I i is the feature vector of the i-th identity information; is an XOR operator; C is the timestamp carried by the encryptor; h(C) is the encryption processing function of the timestamp; The encryptor determines a hybrid encryption algorithm composed of an asymmetric encryption algorithm RSA and a symmetric encryption algorithm AES, and combines the encryption key K key , encrypt the multi-dimensional identity information to obtain encrypted data D enc ;in, is the key obtained by encrypting with the asymmetric encryption algorithm RSA, and E pub is the public key when using the asymmetric encryption algorithm RSA; M enc is the identity information obtained by encrypting with the symmetric encryption algorithm AES, and M enc =AES(M,K key ).

3. The identity binding verification method according to claim 2, characterized in that: The specific steps of extracting features of each type of identity information in the multi-dimensional identity information M by the encryptor include: The encryptor uses the scale-invariant feature transform algorithm SIFT or ORB to extract the feature points of each biometric feature and forms a corresponding feature vector through the feature points; The encryptor uses a preset hash function SHA-256 to convert the password into a hash value of fixed length to form a corresponding feature vector; The encryptor uses a character recognition algorithm to extract numbers or letters in the verification code and then converts them into numerical values to form a corresponding feature vector.

4. The identity binding verification method according to claim 3, characterized in that: If the decryptor receives the encrypted data sent by the encryptor, it decrypts the multi-dimensional identity information and extracts the feature vector. It further calculates the similarity between the decrypted multi-dimensional identity information and the user identity binding information based on the comparative features corresponding to each identity information in the preset user identity binding information to determine whether the identity information matches successfully. After determining that the identity matches successfully, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is successfully bound. The specific steps of determining whether the identity information is successfully bound include: If the decryptor receives the encrypted data D sent by the encryptor enc , then the inverse algorithm of the hybrid encryption algorithm decrypts the encrypted key, and then uses the decrypted key to decrypt the encrypted multi-dimensional identity information to obtain the decrypted multi-dimensional identity information The decryptor decrypts the multi-dimensional identity information Perform feature extraction; The decryptor is implemented by the formula Calculate the decrypted multi-dimensional identity information The similarity between the user identity binding information in, Its with I existing,j The maximum similarity between them; Decrypted multi-dimensional identity information The feature vector of the i-th identity information in existing,j is the comparison feature corresponding to the j-th identity information in the preset user identity binding information; is the inner product; is the weight coefficient of the ith contrast feature in the identity information comparison, and its value is a constant between [0,1]; n is the decrypted multidimensional identity information The number of types of identity information contained in is equal to the number of types of identity information contained in the multi-dimensional identity information M; Decrypted multi-dimensional identity information The square of the eigenvector of the i-th identity information; I existing,i is the comparison feature corresponding to the i-th identity information in the preset user identity binding information; is the square of the comparison feature corresponding to the i-th identity information in the preset user identity binding information; If the decryptor determines that the calculated similarity If the calculated similarity is greater than the first preset threshold, the identity match is deemed successful; otherwise, If the value is less than or equal to the first preset threshold, the identity matching is deemed to have failed; After the decryptor determines that the identity match is successful, if the calculated similarity is determined is greater than a second preset threshold, the simple verification mode and the algorithm contained therein are selected; or, if the calculated similarity is determined to be If the value of the simple verification mode is less than or equal to the second preset threshold, a multiple verification mode and the algorithms contained therein are selected; wherein the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash check algorithm and an anomaly detection algorithm based on machine learning; The decryptor uses the formula Calculate the final verification score C final ; Wherein, m is the total number of algorithms contained in the simple verification mode or the multiple verification mode; α k The weight coefficients pre-assigned to each algorithm in the simple verification mode or the multiple verification mode are constants; is the verification output of the kth algorithm in the simple verification mode or the multiple verification mode, and takes a value of 1 or 0, where a value of 1 indicates that the current algorithm verification has passed, and a value of 0 indicates that the current algorithm verification has failed; λ(·) is a dynamic adjustment function; β, γ, δ and λ0 are all preset constants; θ1 and γ2 are both thresholds pre-set between [0, 1]; If the decryptor determines the final verification score C final If the final verification score C is greater than the third preset threshold, the identity binding is deemed successful; otherwise, final If the value is less than or equal to the third preset threshold, it is determined that the identity binding has failed.

5. An identity binding verification system, characterized in that: include: an encryptor and a decryptor; wherein, The encryptor is configured to collect multiple identity information of a user to form multi-dimensional identity information, extract feature vectors of each identity information to combine and generate an encryption key, and further combine the multi-dimensional identity information with the encryption key using a preset hybrid encryption algorithm to generate encrypted data; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature; The decryptor is used to decrypt the multi-dimensional identity information and extract the feature vector when receiving the encrypted data sent by the encryptor, and further combine the comparative features corresponding to each identity information in the preset user identity binding information to calculate the similarity between the decrypted multi-dimensional identity information and the user identity binding information to determine whether the identity information matches successfully. After determining that the identity match is successful, the corresponding verification mode and the algorithm contained therein are selected according to the calculated similarity to perform identity binding verification to determine whether the identity information is bound successfully; wherein, the verification mode includes a simple verification mode and a multiple verification mode; the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash verification algorithm and an anomaly detection algorithm based on machine learning.

6. The identity binding verification system according to claim 5, characterized in that: The encryptor comprises: An information collection and feature extraction unit, configured to collect multiple identity information of a user to form multi-dimensional identity information M, and perform feature extraction on each type of identity information in the multi-dimensional identity information M; wherein the multiple identity information includes a password, a verification code, and at least one biometric feature; Encryption key generation unit, used to generate the encryption key through the formula Generate encryption key K key ; Among them, w i is the weight coefficient of the i-th identity information, and its value is a constant between [0,1]; n is the number of identity information types contained in the multi-dimensional identity information M; I i is the feature vector of the i-th identity information; is an XOR operator; C is the timestamp carried by the encryptor; h(C) is the encryption processing function of the timestamp; The hybrid encryption unit is used to determine the hybrid encryption algorithm composed of the asymmetric encryption algorithm RSA and the symmetric encryption algorithm AES, and combines the encryption key K key , encrypt the multi-dimensional identity information to obtain encrypted data D enc ;in, is the key obtained by encrypting with the asymmetric encryption algorithm RSA, and E pub is the public key when using the asymmetric encryption algorithm RSA; M enc is the identity information obtained by encrypting with the symmetric encryption algorithm AES, and M enc =AES(M,K key ).

7. The identity binding verification system according to claim 6, characterized in that: The decryptor comprises: The identity information decryption unit is used to decrypt the encrypted data D sent by the encryptor. enc , then the inverse algorithm of the hybrid encryption algorithm decrypts the encrypted key, and then uses the decrypted key to decrypt the encrypted multi-dimensional identity information to obtain the decrypted multi-dimensional identity information Decryption information feature extraction unit, used to extract the decrypted multi-dimensional identity information Perform feature extraction; Similarity calculation unit, used to calculate the similarity through the formula Calculate the decrypted multi-dimensional identity information The similarity between the user identity binding information in, Its with I existing,j The maximum similarity between them; Decrypted multi-dimensional identity information The feature vector of the i-th identity information in existing,j is the comparison feature corresponding to the j-th identity information in the preset user identity binding information; is the inner product; is the weight coefficient of the ith contrast feature in the identity information comparison, and its value is a constant between [0,1]; n is the decrypted multidimensional identity information The number of types of identity information contained in is equal to the number of types of identity information contained in the multi-dimensional identity information M; Decrypted multi-dimensional identity information The square of the eigenvector of the i-th identity information; I existing,i is the comparison feature corresponding to the i-th identity information in the preset user identity binding information; is the square of the comparison feature corresponding to the i-th identity information in the preset user identity binding information; The identity matching judgment unit is used to determine if the calculated similarity If the calculated similarity is greater than the first preset threshold, the identity match is deemed successful; otherwise, If the value is less than or equal to the first preset threshold, the identity matching is deemed to have failed; Verification mode selection unit, used to determine the calculated similarity after the identity match is successful is greater than a second preset threshold, the simple verification mode and the algorithm contained therein are selected; or, if the calculated similarity is determined to be If the value of the simple verification mode is less than or equal to the second preset threshold, a multiple verification mode and the algorithms contained therein are selected; wherein the simple verification mode includes a hash value check algorithm; the multiple verification mode includes a multiple hash check algorithm and an anomaly detection algorithm based on machine learning; The verification score unit is used to calculate the verification score based on the selected verification mode and its included algorithms through the formula Calculate the final verification score C final ; Wherein, m is the total number of algorithms contained in the simple verification mode or the multiple verification mode; α k The weight coefficients pre-assigned to each algorithm in the simple verification mode or the multiple verification mode are constants; is the verification output of the kth algorithm in the simple verification mode or the multiple verification mode, and takes a value of 1 or 0, where a value of 1 indicates that the current algorithm verification has passed, and a value of 0 indicates that the current algorithm verification has failed; λ(·) is a dynamic adjustment function; β, γ, δ and λ0 are all preset constants; θ1 and θ2 are both thresholds pre-set between [0, 1]; The identity binding judgment unit is used to determine the final verification score C final If the final verification score C is greater than the third preset threshold, the identity binding is deemed successful; otherwise, final If the value is less than or equal to the third preset threshold, it is determined that the identity binding has failed.