A Face Data Lifecycle Management System and Method
By using national cryptographic encryption and SSL protocols, implicit watermarking for traceability, and role-based access control, the system addresses the issues of uniformity and security in the management of facial recognition data in universities, enabling full lifecycle data supervision and authorized access, and reducing the risk of data leakage.
Patent Information
- Application Number
- CN202510621047.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-05-14
AI Technical Summary
Existing technologies cannot uniformly manage the facial data of teachers and students from different brands and scenarios. They lack secure data storage and distribution mechanisms, cannot achieve full lifecycle management, and pose a risk of leakage and lack compliance.
The system employs the national cryptographic algorithm SM4 and the SSL protocol to encrypt and store facial data, establishes a role-based access control mechanism, embeds implicit watermarks for traceability, implements cross-system data destruction, and ensures data quality and security through quality assessment and feature extraction algorithms.
It enables full lifecycle supervision of facial data of university faculty and students from generation to destruction, ensuring data security, reducing the risk of leakage, and ensuring compliance and the authorized scope of data use.
Smart Images

Figure CN120541877B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security and privacy protection technology, specifically relating to a face data full lifecycle management system and method. Background Technology
[0002] Facial recognition technology is currently widely used in universities for scenarios such as school gates, dormitories, canteens, unified identity authentication, and new student identity verification, and has been well received by teachers and students. However, network security, data security, and personal information security also need to be given more attention.
[0003] Problems with existing technology:
[0004] High management difficulty: It is impossible to manage the faces of teachers and students in a unified manner. Different brands, different usage scenarios, and different face quality requirements lead to repeated collection of teachers' and students' facial information, which increases management difficulty, reduces user satisfaction, and expands the risk of leakage.
[0005] The authorization mechanism is inadequate: individuals cannot authorize or withdraw facial recognition, making it impossible to form a closed-loop management system.
[0006] Insecure data storage and distribution mechanisms: The lack of secure and compliant data storage and distribution mechanisms leads to the disorderly use of facial data and sensitive personal information, posing a risk of leakage.
[0007] Passive supervision: It is impossible to achieve full lifecycle management of the facial data of all teachers and students, and to make unified management, supervision, early warning and analysis, so the work is relatively passive;
[0008] Compliance risks: If facial recognition is forced to be used, complaints may arise, causing adverse effects. Summary of the Invention
[0009] The purpose of this invention is to provide a facial data full lifecycle management system and method, which can realize full lifecycle supervision of facial data of college teachers and students from generation to destruction, and ensure the security of facial data and personal information.
[0010] The specific technical solution adopted by this invention is as follows:
[0011] A face data full lifecycle management system includes a full lifecycle management system, which internally includes a data acquisition module, a data storage module, a data processing module, a data distribution module, a data destruction module, and a monitoring and analysis module.
[0012] The data storage module uses the national cryptographic algorithm SM to encrypt and store the data in the face database; during data transmission, the SSL protocol is used to encrypt the data.
[0013] The data distribution module uses the SSL / TLS protocol to encrypt the transmission channel; when establishing a connection, the system performs strict authentication, and only authorized business systems can obtain face copy data; at the same time, the integrity of the transmitted data is verified.
[0014] The data distribution module employs implicit watermark embedding and traceability to perform implicit watermark processing when data is distributed to the face business system, and provides real data traceability capabilities to trace the source of face data in the event of security incidents such as data leakage.
[0015] The data distribution module adopts an authorized access control mechanism: a role-based access control mechanism is established to assign different access permissions to different business systems, ensuring that facial data is used only within the authorized scope;
[0016] The data destruction module employs cross-system data destruction: when an individual withdraws authorization to use facial data, the system first destroys the user's facial data within its own system; then, it sends a destruction instruction to all business systems that have acquired the user's facial data through a predefined interface; upon receiving the instruction, the business system immediately deletes the relevant data stored locally and returns the destruction result to the system.
[0017] The data acquisition module is used to perform real-time quality assessment of the acquired images during the mobile phone camera acquisition process.
[0018] The data processing module employs a quality verification algorithm: it performs quality verification on the acquired face images. This algorithm comprehensively considers the image's feature indicators, and only when all the image quality indicators reach the preset threshold is the image considered to be of acceptable quality.
[0019] The data processing module employs a feature extraction algorithm: it extracts features from qualified facial images, and the extracted feature values have high discriminative power and stability, which are used to accurately represent the biometric features of the face.
[0020] The regulatory analysis module includes a regulatory log recording unit, which records the entire lifecycle of facial data in detail, including information such as data collection time, collection personnel, authorized business systems, and destruction time.
[0021] The regulatory analysis module includes a real-time monitoring unit, allowing regulatory personnel to view the usage of facial data in real time through the system interface, and also features abnormal access detection.
[0022] The regulatory analysis module includes a data analysis and report generation unit. The system regularly analyzes regulatory logs and generates various statistical reports.
[0023] A method for full lifecycle management of facial data, with the following specific steps:
[0024] Step 1: Personal Authorization: Before facial data collection, the system displays an authorization agreement to the individual, clearly informing them of the purpose of data collection, scope of use, storage period, and other information. The individual then authorizes the data through the system interface.
[0025] Step 2: Face capture and verification: Face images are captured using a mobile phone camera according to a unified standard and process; the captured face images are verified for quality through a quality assessment algorithm to ensure that the images are clear, unobstructed, and free of blur; at the same time, the captured face images are associated with personal identity information for public security face identity verification.
[0026] Step 3: Secure Storage and Distribution: Verified facial data is encrypted using national cryptographic algorithms and stored in the database; when other business systems need to use facial data, the system distributes the matching data to the relevant business systems through SSL secure encrypted transmission.
[0027] Step 4: Authorization and Access Control: Establish a role-based access control mechanism to assign different access permissions to different business systems, ensuring that facial data is used only within the authorized scope;
[0028] Step 5: Full Lifecycle Monitoring and Analysis: The system conducts full lifecycle monitoring and analysis of user facial data from generation to destruction, recording information such as data collection time, verification status, usage, and destruction time, and generating a full monitoring log; supervisors can view the monitoring log through the system interface to monitor and analyze the use of facial data in real time.
[0029] In step 3, a face recognition function is added. The specific steps are as follows:
[0030] Step 3.1: Watermark Information Generation and Encryption: Construct a traceability identifier and embed watermark fragments;
[0031] Step 3.2: Data distribution and watermark association: Construct a watermark-distribution record mapping table and store it encrypted;
[0032] Step 3.3: In the event of a data breach, perform implicit watermarking for source tracing;
[0033] Step 3.4: Watermark Extraction and Decoding: Feature Vector Sampling and Identifier Reconstruction;
[0034] Step 3.5: Source tracing and verification: Record the query and match, and perform the query in the watermark-distribution record mapping table according to the reconstruction identifier.
[0035] In step 5, the facial data is revoked and destroyed, and the specific steps are as follows:
[0036] Step 5.1: Triggering conditions and event modeling: User triggers authorization revocation event, data status is marked;
[0037] Step 5.2: Data Destruction in this System: Perform logical deletion and physical clearing;
[0038] Step 5.3: Cross-system command broadcast: Predefine destruction commands and use a broadcast mechanism to send the commands to all related business systems;
[0039] Step 5.4: Business System Response and Feedback;
[0040] Step 5.5: State Synchronization and Auditing: The master system verifies the response signatures of all business systems, updates the global state, and writes it to the audit log.
[0041] The technical effects achieved by this invention are as follows:
[0042] This invention comprehensively manages the personal authorization, face collection, identity and quality verification, national cryptographic storage and distribution, revocation and destruction, and traceability of facial data, thereby achieving full lifecycle supervision of the facial data of university teachers and students from generation to destruction and ensuring the security of facial data and personal information.
[0043] This invention is the first to propose the concept of full lifecycle management of facial data in universities, covering all aspects from data collection to destruction, and realizing comprehensive supervision of facial data.
[0044] This invention combines multiple algorithm standards and can be adapted to various brands of facial recognition quality algorithms, such as Megvii, SenseTime, and Baidu, thus solving the problem of quality standard compatibility between different algorithms.
[0045] The facial recognition traceability function in this invention adds an implicit digital watermark to the distributed film. In the event of a security incident such as a data breach, the system can trace the source of the data and determine the responsible party through the digital watermark information.
[0046] The facial data revocation and destruction function in this invention enables the system to quickly and uniformly destroy relevant data from this system to all business systems that have acquired the user's facial data when an individual withdraws the authorization to use the facial data. It also ensures that the data cannot be recovered during the destruction process. Attached Figure Description
[0047] Figure 1 This is a system diagram of the management system provided in an embodiment of the present invention;
[0048] Figure 2 This is a flowchart of the management method provided in an embodiment of the present invention;
[0049] Figure 3This is a flowchart of the face tracing function provided in an embodiment of the present invention;
[0050] Figure 4 This is a flowchart of data cancellation and destruction provided in an embodiment of the present invention.
[0051] The attached diagram lists the components represented by each number as follows:
[0052] 1. Full lifecycle management system; 101. Data acquisition module; 102. Data storage module; 103. Data processing module; 104. Data distribution module; 105. Data destruction module; 106. Monitoring and analysis module. Detailed Implementation
[0053] To make the objectives and advantages of this invention clearer, the invention will be specifically described below with reference to embodiments. It should be understood that the following text is merely used to describe one or more specific embodiments of the invention and does not strictly limit the scope of protection specifically claimed by the invention.
[0054] like Figure 1 As shown, a face data full lifecycle management system includes a full lifecycle management system 1. The full lifecycle management system 1 is internally configured with a data acquisition module 101, a data storage module 102, a data processing module 103, a data distribution module 104, a data destruction module 105, and a monitoring and analysis module 106.
[0055] (a) Data acquisition module 101;
[0056] During the mobile phone camera capture process, the system performs real-time quality assessment on the captured images, such as detecting indicators like brightness, contrast, and sharpness. If the image quality does not meet the standards, the user is prompted to recapture the image.
[0057] The specific process is as follows:
[0058] Step 1, Brightness Detection
[0059] Mathematical formula: Where I(x) i y i ) represents a pixel (x) i y i The grayscale value of ) is N, where N is the total number of pixels, and the brightness threshold can be set to [L]. min L max If the brightness exceeds the specified range, it is determined that the brightness does not meet the standard.
[0060] Step 2, Contrast Evaluation
[0061] Mathematical formula: Contrast ratio is measured by calculating the standard deviation of pixel values and average brightness. If C RMS <C threshold The message indicates insufficient contrast.
[0062] Step 3, Sharpness Detection
[0063] Tenengrad gradient method: Where Gx and Gy are the Sobel convolution results in the horizontal and vertical directions of the image, respectively, and the sharpness threshold S is the image sharpness threshold S. threshold It needs to be dynamically adjusted according to equipment performance;
[0064] Step 4: Joint judgment based on multiple indicators
[0065] The system uses preset thresholds to perform a weighted comprehensive score on brightness, contrast, and sharpness.
[0066] Where w1, w2, and w3 are weighting coefficients, and their sum is 1. If Q < Q threshold This triggers a resampling prompt;
[0067] Step 5: Real-time feedback optimization
[0068] Using dynamic data management logic, when the system detects a quality problem, it displays specific indicators (such as "insufficient brightness" or "blurry image") on the mobile phone interface and guides the user to adjust the shooting angle or ambient light.
[0069] Based on the above, this data acquisition module quantifies image quality indicators through mathematical modeling and achieves efficient acquisition by combining a dynamic feedback mechanism, which meets the requirements of university management systems for data accuracy and real-time performance.
[0070] (ii) Data storage module 102;
[0071] Encrypted storage: The face database is encrypted using the SM4 national cryptographic algorithm; during data transmission, SSL is used to encrypt the data to ensure data security during transmission.
[0072] 2.1) The SM4 encryption algorithm, using a block cipher mode, can be divided into the following core steps:
[0073] Step 1, Key Expansion: Expand the initial 128-bit key into a 32-round key.
[0074] Where CTi are fixed parameters and T′ are nonlinear transformation functions;
[0075] Step 2, Round Function Operation: In each round, a non-linear transformation is performed on the 128-bit data block.
[0076] The T function includes an S-box permutation (a nonlinear table with four 8-bit inputs) and a linear transformation L, where L is specifically:
[0077]
[0078] 2.2) Encrypted storage implementation process:
[0079] Step 1, face feature vector preprocessing: Divide the 128-dimensional face feature vector into SM4 group length (128 bits), and fill in any insufficient parts to complete the block;
[0080] Step 2, CBC mode encryption: Initialization vectors (IVs) are used to implement inter-block association to prevent duplicate plaintext from generating the same ciphertext. Where C0 = IV, P i For the i-th plaintext block, C i This corresponds to the ciphertext block.
[0081] 2.3) Data transmission is encrypted using the SSL protocol:
[0082] Step 1, Key Exchange and Authentication:
[0083] ECDH Key Negotiation (based on Elliptic Curve): Both parties select the elliptic curve parameter E: y 2 =x 3 +ax+b, generate a temporary public / private key pair: Q A =d A ·G, Q B =d B ·G;
[0084] Shared key calculation K=d A ·Q B =d B ·Q A =(x K y K Finally, the x-coordinate is extracted as the symmetric key;
[0085] Step 2, Data Transmission Encryption Stage:
[0086] AES-GCM encryption (a commonly used symmetric algorithm in SSL):
[0087] 2.4) Encrypt the data stream in blocks and generate authentication tags:
[0088] (Ciphertext, Tag) = AES_GCM_Encrypt(K, IV, Plaintext, AAD), where AAD is additional authentication data and Tag is used to verify data integrity.
[0089] Full-process mathematical correlation model:
[0090] Step 1, end-to-end encryption verification mechanism:
[0091] Storage side: Facial data is encrypted and a hash fingerprint is generated, H enc =SHA256(SM4(CBC,P));
[0092] Transmitter: SSL encryption with MAC verification appended.
[0093] MAC = HMAC(K) mac Ciphertxt (Ciphertxt||Seq_num) is used by the receiver to verify the consistency between the MAC and the decrypted Henc.
[0094] Step 2, Key Lifecycle Management:
[0095] A layered encryption mechanism is employed: the master key Kmaster is stored in the HSM hardware module; the data encryption key...
[0096] K data =PRF(K master ,Label); The session key Ksession is dynamically generated through the SSL handshake.
[0097] Based on the above, the data storage module uses SM4 to encrypt face data storage, SSL protocol to protect the transmission channel, and elliptic curve key exchange and hierarchical key management to form a complete security closed loop.
[0098] (III) Data Processing Module 103;
[0099] 3.1) Quality verification algorithm: An advanced face quality assessment algorithm is used to verify the quality of the acquired face images. The algorithm comprehensively considers multiple feature indicators of the image, such as the degree of eye opening, facial pose, occlusion, etc. Only when the image quality indicators reach the preset threshold is the image considered to be of qualified quality.
[0100] The specific process is as follows:
[0101] Step 1: Let the acquired face image be I, and there be n feature metrics to be evaluated, denoted as f1, f2, ..., fn. n The corresponding preset thresholds are t1, t2, ..., t n ;
[0102] Step 2, Feature index quantification function: For each feature index f i There exists a quantization function Q i(I), used to convert image I into a quantized value of the feature index. For example, the quantization function Q1(I) of the degree of eye opening can be expressed as a certain statistical value of the pixels in the eye region calculated by the image processing algorithm.
[0103] Step 3, Quality Judgment Criteria: The quality judgment criteria for image I can be expressed as: Where ∧ represents the logical AND operation, and when this condition is true, the quality of image I is considered acceptable.
[0104] 3.2) Feature Extraction Algorithm: A face feature extraction algorithm using deep learning technology is used to extract features from qualified face images; the extracted feature values have high discriminative power and stability, and can accurately represent the biological characteristics of the face;
[0105] The specific process is as follows:
[0106] Step 1, Data Preprocessing: Preprocess the qualified face images, including normalization, histogram equalization and other operations, to improve the quality and consistency of the images. Let the preprocessed face image be I′, the deep learning model be M, and the model parameters be θ.
[0107] Step 2, Deep Learning Model Training: The deep learning model is trained using a large amount of facial image data. During training, a loss function L is typically used to measure the difference between the model's output and the true labels. For example, in face recognition tasks, a commonly used loss function is the triplet loss, whose mathematical expression is: L triplet =max(||f a -f p || 2 -||f a -f n || 2 +α, 0), where fa is the feature vector of the anchor sample, fp is the feature vector of the positive sample (the sample belonging to the same class as the anchor sample), fn is the feature vector of the negative sample (the sample belonging to a different class than the anchor sample), and α is a positive boundary value; the goal of training is to minimize the loss function Laplet by optimizing the model parameters θ.
[0108] Step 3: Input the preprocessed face image into the trained deep learning model. The model outputs the feature vector of the face image. The output of model M on image I′ can be expressed as f=M(I′;θ), where f is the extracted face feature vector, which is usually a high-dimensional vector.
[0109] (iv) Data distribution module 104;
[0110] 4.1) Secure Transmission: The transmission channel is encrypted using the SSL / TLS protocol to ensure that data is not stolen or tampered with during transmission; when establishing a connection, the system performs strict authentication, and only authorized business systems can obtain face copy data; at the same time, the integrity of the transmitted data is verified to prevent data damage or loss during transmission.
[0111] The specific process is as follows:
[0112] Step 1: Establish an encrypted channel (SSL / TLS):
[0113] The client and server negotiate the encryption algorithm, verify the validity of the digital certificate, and generate a session key.
[0114] K session =KeyExchange(PK) server -SK client ), where PK server SK is the server's public key. client K is the client's private key. session The negotiated symmetric key;
[0115] Step 2, Identity Verification:
[0116] Business systems need to provide digital certificates or tokens, and the server verifies their legitimacy:
[0117] Verify (Sig) token PK issuer ) = True, where Sig token Sign the token, PK issuer For issuing organization public keys;
[0118] Step 3, encrypted data transmission:
[0119] Facial data is encrypted using a symmetric encryption algorithm to ensure confidentiality during transmission: C = E(K) session , M), where C is the ciphertext, M is the plaintext data, and E is the encryption function;
[0120] Step 4, Integrity Verification:
[0121] Generate a hash digest of the transmitted data and verify its integrity using a signature or MAC: H(M) = SHA256(M), Verify(H(M), Signature(M)) = SHA256(M), Signature(H(M)) = SHA256(M)). hash ) = True, where H(M) is the hash value, Sig hash The signature generated for the server.
[0122] 4.2) Implicit watermark embedding and traceability: Implicit watermark processing is performed when the data is distributed to the face recognition business system, and real data traceability capability is provided so that the source of face data can be traced in the event of security incidents such as data leakage;
[0123] The process of embedding a hidden watermark is as follows:
[0124] Step 1: Watermark Information Generation and Encryption:
[0125] Source identification construction: Let the set of business systems be S = {s1, s2, ..., s} m The distribution timestamp is t, and a unique watermark identifier ID is generated. w =H(K) master ||s i ||t)mod 2 N Where H is the SHA-256 hash function, K maser The master key is N, and the watermark bit length is N (usually 64-128 bits).
[0126] Watermark fragment embedding: Based on an improved LSB (least significant bit) algorithm or pseudo-column watermarking technology, the ID is embedded... w Distributed embedding of facial feature vectors, on the facial feature matrix (d is the feature dimension), the embedding rule is: Where b k ∈{0,1} is the k-th binary value of the watermark, and α is a scaling factor (usually taken as 0.01-0.05) to ensure that the watermark is imperceptible;
[0127] Step 2, Data distribution and watermark association:
[0128] Mapping table storage: Maintaining the watermark-distribution record mapping table W map The data structure is: W map (ID w )={s i The following data, including t, IP address, and operator ID, are stored using a blockchain or encrypted database to prevent tampering.
[0129] The process of tracing the source of hidden watermarks is as follows:
[0130] Step 1, Watermark Extraction and Decoding:
[0131] Feature vector sampling: Extracting feature vector F from leaked data leak The calculation is performed in reverse order of the watermark embedding rules: Where j is a predefined watermark embedding position index;
[0132] Identifier Reconstruction: Reconstructing the complete ID by correcting noise interference through a majority voting algorithm. w :
[0133] Where δ is the Kronecker function, ensuring a fault tolerance rate of ≤5%;
[0134] Step 2, source tracing and verification:
[0135] Record queries and matches: in W map Search Verify the source of the leak:
[0136] Matching conditions: Supports fuzzy search to address timestamp discrepancies.
[0137] 4.3) Authorized Access Control: Establish a role-based access control (RBAC) mechanism to assign different access permissions to different business systems; for example, the dormitory management system can only access facial data related to dormitory access authorization, and the library management system can only access facial data related to library borrowing authorization; in this way, it is ensured that facial data is only used within the authorized scope.
[0138] The specific process is as follows:
[0139] Step 1, Role-Permission Matrix Modeling:
[0140] Role definition: Construct a role set R = {r1, r2, ..., r...} k For example: r1: Dormitory Management System role; r2: Library Management System role;
[0141] Permission definition: Create a set of operation permissions P = {p1, p2, ..., p...} m For example: p1: accessing dormitory access control facial recognition data; p2: accessing library borrowing facial recognition data;
[0142] Permission allocation relationship: Constructing a role-permission allocation matrix Example: PA(r1, p1) = 1, PA(r2, p2) = 1;
[0143] Step 2, User-Role Mapping:
[0144] User set: U = {u1, u2, ..., u} n};
[0145] User role assignment: Establish a user-role assignment matrix
[0146] Example: In the dormitory management system, u1 corresponds to UA(u1, r1) = 1:
[0147] Step 3, Data Resource Isolation:
[0148] Data Classification: Define a face dataset D = {d1, d2, ..., d...} l For example: d1: dormitory access control facial feature vector library; d2: library borrowing facial feature vector library;
[0149] Permission-Resource Binding: This is achieved through permission p. j Related data range constraints: Example: Scope(p1) = {d1};
[0150] Step 4, Access Control Verification:
[0151] When the business system u i Request to access data d k hour:
[0152]
[0153] Access is allowed only if the condition is true.
[0154] (v) Data destruction module 105;
[0155] Cross-system data destruction: When an individual withdraws authorization to use facial data, the system first destroys the user's facial data within its own system; then, it sends destruction instructions to all business systems that have acquired the user's facial data through a predefined interface; upon receiving the instructions, the business systems immediately delete the relevant data stored locally and report the destruction results back to the system.
[0156] The specific process is as follows:
[0157] Step 1, Triggering conditions and event modeling:
[0158] User authorization revocation event: Let the user set be U. When user u∈U triggers authorization revocation, a destruction event is generated: E(u)={(u,t0)}, where t0 is the event trigger time;
[0159] Data status marker: The system maintains a user data status matrix D(u)∈{0,1}, where D(u)=1 indicates that the data exists and 0 indicates that it has been destroyed;
[0160] Step 2: Destroy the data in this system.
[0161] Logical deletion: Mark the record to be deleted in the database: D(u)←0, operation time t1=t0+Δt1;
[0162] Physical erasure: Invokes a secure erase algorithm to overwrite the storage medium.
[0163] SecureErase(u) = Overwrite(Data(u), Pattern), where Pattern is a random overwrite sequence conforming to the NIST standard;
[0164] Step 3, cross-system command broadcasting:
[0165] Interface definition: The predefined destruction command format is Msg = {uSig(u)}, where sig is a hash-based message authentication code: Sig(u) = HMAC(K) shared ,u||t1);
[0166] Broadcast mechanism: Broadcast to all related business systems set S = {s1, s2, ..., s...} n Send command:
[0167] Broadcast(si, Msg):
[0168] Step 4, Business System Response and Feedback:
[0169] Atomic operations: business system s i Execute after receiving the instruction:
[0170]
[0171] Feedback verification: Return response Where t2 is the operation completion time;
[0172] Step 5, Status Synchronization and Auditing:
[0173] Aggregation result: The main system verifies the response signatures of all business systems and updates the global state.
[0174] Only when all Delete(s) i When u) = 1, the cross-system destruction is considered successful;
[0175] Log recording: Write to audit log L to meet compliance requirements:
[0176]
[0177] (vi) Regulatory Analysis Module 106
[0178] 6.1) Regulatory log recording;
[0179] The system records the entire lifecycle of facial data in detail, including information such as data collection time, collection personnel, authorized business systems, and destruction time; this information is stored in the database in the form of logs to provide data support for subsequent regulatory analysis;
[0180] The specific process is as follows:
[0181] Step 1, Full lifecycle event modeling:
[0182] Event type definition: Construct operation set E = {e1, e2, ..., e} k The data collection includes: e1: Data acquisition (time, operator, device ID); e2: Data storage (storage location, encryption status); e3: Data access (business system ID, access purpose); e4: Data destruction (triggering conditions, execution result).
[0183] Log entry generation: One log record is generated for each event. i =(t i o i u i d i s i ), where: t i : Timestamp (accurate to milliseconds); o i Operation type (e.g., O) i ∈E); u i : Operation subject (personnel ID / system ID); d i : Data identifier (unique hash value of face data); s i Operation status (success / failure / error code);
[0184] Step 2, Log Storage Mechanism: Logs are stored using a time-series database, and each record meets certain requirements; hash chain technology is used to ensure that logs are immutable; logs can be retrieved by time range, statistically analyzed by operation frequency, and anomaly detection is supported;
[0185] Anomaly detection is based on a rule engine, and anomaly conditions are defined as follows:
[0186] Where Δt min : Set the minimum operation interval, such as multiple sensitive operations within 1 second.
[0187] 6.2) Real-time monitoring
[0188] Supervisory personnel can view the usage of facial data in real time through the system interface, such as which business systems use facial data, and it also has the ability to detect abnormal access.
[0189] The abnormal access detection process is as follows:
[0190] Step 1, Anomaly Detection Model:
[0191] Access frequency analysis based on Poisson distribution: λ = historical average visit rate, when P(X≥k) currentAn alarm is triggered when ) < 0.01;
[0192] Step 2, Data Heatmap Model:
[0193] Face data access popularity calculation: α and β are adjustment coefficients used to balance time decay and safety level;
[0194] Step 3, Real-time Event Stream Processing:
[0195] Sliding window statistics (e.g., 5-minute window):
[0196] W represents all events within the current time window;
[0197] Application example: Abnormal access detection in a library system:
[0198] When the library system S lib More than 100 face data read requests were initiated within 10 minutes (historical average λ = 20): Triggering a Level 1 alarm;
[0199] The monitoring interface automatically highlights the node in red and displays the dormitory access control data it accessed. dorm This indicates a risk of exceeding authority.
[0200] 6.3) Data Analysis and Report Generation
[0201] The system regularly analyzes the monitoring logs and generates various statistical reports, such as facial data usage trend reports and data leakage risk assessment reports. These reports can help university administrators understand the use of facial data, identify potential security risks in a timely manner, and take corresponding preventive measures.
[0202] Based on the above system components: the Personal Face Data Full Lifecycle Management System, for the first time, proposes the concept of full lifecycle management of face data in universities, covering all aspects from data collection to destruction, and realizing comprehensive supervision of face data; it also features unified multi-algorithm standards, and can adapt to various brands of face recognition quality algorithms, such as Megvii, SenseTime, Baidu, etc., solving the problem of compatibility of quality standards between different algorithms.
[0203] like Figure 2 As shown, a method for full lifecycle management of facial data includes the following specific steps:
[0204] Step 1: Personal Authorization: Before facial data collection, the system displays an authorization agreement to the individual, clearly informing them of the purpose of data collection, scope of use, storage period, and other information. The individual then authorizes the data through the system interface.
[0205] Step 2: Face capture and verification: Face images are captured using a mobile phone camera according to a unified standard and process; the captured face images are verified for quality through a quality assessment algorithm to ensure that the images are clear, unobstructed, and free of blur; at the same time, the captured face images are associated with personal identity information for public security face identity verification.
[0206] Step 3: Secure Storage and Distribution: Verified facial data is encrypted using national cryptographic algorithms and stored in the database; when other business systems need to use facial data, the system distributes the matching data to the relevant business systems through SSL secure encrypted transmission.
[0207] Step 4: Authorization and Access Control: Establish a role-based access control mechanism to assign different access permissions to different business systems, ensuring that facial data is used only within the authorized scope;
[0208] Step 5: Full Lifecycle Monitoring and Analysis: The system conducts full lifecycle monitoring and analysis of user facial data from generation to destruction, recording information such as data collection time, verification status, usage, and destruction time, and generating a full monitoring log. Supervisors can view the monitoring log through the system interface to monitor and analyze the use of facial data in real time.
[0209] According to the above process, comprehensive management is carried out on all aspects of facial data, including personal authorization, facial data collection, identity and quality verification, national cryptographic storage and distribution, revocation and destruction, and traceability. This enables full lifecycle supervision of facial data of university teachers and students from generation to destruction, ensuring the security of facial data and personal information.
[0210] like Figure 3 As shown, in step 3, a face tracing function is added. The specific steps are as follows:
[0211] Step 3.1: Watermark Information Generation and Encryption: Construct a traceability identifier and embed watermark fragments;
[0212] Step 3.2: Data distribution and watermark association: Construct a watermark-distribution record mapping table and store it encrypted;
[0213] Step 3.3: In the event of a data breach, perform implicit watermarking for source tracing;
[0214] Step 3.4: Watermark Extraction and Decoding: Feature Vector Sampling and Identifier Reconstruction;
[0215] Step 3.5: Source tracing and verification: Record the query and match, and perform the query in the watermark-distribution record mapping table according to the reconstruction identifier.
[0216] According to the above process: an implicit digital watermark is added to the issued film; in the event of a data breach or other security incident, the system can trace the source of the data and determine the responsible party through the digital watermark information.
[0217] like Figure 4 As shown, in step 5, the facial data is revoked and destroyed. The specific steps are as follows:
[0218] Step 5.1: Triggering conditions and event modeling: User triggers authorization revocation event, data status is marked;
[0219] Step 5.2: Data Destruction in this System: Perform logical deletion and physical clearing;
[0220] Step 5.3: Cross-system command broadcast: Predefine destruction commands and use a broadcast mechanism to send the commands to all related business systems;
[0221] Step 5.4: Business System Response and Feedback;
[0222] Step 5.5: State Synchronization and Auditing: The master system verifies the response signatures of all business systems, updates the global state, and writes it to the audit log.
[0223] According to the above process: when an individual withdraws authorization to use facial data, the system uses cross-system data destruction technology to quickly and uniformly destroy the relevant data from this system to all business systems that have acquired the user's facial data; the destruction process follows a strict data destruction policy to ensure that the data cannot be recovered during the destruction process.
[0224] The above description is merely a preferred embodiment of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention. Structures, devices, and operating methods not specifically described or explained in this invention are implemented according to conventional methods in the art unless otherwise specified or limited.
Claims
1. A face data full lifecycle management system, comprising a full lifecycle management system (1), characterized in that: The full lifecycle management system (1) is internally equipped with a data acquisition module (101), a data storage module (102), a data processing module (103), a data distribution module (104), a data destruction module (105), and a monitoring and analysis module (106). The data storage module (102) uses the national cryptographic encryption algorithm SM4 to encrypt and store the data in the face database; during data transmission, the SSL protocol is used to encrypt the data. The data distribution module (104) uses the SSL / TLS protocol to encrypt the transmission channel; when establishing a connection, the system performs strict identity verification, and only authorized business systems can obtain face copy data; at the same time, the integrity of the transmitted data is verified. The data distribution module (104) uses implicit watermark embedding and traceability to perform implicit watermark processing when the data is distributed to the face business system, and provides real data traceability capability to trace the source of face data in the event of a data leakage security incident. The data distribution module (104) adopts an authorized access control mechanism: a role-based access control mechanism is established to allocate different access permissions to different business systems, ensuring that face data is used only within the authorized scope; The data destruction module (105) adopts cross-system data destruction: when a user withdraws the authorization to use face data, the system first destroys the user's face data in its own system; then, it sends a destruction instruction to all business systems that have acquired the user's face data through a predefined interface; after receiving the instruction, the business system immediately deletes the relevant data stored locally and feeds back the destruction result to the system. The specific operation process of the regulatory analysis module (106) is as follows: Step 1, Full lifecycle event modeling: Event type definition: Collection of construction operations ,include: Data collection includes time, operator, and device ID; Data storage, including storage location and encryption status; Data access includes business system ID and access purpose; Data destruction, including triggering conditions and execution results; Other information logs; Log entry generation: One log record is generated for each event. ,in: : timestamp; Operation type, ; : Operation subject, personnel ID / system ID; Data identifiers, including unique hash values for facial data; Operation status, including success / failure / error code; Step 2: Use a time-series database to store logs and use hash chain technology to ensure that the logs are immutable; support log retrieval by time range, statistics by operation frequency, and anomaly detection. Step 3: Real-time monitoring; Step 4: Data analysis and report generation.
2. The face data full lifecycle management system according to claim 1, characterized in that: The data acquisition module (101) is used to perform real-time quality assessment of the acquired images during the mobile phone camera acquisition process.
3. The face data full lifecycle management system according to claim 1, characterized in that: The data processing module (103) adopts a quality verification algorithm: the collected face images are verified for quality. The algorithm comprehensively considers the image's feature indicators, including the degree of eye opening, facial posture, and occlusion. Only when the image quality indicators reach the preset threshold is the image quality deemed qualified.
4. The face data full lifecycle management system according to claim 1, characterized in that: The data processing module (103) employs a feature extraction algorithm: it extracts features from qualified facial images, and the extracted feature values have high discriminative power and stability, which are used to accurately represent the biological characteristics of the face.
5. A face data full lifecycle management system according to claim 1, characterized in that: The regulatory analysis module (106) includes a regulatory log recording unit. The system records the entire lifecycle of face data in detail, including the data collection time, collection personnel, authorized business system, and destruction time information.
6. A face data full lifecycle management system according to claim 1, characterized in that: The regulatory analysis module (106) includes a real-time monitoring unit, which allows regulatory personnel to view the usage of facial data in real time through the system interface, and also has the ability to detect abnormal access.
7. A face data full lifecycle management system according to claim 1, characterized in that: The regulatory analysis module (106) includes a data analysis and report generation unit. The system regularly analyzes regulatory logs and generates various statistical reports.
8. A method for full lifecycle management of facial data, using the facial data full lifecycle management system as described in claim 7, characterized in that, The specific steps are as follows: Step 1: Personal Authorization: Before facial data collection, the system displays an authorization agreement to the individual, clearly informing them of the purpose of data collection, scope of use, and storage period. The individual then authorizes the data through the system interface. Step 2: Face capture and verification: Face images are captured using a mobile phone camera according to a unified standard and process; the captured face images are verified for quality through a quality assessment algorithm to ensure that the images are clear, unobstructed, and without blurriness; at the same time, the captured face images are associated with personal identity information for public security face identity verification. Step 3: Secure Storage and Distribution: Verified facial data is encrypted using national cryptographic algorithms and stored in the database; when other business systems need to use facial data, the system distributes the matching data to the relevant business systems through SSL secure encrypted transmission. Step 4: Authorization and Access Control: Establish a role-based access control mechanism to assign different access permissions to different business systems, ensuring that facial data is used only within the authorized scope; Step 5: Full Lifecycle Monitoring and Analysis: The system conducts full lifecycle monitoring and analysis of user facial data from generation to destruction, recording data collection time, verification status, usage status, and destruction time information, and generating a full monitoring log; supervisors can view the monitoring log through the system interface to monitor and analyze the use of facial data in real time.
9. A method for full lifecycle management of facial data according to claim 8, characterized in that, In step 3, a face recognition function is added. The specific steps are as follows: Step 3.1: Watermark Information Generation and Encryption: Construct a traceability identifier and embed watermark fragments; Step 3.2: Data distribution and watermark association: Construct a watermark-distribution record mapping table and store it encrypted; Step 3.3: In the event of a data breach, perform implicit watermarking for source tracing; Step 3.4: Watermark Extraction and Decoding: Feature Vector Sampling and Identifier Reconstruction; Step 3.5: Source tracing and verification: Record the query and match, and perform the query in the watermark-distribution record mapping table according to the reconstruction identifier.
10. A method for full lifecycle management of facial data according to claim 8, characterized in that, In step 5, the facial data is revoked and destroyed, and the specific steps are as follows: Step 5.1: Triggering conditions and event modeling: User triggers authorization revocation event, data status is marked; Step 5.2: Data Destruction in this System: Perform logical deletion and physical clearing; Step 5.3: Cross-system command broadcast: Predefine destruction commands and use a broadcast mechanism to send the commands to all related business systems; Step 5.4: Business System Response and Feedback; Step 5.5: State Synchronization and Auditing: The master system verifies the response signatures of all business systems, updates the global state, and writes it to the audit log.
Citation Information
Patent Citations
Information collection and management system based on face recognition technology
CN119741745A
Digital identity system
US20160239657A1