Intelligent bus linkage key management system
By submitting vehicle use information online and a multi-layer protection system by user terminals, the problems of cumbersome approval process and poor security in traditional key management are solved, and automated approval and efficient and secure identity authentication are achieved.
Patent Information
- Application Number
- CN202510715606.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-05-30
AI Technical Summary
The approval process of traditional key management methods is cumbersome and relies on manual labor, resulting in a long cycle; poor security, prone to approval errors or data leakage; identity authentication decreases in accuracy in complex environments, prone to misidentification or rejection.
User terminals are used to submit vehicle usage information online, build a multi-layer protection system, and use hash processing and Blowfish encryption algorithm to ensure data security; use dual-factor authentication method, combining online signatures and multi-faceted face images for identity recognition.
It has realized an automated approval process, improved the collaborative efficiency of multiple departments, ensured data security, improved the accuracy and reliability of identity authentication, and prevented identity impersonation and forgery.
Smart Images

Figure CN120544299A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of intelligent key management, and in particular to a smart car-link key management system. Background Art
[0002] Zhihui Car-Link Key Management is an intelligent management system for vehicle keys. With the increase in the number of vehicles and the growing demand for vehicle management, traditional manual key management methods can no longer meet the needs of modern enterprises. In traditional key management, the approval process is cumbersome and manual, resulting in long approval cycles and prone to approval errors or delays due to negligence. Traditional key management systems often use simple encryption methods or lack dynamic protection mechanisms. Faced with increasingly complex cyberattacks, sensitive information is easily stolen, and the data storage and transmission process has significant security risks. Traditional identity authentication often uses a single password or card swipe method. Passwords can be forgotten, leaked, or cracked, while card swipe methods carry the risk of card loss or duplication. Facial recognition significantly reduces accuracy in scenarios such as low light and changes in user posture, making it prone to misidentification or rejection. It cannot meet the high reliability and security requirements of modern enterprises for identity authentication. Summary of the Invention
[0003] In view of the above situation, in order to overcome the defects of the prior art, the present invention provides a smart car-link key management system. In view of the problem that the approval process in traditional key management is cumbersome and relies on manual labor, resulting in a long approval cycle and prone to approval errors or delays due to negligence, this solution allows the user terminal to submit vehicle information online, automatically completes the approval according to preset rules, and generates an approval form that is synchronized to the smart key cabinet. This automated process breaks the information barriers between departments, eliminates the manual transmission and verification links, shortens the approval time, and greatly improves the efficiency of multi-department collaboration; in view of the fact that traditional key management systems often use simple encryption methods or lack dynamic protection mechanisms, facing increasingly complex network attacks, sensitive information is easily stolen, and there are great security risks in the data storage and transmission process, this solution constructs a multi-layer protection system, hashes the password when the user registers to avoid the leakage of the plaintext password, uses the long short-term memory network to construct an intrusion detection model, and optimizes the model parameters by the stochastic gradient descent method. When abnormal access is detected, an immediate warning is issued. At the same time, the Blowfish encryption algorithm is used to iteratively encrypt the user information database data to ensure the security of data access, effectively resist external intrusion and internal illegal access, and protect the confidentiality and integrity of user data. Traditional identity authentication mostly uses a single password or card swiping method, and the accuracy of face recognition is greatly reduced in scenarios such as insufficient light and changes in user posture, and it is prone to misrecognition or rejection. This solution adopts a dual authentication method, collects the time series of user online signatures and multi-posture face images, uses the linear discriminant analysis algorithm to reduce the dimension of features, constructs intra-class and inter-class scatter matrices, and uses the exponential discriminant analysis method to find the optimal projection matrix, and converts the feature data into a one-dimensional fusion feature vector. It combines the uniqueness and dynamics of biometric features. Even in complex environments, it can accurately identify user identities through multi-dimensional feature matching, effectively prevent identity fraud and forgery, and improve the security and reliability of the key management system.
[0004] The technical solution adopted by the present invention is as follows: The present invention provides a smart car-link key management system, which specifically includes a user terminal, an intelligent key cabinet and an approval unit;
[0005] The user fills in the vehicle use information on the user terminal, which includes the user's name, user ID, vehicle use time, vehicle use location and vehicle type, and submits the application. The approval unit automatically approves the application and, if approved, generates an approval form and sends it to the smart key cabinet.
[0006] The smart key cabinet includes a data encryption module and a linkage authentication module. The data encryption module includes a cloud server, a user registration unit, an intrusion detection unit and a data access control unit. The linkage authentication module extracts the user's online signature and facial features and uses a dual authentication method to identify approved users.
[0007] The user registration unit sends a registration request to the cloud server, the registration request includes the user's work number and user terminal password. After receiving the registration request, the cloud server hashes the password and generates a hashed password that is stored in the user information database of the cloud server;
[0008] The intrusion detection unit establishes and initializes a long short-term memory network as an intrusion detection model, randomly generates a model parameter vector, and uses a stochastic gradient descent method to optimize the model parameters in the long short-term memory network. The formula used is as follows: ;
[0009] Where, It is The model parameter vector in the long short-term memory network at iteration time, It is The model parameter vector in the long short-term memory network at iteration time, is the learning rate, is the objective function gradient;
[0010] The data access control unit collects user access data and inputs the user access data into the intrusion detection model for training. When an abnormal access is detected, the intrusion detection unit issues an abnormality warning;
[0011] The Blowfish encryption algorithm is used to iteratively encrypt the data in the user information database of the cloud server. The formula used is as follows:
[0012] Where, and They are the left and right halves of the 64-bit plaintext grouped together. is the number of iterations, It is the subkey generated by the Blowfish encryption algorithm during the key expansion phase. is a bitwise exclusive OR operation, represents a swap operation, is a nonlinear transformation function, 、 、 and It is the S-box generated by the Blowfish encryption algorithm during the key expansion phase. 、 、 and It will The index of each group after splitting;
[0013] When a user accesses the user information database, he sends a login request containing his work ID and user terminal secret. The cloud server verifies the hash password. After the verification is passed, a one-time hash summary is generated and dynamically authorized to access data using the Blowfish encryption algorithm.
[0014] The linkage authentication module uses a dual authentication method to identify the user, and the dual authentication method specifically includes the following steps:
[0015] Step S1: Data collection: collecting the user's online signature and multi-pose facial images. The online signature is obtained through a digital tablet and stored in a time series format, including coordinates, pressure value, azimuth, altitude, and timestamp. The multi-pose facial images are obtained through a high-resolution camera, including the front face, the side face tilted 15° to the left, the side face tilted 15° to the right, and images under high light intensity and low light intensity. The multi-pose facial images are uniformly scaled and grayscale normalized.
[0016] Step S2: Feature extraction, extracting signature dynamic features and facial features respectively. The signature dynamics include displacement, velocity and acceleration. The facial features include facial texture features and facial gradient features. The facial features are obtained through context-awareness method.
[0017] Step S3: Feature dimensionality reduction: Use the linear discriminant analysis algorithm to reduce the dimensionality of signature features and facial features, and construct a scatter matrix. The scatter matrix includes the intra-class scatter matrix and the inter-class scatter matrix. The formula used is as follows: ; ;
[0018] Where, is the intra-class scatter matrix, is the between-class scatter matrix, is the feature vector of the same type of samples, is the feature vector of heterogeneous samples, and are respectively the set of similar sample pairs and the set of heterogeneous sample pairs, Represents a transpose operation;
[0019] Step S4: Use the exponential discriminant analysis method to transform the feature data into the projection space through the projection matrix, find the optimal projection matrix, and obtain the one-dimensional fusion feature vector. The formula used is as follows: ;
[0020] Where, is the optimal projection matrix, is the projection matrix, is the element-wise inverse tangent, Represents a transpose operation;
[0021] Step S5: Identity authentication, establish and initialize a deep neural network model, the deep neural network model uses ReLu as the activation function, inputs the one-dimensional fusion feature vector into the deep neural network model for training, and the deep neural network model outputs the online signature and face authentication results.
[0022] Furthermore, in step S2, facial features are acquired through a context-aware method, which specifically includes the following steps:
[0023] Step S21: Connect the center points of both eyes and calculate the rotation angle, which is the angle between the line connecting the centers of both eyes and the horizontal axis. Correct the facial image through rotation transformation. The formula used is as follows: ; ;
[0024] Where, and They are the first The horizontal and vertical coordinates of the pixels, and They are the first The horizontal and vertical coordinates of the pixels, and These are the horizontal and vertical coordinates of the rotation center, respectively. The rotation center is set to the center of the face image.
[0025] Step S22: vertically divide the facial image into three parts: upper, middle, and lower. Select the points corresponding to the maximum and minimum vertical coordinates in each area from the upper, middle, and lower parts to generate a hexagonal area. Keep the facial core area and remove the irrelevant areas at the edge of the hexagon to obtain the region of interest.
[0026] Step S23: extracting facial texture features from the region of interest using the local binary pattern histogram. The formula used is as follows: ;
[0027] Where, is the local binary pattern value, is the threshold comparison function, is the number of neighborhood pixels, It is The grayscale value of the neighboring pixels, is the grayscale value of the center pixel;
[0028] Step S24: Using the gradient histogram algorithm, the face is divided into pixel blocks, each pixel block is divided into units, and the 9-dimensional gradient direction feature is calculated for each unit to obtain the face gradient feature.
[0029] The beneficial effects achieved by the present invention using the above scheme are as follows:
[0030] (1) In traditional key management, the approval process is cumbersome and manual, resulting in a long approval cycle and prone to approval errors or delays due to negligence. This solution allows users to submit vehicle information online through the user terminal, automatically complete the approval process based on preset rules, and generate an approval form that is synchronized to the smart key cabinet. This automated process breaks the information barriers between departments, eliminates the manual transmission and verification links, shortens the approval time, and greatly improves the efficiency of multi-department collaboration;
[0031] (2) In view of the fact that traditional key management systems often use simple encryption methods or lack dynamic protection mechanisms, and in the face of increasingly complex network attacks, sensitive information is easily stolen, and there are great security risks in the data storage and transmission process, this solution builds a multi-layer protection system. When users register, the password is hashed to avoid the leakage of plaintext passwords. The intrusion detection model is constructed using the long short-term memory network, and the model parameters are optimized by the stochastic gradient descent method. When abnormal access is detected, an immediate warning is issued. At the same time, the Blowfish encryption algorithm is used to iteratively encrypt the user information database data to ensure the security of data access, effectively resist external intrusion and internal illegal access, and protect the confidentiality and integrity of user data.
[0032] (3) Traditional identity authentication mostly uses a single password or card swiping method, while the accuracy of face recognition drops significantly in scenarios such as insufficient light and changes in user posture, and is prone to misrecognition or rejection. This solution adopts a dual authentication method, collects the time series of the user's online signature and multi-posture face images, uses the linear discriminant analysis algorithm to reduce the dimension of the features, constructs the intra-class and inter-class scatter matrices, and uses the exponential discriminant analysis method to find the optimal projection matrix, converts the feature data into a one-dimensional fusion feature vector, combines the uniqueness and dynamics of biometrics, and can accurately identify the user's identity through multi-dimensional feature matching even in complex environments, effectively preventing identity fraud and forgery, and improving the security and reliability of the key management system. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 This is a module connection diagram of the Zhihui Car Link key management system provided by the present invention.
[0034] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention. DETAILED DESCRIPTION
[0035] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments; based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0036] In the description of the present invention, it should be understood that terms such as "upper", "lower", "front", "back", "left", "right", "top", "bottom", "inside" and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific direction, be constructed and operated in a specific direction. Therefore, they should not be understood as limiting the present invention.
[0037] Example 1, see Figure 1 The present invention provides a smart car-link key management system, which specifically includes a user terminal, an intelligent key cabinet and an approval unit;
[0038] The user fills in the vehicle use information on the user terminal, which includes the user's name, user ID, vehicle use time, vehicle use location and vehicle type, and submits the application. The approval unit automatically approves the application and, if approved, generates an approval form and sends it to the smart key cabinet.
[0039] The smart key cabinet includes a data encryption module and a linkage authentication module. The data encryption module includes a cloud server, a user registration unit, an intrusion detection unit and a data access control unit. The linkage authentication module extracts the user's online signature and facial features and uses a dual authentication method to identify approved users.
[0040] Example 2, see Figure 1 This embodiment is based on the above embodiment. In the user registration unit, the user sends a registration request to the cloud server. The registration request includes the user's work number and user terminal password. After receiving the registration request, the cloud server hashes the password and generates a hashed password that is stored in the user information database of the cloud server.
[0041] The intrusion detection unit establishes and initializes a long short-term memory network as an intrusion detection model, randomly generates a model parameter vector, and uses a stochastic gradient descent method to optimize the model parameters in the long short-term memory network. The formula used is as follows: ;
[0042] Where, It is The model parameter vector in the long short-term memory network at iteration time, It is The model parameter vector in the long short-term memory network at iteration time, is the learning rate, is the objective function gradient;
[0043] The data access control unit collects user access data and inputs the user access data into the intrusion detection model for training. When an abnormal access is detected, the intrusion detection unit issues an abnormality warning;
[0044] The Blowfish encryption algorithm is used to iteratively encrypt the data in the user information database of the cloud server. The formula used is as follows:
[0045] Where, and They are the left and right halves of the 64-bit plaintext grouped together. is the number of iterations, It is the subkey generated by the Blowfish encryption algorithm during the key expansion phase. is a bitwise exclusive OR operation, represents a swap operation, is a nonlinear transformation function, 、 、 and It is the S-box generated by the Blowfish encryption algorithm during the key expansion phase. 、 、 and It will The index of each group after splitting;
[0046] When a user accesses the user information database, he sends a login request containing his work ID and user terminal secret. The cloud server verifies the hash password. After the verification is passed, a one-time hash summary is generated and dynamically authorized to access data using the Blowfish encryption algorithm.
[0047] Example 3, see Figure 1 This embodiment is based on the above embodiment. The linkage authentication module uses a dual authentication method to identify the user. The dual authentication method specifically includes the following steps:
[0048] Step S1: Data collection: collecting the user's online signature and multi-pose facial images. The online signature is obtained through a digital tablet and stored in a time series format, including coordinates, pressure value, azimuth, altitude, and timestamp. The multi-pose facial images are obtained through a high-resolution camera, including the front face, the side face tilted 15° to the left, the side face tilted 15° to the right, and images under high light intensity and low light intensity. The multi-pose facial images are uniformly scaled and grayscale normalized.
[0049] Step S2: Feature extraction, extracting signature dynamic features and facial features respectively. The signature dynamics include displacement, velocity and acceleration. The facial features include facial texture features and facial gradient features. The facial features are obtained through context-awareness method.
[0050] Step S3: Feature dimensionality reduction: Use the linear discriminant analysis algorithm to reduce the dimensionality of signature features and facial features, and construct a scatter matrix. The scatter matrix includes the intra-class scatter matrix and the inter-class scatter matrix. The formula used is as follows: ; ;
[0051] Where, is the intra-class scatter matrix, is the between-class scatter matrix, is the feature vector of the same type of samples, is the feature vector of heterogeneous samples, and are respectively the set of similar sample pairs and the set of heterogeneous sample pairs, Represents a transpose operation;
[0052] Step S4: Use the exponential discriminant analysis method to transform the feature data into the projection space through the projection matrix, find the optimal projection matrix, and obtain the one-dimensional fusion feature vector. The formula used is as follows: ;
[0053] Where, is the optimal projection matrix, is the projection matrix, is the element-wise inverse tangent, Represents a transpose operation;
[0054] Step S5: Identity authentication, establish and initialize a deep neural network model, the deep neural network model uses ReLu as the activation function, inputs the one-dimensional fusion feature vector into the deep neural network model for training, and the deep neural network model outputs the online signature and face authentication results.
[0055] Example 4, see Figure 1This embodiment is based on the above embodiment. In step S2, facial features are acquired through a context-aware method, specifically including the following steps:
[0056] Step S21: Connect the center points of both eyes and calculate the rotation angle, which is the angle between the line connecting the centers of both eyes and the horizontal axis. Correct the facial image through rotation transformation. The formula used is as follows: ; ;
[0057] Where, and They are the first The horizontal and vertical coordinates of the pixels, and They are the first The horizontal and vertical coordinates of the pixels, and These are the horizontal and vertical coordinates of the rotation center, respectively. The rotation center is set to the center of the face image.
[0058] Step S22: vertically divide the facial image into three parts: upper, middle, and lower. Select the points corresponding to the maximum and minimum vertical coordinates in each area from the upper, middle, and lower parts to generate a hexagonal area. Keep the facial core area and remove the irrelevant areas at the edge of the hexagon to obtain the region of interest.
[0059] Step S23: extracting facial texture features from the region of interest using the local binary pattern histogram. The formula used is as follows: ;
[0060] Where, is the local binary pattern value, is the threshold comparison function, is the number of neighborhood pixels, It is The grayscale value of the neighboring pixels, is the grayscale value of the center pixel;
[0061] Step S24: Using the gradient histogram algorithm, the face is divided into pixel blocks, each pixel block is divided into units, and the 9-dimensional gradient direction feature is calculated for each unit to obtain the face gradient feature.
[0062] Example 5: This example is based on the above example. In Example 4, the facial image is vertically divided into three parts: upper, middle and lower parts, where the upper part is the upper 1 / 4 area of the facial image, the middle part is the middle 1 / 2 area of the facial image, and the lower part is the bottom 1 / 4 area of the facial image.
[0063] Example 6. This example is based on the above example. In Example 4, a deep neural network model is established and initialized. The deep neural network model uses ReLu as the activation function, and the one-dimensional fused feature vector is input into the deep neural network model for training. The batch size during training is 300, the maximum number of epochs is 800, the gradient threshold is set to 1, Adam is used as the optimizer, and the cross entropy loss is used as the loss function.
[0064] Example 7: This example is based on the above example. In Example 2, the objective function is the binary cross entropy loss function.
[0065] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0066] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
[0067] The present invention and its embodiments are described above. This description is not restrictive. The drawings show only one embodiment of the present invention, and the actual structure is not limited thereto. In short, if a person skilled in the art is inspired by this and, without departing from the purpose of the present invention, designs structures and embodiments similar to this technical solution without inventiveness, they shall fall within the scope of protection of the present invention.
Claims
1. A smart car-link key management system, characterized in that: Includes user terminal, smart key cabinet and approval unit; The user fills in the vehicle information on the user terminal and submits the application. The approval unit automatically approves the application. If approved, an approval form is generated and sent to the smart key cabinet. The smart key cabinet includes a data encryption module and a linkage authentication module. The data encryption module includes a cloud server, a user registration unit, an intrusion detection unit and a data access control unit. The linkage authentication module extracts the user's online signature and facial features and uses a dual authentication method to identify approved users.
2. The smart car-link key management system according to claim 1, characterized in that: The user registration unit sends a registration request to the cloud server, the registration request includes the user's work number and user terminal password. After receiving the registration request, the cloud server hashes the password and generates a hashed password that is stored in the user information database of the cloud server; The intrusion detection unit establishes and initializes a long short-term memory network as an intrusion detection model, randomly generates a model parameter vector, and optimizes the model parameters in the long short-term memory network using a stochastic gradient descent method; The data access control unit collects user access data and inputs the user access data into the intrusion detection model for training. When an abnormal access is detected, the intrusion detection unit issues an abnormality warning; Use the Blowfish encryption algorithm to iteratively encrypt the data in the user information database in the cloud server; When a user accesses the user information database, he sends a login request containing his work ID and user terminal secret. The cloud server verifies the hash password. After the verification is passed, a one-time hash summary is generated and dynamically authorized to access data using the Blowfish encryption algorithm.
3. The smart car-link key management system according to claim 1, characterized in that: The linkage authentication module uses a dual authentication method to identify the user, and the dual authentication method specifically includes the following steps: Step S1: Data collection, collecting the user's online signature and multi-pose facial images. The online signature is obtained through a digital tablet and stored in a time series format. The multi-pose facial images are uniformly scaled and grayscale normalized. Step S2: Feature extraction, extracting signature dynamic features and facial features respectively. The signature dynamics include displacement, velocity and acceleration. The facial features include facial texture features and facial gradient features. The facial features are obtained through context-awareness method. Step S3: Feature dimensionality reduction, using the linear discriminant analysis algorithm to reduce the dimensionality of signature features and facial features and construct a scatter matrix; Step S4: Using the exponential discriminant analysis method, the feature data is converted into the projection space through the projection matrix, and the optimal projection matrix is found to obtain a one-dimensional fusion feature vector; Step S5: Identity authentication, establish and initialize a deep neural network model, the deep neural network model uses ReLu as the activation function, inputs the one-dimensional fusion feature vector into the deep neural network model for training, and the deep neural network model outputs the online signature and face authentication results.
4. The smart car-link key management system according to claim 3, characterized in that: In step S2, facial features are acquired through a context-aware method, which specifically includes the following steps: Step S21: Connect the center points of both eyes and calculate the rotation angle, which is the angle between the line connecting the centers of both eyes and the horizontal axis, and correct the facial image through rotation transformation; Step S22: vertically divide the facial image into three parts: upper, middle, and lower. Select the points corresponding to the maximum and minimum vertical coordinates in each area from the upper, middle, and lower parts to generate a hexagonal area. Keep the facial core area and remove the irrelevant areas at the edge of the hexagon to obtain the region of interest. Step S23: extracting facial texture features from the region of interest using a local binary pattern histogram; Step S24: Using the gradient histogram algorithm, the face is divided into pixel blocks, each pixel block is divided into units, and the 9-dimensional gradient direction feature is calculated for each unit to obtain the face gradient feature.
Citation Information
Patent Citations
Intelligent key authorization method and system
CN110148239A
Bus key supervision system
CN112133002A
Authentication and access control method with privacy protection in mobile cloud service environment
CN115865520A
Traffic flow prediction method based on space division and static weighting
CN118820686A
Method for predicting fracture pressure of stratified shale extended reach well based on machine learning model
CN119918399A