A certificate authorization access control system, method and camera pan / tilt based on face encryption features
Through distributed multimodal scanning and elliptical domain homomorphic encryption technology, combined with a hybrid strategy of random salt values and device-side keys, a local access dependency graph is constructed, which solves the problems of man-in-the-middle attacks and authorization tampering in face encryption systems in high-security scenarios, and realizes real-time hierarchical control and efficient identity authentication of remote gimbals.
Patent Information
- Application Number
- CN202511046547.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-29
AI Technical Summary
Existing facial encryption systems are difficult to effectively resist man-in-the-middle attacks and the risk of authorization chain tampering in high-security scenarios. In particular, the lack of substantial binding to people in remote gimbal access management leads to security risks of illegal manipulation of the gimbal.
Through distributed multimodal acquisition nodes, the visible light and near-infrared light domains are scanned synchronously to generate the original facial data stream. The recalculated facial encryption vector is constructed by combining elliptical domain homomorphic reversible encryption, time-series random salt value and device-side security element key. The multi-dimensional confidence fusion network is combined to identify potential fraudulent paths, build a local access dependency graph, and dynamically generate hierarchical access control responses.
It achieves stable encryption in complex lighting, occlusion and multi-terminal environments, resists replay attacks and differential analysis, identifies potential fraudulent paths early, and responds dynamically in levels, improving the level of refinement of access control and the degree of intelligent perception, and is suitable for identity authentication and permission management in high-security scenarios.
Smart Images

Figure CN120547003B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of face encryption technology, and in particular to a certificate authorization access control system, method and camera pan / tilt platform based on face encryption features. Background Art
[0002] With the development of facial encryption technology, facial features are increasingly being used as a means of identity authentication in access control. However, current facial encryption systems mostly use the face as a login credential, failing to deeply integrate with encryption technology, making it difficult to build a cryptographically strong access control system. This makes it difficult to effectively defend against man-in-the-middle attacks and the risk of authorization chain tampering in high-security scenarios, such as remotely controlling a pan / tilt, retrieving surveillance evidence, or configuring core parameters. This is particularly true in the specific scenario of remote pan / tilt access management, where users often remotely control pan / tilt rotation, zoom, and capture using terminal devices. Existing technologies often rely on a single account and password or certificate verification method to identify the operator, lacking a substantial binding to a person. Once the certificate or account credentials are leaked, the pan / tilt could be illegally controlled remotely, leading to security risks such as adjusting blind spots and leaking sensitive data. Therefore, it is necessary to design a certificate-authorized access control system, method, and camera pan / tilt based on facial encryption features to enhance access control capabilities in high-security scenarios. Summary of the Invention
[0003] In response to the shortcomings of the existing technology, the present invention provides a certificate-authorized access control system, method and camera pan / tilt based on facial encryption features, which have the advantage of improving access control capabilities in high-security scenarios and solve the problems in the above-mentioned background technology.
[0004] To achieve the above-mentioned purpose of improving access control capabilities in high-security scenarios, the present invention provides the following technical solution: a certificate authorization access control method based on facial encryption features, comprising the following steps:
[0005] The distributed multimodal acquisition nodes are used to synchronously scan the visible light and near-infrared light domains of the high-security protection zone, extract the facial geometric boundaries, spectral texture, and ambient light drift parameters, and generate the first facial raw data stream;
[0006] Perform elliptic domain homomorphic reversible encryption on the first face raw data stream, combine the time-series random salt value with the device-side secure element key to construct a recalculated face encryption vector for cross-terminal authentication, and form a session-level identity composite identifier;
[0007] Based on the composite identity, a multi-dimensional confidence fusion network is used to predict the authenticity evolution trajectory of the current access session. By integrating historical behavior entropy fluctuations, certificate revocation chain propagation characteristics, and light field occlusion patterns, potential fraudulent paths are identified and an abnormal trend vector is output.
[0008] The access requests and impact ranges corresponding to the abnormal trend vectors are delineated as high-risk candidate segments. The face encryption nodes, certificate key nodes, and PTZ control instruction nodes within the candidate segments are integrated to construct a local access dependency graph.
[0009] Based on the local access dependency graph and the entropy mutation inflection point appearing in the global security margin curve, intervention decisions are made on the authorization evolution path to dynamically generate hierarchical access control response results.
[0010] Preferably, the process of generating the first original face data stream is:
[0011] Visible light cameras, near-infrared fill-light cameras, and light environment sensors are deployed at the entrance to the protection area, control consoles, and inspection channels to achieve microsecond-level alignment of all acquisition nodes.
[0012] A field-of-view joint calibration algorithm is used to dynamically calibrate the internal and external parameters of multiple camera units, eliminate lens distortion, and perform geometric alignment on overlapping fields of view to obtain a cross-modal spatial mapping matrix.
[0013] Call the adaptive light drift compensation model to perform light intensity normalization and pseudo-color fusion on visible light frames and near-infrared frames;
[0014] Based on the face semantic segmentation network, the fused frame is segmented pixel by pixel to extract the geometric boundary and spectral texture features of the face, and low-quality frames are eliminated according to the preset threshold;
[0015] Aggregate the retained frames in time order to form the first face raw data stream.
[0016] Preferably, the process of performing the elliptical domain homomorphic reversible encryption operation on the first face original data stream is:
[0017] Performing ellipse domain coordinate remapping on facial key points in the first face raw data stream;
[0018] For the mapped pixel intensity sequence, the improved homomorphic encryption algorithm is called to perform layered reversible encryption;
[0019] A resettable random blinding factor is implanted during the homomorphic operation to make each encrypted output statistically independent of each other;
[0020] After encryption is completed, a reverse verifiable hash check is performed on the encrypted domain pixel block. If the check passes, the ellipse domain encryption feature set is output.
[0021] Preferably, the process of combining the time-series random salt value and the device-side secure element key to construct a recalculated face encryption vector for cross-terminal authentication is as follows:
[0022] The master server issues a random salt value calculated based on the time drift margin and distributes it to each collection node through a secure channel.
[0023] Call the built-in security element of the camera pan / tilt control board to extract the unique device identification code and dynamically derived key to generate a local private key pair;
[0024] The output elliptical domain encrypted feature set is mixed with the random salt value through convolution hashing operation, and the private key is used to complete the secondary encryption to obtain a recalculated face encryption vector.
[0025] Preferably, the process of forming a session-level identity composite identifier is as follows:
[0026] The recalculated face encryption vector is bidirectionally bound to the digital certificate fingerprint obtained during the handshake phase, and a session hash value is generated through a multi-layer hash aggregation mechanism.
[0027] Write the session hash value, current timestamp, unique device identification code and access entry number into the one-time session token and encrypt it using a session-level symmetric encryption algorithm;
[0028] A session trace chain is established on the access control gateway side to record the session token life cycle, recalculate the checksum and certificate status, and finally output the session-level identity composite identifier.
[0029] Preferably, the process of identifying potential fraudulent paths and outputting abnormal trend vectors is:
[0030] Receive the session-level identity composite identifier and solve the validity of the vector and token to construct a sequence of session-level behavior vectors;
[0031] A conversation authenticity model based on a hidden state Markov network is established. The likelihood of the behavior vector sequence is estimated using a library of historical normal conversations, and a preliminary abnormal deviation degree is output.
[0032] The initial anomaly deviation degree is superimposed with the historical behavior entropy fluctuation curve, and the certificate revocation chain propagation delay and light field occlusion probability are integrated to form a multi-factor anomaly confidence level.
[0033] Perform sliding window frequency domain analysis on the anomaly confidence, extract features, and generate anomaly trend vectors.
[0034] Preferably, the process of defining the access request and impact range corresponding to the abnormal trend vector as a high-risk candidate segment is as follows:
[0035] Based on the intensity peak in the abnormal trend vector, locate the core access request and associated command sequence that caused the abnormality;
[0036] Through the command and function mapping relationship, the command sequence is mapped to the physical action domain and viewing angle coverage domain of the camera pan / tilt head, and the affected viewing area is preliminarily determined;
[0037] Combine the terminal network address and geographic tag recorded in the identity composite identifier to perform geographic and behavioral joint clustering on cross-regional access segments and eliminate low-risk segments;
[0038] The dynamic impact radius model is used to calculate the propagation margin of the remaining access segments, expand or shrink the suspicious time window and field of view, and finally define the core access request and the extended impact domain as high-risk candidate segments.
[0039] Preferably, the process of constructing a local access dependency graph is:
[0040] Extract all involved face encryption nodes, certificate key nodes, and gimbal control command nodes within the high-risk candidate segment and aggregate them into a heterogeneous node pool;
[0041] Based on the temporal causality between nodes, key hierarchy and instruction chain calling relationship, a set of directed edges is defined, and a dependency strength weight is added to each edge;
[0042] The node pool and directed edges are constructed into a trimodal access graph and fed into a hybrid graph convolution and attention network to learn node embedding vectors.
[0043] The node influence sorting algorithm is used to identify the most influential dependency paths and potential risk diffusion points in the graph, and output the local access dependency graph.
[0044] Preferably, the safety margin and controllable delay of each node are calculated;
[0045] Build a multi-objective priority decision-making model based on safety margin and controllable delay to calculate the expected risk reduction rate and business interference;
[0046] A hierarchical weight allocation algorithm is used to combine risk reduction rate and business interference degree into intervention priority, generating a response strategy queue with priority.
[0047] Response strategies are executed in sequence according to priority, and the execution status is fed back to the session trajectory chain in real time. The global security margin is re-evaluated after execution, and the hierarchical access control response result is finally output.
[0048] A certificate authorization access control system based on facial encryption features, comprising:
[0049] Face acquisition module: responsible for synchronous scanning of visible light and near-infrared images, light drift compensation and semantic segmentation, and outputting raw face data stream;
[0050] Encryption generation module: performs elliptic domain homomorphic reversible encryption on the original face data stream, and combines the random salt value with the security element key to generate a recalculated face encryption vector;
[0051] Behavior prediction module: Based on session-level identity composite identification, it integrates historical behavior entropy fluctuations and certificate revocation chain information to predict access session authenticity in real time and output abnormal trend vectors;
[0052] Graph construction module: This module locks down the scope of suspicious access requests based on abnormal trend vectors, extracts face encryption nodes, certificate key nodes, and PTZ instruction nodes, and generates a local access dependency graph.
[0053] Access control module: Combining the local dependency graph with the global security margin changes, it implements intervention judgment on the authorized path, dynamically outputs a hierarchical response strategy, and drives the camera pan / tilt to perform corresponding security actions.
[0054] Compared with the existing technology, the present invention provides a certificate-authorized access control system, method and camera platform based on facial encryption features, which have the following beneficial effects:
[0055] The present invention introduces distributed multimodal acquisition and elliptical domain homomorphic encryption mechanism to achieve stable encryption and recalculation of facial features in complex lighting, partial occlusion and multi-terminal heterogeneous environments, avoiding the risk of plaintext feature leakage in traditional biometrics; the hybrid encryption strategy that integrates time-series random salt values and device-side security element keys can effectively resist replay attacks and differential analysis, and improve the ability of identity authentication; by constructing an identity composite identifier and combining a multi-factor confidence fusion algorithm, it can comprehensively evaluate the evolution trajectory and abnormal trends of access sessions, and achieve early identification of potential fraudulent paths; by constructing a local access dependency graph and identifying high-impact risk paths, it effectively reveals the key nodes and propagation patterns in the access link, and provides a structured decision-making basis for dynamic hierarchical response strategies; ultimately, it achieves real-time intervention and hierarchical control of abnormal behaviors, comprehensively improving the perception intelligence level and access control refinement level of the boundary protection system, and is suitable for identity authentication and authority management systems in high-security scenarios such as financial computer rooms, military facilities, and sensitive data centers. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 Schematic diagram of the method of the present invention;
[0057] Figure 2 Schematic diagram of the system of the present invention. DETAILED DESCRIPTION
[0058] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0059] Example 1: Please refer to Figure 1 As shown, the certificate authorization access control method based on face encryption features according to an embodiment of the present invention includes the following steps:
[0060] S1: The visible light and near-infrared light domains of the high-security protection area are scanned synchronously through distributed multimodal acquisition nodes, and the facial geometric boundaries, spectral texture, and ambient light drift parameters are extracted to generate the first facial raw data stream.
[0061] The process of generating the first face original data stream in S1 is as follows:
[0062] Visible light cameras, near-infrared fill-light cameras, and light environment sensors are deployed at the entrance to the protection area, control consoles, and inspection channels to achieve microsecond-level alignment of all acquisition nodes.
[0063] A joint field-of-view calibration algorithm is used to dynamically calibrate the internal and external parameters of multiple camera units, eliminating lens distortion and geometrically aligning overlapping fields of view to obtain a cross-modal spatial mapping matrix. Each camera unit first captures a standard checkerboard target, and a sparse sub-pixel corner detection algorithm is used to iteratively optimize the focal length, principal point, and distortion coefficient. The residual error is controlled within 0.5%. The visible light and near-infrared camera units in the same installation group alternately capture environmental feature points, and the rotation and translation relationship between the two camera coordinate systems is calculated using least squares registration. A mapping matrix is generated based on the external parameter relationship, and the near-infrared frame is reprojected to the visible light frame coordinate system via bilinear interpolation. Mutual information evaluation is performed on the overlapping area, and the overlap error is less than one pixel.
[0064] An adaptive light drift compensation model is called to perform light intensity normalization and pseudo-color fusion on visible light and near-infrared frames to improve the fidelity of facial details in low-light and backlit scenes. The light sensor outputs the ambient brightness value every ten milliseconds, and the system calculates the mean and variance within a continuous 300 sample window to obtain the light drift trend. The three-channel histogram of the visible light frame is remapped to the 95% dynamic range. The grayscale of the near-infrared frame is scaled to 0-255. The normalized near-infrared grayscale is used as the brightness information, and the chromaticity information of the visible light frame is used to construct a pseudo-color image. Under low-light conditions, the weighting coefficient is gradually increased from 0.3 to 0.7 to enhance facial details. Local contrast-limited adaptive histogram equalization is performed on the pseudo-color frame, combining the difference in visible and near-infrared reflection to suppress highlight areas.
[0065] Based on the face semantic segmentation network, the fused frame is segmented pixel by pixel, the geometric boundaries and spectral texture features of the face are extracted, and low-quality frames are eliminated according to the preset threshold; a dual-path convolutional network of encoder and decoder is adopted, the encoder depth is six layers of convolution plus three layers of pooling, and the decoder is symmetrically upsampled; training is performed with reference to the cross entropy and focal loss hybrid objectives; the pseudo-color frame is input into the network and the face probability map is output; the threshold is set to 0.5 to obtain a binary segmentation mask; contour tracing is performed on the binary mask and polygons are fitted, and then the geometric boundaries of the face are calculated using the minimum circumscribed ellipsoid; texture vectors such as local binary patterns and directional gradient histograms are calculated in the mask area and merged into spectral texture features; frames are marked as low quality and discarded based on the judgment conditions of gradient energy lower than 30, motion blur score higher than 0.65 or occlusion rate higher than 30%;
[0066] Aggregate the retained frames in time order to form the first face raw data stream.
[0067] S2: Perform elliptic domain homomorphic reversible encryption operations on the first face original data stream, combine the time-series random salt value and the device-side security element key to construct a recalculated face encryption vector for cross-terminal authentication, and form a session-level identity composite identifier.
[0068] The process of performing the elliptical domain homomorphic reversible encryption operation on the first face original data stream by S2 is as follows:
[0069] Perform elliptical domain coordinate remapping on the facial key points in the first face raw data stream to reduce the impact of local occlusion on encryption stability; In each frame image of the first face raw data stream, use a 68-point facial feature template to locate key points such as the corners of the mouth, corners of the eyes, and the tip of the nose, remove low-confidence points affected by occlusion or blurring through Euclidean distance and local gradient threshold, retain no less than 50 high-confidence key points, perform principal component analysis on the retained key points, and the first principal component gives the direction of the main axis of the ellipse; At the same time, calculate the long and short sides of the maximum circumscribed rectangle as the initial values of the major and minor axes of the ellipse, perform posture compensation on the major and minor axes according to the facial posture angle to ensure that the ellipse envelope fits the facial contour closely, and convert the key points from the Cartesian coordinate system to the elliptical polar coordinate system to obtain two sets of parameters: amplitude and radius; The amplitude is uniformly mapped to the range of 0-360°, and the radius is normalized to 0-1. Perform a spline smoothing on the amplitude sequence to reduce the jitter introduced by single-frame noise; The radius sequence is truncated at the 95% quantile to alleviate the influence of extreme values of local occlusion;
[0070] An improved homomorphic encryption algorithm is used to perform layered reversible encryption on the mapped pixel intensity sequence, ensuring direct similarity calculations without decryption. Pixels within the elliptical domain are decomposed into three layers: low-frequency, medium-frequency, and high-frequency, using the discrete cosine transform. Each layer forms a one-dimensional intensity vector. To reduce computational complexity, all coefficients are retained for the low-frequency layer, the top 40% of the medium-frequency layer is retained by energy percentage, and the top 10% of the high-frequency layer is retained. An improved Paulier homomorphic encryption algorithm is employed: the modulus length is set to 2400 bits, and the multiplication threshold is set to 5, achieving a compromise between security and real-time performance. The public key is uniformly generated by the trust center during system initialization, and the private key is split and stored in a two-level hardware security module. No single point can independently recover the complete private key. Homomorphic addition and homomorphic multiplication encryption are performed on each layer's intensity vector, forming three sets of ciphertext vectors. Identifier tags are used to reconstruct the ciphertexts from different layers into a complete ciphertext sequence and write a frame-level index. Zero-knowledge provable auxiliary information is appended to the end of the ciphertext sequence to prove that the encrypted vector originates from legitimate plaintext without revealing the plaintext content.
[0071] During the homomorphic operation, a resettable random blinding factor is implanted to make each encrypted output statistically independent, preventing differential analysis from stealing valid information. The device-side hardware random number generator is called to generate a 128-bit random number per frame. This number is expanded to the vector length using a polynomial diffusion algorithm. The blinding factor and the ciphertext vector are homomorphically added and mixed at a ratio of 10:1 to ensure the statistical independence of the two encrypted outputs. The blinding factor is automatically reset before the start of the next frame, and the old blinding factor is immediately placed in a destruction queue to prevent replay or differential analysis. The system records the blinding factor index number in the session token and only discloses the index number to the authorized decryption end through a controlled channel when decryption is required. The blinding factor itself is not disclosed.
[0072] After encryption is completed, a reverse verifiable hash check is performed on the encrypted domain pixel block to verify the encryption integrity and reversibility. If the check passes, the elliptical domain encryption feature set is output; the ciphertext vector is serially double-hashed using the three-version secure hash algorithm and the tree-shaking hash algorithm. The former ensures collision resistance, and the latter provides fast verification. After each encryption of 120 ciphertext elements, the hash value of this segment is written into the intra-frame checksum table; the error diffusion range is limited to 120 elements to facilitate local retransmission. The encryption module compares the full-frame hash value with the checksum table before output. If there is a hash inconsistency, check bit anomaly, or blind factor mismatch, it is immediately marked as failed and re-encrypted. After the check passes, the ciphertext vector, checksum table, and blind factor index number are integrated and encapsulated into the elliptical domain encryption feature set.
[0073] The process of combining the time-series random salt value and the device-side secure element key in S2 to construct a recalculated face encryption vector for cross-terminal authentication is as follows:
[0074] The master control server issues a random salt value calculated based on the time drift margin and distributes it to each collection node via a secure channel. The master control server uses a second-level timestamp as a benchmark, introduces a forward and backward drift margin evaluation function, and calculates the possible offset range of the current system clock. Within the offset range, a hardware true random number source is used to generate a 256-bit random bit stream, which is mapped into a random salt value sequence, and the salt value generation time and validity period are recorded. A hierarchical key management strategy is adopted, and a one-time message authentication hash is performed on the salt value sequence with the control center's root key to generate a verification tag. The salt value sequence and verification tag are synchronously sent to all collection nodes via a secure channel through an isolated intranet. The secure channel uses end-to-end symmetric key encryption. After receiving the salt value, the collection node immediately verifies the verification tag and writes it to the local cache if the verification is successful.
[0075] The built-in secure element of the camera pan / tilt control board is called to extract the unique device identification code and dynamically derived key to generate a local private key pair. After passing the power-on self-test, the built-in secure element of the camera pan / tilt control board outputs the unique device identification code and derives a session key pool in the secure area. The latest dynamically derived key is selected from the session key pool and input into the elliptic curve key generation logic in combination with the device identification code to generate a local private key and corresponding public key. The private key exists only in the protected area of the secure element and cannot be directly read from the outside. The public key is cached in the open area of the control board after a hashing operation for subsequent encryption operations. To improve the ability to resist side-channel attacks, the key generation algorithm introduces a random masking factor, and the power consumption and electromagnetic radiation characteristics of each generation process are randomized. After the key pair is successfully generated, the secure element writes an event tag to the system log.
[0076] The output elliptical domain encrypted feature set is subjected to a convolution hash mixing operation with a random salt value, and a secondary encryption is performed using a private key to obtain a recalculated face encryption vector; the elliptical domain encrypted feature set and the random salt value are received, and the two are aligned according to the frame sequence number to ensure one-to-one correspondence; a convolution operation is performed on the encrypted feature vector and the salt value sequence of each frame, and the convolution kernel is a Gaussian weight matrix in a sliding window, and the convolution result forms a mixed vector; a multiple hash function chain is applied to the mixed vector, the first hash is used to diffuse randomness, and the second hash is used to compress the data length to obtain a hash mixing result; the hash mixing result is input into the security element, and the local private key is called to perform secondary encryption, and the secondary encryption adopts the fast exponential operation mode of the encryption algorithm to reduce latency; after the secondary encryption is completed, the ciphertext vector is output, and the salt value validity period, frame sequence number and encryption round label are appended to the end of the vector to facilitate cross-terminal consistency verification.
[0077] The process of forming the session-level identity composite identifier in S2 is as follows:
[0078] The recomputable face encryption vector is bidirectionally bound to the digital certificate fingerprint obtained during the handshake phase, and a session hash value is generated through a multi-layer hash aggregation mechanism. First, the ciphertext body of the recomputable face encryption vector is taken, and then the digital certificate fingerprint returned during the handshake phase is taken. The two fields are arranged in ascending order according to the frame sequence number, and fixed-length all-zero padding is used to align the two fields to prevent length leakage. The hardware true random number source is called to generate a 128-bit random bit stream, which is inserted into the front end of the vector and the end of the fingerprint respectively to improve the ability to resist splicing attacks. The first-layer hash uses a variable-length hash function to output a 512-bit intermediate hash value. The second-layer hash uses a sponge structure hash function to mix the intermediate hash value with the time entropy seed to output a 384-bit hash fragment. The final layer hash performs hash compression on the 384-bit fragment and the device local counter to finally obtain a 256-bit session hash value.
[0079] The session hash value, current timestamp, unique device identifier, and access entry number are written to a one-time session token and encrypted using a session-level symmetric encryption algorithm. The session hash value, current system timestamp, unique device identifier, and access entry number are concatenated in the order of hash value-time-device-entry. Length markers are inserted between fields to prevent parsing ambiguity. A random serial number is generated for the token. The serial number does not repeat on the same device within 24 hours and is used as a lifecycle management index. The session working key is derived from the system master key tree and is valid only within this session. The entire token is encrypted using block encryption mode, with random padding of a maximum length of 16 bytes to prevent the last block from being visible. A short hash is then performed on the encrypted token and appended to the end of the token.
[0080] Establish a session trace chain on the access control gateway side to record the session token life cycle, recalculate the checksum and certificate status, and make the entire process traceable;
[0081] The final output includes a session-level identity composite identifier that can be recalculated as a face encryption vector, a certificate fingerprint, and a session token.
[0082] S3: Based on the composite identity, a multi-dimensional confidence fusion network is called to predict the authenticity evolution trajectory of the current access session. The historical behavior entropy fluctuations, certificate revocation chain propagation characteristics and light field occlusion patterns are integrated to identify potential fraudulent paths and output abnormal trend vectors.
[0083] The process of identifying potential fraudulent paths and outputting abnormal trend vectors in S3 is as follows:
[0084] Receive the session-level identity composite identifier and decipher the validity of the vector and token, constructing a sequence of session-level behavior vectors, including access start and end times, instruction type, device location, and certificate status code;
[0085] A conversation authenticity model based on a hidden state Markov network is established. The likelihood of the behavior vector sequence is estimated using a library of historical normal conversations, and a preliminary abnormal deviation degree is output. Normal access and suspicious access are set as the hidden state set, and the discretized instruction category, time interval level, and position level in the behavior vector are used as the observation symbol set. The state transition probability matrix and observation probability matrix are trained on the historical normal conversation library using the maximum expectation algorithm, with the model convergence threshold set to 0.5%. The forward algorithm is used to calculate the likelihood of the observation sequence of the real-time generated behavior vector sequence, and the result is logarithmically compared with the historical mean to obtain a preliminary abnormal deviation degree. If the sequence contains a control instruction that is still initiated despite the certificate status code being revoked, the deviation degree is directly increased to above the warning threshold.
[0086] The preliminary abnormal offset is superimposed with the historical behavioral entropy fluctuation curve, and the certificate revocation chain propagation delay and light field occlusion probability are integrated to form a multi-factor abnormality confidence; the behavioral entropy curve of the same device in the last forty-eight hours is queried, and after smoothing short-term fluctuations with the sliding window averaging method, it is weighted and summed with the current offset. The weight distribution principle is: the offset weight is 60%, the historical entropy weight is 40%, and the weight is dynamically adjusted with the daily use frequency of the device. The time difference from the revocation request to the gateway taking effect of the certificate status is calculated; if the delay exceeds the set threshold of five minutes, the abnormal confidence is multiplied by one plus the delay ratio coefficient, and the occlusion probability is obtained from the real-time light field monitoring log of the acquisition node; if the probability is higher than 30%, it means that the facial features are distorted, and the confidence is reduced by 20%. Combining the above three factors, a multi-factor abnormality confidence is obtained;
[0087] A sliding window frequency domain analysis is performed on the anomaly confidence level to extract features such as anomaly intensity, duration, and sudden spikes to generate an anomaly trend vector. A discrete Fourier transform is performed on each window using a sliding window of 30 seconds in length and 5 seconds in step size to obtain a frequency domain amplitude spectrum. The total energy of the low-frequency components from 0 to 0.1 Hz in the amplitude spectrum is recorded as an indicator of anomaly persistence. The amplitude of high-frequency spikes above 0.3 Hz is recorded as an indicator of sudden anomaly intensity. The ratio of low-frequency to high-frequency energy is calculated to evaluate the anomaly trend.
[0088] S4: The access requests and impact range corresponding to the abnormal trend vector are delineated as high-risk candidate segments, and the face encryption nodes, certificate key nodes, and gimbal control instruction nodes in the candidate segments are integrated to construct a local access dependency graph.
[0089] The process of defining the access request and impact range corresponding to the abnormal trend vector as a high-risk candidate segment in S4 is as follows:
[0090] Based on the intensity peak in the abnormal trend vector, locate the core access request and associated command sequence that caused the abnormality;
[0091] Through the command-function mapping relationship, the command sequence is mapped to the physical action domain and field of view coverage of the camera head, preliminarily determining the affected field of view segment. Each command in the command sequence is mapped to the physical action domain and the lens focus coordinates at the corresponding time point. The field of view coverage area of the lens in each time slice is calculated, and the frames are merged to obtain continuous field of view segments. Based on the frequency and duration of field of view switching, the coverage area is divided into static field of view blocks and dynamic transition zones. The static blocks are considered key observation areas, and the transition zones are judged as suspected cover behavior areas. If rapid switching commands are present, the sequence will be marked as evasive observation behavior and the suspicion level will be increased.
[0092] Combine the terminal network address and geographic tag recorded in the identity composite identifier to perform geographic and behavioral joint clustering on access fragments suspected of cross-region or high-frequency jumps, and eliminate low-risk fragments; read the terminal network address and geographic location tag carried in the identity composite identifier; detect whether the current access request jumps to multiple geographic regions in a short period of time, such as switching from the main control room to the backdoor channel in a short period of time, and mark it as a geographic jump access; perform K-means clustering on the time interval, function distribution and geographic tags of the command sequence to evaluate whether the current access behavior belongs to the normal operation class or the atypical behavior class; align the clustering results with the historical behavior pattern in the abnormal trend vector, and eliminate access fragments that are far away from the high-confidence abnormal behavior category;
[0093] The dynamic impact radius model is used to calculate the propagation margin of the remaining access segments, expand or shrink the suspicious time window and field of view, and finally define the core access request and the extended impact domain as high-risk candidate segments.
[0094] The process of constructing the local access dependency graph in S4 is as follows:
[0095] Extract all involved face encryption nodes, certificate key nodes and gimbal control instruction nodes in the high-risk candidate segment and aggregate them into a heterogeneous node pool; extract all session-level identity composite identifiers contained in the segment according to the session number corresponding to the high-risk candidate segment; parse the recalculated face encryption vector, the corresponding camera timestamp, device number and shooting location, construct each vector and its context metadata into an independent face encryption node, and assign a unique node number and label information; retrieve the certificate information involved in all access sessions in the candidate segment, including digital certificate fingerprint, revocation status, issuing agency information, key type, etc.; abstract the certificate key elements with access authentication function into certificate key nodes, and mark the key level and revocation status; collect all device control instructions in the candidate segment, including gimbal rotation, zoom, preset position call, etc.; each instruction records the corresponding device number, execution time, command type and execution result status code, constructs it into a gimbal control instruction node, and attaches the field of view mapping parameters corresponding to the physical action domain; the above three types of nodes are uniformly included in the heterogeneous node pool;
[0096] Based on the temporal causal relationship between nodes, key hierarchy and instruction chain calling relationship, a set of directed edges is defined, and a dependency strength weight is attached to each edge; all nodes in the heterogeneous node pool are traversed, and an event chain is constructed according to the timestamp order; if node A (such as a face encryption node) occurs before node B (such as a certificate verification node) and belongs to the same session trajectory, a "temporal causal edge" is established from A to B, and a time difference field is attached to the edge attribute; the certificate key nodes are constructed into a tree-like key structure according to the issuance relationship. If a certificate issues or verifies another certificate, a hierarchical edge is established, and the key strength and trust level are attached as edge weight factors; if there is a key replacement operation in the session, the key replacement path is recorded, and the edge attribute is set to dynamic association; the calling order of continuous control instructions in the same session is parsed. If an instruction triggers another instruction or depends on its result (such as automatic focus after a preset position call), a logical call edge is established; If an encrypted identity or certificate information is included in the instruction call, an identity tag is added to the edge attributes to facilitate the subsequent recognition of context coupling strength by the graph neural network. All directed edges are assigned a dependency strength weight by default, with the initial value calculated based on the following factors: the shorter the time interval between nodes, the higher the key level, and the more frequent the calls, the greater the strength weight. If an edge has appeared in a historical anomaly path, its weight is automatically increased to an empirical anomaly-related edge and displayed in bold on the graph.
[0097] The node pool and its directed edges are constructed into a trimodal access graph and input into a hybrid graph convolution and attention network to learn node embedding vectors. Face encryption nodes, certificate key nodes, and gimbal control command nodes are classified as three types of nodes, and their types are marked in a unified graph structure. All established directed edges are integrated to form a complete trimodal access graph, where the direction of the edge represents the dependency relationship and the edge attributes represent the weight and dependency semantics. The trimodal access graph is input into a hybrid graph neural network model. In the first stage, a graph convolutional neural network is used to perform preliminary feature aggregation on the nodes. In the second stage, an attention mechanism is introduced to identify high-attention dependency edges by weighting the embedding vectors of neighboring nodes, thereby capturing key nodes in potential abnormal paths. After model training, each node generates a multidimensional embedding vector that encodes its dependency status, call frequency, and propagation influence range in the entire access graph.
[0098] The node influence sorting algorithm is used to identify the most influential dependency paths and potential risk diffusion points in the graph, and output the local access dependency graph.
[0099] S5: Based on the local access dependency graph and the entropy mutation inflection point appearing in the global security margin curve, intervention decisions are made on the authorization evolution path to dynamically generate hierarchical access control response results.
[0100] The process of dynamically generating the hierarchical access control response result in S5 is as follows:
[0101] Align the critical dependency path in the local access dependency graph with the entropy mutation inflection point in the global safety margin curve to calculate the safety margin and controllable delay of each node;
[0102] A multi-objective priority decision-making model is built based on safety margins and controllable delays. The expected risk reduction rate and business disruption are calculated for possible intervention measures, including command demotion, temporary certificate freeze, face re-verification, and gimbal security posture lock.
[0103] A hierarchical weight allocation algorithm is used to combine risk reduction rate and business interference degree into intervention priority, generating a response strategy queue with priority.
[0104] Response strategies are executed sequentially according to priority, and the execution status is fed back to the session trajectory chain in real time. The global safety margin is re-evaluated after execution. If entropy mutations still exist, the response strategy queue is iteratively adjusted.
[0105] Finally, the hierarchical access control response result is output.
[0106] Example 2: Please refer to Figure 2 As shown, a certificate authorization access control system based on facial encryption features includes:
[0107] Face acquisition module: responsible for synchronous scanning of visible light and near-infrared images, light drift compensation and semantic segmentation, and outputting raw face data stream;
[0108] Encryption generation module: performs elliptic domain homomorphic reversible encryption on the original face data stream, and combines the random salt value with the security element key to generate a recalculated face encryption vector;
[0109] Behavior prediction module: Based on session-level identity composite identification, it integrates historical behavior entropy fluctuations and certificate revocation chain information to predict access session authenticity in real time and output abnormal trend vectors;
[0110] Graph construction module: This module locks down the scope of suspicious access requests based on abnormal trend vectors, extracts face encryption nodes, certificate key nodes, and PTZ instruction nodes, and generates a local access dependency graph.
[0111] Access control module: Combining the local dependency graph with the global security margin changes, it implements intervention judgment on the authorized path, dynamically outputs a hierarchical response strategy, and drives the camera pan / tilt to perform corresponding security actions.
[0112] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0113] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A certificate authorization access control method based on face encryption features, characterized in that: The following steps are involved: The distributed multimodal acquisition nodes are used to synchronously scan the visible light and near-infrared light domains of the high-security protection zone, extract the facial geometric boundaries, spectral texture, and ambient light drift parameters, and generate the first facial raw data stream; Perform elliptic domain homomorphic reversible encryption on the first face raw data stream, combine the time-series random salt value with the device-side secure element key to construct a recalculated face encryption vector for cross-terminal authentication, and form a session-level identity composite identifier; Based on the composite identity, a multi-dimensional confidence fusion network is used to predict the authenticity evolution trajectory of the current access session. By integrating historical behavior entropy fluctuations, certificate revocation chain propagation characteristics, and light field occlusion patterns, potential fraudulent paths are identified and an abnormal trend vector is output. The access requests and impact ranges corresponding to the abnormal trend vectors are delineated as high-risk candidate segments. The face encryption nodes, certificate key nodes, and PTZ control instruction nodes within the candidate segments are integrated to construct a local access dependency graph. Based on the local access dependency graph and the entropy mutation inflection point appearing in the global security margin curve, intervention decisions are made on the authorization evolution path to dynamically generate hierarchical access control response results.
2. A certificate authorization access control method based on face encryption features according to claim 1, characterized in that: The process of generating the first face raw data stream is: Visible light cameras, near-infrared fill-light cameras, and light environment sensors are deployed at the entrance to the protection area, control consoles, and inspection channels to achieve microsecond-level alignment of all acquisition nodes. A field-of-view joint calibration algorithm is used to dynamically calibrate the internal and external parameters of multiple camera units, eliminate lens distortion, and perform geometric alignment on overlapping fields of view to obtain a cross-modal spatial mapping matrix. Call the adaptive light drift compensation model to perform light intensity normalization and pseudo-color fusion on visible light frames and near-infrared frames; Based on the face semantic segmentation network, the fused frame is segmented pixel by pixel to extract the geometric boundary and spectral texture features of the face, and low-quality frames are eliminated according to the preset threshold; Aggregate the retained frames in time order to form the first face raw data stream.
3. The certificate authorization access control method based on face encryption features according to claim 2 is characterized in that: The process of performing elliptical domain homomorphic reversible encryption on the first face original data stream is as follows: Performing ellipse domain coordinate remapping on facial key points in the first face raw data stream; For the mapped pixel intensity sequence, the improved homomorphic encryption algorithm is called to perform layered reversible encryption; A resettable random blinding factor is implanted during the homomorphic operation to make each encrypted output statistically independent of each other; After encryption is completed, a reverse verifiable hash check is performed on the encrypted domain pixel block. If the check passes, the ellipse domain encryption feature set is output.
4. The certificate authorization access control method based on face encryption features according to claim 3 is characterized in that: The process of combining the time-series random salt value and the device-side secure element key to construct a recalculated face encryption vector for cross-terminal authentication is as follows: The master server issues a random salt value calculated based on the time drift margin and distributes it to each collection node through a secure channel. Call the built-in security element of the camera pan / tilt control board to extract the unique device identification code and dynamically derived key to generate a local private key pair; The output elliptical domain encrypted feature set is mixed with the random salt value through convolution hashing operation, and the private key is used to complete the secondary encryption to obtain a recalculated face encryption vector.
5. The certificate authorization access control method based on face encryption features according to claim 4 is characterized in that: The process of forming a session-level composite identity is as follows: The recalculated face encryption vector is bidirectionally bound to the digital certificate fingerprint obtained during the handshake phase, and a session hash value is generated through a multi-layer hash aggregation mechanism. Write the session hash value, current timestamp, unique device identification code and access entry number into the one-time session token and encrypt it using a session-level symmetric encryption algorithm; A session trace chain is established on the access control gateway side to record the session token life cycle, recalculate the checksum and certificate status, and finally output the session-level identity composite identifier.
6. The certificate authorization access control method based on face encryption features according to claim 5 is characterized in that: The process of identifying potential fraudulent paths and outputting abnormal trend vectors is as follows: Receive the session-level identity composite identifier and solve the validity of the vector and token to construct a sequence of session-level behavior vectors; A conversation authenticity model based on a hidden state Markov network is established. The likelihood of the behavior vector sequence is estimated using a library of historical normal conversations, and a preliminary abnormal deviation degree is output. The initial anomaly deviation degree is superimposed with the historical behavior entropy fluctuation curve, and the certificate revocation chain propagation delay and light field occlusion probability are integrated to form a multi-factor anomaly confidence level. Perform sliding window frequency domain analysis on the anomaly confidence, extract features, and generate anomaly trend vectors.
7. The certificate authorization access control method based on face encryption features according to claim 6 is characterized in that: The process of defining the access requests and impact ranges corresponding to the abnormal trend vectors as high-risk candidate segments is as follows: Based on the intensity peak in the abnormal trend vector, locate the core access request and associated command sequence that caused the abnormality; Through the command and function mapping relationship, the command sequence is mapped to the physical action domain and viewing angle coverage domain of the camera pan / tilt head, and the affected viewing area is preliminarily determined; Combine the terminal network address and geographic tag recorded in the identity composite identifier to perform geographic and behavioral joint clustering on cross-regional access segments and eliminate low-risk segments; The dynamic impact radius model is used to calculate the propagation margin of the remaining access segments, expand or shrink the suspicious time window and field of view, and finally define the core access request and the extended impact domain as high-risk candidate segments.
8. The certificate authorization access control method based on face encryption features according to claim 7 is characterized in that: The process of building a local access dependency graph is: Extract all involved face encryption nodes, certificate key nodes, and gimbal control command nodes within the high-risk candidate segment and aggregate them into a heterogeneous node pool; Based on the temporal causality between nodes, key hierarchy and instruction chain calling relationship, a set of directed edges is defined, and a dependency strength weight is added to each edge; The node pool and directed edges are constructed into a trimodal access graph and fed into a hybrid graph convolution and attention network to learn node embedding vectors. The node influence sorting algorithm is used to identify the most influential dependency paths and potential risk diffusion points in the graph, and output the local access dependency graph.
9. The certificate authorization access control method based on face encryption features according to claim 8, characterized in that: The process of dynamically generating hierarchical access control response results is as follows: Align the critical dependency path in the local access dependency graph with the entropy mutation inflection point in the global safety margin curve to calculate the safety margin and controllable delay of each node; Build a multi-objective priority decision-making model based on safety margin and controllable delay to calculate the expected risk reduction rate and business interference; A hierarchical weight allocation algorithm is used to combine risk reduction rate and business interference degree into intervention priority, generating a response strategy queue with priority. Response strategies are executed in sequence according to priority, and the execution status is fed back to the session trajectory chain in real time. The global security margin is re-evaluated after execution, and the hierarchical access control response result is finally output.
10. A certificate authorization access control system based on facial encryption features, applied to the method according to any one of claims 1 to 9, characterized in that: include: Face acquisition module: responsible for synchronous scanning of visible light and near-infrared images, light drift compensation and semantic segmentation, and outputting raw face data stream; Encryption generation module: performs elliptic domain homomorphic reversible encryption on the original face data stream, and combines the random salt value with the security element key to generate a recalculated face encryption vector; Behavior prediction module: Based on session-level identity composite identification, it integrates historical behavior entropy fluctuations and certificate revocation chain information to predict access session authenticity in real time and output abnormal trend vectors; Graph construction module: This module locks down the scope of suspicious access requests based on abnormal trend vectors, extracts face encryption nodes, certificate key nodes, and PTZ instruction nodes, and generates a local access dependency graph. Access control module: Combining the local dependency graph with the global security margin changes, it implements intervention judgment on the authorized path, dynamically outputs a hierarchical response strategy, and drives the camera pan / tilt to perform corresponding security actions.
Citation Information
Patent Citations
Information collection and management system based on face recognition technology
CN119741745A
Self-service intelligent visitor authorization method and system
CN120281583A