Face authentication method and device, electronic equipment, medium and program product

Through fuzzy matching technology of encrypted index and query trapdoor, the problems of privacy leakage and high computing load in face authentication are solved, and efficient and secure face authentication in financial business scenarios is realized, which is suitable for mobile devices and edge terminals.

CN120654223APending Publication Date: 2025-09-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510866616.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing facial recognition technology has privacy leakage risks, high computational costs, and large response delays in financial business scenarios. It is difficult to meet real-time and stability requirements, and there is a lack of practical systems that balance privacy protection and rapid response.

Method used

Fuzzy matching of encrypted index and query trapdoor is used to replace traditional plaintext comparison. The target keyword set is generated by obtaining the facial feature vector and encrypted. The query trapdoor and the encrypted index in the face ciphertext database are used to perform fuzzy matching search. Combined with Bloom filter encoding and local sensitive hash function, private storage and encrypted retrieval of facial features are achieved.

Benefits of technology

It reduces computing load, improves response efficiency, enhances privacy and security, has a certain fault tolerance capability, and improves the authentication experience under non-ideal conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120654223A_ABST
    Figure CN120654223A_ABST
Patent Text Reader

Abstract

The invention provides a face authentication method which can be applied to the technical field of artificial intelligence, the technical field of big data and the field of financial science and technology. The method comprises the following steps: acquiring a face feature vector of a to-be-authenticated face image; generating a target keyword set based on the face feature vector, and encrypting the target keyword set to obtain a query trap door; executing fuzzy matching search by using the query trap door and an encryption index stored in a face ciphertext database to obtain a matching result; and face authentication is carried out based on the matching result, and the face ciphertext database is constructed based on the following modes: obtaining historical face feature vectors; generating a historical keyword set based on the historical face feature vector, and constructing an encryption index based on the historical keyword set; and associating the encrypted index with the corresponding user identity information, and storing the encrypted index and the corresponding user identity information in the face ciphertext database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the fields of artificial intelligence technology, big data technology, and financial technology, and more specifically to a face recognition method, device, equipment, medium, and program product. Background Art

[0002] Existing facial recognition technology is widely used in financial business scenarios for key processes such as remote account opening, online payments, and risk control. However, current mainstream facial recognition solutions have significant limitations: Traditional static feature library comparison methods often store facial features in plaintext, posing a serious risk of privacy leakage. Furthermore, while homomorphic encryption and federated learning have improved data security to some extent, the former suffers from high computational costs and significant response latency, making it difficult to meet the real-time and stability requirements of financial systems. The latter, however, relies on complex distributed architectures and high-frequency synchronization mechanisms, making it unsuitable for mobile terminals or offline devices.

[0003] Although searchable encryption schemes that support fuzzy queries to enhance fault tolerance already exist in fields such as natural language processing and image retrieval, these schemes mostly focus on text or ordinary image data. When it comes to encrypted facial feature matching, especially for applications in the financial industry that require high security, low latency, and multi-device compatibility, there is still a lack of practical systems that can balance privacy protection and rapid response. Summary of the Invention

[0004] In view of the above problems, the present disclosure provides a face authentication method, apparatus, device, medium and program product.

[0005] According to a first aspect of the present disclosure, a face authentication method is provided, the method comprising: obtaining a face feature vector of a face image to be authenticated; generating a target keyword set based on the face feature vector, encrypting the target keyword set, and obtaining a query trapdoor; performing a fuzzy matching search using the query trapdoor and an encrypted index stored in a face ciphertext database to obtain a matching result; and performing face authentication based on the matching result, wherein the face ciphertext database is constructed in the following manner: obtaining a historical face feature vector; generating a historical keyword set based on the historical face feature vector, and constructing an encrypted index based on the historical keyword set; associating the encrypted index with corresponding user identity information, and storing the encrypted index in the face ciphertext database.

[0006] According to an embodiment of the present disclosure, obtaining the facial feature vector of the facial image to be authenticated includes: using a target facial recognition model to perform feature encoding on the facial image to be authenticated to obtain a floating-point feature vector; and performing fixed-point quantization processing on the floating-point feature vector to obtain the facial feature vector, wherein the fixed-point quantization processing includes mapping the floating-point feature vector to an integer representation of a preset bit width.

[0007] According to an embodiment of the present disclosure, generating a historical keyword set based on the historical facial feature vector and constructing an encryption index based on the historical keyword set include: applying multiple local sensitive hash functions to the historical facial feature vector to generate multiple historical hash values; forming the multiple historical hash values ​​into a historical keyword set, performing a target secure hash operation on each keyword in the historical keyword set to obtain multiple secure hash results; and intercepting a preset bit interval from each secure hash result as the encryption index.

[0008] According to an embodiment of the present disclosure, the target keyword set is generated based on the facial feature vector, the target keyword set is encrypted, and a query trapdoor is obtained, including: applying multiple local sensitive hash functions to the facial feature vector to generate multiple target hash values; generating the target keyword set based on the multiple target hash values; for each keyword in the target keyword set, multiple keyword variants are generated based on feature perturbation or semantic similarity; and a target secure hash operation is performed on the target keyword set and the multiple keyword variants to generate multiple trapdoor tokens, and the multiple trapdoor tokens are combined to form the query trapdoor.

[0009] According to an embodiment of the present disclosure, associating the encrypted index with the corresponding user identity information and storing it in the face ciphertext database includes: performing Bloom filter encoding on the encrypted index to generate a Bloom filter bit vector; using the Bloom filter bit vector as the value field and the corresponding user identity information as the key field to form a key-value pair record; and storing the key-value pair record in the face ciphertext database.

[0010] According to an embodiment of the present disclosure, the use of the query trapdoor and the encrypted index stored in the face ciphertext database to perform a fuzzy matching search to obtain a matching result includes: determining the bit positions of multiple trapdoor tokens in the query trapdoor; and performing a bitwise comparison operation on the bit position and the Bloom bit vector corresponding to each record in the face ciphertext database, and obtaining the matching result based on the comparison result.

[0011] According to an embodiment of the present disclosure, obtaining the matching result based on the comparison result includes: obtaining multiple preliminary candidate records based on the comparison result; for the multiple preliminary candidate records, counting the number of corresponding hit positions in the bitwise comparison operation, and calculating the similarity score based on the number of positions; and sorting the multiple preliminary candidate records based on the similarity score, and obtaining the matching result based on the sorting result.

[0012] The second aspect of the present disclosure provides a face authentication device, which includes: a data acquisition module, which is used to obtain a face feature vector of a face image to be authenticated; an encryption processing module, which is used to generate a target keyword set based on the face feature vector, encrypt the target keyword set, and obtain a query trapdoor, wherein the face ciphertext database is constructed based on the following methods: obtaining a historical face feature vector; generating a historical keyword set based on the historical face feature vector, and constructing an encryption index based on the historical keyword set; associating the encrypted index with the corresponding user identity information and storing it in the face ciphertext database; a fuzzy matching search module, which is used to perform a fuzzy matching search using the query trapdoor and the encrypted index stored in the face ciphertext database to obtain a matching result; and a face authentication module, which is used to perform face authentication based on the matching result.

[0013] According to an embodiment of the present disclosure, the data acquisition module can also be used to use the target face recognition model to perform feature encoding on the face image to be authenticated to obtain a floating-point feature vector; and perform fixed-point quantization processing on the floating-point feature vector to obtain the face feature vector, wherein the fixed-point quantization processing includes mapping the floating-point feature vector to an integer representation of a preset bit width.

[0014] According to an embodiment of the present disclosure, the encryption processing module can also be used to apply multiple local sensitive hash functions to the facial feature vector to generate multiple target hash values; generate the target keyword set based on the multiple target hash values; for each keyword in the target keyword set, generate multiple keyword variants based on feature perturbation or semantic similarity; and perform target secure hash operations on the target keyword set and multiple keyword variants to generate multiple trapdoor tokens, and combine the multiple trapdoor tokens to form the query trapdoor.

[0015] According to an embodiment of the present disclosure, the fuzzy matching search module can also be used to determine the bit positions of multiple trapdoor tokens in the query trapdoor; and perform a bitwise comparison operation on the bit positions with the Bloom bit vector corresponding to each record in the face ciphertext database, and obtain the matching result based on the comparison result.

[0016] According to an embodiment of the present disclosure, the face recognition module can also be used to obtain multiple preliminary candidate records based on the comparison results; for multiple preliminary candidate records, count the number of corresponding hit positions in the bitwise comparison operation, and calculate the similarity score based on the number of positions; and sort the multiple preliminary candidate records based on the similarity score, and obtain the matching result based on the sorting result.

[0017] According to an embodiment of the present disclosure, the face authentication device may further include a face ciphertext database construction module. The face ciphertext database construction module may be configured to apply multiple locality-sensitive hash functions to the historical face feature vectors to generate multiple historical hash values; combine the multiple historical hash values ​​into a historical keyword set; perform a target secure hash operation on each keyword in the historical keyword set to obtain multiple secure hash results; and extract a preset bit interval from each secure hash result as the encryption index.

[0018] According to an embodiment of the present disclosure, the face ciphertext database construction module can also be used to perform Bloom filter encoding on the encrypted index to generate a Bloom filter bit vector; use the Bloom filter bit vector as the value field and the corresponding user identity information as the key field to form a key-value pair record; and store the key-value pair record in the face ciphertext database.

[0019] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0020] The fourth aspect of the present disclosure further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the computer program or instructions are executed by a processor.

[0021] The fifth aspect of the present disclosure further provides a computer program product, comprising a computer program or instructions, which implement the steps of the above method when executed by a processor.

[0022] According to the embodiments of the present disclosure, the traditional plaintext comparison operation is replaced by fuzzy matching between the encrypted index and the query trapdoor, thereby avoiding high-overhead image or vector-level similarity calculations, effectively reducing the computational load of the system in the authentication stage, and improving the overall response efficiency, which is suitable for environments with limited computing resources such as mobile devices or edge terminals; at the same time, keyword encryption and ciphertext database construction methods are adopted to realize private storage and encrypted retrieval of facial features, so that user sensitive information is always invisible during the authentication process, thereby enhancing the privacy security of the system; in addition, combined with the fuzzy matching characteristics of the query trapdoor, while ensuring the recognition accuracy, it has a certain fault tolerance capability, which improves the user's authentication experience under non-ideal conditions such as natural lighting and angle changes. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0024] Figure 1 Schematically illustrates an application scenario diagram of the face authentication method, apparatus, device, medium, and program product according to an embodiment of the present disclosure;

[0025] Figure 2 The following schematically shows a flow chart of a face recognition method according to an embodiment of the present disclosure;

[0026] Figure 3 Schematically illustrates a flow chart of a method for constructing an encryption index based on a historical keyword set according to some exemplary embodiments of the present disclosure;

[0027] Figure 4 Schematically shows a flow chart of a method for obtaining a query trapdoor according to an embodiment of the present disclosure;

[0028] Figure 5 Schematically shows a structural block diagram of a face authentication device according to an embodiment of the present disclosure; and

[0029] Figure 6 The block diagram schematically shows an electronic device suitable for implementing the face authentication method according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0030] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0031] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0032] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0033] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0034] First, the technical terms described in this article are explained and illustrated as follows.

[0035] Searchable encryption: An encryption method that allows keyword searches on encrypted data, ensuring both ciphertext storage and query functionality. Searchable encryption can be categorized into symmetric and asymmetric models and is widely used in privacy-preserving data retrieval systems.

[0036] Locality-Sensitive Hashing (LSH): A hashing algorithm for approximate nearest neighbor search. It maps high-dimensional feature vectors to a low-dimensional hash space, so that similar input data are mapped to the same hash value with a high probability.

[0037] Bloom filter: A highly space-efficient probabilistic data structure. It is used to determine whether an element is in a set. It supports fast insertion and query operations, has a low false positive rate but no false rejections, and is suitable for efficiently representing keyword sets and supporting fast matching queries.

[0038] Fuzzy search: A search mechanism that allows for keyword matching under certain perturbations or approximations. Its goal is to return similar or relevant matching results even when the user's query keywords are not exactly the same as the stored keywords.

[0039] Trapdoor: In searchable encryption, a cryptographic token generated by a legitimate queryer based on a query keyword is used to perform a search within the ciphertext without revealing the keyword. Trapdoor generation typically relies on the keyword, key, and encryption algorithm design.

[0040] Multi-trapdoor matching: A matching strategy that uses multiple trapdoors to perform parallel testing on ciphertext indexes to improve query matching accuracy and coverage.

[0041] Top-k nearest neighbor matching: A method that returns the top k matches that best meet the query criteria from all candidate results based on matching scores or similarity metrics to support result sorting and optimal identification.

[0042] In financial business scenarios, facial recognition, as a core technology for "zero-contact" identity verification, has been widely adopted in key processes such as remote account opening, online payment, transaction authorization, and biometric risk control. It has become a key support for improving user experience and security in the digital transformation of finance. However, existing facial recognition technologies still face numerous challenges in practical deployment. For one thing, traditional static feature comparison solutions often rely on centralized facial feature libraries and store user feature data in plaintext or with weak encryption, making them vulnerable to hacker attacks. A leak poses serious privacy risks and a crisis of trust. Furthermore, while emerging privacy-preserving technologies such as homomorphic encryption and federated learning provide theoretical support for facial data processing, they remain constrained by the "millisecond-level response" and "end-to-end computing" requirements of financial scenarios. Homomorphic encryption solutions are computationally complex and have high latency, making them unsuitable for high-concurrency scenarios such as online payment and real-time risk control. Federated learning, on the other hand, requires frequent synchronization of model parameters across multiple terminals, relying heavily on network stability and on-device computing power, making it difficult to support typical financial use cases such as offline authentication and edge recognition.

[0043] Meanwhile, in fields such as natural language processing and image retrieval, research has proposed fuzzy searchable encryption (FSE) techniques to enable fault-tolerant search in ciphertext spaces, improving tolerance to noise such as spelling errors and input errors. While these technologies have initially demonstrated the feasibility of encrypted search, they currently focus on fuzzy retrieval of text keywords or general images and have yet to offer practical solutions for the high-dimensional, time-sensitive, and privacy-critical encrypted facial feature matching problem. In the financial industry, in particular, authentication systems must simultaneously meet high recognition accuracy, strong resistance to attacks, robustness to angle changes and image quality degradation, and deployability on low-power mobile devices. Traditional exact matching or fully homomorphic computing methods cannot simultaneously address these requirements, making it difficult to implement large-scale, secure, and controllable facial authentication services across all financial scenarios.

[0044] Based on this, an embodiment of the present disclosure provides a face authentication method, including: obtaining a face feature vector of a face image to be authenticated; generating a target keyword set based on the face feature vector, encrypting the target keyword set, and obtaining a query trapdoor; performing a fuzzy matching search using the query trapdoor and the encrypted index stored in a face ciphertext database to obtain a matching result; and performing face authentication based on the matching result, wherein the face ciphertext database is constructed based on the following method: obtaining a historical face feature vector; generating a historical keyword set based on the historical face feature vector, and constructing an encrypted index based on the historical keyword set; associating the encrypted index with the corresponding user identity information, and storing it in the face ciphertext database. By replacing traditional plaintext comparison operations with fuzzy matching between encrypted indexes and query trapdoors, high-overhead image or vector-level similarity calculations are avoided, effectively reducing the system's computational load during the authentication phase and improving overall response efficiency. This approach is suitable for environments with limited computing resources, such as mobile devices or edge terminals. At the same time, keyword encryption and ciphertext database construction are used to achieve private storage and encrypted retrieval of facial features, making user sensitive information invisible during the authentication process and enhancing the privacy security of the system. In addition, combined with the fuzzy matching characteristics of the query trapdoor, it has a certain fault tolerance while ensuring recognition accuracy, improving the user's authentication experience under non-ideal conditions such as natural lighting and angle changes.

[0045] It should be noted that the face recognition methods, devices, equipment, media, and program products identified in this disclosure can be used in the fields of artificial intelligence technology, big data technology, and financial technology, and can also be used in a variety of fields other than artificial intelligence technology, big data technology, and financial technology. The application fields of the face recognition methods, devices, equipment, media, and program products provided in the embodiments of this disclosure are not limited.

[0046] In the technical solutions disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0047] In scenarios where personal information is used for automated decision-making, the methods, devices, and systems provided by the embodiments of the present disclosure all provide users with corresponding operation portals for them to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge, and skills, and have reached a certain level of professionalism.

[0048] Figure 1 The application scenario diagram of the face authentication method, apparatus, device, medium and program product according to the embodiments of the present disclosure is schematically shown.

[0049] like Figure 1 As shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or optical fiber cables.

[0050] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0051] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0052] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.

[0053] It should be noted that the face recognition method provided in the embodiments of the present disclosure can generally be executed by the server 105. Accordingly, the face recognition device provided in the embodiments of the present disclosure can generally be set in the server 105. The face recognition method provided in the embodiments of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the face recognition device provided in the embodiments of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.

[0054] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0055] The following will be based on Figure 1 The scene described by Figures 2 to 4 The face recognition method of the disclosed embodiment is described in detail.

[0056] Figure 2 The flowchart of the face authentication method according to the embodiment of the present disclosure is schematically shown.

[0057] like Figure 2 As shown, the face authentication method 200 of this embodiment includes operations S210 to S240.

[0058] In operation S210 , a facial feature vector of a face image to be authenticated is obtained.

[0059] Specifically, the system uses a camera module to capture a facial image of the current user based on the user's actions on the authentication terminal. The authentication terminal can be a mobile device (such as a smartphone or tablet), an embedded identification device (such as an access control terminal or attendance machine), or a networked terminal (such as a remote counter or automated teller machine). The system performs face detection on the captured image, extracts the facial region, and feeds it into a pre-set facial recognition model for feature extraction.

[0060] To balance computational performance and extraction accuracy, the face recognition model used for feature extraction can be a lightweight deep neural network model. This model outputs a fixed-length floating-point feature vector, representing the high-dimensional feature representation of the facial image in the embedding space. Typical dimensions are 128 or 256, which are used for subsequent keyword mapping and matching.

[0061] In some embodiments, to improve the system's robustness to varying image quality, the feature extraction process can also be combined with an image preprocessing module to perform enhancements, such as brightness normalization, face alignment, or blurred area recognition. For some edge devices, to reduce front-end computing pressure, the model can also be deployed in a quantized form, such as using an inference framework to load an 8-bit fixed-point model to further accelerate the forward reasoning process and reduce memory usage.

[0062] It should be noted that the facial recognition model in the disclosed embodiments can perform inference calculations locally on the authentication terminal, or upload the image to a trusted computing server for feature encoding and return of the results, adapting to authentication scenarios with different deployment architectures. In scenarios where multiple people are being recognized simultaneously, the system can also use the face tracking module to select the clearest face frame as input, improving feature stability.

[0063] In operation S220, a target keyword set is generated based on the facial feature vector, and the target keyword set is encrypted to obtain a query trapdoor. The facial ciphertext database is constructed by obtaining historical facial feature vectors; generating a historical keyword set based on the historical facial feature vectors; constructing an encrypted index based on the historical keyword set; and associating the encrypted index with the corresponding user identity information and storing it in the facial ciphertext database.

[0064] Specifically, operation S220 can generate facial retrieval credentials for encrypted authentication based on the user's currently collected facial feature vector. A set of representative information identifiers can be extracted based on the facial feature vector to express the uniqueness and matchability of the user's face in the feature space. These information identifiers can be strings, encoded sequences, or other data structures that can be used for subsequent authentication after performing specific processing on the feature vector, forming the target keyword set.

[0065] In the embodiments of the present disclosure, the generated target keyword set will be further converted into authentication credentials that can be used for ciphertext matching. To ensure information security during the authentication process, the target keyword set can be encrypted so that it can still be used for subsequent similarity matching operations without exposing the original feature information. The encryption processing method can be flexibly configured according to the system security policy, such as a one-way function, a pseudo-random function family, a hash mapping scheme, etc. The generated result is called a query trapdoor.

[0066] According to the embodiments of the present disclosure, the query trapdoor is used to match the encrypted index in the face ciphertext database in subsequent steps, so its generation method must be compatible with the database index generation strategy. In actual deployment, to enhance the adaptability of the system, the query trapdoor can support a certain degree of fuzziness to tolerate feature offsets in the user's current captured image due to changes in shooting angle, lighting conditions, or facial state. For example, several strategies can be pre-set to introduce diversity and fault tolerance mechanisms during keyword extraction or encryption processing to ensure that the authentication process strikes a balance between accuracy and robustness.

[0067] In some exemplary embodiments, the generation and encryption of the target keyword set can be performed locally on the terminal or uploaded to a trusted server for processing over the network. The terminal-side computation path is suitable for scenarios that emphasize privacy isolation or edge computing performance, while server-side processing is more suitable for high-concurrency, large-scale centralized authentication environments. For systems deployed in corporate intranets, smart access control systems, or self-service terminals, a hybrid processing architecture can also be adopted, moving some query trap generation operations to the client and delaying some operations to the authentication service node to optimize system load and response speed.

[0068] According to the embodiments of the present disclosure, the facial ciphertext database used must be pre-built and, in a manner consistent with the query trap generation process described above, feature vectors are extracted from historically collected user facial images to generate a historical keyword set and construct an encryptable index data structure. To ensure accuracy and consistency in the subsequent matching phase, the system can uniformly apply the same feature processing logic, encoding method, and encryption rules during database construction. The constructed facial ciphertext database can be bound to the user's identity tag for rapid query and identity matching when an authentication request occurs.

[0069] In operation S230, a fuzzy matching search is performed using the query trapdoor and the encrypted index stored in the face ciphertext database to obtain a matching result.

[0070] In the disclosed embodiments, a query trapdoor can be used to perform a matching operation in a ciphertext database without exposing the user's plaintext facial features, thereby obtaining an identity match result for the user to be authenticated. Specifically, upon receiving the query trapdoor generated by operation S220, a search process can be triggered with the ciphertext facial database. This process does not rely on decrypting or restoring feature vectors, but instead completes identity matching at the ciphertext index level, ensuring data security throughout the authentication process.

[0071] Specifically, the authentication credentials in the query trapdoor can be used as retrieval parameters and matched against each encrypted index record in the face ciphertext database in turn. Each index record corresponds to the encrypted identifier of a historically registered user. The information contained does not reveal the user's original facial image or feature content, but is only expressed in an encrypted structure. In the actual matching process, the query trapdoor does not require complete consistency with the database record. Instead, by setting a reasonable similarity matching strategy, a certain degree of deviation is allowed to adapt to slight noise or changes that may appear in the authentication image, such as light interference, changes in facial angle, or image compression loss.

[0072] To improve search efficiency, structured indexing can also be used to quickly narrow the comparison scope during the matching process. For example, the system can support batch parallel matching logic, using matrix or bit-level operations to simultaneously match a large number of candidate items in a single query, thereby maintaining response speed while meeting the needs of large-scale applications. In different system deployment environments, matching logic can be completed on the server side or embedded in edge terminals for execution, supporting both online and offline working modes.

[0073] In operation S240 , face authentication is performed based on the matching result.

[0074] Specifically, the matching results may include a set of possible candidate identity information, each of which may be accompanied by a scoring indicator indicating the degree of match, such as a similarity score, number of hits, or a confidence value. The system can preset an authentication threshold based on business rules. When the highest-scoring candidate identity exceeds this threshold, the authentication is considered successful and the corresponding identity is output as the final authentication result. If no candidate record meets the minimum matching requirements, the system may determine that the authentication has failed, prompting the user to retry, switch authentication methods, or transfer to manual review.

[0075] In some embodiments, the system can also return multiple top-ranked identity candidates based on the matching results and further enhance authentication decisions by combining external conditions or auxiliary information. For example, in an access control management system, the system can combine card swipe information, location information, or time period restrictions for cross-comparison to improve recognition accuracy. In mobile identity verification scenarios, the system can also combine device fingerprints, operational behavior tracing, and other data to implement a more comprehensive authentication risk control strategy.

[0076] To facilitate further use of the authentication results, the final output can be structured and encapsulated into an authentication response packet containing the identity ID, match score, authentication status, and more. This authentication response packet can be returned to the calling end through an interface to drive subsequent processes such as interface display, service release, operation authorization, or logging. If the system is deployed in a distributed environment, the authentication results can also be sent to other service modules via message middleware, achieving consistent authentication processing across systems.

[0077] From a user interaction perspective, the system can trigger real-time front-end interface updates after the authentication result is generated, providing feedback on whether the authentication was successful and whether further confirmation or identity verification is required. In certain user experience-sensitive scenarios, the system can also design a multi-layer authentication mechanism. For example, full authentication is required for the first use, and after passing, partial authentication or verification-free methods can be used for a short period of time, thereby improving the continuity and smoothness of the user experience while ensuring security.

[0078] The face recognition method of the embodiment of the present disclosure will be described in detail below in the form of a preferred embodiment.

[0079] In an embodiment of the present disclosure, obtaining a facial feature vector of a facial image to be authenticated may include: using a target facial recognition model to perform feature encoding on the facial image to be authenticated to obtain a floating-point feature vector; and performing fixed-point quantization processing on the floating-point feature vector to obtain a facial feature vector, wherein the fixed-point quantization processing includes mapping the floating-point feature vector to an integer representation of a preset bit width.

[0080] Specifically, a facial recognition model deployed on the client or edge device can perform feature encoding on the facial image to be authenticated. After receiving the facial image, the facial recognition model can output a set of high-dimensional floating-point vectors, such as a 128-dimensional or 512-dimensional array of real numbers, that represent the unique distribution of the face in the feature space. Furthermore, this stage can be combined with image preprocessing operations, such as face alignment, face cropping, and normalization, to improve the stability and generalization of feature extraction.

[0081] Furthermore, to adapt to the keyword generation and encrypted index construction steps, the floating-point feature vector can be further converted into an integer facial feature vector. This can be accomplished through fixed-point quantization, which specifically involves setting a bit width parameter (e.g., 8-bit, 10-bit, or 16-bit), scaling the floating-point value, and rounding it to an integer value within the corresponding range. For example, a floating-point feature in the range [-1, 1] can be mapped to an 8-bit signed integer in the interval [-128, 127].

[0082] It should be noted that, under the premise of maintaining recognition accuracy, facial feature vectors in integer form are more suitable for operations such as local sensitive hashing (LSH) processing, keyword generation, and encryption trapdoor construction in the embodiments of the present disclosure.

[0083] Figure 3 The flowchart of a method for constructing an encryption index based on a historical keyword set according to some exemplary embodiments of the present disclosure is schematically shown.

[0084] like Figure 3 As shown, the method for constructing an encrypted index based on a historical keyword set includes operations S310 to S330.

[0085] In operation S310, a plurality of locality-sensitive hash functions are applied to the historical facial feature vectors to generate a plurality of historical hash values.

[0086] The Locality Sensitive Hashing (LSH) strategy can map high-dimensional vectors to low-dimensional discrete representations while maintaining semantic similarity. Therefore, for two feature vectors that are close to each other in the original space, their hash results are likely to be similar or identical in the new hash space, facilitating subsequent matching.

[0087] In the embodiments of the present disclosure, to enhance the coverage and robustness of the mapping, multiple distinct hash functions can be constructed, each focusing on a different dimension or distribution pattern of the feature space. By applying multiple hash functions to the same feature vector, multiple hash values ​​that are not completely duplicates but still correlated can be generated. These hash values ​​together constitute the identity set of the vector. The system can preset the number and parameters of hash functions to adjust the granularity of feature extraction and collision tolerance according to actual business needs.

[0088] According to the embodiments of the present disclosure, each historical facial feature vector can be mapped into multiple shorter historical hash values, each representing a discrete representation of the original vector under a certain "semantic projection." Historical hash values ​​not only significantly compress the data volume but also reduce the risk of leakage during subsequent processing.

[0089] In operation S320 , the multiple historical hash values ​​are grouped into a historical keyword set, and a target secure hash operation is performed on each keyword in the historical keyword set to obtain multiple secure hash results.

[0090] For example, a key-driven secure hashing process can be performed on each historical keyword. To ensure the irreversibility of the keyword and its ability to resist brute force cracking, a cryptographically strong hashing algorithm can be used, such as a key-based hash message authentication code. This type of algorithm can not only ensure that different inputs produce highly dispersed output values, but also improve the system's anti-attack capabilities in combination with private keys. Specifically, the system uses a preset encryption key as a parameter and each historical keyword as input to calculate the corresponding hash value. This process ensures that even if the server obtains the encrypted index, it cannot restore the original feature keyword, thereby protecting the privacy and security of the user's facial information.

[0091] In operation S330, a preset bit interval is extracted from each secure hash result as the encryption index. For example, the preset bit interval can be the first several bits (e.g., 32 bits) extracted from each hash output to obtain sufficient distinguishing ability and good spatial sparsity.

[0092] Figure 4 The flowchart of the method for obtaining a query trapdoor according to an embodiment of the present disclosure is schematically shown.

[0093] like Figure 4 As shown, the method for obtaining a query trapdoor may include operations S410 to S440.

[0094] In operation S410, a plurality of locality-sensitive hash functions are applied to the facial feature vector to generate a plurality of target hash values.

[0095] In operation S420, the target keyword set is generated based on a plurality of target hash values.

[0096] In the embodiments of the present disclosure, for keyword extraction of facial feature vectors, whether used for query trapdoor generation or for facial ciphertext index construction, a unified processing idea can be adopted, that is, high-dimensional vectors are encoded through multiple local sensitive hash (LSH) functions, and continuous facial feature representations are mapped into a discrete set of hash values.

[0097] Specifically, when a user initiates an authentication request, features are extracted from the currently captured facial image and multiple LSH functions are applied to generate corresponding hash value sets, forming a target keyword set for further generating encrypted query trapdoors. During the database construction phase, the system also performs similar LSH hash operations on the feature vectors of historically captured facial images to obtain a historical keyword set, from which a ciphertext index is constructed. Because the same hash function and processing logic are used in both stages, facial images with similar structures in the feature space are guaranteed to maintain semantic consistency in their mapped keywords, providing a good foundation for subsequent fuzzy matching searches.

[0098] It's important to note that while the keyword generation processes for both are similar, their uses differ fundamentally. Keyword generation on the query side focuses more on real-time performance and fault tolerance, and can further introduce strategies such as feature perturbations and keyword variant expansion to improve matching capabilities in the presence of partial deviations. Keyword construction on the index side, on the other hand, emphasizes stability and uniqueness, ensuring that indexes corresponding to the same identity have high discrimination and low false positive rates. Therefore, in their implementation, while both share the LSH processing logic, their parameter configuration and processing strategies can be optimized based on the application scenario to balance overall system accuracy and efficiency.

[0099] In operation S430 , for each keyword in the target keyword set, multiple keyword variants are generated based on feature perturbation or semantic similarity.

[0100] Specifically, for each keyword in the target keyword set, several keyword variants can be generated based on feature perturbation strategies (such as small perturbations in the vector space) or semantic proximity (such as close Hamming distance between hash values). Keyword variants can cover areas in the feature space that are close to, but not identical to, the original keyword, helping to accurately match the target identity even with slight changes in facial pose, lighting, or image quality.

[0101] In operation S440 , a target secure hash operation is performed on the target keyword set and the plurality of keyword variants to generate a plurality of trapdoor tokens, and the plurality of trapdoor tokens are combined into the query trapdoor.

[0102] Specifically, for each keyword and its variant, a key-driven secure hash function is called to perform a one-way hash mapping, generating a set of irreversible hash values. These hash values ​​are trapdoor tokens, which represent the equivalent form of the original keyword information under cryptographic semantics.

[0103] According to the embodiments of the present disclosure, secure hashing not only effectively conceals user query intent and prevents direct server-side snooping of keyword content, but also ensures the system's collision and reconstruction resistance during the matching process. In actual deployment, the system can set a uniform output bit width for each trapdoor token, such as a fixed-length 32-bit or 64-bit truncated value, to compress the transmitted data size and maintain structural consistency.

[0104] Furthermore, all generated trapdoor tokens can be collected and organized into a holistic structure to form the final query trapdoor. The query trapdoor serves as the entry point for fuzzy search and will be compared with the ciphertext index in the database in the subsequent matching phase to achieve face identity retrieval and authentication in an encrypted environment.

[0105] In an embodiment of the present disclosure, the process of associating an encrypted index with corresponding user identity information and storing it in a face ciphertext database may include the following steps: performing Bloom filter encoding on the encrypted index to generate a Bloom filter bit vector; using the Bloom filter bit vector as the value field and the corresponding user identity information as the key field to form a key-value pair record; and storing the key-value pair record in the face ciphertext database.

[0106] Specifically, a Bloom filter encoding operation can be performed on each encrypted index, mapping multiple keyword index identifiers in the encrypted index into a Bloom filter bit vector. A Bloom filter bit vector is a sparse binary array in which each keyword index identifier is mapped to a number of Bloom filter bits using a set of preset hash functions, and the values ​​at these bit positions are set to 1. This method allows multiple keyword information to be compactly encoded into a bit vector structure of uniform length, reducing the storage space occupied by the index and achieving efficient matching capabilities.

[0107] Furthermore, the generated Bloom filter bit vector can be used as the value field of the database record, and the user identity information corresponding to the encrypted index (such as user ID, user tag or its hash identifier) ​​can be used as the key field to form a storage unit of the key-value pair structure.

[0108] According to an embodiment of the present disclosure, the key-value pair records can be written into a face encryption database. The face encryption database can adopt a lightweight key-value storage structure with high concurrent access capabilities, suitable for deployment in embedded terminals or edge devices.

[0109] It should be noted that the facial ciphertext database does not store any plaintext facial images or original feature data, thereby ensuring authentication efficiency while improving the overall data privacy security of the system.

[0110] In an embodiment of the present disclosure, the process of performing fuzzy matching search using a query trapdoor and an encrypted index stored in a face ciphertext database may include two stages: extraction of bit positions and bitwise comparison of Bloom filter vectors.

[0111] Specifically, the system receives a query trapdoor generated from the facial image to be authenticated, which contains multiple encrypted trapdoor tokens. Each trapdoor token is binary data generated from the target keyword or its variant using a target secure hash function. To achieve higher fault tolerance and matching accuracy, a "multi-trapdoor matching" strategy can be adopted to uniformly perform a bit extraction operation on all trapdoor tokens in the query trapdoor. This operation determines a set of bit positions corresponding to each trapdoor token based on preset rules (such as truncating the first n bits or selecting specific hash bits). These bit positions together constitute feature probes used to perform index comparison in the Bloom filter, thereby achieving efficient fuzzy matching authentication without exposing the original data.

[0112] Then, we can traverse each record stored in the face ciphertext database and perform a bitwise comparison on the Bloom bit vector corresponding to each record. We can check whether all bits in the Bloom bit vector identified by the query trapdoor are 1. According to the properties of the Bloom filter, if a record hits all the bits corresponding to the trapdoors (i.e., all the corresponding bits in the Bloom bit vector are 1), then the record can be determined to be a candidate for a successful preliminary match.

[0113] According to the embodiments of the present disclosure, fuzzy matching is highly efficient and fault-tolerant, quickly eliminating most irrelevant records while retaining a certain degree of similarity for subsequent sorting and refined identification. Because Bloom filters have a certain probability of false positives, the matching results generated at this stage constitute a preliminary candidate set, which will be further screened and evaluated in subsequent processing stages.

[0114] In an embodiment of the present disclosure, obtaining the final matching result based on the comparison result between the query trapdoor and the database encrypted index may include three stages: preliminary candidate extraction, similarity evaluation, and result sorting and selection.

[0115] Specifically, after completing a bitwise comparison between the query trapdoor and the Bloom bit vector corresponding to each encrypted index record, a set of records that meet the preliminary hit criteria can be identified. If a record has all or most of the bits corresponding to the trapdoor set to 1 (i.e., a hit), it is included in the preliminary candidate record set. For example, a parallel bitwise query mechanism using a Bloom filter can be employed to efficiently select facial records with similar features to the query from the database at a low computational cost.

[0116] Furthermore, each preliminary candidate record can be analyzed to quantify its match with the query. To do this, the system counts the actual number of hits between the record's Bloom bit vector and the corresponding bits of all trapdoor tokens in the query trapdoor. The more hits there are, the higher the degree of feature overlap between the record and the query face. Based on this, the system calculates a similarity score, which can be the absolute value of the number of hits, a hit ratio, or a weighted function. The specific implementation can be flexibly adjusted to adapt to different accuracy and efficiency requirements.

[0117] The final matching result is obtained by sorting all candidate records according to their similarity scores. Records with high scores are considered to be closer to the facial features of the person being authenticated and are more likely to correspond to the same user. The sorting results can be used to generate a top-K nearest match set or to set a threshold to filter records with a high enough match confidence level for subsequent face authentication. This similarity-based sorting mechanism effectively improves the accuracy and stability of the authentication system, balancing privacy protection and accurate recognition without revealing the original facial features.

[0118] According to the embodiments of the present disclosure, by converting facial feature vectors into a set of keywords, and combining local sensitive hashing, key-driven secure hashing algorithm and Bloom filter to build an encrypted index, a facial ciphertext retrieval mechanism that supports fuzzy matching is implemented. During the authentication process, the query request is encrypted as a query trapdoor, and only a bit-by-bit comparison is performed with the encrypted index, without restoring the original feature data, effectively protecting user privacy. The Bloom filter is used for preliminary screening, and then combined with similarity evaluation and Top-K sorting to ensure the accuracy and computational efficiency of the match. In addition, the embodiments of the present disclosure support dynamic adjustment of the matching range and result accuracy, which improves the flexibility of the authentication process and user experience, and takes into account security, performance and practicality as a whole, and is suitable for large-scale, privacy-sensitive identity recognition scenarios.

[0119] Corresponding to the above-mentioned face authentication method, an embodiment of the present disclosure further provides a face authentication device.

[0120] Figure 5 The structure block diagram of the face authentication device according to an embodiment of the present disclosure is schematically shown.

[0121] like Figure 5 As shown, the face authentication device 500 of this embodiment includes a data acquisition module 510 , an encryption processing module 520 , a fuzzy matching search module 530 and a face authentication module 540 .

[0122] The data acquisition module 510 may be used to acquire a facial feature vector of a face image to be authenticated. In one embodiment, the data acquisition module 510 may be used to perform the operation S210 described above, which will not be described in detail here.

[0123] The encryption processing module 520 can be used to generate a target keyword set based on the facial feature vector, encrypt the target keyword set, and obtain a query trapdoor. The facial ciphertext database is constructed by: obtaining historical facial feature vectors; generating a historical keyword set based on the historical facial feature vectors; constructing an encrypted index based on the historical keyword set; and associating the encrypted index with corresponding user identity information and storing it in the facial ciphertext database. In one embodiment, the encryption processing module 520 can be used to perform operation S220 described above, which will not be further described here.

[0124] The fuzzy matching search module 530 can be used to perform a fuzzy matching search using the query trapdoor and the encrypted index stored in the face ciphertext database to obtain a matching result. In one embodiment, the fuzzy matching search module 530 can be used to perform the operation S230 described above, which will not be repeated here.

[0125] The face recognition module 540 may be used to perform face recognition based on the matching result. In one embodiment, the face recognition module 540 may be used to perform the operation S240 described above, which will not be described in detail here.

[0126] According to an embodiment of the present disclosure, the data acquisition module 510 can also be used to use the target face recognition model to perform feature encoding on the face image to be authenticated to obtain a floating-point feature vector; and perform fixed-point quantization processing on the floating-point feature vector to obtain the face feature vector, wherein the fixed-point quantization processing includes mapping the floating-point feature vector to an integer representation of a preset bit width.

[0127] According to an embodiment of the present disclosure, the encryption processing module 520 can also be used to apply multiple local sensitive hash functions to the facial feature vector to generate multiple target hash values; generate the target keyword set based on the multiple target hash values; for each keyword in the target keyword set, generate multiple keyword variants based on feature perturbation or semantic similarity; and perform target secure hash operations on the target keyword set and multiple keyword variants to generate multiple trapdoor tokens, and combine the multiple trapdoor tokens to form the query trapdoor.

[0128] According to an embodiment of the present disclosure, the fuzzy matching search module 530 can also be used to determine the bit positions of multiple trapdoor tokens in the query trapdoor; and perform a bitwise comparison operation on the bit positions with the Bloom bit vector corresponding to each record in the face ciphertext database, and obtain the matching result based on the comparison result.

[0129] According to an embodiment of the present disclosure, the face recognition module 540 can also be used to obtain multiple preliminary candidate records based on the comparison results; for multiple preliminary candidate records, count the number of corresponding hit positions in the bitwise comparison operation, and calculate the similarity score based on the number of positions; and sort the multiple preliminary candidate records based on the similarity score, and obtain the matching result based on the sorting result.

[0130] According to an embodiment of the present disclosure, the face authentication device 500 may further include a face ciphertext database construction module. The face ciphertext database construction module may be configured to apply multiple locality-sensitive hash functions to the historical face feature vectors to generate multiple historical hash values; combine the multiple historical hash values ​​into a historical keyword set; perform a target secure hash operation on each keyword in the historical keyword set to obtain multiple secure hash results; and extract a preset bit interval from each secure hash result as the encryption index.

[0131] According to an embodiment of the present disclosure, the face ciphertext database construction module can also be used to perform Bloom filter encoding on the encrypted index to generate a Bloom filter bit vector; use the Bloom filter bit vector as the value field and the corresponding user identity information as the key field to form a key-value pair record; and store the key-value pair record in the face ciphertext database.

[0132] According to embodiments of the present disclosure, any multiple modules among the data acquisition module 510, encryption processing module 520, first face recognition module 530, and face recognition module 540 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present disclosure, at least one of the data acquisition module 510, encryption processing module 520, first face recognition module 530, and face recognition module 540 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of the three implementation methods, or any appropriate combination of any of these. Alternatively, at least one of the data acquisition module 510, the encryption processing module 520, the first face recognition module 530 and the face recognition module 540 can be at least partially implemented as a computer program module, which can perform corresponding functions when executed.

[0133] Figure 6The block diagram schematically shows an electronic device suitable for implementing the face authentication method according to an embodiment of the present disclosure.

[0134] like Figure 6 As shown, an electronic device 600 according to an embodiment of the present disclosure includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage portion 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 601 may also include onboard memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0135] Various programs and data required for the operation of the electronic device 600 are stored in the RAM 603. The processor 601, ROM 602, and RAM 603 are connected to each other via a bus 604. The processor 601 executes the various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 602 and / or RAM 603. It should be noted that the programs may also be stored in one or more memories other than the ROM 602 and RAM 603. The processor 601 may also execute the various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in the one or more memories.

[0136] According to an embodiment of the present disclosure, electronic device 600 may further include an input / output (I / O) interface 605, which is also connected to bus 604. Electronic device 600 may also include one or more of the following components connected to I / O interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 608 including a hard disk; and a communication section 609 including a network interface card such as a LAN card or modem. Communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to I / O interface 605 as needed. Removable media 611, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 610 as needed, so that computer programs read from the removable media can be installed into storage section 608 as needed.

[0137] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.

[0138] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 602 and / or RAM 603 described above, and / or one or more memories other than ROM 602 and RAM 603.

[0139] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to enable the computer system to implement the face recognition method provided by the embodiments of the present disclosure.

[0140] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the processor 601 executes the computer program. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0141] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 609, and / or installed from a removable medium 611. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0142] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from a removable medium 611. When the computer program is executed by the processor 601, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0143] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0144] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0145] Those skilled in the art will appreciate that the features described in the various embodiments of the present disclosure may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in the present disclosure. In particular, the features described in the various embodiments of the present disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of the present disclosure. All such combinations and / or couplings fall within the scope of the present disclosure.

[0146] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A face recognition method, characterized in that: The method comprises: Obtain the facial feature vector of the face image to be authenticated; generating a target keyword set based on the facial feature vector, and encrypting the target keyword set to obtain a query trapdoor; Performing a fuzzy matching search using the query trapdoor and the encrypted index stored in the face ciphertext database to obtain a matching result; and Perform face authentication based on the matching result, Among them, the face ciphertext database is constructed based on the following method: obtaining historical face feature vectors; generating a historical keyword set based on the historical face feature vectors, and constructing an encrypted index based on the historical keyword set; associating the encrypted index with the corresponding user identity information and storing it in the face ciphertext database.

2. The method according to claim 1, characterized in that The step of obtaining a facial feature vector of a face image to be authenticated includes: Using a target face recognition model to perform feature encoding on the face image to be authenticated to obtain a floating-point feature vector; and Performing fixed-point quantization processing on the floating-point feature vector to obtain the facial feature vector, wherein the fixed-point quantization processing includes mapping the floating-point feature vector into an integer representation with a preset bit width.

3. The method according to claim 1 or 2, characterized in that Generating a historical keyword set based on the historical facial feature vector and constructing an encrypted index based on the historical keyword set includes: Applying multiple locality-sensitive hash functions to the historical facial feature vectors to generate multiple historical hash values; Combining a plurality of historical hash values ​​into a historical keyword set, performing a target secure hash operation on each keyword in the historical keyword set to obtain a plurality of secure hash results; and A preset bit interval is intercepted from each secure hash result as the encryption index.

4. The method according to claim 1 or 2, characterized in that The step of generating a target keyword set based on the facial feature vector and encrypting the target keyword set to obtain a query trapdoor includes: Applying multiple locality-sensitive hash functions to the facial feature vector to generate multiple target hash values; generating the target keyword set based on a plurality of target hash values; For each keyword in the target keyword set, generating multiple keyword variants based on feature perturbation or semantic similarity; and A target secure hash operation is performed on the target keyword set and multiple keyword variants to generate multiple trapdoor tokens, and the multiple trapdoor tokens are combined into the query trapdoor.

5. The method according to claim 4, characterized in that The associating the encrypted index with the corresponding user identity information and storing the encrypted index in the face ciphertext database includes: Performing Bloom filter encoding on the encrypted index to generate a Bloom filter bit vector; Using the Bloom filter bit vector as the value field and the corresponding user identity information as the key field to form a key-value pair record; and The key-value pair records are stored in the face ciphertext database.

6. The method according to claim 4, characterized in that The method of performing a fuzzy matching search using the query trapdoor and the encrypted index stored in the face ciphertext database to obtain a matching result includes: determining bit positions of a plurality of trapdoor tokens in the query trapdoor; and A bitwise comparison operation is performed on the bit position and the Bloom bit vector corresponding to each record in the face ciphertext database, and the matching result is obtained based on the comparison result.

7. The method according to claim 6, characterized in that The obtaining of the matching result based on the comparison result includes: Acquire multiple preliminary candidate records based on the comparison results; For the plurality of preliminary candidate records, counting the number of corresponding hit positions in the bitwise alignment operation, and calculating a similarity score based on the number of positions; and The plurality of preliminary candidate records are sorted based on the similarity scores, and the matching result is obtained based on the sorting result.

8. A face recognition device, characterized in that: The device comprises: The data acquisition module is used to obtain the facial feature vector of the face image to be authenticated; An encryption processing module is configured to generate a target keyword set based on the facial feature vector, encrypt the target keyword set, and obtain a query trapdoor, wherein the facial ciphertext database is constructed by: obtaining historical facial feature vectors; generating a historical keyword set based on the historical facial feature vectors; constructing an encryption index based on the historical keyword set; associating the encryption index with corresponding user identity information and storing the result in the facial ciphertext database; A fuzzy matching search module is used to: perform a fuzzy matching search using the query trapdoor and the encrypted index stored in the face ciphertext database to obtain a matching result; and The face authentication module is used to perform face authentication based on the matching result.

9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

11. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.