A method and system for the handover of asset escort tasks based on identity verification

By employing collaborative identity verification technology that combines multimodal biometric fusion and secure multi-party computation, the problems of privacy leakage and insufficient security redundancy in the handover process of asset escort missions have been solved. This technology enables real-time and accurate identity verification and traceable handover evidence storage, forming a defense-in-depth system.

CN121352659BActive Publication Date: 2026-04-03ZHEJIANG ANBANG SECURITY TECH SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-19
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In the handover process of asset escort missions, existing technologies present privacy risks due to centralized biometric verification schemes that centrally store biometric templates, static credential verification schemes that are easily intercepted and reused, and insufficient security redundancy in complex environments.

Method used

Employing multimodal biometric fusion, secure multi-party computation, dynamic weight adjustment, and distributed evidence storage technologies, the system collects multimodal biometric data and dynamically encrypted credentials in real time through the handover terminal. It then generates dynamic decision weights by combining handover context data, performs collaborative identity verification using a secure multi-party computation protocol, and generates distributed evidence storage.

Benefits of technology

It enables real-time and accurate identity verification in dynamic handover environments, prevents biometric leakage and identity impersonation, provides a defense-in-depth system, enhances security redundancy, ensures the immutability and traceability of handover event data, and forms a secure automated business closed loop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121352659B_ABST
    Figure CN121352659B_ABST
Patent Text Reader

Abstract

This invention relates to the field of security technology, and in particular to a handover method for asset escort tasks based on identity verification. The method includes acquiring handover context data and behavioral state data of each role in the necessary role set; generating dynamic decision weights for each role based on the handover context data; and generating behavioral biometric confidence scores for each role based on the behavioral state data to obtain collaborative verification input data. In a secure multi-party computation network, a secure multi-party computation protocol is invoked to perform collaborative identity verification based on the initial identity verification benchmark, the on-site verification request, and the collaborative verification input data. This invention eliminates the privacy leakage risk of centralized storage by introducing a secure multi-party computation protocol, and constructs a dynamic decision-making mechanism and integrates behavioral biometric confidence scores, thereby forming a defense-in-depth system with higher security redundancy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security technology, and in particular to a method and system for the handover of asset escort tasks based on identity verification. Background Technology

[0002] In the handover phase of asset escort missions, existing technologies primarily employ two types of identity verification schemes to confirm personnel identity and the legitimacy of operations. One type is a centralized biometric verification scheme. This scheme centrally stores biometric templates (such as fingerprints and facial feature vectors) of the escort personnel and recipients on a central server. During the handover, on-site terminals collect the personnel's current biometric data, transmit it to the central server via an encrypted channel, and compare it with the pre-stored templates. If the comparison is successful, identity verification is complete. The other type is a static credential verification scheme. This scheme uses physical keys, fixed passwords, or static digital tokens as handover credentials. During the handover, personnel input credential information, and the terminal or server verifies the validity of the credential before allowing the handover operation. Some schemes also incorporate a simple timestamp mechanism to prevent long-term reuse of credentials.

[0003] The aforementioned existing technologies have the following problems in practical applications. For centralized biometric verification schemes, the centralized storage of biometric templates makes the server a single point of failure risk. Once the server is attacked or data is leaked, a large amount of sensitive biometric information will be leaked, and it is difficult to trace and remedy the leak afterward. At the same time, the verification logic of this scheme relies on the central node, and the two parties handing over the transaction need to establish a high degree of trust with the central node. In cross-institutional transportation, such as asset transfer between different banks, the trust cost is high and the verification efficiency is easily affected by network latency. As for static certificate verification schemes, the static attributes of the certificates make them easy to be intercepted, copied, or reused. Even with the combination of timestamps, it is difficult to cope with replay attacks in complex environments. In high-value asset transportation scenarios, the security redundancy is insufficient. Summary of the Invention

[0004] The main objective of this invention is to provide a method and system for the handover of asset escort tasks based on identity verification, aiming to solve the technical problems mentioned in the background art.

[0005] A handover method for an identity-based asset escort mission includes:

[0006] Obtain the escort mission instruction, parse the escort mission instruction to obtain the necessary role set, and obtain the multimodal biometric template set and encrypted identity public key based on the necessary role set to establish an initial identity verification benchmark;

[0007] Based on the escort mission instructions, the current biometric data and dynamic encryption credentials of each role in the necessary role set are collected in real time through the handover terminal, and an on-site verification request is generated based on the current biometric data and dynamic encryption credentials.

[0008] Acquire handover scenario data and behavioral state data of each role in the necessary role set; generate dynamic decision weights for each role based on the handover scenario data; and generate behavioral biometric confidence scores for each role based on the behavioral state data to obtain collaborative verification input data.

[0009] In a secure multi-party computation network, a secure multi-party computation protocol is invoked to perform collaborative identity verification based on the initial identity verification benchmark, the on-site verification request, and the collaborative verification input data, thereby generating an identity verification result.

[0010] Determine whether the identity verification result is passed. If it is passed, synchronously record the handover event data containing the task identifier and asset status. After encrypting and digitally signing the handover event data, generate a handover certificate.

[0011] The status of the escort mission is updated based on the handover and evidence storage, and the execution authority for the next step is triggered after the handover is completed.

[0012] Preferably, the steps of obtaining the escort mission instruction, parsing the escort mission instruction to obtain the associated necessary role set, and obtaining the pre-registered multimodal biometric template set and encrypted identity public key based on the necessary role set to establish an initial identity verification benchmark include:

[0013] Based on the necessary role set, the escort officer identifier and the receiver identifier are obtained. Based on the escort officer identifier and the receiver identifier, the corresponding pre-registered multimodal biometric template set and encrypted identity public key are obtained from the secure storage module. The biometric template set includes fingerprint feature vector and face feature vector.

[0014] By employing a feature-level fusion algorithm to calculate the fusion weights of fingerprint feature vectors and face feature vectors in the multimodal biometric template set, a multimodal biometric baseline template is generated.

[0015] The task context parameters are obtained according to the escort task instructions, and a one-time dynamic identity verification code for handover verification is generated according to the encrypted identity public key and the task context parameters.

[0016] The initial identity verification benchmark is established based on the multimodal biometric benchmark template and the one-time dynamic identity verification code.

[0017] Preferably, the step of collecting the current biometric data and dynamic encryption credentials of on-site personnel in real time through the handover terminal based on the escort mission instruction, and generating an on-site verification request based on the current biometric data and dynamic encryption credentials includes:

[0018] The fingerprint sensor and facial camera of the handover terminal simultaneously collect the current biometric data of the personnel on site, including fingerprint images and facial images.

[0019] The fingerprint image and facial image are preprocessed and feature extracted to obtain the current fingerprint feature vector and the current facial feature vector;

[0020] Obtain the current timestamp and the task number according to the escort task instruction. Digitally sign the current timestamp and the task number in the handover terminal to generate a dynamic encrypted certificate.

[0021] The current fingerprint feature vector, the current face feature vector, and the dynamic encryption credential are encapsulated to generate an on-site verification request.

[0022] Preferably, the steps of obtaining handover context data and behavioral state data of each role in the necessary role set, generating dynamic decision weights for each role based on the handover context data, and generating behavioral biometric confidence scores for each role based on the behavioral state data to obtain collaborative verification input data include:

[0023] Assign basic decision weights to each role in the set of necessary roles;

[0024] Obtain the deviation distance between the real-time geographical location of the handover terminal and the preset handover route, as well as the deviation duration between the handover time and the preset handover time window from the handover scenario data, and obtain the scenario risk coefficient based on the deviation distance and deviation duration;

[0025] The basic decision weight of each role is dynamically adjusted according to the situational risk coefficient to obtain its dynamic decision weight. The higher the situational risk coefficient, the greater the increase in the dynamic decision weight of the core role in the necessary role set is compared with that of the non-core role.

[0026] The handholding posture data and movement trajectory data of the handover terminal are obtained from the behavior state data. The handholding posture data and movement trajectory data are preprocessed and feature extracted to obtain a behavior feature sequence.

[0027] The behavioral feature sequence is compared in real time with the pre-registered behavioral biometric template corresponding to the current role to generate behavioral biometric confidence.

[0028] The collaborative verification input data is obtained based on the dynamic decision weights and the confidence levels of the behavioral biometrics.

[0029] Preferably, the step of invoking a secure multi-party computation protocol to perform collaborative identity verification based on the initial authentication benchmark, the on-site verification request, and the collaborative verification input data in a secure multi-party computation network, and generating an identity verification result, includes:

[0030] Based on a secure multi-party computation protocol, the similarity score between the current biometric data in the on-site verification request and the multimodal biometric benchmark template in the initial identity verification benchmark is calculated, and the validity of the dynamic encrypted credential in the on-site verification request is verified.

[0031] The similarity score is compared with a preset individual verification threshold under encrypted conditions to generate a preliminary verification result;

[0032] Based on the preliminary verification results, the dynamic decision weights and behavioral biometric confidence levels in the collaborative verification input data, the encryption contribution value is calculated using a weighted decision algorithm, and the global collaborative decision score is calculated based on the encryption contribution values ​​of all roles in the necessary role set.

[0033] The global collaborative decision score is compared with a preset collaborative decision threshold, and the identity verification result is obtained based on the comparison result.

[0034] Preferably, the step of determining whether the identity verification result is passed, and if passed, synchronously recording handover event data containing task identifier and asset status, and generating handover evidence after encrypting and digitally signing the handover event data, includes:

[0035] The system acquires real-time asset status images during the handover process and calculates their first hash value. It also assembles a structured event data packet by acquiring the handover timestamp, geographic location information, role identifiers of both parties, and task number.

[0036] Calculate the second hash value of the structured event data packet, and combine the first hash value and the second hash value to generate a global data fingerprint;

[0037] The global data fingerprint is digitally signed using the private key of the handover terminal to generate digital signature data;

[0038] The digital signature data, the global data fingerprint, and the structured event data packet are combined and encrypted using the public key of the central scheduling server to generate an encrypted data packet.

[0039] The encrypted data packets are sent to the central dispatch server and all handover terminals for distributed storage, and a unique certificate number is assigned to each of them to generate handover certificates.

[0040] This invention also discloses a handover system for asset escort tasks based on identity verification, comprising:

[0041] An initialization module is used to obtain escort mission instructions, obtain a necessary set of roles by parsing the escort mission instructions, and obtain a multimodal biometric template set and an encrypted identity public key based on the necessary set of roles to establish an initial identity verification benchmark.

[0042] The verification preparation module is used to collect the current biometric data and dynamic encryption credentials of each role in the necessary role set in real time through the handover terminal based on the escort mission instruction, and generate an on-site verification request based on the current biometric data and dynamic encryption credentials.

[0043] The collaborative preparation module is used to acquire handover scenario data and behavioral status data of each role in the necessary role set, generate dynamic decision weights for each role based on the handover scenario data, and generate behavioral biometric confidence scores for each role based on the behavioral status data, so as to obtain collaborative verification input data.

[0044] The multi-party verification module is used to call the secure multi-party computing protocol to perform collaborative identity verification in a secure multi-party computing network based on the initial identity verification benchmark, the on-site verification request and the collaborative verification input data, and generate an identity verification result.

[0045] The evidence generation module is used to determine whether the identity verification result is passed. If it is passed, it synchronously records the handover event data containing the task identifier and asset status. After encrypting and digitally signing the handover event data, it generates handover evidence.

[0046] The status management module is used to update the status of the escort mission based on the handover and evidence storage, and to trigger the execution permission of the next step after the handover is completed.

[0047] The collaborative preparation module includes:

[0048] A weight allocation unit is used to assign basic decision weights to each role in the necessary role set.

[0049] The scenario risk calculation unit is used to obtain the deviation distance between the real-time geographical location of the handover terminal and the preset handover route, as well as the deviation duration between the handover time and the preset handover time window in the handover scenario data, and to obtain the scenario risk coefficient based on the deviation distance and the deviation duration.

[0050] The dynamic weight generation unit is used to dynamically adjust the basic decision weight of each role according to the situation risk coefficient to obtain its dynamic decision weight. The higher the situation risk coefficient, the greater the increase in the dynamic decision weight of the core role in the necessary role set is than that of the non-core role.

[0051] The behavior feature extraction unit is used to acquire the holding posture data and movement trajectory data of the handover terminal in the behavior state data, and to preprocess and extract features from the holding posture data and movement trajectory data to obtain a behavior feature sequence.

[0052] The confidence generation unit is used to compare the behavioral feature sequence with the pre-registered behavioral biometric template corresponding to the current role in real time to generate behavioral biometric confidence.

[0053] The verification data acquisition unit is used to acquire collaborative verification input data based on the dynamic decision weights and the confidence level of the behavioral biometrics.

[0054] The present invention also discloses a computer device, including a memory and a processor, wherein the memory stores a computer program, characterized in that the processor executes the computer program to implement the steps of a handover method for an identity-based asset escort task.

[0055] The present invention also discloses a computer-readable storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the steps of a handover method for an identity-based asset escort task.

[0056] The beneficial effects of this invention are as follows: By introducing a secure multi-party computation protocol, this invention eliminates the risk of privacy leakage from centralized storage and constructs a dynamic decision-making mechanism. It obtains the deviation distance and duration of the handover point through the terminal positioning and timing module, calculates the situational risk coefficient, and dynamically adjusts the decision weights of different roles. Core roles receive a greater increase in weight under high-risk situations, enabling the verification logic to adapt to on-site risks and avoiding the rigidity of static verification. Furthermore, it integrates behavioral biometric confidence scores. The terminal inertial measurement unit continuously collects personnel holding posture and movement trajectory data, compares it with pre-registered behavioral templates to generate confidence scores, serving as an important dimension of verification input. This prevents the risk of terminal hijacking after identity verification, thus forming a defense-in-depth system with higher security redundancy. Attached Figure Description

[0057] Figure 1 This is a schematic diagram of a method flow according to an embodiment of this application.

[0058] Figure 2 This is a schematic diagram of the system structure according to an embodiment of this application.

[0059] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0060] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0061] like Figure 1 As shown, this application provides a handover method for asset escort tasks based on identity verification, including:

[0062] S1, obtain the escort mission instruction, obtain the necessary role set by parsing the escort mission instruction, and obtain the multimodal biometric template set and encrypted identity public key according to the necessary role set to establish an initial identity verification benchmark;

[0063] S2, based on the escort mission instruction, the current biometric data and dynamic encryption credentials of each role in the necessary role set are collected in real time through the handover terminal, and an on-site verification request is generated according to the current biometric data and dynamic encryption credentials;

[0064] S3, acquire handover scenario data and behavioral state data of each role in the necessary role set, generate dynamic decision weights for each role based on the handover scenario data, and generate behavioral biometric confidence scores for each role based on the behavioral state data, so as to obtain collaborative verification input data;

[0065] S4, In the secure multi-party computation network, based on the initial identity verification benchmark, the on-site verification request and the collaborative verification input data, the secure multi-party computation protocol is invoked to perform collaborative identity verification and generate an identity verification result;

[0066] S5, determine whether the identity verification result is passed. If passed, synchronously record the handover event data containing the task identifier and asset status. After encrypting and digitally signing the handover event data, generate a handover certificate.

[0067] S6, update the status of the escort mission according to the handover and storage certificate, and trigger the execution permission of the next step after the handover is completed.

[0068] As described in steps S1-S6 above, in asset escort scenarios, the handover process is a key node in asset transfer and is directly related to asset security. It is necessary to ensure that the identities of the personnel involved in the handover are legal and the operation process is compliant, while preventing security risks caused by biometric leakage, identity theft, and abnormal situations. Furthermore, escort missions are characterized by high mobility and complex environments. Therefore, this invention achieves the security, dynamic adaptability, and traceability of identity verification in the asset escort handover process through a solution that verifies information from multiple dimensions and adapts to dynamic environments.

[0069] Existing technologies mostly employ centralized identity verification models, which pose privacy risks due to centralized storage of biometric data. Furthermore, verification strategies are often static, based on pre-stored data, failing to adapt to dynamic situations during the handover process. This makes it difficult to prevent subsequent risks such as terminal hijacking after successful identity verification. This invention addresses these issues through the synergistic application of multimodal biometric fusion, secure multi-party computation, dynamic weight adjustment, and distributed evidence storage technologies. First, it obtains the escort mission instruction. By parsing the instruction, it acquires a necessary set of roles. Based on this set, it obtains a multimodal biometric template set and an encrypted identity public key to establish an initial identity verification benchmark. This avoids verification deviations caused by ambiguous benchmarks or disconnection from the mission. The one-time dynamic identity verification code effectively prevents repeated verification risks after the benchmark template is stolen. Then, based on the escort mission instruction, the handover terminal collects the current biometric data and dynamic encrypted credentials of each role in the necessary set in real time. Finally, it generates a current identity verification code based on the current biometric data and dynamic encrypted credentials. The system first obtains on-site verification requests to ensure the real-time nature and uniqueness of identity verification. The timestamp feature of the dynamic encrypted credentials effectively resists replay attacks and avoids the risk of reusing pre-made credentials. Then, it acquires handover scenario data and behavioral status data of each role in the necessary role set. Based on the handover scenario data, it generates dynamic decision weights for each role and behavioral biometric confidence scores for each role based on the behavioral status data, thus obtaining collaborative verification input data. This allows the handover scenario and personnel behavioral status to be incorporated into the verification system. Dynamic weight adjustments match security strategies with scenario risks, and behavioral biometric monitoring extends verification from single-point verification to process verification, effectively preventing subsequent security risks after successful identity verification. Next, in a secure multi-party computation network, based on the initial identity verification benchmark, the on-site verification request, and the collaborative verification input data, a secure multi-party computation protocol is invoked to perform collaborative identity verification, generating identity verification results. This avoids centralized transmission and storage of biometric data, protecting privacy, while the fusion calculation of multi-dimensional parameters ensures the accuracy and reliability of the verification results.Next, it is determined whether the identity verification result is successful. If successful, the handover event data containing the task identifier and asset status is recorded synchronously. After encrypting and digitally signing the handover event data, a handover certificate is generated. Cryptographic technology and distributed storage ensure the immutability and traceability of the handover event data, providing more effective electronic evidence for tracing potential disputes. Finally, the status of the escort mission is updated according to the handover certificate, and the execution authority of the next step is triggered after the handover is completed. The central dispatch server receives the handover certificate, parses the structured event data packet, extracts the task number, and updates the status of the escort mission from "..." The handover process is updated from "in progress" to "handover complete," and the update result is synchronized to all associated terminals and monitoring platforms. Based on the preset workflow of the escort mission, permission instructions are sent to the next execution system. For example, an entry permission instruction containing the entry location number and encrypted operation password is sent to the warehouse management system, or a task archiving instruction is sent to the central dispatch system. After the permission is triggered, the handover terminal automatically clears the temporary data for this task, ensuring no data remains. This achieves seamless connection between the handover process and subsequent logistics links. By binding the identity verification result with the business process execution permission, a secure automated business closed loop is formed, avoiding the risks and efficiency bottlenecks caused by human intervention.

[0070] In one embodiment of the present invention, the steps of obtaining the escort mission instruction, obtaining the associated necessary role set by parsing the escort mission instruction, and obtaining the pre-registered multimodal biometric template set and encrypted identity public key based on the necessary role set to establish an initial identity verification benchmark include:

[0071] S11, obtain the escort officer identifier and the receiver identifier according to the necessary role set, and obtain the corresponding pre-registered multimodal biometric template set and encrypted identity public key from the secure storage module according to the escort officer identifier and the receiver identifier, wherein the biometric template set includes fingerprint feature vector and face feature vector;

[0072] S12, by employing a feature-level fusion algorithm to calculate the fusion weights of the fingerprint feature vector and the face feature vector in the multimodal biometric template set, a multimodal biometric baseline template is generated;

[0073] S13, Obtain task context parameters according to the escort task instruction, and generate a one-time dynamic identity verification code for handover verification according to the encrypted identity public key and the task context parameters;

[0074] S14, establish the initial identity verification benchmark based on the multimodal biometric benchmark template and the one-time dynamic identity verification code.

[0075] As described in steps S11-S14 above, since the initial identity verification benchmark is the standard answer for the entire identity verification process, its accuracy, uniqueness, and timeliness directly determine the reliability of subsequent verification results. However, the escort task has role division, such as the escort being responsible for handover and the recipient being responsible for receiving. Different roles require different identity verification standards. Therefore, this invention first determines the exclusive role based on the task, then retrieves the multimodal biometric template and encryption key corresponding to the role, generates an optimized benchmark template through a fusion algorithm, and finally generates a one-time verification code in combination with the task parameters, forming a dynamic benchmark that is deeply bound to both the task and the role, preventing the risk of benchmark information being reused in other tasks.

[0076] Specifically, based on the necessary role set, the escort officer identifier and the recipient identifier are obtained. Then, based on these identifiers, the corresponding pre-registered multimodal biometric template set and encrypted identity public key are retrieved from the secure storage module. The biometric template set includes fingerprint and facial feature vectors. The escort task instruction includes a task number and a preset handover point. By parsing the task number in the instruction, the necessary role set bound to this task is retrieved from the task database of the central dispatch server, and the escort officer identifier and recipient identifier are extracted. These identifiers distinguish different role identities. Using these identifiers as indexes, the secure storage module is accessed through an encrypted transmission channel based on the SM4 algorithm to retrieve the corresponding pre-registered multimodal biometric template set and encrypted identity public key. The biometric template set explicitly includes fingerprint and facial feature vectors, and the fingerprint feature vector conforms to ISO / IEC standards. The 19794-2 standard extracts 1024-dimensional minutiae point features, including the coordinates and orientation angles of endpoints and bifurcation points. The facial feature vector is extracted using the MTCNN+ArcFace algorithm to extract 512-dimensional depth features, including the location and texture information of key facial organs. The encrypted identity public key is generated based on the SM2 asymmetric encryption algorithm, with each role corresponding to a unique public key. The private key is kept by the role's own person through a hardware key device.

[0077] Then, a feature-level fusion algorithm is used to calculate the fusion weights of the fingerprint feature vector and the face feature vector in the multimodal biometric template set, generating a multimodal biometric baseline template. The feature-level fusion algorithm assigns fusion weights based on the confidence levels of the two biometric features. First, the confidence levels of the fingerprint feature vector and the face feature vector are calculated separately. The fingerprint feature confidence level is determined based on the acquisition quality during pre-registration; for example, the fingerprint image clarity must be ≥80 points and the number of effective minutiae points must be ≥30. If these conditions are met, the confidence level is between 0.8 and 1.0; otherwise, it is reduced accordingly. The face feature confidence level is determined with reference to the lighting conditions during pre-registration. Conditions (500-1000 lux is preferred) and pose angle (frontal pose deviation ≤15°) are met. When these conditions are met, the confidence level is between 0.8 and 1.0. Then, a weighted average method is used to calculate the fusion weight. Next, the fingerprint feature vector and the face feature vector are concatenated dimensionally to obtain the initial fusion vector. Then, the initial fusion vector is adjusted by weighting the fusion weight to finally generate a multimodal biometric baseline template. The matching threshold of the multimodal biometric baseline template is set according to the cosine similarity threshold. Through algorithm optimization, multi-feature collaboration is achieved, so that the fused multimodal biometric baseline template can effectively resist the risk of single feature forgery.

[0078] Next, task context parameters are obtained according to the escort task instruction. A one-time dynamic identity verification code for handover verification is generated based on the encrypted identity public key and the task context parameters. The task context parameters include the task number, the start timestamp of the preset handover time window, and the latitude and longitude of the preset handover location. The task context parameters ensure that the verification code is bound to this task. Then, the task context parameters are concatenated in the format of "task number-timestamp-latitude and longitude" and Base64 encoded to generate a 32-bit parameter encoding string. The parameter encoding string is then asymmetrically encrypted using the encrypted identity public key to generate a 64-bit one-time dynamic identity verification code. This verification code is only valid within the preset handover time window of this task. Even if it is obtained after the expiration, it cannot be used for verification.

[0079] Finally, the initial identity verification benchmark is established based on the multimodal biometric benchmark template and the one-time dynamic identity verification code. The initial identity verification benchmark is stored in JSON format and includes fields such as task number, role type, role identifier, biometric benchmark template, dynamic verification code, and effective time window. The integrated initial identity verification benchmark will be synchronized to the node devices of the handover terminal and the secure multi-party computing network through a secure transmission protocol, providing a unified comparison standard for collaborative identity verification and providing more accurate and secure benchmark support.

[0080] In one embodiment of the present invention, the step of collecting the current biometric data and dynamic encryption credentials of on-site personnel in real time through a handover terminal based on the escort mission instruction, and generating an on-site verification request based on the current biometric data and dynamic encryption credentials includes:

[0081] S21, the fingerprint sensor and face camera of the handover terminal are used to simultaneously collect the current biometric data of the personnel on site, including fingerprint images and facial images;

[0082] S22, preprocess and extract features from the fingerprint image and facial image to obtain the current fingerprint feature vector and the current facial feature vector;

[0083] S23, obtain the current timestamp and the task number according to the escort task instruction, and digitally sign the current timestamp and the task number in the handover terminal to generate a dynamic encrypted certificate;

[0084] S24, the current fingerprint feature vector, the current face feature vector, and the dynamic encryption credential are encapsulated to generate an on-site verification request.

[0085] As described in steps S21-S24 above, since the handover process takes place in a mobile environment that may be subject to complex interference, the authenticity of the participants' identities needs to be confirmed through real-time data collection. Traditional methods that rely on static credentials or post-event data entry are insufficient to address risks such as on-site identity theft and data tampering. Furthermore, the handover process requires high efficiency and security, and the on-site data collection must be real-time, complete, and tamper-proof. It must be able to quickly compare with pre-registered baseline data while preventing data leakage or forgery during the collection process. Therefore, this invention achieves standardized generation of on-site verification requests by real-time collection of on-site biometrics, preprocessing to extract feature vectors, generating dynamic encrypted credentials, and encapsulating data to generate requests. This ensures that the request data accurately matches the initial identity verification baseline while preventing data tampering and identity theft. Through a security control scheme from collection to encapsulation, it ensures that the verification requests generated on-site accurately reflect the true identity status of the participants.

[0086] Specifically, the handover terminal uses a PAD or smartphone that meets industrial-grade security standards, with a built-in fingerprint sensor and face camera. The fingerprint sensor adopts a capacitive design with a resolution of no less than 500 DPI and a collection area of ​​no less than 16mm×16mm. The face camera is an RGB camera with more than 2 million pixels and has autofocus and light compensation functions. After the handover is triggered (either by personnel actively operating the terminal or by the terminal detecting a geofence), the terminal controls the fingerprint sensor and face camera to simultaneously start collecting data. Then, a standardized preprocessing algorithm is used to eliminate environmental interference. Fixed-dimensional feature vector extraction ensures that the biometric features collected on-site match the multimodal biometric reference template in the initial identity verification benchmark. The current timestamp is obtained, and the task number is acquired according to the escort mission instructions. The current timestamp and the task number are digitally signed within the handover terminal to generate a dynamic encrypted credential. Because the timestamp is unique and the task number is bound to the current escort mission, this dynamic encrypted credential is only valid within the current time and mission scope. If an attacker intercepts the credential, it cannot be reused in other scenarios due to an expired timestamp or a mismatched task number. Therefore, by combining hardware security with cryptographic algorithms, the credential is given dynamism and uniqueness, avoiding the easy reuse of traditional static credentials. The problem is that the current fingerprint feature vector, the current face feature vector, and the dynamic encryption credential are finally encapsulated to generate an on-site verification request. The data encapsulation uses the Protobuf binary protocol. During encapsulation, a structured data field is defined, containing "request identifier, role identifier, biometric data, dynamic encryption credential, and collection timestamp." The request identifier is a randomly generated 32-bit UUID used to uniquely identify this verification request. The role identifier is the security guard identifier or recipient identifier corresponding to the on-site personnel. The biometric data field stores the current fingerprint and face feature vectors. The dynamic encryption credential field stores 64-bit signature data. The collection timestamp field stores the timestamp. After filling each field according to the above definitions, the data is compiled into a binary data stream using a Protobuf compiler to generate the on-site verification request. This on-site verification request ensures that both devices can read the data normally, improving the compatibility and efficiency of the verification process.

[0087] In one embodiment of the present invention, the steps of obtaining handover scenario data and behavioral state data of each role in the necessary role set, generating dynamic decision weights for each role based on the handover scenario data, and generating behavioral biometric confidence scores for each role based on the behavioral state data to obtain collaborative verification input data include:

[0088] S31, assign basic decision weights to each role in the set of necessary roles;

[0089] S32, obtain the deviation distance between the real-time geographical location of the handover terminal and the preset handover route, and the deviation duration between the handover time and the preset handover time window in the handover scenario data, and obtain the scenario risk coefficient based on the deviation distance and the deviation duration;

[0090] S33, dynamically adjust the basic decision weight of each role according to the situational risk coefficient to obtain its dynamic decision weight, wherein the higher the situational risk coefficient, the greater the increase in the dynamic decision weight of the core role in the necessary role set is than that of the non-core role.

[0091] S34, acquire the holding posture data and movement trajectory data of the handover terminal in the behavior state data, preprocess and extract features from the holding posture data and movement trajectory data to obtain a behavior feature sequence;

[0092] S35, compare the behavioral feature sequence with the pre-registered behavioral biometric template corresponding to the current role in real time to generate behavioral biometric confidence.

[0093] S36, obtain collaborative verification input data based on the dynamic decision weights and the confidence level of the behavioral biometrics.

[0094] As described in steps S31-S36 above, since the handover process is not in an ideal fixed environment, there may be changes in the situation such as the handover point deviating from the preset route or the handover time exceeding the planned window. At the same time, the personnel's operation behavior during the handover process (such as the posture of holding the terminal and the movement trajectory) may also contain hidden abnormal identity signals (such as changes in operation behavior after the terminal is hijacked by others). If only biometrics and static credentials are used for verification, these dynamic risks cannot be perceived, which may lead to a disconnect between the identity verification results and the actual security status. For example, in high-risk situations that deviate from the preset location, verification according to the conventional standards may easily cause security risks. Or, after the initial identity verification is passed, abnormal personnel operation behavior may go unnoticed, making it difficult to prevent subsequent risks. Existing technologies mainly focus on the verification of identity credentials, ignoring the problems of situation and behavioral factors. They cannot dynamically adjust the verification influence of each role according to the handover risk, making it difficult to cope with complex and ever-changing on-site risks. Therefore, this invention constructs a collaborative verification input system that takes into account both the handover situation and the personnel's behavioral status, so that the verification process can adapt to dynamic risk scenarios and identify abnormal personnel behavior, thereby better matching the actual situation on site and improving the comprehensiveness and accuracy of identity verification.

[0095] Specifically, a basic decision-making weight is first assigned to each role in the necessary role set. The allocation of the basic decision-making weight is determined in conjunction with the importance of the role responsibilities in the asset escort task. The necessary role set includes the escort (core role, responsible for asset transfer), the recipient (core role, responsible for asset receipt), and the third-party supervisor (non-core role). Based on the responsibility weight of each role in the handover, the basic decision-making weights are preset as follows: escort 0.5, recipient 0.3, supervisor 0.2, and the total weight of the core roles is not less than 0.8. This ensures that the core roles play a leading role in the verification decision-making process. By clarifying the verification importance of different roles in normal situations, the verification opinions of the core roles are not weakened due to unreasonable weight allocation.

[0096] Then, the deviation distance between the real-time geographical location of the handover terminal and the preset handover route, as well as the deviation duration between the handover time and the preset handover time window, are obtained from the handover scenario data. The scenario risk coefficient is obtained based on the deviation distance and deviation duration. The handover scenario data is obtained through the positioning and timing module of the handover terminal. The real-time geographical location is collected through the Beidou positioning module built into the terminal. The preset handover route is extracted from the escort mission instruction (including route planning with multiple coordinate points or a specific geofence range). The straight-line distance (i.e., deviation distance) between the real-time geographical location and the preset route is calculated using the Haversine formula. The handover time is obtained from the terminal system clock. The preset handover time window is also obtained from the escort mission instruction. The difference between the current time and the time window (i.e., deviation duration; if it is within the time window, the deviation duration is 0) is calculated. The scenario risk coefficient is calculated using a weighted summation model, with both the geographical location risk sub-coefficient and the time risk sub-coefficient having a weight of 0.5. The geographical location risk sub-coefficient is divided according to the deviation distance: 0.1 when the deviation distance is ≤10 meters, 0.5 when the deviation distance is 10 meters < deviation distance ≤50 meters, and 0.9 when the deviation distance is >50 meters. The time risk sub-coefficient is divided according to the deviation duration: 0.1 when the deviation duration is 0, 0.5 when the deviation duration is 0 < deviation duration ≤10 minutes, and 0.9 when the deviation duration is >10 minutes. By quantifying the risk level of the current handover scenario, verification bias caused by subjective judgment of scenario risk is avoided.

[0097] Then, based on the situational risk coefficient, the basic decision weight of each role is dynamically adjusted to obtain its dynamic decision weight. The higher the situational risk coefficient, the greater the increase in the dynamic decision weight of the core roles in the necessary role set compared to non-core roles. The dynamic weight adjustment follows the principle that the higher the risk, the more prominent the weight of the core roles. The adjustment rules are preset in the algorithm module of the handover terminal: when the situational risk coefficient ≤ 0.3 (low risk), the weights of core and non-core roles remain unchanged; when 0.3 < situational risk coefficient ≤ 0.6 (medium risk), the weight of the core role... The weight of core roles is increased by 20%, while the weight of non-core roles is decreased by 10%. When the situational risk coefficient is greater than 0.6 (high risk), the weight of core roles is increased by 50%, and the weight of non-core roles is decreased by 50%. After the adjustment, the weight of all roles is normalized to 1 (i.e., the weight of each role after adjustment is divided by the sum of the weights of all roles after adjustment). By linking the verification influence of each role with the situational risk, the dynamic decision-making weight of core roles is increased in high-risk scenarios, and their verification opinions account for a higher proportion in subsequent collaborative decision-making. This directly enhances the reliability of verification results in high-risk scenarios and avoids insufficient risk response due to fixed weights.

[0098] Next, the handholding posture data and movement trajectory data of the handover terminal are acquired from the behavioral state data. These data are then preprocessed and feature extracted to obtain a behavioral feature sequence. The behavioral state data is collected by the inertial measurement unit (IMU) of the handover terminal, which includes a three-axis accelerometer and a three-axis gyroscope. Handholding posture data and movement trajectory data are continuously collected from the time the handover is triggered until the identity verification result is generated. During the data preprocessing stage, a 10-point sliding window filter is used to eliminate high-frequency noise in the handholding posture data, and the acceleration within a 5-second acquisition cycle is calculated. The mean, variance, and gyroscope mean and variance (a total of 8 feature values) are calculated. The displacement distance (the sum of the distances between adjacent points) and the trajectory direction change angle (the sum of the angles between the lines connecting adjacent points) of 5 location points are calculated for the movement trajectory data, resulting in 2 feature values. These two types of feature values ​​are combined to form a 10-dimensional behavioral feature sequence. For example, when a person is holding the terminal normally during the handover, the acceleration variance is small (stable holding), and the trajectory direction change angle is close to 0 (handover at a fixed position). If the terminal is snatched by someone else, the acceleration variance will increase sharply, and the trajectory direction change angle will also fluctuate abnormally. These changes will be reflected in the behavioral feature sequence.

[0099] Next, the behavioral feature sequence is compared in real time with the pre-registered behavioral biometric template of the corresponding current role to generate behavioral biometric confidence. The pre-registered behavioral biometric template is retrieved from a secure storage module. During the pre-registration phase, each role collects multiple sets of standard behavioral data (such as typical behaviors like holding a terminal normally and completing handover operations). The behavioral biometric template is then clustered using the K-means clustering algorithm. The calculation of the behavioral biometric confidence uses an Euclidean distance similarity model. First, the Euclidean distance between the behavioral feature sequence and the pre-registered template is calculated, and then the distance is converted to 0- through confidence calculation. The confidence value in interval 1 indicates that if the confidence level is ≥0.7, the behavior is considered to be highly consistent. If the confidence level is <0.7, the behavior is considered to be abnormal, highlighting the impact of the abnormal behavior. For example, if the Euclidean distance between a receiver's behavioral feature sequence and the template is 0.3, the corresponding confidence level is 1 / (1+0.3)≈0.77 (normal range). If the Euclidean distance increases to 1.5 due to terminal hijacking, the confidence level becomes 1 / (1+1.5)=0.4, which is adjusted to 0.2. This low confidence level can effectively reflect abnormal behavior, provide risk warnings at the behavioral level, and make up for the blind spots of traditional verification that only rely on biometrics.

[0100] Finally, collaborative verification input data is obtained based on the dynamic decision weights and the behavioral biometric confidence levels. The collaborative verification input data is based on roles, and the data format includes role identifiers, dynamic decision weights, behavioral biometric confidence levels, and corresponding situational risk coefficients. The integrated collaborative verification input data is synchronized to a secure multi-party computation network and participates in subsequent verification along with the initial identity verification benchmark and on-site verification request. This step transforms situational risk and behavioral status into quantifiable verification parameters, enabling the collaborative verification process to not only verify identity authenticity but also to comprehensively judge on-site risk and behavioral consistency, thereby improving the comprehensiveness and accuracy of the verification results.

[0101] In one embodiment of the present invention, the step of invoking a secure multi-party computation protocol to perform collaborative identity verification based on the initial authentication benchmark, the on-site verification request, and the collaborative verification input data in a secure multi-party computation network, and generating an identity verification result, includes:

[0102] S41, based on a secure multi-party computation protocol, calculate the similarity score between the current biometric data in the on-site verification request and the multimodal biometric benchmark template in the initial identity verification benchmark, and verify the validity of the dynamic encrypted credential in the on-site verification request;

[0103] S42, compare the similarity score with a preset individual verification threshold in an encrypted state to generate a preliminary verification result;

[0104] S43, based on the preliminary verification results, the dynamic decision weights and behavioral biometric confidence in the collaborative verification input data, calculate the encryption contribution value using a weighted decision algorithm, and calculate the global collaborative decision score based on the encryption contribution values ​​of all roles in the necessary role set;

[0105] S44, compare the global collaborative decision score with the preset collaborative decision threshold, and obtain the identity verification result based on the comparison result.

[0106] As described in steps S41-S44 above, since identity verification is the core line of defense, and the multiple parties involved in the handover (such as the escort, the receiver, and the dispatcher) may belong to different institutions and there are trust boundaries between them, direct transmission or centralized storage of sensitive data such as biometrics can easily lead to privacy leakage risks. At the same time, the handover process is affected by multiple factors. Existing technical solutions adopt a centralized verification model, which requires data from all parties to be centralized on the same platform, increasing the risk of data leakage. Moreover, the verification is mainly carried out from the identity dimension, resulting in one-sided verification results and difficulty in dealing with complex security scenarios. Therefore, this invention completes the collaborative calculation of multi-dimensional parameters in an encrypted state through a secure multi-party computation protocol, which not only protects data privacy but also realizes multi-factor comprehensive verification, thus making it more secure.

[0107] First, based on the secure multi-party computation protocol, the similarity score between the current biometric data in the on-site verification request and the multimodal biometric benchmark template in the initial identity verification benchmark is calculated, and the validity of the dynamic encrypted credential in the on-site verification request is verified. The participating nodes in the secure multi-party computation network include the terminals of both parties, the central scheduling server node, and the monitoring node. Each node is equipped with the secure multi-party computation protocol, supporting numerical calculation and verification operations in encrypted mode. First, the similarity score between the current biometric data and the multimodal biometric benchmark template is calculated. The current biometric data includes the current fingerprint feature vector and the current face feature vector. The multimodal biometric benchmark template comes from the initial identity verification benchmark. The calculation process uses a cosine similarity algorithm. Under the secure multi-party computation protocol, each node only inputs its locally held data secret share (e.g., the server node inputs the benchmark template). The process involves several steps. First, a secret share (the secret share of the current biometric data input by the terminal node) is used. Through secret sharing technology, the vector dot product and magnitude are collaboratively calculated to obtain a similarity score in the encrypted state. This score ranges from 0 to 1, with a higher score indicating a better feature match. Second, the validity of the dynamic encrypted credential is verified. The dynamic encrypted credential originates from an on-site verification request. During the verification process, the terminal node sends the digital signature corresponding to the credential to the server node. The server node uses a pre-stored public key of the handover terminal (associated with terminal information from the encrypted identity public key) to decrypt the signature, extract the timestamp and task number, and compare them with the current timestamp and task number. If the timestamp is within the preset validity period and the task number matches, the credential is deemed valid. This process completes the calculation of basic parameters for identity verification and the determination of credential validity while protecting data privacy, avoiding the risk of leakage caused by the plaintext transmission of sensitive data.

[0108] The similarity score is then compared with a preset individual verification threshold in an encrypted state to generate a preliminary verification result. The preset individual verification threshold is calibrated based on historical verification data and security requirements, for example, set to 0.85 (cosine similarity threshold). This individual verification threshold is stored in each node of the secure multi-party computation network and participates in the comparison in encrypted form. First, the encrypted similarity score is compared with the encrypted individual verification threshold through the comparison sub-protocol in the secure multi-party computation protocol. During the comparison process, each node only processes its local encrypted data and does not obtain plaintext information from other nodes. If the encrypted similarity score is greater than or equal to the encrypted threshold, a preliminary verification result of "pass" (in encrypted Boolean value) is generated. If the similarity score is 0.92, which is greater than the encryption threshold of 0.85, the initial verification result is 1, indicating that the biometrics of the role meet the requirements. If the similarity score is 0.78, which is less than the threshold, the initial verification result is 0. This step ensures that the generation process of individual verification results is still under privacy protection, preventing the initial results from being illegally tampered with or stolen. At the same time, it provides a basic verification basis for a single role for subsequent global collaborative decision-making. In multi-role handover scenarios, each role needs to generate an initial verification result independently, providing individual-level support for comprehensive judgment.

[0109] Next, based on the preliminary verification results, the dynamic decision weights and behavioral biometric confidence levels in the collaborative verification input data, an encrypted contribution value is calculated using a weighted decision algorithm. Then, a global collaborative decision score is calculated based on the encrypted contribution values ​​of all roles in the necessary role set. The dynamic decision weights and behavioral biometric confidence levels are input into the secure multi-party computation network in encrypted form. First, the encrypted contribution value for each role is calculated using the formula EC = PV * DW * BC, where EC represents the encrypted contribution value, PV represents the preliminary verification result, DW represents the dynamic decision weights, and BC represents the behavioral biometric confidence level. Since all three parameters are encrypted, this multiplication operation is performed through a multiplication sub-protocol within the secure multi-party computation protocol. Each node performs collaborative calculations without acquiring the plaintext parameters. For example, a security guard... The initial verification result for one party is an encrypted 1, the dynamic decision weight is an encrypted 0.6, the behavioral biometric confidence level is an encrypted 0.85, and its encrypted contribution value is 0.51 obtained through encrypted multiplication. The initial verification result for another party is an encrypted 1, the dynamic decision weight is an encrypted 0.4, the behavioral biometric confidence level is an encrypted 0.9, and the encrypted contribution value is an encrypted 0.36. Subsequently, through the addition sub-protocol in the secure multi-party computation protocol, the encrypted contribution values ​​of all roles are summed to obtain an encrypted global collaborative decision score. This achieves deep integration of individual verification results with dynamic risk parameters and behavioral status parameters, enabling the global collaborative decision score to comprehensively reflect the verification situation of multiple roles and multiple dimensions. This avoids ignoring situations where a single dimension passes but has potential risks, thus improving the security of the handover process.

[0110] Finally, the global collaborative decision score is compared with a preset collaborative decision threshold. The identity verification result is obtained based on the comparison result. The preset collaborative decision threshold is set according to the security requirements of multi-role collaborative verification and is also stored in encrypted form on each node. First, the encrypted global collaborative decision score is compared with the encrypted collaborative decision threshold through a secure multi-party computation protocol. If the encrypted global score is greater than or equal to the encryption threshold, a "passed" identity verification result (plaintext) is generated; otherwise, a "failed" result is generated. The decryption process must meet preset permission requirements, and decryption is performed collaboratively by a majority of nodes in the secure multi-party computation network (e.g., more than 2 / 3 of the nodes) to prevent a single node from tampering with the result. For example, when the encrypted global score is 0.87, which is greater than the encryption threshold of 0.6, a "passed" identity verification result is output after collaborative decryption by a majority of nodes. If the global score is 0.55, which is less than the threshold, a "failed" result is output, and the reason for failure is simultaneously indicated (e.g., low confidence in a role's biometric characteristics), thus ensuring the fairness of the identity verification result and more accurately identifying risks in escort and handover scenarios.

[0111] In one embodiment of the present invention, the step of determining whether the identity verification result is passed, and if passed, synchronously recording handover event data containing task identifier and asset status, and generating handover evidence after encrypting and digitally signing the handover event data, includes:

[0112] S51: Obtain real-time asset status images during the handover process and calculate its first hash value. At the same time, obtain the handover timestamp, geographical location information, role identifiers of both parties in the handover, and task number to form a structured event data packet.

[0113] S52, calculate the second hash value of the structured event data packet, and combine the first hash value and the second hash value to generate a global data fingerprint;

[0114] S53, use the private key of the handover terminal to digitally sign the global data fingerprint and generate digital signature data;

[0115] S54, combine the digital signature data, the global data fingerprint, and the structured event data packet, encrypt them using the public key of the central scheduling server, and generate an encrypted data packet;

[0116] S55, the encrypted data packets are sent to the central dispatch server and all handover terminals for distributed storage, and a unique certificate number is assigned to each of them to generate handover certificates.

[0117] As described in steps S51-S55 above, clear and tamper-proof event records need to be retained after the handover to address potential asset status disputes and compliance audit requirements. Furthermore, since the handover involves the transfer of asset ownership, relevant data (such as asset status, handover time, and participants) must be authentic and complete. If the data is tampered with or lost, liability cannot be determined and auditing will lack a basis. Additionally, asset status images serve as direct evidence, but their original data volume is large, and direct storage would consume excessive resources. It is also necessary to ensure that the images have not been tampered with. Therefore, this invention uses a combination of multi-layer hash verification, asymmetric encryption, and distributed storage to securely solidify and distribute the handover event data, ensuring the handover process is traceable and the data is tamper-proof, providing strong electronic evidence support for the asset escort handover process.

[0118] The distributed storage relies on a multi-node storage architecture, with storage nodes including a central dispatch server (core storage node), escort terminals (handover participant nodes), and receiving terminals (handover participant nodes). Encrypted data packets are synchronized to the three nodes via a 5G private network or VPN secure channel, achieving a "one primary, two backups" distributed backup to avoid data loss due to single-node failure. A unique certificate number is generated by the central dispatch server and associated with the encrypted data packet, stored on each node as a unique index for subsequent certificate queries.

[0119] like Figure 2 As shown, this invention also discloses a handover system for asset escort tasks based on identity verification, comprising:

[0120] An initialization module is used to obtain escort mission instructions, obtain a necessary set of roles by parsing the escort mission instructions, and obtain a multimodal biometric template set and an encrypted identity public key based on the necessary set of roles to establish an initial identity verification benchmark.

[0121] The verification preparation module is used to collect the current biometric data and dynamic encryption credentials of each role in the necessary role set in real time through the handover terminal based on the escort mission instruction, and generate an on-site verification request based on the current biometric data and dynamic encryption credentials.

[0122] The collaborative preparation module is used to acquire handover scenario data and behavioral status data of each role in the necessary role set, generate dynamic decision weights for each role based on the handover scenario data, and generate behavioral biometric confidence scores for each role based on the behavioral status data, so as to obtain collaborative verification input data.

[0123] The multi-party verification module is used to call the secure multi-party computing protocol to perform collaborative identity verification in a secure multi-party computing network based on the initial identity verification benchmark, the on-site verification request and the collaborative verification input data, and generate an identity verification result.

[0124] The evidence generation module is used to determine whether the identity verification result is passed. If it is passed, it synchronously records the handover event data containing the task identifier and asset status. After encrypting and digitally signing the handover event data, it generates handover evidence.

[0125] The status management module is used to update the status of the escort mission based on the handover and evidence storage, and to trigger the execution permission of the next step after the handover is completed.

[0126] The collaborative preparation module includes:

[0127] A weight allocation unit is used to assign basic decision weights to each role in the necessary role set.

[0128] The scenario risk calculation unit is used to obtain the deviation distance between the real-time geographical location of the handover terminal and the preset handover route, as well as the deviation duration between the handover time and the preset handover time window in the handover scenario data, and to obtain the scenario risk coefficient based on the deviation distance and the deviation duration.

[0129] The dynamic weight generation unit is used to dynamically adjust the basic decision weight of each role according to the situation risk coefficient to obtain its dynamic decision weight. The higher the situation risk coefficient, the greater the increase in the dynamic decision weight of the core role in the necessary role set is than that of the non-core role.

[0130] The behavior feature extraction unit is used to acquire the holding posture data and movement trajectory data of the handover terminal in the behavior state data, and to preprocess and extract features from the holding posture data and movement trajectory data to obtain a behavior feature sequence.

[0131] The confidence generation unit is used to compare the behavioral feature sequence with the pre-registered behavioral biometric template corresponding to the current role in real time to generate behavioral biometric confidence.

[0132] The verification data acquisition unit is used to acquire collaborative verification input data based on the dynamic decision weights and the confidence level of the behavioral biometrics.

[0133] The present invention also discloses a computer device, including a memory and a processor, wherein the memory stores a computer program, characterized in that the processor executes the computer program to implement the steps of a handover method for an identity-based asset escort task.

[0134] The present invention also discloses a computer-readable storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the steps of a handover method for an identity-based asset escort task.

[0135] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.

[0136] The above description is merely a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A method for the handover of asset escort tasks based on identity verification, characterized in that, include: Obtain the escort mission instruction, parse the escort mission instruction to obtain the necessary role set, and obtain the multimodal biometric template set and encrypted identity public key based on the necessary role set to establish an initial identity verification benchmark; Based on the escort mission instructions, the current biometric data and dynamic encryption credentials of each role in the necessary role set are collected in real time through the handover terminal, and an on-site verification request is generated based on the current biometric data and dynamic encryption credentials. Assign basic decision weights to each role in the set of necessary roles; Obtain the deviation distance between the real-time geographical location of the handover terminal and the preset handover route, as well as the deviation duration between the handover time and the preset handover time window from the handover scenario data, and obtain the scenario risk coefficient based on the deviation distance and deviation duration; The basic decision weight of each role is dynamically adjusted according to the situational risk coefficient to obtain its dynamic decision weight. The higher the situational risk coefficient, the greater the increase in the dynamic decision weight of the core role in the necessary role set is compared with that of the non-core role. The handholding posture data and movement trajectory data of the handover terminal are obtained from the behavior state data. The handholding posture data and movement trajectory data are preprocessed and feature extracted to obtain a behavior feature sequence. The behavioral feature sequence is compared in real time with the pre-registered behavioral biometric template corresponding to the current role to generate behavioral biometric confidence. The collaborative verification input data is obtained based on the dynamic decision weights and the confidence levels of the behavioral biometrics. In a secure multi-party computation network, a secure multi-party computation protocol is invoked to perform collaborative identity verification based on the initial identity verification benchmark, the on-site verification request, and the collaborative verification input data, thereby generating an identity verification result. Determine whether the identity verification result is passed. If it is passed, synchronously record the handover event data containing the task identifier and asset status. After encrypting and digitally signing the handover event data, generate a handover certificate. The status of the escort mission is updated based on the handover and evidence storage, and the execution authority for the next step is triggered after the handover is completed.

2. The method for handing over an asset escort task based on identity verification according to claim 1, characterized in that, The steps of obtaining the escort mission instruction, parsing the escort mission instruction to obtain the associated necessary role set, and obtaining the pre-registered multimodal biometric template set and encrypted identity public key based on the necessary role set to establish an initial identity verification benchmark include: Based on the necessary role set, the escort officer identifier and the receiver identifier are obtained. Based on the escort officer identifier and the receiver identifier, the corresponding pre-registered multimodal biometric template set and encrypted identity public key are obtained from the secure storage module. The biometric template set includes fingerprint feature vector and face feature vector. By employing a feature-level fusion algorithm to calculate the fusion weights of fingerprint feature vectors and face feature vectors in the multimodal biometric template set, a multimodal biometric baseline template is generated. The task context parameters are obtained according to the escort task instructions, and a one-time dynamic identity verification code for handover verification is generated according to the encrypted identity public key and the task context parameters. The initial identity verification benchmark is established based on the multimodal biometric benchmark template and the one-time dynamic identity verification code.

3. The method for handing over an asset escort task based on identity verification according to claim 1, characterized in that, The step of collecting the current biometric data and dynamic encrypted credentials of on-site personnel in real time through the handover terminal based on the escort mission instruction, and generating an on-site verification request based on the current biometric data and dynamic encrypted credentials includes: The fingerprint sensor and facial camera of the handover terminal simultaneously collect the current biometric data of the personnel on site, including fingerprint images and facial images. The fingerprint image and facial image are preprocessed and feature extracted to obtain the current fingerprint feature vector and the current facial feature vector; Obtain the current timestamp and the task number according to the escort task instruction. Digitally sign the current timestamp and the task number in the handover terminal to generate a dynamic encrypted certificate. The current fingerprint feature vector, the current face feature vector, and the dynamic encryption credential are encapsulated to generate an on-site verification request.

4. The method for handing over an asset escort task based on identity verification according to claim 1, characterized in that, The step of invoking a secure multi-party computation protocol to perform collaborative identity verification in a secure multi-party computation network based on the initial authentication benchmark, the on-site verification request, and the collaborative verification input data, and generating an identity verification result, includes: Based on a secure multi-party computation protocol, the similarity score between the current biometric data in the on-site verification request and the multimodal biometric benchmark template in the initial identity verification benchmark is calculated, and the validity of the dynamic encrypted credential in the on-site verification request is verified. The similarity score is compared with a preset individual verification threshold under encrypted conditions to generate a preliminary verification result; Based on the preliminary verification results, the dynamic decision weights and behavioral biometric confidence levels in the collaborative verification input data, the encryption contribution value is calculated using a weighted decision algorithm, and the global collaborative decision score is calculated based on the encryption contribution values ​​of all roles in the necessary role set. The global collaborative decision score is compared with a preset collaborative decision threshold, and the identity verification result is obtained based on the comparison result.

5. The method for handing over an asset escort task based on identity verification according to claim 1, characterized in that, The steps of determining whether the identity verification result is passed, and if passed, synchronously recording handover event data containing task identifier and asset status, and generating handover evidence after encrypting and digitally signing the handover event data, include: The system acquires real-time asset status images during the handover process and calculates their first hash value. It also assembles a structured event data packet by acquiring the handover timestamp, geographic location information, role identifiers of both parties, and task number. Calculate the second hash value of the structured event data packet, and combine the first hash value and the second hash value to generate a global data fingerprint; The global data fingerprint is digitally signed using the private key of the handover terminal to generate digital signature data; The digital signature data, the global data fingerprint, and the structured event data packet are combined and encrypted using the public key of the central scheduling server to generate an encrypted data packet. The encrypted data packets are sent to the central dispatch server and all handover terminals for distributed storage, and a unique certificate number is assigned to each of them to generate handover certificates.

6. A handover system for asset escort tasks based on identity verification, characterized in that, It includes multiple modules for implementing the steps of the method according to any one of claims 1 to 5.

7. The asset escort task handover system based on identity verification according to claim 6, characterized in that, It includes multiple units, which are used to implement the steps of the method according to any one of claims 1 to 5.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Financial escort handover system

    CN114238911A

  • Data processing method and device based on escorting service multi-party flattening communication

    CN117336100A