Biological voucher processing system and method

By using the synchronous image matting and encryption operations of the biometric credential processing system, the problems of latency and insufficient adaptability in existing technologies are solved, achieving real-time and efficient image processing and accurate identity verification.

CN121523770APending Publication Date: 2026-02-13ZKTECO CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511709604.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-20
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing technologies suffer from processing delays and poor scenario adaptation in personnel identity verification and monitoring screen analysis, which makes it impossible to meet business timeliness and accuracy requirements.

Method used

A biometric credential processing system is provided, which combines credential management services, intermediate services, cloud storage and device management services to achieve synchronous image cutout and encryption operations, simplify the image processing process, provide real-time feedback on cutout results, and process upload operations within the business system.

Benefits of technology

It achieves real-time and scene adaptability in image processing, solves the problems of latency and insufficient adaptability in traditional technologies, and improves the efficiency and accuracy of identity verification and monitoring analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121523770A_ABST
    Figure CN121523770A_ABST
Patent Text Reader

Abstract

The invention discloses a biological voucher processing system and a biological voucher processing method, which are used for solving the problems that the service timeliness cannot be met and the scene adaptation is poor due to processing delay in the prior art. The biological voucher processing system comprises a voucher management service, and an intermediate service, a cloud storage and an equipment management service which are respectively connected with the voucher management service. The device management service is connected with at least one device; receiving the to-be-processed image from the certificate management service through the intermediate service, and performing synchronous matting on the to-be-processed image to obtain a processed image; receiving the processed image returned by the intermediate service through the certificate management service, encrypting the processed image, and transmitting the encrypted image to the cloud storage; and receiving voucher data generated by the voucher management service through the device management service, determining a target device based on the voucher data, and issuing a voucher to the target device according to the voucher data, so that the target device obtains the encrypted processed image from the cloud storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of image processing technology, and in particular to a biometric credential processing system, a biometric credential processing method, an electronic device, and a storage medium. Background Technology

[0002] With the intelligent upgrade of the security and time attendance industries, the demand for image cutout technology is increasingly prominent in scenarios such as personnel identity verification, attendance archiving, and surveillance video analysis. For example, in attendance scenarios, it is necessary to separate employee faces from complex backgrounds to ensure accurate identity verification. In security scenarios, it is necessary to extract the main image of personnel from surveillance footage to support key functions such as trajectory tracking or identity comparison. How to efficiently and accurately perform subject separation in these scenarios has become a key direction for industry technology optimization.

[0003] Currently, the industry employs various image cutout solutions, including built-in segmentation modules in attendance devices, third-party tools used in security systems, and manual cutout. However, these solutions suffer from insufficient adaptability in practical applications. Built-in modules can only adapt to fixed angles and lighting conditions. Third-party tools struggle to achieve real-time integration with the system. Manual operation is inefficient. Therefore, there is an urgent need for a dedicated solution that can deeply integrate with security and attendance systems to improve overall processing efficiency and accuracy.

[0004] Furthermore, while traditional technologies can achieve basic image matting using face detection bounding boxes in simple scenarios such as indoor fixed camera positions and uniform lighting, they are prone to problems such as inaccurate edges, background residue, and missing subject features in complex scenarios such as outdoor people overlapping with the background, blurred edges due to wearing masks or glasses, and noise in nighttime surveillance, leading to unstable accuracy. This results in inconsistencies in accuracy, failing to meet the requirements for high-precision recognition and standardized archiving, and some technologies are also difficult to adapt to real-time security analysis due to high latency.

[0005] In summary, the current image matting solutions suffer from two main problems. First, the processing latency is inconsistent with business timeliness. Second, they have poor scene adaptability. Summary of the Invention

[0006] This invention provides a biometric credential processing system, a biometric credential processing method, an electronic device, and a storage medium, which solve or partially solve the technical problems of current related technologies that fail to meet business timeliness requirements due to processing delays and have poor scenario adaptability.

[0007] This invention provides a biometric credential processing system, comprising a credential management service, an intermediate service, cloud storage, and a device management service connected to the credential management service; the device management service connects to at least one device; wherein,

[0008] The intermediate service is used to receive the image to be processed from the credential management service and synchronously cut out the image to obtain the processed image.

[0009] The credential management service is used to receive the processed image returned by the intermediate service, encrypt the processed image, and then transmit it to the cloud storage.

[0010] The device management service is used to receive credential data generated by the credential management service, determine the target device based on the credential data, and issue credentials to the target device according to the credential data, so that the target device can obtain the encrypted processed image from the cloud storage.

[0011] Optionally, the image to be processed transmitted through the credential management service is an image string; the intermediate service is specifically used for:

[0012] The image to be processed is converted from an image string into the original image by decoding;

[0013] The image processing function in the shared object library is called to synchronously remove the biometric features from the original image, and it is determined whether the removal is successful.

[0014] If not, retry the synchronized cutout action;

[0015] If so, output the biometric features obtained from the synchronized matting as the processed image.

[0016] Optionally, the credential data includes a new credential operation event, a biometric credential ID, and a biometric credential link; the device management service is specifically used for:

[0017] Based on the newly added voucher operation event, the voucher issuance action is triggered;

[0018] The target device is determined from the at least one device based on the biometric credential ID;

[0019] The biometric credential link is sent to the target device so that the target device can retrieve the encrypted processed image from the cloud storage based on the biometric credential link.

[0020] Optionally, the cloud storage is also used for:

[0021] The system receives and successfully stores the encrypted processed image, generates a cloud storage result based on the storage location of the encrypted processed image, and feeds the cloud storage result back to the credential management service.

[0022] Optionally, the credential management service is also used for:

[0023] Extract the storage location of the encrypted processed image in the cloud storage from the cloud storage results, and generate a biometric credential link based on the storage location;

[0024] Generate the new credential operation event and biometric credential ID corresponding to the encrypted processed image;

[0025] The newly added credential operation event, the biometric credential ID, and the biometric credential link are integrated as credential data for the encrypted processed image.

[0026] Optionally, the credential management service connects to the application side; the credential management service is also used for:

[0027] Receive the credential creation request initiated by the application side, and extract the image to be processed from the credential creation request;

[0028] Perform data format validation on the image to be processed;

[0029] After verification, the image to be processed is encoded into an image string and sent to the intermediate service to initiate synchronous image cutout, while the image to be processed is simultaneously added to the database.

[0030] Optionally, the credential management service is also used for:

[0031] The credential data is fed back to the application side in real time.

[0032] This invention also provides a biometric credential processing method applied to a biometric credential processing system, the biometric credential processing system including a credential management service, an intermediate service, cloud storage, and a device management service respectively connected to the credential management service; the device management service connects to at least one device; the method includes:

[0033] The intermediate service receives the image to be processed from the credential management service and performs synchronous image cutout on the image to be processed to obtain the processed image.

[0034] The credential management service receives the processed image returned by the intermediate service, encrypts the processed image, and then transmits it to the cloud storage.

[0035] The device management service receives credential data generated by the credential management service, determines the target device based on the credential data, and issues a credential to the target device according to the credential data, so that the target device can obtain the encrypted processed image from the cloud storage.

[0036] The present invention also provides an electronic device, the device comprising a processor and a memory:

[0037] The memory is used to store program code and transmit the program code to the processor;

[0038] The processor is used to execute the biometric credential processing method as described above according to the instructions in the program code.

[0039] The present invention also provides a computer-readable storage medium for storing program code for performing the biometric credential processing method described above.

[0040] As can be seen from the above technical solutions, the present invention has the following advantages:

[0041] A biometric credential processing system and method are provided. The biometric credential processing system includes a credential management service, an intermediate service connected to the credential management service, cloud storage, and a device management service. The device management service connects to at least one device. The intermediate service receives an image to be processed from the credential management service and performs simultaneous image matting on the image to obtain a processed image. The credential management service receives the processed image returned by the intermediate service, encrypts the processed image, and transmits it to cloud storage. The device management service receives credential data generated by the credential management service, determines the target device based on the credential data, and issues a credential to the target device to enable the target device to retrieve the encrypted processed image from cloud storage. On the one hand, by simplifying the entire image processing flow and providing a unified intermediate service for image detection and matting operations, the matting results can be fed back to the caller in real time. On the other hand, the encryption and cloud storage upload operations are processed within the business system, replacing the old system's logic of triggering image matting, encryption, and upload based on storage actions, resulting in better scenario adaptability. In addition, the intermediate service is lightweight and targeted, and only performs detection and image matting operations during processing, solving the problem that traditional technologies cannot perform simultaneous operations. Attached Figure Description

[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0043] Figure 1 This is a schematic diagram of a current credential registration process;

[0044] Figure 2 This is a schematic diagram of the structure of a biometric credential processing system;

[0045] Figure 3This is a flowchart illustrating the steps of a biometric credential processing method.

[0046] Figure 4 This is a schematic diagram of the overall process of a biometric credential processing method. Detailed Implementation

[0047] This invention provides a biometric credential processing system, a biometric credential processing method, an electronic device, and a storage medium to solve or partially solve the technical problems of current related technologies, such as the inability to meet business timeliness requirements due to processing delays and poor scenario adaptability.

[0048] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0049] To enable those skilled in the art to better understand the technical solutions provided in the embodiments of the present invention, some of the technical features involved in the solutions are briefly described first:

[0050] Biometric credentials refer to credentials that use an individual's biological characteristics as a basis for identity verification. Common biometric characteristics include fingerprints, iris scans, facial features, voice, and hand geometry. Through biometric technology, these characteristics can be used to confirm an individual's identity, thereby improving security and convenience. Biometric credentials have wide applications in daily life, such as fingerprint unlocking of mobile phones and facial recognition payment.

[0051] As an example, the industry currently employs various image cutout solutions, including built-in segmentation modules in attendance devices, third-party tools used in security systems, and manual cutout. However, these solutions suffer from insufficient adaptability in practical applications. Built-in modules can only adapt to fixed angles and lighting conditions. Third-party tools struggle to achieve real-time integration with the system. Manual operation is inefficient. Therefore, there is an urgent need for a dedicated solution that can deeply integrate with security and attendance systems to improve overall processing efficiency and accuracy.

[0052] Furthermore, while traditional technologies can achieve basic image matting using face detection bounding boxes in simple scenarios such as indoor fixed camera positions and uniform lighting, they are prone to problems such as inaccurate edges, background residue, and missing subject features in complex scenarios such as outdoor people overlapping with the background, blurred edges due to wearing masks or glasses, and noise in nighttime surveillance, leading to unstable accuracy. This results in inconsistencies in accuracy, failing to meet the requirements for high-precision recognition and standardized archiving, and some technologies are also difficult to adapt to real-time security analysis due to high latency.

[0053] In summary, the current image matting solutions suffer from two main problems. First, the processing latency is inconsistent with business timeliness. Second, they have poor scene adaptability.

[0054] For example, taking facial recognition credentials as an example, refer to Figure 1 This diagram illustrates a current credential registration process. In the current platform service, application-side credential registration requires calling the Credential Management Service (CMS) to perform face credential registration. The implementation process is as follows:

[0055] Step 1: The application side (business side) initiates a credential creation request;

[0056] Step 2: The voucher management service performs local logical operations on the voucher data (data format verification, data entry, etc.), then uploads the face image to cloud storage, and receives the storage results from the cloud storage.

[0057] Step 3: The credential management service notifies the device management service to synchronize credential data (personnel information and facial images) to the device;

[0058] Step 4: The voucher management service returns the voucher creation result to the application side;

[0059] Step 5: After storing the face image in cloud storage, the image processing operation is triggered upon completion of storage. At this time, the face data is processed asynchronously.

[0060] Step 6: Asynchronous operation, mainly performing image cutout, encryption, and uploading to cloud storage services; simultaneously calling the face detection service for image cutout processing;

[0061] Step 7: After the operation is completed, upload the processed face cutout data to cloud storage;

[0062] Step 8: After obtaining the cloud storage address, the credential management service updates the processing results, mainly by first updating the cloud storage and then asynchronously updating the storage address of the face cutout data in the personnel credential.

[0063] Step 9: The credential management service updates personnel information and face cutout data, and pushes this information to the devices synchronously via a link through the device management service;

[0064] Step 10: The voucher management service notifies the data push service (device message service) of the processing result.

[0065] Step 11: The data push service will synchronize the processing results to the application side, informing the application side that the image processing has been completed.

[0066] Step 12: The device reads the face cutout data from the cloud storage according to the sent link.

[0067] As the examples above illustrate, asynchronous image matting requires first storing the captured images (attendance faces, surveillance personnel images) to the server, then queuing for background processing, which can take seconds or even minutes. Security systems, on the other hand, need to identify and extract personnel in real time for alerts, and attendance systems require rapid facial verification. This delay caused by asynchronous image matting leads to delayed alerts and slow attendance recording, failing to meet the real-time needs of the industry.

[0068] Asynchronous image matting uses a general algorithm for batch processing, which is not optimized for scenarios such as security (overlapping people and backgrounds, noise at night) and attendance (wearing masks, backlighting). This easily leads to edge deviation, background residue, and missing facial features. Furthermore, it cannot adjust parameters for individual image scenarios, resulting in large fluctuations in accuracy within the same batch, making it difficult to meet the requirements for identity verification and standardized archiving.

[0069] Therefore, one of the core inventive points of this invention is to propose a system and method for high-concurrency biometric credential processing. By simplifying the entire image processing flow and providing a unified intermediate service for image detection and matting operations, the matting results can be fed back to the caller in real time. Encryption and cloud storage upload operations are processed within the business system, replacing the old system's logic of triggering image matting, encryption, and uploading based on storage actions, thus providing better scenario adaptability. Furthermore, the intermediate service is lightweight and targeted, processing only detection and matting operations, solving the problem of traditional technologies being unable to perform synchronous operations. The intermediate service provided by this invention is designed with an on-demand, elastic scaling mechanism, which solves the defects in the old system where, after successful credential addition, the image operation results were not read and the feedback of results was delayed when the application side or the issuing device was fed back after asynchronous operations.

[0070] Reference Figure 2 The diagram shows a schematic representation of a biometric credential processing system provided in an embodiment of the present invention.

[0071] Combination Figure 2 The biometric credential processing system 200 provided in this embodiment of the invention mainly includes a credential management service (CMS) 201, an intermediate service 202, a cloud storage 203, and a device management service (DMS) 204, all connected to the credential management service 201. The device management service 204 is connected to at least one device 205.

[0072] In specific applications, the intermediate service 202 can be mainly used to receive the image to be processed from the credential management service 201, and synchronously perform image matting on the image to be processed to obtain the processed image.

[0073] The credential management service 201 is mainly used to receive the processed images returned by the intermediate service 202, encrypt the processed images, and then transmit them to the cloud storage 203.

[0074] Device management service 204 is mainly used to receive credential data generated by credential management service 201, determine target device 205 based on credential data, and issue credential to target device 205 according to credential data so that target device 205 can obtain encrypted processed image from cloud storage 203.

[0075] In some embodiments, the credential management service 201 connects to the application side 206. The application side 206 can then initiate a credential creation request based on the image to be processed. Upon receiving the credential creation request from the application side 206, the credential management service 201 extracts the image to be processed from the request; then it performs data format validation on the image; after successful validation, it encodes the image into an image string and sends it to the intermediate service 202 to initiate synchronous image cutout, while simultaneously performing an image storage operation.

[0076] Understandably, to facilitate transmission and save transmission time, the image to be processed transmitted from the credential management service 201 to the intermediate service 202 is an image string. After receiving the image to be processed in image string format, the intermediate service 202 can decode it to convert the image to be processed from the image string into the original image; then, it calls the image processing function in the shared object library (.so library) to synchronously remove biometric features from the original image and determines whether the removal is successful; if not, it retryes the synchronous removal action; if so, it outputs the biometric features obtained by synchronous removal as the processed image.

[0077] The intermediate service 202 sends the unencrypted processed image back to the credential management service 201, which then encrypts the processed image and uploads the encrypted processed image to the cloud storage 203.

[0078] Cloud storage 203 receives and successfully stores the encrypted processed image, generates the cloud storage 203 result based on the storage location of the encrypted processed image, and feeds the cloud storage 203 result back to the credential management service 201.

[0079] At this point, the credential management service 201 can extract the storage location of the encrypted processed image in the cloud storage 203 from the results of the cloud storage 203, and generate a biometric credential link based on the storage location; at the same time, it can also generate the new credential operation event and biometric credential ID corresponding to the encrypted processed image; then, it integrates the new credential operation event, biometric credential ID and biometric credential link as credential data for the encrypted processed image.

[0080] The "Add Credential" operation event corresponds to the action of adding a credential. When adding a credential, the credential management service 201 will push the corresponding event (event type: Add Operation) and the biometric credential ID to the device management service 204. The device management service 204 will issue the credential based on these two factors, sending the biometric credential link to the corresponding device 205.

[0081] Furthermore, the voucher management service 201 can also feed voucher data back to the application side 206 in real time.

[0082] Based on the preceding discussion, credential data can include a new credential operation event, a biometric credential ID, and a biometric credential link. Specifically, device management service 204 can be used to: trigger a credential issuance action based on the new credential operation event; determine a target device 205 from at least one device 205 based on the biometric credential ID; and issue the biometric credential link to the target device 205, enabling the target device 205 to retrieve the encrypted processed image from cloud storage 203 based on the biometric credential link.

[0083] Taking facial recognition credentials as an example, the optimized system provided in this embodiment of the invention performs biometric credential processing. When application 206 calls credential management service 201 to perform a new facial recognition credential operation, assuming that the cutout image of the face can be obtained and the cutout result can be returned to application 206 simultaneously, then the user on application 206 can know in real time whether the operation was successful after adding the credential. For device 205, the credential image of the registered user can also be retrieved in a timely manner. To meet the synchronization requirement, this embodiment of the invention adds an intermediate service 202, which is specifically used to process the cutout operation and return the cutout result in real time. The cutout processing operation is performed in the intermediate service 202, which can process and return the cutout detection and cutout result in real time.

[0084] This invention proposes a system for high-concurrency biometric credential processing. By simplifying the entire image processing system framework, the image processing workflow is streamlined. A unified intermediate service is provided for image detection and matting operations, enabling real-time feedback of matting results to the caller. Encryption and cloud storage upload operations are handled within the business system, replacing the old system's trigger-based logic for image matting, encryption, and uploading based on storage actions, offering better scenario adaptability. Furthermore, the intermediate service is lightweight and targeted, focusing solely on detection and matting operations, solving the problem of traditional technologies' inability to perform synchronous operations. The intermediate service provided by this invention is designed with an on-demand, elastic scaling mechanism, addressing the shortcomings of the old system where, after successful credential addition, image operation results were not read and feedback was delayed when sent to the application or distribution device.

[0085] Reference Figure 3 This diagram illustrates a flowchart of a biometric credential processing method according to an embodiment of the present invention. The method is applied to a biometric credential processing system as described in the foregoing embodiments. The biometric credential processing system includes a credential management service, an intermediate service, cloud storage, and a device management service connected to the credential management service; the device management service connects to at least one device; the method specifically includes the following steps:

[0086] Step 301: Receive the image to be processed from the voucher management service through the intermediate service, and simultaneously perform image matting on the image to be processed to obtain the processed image;

[0087] Step 302: Receive the processed image returned by the intermediate service through the credential management service, encrypt the processed image, and then transmit it to the cloud storage.

[0088] Step 303: Receive credential data generated by the credential management service through the device management service, determine the target device based on the credential data, and issue a credential to the target device according to the credential data, so that the target device can obtain the encrypted processed image from the cloud storage.

[0089] In one optional embodiment, the image to be processed transmitted by the credential management service is an image string; the process in step 301, which involves synchronously removing background elements from the image to be processed through the intermediate service to obtain the processed image, includes:

[0090] The image to be processed is converted from an image string into the original image by decoding;

[0091] The image processing function in the shared object library is called to synchronously remove the biometric features from the original image, and it is determined whether the removal is successful.

[0092] If not, retry the synchronized cutout action;

[0093] If so, output the biometric features obtained from the synchronized matting as the processed image.

[0094] In one optional embodiment, the credential data includes a new credential operation event, a biometric credential ID, and a biometric credential link; step 303, which involves the device management service determining the target device based on the credential data and issuing a credential to the target device according to the credential data, so that the target device can obtain the encrypted processed image from the cloud storage, includes:

[0095] Based on the newly added voucher operation event, the voucher issuance action is triggered;

[0096] The target device is determined from the at least one device based on the biometric credential ID;

[0097] The biometric credential link is sent to the target device so that the target device can retrieve the encrypted processed image from the cloud storage based on the biometric credential link.

[0098] In an optional embodiment, the method further includes:

[0099] The cloud storage receives and successfully stores the encrypted processed image, generates a cloud storage result based on the storage location of the encrypted processed image, and feeds the cloud storage result back to the credential management service.

[0100] In an optional embodiment, the method further includes generating voucher data through the voucher management service, wherein the process of generating voucher data through the voucher management service includes:

[0101] Extract the storage location of the encrypted processed image in the cloud storage from the cloud storage results, and generate a biometric credential link based on the storage location;

[0102] Generate the new credential operation event and biometric credential ID corresponding to the encrypted processed image;

[0103] The newly added credential operation event, the biometric credential ID, and the biometric credential link are integrated as credential data for the encrypted processed image.

[0104] In one optional embodiment, the credential management service connects to the application side; the method further includes:

[0105] The credential management service receives the credential creation request initiated by the application side and extracts the image to be processed from the credential creation request; performs data format verification on the image to be processed; after the verification is passed, the image to be processed is encoded into an image string and sent to the intermediate service to initiate synchronous image cutout, and at the same time performs a database entry operation on the image to be processed.

[0106] In an optional embodiment, the method further includes:

[0107] The voucher management service feeds the voucher data back to the application side in real time.

[0108] As the method embodiments are basically similar to the system embodiments, they are described in a relatively simple manner. For relevant details, please refer to the description of the system embodiments described above.

[0109] In this embodiment of the invention, based on the high-concurrency biometric credential processing system proposed in the preceding embodiments, a corresponding processing method is proposed. An intermediate service receives an image to be processed from a credential management service and performs synchronous image matting on the image to obtain a processed image. The credential management service receives the processed image returned by the intermediate service, encrypts the processed image, and transmits it to cloud storage. A device management service receives credential data generated by the credential management service, determines the target device based on the credential data, and issues a credential to the target device according to the credential data, enabling the target device to retrieve the encrypted processed image from cloud storage.

[0110] In the biometric credential processing, a unified intermediate service is provided to perform image detection and cutout operations, enabling real-time feedback of the cutout results to the caller. Encryption and cloud storage upload operations are handled within the business system, replacing the old system's trigger-based logic for image cutout, encryption, and uploading based on storage actions, offering better scenario adaptability. Furthermore, the intermediate service is lightweight and targeted, focusing solely on detection and cutout operations, solving the problem of traditional technologies' inability to perform synchronous operations. The intermediate service provided by this invention is designed with an on-demand, elastic scaling mechanism, resolving the shortcomings of old systems where asynchronous operations resulted in delayed image reading and result feedback delays when the image operation results were fed back to the application or distribution device after successful credential creation. The technical solution provided by this invention is applicable to image processing scenarios in security, attendance, and other fields, such as identity verification, attendance tracking, access control, and visitor management.

[0111] Based on the biometric credential processing system described in the preceding embodiments, for better illustration, a facial recognition credential will be used as an example, referring to... Figure 4 This diagram illustrates the overall flow of a biometric credential processing method according to an embodiment of the present invention. It should be noted that this embodiment only provides a brief description of the general flow of biometric credential processing. The specific implementation process of each step can be understood by referring to the relevant content in the foregoing embodiments, and will not be elaborated upon here. It is understood that the present invention does not impose any limitations on this.

[0112] Reference Figure 4 The overall processing flow in the biometric credential processing system can be as follows:

[0113] Step S1: The application initiates a credential creation request to the credential management service based on the image to be processed;

[0114] Step S2: The voucher management service receives the voucher creation request, processes the image to be processed according to its own logic (basic data format verification and database entry operation), and initiates face detection and synchronous image cutout processing to the intermediate service;

[0115] Step S3: The intermediate service performs face detection and synchronous matting on the image to be processed through algorithm matting to obtain the processed image (i.e., the face features obtained through synchronous matting).

[0116] Step S4: The intermediate service feeds back the processed image as the image processing result to the voucher management service;

[0117] Step S5: The credential management service encrypts the processed image and uploads the encrypted processed image to cloud storage;

[0118] Step S6: The cloud storage receives and successfully stores the encrypted processed image, generates a cloud storage result based on the storage location of the encrypted processed image, and feeds the cloud storage result back to the credential management service.

[0119] Step S7: The voucher management service adds voucher data based on the cloud storage results and provides real-time feedback to the application side;

[0120] Step S8: The credential management service notifies the device management service to send credential data to the target device, which mainly links the biometric credentials used to obtain the processed image to the corresponding target device;

[0121] Step S9: The target device reads the encrypted processed image from cloud storage based on the biometric credential link.

[0122] This invention also provides an electronic device, which includes a processor and a memory:

[0123] The memory is used to store program code and transfer the program code to the processor;

[0124] The processor is used to execute the biometric credential processing method of any embodiment of the present invention according to the instructions in the program code.

[0125] This invention also provides a computer-readable storage medium for storing program code for executing the biometric credential processing method of any embodiment of this invention.

[0126] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0127] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this invention are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0128] In the embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units through some interfaces, and may be electrical, mechanical, or other forms.

[0129] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0130] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0131] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0132] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A biometric credential processing system, characterized in that, The biometric credential processing system includes a credential management service, an intermediate service, cloud storage, and a device management service connected to the credential management service; the device management service connects to at least one device; wherein... The intermediate service is used to receive the image to be processed from the credential management service and synchronously cut out the image to obtain the processed image. The credential management service is used to receive the processed image returned by the intermediate service, encrypt the processed image, and then transmit it to the cloud storage. The device management service is used to receive credential data generated by the credential management service, determine the target device based on the credential data, and issue credentials to the target device according to the credential data, so that the target device can obtain the encrypted processed image from the cloud storage.

2. The biometric credential processing system according to claim 1, characterized in that, The image to be processed transmitted by the credential management service is an image string; the intermediate service is specifically used for: The image to be processed is converted from an image string into the original image by decoding; The image processing function in the shared object library is called to synchronously remove the biometric features from the original image, and it is determined whether the removal is successful. If not, retry the synchronized cutout action; If so, output the biometric features obtained from the synchronized matting as the processed image.

3. The biometric credential processing system according to claim 1, characterized in that, The credential data includes a new credential operation event, a biometric credential ID, and a biometric credential link; the device management service is specifically used for: Based on the newly added voucher operation event, the voucher issuance action is triggered; The target device is determined from the at least one device based on the biometric credential ID; The biometric credential link is sent to the target device so that the target device can retrieve the encrypted processed image from the cloud storage based on the biometric credential link.

4. The biometric credential processing system according to claim 1, characterized in that, The cloud storage is also used for: The system receives and successfully stores the encrypted processed image, generates a cloud storage result based on the storage location of the encrypted processed image, and feeds the cloud storage result back to the credential management service.

5. The biometric credential processing system according to claim 4, characterized in that, The credential management service is also used for: Extract the storage location of the encrypted processed image in the cloud storage from the cloud storage results, and generate a biometric credential link based on the storage location; Generate the new credential operation event and biometric credential ID corresponding to the encrypted processed image; The newly added credential operation event, the biometric credential ID, and the biometric credential link are integrated as credential data for the encrypted processed image.

6. The biometric credential processing system according to any one of claims 1 to 5, characterized in that, The credential management service connects to the application side; the credential management service is also used for: Receive the credential creation request initiated by the application side, and extract the image to be processed from the credential creation request; Perform data format validation on the image to be processed; After verification, the image to be processed is encoded into an image string and sent to the intermediate service to initiate synchronous image cutout, while the image to be processed is simultaneously added to the database.

7. The biometric credential processing system according to claim 6, characterized in that, The credential management service is also used for: The credential data is fed back to the application side in real time.

8. A method for processing biometric credentials, characterized in that, The system is applied to a biometric credential processing system, which includes a credential management service, an intermediate service, a cloud storage service, and a device management service connected to the credential management service. The device management service connects to at least one device; the method includes: The intermediate service receives the image to be processed from the credential management service and performs synchronous image cutout on the image to be processed to obtain the processed image. The credential management service receives the processed image returned by the intermediate service, encrypts the processed image, and then transmits it to the cloud storage. The device management service receives credential data generated by the credential management service, determines the target device based on the credential data, and issues a credential to the target device according to the credential data, so that the target device can obtain the encrypted processed image from the cloud storage.

9. An electronic device, characterized in that, The device includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is used to execute the biometric credential processing method of claim 8 according to the instructions in the program code.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store program code for executing the biometric credential processing method of claim 8.