Iris data storage method and system, electronic equipment and storage medium

By splitting iris features into multiple fragments and distributing and communicating them in isolation across different agent terminals, the security and scalability issues of traditional iris data storage systems are solved, achieving efficient and secure iris identity authentication.

CN121808855APending Publication Date: 2026-04-07北京中科领虹科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Traditional iris data storage systems face challenges in the internet era, including risks of data leakage, single points of failure due to centralized storage, limited system scalability, high maintenance costs, and poor data backup capabilities.

Method used

A distributed storage method is adopted to split iris features into multiple segments, store them on different proxy terminals, and isolate communication through a virtual network. Proxy codes are generated for anonymization configuration, thereby realizing the distributed storage and comparison of iris segments.

Benefits of technology

It improves the security of iris data and the fault tolerance of the storage system, reduces the impact of single points of failure, and enhances user privacy protection and authentication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121808855A_ABST
    Figure CN121808855A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an iris data storage method and system, electronic equipment and a storage medium. The iris data storage method comprises the following steps: acquiring a first iris feature of a target person, splitting the first iris feature to obtain a plurality of first iris segments, and determining proxy terminals corresponding to the first iris segments; each first iris segment is stored to a corresponding proxy terminal, each proxy terminal is in one-to-one correspondence with each first iris segment, and communication between the proxy terminals is isolated. By adopting the embodiment of the invention, the safety of iris data storage can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of iris recognition technology, specifically to an iris data storage method, system, electronic device, and storage medium. Background Technology

[0002] With the development of modern society, more and more personal information and property assets are being digitized and networked, and the security and confidentiality of this information are receiving increasing attention. Identity authentication, as an important technology in the field of information security, is also gaining increasing importance.

[0003] As a type of biometric identification technology, iris recognition technology has broad application prospects in the field of identity authentication. It is characterized by its unforgeability and high recognizability, and is also more secure and reliable than technologies such as fingerprint recognition and facial recognition.

[0004] However, traditional iris data storage systems have many drawbacks when used on the Internet. They typically store iris data centrally as long vectors, which means that if the data is lost, the person's complete iris data will be leaked. Summary of the Invention

[0005] This application provides an iris data storage method, system, electronic device, and storage medium, which can improve the security of iris data storage.

[0006] In a first aspect, this application provides an iris data storage method applied to a server, the iris data storage method comprising: Obtain the first iris feature of the target person, split the first iris feature to obtain multiple first iris segments, and determine the agent terminal corresponding to each first iris segment; Each of the first iris segments is stored in a corresponding proxy terminal, and each proxy terminal corresponds one-to-one with each of the first iris segments, and the proxy terminals are isolated from each other in communication.

[0007] By adopting the above technical solution, distributed storage of the first iris feature is achieved. This distributed storage method effectively improves the security of biometric information by splitting the complete first iris feature into multiple feature fragments and storing them separately on different agent terminals. Even if a hacker intrudes into a single agent terminal, they can only obtain partial feature fragments and cannot recover the complete first iris feature. Furthermore, because the agent terminals are isolated from each other and cannot exchange information, it is difficult for hackers to correlate information across multiple agent terminals to launch attacks. In addition, distributed storage also improves the fault tolerance of the storage system and reduces the impact of single points of failure.

[0008] Optionally, the step of splitting the first iris feature to obtain multiple first iris segments and determining the proxy terminal corresponding to each first iris segment includes: Based on the data length of the first iris feature, the first iris feature is split into multiple first iris segments; Based on the number of segments and network size of the first iris segments, multiple virtual networks are divided; Based on the basic information of the target personnel, a proxy terminal corresponding to each of the first iris segments is configured in each of the virtual networks, and communication between the virtual networks is isolated.

[0009] By adopting the above technical solution, the first iris feature is first divided into multiple first iris segments according to certain rules, which not only facilitates storage and processing but also improves storage security. Secondly, by setting up multiple isolated virtual networks and storing the data in groups within the networks, the first iris segments are decentralized, reducing the storage pressure on individual agent terminals and improving storage efficiency.

[0010] Optionally, the basic information includes a mobile phone number, ID card number, and terminal address. The step of configuring a proxy terminal corresponding to each of the first iris segments in each of the virtual networks based on the target person's basic information includes: Generate a proxy code based on the mobile phone number, the ID card number, and the terminal address; Based on the proxy code and the number of each virtual network, each proxy terminal is configured into the corresponding virtual network.

[0011] By adopting the above technical solution, the method of generating proxy codes based on the target personnel's basic information achieves anonymized configuration based on user information. This prevents the direct inference of the user's true identity from the proxy code, effectively protecting user privacy. Furthermore, the standardized length and format of the proxy codes facilitate batch configuration of proxy terminals. Allocating proxy terminals to isolated virtual networks based on the proxy codes achieves both distributed storage of fragmented user data and improved storage efficiency through virtual network partitioning.

[0012] Optionally, after storing each of the first iris segments to the corresponding proxy terminal, the method further includes: The second iris feature of the target person during identity authentication is obtained, and the second iris feature is split to obtain multiple second iris segments; Each of the second iris segments is sent to the corresponding proxy terminal, so that each proxy terminal compares the second iris segment with the stored first iris segment to obtain the comparison result; Based on the comparison results returned by each of the agent terminals, the identity of the target personnel is verified.

[0013] By adopting the above technical solution, feature extraction, comparison, and result feedback are performed in a distributed manner, avoiding the performance and security bottlenecks of a central server and improving authentication efficiency. Simultaneously, distributed storage enhances security, making it difficult for attackers to obtain the identity of a target person through partial iris fragments. Overall, highly efficient and secure iris authentication is achieved.

[0014] A second aspect of this application provides another iris data storage method, applied to any one of multiple proxy terminals, wherein communication between the proxy terminals is isolated, and the iris data storage method includes: In response to a data distribution instruction sent by the server, the first iris fragment carried in the data distribution instruction is stored. The first iris fragment is obtained by splitting the first iris feature of the target person.

[0015] By adopting the above technical solution, after the server segments the first iris feature extracted during the registration of the target person, it distributes the different segments to different agent terminals for storage via data distribution instructions. In this way, the first iris feature can be distributed for storage, effectively improving the security of the iris feature data, while also enhancing the scalability and fault tolerance of the storage.

[0016] Optionally, the method further includes: In response to a data comparison instruction sent by the server, the second iris segment carried in the data comparison instruction is obtained; The first iris segment is compared with the second iris segment to obtain a comparison result, and the comparison result is sent to the server so that the server can authenticate the target person based on the comparison results sent by each of the agent terminals.

[0017] By employing the above technical solution, the server collects fragment-level comparison results from each proxy terminal and comprehensively determines the final identity authentication result. This distributed comparison method avoids server performance bottlenecks and improves authentication efficiency. At the same time, it is very difficult for attackers to deceive using only partial fragments of content.

[0018] A third aspect of this application provides an iris data storage device, comprising: The first iris feature segmentation module is used to obtain the first iris feature of the target person, segment the first iris feature to obtain multiple first iris segments, and determine the agent terminal corresponding to each first iris segment. The first iris feature storage module is used to store each of the first iris segments to the corresponding proxy terminal. Each proxy terminal corresponds one-to-one with each of the first iris segments, and the proxy terminals are isolated from each other in communication.

[0019] A fourth aspect of this application provides another iris data storage device, comprising: The second iris fragment storage module is used to store the first iris fragment carried in the data distribution instruction sent by the server in response to the data distribution instruction. The first iris fragment is obtained by splitting the first iris feature of the target person.

[0020] A fifth aspect of this application provides a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the method steps described above.

[0021] A sixth aspect of this application provides an electronic device comprising: The device includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to enable the electronic device to perform the above-described method steps.

[0022] In summary, one or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages: By adopting the technical solution of this application, distributed storage of the first iris feature is achieved. This distributed first iris feature storage method effectively improves the security of biometric information by splitting the complete first iris feature into multiple feature fragments and storing them separately on different agent terminals. Even if a hacker intrudes into a single agent terminal, they can only obtain partial feature fragments and cannot recover the complete first iris feature. Furthermore, because the agent terminals are isolated from each other and cannot exchange information, it is difficult for hackers to correlate information across multiple agent terminals to launch attacks. In addition, distributed storage also improves the fault tolerance of the storage system and reduces the impact of single-point failures. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of an implementation environment for a solution provided in an embodiment of this application; Figure 2 This is a flowchart illustrating an iris data storage method provided in an embodiment of this application; Figure 3 This is a flowchart illustrating another iris data storage method provided in an embodiment of this application; Figure 4 This is a schematic diagram of the structure of an iris data storage device provided in an embodiment of this application; Figure 5 This is a schematic diagram of another iris data storage device provided in an embodiment of this application; Figure 6 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of this application.

[0024] Explanation of reference numerals in the attached figures: 700, electronic device; 701, processor; 702, communication bus; 703, user interface; 704, network interface; 705, memory. Detailed Implementation

[0025] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0026] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.

[0027] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0028] With the development of information technology, more and more personal privacy information and digital assets are being digitized and transmitted over networks, making information security and confidentiality a widespread concern in today's society. In the field of information security, identity authentication technology, as an important means of ensuring information security, is of particular importance in its research and application.

[0029] Biometric recognition is a current research hotspot in the field of identity authentication. Among them, iris recognition is considered one of the most reliable and secure biometric recognition methods due to the uniqueness and stability of biometric features. Compared with other biometric recognition methods such as fingerprints, iris recognition has higher recognition accuracy and lower false recognition rate. Current iris recognition systems mostly adopt the method of converting extracted iris features into templates and storing them centrally.

[0030] However, this centralized iris feature storage method has significant drawbacks in the Internet environment: (1) centralized storage templates are at risk of data leakage. Once the templates are illegally obtained, it will lead to serious problems of personal identity theft; (2) centralized storage is a system bottleneck, which limits the system's scalability and poses a single point of failure risk; (3) centralized architecture is difficult to achieve elastic expansion of storage capacity and processing power; (4) the cost of maintaining a centralized storage system is high and complex; (5) data backup and disaster recovery capabilities are poor.

[0031] To address the aforementioned issues, this application proposes an iris data storage method, system, electronic device, and storage medium. This solution should achieve distributed processing throughout the entire process of iris feature extraction, storage, comparison, and identity recognition, ensuring performance, security, and scalability through algorithmic and protocol innovations. Furthermore, user privacy protection, system fault tolerance, and practical application scenario requirements are considered to achieve the optimal overall balance.

[0032] Please refer to Figure 1 The diagram illustrates an implementation environment for a solution provided in one embodiment of this application. This implementation environment can be implemented as an iris identity storage and authentication system, which may include a server and multiple agent terminals. Each agent terminal can be directly or indirectly connected to the server via wired or wireless networks.

[0033] In the embodiments of this application, the server refers to the core management platform of the iris recognition authentication system, and the agent terminal is an intelligent terminal node connected to the server.

[0034] For example, the server can consist of three functional modules: a feature engine, a matching engine, and an MQTT Broker. The MQTT Broker is used for interactive communication with various agent terminals; the feature engine collects iris images registered by users, extracts and encodes features from the images to obtain an iris feature template. The server then divides this template into multiple feature segments according to predetermined rules and distributes these different feature segments to various agent terminals connected to the platform for distributed storage.

[0035] During the authentication phase, the user provides another on-site iris image. The server uses a feature engine to extract features from the iris image, breaks down the extracted iris features into iris segments, and sends each iris segment to the corresponding proxy terminal for comparison. The proxy terminal returns the comparison results to the server. The server then uses a matching engine to authenticate the user's identity based on the comparison results returned by all proxy terminals.

[0036] In this embodiment, a proxy terminal refers to a network node device equipped with iris feature processing and storage capabilities. Further, a proxy terminal can be understood as a smart IoT device that supports local storage and computing, connecting to the network and accessing an iris identity storage and authentication system.

[0037] For example, the proxy terminal can consist of three functional modules: a data engine, a comparison engine, and an MQTT CLIENT. The MQTT CLIENT is used for interactive communication with the server; the data engine receives assigned iris feature fragments from the server and stores them securely locally; the comparison engine performs feature comparison between the locally stored iris fragments and the extracted iris fragments of the comparison sample when the proxy terminal receives a comparison instruction, and returns the comparison result to the server. The server can then obtain an overall comparison judgment based on all the comparison results returned by each proxy terminal, thus completing the iris identity authentication process.

[0038] For example, a server can be a single server, a server cluster consisting of multiple servers, or a cloud computing service center.

[0039] The above embodiments describe the implementation environment of the solution provided in this application and the interaction between various devices within that environment. Based on the above embodiments, the process of the server and the proxy terminal executing the iris data storage method will be described below.

[0040] Please refer to Figure 2 The diagram illustrates a flowchart of an iris data storage method provided in an embodiment of this application. This method is applied to a server and specifically includes the following steps: Step 201: Obtain the first iris feature of the target person, split the first iris feature to obtain multiple first iris segments, and determine the agent terminal corresponding to each first iris segment.

[0041] The first iris feature refers to the raw iris feature data of the target person obtained by the server during the registration phase. It can be understood as binary data representing the iris characteristics of the target person, extracted after preprocessing, segmentation, and encoding. The first iris feature contains complete feature information of the target person's iris image.

[0042] Furthermore, the server can split the first iris feature into multiple first iris segments, which can be understood as each first iris segment retaining some feature information from the first iris feature.

[0043] Specifically, to achieve secure distributed storage of iris features, it is necessary to acquire the target individual's first iris feature and split it into multiple iris segments for distributed storage. During the registration phase, the server first acquires the target individual's iris image and extracts the first iris feature using image processing algorithms. The first iris feature is represented using binary encoding. Then, the server splits the first iris feature according to preset rules, obtaining multiple first iris segments. Simultaneously, proxy terminals are determined to store each first iris segment, ensuring that the first iris feature is distributed and stored across different proxy terminals, effectively protecting the security of the first iris feature.

[0044] Based on the above embodiments, as an optional embodiment, step 201: splitting the first iris feature to obtain multiple first iris segments, and determining the proxy terminal corresponding to each first iris segment, may further include the following steps: Step 301: Based on the data length of the first iris feature, split the first iris feature to obtain multiple first iris segments.

[0045] In one feasible implementation, the server can divide the first iris feature into multiple first iris segments of equal length according to the data length of the first iris feature.

[0046] Specifically, the server uses an equal-length segmentation method to split the first iris feature, which uniformly divides the original feature into multiple iris segments of the same length. This balanced segmentation of the first iris feature facilitates subsequent load balancing. Simultaneously, the equal-length segments also allow for a unified distribution and storage model, simplifying management and ensuring consistent storage requirements that meet the storage capabilities of most proxy terminals.

[0047] In another feasible implementation, the server can split the first iris feature into multiple first iris segments of different lengths according to the iris fragmentation algorithm, and assign different lengths to the first iris segments of different lengths.

[0048] Specifically, the server-side uses a variable-length method to segment the first iris feature, which can be divided into iris segments of different lengths according to a preset algorithm. This optimizes segment storage allocation, distributing segments of different lengths based on the storage capacity of the proxy terminal. Combined with weight settings, this also improves the accuracy of the comparison. It achieves a better balance between storage efficiency and comparison performance.

[0049] It should be noted that the server uses a variable-length method to segment the first iris feature, which can be divided into iris segments of different lengths according to a preset algorithm. Furthermore, the number of first iris segments obtained will vary depending on the iris fragmentation algorithm used.

[0050] Step 302: Divide the network into multiple virtual networks based on the number of segments of the multiple first iris segments and the network size.

[0051] A virtual network refers to multiple logically isolated network groups divided by a server according to certain rules based on network size and the number of proxy terminals. In the embodiments of this application, a virtual network can be understood as a logical grouping of proxy terminals participating in distributed iris feature storage by the server. Virtual networks are isolated from each other, and proxy terminals within a network only connect to other proxy terminals within the same virtual network.

[0052] Virtual networks can be used to guide servers in distributing fragmented iris feature data to different agent terminals for storage. By allocating feature data to isolated virtual networks, decentralized storage of biometric data can be achieved, improving data security. Furthermore, grouping agent terminals within the virtual network can improve the storage efficiency of feature data and reduce the storage burden on individual agent terminals.

[0053] Specifically, to achieve distributed storage, the server can rationally set up multiple virtual networks based on the number of available proxy terminals within the network scale. The number of virtual networks can be set to a multiple of n, where n depends on the network scale; the larger the network scale, the larger the multiple n. This allows for the creation of a sufficient number of virtual networks to correspond to all the first iris segments.

[0054] In one feasible implementation, the principle of grouping is to ensure that the number of agents in a single group does not exceed 1% of the total number of agent terminals belonging to this virtual network.

[0055] For example, if there are currently 10,000 proxy terminals, then the number of packets in each virtual network is 1% of the number of proxy terminals, i.e., 100. The server can distribute these 10,000 proxy terminals into 100 virtual networks using a modulo-remainder grouping algorithm.

[0056] This ensures that each proxy terminal stores its own iris fragments while minimizing the number of fragments that a single terminal needs to store. Since each virtual network contains only 100 proxy terminals, far fewer than the total of 10,000, this improves the efficiency of the proxy terminals in storing iris feature fragments.

[0057] Step 303: Based on the basic information of the target personnel, configure the agent terminal corresponding to each first iris segment in each virtual network, and isolate communication between each virtual network.

[0058] Specifically, after allocating the first iris fragment to each virtual network, the server needs to further determine the storage proxy terminal corresponding to each fragment. To protect user privacy, the terminal cannot be directly determined directly through the user ID. Therefore, the server can generate a proxy code based on the target user's basic information and assign the corresponding proxy terminal within the virtual network based on this code. This achieves anonymized allocation of the first iris fragment based on the user's basic information. Different users' fragments are assigned to their own different random proxy terminals, making it difficult to recover the target user's basic information from the terminal information, thus protecting user privacy. Simultaneously, since the virtual networks are logically isolated, it is impossible to directly determine which networks a person's fragment has been assigned to, further improving privacy protection.

[0059] In one feasible implementation, the basic information includes a mobile phone number, ID card number, and terminal address. Step 303, which involves configuring the proxy terminal corresponding to each first iris segment in each virtual network based on the target person's basic information, may further include the following steps: Step 401: Generate a proxy code based on the mobile phone number, ID card number, and terminal address.

[0060] Specifically, after obtaining the target person's mobile phone number, ID card number, and terminal address, the server can generate a code to identify the proxy terminal based on this information. The server can extract, concatenate, and perform operations on the numbers in the mobile phone number, ID card number, and terminal address to generate a fixed-length number sequence, which serves as the proxy code.

[0061] For example, the first three digits of the mobile phone number, the first six digits of the ID card, and the terminal MAC address are extracted and concatenated in sequence to obtain a 32-bit proxy code. Thus, the proxy code generated from the user's basic information effectively achieves anonymization based on this information. The user's real identity is difficult to deduce through the code, effectively protecting user privacy. At the same time, the standardized code length and format facilitate the subsequent designation of proxy terminals based on the code, enabling convenient configuration of proxy terminals.

[0062] Step 402: Configure each proxy terminal to the corresponding virtual network according to the proxy code and the number of each virtual network.

[0063] Specifically, the server can configure proxy codes on each proxy terminal, and then configure each proxy terminal in the corresponding virtual network according to the grouping method of the virtual network described above.

[0064] Step 202: Store each first iris segment to the corresponding proxy terminal. Each proxy terminal corresponds one-to-one with each first iris segment, and communication between each proxy terminal is isolated.

[0065] Specifically, the server stores each of the multiple first iris segments of the target person in a proxy terminal, and the various proxy terminals communicate with each other in isolation, only communicating and interacting with the server.

[0066] The above embodiments illustrate the process by which the server stores the first iris feature of the target person. Based on the above embodiments, the following will describe the process by which the server performs iris identity authentication on the target person. Specifically, this process may include the following steps: Step 501: Obtain the second iris feature when the target person performs identity authentication, split the second iris feature, and obtain multiple second iris segments.

[0067] The second iris segment refers to multiple iris feature data segments obtained by the server during the identity authentication phase of the target person's current iris image, after processing, extraction, and segmentation. In this embodiment, the second iris segment can be understood as the feature representation of the current iris sample used for comparison, which is the verification data corresponding to the first iris segment during registration.

[0068] Specifically, during the registration phase, the server has already acquired the target individual's first iris feature and stored it in a distributed manner. During authentication, the target individual needs to provide a current iris sample for verification. The server will acquire the current iris image, process it, and extract the second iris feature representing the current iris information. To compare with the first iris feature, the format of the second iris feature needs to be consistent.

[0069] Therefore, the server will split the extracted second iris features in the same way, generating multiple second iris segments. These second iris segments are consistent with the first iris segment in magnitude and format. This provides the feature data foundation for subsequent authentication.

[0070] Step 502: Send each second iris segment to the corresponding agent terminal so that each agent terminal can compare the second iris segment with the stored first iris segment and obtain the comparison result.

[0071] Specifically, after obtaining the second iris segment, the server needs to send each segment to its corresponding proxy terminal. The server can query the previous storage mapping relationship to determine the terminal corresponding to each second iris segment. Then, each segment is sent to the designated terminal. After receiving the second iris segment, the proxy terminal compares it with the first iris segment stored locally, calculates the similarity between the segments, and finally obtains the local comparison result of the segment.

[0072] Step 503: Based on the comparison results reported by each agent terminal, verify the identity of the target personnel.

[0073] Specifically, after each agent terminal completes the comparison of the first and second iris segments, it needs to send its local comparison results back to the server. The server will collect the segment-level comparison results returned by each terminal. For example, each segment returns a similarity score.

[0074] The server can integrate the returned multi-component values ​​using a data fusion algorithm (such as mean or weighted algorithm) to calculate an overall similarity score representing the comparison results of all segments. Finally, the server compares this overall score with a set threshold. If the score is higher than the threshold, the two segments are considered to be from the same person, and the identity verification is successful; if the score is lower than the threshold, the segments are considered to be from different people, and the verification fails.

[0075] The above embodiments describe the process of the server executing the iris data storage method. Based on the above embodiments, the process of the proxy terminal executing the iris data storage method will be described below. The server's execution will not be elaborated upon further; please refer to the descriptions in the above embodiments for details.

[0076] Please refer to Figure 3 This document illustrates a flowchart of another iris data storage method provided in an embodiment of this application. This method is applied to a proxy terminal and specifically includes the following steps: Step 601: In response to the data distribution instruction sent by the server, store the first iris fragment carried in the data distribution instruction. The first iris fragment is obtained by splitting the first iris feature of the target person.

[0077] The data distribution instruction refers to the data packet sent by the server to the proxy terminal for transmitting the first iris segment. In this embodiment, it can be understood as a data packet containing the first iris segment data and related control information sent by the server to a designated proxy terminal according to a distributed storage strategy. The data distribution instruction is used to distribute the iris feature segment to different proxy terminals and instruct the terminal to store the segment data.

[0078] For example, the data distribution instruction may include address information for a specific agent terminal, the first iris segment data to be transmitted, data integrity verification information, storage instructions, etc. The terminal agent can parse the data distribution instruction to perform functions such as receiving, verifying, and storing the first iris segment data.

[0079] Specifically, firstly, the agent terminal can use the server's public key to sign and verify the received first iris fragment data, verifying its integrity and accuracy, and preventing the data from being tampered with during transmission.

[0080] Then, the proxy terminal can use the SM3 symmetric encryption algorithm to encrypt the first iris segment data. The encryption key is randomly generated locally for each terminal, ensuring key independence between different terminals. This way, even if a hacker obtains the stored data, they cannot access the plaintext without knowing the key.

[0081] Finally, the proxy terminal stores the verified and encrypted first iris segment data in a local database or file medium, using persistent storage. After storage is complete, the proxy terminal can send a confirmation message to the server.

[0082] In summary, through the three processes of data verification, encryption, and persistence, the proxy terminal achieves comprehensive security control over the transmission and storage of the first iris segment, ensuring the confidentiality and integrity of biometric information.

[0083] Step 602: In response to the data comparison instruction sent by the server, obtain the second iris segment carried in the data comparison instruction, compare the first iris segment with the second iris segment to obtain the comparison result, and send the comparison result to the server so that the server can authenticate the target person's identity based on the comparison results sent by each agent terminal.

[0084] A data comparison instruction refers to a data packet sent by the server to the proxy terminal for transmitting the second iris segment. In this embodiment, the data comparison instruction can be understood as a data packet containing the second iris segment data and related control information sent by the server to a designated proxy terminal according to verification requirements. The data comparison instruction is used to distribute the current second iris segment to different proxy terminals and instruct the terminals to perform comparison verification of the stored first iris segment.

[0085] Specifically, when identity authentication is required, the server obtains the target person's current second iris image and generates multiple second iris fragments in the same manner. Then, through data comparison instructions, each second iris fragment is transmitted to the corresponding agent terminal.

[0086] After receiving the data comparison instruction, the proxy terminal extracts the first iris fragment stored locally, decrypts and compares it, calculates the similarity between the two iris fragments, and obtains the comparison result. This result is then sent back to the server. After receiving the comparison results from all proxy terminals, the server can calculate the final similarity result based on all the comparison results and determine whether the target person's identity verification is successful based on a threshold.

[0087] Reference Figure 4 This is a schematic diagram of the structure of an iris data storage device provided in an embodiment of this application. The iris data storage device includes: The first iris feature segmentation module is used to obtain the first iris feature of the target person, segment the first iris feature to obtain multiple first iris segments, and determine the agent terminal corresponding to each first iris segment. The first segment feature storage module is used to store each of the first iris segments to the corresponding proxy terminal. Each proxy terminal corresponds one-to-one with each of the first iris segments, and the proxy terminals are isolated from each other in communication.

[0088] Based on the above embodiments, the first iris feature segmentation module is further configured to segment the first iris feature according to the data length of the first iris feature to obtain multiple first iris segments; divide multiple virtual networks according to the number of segments and network scale of the multiple first iris segments; configure proxy terminals corresponding to each first iris segment in each virtual network according to the basic information of the target person, and isolate communication between each virtual network.

[0089] Based on the above embodiments, the first iris feature segmentation module is further configured to generate a proxy code based on the mobile phone number, the ID card number, and the terminal address; and to configure each proxy terminal to the corresponding virtual network based on the proxy code and the number of each virtual network.

[0090] Based on the above embodiments, the iris data storage device further includes: The first iris authentication module is used to acquire the second iris feature of the target person when performing identity authentication, split the second iris feature to obtain multiple second iris segments; send each second iris segment to a corresponding proxy terminal, so that each proxy terminal compares the second iris segment with the stored first iris segment to obtain a comparison result; and perform identity authentication on the target person based on the comparison result fed back by each proxy terminal.

[0091] Reference Figure 5 This is a schematic diagram of another iris data storage device provided in an embodiment of this application. The iris data storage device includes: The second iris fragment storage module is used to store the first iris fragment carried in the data distribution instruction sent by the server in response to the data distribution instruction. The first iris fragment is obtained by splitting the first iris feature of the target person.

[0092] The second iris authentication module is used to respond to the data comparison instruction sent by the server, obtain the second iris segment carried in the data comparison instruction; compare the first iris segment with the second iris segment to obtain the comparison result, and send the comparison result to the server so that the server can authenticate the target person based on the comparison results sent by each of the agent terminals.

[0093] It should be noted that the above embodiments of the apparatus are only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0094] This application also provides a computer storage medium that can store multiple instructions. The instructions are adapted to be loaded and executed by a processor using the iris data storage method described in the above embodiments. The specific execution process can be referred to the detailed description of the illustrated embodiments, which will not be repeated here.

[0095] This application also discloses an electronic device. (See reference...) Figure 6 , Figure 6 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of this application. The electronic device 700 may include: at least one processor 701, at least one network interface 704, a user interface 703, a memory 705, and at least one communication bus 702.

[0096] The communication bus 702 is used to enable communication between these components.

[0097] The user interface 703 may include a display interface and a camera interface. Optionally, the user interface 703 may also include a standard wired interface and a wireless interface.

[0098] The network interface 704 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0099] The processor 701 may include one or more processing cores. The processor 701 connects to various parts of the server using various interfaces and lines, and performs various server functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 705, and by calling data stored in memory 705. Optionally, the processor 701 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 701 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface graphics, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 701 and may be implemented as a separate chip.

[0100] The memory 705 may include random access memory (RAM) or read-only memory. Optionally, the memory 705 may include a non-transitory computer-readable storage medium. The memory 705 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 705 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 705 may also be at least one storage device located remotely from the aforementioned processor 701. (Refer to...) Figure 6 The memory 705, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for an iris data storage method.

[0101] exist Figure 6In the illustrated electronic device 700, the user interface 703 is mainly used to provide an input interface for the user and to acquire user input data; while the processor 701 can be used to call an application program stored in the memory 705 for an iris data storage method. When executed by one or more processors 701, the electronic device 700 performs one or more of the methods described in the above embodiments. It should be noted that, for the foregoing method embodiments, for the sake of simplicity, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0102] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0103] In the various embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some service interface; the indirect coupling or communication connection between apparatuses or units may be electrical or other forms.

[0104] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0105] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0106] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, portable hard drives, magnetic disks, or optical disks.

[0107] The above description is merely an exemplary embodiment of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Other embodiments of this disclosure will be readily apparent to those skilled in the art upon consideration of the specification and the disclosure of practical truths.

[0108] This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are to be considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.

Claims

1. A method for storing iris data, characterized in that, The iris data storage method, applied to a server, includes: Obtain the first iris feature of the target person, split the first iris feature to obtain multiple first iris segments, and determine the agent terminal corresponding to each first iris segment; Each of the first iris segments is stored in a corresponding proxy terminal, and each proxy terminal corresponds one-to-one with each of the first iris segments, and the proxy terminals are isolated from each other in communication.

2. The iris data storage method according to claim 1, characterized in that, The step of splitting the first iris feature to obtain multiple first iris segments and determining the proxy terminal corresponding to each first iris segment includes: Based on the data length of the first iris feature, the first iris feature is split into multiple first iris segments; Based on the number of segments and network size of the first iris segments, multiple virtual networks are divided; Based on the basic information of the target personnel, a proxy terminal corresponding to each of the first iris segments is configured in each of the virtual networks, and communication between the virtual networks is isolated.

3. The iris data storage method according to claim 2, characterized in that, The basic information includes a mobile phone number, ID card number, and terminal address. The step of configuring proxy terminals corresponding to each of the first iris segments in each of the virtual networks based on the target person's basic information includes: Generate a proxy code based on the mobile phone number, the ID card number, and the terminal address; Based on the proxy code and the number of each virtual network, each proxy terminal is configured into the corresponding virtual network.

4. The iris data storage method according to claim 1, characterized in that, After storing each of the first iris segments to the corresponding proxy terminal, the method further includes: The second iris feature of the target person during identity authentication is obtained, and the second iris feature is split to obtain multiple second iris segments; Each of the second iris segments is sent to the corresponding proxy terminal, so that each proxy terminal compares the second iris segment with the stored first iris segment to obtain the comparison result; Based on the comparison results returned by each of the agent terminals, the identity of the target personnel is verified.

5. A method for storing iris data, characterized in that, The iris data storage method, applicable to any one of multiple proxy terminals, wherein communication between the proxy terminals is isolated, includes: In response to a data distribution instruction sent by the server, the first iris fragment carried in the data distribution instruction is stored. The first iris fragment is obtained by splitting the first iris feature of the target person.

6. The iris data storage method according to claim 5, characterized in that, The method further includes: In response to a data comparison instruction sent by the server, the second iris segment carried in the data comparison instruction is obtained; The first iris segment is compared with the second iris segment to obtain a comparison result, and the comparison result is sent to the server so that the server can authenticate the target person based on the comparison results sent by each of the agent terminals.

7. An iris data storage device, characterized in that, include: The first iris feature segmentation module is used to obtain the first iris feature of the target person, segment the first iris feature to obtain multiple first iris segments, and determine the agent terminal corresponding to each first iris segment. The first segment feature storage module is used to store each of the first iris segments to the corresponding proxy terminal. Each proxy terminal corresponds one-to-one with each of the first iris segments, and the proxy terminals are isolated from each other in communication.

8. An iris data storage device, characterized in that, include: The second iris fragment storage module is used to store the first iris fragment carried in the data distribution instruction sent by the server in response to the data distribution instruction. The first iris fragment is obtained by splitting the first iris feature of the target person.

9. An electronic device, characterized in that, The device includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method as described in any one of claims 1-4 or 5-6.

10. A computer storage medium, characterized in that, The computer storage medium stores instructions that, when executed, perform the method as described in any one of claims 1-4 or 5-6.