Region management method and device and electronic equipment

By using biometric identification technology, the system collects and verifies users' fingerprints, voiceprints, or vein patterns using target devices. This solves the problems of low security and insufficient user experience in user access control management in financial institutions, enabling intelligent authentication management of financial institutions and improving the security and convenience of user access areas.

CN121884489APending Publication Date: 2026-04-17INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2025-12-25
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, the management of user access control areas by financial institutions suffers from low security and insufficient user experience. Physical access cards are easily lost and copied, the biometric information collection process is inflexible, and user operation is inconvenient.

Method used

Using biometric identification technology, the system collects and verifies the user's fingerprint, voiceprint, or vein features through the target device. Combined with encrypted transmission and wireless communication, it enables access control management for users entering and exiting areas.

Benefits of technology

It improves the security and user experience of user access control authentication, avoids the security risks of physical access cards, simplifies the biometric data collection process, and enhances the internal security management of financial institutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121884489A_ABST
    Figure CN121884489A_ABST
Patent Text Reader

Abstract

The invention discloses a region management method and device and electronic equipment, and relates to the field of financial science and technology, and the method comprises the steps: collecting the biological characteristics of a target user through target equipment after the authorization information of the target user is received, and obtaining the to-be-detected biological characteristics, the biological characteristics are at least one of fingerprint characteristics, voiceprint characteristics and vein characteristics; determining a target similarity between the to-be-detected biological feature and a preset biological feature through the target device; under the condition that the target similarity is greater than or equal to the preset similarity, switching the target equipment into an activated state; and performing authority authentication management on the access area of the target user through the target device in the activated state. The technical problems of low security and low user experience in authentication management of the authority of the user in and out of the area based on the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial technology, and more specifically, to a method, apparatus, and electronic device for managing a region. Background Technology

[0002] In financial institutions such as banks, it is necessary to manage users' access permissions to ensure the secure operation of the financial institution. Existing technologies have the following limitations in practical applications:

[0003] 1. Low security:

[0004] Financial institutions generally use physical access cards as identification credentials for users to enter and exit a financial area. Although this method is simple to operate, physical access cards are easy to lose and are subject to the risk of being copied, which could lead to unauthorized personnel entering sensitive areas and pose potential risks to the security management of financial institutions.

[0005] 2. Insufficient user experience:

[0006] Financial institutions can also collect users' biometric information (such as facial images) through fixed access control devices. When authenticating users who need to enter a secure area, the fixed access control device needs to take pictures of the user's face at a fixed angle. The image acquisition quality is affected by lighting and shooting distance. Users need to constantly adjust the lighting angle and shooting distance to ensure the image acquisition quality. This biometric information collection process has low flexibility, which leads to inconvenience for users and a poor user experience.

[0007] Therefore, it is evident that the existing technology of managing user access permissions to and from areas based on physical access cards suffers from low security and poor user experience.

[0008] There is currently no effective solution to the above problems. Summary of the Invention

[0009] This application provides a method, apparatus, and electronic device for area management, which at least solves the technical problems of low security and poor user experience in the authentication management of user access rights to areas based on existing technologies.

[0010] According to one aspect of this application, a region management method is provided, comprising: after receiving authorization information from a target user, collecting the target user's biometric features through a target device to obtain a biometric feature to be detected, wherein the target user is a user of a financial institution, and the biometric feature is at least one of the following: fingerprint feature, voiceprint feature, and vein feature; determining the target similarity between the biometric feature to be detected and a preset biometric feature through the target device, wherein the preset biometric feature is the biometric feature bound when the target user first uses the target device; switching the target device to an active state if the target similarity is greater than or equal to the preset similarity; and performing access authentication management for the target user's entry and exit areas through the active target device.

[0011] Optionally, the target device includes at least a feature processing module, a wireless communication module, a display and interaction module, a vibration motor, a power supply module, a processor, and a storage module. The step of collecting the biometrics of the target user through the target device to obtain the biometrics to be detected includes: collecting the biometric information of the target user through the feature processing module in the target device, wherein the biometric information is at least one of the following: fingerprint image, audio, and vein distribution image of a preset body part; denoising the biometric information through the feature processing module, and extracting features from the denoised biometric information to obtain the biometrics to be detected.

[0012] Optionally, the step of determining the target similarity between the biometric feature to be detected and preset biometric features through the target device includes: encrypting the biometric feature to be detected based on a preset algorithm to obtain the encrypted feature to be detected; transmitting the encrypted feature to be detected to a preset database of a financial institution through a preset secure channel, wherein the preset database is used to store the preset biometric features bound to the target device by L users of the financial institution for the first time, where L is a positive integer; obtaining the similarity between the biometric feature to be detected and each preset biometric feature stored in the preset database to obtain L similarities; and taking the maximum similarity among the L similarities as the target similarity.

[0013] Optionally, access control management for the target user's access area is performed through the activated target device, including: taking the distance between the target user and the access control device in the access area as a first distance; if the first distance is less than a preset distance, generating an authentication signal for the target user based on the biometric features to be detected by the target device, wherein the authentication signal is used to represent the identity of the target user; encrypting the authentication signal to obtain an encrypted authentication signal; transmitting the encrypted authentication signal to the access control device through a preset wireless communication method; decrypting the encrypted authentication signal after receiving it to obtain an authentication signal; and performing access control management for the access area based on the authentication signal.

[0014] Optionally, access control management is performed on the access area based on the authentication signal, including: determining the security level of the target user based on the authentication signal; determining the security level of the access area based on the area identifier of the access area; switching the access control device of the access area to the open state when the security level of the target user is higher than or equal to the security level of the access area; and keeping the access control device of the access area closed and generating an early warning message when the security level of the target user is lower than or equal to the security level of the access area.

[0015] Optionally, after switching the access control device in the access area to the open state, the area management method further includes: using the distance between the target user and the financial device in the access area as a second distance; if the second distance is less than a preset distance, generating a dynamic password through the target device; transmitting the dynamic password to the financial device through a preset wireless communication method; after the financial device receives the dynamic password, performing identity authentication management on the target user based on the dynamic password; and after the target user's identity authentication is successful, switching the financial device to the unlock state.

[0016] Optionally, after determining the target similarity between the biometric feature to be detected and the preset biometric feature through the target device, the area management method further includes: generating an early warning message when the target similarity is less than the preset similarity, wherein the early warning message is used to prompt the management personnel of the financial institution to perform security authentication of the user's identity.

[0017] According to another aspect of this application, an area management device is also provided, comprising: a feature acquisition unit, configured to acquire the biometric features of the target user through a target device after receiving authorization information from the target user, to obtain a biometric feature to be detected, wherein the target user is a user of a financial institution, and the biometric feature is at least one of the following: fingerprint feature, voiceprint feature, and vein feature; a target similarity determination unit, configured to determine the target similarity between the biometric feature to be detected and a preset biometric feature through the target device, wherein the preset biometric feature is the biometric feature bound when the target user first uses the target device; and a device activation unit, configured to switch the target device to an active state when the target similarity is greater than or equal to the preset similarity; and to perform access authentication management for the target user's entry and exit areas through the active target device.

[0018] According to another aspect of this application, a computer program product is also provided, which stores a computer program, wherein, when the computer program is running, it controls the computer program product to execute any of the above-mentioned area management methods.

[0019] According to another aspect of this application, an electronic device is also provided, wherein the electronic device includes one or more processors and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the region management method described above.

[0020] In this application, after receiving the authorization information of the target user, the biometric features of the target user are collected through the target device to obtain the biometric features to be detected. The target user is a user of a financial institution, and the biometric features are at least one of the following: fingerprint features, voiceprint features, and vein features. Then, this application determines the target similarity between the biometric features to be detected and preset biometric features through the target device. The preset biometric features are the biometric features bound when the target user first uses the target device. Then, if the target similarity is greater than or equal to the preset similarity, this application switches the target device to an active state and performs access authentication management for the target user's entry and exit areas through the active target device.

[0021] As can be seen from the above, this application adopts biometric identification, which collects and verifies the user's biometric features through the target device, thereby improving the management effect and user experience of user access area authorization management. This achieves the technical effect of intelligent authentication management of the internal security area of ​​financial institutions, and solves the technical problems of low security and low user experience in the authentication management of user access area authorization based on existing technology.

[0022] In other words, this application avoids the security risks of physical access cards being easily lost or copied by using the uniqueness of biometric features (such as fingerprints, voiceprints, or vein features). At the same time, this application authenticates the target user's identity through a biometric identification module integrated into the target device. Then, the target device performs permission authentication for the areas the target user needs to enter and the financial devices that need to be interacted with, simplifying the user's biometric collection process and improving the user experience. Attached Figure Description

[0023] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0024] Figure 1 This is a hardware structure block diagram of an optional computer terminal (or mobile device) for implementing a region management method according to an embodiment of this application;

[0025] Figure 2 This is a flowchart of an optional area management method according to an embodiment of this application;

[0026] Figure 3 This is a schematic diagram of an optional area management device according to an embodiment of this application;

[0027] Figure 4 This is a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0028] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0029] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0030] It should also be noted that all relevant information (including but not limited to the target user's biometric information) and data (including but not limited to data used for display and analysis) involved in this application are information and data authorized by the user or fully authorized by all parties. For example, if there is an interface between this system and the relevant user or organization, before obtaining the relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information only after receiving consent from the aforementioned user or organization.

[0031] Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of relevant information and data involved in this application all comply with the relevant laws, regulations, and standards of the relevant regions, and necessary confidentiality measures have been taken. This application does not violate public order and good morals. In addition, this application provides a corresponding operation entry point for users to choose to agree to or refuse authorization. If the user chooses to refuse authorization, the corresponding expert decision-making process will be initiated.

[0032] The present invention will now be described in detail with reference to various embodiments.

[0033] Example 1

[0034] According to an embodiment of this application, a method embodiment for area management is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0035] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, or similar computing devices. Figure 1 This is a hardware structure block diagram of an optional computer terminal (or mobile device) for implementing a region management method according to an embodiment of this application. For example... Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0036] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0037] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the area management method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned area management method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0038] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0039] The display can be configured as a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0040] Under the aforementioned operating environment, this application provides a regional management system (hereinafter referred to as the management system) for executing the regional management method of this application. Figure 2 This is a flowchart of an optional area management method according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:

[0041] Step S201: After receiving the authorization information of the target user, the target device collects the biometrics of the target user to obtain the biometrics to be detected, wherein the biometrics is at least one of the following: fingerprint features, voiceprint features, and vein features.

[0042] Optionally, the target users, specifically those working in financial institutions, whose personal information and permissions have been pre-registered in the financial system.

[0043] Optionally, the target device only initiates biometric collection upon receiving explicit authorization information, avoiding unnecessary collection of user biometric data and enhancing user privacy protection. The authorization information can be set as a simple button operation, making it easy for users to quickly start the device for identity verification and improving ease of operation.

[0044] Step S202: Determine the target similarity between the biometric feature to be detected and the preset biometric feature through the target device, wherein the preset biometric feature is the biometric feature bound when the target user first uses the target device.

[0045] Optionally, biometrics refers to physiological attributes that can uniquely identify a user. By collecting a user's biometrics, the following functions can be achieved:

[0046] (1) High-security authentication: By utilizing the uniqueness and non-replicability of biometrics, the accuracy of identity verification is improved and the system security is enhanced.

[0047] (2) Convenience: Users do not need to remember complex passwords or carry easily lost physical cards; they can complete authentication simply by using biometrics.

[0048] Optionally, preset biometrics refers to the biometric template bound by the target user during the registration process when the device is used for the first time, which is stored on the target device or in a database that can communicate remotely with the target device.

[0049] Optionally, target similarity refers to the degree of matching between the biometric feature to be detected and the preset biometric feature obtained through analysis of the target device.

[0050] Step S203: If the target similarity is greater than or equal to the preset similarity, switch the target device to the active state.

[0051] Optionally, the management system ensures that the target device will not be misidentified due to similar biometric features between different users by setting a preset similarity, thus ensuring that only the first-time authenticated and authorized user of the target device has the right to use the target device, thereby enhancing the security of the target device.

[0052] Step S204: Perform access control management for the target user's access area through the activated target device.

[0053] Optionally, by implementing access control management, user access permissions can be dynamically adjusted according to the access needs of financial institutions for different financial areas, thereby improving the level of precision in the security management of financial institutions for these areas. This mechanism can protect the sensitive areas of financial institutions from unauthorized user access.

[0054] As can be seen from the above, this application adopts biometric identification, which collects and verifies the user's biometric features through the target device, thereby improving the management effect and user experience of user access area authorization management. This achieves the technical effect of intelligent authentication management of the internal security area of ​​financial institutions, and solves the technical problems of low security and low user experience in the authentication management of user access area authorization based on existing technology.

[0055] In other words, this application avoids the security risks of physical access cards being easily lost or copied by using the uniqueness of biometric features (such as fingerprints, voiceprints, or vein features). At the same time, this application authenticates the target user's identity through a biometric identification module integrated into the target device. Then, the target device performs permission authentication for the areas the target user needs to enter and the financial devices that need to be interacted with, simplifying the user's biometric collection process and improving the user experience.

[0056] In one optional embodiment, the target device includes at least a feature processing module, a wireless communication module, a display and interaction module, a vibration motor, a power supply module, a processor, and a storage module, wherein the functions of each module are as follows:

[0057] (1) Fingerprint recognition module: used to collect and verify the wearer's fingerprint information. This module has a built-in high-precision capacitive fingerprint sensor with a resolution of 508 DPI (Dots Per Inch). It can complete fingerprint feature extraction and comparison within 0.5 seconds and perform real-time matching with the internal user fingerprint database of financial institutions through an encrypted channel. The comparison is completed through the biometric recognition system.

[0058] (2) Wireless communication module: Supports multiple communication protocols, including NFC (Near Field Communication), Bluetooth 5.0 and WiFi (Wireless Fidelity, used for data exchange and command transmission with access control systems, office equipment, servers, etc. within financial institutions. The communication distance is 0-10 cm in NFC mode, 10-50 meters in Bluetooth mode, and up to 100 meters in WiFi mode. This module can connect to a mobile phone via Bluetooth and implement other functions through a mobile office app.

[0059] (3) Display and Interaction Module: Equipped with a small OLED (Organic Light Emitting Diode) display screen (resolution of 128×64 or higher) to display information such as time, authentication status, and office sessions. Users can enter a password via touch screen or physical buttons to unlock advanced functions (such as device control permissions).

[0060] (4) Vibration Motor: Equipped with a miniature vibration motor, the vibration is controlled by the watch's processor and drive chip. The system sends signals to the motor to adjust the vibration intensity, duration or mode (such as short vibration, continuous vibration or a specific rhythm) according to notification, alarm or haptic feedback needs. When a message, call or application notification is received, the motor will trigger a short or continuous vibration to remind the wearer.

[0061] (5) Power module: Built-in high-capacity lithium battery (capacity varies from 50 to 300mAh depending on the form), supports wireless charging technology (e.g., wireless charging standard), charging time is about 1-2 hours, and battery life is 3-7 days when fully charged.

[0062] (6) Processor and storage unit: Built-in low-power microprocessor with a clock speed of up to 120MHz, responsible for coordinating the work of various modules. The storage unit includes 16MB of flash memory, used to store basic user information, fingerprint templates and temporary data.

[0063] Optionally, the management system first collects the target user's biometric information through the feature processing module in the target device. The biometric information includes at least one of the following: fingerprint image, audio, and vein distribution image of a preset body part. Then, the management system performs noise reduction processing on the biometric information through the feature processing module and extracts features from the biometric information obtained after noise reduction to obtain the biometric features to be detected.

[0064] Optionally, the feature processing module in the target device: This is a part inside the device (such as a smartwatch or ring) that is specifically responsible for the collection and processing of biometric data, including corresponding sensors (such as fingerprint sensors, microphones, and finger vein sensors) and preliminary data processing capabilities.

[0065] Optionally, biometric information, including fingerprint images, audio (voiceprint samples), and vein distribution images of preset body parts, is raw biometric data directly collected from the target user after obtaining the target user's authorization information, and is used for subsequent feature extraction and comparison.

[0066] Optionally, the feature processing module in the target device supports the collection of biometric information of different types of target users. That is, the target device is not limited to common fingerprint recognition, but also includes the collection of voiceprint and vein distribution images, which expands the scope of biometric recognition and adapts to more application scenarios.

[0067] Optionally, noise reduction refers to removing redundant or irrelevant data from the collected biometric information that may interfere with accurate identification, such as scratches and stains in fingerprint images, and environmental noise in audio signals.

[0068] Optionally, the management system performs denoising processing and feature extraction on the resulting biological information, achieving the following effects:

[0069] (1) Enhanced recognition stability: By denoising, the influence of external interference factors on biometric matching is reduced, thereby improving the stability and success rate of recognition.

[0070] (2) Accelerate the matching process: Feature extraction transforms complex biological information into feature values ​​that are easy to calculate and compare. This not only saves computing resources but also speeds up the biometric comparison process, making identity authentication faster and more efficient.

[0071] (3) Enhance anti-attack capability: Through feature extraction, the core biometric features of the target user are obtained, thereby ensuring that the subsequent biometric information processing uses biometric features rather than complete and original biometric data, which to a certain extent increases the difficulty of cracking biometric information and improves the security of user biometric information.

[0072] In summary, through the above two steps, this embodiment can extract clear and stable biometric features to be detected from the collected biometric information, thus providing a solid foundation for subsequent comparison and identity verification. This not only ensures the accuracy and speed of identity authentication but also enhances the security protection capabilities of the financial system and provides reliable technical support for the regional management of financial institutions.

[0073] In one optional embodiment, the management system first encrypts the biometric feature to be detected based on a preset algorithm to obtain the encrypted feature to be detected. Then, the management system transmits the encrypted feature to be detected to a preset database of the financial institution through a preset secure channel. The preset database is used to store the preset biometric features bound to the target device by L users of the financial institution for the first time, where L is a positive integer. Then, the management system obtains the similarity between the biometric feature to be detected and each preset biometric feature stored in the preset database to obtain L similarities. Finally, the management system takes the maximum similarity among the L similarities as the target similarity.

[0074] Optionally, the preset algorithm can be set to AES (Advanced Encryption Standard, a symmetric encryption algorithm) or RSA (Rivest Shamir Adleman, an asymmetric encryption algorithm) to protect the security of biometric data during transmission.

[0075] Optionally, the management system encrypts the biometric features to be detected according to a preset algorithm, which has the following functions:

[0076] (1) Data security: Encryption ensures the confidentiality of biometric data during transmission. Even if the data is intercepted in the middle, attackers cannot directly interpret and use it.

[0077] (2) Privacy protection: The encrypted data is difficult to reverse engineer and can effectively prevent the leakage of personal biometric information and comply with data protection regulations.

[0078] Optionally, a pre-defined secure channel refers to a communication path that uses a secure protocol (such as TLS / SSL (Transport Layer Security) or a dedicated encrypted network to ensure that data transmission is not accessed or tampered with without authorization.

[0079] Optionally, a preset database, i.e., a central database used by financial institutions to store the preset biometrics of all users' first-time binding of target devices.

[0080] Optionally, the management system transmits the encrypted features to be detected to a pre-set database of the financial institution through a pre-set secure channel, which has the following functions:

[0081] (1) Centralized management: The existence of the pre-set database makes the management of biometric data more centralized, and facilitates unified permission settings and data maintenance.

[0082] (2) High-speed comparison: The preset database can quickly retrieve and compare the user's biometric features by preloading the user's biometric features, thereby improving the response speed of identity verification.

[0083] Optionally, by using the maximum similarity among L similarities as the target similarity, the management system can effectively distinguish the most likely matching object, avoiding the uncertainty of multiple matching. Furthermore, the device will only enter the activation state when the target similarity reaches a preset minimum threshold, which further enhances the security and accuracy of the system and prevents the possibility of false activation.

[0084] In summary, the management system achieves efficient and secure verification of user biometrics through encrypted transmission, centralized database management, and multi-factor comparison, which not only protects personal privacy but also enhances the security of user identity authentication operations.

[0085] In one optional embodiment, the management system first uses the distance between the target user and the access control device in the access area as a first distance. If the first distance is less than a preset distance, the management system generates an authentication signal for the target user based on the biometric features to be detected by the target device. The authentication signal is used to represent the identity of the target user. Then, the management system encrypts the authentication signal to obtain an encrypted authentication signal. After that, the management system transmits the encrypted authentication signal to the access control device through a preset wireless communication method. After the access control device receives the encrypted authentication signal, the management system decrypts the encrypted authentication signal to obtain an authentication signal. Finally, the management system performs access control management for the access area based on the authentication signal.

[0086] Optionally, the authentication signal refers to a signal generated based on the biometric features to be detected and used to identify the user to the access control device. The authentication signal contains the identity identifier of the target user.

[0087] Optionally, the management system automatically generates an authentication signal when the target device approaches the access control device, eliminating the need for manual operation by the user and improving the convenience of authenticating access to the area the user needs to enter.

[0088] Optionally, the management system encrypts the authentication signal to obtain an encrypted authentication signal, thereby ensuring the security of data during transmission and preventing information from being intercepted and cracked. The application of encryption technology ensures the confidentiality of the authentication signal during transmission, avoids security risks caused by eavesdropping on the authentication signal, and improves the security of user access control authentication.

[0089] Optionally, the preset wireless communication method refers to communication methods such as NFC, Bluetooth, or WiFi. The management system transmits encrypted authentication signals to the access control device through the preset wireless communication method, which has the following functions:

[0090] (1) High-efficiency communication: The choice of wireless communication technology ensures fast data transmission and shortens the total time for target user authentication.

[0091] (2) Flexible deployment: It supports multiple wireless communication methods to adapt to different scenario requirements. For example, NFC is suitable for fast authentication at close range, while Bluetooth or WiFi performs better at medium and long distances and in complex environments.

[0092] Optionally, after the access control device receives the encrypted authentication signal, the management system decrypts the encrypted authentication signal to obtain the authentication signal, which has the following functions:

[0093] (1) Protecting data integrity: The access control device can only decrypt the encrypted authentication signal with the correct algorithm key, which ensures the integrity of the data and prevents the use of false authentication signals.

[0094] (2) Seamless integration: The overall decryption process is fast and has a high degree of integration with the access control system, ensuring a smooth identity authentication process.

[0095] Optionally, the management system implements access control for users by performing access authentication management based on authentication signals. The management system can flexibly set access permissions for different financial areas according to the user's role and task. This management method based on user identity and permissions ensures that employees can only access the financial areas within their scope of responsibility, thereby improving the security of financial institutions.

[0096] In one optional embodiment, the management system first determines the security level of the target user based on the authentication signal. Then, the management system determines the security level of the access area based on the area identifier of the access area. If the security level of the target user is higher than or equal to the security level of the access area, the management system switches the access control device of the access area to the open state. If the security level of the target user is lower than or equal to the security level of the access area, the management system keeps the access control device of the access area closed and generates an early warning message.

[0097] Optionally, the authentication signal refers to a signal generated based on the biometric features to be detected and used to identify the user to the access control device. The authentication signal contains the identity identifier of the target user.

[0098] Optionally, the security level refers to a numerical label assigned to a user or financial area. The security level represents the user's access permissions and the area's security level. The user's security level can be dynamically adjusted based on multiple factors such as the user's role (e.g., ordinary employee, manager), job responsibilities, and historical behavior records. The security level of the financial area can be dynamically adjusted based on multiple factors such as the financial products stored in the area and historical events that have occurred in the area.

[0099] Optionally, access control equipment refers to electronic door locks or turnstiles installed at various entrances and exits of the financial area to control the entry and exit of personnel.

[0100] Optionally, the management system compares the security levels of users and areas to ensure that only users with sufficient permissions can enter the corresponding areas, thereby achieving automated and intelligent access control and improving the efficiency of security management of financial institutions' financial areas.

[0101] Optionally, if the security level of the target user is lower than or equal to the security level of the access area, the management system keeps the access control device in the access area closed and generates an early warning message. This mechanism strengthens the security measures of the financial area. When the user attempting to access the area does not have sufficient permissions, not only will the access control device not be opened, but the early warning system will also be automatically triggered to warn the security team that an unauthorized user is attempting to access the area. This helps to respond promptly and prevent potential security threats, such as preventing unauthorized personnel from entering high-security areas.

[0102] In one optional embodiment, the management system first uses the distance between the target user and the financial device in the access area as a second distance. Then, if the second distance is less than a preset distance, the management system generates a dynamic password through the target device. The management system then transmits the dynamic password to the financial device through a preset wireless communication method. After the financial device receives the dynamic password, the management system performs identity authentication management on the target user based on the dynamic password. After the target user's identity authentication is successful, the management system switches the financial device to the unlocked state.

[0103] Optionally, the preset distance refers to the effective range within which a target device (such as a smartwatch or ring) and a financial device (such as a bank's internal computer or safe) can trigger the generation of a dynamic password.

[0104] Optionally, the dynamic password is generated only when the target device is near the financial device, and it is valid for one use only within its validity period, after which it becomes invalid.

[0105] Optionally, if the distance between the target user wearing the target device and the financial device is less than a preset distance, the management system generates a dynamic password through the target device, adding a dynamic element for subsequent user authentication. Even if a highly accurate biometric feature is stolen by an attacker, authentication cannot be completed without the attacker generating a dynamic password in real time, thereby improving the security of the financial device.

[0106] Optionally, the management system transmits the dynamic password to the financial device via a preset wireless communication method, which has the following functions:

[0107] (1) Fast transmission: Wireless communication technology allows dynamic passwords to be transmitted from the target device to the financial device in an instant, reducing potential interception opportunities.

[0108] (2) Non-contact certification: Certification can be completed without physical contact, which improves the convenience of operation and hygiene standards, and is especially important in the current environment of enhanced public health awareness.

[0109] Optionally, after receiving the dynamic password, the financial device performs identity authentication management on the target user based on the dynamic password, and switches the financial device to the unlocked state after the target user's identity authentication is successful, which has the following functions:

[0110] (1) Dual authentication: The dual authentication mechanism combining dynamic passwords and biometrics significantly improves the security level of access control and reduces the risk of single authentication methods being cracked.

[0111] (2) Instant response: The authentication process is fast. Once the authentication is successful, the financial device immediately enters the unlocked state, reducing waiting time and improving work efficiency.

[0112] (3) Access control: Through identity authentication management, the access rights of target users to specific financial devices can be precisely controlled. For example, only designated users are allowed to operate high-value safes or access sensitive information systems, which enhances internal control and management efficiency.

[0113] In summary, the management system improves the security, immediacy, and convenience of access control for internal devices in financial institutions by combining dynamic passwords with biometric recognition and real-time, contactless authentication supported by wireless communication technology.

[0114] In one optional embodiment, after determining the target similarity between the biometric feature to be detected and the preset biometric feature through the target device, the management system generates an early warning message if the target similarity is less than the preset similarity. The early warning message is used to prompt the management personnel of the financial institution to perform security authentication of the target user's identity.

[0115] Optionally, if the target similarity is less than a preset similarity, an early warning message is generated, which has the following functions:

[0116] (1) Enhanced security: By setting a preset similarity, the management system can issue a timely warning when the biometric recognition results are not accurate enough, thus avoiding security vulnerabilities caused by misidentification.

[0117] (2) Proactive risk prevention and control: The generation of early warning information enables managers to intervene in a timely manner and manually review the authentication failure events, thereby strengthening risk control over the user's entry and exit areas.

[0118] (3) Improve management response capability: The early warning mechanism triggers the immediate response of management personnel, which can quickly handle authentication anomalies and reduce the potential threat of users forcibly breaking in.

[0119] (4) Improve audit trail: Each generated warning message will be recorded in the log. These log records can be used for subsequent audits and event tracking, helping financial institutions to improve their security management processes and strategies.

[0120] In summary, this embodiment enhances the security and management response of biometric-based smart devices by introducing an early warning mechanism. This mechanism not only effectively prevents user identity theft but also improves the security management level of user access areas through proactive risk prevention and control.

[0121] Optionally, in the above embodiments, the target device can be configured as a smartwatch, with the following structural design:

[0122] The target device is in the form of a smart bracelet, with a watch face diameter of approximately 40mm and a thickness of approximately 10mm. The case is made of stainless steel or aluminum alloy, and the strap is made of silicone or leather. A fingerprint sensor (approximately 10mm x 10mm) is located on the front of the watch face, below which is a 1.3-inch OLED touchscreen with a resolution of 240 x 240 pixels. Other target devices in the smart bracelet form include:

[0123] NFC module: Supports the 13.56MHz band for access control unlocking and device linkage.

[0124] Bluetooth module: Supports Bluetooth 5.0 for connecting to mobile phones or computers.

[0125] WiFi module: Supports the 2.4GHz band for data upload.

[0126] Battery: 300mAh capacity, supports wireless charging, and lasts for about 7 days.

[0127] Fingerprint sensor: Used to collect fingerprints and related data.

[0128] Optionally, in the above embodiments, the target device can also be configured as a smart ring, with the following structural design:

[0129] The target device is ring-shaped, with an inner diameter ranging from 16-22mm (customizable), made of titanium alloy or ceramic, weighing approximately 5g. The fingerprint sensor is located on the inner ring (approximately 8mm x 8mm), authenticating via contact reading. The ring integrates the following components:

[0130] Miniature NFC chip: Supports access control unlocking and linkage with financial devices.

[0131] Bluetooth module: Supports low-power communication.

[0132] Battery: 50mAh capacity, with an ultra-low power consumption design, providing approximately 3 days of battery life.

[0133] Finger vein sensor: Used to collect the user's finger vein information.

[0134] Optionally, the target device can also be configured as a hybrid form (watch + ring linkage). By combining the advantages of a watch and a ring, the bracelet acts as the main device, responsible for display and complex calculations, while the ring acts as an auxiliary device, responsible for quick authentication. The two pair via Bluetooth and work together to become a single target device.

[0135] As can be seen from the above, this application adopts biometric identification, which collects and verifies the user's biometric features through the target device, thereby improving the management effect and user experience of user access area authorization management. This achieves the technical effect of intelligent authentication management of the internal security area of ​​financial institutions, and solves the technical problems of low security and low user experience in the authentication management of user access area authorization based on existing technology.

[0136] In other words, this application avoids the security risks of physical access cards being easily lost or copied by using the uniqueness of biometric features (such as fingerprints, voiceprints, or vein features). At the same time, this application authenticates the target user's identity through a biometric identification module integrated into the target device. Then, the target device performs permission authentication for the areas the target user needs to enter and the financial devices that need to be interacted with, simplifying the user's biometric collection process and improving the user experience.

[0137] Example 2

[0138] This application embodiment can also provide a region management device. It should be noted that the region management device of this application embodiment can be used to execute the region management method provided in this application embodiment. The region management device provided in this application embodiment is described below.

[0139] According to an embodiment of this application, an apparatus for implementing the above-described area management method is also provided. Figure 3 This is a schematic diagram of an optional area management device according to an embodiment of this application, such as... Figure 3 As shown, the device includes: a feature acquisition unit 301, a target similarity determination unit 302, a device activation unit 303, and an authorization authentication unit 304.

[0140] Optionally, the feature acquisition unit 301 is used to acquire the biometric features of the target user through the target device after receiving the authorization information of the target user, and obtain the biometric features to be detected, wherein the biometric features are at least one of the following: fingerprint features, voiceprint features, and vein features; the target similarity determination unit 302 is used to determine the target similarity between the biometric features to be detected and the preset biometric features through the target device, wherein the preset biometric features are the biometric features bound when the target user first uses the target device; the device activation unit 303 is used to switch the target device to an active state when the target similarity is greater than or equal to the preset similarity; and the permission authentication unit 304 is used to perform permission authentication management for the target user's access area through the active target device.

[0141] In one optional embodiment, the target device includes at least a feature processing module, a wireless communication module, a display and interaction module, a vibration motor, a power supply module, a processor, and a storage module. The feature acquisition unit includes a biometric acquisition subunit and a biometric processing subunit.

[0142] Optionally, the biometric acquisition subunit is used to acquire the biometric information of the target user through the feature processing module in the target device, wherein the biometric information is at least one of the following: fingerprint image, audio, and vein distribution image of a preset body part; the biometric processing subunit is used to denoise the biometric information through the feature processing module, and to extract features from the denoised biometric information to obtain the biometric feature to be detected.

[0143] In an optional embodiment, the target similarity determination unit 302 includes: a feature encryption subunit, a feature transmission subunit, a similarity acquisition subunit, and a target similarity determination subunit.

[0144] Optionally, the feature encryption subunit is used to encrypt the biometric feature to be detected based on a preset algorithm to obtain the encrypted feature to be detected; the feature transmission subunit is used to transmit the encrypted feature to be detected to a preset database of a financial institution through a preset secure channel, wherein the preset database is used to store the preset biometric features bound to the target device by L users of the financial institution for the first time, where L is a positive integer; the similarity acquisition subunit is used to obtain the similarity between the biometric feature to be detected and each preset biometric feature stored in the preset database to obtain L similarities; and the target similarity determination subunit is used to take the maximum similarity among the L similarities as the target similarity.

[0145] In one optional embodiment, the device activation unit 303 includes: a distance determination subunit, an authentication signal generation subunit, an authentication signal encryption subunit, an authentication signal transmission subunit, an authentication signal decryption subunit, and an authorization authentication subunit.

[0146] Optionally, the distance determination subunit is used to take the distance between the target user and the access control device in the access area as a first distance; the authentication signal generation subunit is used to generate an authentication signal for the target user based on the biometric features to be detected by the target device when the first distance is less than a preset distance, wherein the authentication signal is used to represent the identity of the target user; the authentication signal encryption subunit is used to encrypt the authentication signal to obtain an encrypted authentication signal; the authentication signal transmission subunit is used to transmit the encrypted authentication signal to the access control device through a preset wireless communication method; the authentication signal decryption subunit is used to decrypt the encrypted authentication signal after the access control device receives it to obtain an authentication signal; and the access control authentication subunit is used to perform access control authentication management for the access area based on the authentication signal.

[0147] In one optional embodiment, the access control authentication subunit includes: a first-level determination module, a second-level determination module, an access control opening module, and an access control early warning module.

[0148] Optionally, the first-level determination module is used to determine the security level of the target user based on the authentication signal; the second-level determination module is used to determine the security level of the entry / exit area based on the area identifier of the entry / exit area; the access control opening module is used to switch the access control device of the entry / exit area to the open state when the security level of the target user is higher than or equal to the security level of the entry / exit area; and the access control warning module is used to keep the access control device of the entry / exit area in the closed state and generate warning information when the security level of the target user is lower than or equal to the security level of the entry / exit area.

[0149] In one optional embodiment, the authorization authentication subunit further includes: a distance determination module, a password generation module, a password transmission module, a device authentication module, and an unlocking module.

[0150] Optionally, the distance determination module is used to determine the distance between the target user and the financial device in the access area as a second distance; the password generation module is used to generate a dynamic password through the target device when the second distance is less than a preset distance; the password transmission module is used to transmit the dynamic password to the financial device through a preset wireless communication method; the device authentication module is used to perform identity authentication management on the target user based on the dynamic password after the financial device receives it; and the unlocking module is used to switch the financial device to the unlocked state after the target user's identity authentication is successful.

[0151] In an optional embodiment, the target similarity determination unit 302 further includes an information interaction management subunit.

[0152] Optionally, the information interaction management subunit is used to generate early warning information when the target similarity is less than a preset similarity. The early warning information is used to prompt the management personnel of the financial institution to perform security authentication of the target user's identity.

[0153] As can be seen from the above, this application adopts biometric identification, which collects and verifies the user's biometric features through the target device, thereby improving the management effect and user experience of user access area authorization management. This achieves the technical effect of intelligent authentication management of the internal security area of ​​financial institutions, and solves the technical problems of low security and low user experience in the authentication management of user access area authorization based on existing technology.

[0154] In other words, this application avoids the security risks of physical access cards being easily lost or copied by using the uniqueness of biometric features (such as fingerprints, voiceprints, or vein features). At the same time, this application authenticates the target user's identity through a biometric identification module integrated into the target device. Then, the target device performs permission authentication for the areas the target user needs to enter and the financial devices that need to be interacted with, simplifying the user's biometric collection process and improving the user experience.

[0155] It should be noted that the feature acquisition unit 301, target similarity determination unit 302, and device activation unit 303 mentioned above correspond to steps S201 to S203 in the method embodiment. The instances and application scenarios implemented by the above units and corresponding steps are the same, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of the device and run in the computer terminal 10 provided in the embodiment.

[0156] Example 3

[0157] Embodiments of this application can also provide an electronic device. Figure 4 This is a structural block diagram of an electronic device according to an embodiment of this application, such as... Figure 4 As shown, the electronic device includes: one or more ( Figure 4 (Only one is shown) Processor 402, memory 404, memory controller, and peripheral interface, wherein the peripheral interface is connected to the radio frequency module, audio module and display.

[0158] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and devices in the embodiments of this application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the above-mentioned area management method.

[0159] The memory may include high-speed random access memory (RAM), and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, which can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks (LANs), mobile communication networks, and combinations thereof.

[0160] The processor can access information and applications stored in the memory via a transmission device to perform the following steps: After receiving authorization information from the target user, the processor collects the target user's biometrics through the target device to obtain the biometrics to be detected, wherein the target user is a user of a financial institution, and the biometrics are at least one of the following: fingerprint features, voiceprint features, and vein features; the processor determines the target similarity between the biometrics to be detected and preset biometrics through the target device, wherein the preset biometrics are the biometrics bound when the target user first uses the target device; if the target similarity is greater than or equal to the preset similarity, the processor switches the target device to an active state; and the processor performs access authentication management for the target user's entry and exit areas through the active target device.

[0161] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: collect the biometric information of the target user through the feature processing module in the target device, wherein the biometric information is at least one of the following: fingerprint image, audio, vein distribution image of a preset body part; perform noise reduction processing on the biometric information through the feature processing module, and extract features from the biometric information obtained by noise reduction processing to obtain the biometric feature to be detected.

[0162] The processor can access information and applications stored in the memory via a transmission device to perform the following steps: encrypting the biometric feature to be detected based on a preset algorithm to obtain the encrypted feature to be detected; transmitting the encrypted feature to be detected to a preset database of a financial institution through a preset secure channel, wherein the preset database is used to store the preset biometric features bound to the target device by L users of the financial institution for the first time, where L is a positive integer; obtaining the similarity between the biometric feature to be detected and each preset biometric feature stored in the preset database to obtain L similarities; and taking the maximum similarity among the L similarities as the target similarity.

[0163] The processor can access the information and application programs stored in the memory via a transmission device to perform the following steps: taking the distance between the target user and the access control device in the access area as a first distance; if the first distance is less than a preset distance, generating an authentication signal for the target user based on the biometric features to be detected by the target device, wherein the authentication signal is used to represent the identity of the target user; encrypting the authentication signal to obtain an encrypted authentication signal; transmitting the encrypted authentication signal to the access control device via a preset wireless communication method; decrypting the encrypted authentication signal after receiving it to obtain an authentication signal; and performing access control management for the access area based on the authentication signal.

[0164] The processor can access the information and application programs stored in the memory via the transmission device to perform the following steps: determine the security level of the target user based on the authentication signal; determine the security level of the access area based on the area identifier of the access area; switch the access control device of the access area to the open state if the security level of the target user is higher than or equal to the security level of the access area; and keep the access control device of the access area closed and generate an early warning message if the security level of the target user is lower than or equal to the security level of the access area.

[0165] The processor can access information and applications stored in the memory via a transmission device to perform the following steps: taking the distance between the target user and the financial device in the access area as a second distance; if the second distance is less than a preset distance, generating a dynamic password through the target device; transmitting the dynamic password to the financial device via a preset wireless communication method; after receiving the dynamic password, the financial device performs identity authentication management based on the dynamic password; after the target user's identity authentication is successful, switching the financial device to the unlocked state.

[0166] The processor can access the information and application stored in the memory via the transmission device to perform the following steps: generating an early warning message when the target similarity is less than a preset similarity, wherein the early warning message is used to prompt the management personnel of the financial institution to perform security authentication of the target user's identity.

[0167] This application provides a regional management solution. In this application, biometric identification is used to collect and verify the user's biometric features through a target device in the form of a wristband or ring. This improves the security and efficiency of user access control, thereby achieving the technical effect of intelligent security management of the internal areas of financial institutions. It also solves the technical problems of low security and low user experience in the authentication management of user access control based on existing technologies.

[0168] In other words, this application utilizes the uniqueness of biometric features (such as fingerprints, voiceprints, or vein patterns) to avoid the security risks of physical access cards being easily lost or copied. At the same time, this application authenticates the target user's identity through a biometric identification module integrated into the target device. Then, the target device authenticates the area that the target user needs to enter. The target user does not need to carry multiple physical cards, thereby simplifying the user's operation process and improving the efficiency of managing the user's access permissions.

[0169] Those skilled in the art will understand that Figure 4 The structure shown is for illustrative purposes only. Electronic devices can also be smartphones, tablets, PDAs, mobile internet devices, PADs, and other terminal devices. Figure 4 This does not limit the structure of the aforementioned electronic device. For example, electronic devices may also include components that are more... Figure 4 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 4 The different configurations shown.

[0170] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0171] Example 4

[0172] Embodiments of this application may also provide a storage medium.

[0173] Optionally, in this embodiment of the application, the storage medium can be used to store the program code executed by the region management method provided in the above method embodiment.

[0174] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.

[0175] This application also provides a computer program product that, when executed on a data processing device, is suitable for performing the steps of a region management method.

[0176] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0177] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0178] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0179] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0180] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0181] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0182] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A zone management method characterized by, include: After receiving authorization information from the target user, the target user's biometrics are collected through the target device to obtain the biometrics to be detected, wherein the biometrics is at least one of the following: Fingerprint features, voiceprint features, and vein features; The target similarity between the biometric feature to be detected and the preset biometric feature is determined by the target device, wherein the preset biometric feature is the biometric feature bound by the target user when first using the target device; If the target similarity is greater than or equal to a preset similarity, the target device will be switched to an active state. The target device in the activated state performs access control management for the target user's entry and exit areas.

2. The area management method according to claim 1, characterized by, The target device includes at least a feature processing module, a wireless communication module, a display and interaction module, a vibration motor, a power supply module, a processor, and a storage module. It collects the biometrics of the target user to obtain the biometrics to be detected, including: The biometric information of the target user is collected through the feature processing module in the target device, wherein the biometric information is at least one of the following: Fingerprint images, audio, and vein distribution images of preset body parts; The biological information is denoised by the feature processing module, and features are extracted from the denoised biological information to obtain the biological features to be detected.

3. The area management method according to claim 2, characterized by, Determining the target similarity between the biometric feature to be detected and a preset biometric feature using the target device includes: The biometric features to be detected are encrypted based on a preset algorithm to obtain the encrypted features to be detected. The encrypted features to be detected are transmitted to a preset database of a financial institution through a preset secure channel. The preset database is used to store the preset biometric features bound to the target device by L users of the financial institution when they first use the target device, where L is a positive integer. Obtain the similarity between the biometric feature to be detected and each preset biometric feature stored in the preset database to obtain L similarity values; The maximum similarity among the L similarities is taken as the target similarity.

4. The area management method according to claim 1, characterized by, Access control management for the target user's entry and exit areas via the activated target device includes: The distance between the target user and the access control device in the access area is taken as the first distance; When the first distance is less than a preset distance, the target device generates an authentication signal for the target user based on the biometric features to be detected, wherein the authentication signal is used to characterize the identity of the target user; The authentication signal is encrypted to obtain an encrypted authentication signal; The encrypted authentication signal is transmitted to the access control device via a preset wireless communication method; After receiving the encrypted authentication signal, the access control device decrypts the encrypted authentication signal to obtain the authentication signal; Based on the authentication signal, access control is performed on the entry and exit area.

5. The area management method according to claim 4, characterized by, Based on the authentication signal, access control is performed on the entry / exit area, including: Based on the authentication signal, the security level of the target user is determined; The security level of the entry / exit area is determined based on the area identifier of the entry / exit area; If the security level of the target user is higher than or equal to the security level of the access area, the access control device of the access area will be switched to the open state. If the security level of the target user is lower than or equal to the security level of the access area, the access control device of the access area shall remain closed, and an early warning message shall be generated.

6. The area management method according to claim 5, characterized by, After switching the access control equipment in the access area to the open state, the area management method further includes: The distance between the target user and the financial equipment in the access area is used as the second distance; If the second distance is less than the preset distance, a dynamic password is generated by the target device; The dynamic password is transmitted to the financial device via a preset wireless communication method; After receiving the dynamic password, the financial device performs identity authentication management on the target user based on the dynamic password. After the target user's identity is successfully authenticated, the financial device is switched to the unlocked state.

7. The area management method according to claim 5, characterized by, After determining the target similarity between the biometric feature to be detected and the preset biometric feature through the target device, the region management method further includes: If the target similarity is less than the preset similarity, the warning information is generated, wherein the warning information is used to prompt the management personnel of the financial institution to perform security authentication of the target user's identity.

8. A zone management device, characterized by, include: The feature acquisition unit is configured to acquire the biometric features of the target user through the target device after receiving the authorization information of the target user, and obtain the biometric features to be detected, wherein the biometric features are at least one of the following: Fingerprint features, voiceprint features, and vein features; A target similarity determination unit is used to determine the target similarity between the biometric feature to be detected and a preset biometric feature through the target device, wherein the preset biometric feature is the biometric feature bound by the target user when first using the target device; The device activation unit is used to switch the target device to an active state when the target similarity is greater than or equal to a preset similarity. The access authentication unit is used to perform access authentication management for the target user's access area through the target device in the activated state.

9. A computer program product, characterised in that, The computer program product includes a computer program, wherein, when the computer program is executed, it controls the computer program product to perform the area management method according to any one of claims 1 to 7.

10. An electronic device, comprising: It includes one or more processors and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the region management method according to any one of claims 1 to 7.