Privacy protection video authentication system based on earth clone scale model

By embedding a distributed chip with a proportional model of Earth clones into the terminal device, the problems of privacy data leakage and rigid compliance strategies in video authentication schemes have been solved, realizing a globally compliant and privacy-protected video authentication system that supports efficient and reliable operation of cross-border businesses.

CN121887408APending Publication Date: 2026-04-17玺链科技有限公司 +3
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
玺链科技有限公司
Filing Date
2026-02-15
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing video authentication solutions have the risk of privacy data leakage and the inability to dynamically adjust compliance strategies based on geographical location, making it difficult to meet the legal and regulatory requirements of various regions worldwide and protect user privacy.

Method used

The distributed chip, which adopts the Earth clone scale model, is internally configured with multiple secure execution environments. Each environment is bound to compliance policies and keys by one or more governance entities. Privacy enhancement processing is performed through the video processing unit to generate authentication credentials, which are then digitally signed by the signing unit to ensure that data processing is completed within the hardware boundary.

Benefits of technology

It enables automatic loading of compliance policies based on terminal location, ensuring that data does not leave the country, meeting local laws and regulations, providing a reliable foundation for cross-border collaboration, eliminating the risk of privacy leaks, and supporting efficient compliance for cross-departmental and cross-border businesses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887408A_ABST
    Figure CN121887408A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection video authentication system, which comprises a distributed chip of an earth clone scale model, a plurality of mutually isolated secure execution environments are configured in the distributed chip, each secure execution environment is associated with one or more external governance entities, and each external governance entity is associated with one or more external governance entities. A compliance strategy set and a cryptographic key which are defined or authorized by the governance entity are stored in the management entity; the video processing unit runs in the specific secure execution environment and is used for receiving an original video data stream and executing privacy enhancement processing on the original video data stream according to a compliance strategy set associated with the secure execution environment so as to generate an authentication credential not including original video data; and the signature unit runs in a distributed chip of the earth clone scale model and is used for digitally signing the authentication credential by using a cryptographic key associated with the secure execution environment to generate a signature credential with a governance attribute for verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically to a digital identity authentication system. Background Technology

[0002] With the globalization of the digital economy, applications such as video-based facial recognition, remote account opening, and cross-border payments are becoming increasingly common. However, these highly sensitive businesses face two fundamental challenges: the risk of personal privacy data leakage and compliance conflicts with differing laws and regulations in various regions of the world.

[0003] In existing technologies, mainstream video authentication schemes typically rely on the operating system and applications of terminal devices (such as smartphones). The typical process is as follows: the terminal camera captures the raw video stream → it is uploaded to a cloud server via the operating system's Application Programming Interface (API) → the server performs face detection, liveness detection, and feature comparison in the background. This "raw data to the cloud" model poses serious privacy risks. Once the cloud server is attacked or internal personnel abuse their privileges, massive amounts of users' raw biometric data face the risk of large-scale leakage. This contradicts the principles of "data minimization" and "local processing" advocated by regulations such as the EU's General Data Protection Regulation (GDPR) and the Personal Information Protection Law of the People's Republic of China.

[0004] Existing solutions cannot dynamically switch compliance policies based on the device's real-time geographic location or jurisdiction. For example, the same app might comply with the GDPR's requirement to prohibit the uploading of raw facial images within the EU, while in other regions it might allow the uploading of feature vectors. Existing solutions lack a mechanism to detect such geographic location changes and automatically adjust their behavior. Current solutions typically obtain device location information through the operating system's location service API. When users actively disable this service for privacy reasons, existing solutions cannot obtain location information, preventing the correct activation of the corresponding compliance policy and rendering the entire compliance system ineffective.

[0005] Furthermore, in cross-border business scenarios, different countries and regions have drastically different legal requirements for the collection, storage, use, and transmission of personal information (especially biometric information). For example, some regions are designated as "high-risk areas" by financial regulators, requiring stricter identity verification and audit trails for transactions occurring within those regions. Current technology lacks an architecture that can hardware-level bind geographical sovereignty in the physical world with data processing rules in the digital world, making it difficult for companies to provide a unified solution globally that meets local compliance requirements while protecting user privacy.

[0006] Therefore, there is an urgent need for a brand-new technical architecture that can deeply integrate geolocation, compliance policies and privacy protection capabilities from the hardware level, so as to achieve "doing things according to the rules wherever you are" and ensure that the most sensitive raw data never leaves the trusted hardware boundary.

[0007] It should be noted that the above description of the technical background is only for the purpose of providing a clear and complete explanation of the technical solutions of the present invention and facilitating understanding by those skilled in the art. It should not be assumed that the above technical solutions are known to those skilled in the art simply because they have been described in the background section of this invention. Summary of the Invention

[0008] The purpose of this invention is to overcome the shortcomings of the prior art and provide a privacy-preserving video authentication system and method based on the Earth clone scale model.

[0009] This invention discloses a privacy-preserving video authentication system, comprising: a distributed chip based on an Earth clone scale model, internally configured with multiple isolated secure execution environments, each of which is associated with one or more external governance entities and stores a set of compliance policies defined or authorized by the governance entity and a hardware-protected cryptographic key; a video processing unit, operating within a specific secure execution environment of the distributed chip based on the Earth clone scale model, for receiving raw video data streams and performing privacy enhancement processing on the raw video data streams according to the set of compliance policies associated with the secure execution environment, to generate authentication credentials that do not include the raw video data; and a signature unit, operating within the distributed chip based on the Earth clone scale model, for digitally signing the authentication credentials using the cryptographic key associated with the specific secure execution environment, generating a signature credential with governance attributes for verification.

[0010] Furthermore, the aforementioned video processing unit executes a dynamic privacy algorithm to control the risk of privacy leakage. This dynamic privacy algorithm calculates and allocates a differential privacy budget E for this video processing based on the set of compliance policies associated with the current secure execution environment. The calculation formula is as follows:

[0011] (Equation 1)

[0012] In the formula, E base Let Wi be the default base privacy budget, where Wi is the quantified value of the i-th sensitivity metric in the compliance policy set, and Si be the corresponding weighting coefficient.

[0013] (Equation 2)

[0014] Furthermore, the aforementioned video processing unit executes a privacy enhancement algorithm to perform privacy enhancement processing. The video processing unit employs an adaptive desensitization equation based on semantic segmentation to generate desensitized frames. The equation is defined as:

[0015] (Equation 3)

[0016] In the formula, For the input frame, B(*;σ) is the Gaussian Blur function, whose standard deviation σ is the dynamic value of the compliance policy set, and R is the set of sensitive regions identified by the semantic segmentation model.

[0017] Furthermore, the distributed chip of the aforementioned Earth clone scale model is also coupled to a high-fidelity spatiotemporal anchoring interface; when generating a signature, the aforementioned signature unit will include the tamper-proof timestamp and spatial coordinate data obtained from the aforementioned interface into the signature scope.

[0018] Furthermore, the video processing unit is also used to generate a zero-knowledge proof (ZKProof, ZKP) based on the intermediate data processed within the aforementioned secure execution environment, according to the verification party's request statement, and to use the zero-knowledge proof as part of the aforementioned authentication credentials.

[0019] Furthermore, the aforementioned video processing unit executes an authentication credential algorithm to generate a zero-knowledge proof, which is expressed as follows:

[0020] (Equation 4)

[0021] In the formula, P represents zero-knowledge proof, and f live with f ref These are the feature vectors extracted in real time and those stored in reference, θ. sim The similarity threshold is defined by the set of compliance policies.

[0022] In the formula, ZKProve is the zero-knowledge proof function, representing the entire proof generation process of the zero-knowledge proof protocol, ensuring that no information about the secret input is leaked. The function contains similarity inequalities. The dot product of two n-dimensional vectors reaches its maximum value if the two vectors point in the same direction. In this invention, the dot product is designed to make the dot product of feature vectors extracted from different photos of the same person very large, while the dot product of feature vectors from different people is very small. and The two vectors represent their lengths. Dividing the dot product by the lengths of the two vectors yields the cosine similarity. This invention determines whether the similarity exceeds a preset safety threshold θ. sim .

[0023] Furthermore, when the location information of the terminal device changes, the distributed chip of the aforementioned Earth clone scale model automatically detects the change and obtains and activates a new set of compliance policies from the governance entity associated with the new location information through a secure channel to dynamically update the aforementioned set of compliance policies.

[0024] Furthermore, the distributed chip of the aforementioned Earth clone scale model is configured to operate independently of the terminal device's operating system and directly acquires location-related raw signals through a dedicated hardware interface. This ensures that even if the operating system's location service function is turned off by the user, the distributed chip of the aforementioned Earth clone scale model can still acquire geographic location data for determining location information.

[0025] Furthermore, if the operating system's location service is detected to be disabled, the distributed chip of the aforementioned Earth clone scale model acquires geographic location data through at least one of the following methods:

[0026] (a) Read the raw signals from the Global Navigation Satellite System (GNSS) module directly via a dedicated hardware bus;

[0027] (b) Read the Mobile Country Code (MCC) and Cell ID of the cellular network baseband chip.

[0028] (c) Control the wireless LAN module to perform passive scanning, obtain the Basic Service Set Identifier (BSSID) of the media access control address of the surrounding access points, and compare it with the hotspot location database stored locally.

[0029] This invention also discloses a privacy-preserving video authentication method, comprising the following steps: determining a secure execution environment matching the location information of a terminal device; loading a set of compliance policies associated with the secure execution environment; importing the original video data stream into the secure execution environment and performing privacy enhancement processing according to the set of compliance policies to generate authentication credentials; signing the authentication credentials using a cryptographic key associated with the secure execution environment to generate a signature credential; and transmitting the signature credential to the verifier for verification.

[0030] The beneficial effects of this invention are as follows.

[0031] By constructing a secure execution environment precisely mapped to the physical world within a distributed chip based on a scale model of an Earth clone, this invention can automatically load and enforce a set of compliance policies for the corresponding jurisdiction based on the real-time location information of the terminal device. This process is independent of the operating system; even if the user disables system-level location services, the chip can still directly obtain location signals through a hardware interface, ensuring that cross-border businesses strictly comply with local laws and regulations anywhere in the world, completely solving the problem of rigid and ineffective compliance policies.

[0032] The processing of all sensitive raw video streams and biometric data is strictly confined to an active, secure execution environment. The system only outputs privacy-enhanced results, such as anonymized digests, hash values, or zero-knowledge proofs (ZKPs). This eliminates the risk of raw data being misused during transmission, storage, or by cloud services, perfectly aligning with the core requirements of mainstream global privacy regulations.

[0033] The signature unit uses a hardware-level private key within a secure execution environment to digitally sign authentication credentials (optionally including a high-fidelity spatiotemporal anchor stamp), generating a "signature credential" with a clear geographical attribute. Any third-party verifier can independently verify the authenticity, integrity, and origin of the credential by retrieving the corresponding public key through public channels. This not only provides a solid foundation of trust for business decisions but also provides tamper-proof cryptographic evidence for post-event auditing and judicial evidence collection.

[0034] This invention, through standardized credential formats and a disclosure mechanism based on zero-knowledge proofs, enables different administrative regions or organizations to mutually recognize specific statements (such as "identity verified" and "age greater than 18") without sharing original sensitive data. This effectively breaks down data silos, safeguarding the data sovereignty of all parties while providing an efficient and reliable technological foundation for cross-departmental and cross-border collaboration in areas such as smart cities, cross-border finance, and public safety. Attached Figure Description

[0035] Figure 1This is a schematic diagram of a privacy-protected video authentication system according to an embodiment of the present invention.

[0036] Figure 2 This is a flowchart of a privacy-protecting video authentication method according to an embodiment of the present invention.

[0037] The reference numerals in the above figures are as follows:

[0038] The privacy-protected video authentication system (10), the distributed chip (100) of the Earth clone scale model, different security execution environments (110a, 110b, 110c, 110d, 110e), the video processing unit (120), the signature unit (130), and the verification server (200) are steps S1 to S5. Detailed Implementation

[0039] To better understand this invention, the following embodiments are provided in conjunction with the accompanying drawings. It should be understood that the embodiments of this invention are for illustrative purposes only and not for limiting the invention; the scope of protection of this invention is defined solely by the claims. The embodiments provided are merely preferred embodiments and are not intended to limit the invention in any way. Those skilled in the art can make changes, equivalent substitutions, or modifications based on the content of this invention to form different implementations. However, any changes and modifications, and any equivalent substitutions made to the method of this invention without departing from the inventive concept are within the scope of protection of this invention.

[0040] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0041] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms “comprising” and / or “including” are used in this specification, they indicate the presence of features, steps, operations, and / or combinations thereof.

[0042] First, please refer to Figure 1 , Figure 1 This is a schematic diagram of a privacy-protecting video authentication system 10 according to an embodiment of the present invention. Figure 1As shown, the privacy-preserving video authentication system 10 based on the Earth clone scale model of the present invention includes a distributed chip 100 of the Earth clone scale model, a video processing unit 120 and a signature unit 130. The distributed chip 100 of the aforementioned Earth clone scale model is internally configured with multiple mutually isolated secure execution environments 110, such as 110a (China), 110b (EU), 110c (USA), 110d (Singapore), and 110e (Brazil). Each of the aforementioned secure execution environments 110 is associated with one or more external governance entities and stores a set of compliance policies defined or authorized by that governance entity, as well as hardware-protected cryptographic keys. The aforementioned video processing unit 120 operates within a specific secure execution environment of the aforementioned distributed chip 110 of the aforementioned Earth clone scale model. It is used to receive raw video data streams and, according to the set of compliance policies associated with the secure execution environment, perform privacy enhancement processing on the raw video data streams to generate authentication credentials that do not include the raw video data. The aforementioned signature unit 130 operates within the aforementioned distributed chip 100 of the aforementioned Earth clone scale model. It is used to digitally sign the aforementioned authentication credentials using the cryptographic keys associated with the aforementioned specific secure execution environment, generating signature credentials with governance attributes for verification.

[0043] For example, in this embodiment of the invention, the distributed chip 100 of the aforementioned Earth clone scale model within the terminal device pre-configures three typical secure execution environments: 110a (China), 110b (EU), and 110c (USA). When performing a general "face video verification" service, the sets of compliance policies loaded in each environment will differ significantly.

[0044] For example, the binding regulations of the Chinese secure execution environment 110a are based on the "Personal Information Protection Law of the People's Republic of China" and the People's Republic of China financial industry standard JR / T 0171-2020 "Technical Specifications for the Protection of Personal Financial Information". Therefore, when a user uses Alipay to scan a QR code for payment within China, the distributed chip 100 of the aforementioned Earth clone scale model of this invention activates 110a. After the aforementioned video processing unit 120 completes face comparison within 110a, it generates a ZKP based on the signature of the "SM2 Elliptic Curve Public Key Cryptography Algorithm" of the State Cryptography Administration of China, which is then signed by the aforementioned signing unit 130. The entire process complies with the strict protection requirements of Chinese law for financial-grade personal information.

[0045] Furthermore, the EU's Secure Enforcement Environment 110b binding regulation is based on the General Data Protection Regulation (GDPR) and the Digital Services Act (DSA). When German user Hans purchases age-restricted goods online, the distributed chip 100 of the aforementioned Earth clone scale model activates 110b. The aforementioned video processing unit 120 first performs high-intensity blurring and desensitization on the video frames, and then generates a ZKP based on the desensitized data to prove that he meets the age requirement. The aforementioned signature unit 130 issues the certificate using the Elliptic Curve Digital Signature Algorithm (ECDSA). The entire process perfectly embodies the GDPR's principles of "data minimization" and "design to protect privacy."

[0046] Furthermore, the U.S. secure execution environment 110c binding regulations are based on state laws (such as the California Consumer Privacy Act (CCPA)) and industry self-regulation standards (such as the National Institute of Standards and Technology's NIST Special Publication 800-63B Digital Identity Guide). When Mr. Smith, a user in California, remotely signs a medical consent form, the distributed chip 100 of the aforementioned Earth clone scale model is activated (110c). The aforementioned video processing unit 120 performs liveness detection and face comparison, and the results, along with a precise timestamp obtained from the high-fidelity spatiotemporal anchoring interface, are signed by the aforementioned signing unit 130 using the RSA algorithm. This credential meets the authenticator assurance level 3 requirements of the NIST Special Publication 800-63B Digital Identity Guide, and the system also records operation logs for CCPA compliance audits.

[0047] Each secure execution environment 110 within the distributed chip 100 of the Earth clone scale model of the present invention acts as a hardware embodiment of laws and regulations. It not only stores summaries of legal provisions for the corresponding region but also transforms these abstract legal requirements into a series of executable, verifiable, and auditable specific technical instructions (i.e., a set of compliance strategies). When the distributed chip 100 of the Earth clone scale model senses a change in location, it essentially switches roles within the global legal landscape, ensuring that every data processing strictly adheres to local legal rules, thereby providing a solid compliance foundation for global digital business.

[0048] Please refer to Figure 2 , Figure 2 This is a flowchart of a privacy-preserving video authentication method according to an embodiment of the present invention. Figure 2As shown, the privacy-preserving video authentication method of the aforementioned privacy-preserving video authentication system includes the following steps: determining a matching secure execution environment based on the location information of the terminal device (S1); loading a set of compliance policies associated with the secure execution environment (S2); importing the original video data stream into the secure execution environment and performing privacy enhancement processing according to the set of compliance policies to generate authentication credentials (S3); signing the authentication credentials using the cryptographic key associated with the secure execution environment to generate a signature credential (S3); and transmitting the signature credential to the verifier for verification (S5).

[0049] It is worth noting that the aforementioned video processing unit 120 executes a dynamic privacy algorithm to control and prevent the risk of privacy leakage. This dynamic privacy algorithm calculates and allocates a differential privacy budget E for this video processing based on the set of compliance policies associated with the current secure execution environment. The calculation formula is as follows:

[0050] (Equation 1)

[0051] In the formula, E base Let Wi be the default base privacy budget, where Wi is the quantified value of the i-th sensitivity metric in the compliance policy set, and Si be the corresponding weighting coefficient.

[0052] (Equation 2)

[0053] A smaller privacy budget E value indicates a higher level of privacy protection. These metrics, such as Si, are quantitative translations of specific clauses in the compliance policy set. Each security execution environment 110 policy set includes a series of such indicators. For example, in biometric types, face image S1=0.95, fingerprint S1=0.90, voice S1=0.70; in data retention requirements, use-and-burn S2=0.85, short-term caching (7 days) allowed S2=0.60, long-term storage S2=0.30; in business risk levels, cross-border large payments S3=0.90, social APP login S3=0.40; in jurisdictional stringency, EU GDPR S4=0.80, ordinary regions S4=0.50.

[0054] This embodiment successfully transforms complex and ambiguous legal compliance language into clear, rigorous, and executable cryptographic parameters through an ingenious mathematical model. This parameter not only quantifies privacy risks but also drives the behavior of the entire privacy enhancement processing engine. For example, in step (S3), if the current security execution environment 110b (EU) compliance policy set defines high-sensitivity indicators (e.g., face S1=0.9, retention S2=0.8), the video processing unit 120 will invoke a dynamic privacy algorithm to convert the legal provisions into mathematical parameters. Assuming the calculated value is E=0.3, this is a very small budget, meaning a high level of privacy protection that meets the requirements of the region. Based on this, the video processing unit 120 will further select to add more noise or use a more complex ZKP to ensure that the final privacy leakage risk does not exceed the budget.

[0055] It is worth noting that the aforementioned video processing unit executes a privacy enhancement algorithm to perform privacy enhancement processing. The video processing unit employs an adaptive desensitization equation based on semantic segmentation to generate desensitized frames. The equation is defined as:

[0056] (Equation 3)

[0057] In the formula, For the input frame, B(*;σ) is the Gaussian blur function, which achieves a smoothing / blurring effect by weighted averaging of the pixel values ​​of the target pixel and its surrounding neighborhood. Its standard deviation σ is determined by the dynamic value of the compliance policy set, which determines the intensity of the blur. The larger σ is, the wider the blur range, the more image details are lost, and the stronger the privacy protection. The smaller σ is, the clearer the image and the higher the data utility, but the privacy risk also increases. It is not a fixed constant, but is dynamically distributed by the compliance policy set bound to the currently active security execution environment 110.

[0058] For example, in 110b (EU), the policy set might specify σ=25 to ensure that faces are completely unrecognizable, meeting the stringent requirements of GDPR; in 110c (US - low-risk scenarios), the policy set might allow σ=8, with only slight blurring to meet basic notification obligations; in 110a (China - factory interiors), if the purpose of monitoring is to check helmet wearing, the policy set might specify that σ=15 is applied only to the face area, while no processing is done on the body and helmet areas.

[0059] R represents the set of sensitive regions identified by the semantic segmentation model. For example, in step (S3), the video processing unit 120 first identifies the sensitive regions R (such as faces and license plates) in the frame using its built-in semantic segmentation model. This invention achieves precise desensitization. For pixels (x, y) within the sensitive regions, a Gaussian blur B is applied, with the blur intensity σ dynamically determined by compliance policies (e.g., the EU requires σ=15, while factory internal monitoring only requires σ=3). Non-sensitive regions remain unchanged, preserving useful information to the greatest extent possible.

[0060] It is worth noting that the distributed chip 100 of the aforementioned Earth clone scale model is also coupled to a high-fidelity spatiotemporal anchoring interface; when generating a signature, the aforementioned signature unit will include the tamper-proof timestamp and spatial coordinate data obtained from the aforementioned interface into the signature scope.

[0061] The video processing unit 120 is further configured to generate a zero-knowledge proof based on intermediate data processed within the secure execution environment, according to the verification party's request, and to use the differential of this zero-knowledge proof as part of the authentication credential. The video processing unit 120 executes an authentication credential algorithm to generate the zero-knowledge proof, which is expressed as follows:

[0062] (Equation 4)

[0063] In the formula, P represents zero-knowledge proof, and f live with f ref These are the feature vectors extracted in real time and those stored in reference, θ. sim The similarity threshold is defined by the set of compliance policies.

[0064] This invention uses ZKProve, a zero-knowledge proof function, to represent the entire proof generation process of the zero-knowledge proof protocol, ensuring that no information about the secret input is leaked. The function contains similarity inequalities. The dot product of two n-dimensional vectors reaches its maximum value if the two vectors point in the same direction. In this invention, the dot product is designed to make the dot product of feature vectors extracted from different photos of the same person very large, while the dot product of feature vectors from different people is very small. and The two vectors represent their lengths. Dividing the dot product by the lengths of the two vectors yields the cosine similarity. This invention determines whether the similarity exceeds a preset safety threshold θ. sim In this way, the authentication credential algorithm can flexibly adapt to the vastly different security and compliance requirements of various regions and industries around the world.

[0065] For example, a user in Germany uses an app to verify their age (must prove age ≥ 18). After the video processing unit 120 extracts facial features within the "German secure execution environment," it does not send the feature vector out but instead executes an authentication credential algorithm. The core of the authentication credential algorithm of this invention is to construct a proof P. After receiving P, the verifier runs the function that verifies P. If the return value is genuine, then the face matching is 100% believed to be successful, but no biometric data is seen throughout the process, perfectly protecting personal privacy under GDPR.

[0066] In another embodiment, when the location information of the terminal device changes, the distributed chip of the aforementioned Earth clone scale model automatically detects the change and obtains and activates a new set of compliance policies from the governance entity associated with the new location information via a secure channel to dynamically update the aforementioned set of compliance policies. The distributed chip of the aforementioned Earth clone scale model is configured to be independent of the terminal device's operating system and directly obtains location-related raw signals through a dedicated hardware interface to ensure that even if the operating system's location service function is turned off by the user, the distributed chip of the aforementioned Earth clone scale model can still obtain geographic location data for determining location information. If the operating system's location service is detected to be turned off, the distributed chip of the aforementioned Earth clone scale model obtains geographic location data in at least one of the following ways: (a) directly reading the raw signals of the Global Navigation Satellite System (GNSS) module through a dedicated hardware bus; (b) reading the Mobile Country Code (MCC) and Cell Identifier (Cell ID) of the cellular network baseband chip; (c) controlling the wireless LAN module to perform passive scanning to obtain the Media Access Control Address (BSSID) of surrounding access points and comparing it with a locally stored hotspot location database.

[0067] For example, a user attempts a large transfer in the Macao Special Administrative Region of the People's Republic of China and has disabled location services on their phone. Upon detecting the operating system's location service being disabled, the distributed chip 100 of the aforementioned Earth clone scale model immediately activates a backup plan: (a) it reads MCC "455" to confirm its location is in the Macao Special Administrative Region of the People's Republic of China; (b) it passively scans for Wi-Fi and matches the casino hotspot database. This then activates a high-risk security execution environment in the region. When signing, the aforementioned signature unit 130 obtains the precise spatiotemporal stamp of the BeiDou satellite through a high-fidelity spatiotemporal anchoring interface and includes it in the signature scope. This allows the verifier to confirm that the transaction indeed occurred at a specific time within a casino in the Macao Special Administrative Region of the People's Republic of China, effectively preventing replay attacks and location spoofing.

[0068] For example, Ms. Wang applies to open a Type II account using a mobile banking app in mainland China. The bank's backend triggers a video authentication request. The distributed chip 100 of the Earth clone scale model in the terminal device detects the location as being in mainland China and activates the "China-Financial Security Execution Environment" 110a. The aforementioned video processing unit 120 drives the camera to capture video within 110a. According to the People's Republic of China Financial Industry Standard JR / T 0171-2020 "Technical Specification for the Protection of Personal Financial Information", the aforementioned video processing unit 120 performs liveness detection and extracts the facial feature vector f. live The aforementioned video processing unit 120 calls the zero-knowledge proof generation module, based on pre-stored reference features f from the ID card photo. ref The ZKP is constructed to prove that the operation was performed by the person in question. The aforementioned signature unit 130 uses the private key of 110a and integrates the timestamp of the National Time Service Center of the Chinese Academy of Sciences obtained from the high-fidelity spatiotemporal anchoring interface for signing. Then the signature certificate is sent to the verification server 200 (i.e. the bank's compliance system). The aforementioned verification server 200 verifies that the signature is valid, the source is within China, and the ZKP is established, thus completing the strong identity verification and allowing the account opening.

[0069] For example, Mr. Smith, a patient in California, signs an informed consent form online for a high-risk surgery. The distributed chip 100 of the aforementioned Earth clone model on Smith's phone detects his location as California, activating the "US-California Health Insurance Portability and Accountability Act (HIPAA) Secure Implementation Environment" 110c. The hospital system requires video confirmation that Smith is fully conscious and voluntarily signing the form. The aforementioned video processing unit 120 records a short video within 110c. Then, in accordance with HIPAA's stringent requirements for health information, the video processing unit 120 invokes a dynamic privacy algorithm, allocates a minimal E budget, and generates a complex ZKP to prove that "the person in the video is Smith himself, and he verbally agreed to the key terms." The aforementioned signing unit 130 issues a credential including P. The aforementioned verification server 200 (hospital legal compliance system) verifies the validity of the credential, thus considering it a legally valid electronic signature. The entire process complies with HIPAA compliance requirements.

[0070] For example, when Mr. Zhang arrives at Singapore Changi International Airport and uses the self-service channel for immigration, the distributed chip 100 of the aforementioned Earth clone scale model inside the self-service gate obtains MCC "525" through the connected Singapore local operator network, activating the "Singapore-Customs Security Execution Environment" 110d. Even if Mr. Zhang's mobile phone location is turned off, the gate, as a dedicated device, can directly read the biometrics in the passport chip using its Earth clone scale model distributed chip 100 as f ref The aforementioned video processing unit 120 captures real-time face data. live The signature unit 130 generates a ZKP certificate proving the match between the two. The signature unit 130 then signs P together with the precise entry time and GPS coordinates obtained from the high-fidelity spatiotemporal anchoring interface. The signature certificate is then sent to the verification server 200 of the Singapore Immigration & Checkpoints Authority to complete the fast, secure, and auditable entry verification.

[0071] The core of this invention lies in providing a hardware-software collaborative solution. By embedding a "distributed chip based on a geographic clone scale model" within the terminal device, this chip internally divides into multiple "secure execution environments" mapped to real-world geographic / administrative divisions. During video authentication, the system automatically activates the corresponding secure execution environment based on the device's real-time location and strictly adheres to the compliance policy set bound to that environment. All sensitive operations are completed within a hardware-isolated environment, outputting only privacy-enhanced "authentication credentials," which are then signed by a private key within the chip, thus achieving the goals of "data remaining within the domain, policy self-adaptation, and verifiable credentials."

[0072] The embodiments of the present invention described above can be implemented in various hardware, software codes, or combinations thereof. For example, embodiments of the present invention can also be program code executing the above methods in a Digital Signal Processor (DSP). The present invention can also relate to various functions executed by a computer processor, digital signal processor, microprocessor, or Field Programmable Gate Array (FPGA). The processor described above can be configured to perform specific tasks according to the present invention, which are accomplished by executing machine-readable software code or firmware code defining the specific methods disclosed in the present invention. The software code or firmware code can be developed into different programming languages ​​and different formats or forms. The software code can also be compiled for different target platforms. However, the different code styles, types, and languages ​​of the software code performing tasks according to the present invention and other types of configuration code do not depart from the spirit and scope of the present invention.

[0073] Therefore, those skilled in the art will recognize that although embodiments of the present invention have been shown and described in detail herein, many other variations or modifications conforming to the principles of the present invention can be directly determined or derived from the disclosure of the present invention without departing from the spirit and scope of the invention. Thus, the scope of the present invention should be understood and recognized as covering all such other variations or modifications.

Claims

1. A privacy-preserving video authentication system, comprising: A distributed chip based on a scale model of an Earth clone, which is internally configured with multiple mutually isolated secure execution environments. Each secure execution environment is associated with one or more external governance entities and stores a set of compliance policies defined or authorized by the governance entity and cryptographic keys. A video processing unit, running within a specific secure execution environment of the distributed chip of the Earth clone scale model, is used to receive raw video data streams and perform privacy enhancement processing on the raw video data streams according to a set of compliance policies associated with the secure execution environment, so as to generate authentication credentials that do not include the raw video data. A signature unit, running within the distributed chip of the Earth clone scale model, is used to digitally sign the authentication credential using the cryptographic key associated with the secure execution environment, generating a signature credential with governance attributes for verification.

2. The privacy-protected video authentication system as described in claim 1, characterized in that, The video processing unit executes a dynamic privacy algorithm to control the risk of privacy leakage. The dynamic privacy algorithm calculates and allocates a differential privacy budget E for this video processing based on the compliance policy set associated with the current secure execution environment. The calculation formula is as follows: In the formula, E base Let Wi be the default base privacy budget, where Wi is the quantified value of the i-th sensitivity metric in the compliance policy set, and Si be the corresponding weighting coefficient. 。 3. The privacy-protected video authentication system as described in claim 1, characterized in that, The video processing unit executes a privacy enhancement algorithm to perform privacy enhancement processing, and uses an adaptive desensitization equation based on semantic segmentation to generate desensitized frames. The adaptive desensitization equation is as follows: 。 In the formula, For the input frame, B(*;σ) is the Gaussian blur function, whose standard deviation σ is the dynamic value of the compliance policy set, and R is the set of sensitive regions identified by the semantic segmentation model.

4. The privacy-protected video authentication system as described in claim 1, characterized in that: When the location information of the terminal device changes, the distributed chip of the Earth clone scale model automatically detects the change and obtains and activates a new set of compliance policies from the governance entity associated with the new location information through a secure channel to dynamically update the set of compliance policies.

5. The privacy-protected video authentication system as described in claim 1, characterized in that: The distributed chip of the Earth clone scale model is configured to be independent of the terminal device's operating system and directly acquires location-related raw signals through a dedicated hardware interface. This ensures that even if the operating system's location service function is turned off by the user, the distributed chip of the Earth clone scale model can still acquire geographic location data for determining location information.

6. The privacy-protected video authentication system as described in claim 5, characterized in that, If the operating system's location service is detected to be disabled, the distributed chip of the Earth clone scale model acquires geographic location data through at least one of the following methods: a) Read the raw signals from the Global Navigation Satellite System module directly via a dedicated hardware bus; b) Read the mobile country code and base station identifier of the cellular network baseband chip; c) Control the wireless LAN module to perform passive scanning, obtain the Media Access Control Address Basic Service Set Identifier of surrounding access points, and compare it with the locally stored hotspot location database.

7. The privacy-protected video authentication system as described in claim 1, characterized in that: The distributed chip of the Earth clone scale model is also coupled to a high-fidelity spatiotemporal anchoring interface; when generating a signature, the signature unit includes the tamper-proof timestamp and spatial coordinate data obtained from the interface into the signature scope.

8. The privacy-preserving video authentication system as described in any one of claims 1 to 7, characterized in that: The video processing unit is also used to generate a zero-knowledge proof based on intermediate data processed within the secure execution environment, according to a verification party's request, and to use the zero-knowledge proof as part of the authentication credential.

9. The privacy-protected video authentication system as described in claim 8, characterized in that, The video processing unit executes an authentication credential algorithm to generate a zero-knowledge proof, the authentication credential algorithm being as follows: In the formula, P represents zero-knowledge proof, and f live with f ref These are the feature vectors extracted in real time and those stored in reference, θ. sim The similarity threshold is defined by the set of compliance policies.

10. A privacy-preserving video authentication method applied to the privacy-preserving video authentication system according to any one of claims 1 to 9, comprising the following steps: Based on the location information of the terminal device, determine the matching secure execution environment; Within the secure execution environment, load the set of compliance policies associated with it; The raw video data stream is imported into the secure execution environment, and privacy enhancement processing is performed according to the compliance policy set to generate authentication credentials; The authentication credential is signed using the cryptographic key associated with the secure execution environment to generate a signature credential; The signature credential is transmitted to the verifier for verification.