WO2022017452A1 - Identity authentication method, apparatus, devices and storage media - Google Patents
Identity authentication method, apparatus, devices and storage media Download PDFInfo
- Publication number
- WO2022017452A1 WO2022017452A1 PCT/CN2021/107818 CN2021107818W WO2022017452A1 WO 2022017452 A1 WO2022017452 A1 WO 2022017452A1 CN 2021107818 W CN2021107818 W CN 2021107818W WO 2022017452 A1 WO2022017452 A1 WO 2022017452A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- target
- public
- identity
- keys
- feature
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
Definitions
- the invention belongs to the field of data security, and in particular, relates to an identity authentication method, apparatus, device and storage medium.
- the electronic devices usually store the user's identity feature information in advance, and during identity authentication, it authenticates whether the input identity feature information matches the pre-stored identity feature information.
- the identity authentication is passed.
- the pre-stored user identity feature information is at risk of being lost or leaked. Therefore, this identity authentication method does not have high security.
- Embodiments of the present invention provide an identity authentication method, apparatus, device and storage medium, which can avoid the loss or leakage of user identity feature information and improve the security of an identity authentication mode.
- an identity authentication method which includes the following steps:
- the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user;
- the authenticating an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user specifically comprises the following steps:
- the method before extracting M first feature points from the target identity feature of the target user, the method further comprises the following steps:
- the target shape is a triangle
- the authenticating the N pieces of signature information by using the acquired Q public keys comprises the following steps:
- the signature set is a set composed of the N pieces of signature information
- the target signature information is any information in the signature set.
- the parameter value of the target shape is a value of the circumference or a value of the area.
- the target identity feature includes one of the following items: fingerprint feature, facial feature, palmprint feature.
- an identity authentication apparatus includes the following modules:
- an extraction module which is configured to extract M first feature points from a target identity feature of a target user during a process of identity authentication of the target user;
- a generation module which is configured to generate N target shapes according to the M first feature points
- a determination module which is configured to determine a parameter value of each target shape of the N target shapes
- the generation module which is further configured to generate N asymmetric public and private keys according to the parameter values of the N target shapes;
- an authentication module which is configured to authenticate an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, pass the identity authentication of the target user;
- the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user;
- the authentication module is specifically configured to perform the following steps:
- the apparatus further includes the following modules:
- a division module which is configured to divide the target identity feature into regions to obtain I regions
- an extraction module which is configured to extract W second feature points from each of the I regions respectively;
- the generation module which is also configured to generate Q target shapes for each region according to the second feature point of each region;
- a calculation module which is configured to calculate a parameter value of each target shape
- the generation module which is configured to generate Q asymmetric public and private keys according to the parameter value of each target shape to obtain the Q public keys.
- the target shape is a triangle
- the authentication module is specifically configured to perform the following steps:
- the signature set is a set composed of the N pieces of signature information
- the target signature information is any information in the signature set.
- the parameter value of the target shape is a value of the circumference or a value of the area.
- the target identity feature comprises one of the following items: fingerprint feature, facial feature and palmprint feature.
- an electronic device comprising a processor and a memory storing computer program instructions; and when the processor executes the computer program instructions, the method as in the first aspect or any possible implementation of the first aspect is implemented.
- a computer storage medium stores computer program instructions.
- the computer program instructions are executed by a processor, the method in the first aspect or any possible implementation of the first aspect is implemented.
- asymmetric public and private keys can be generated based on the parameter values.
- the target user is authenticated based on private keys of the asymmetric public and private keys and acquired Q public keys.
- an identity of the user is authenticated according to a plurality of feature points of the target identity feature input by the user.
- a number of private keys of N private keys matched with the Q public keys is greater than a preset threshold, the identity authentication of the target user is passed.
- the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user.
- the electronic device converts the user's identity feature information, such as facial feature, fingerprint feature, palmprint feature, etc., into digital representation, that is, the electronic device can authenticate the user's identity only by saving the public keys, without saving the original data of the user's identity features, thereby avoiding the loss or leakage of the user's identity information and improving the security of the identity authentication method.
- Fig. 1 is a schematic flowchart of an identity authentication method provided by an embodiment of the present invention
- Fig. 2 is a schematic structural diagram of an identity authentication apparatus provided by an embodiment of the present invention.
- Fig. 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention.
- the electronic devices usually store the user's identity feature information in advance, and during a process of identity authentication, they authenticate whether input identity feature information matches pre-saved identity feature information.
- the identity authentication is passed.
- a pre-stored user fingerprint template is used in related technologies to match the user fingerprint entered into the electronic device.
- the fingerprint template saves complete data of the user's fingerprint, but in the case of data leakage of the electronic device, it is easy to leak the complete data of the user's fingerprint, which will cause unnecessary loss to the user after the complete data of the user's fingerprint are used by criminals. Therefore, in the identity authentication methods in related technologies, the pre-stored user identity feature information is at risk of being lost or leaked. Therefore, this identity authentication method does not have high security.
- the embodiment of the present invention provides an identity authentication method, apparatus, device and storage medium, which can avoid the loss or leakage of user identity feature information and improve the security of the identity authentication mode.
- Fig. 1 shows a schematic flowchart of an identity authentication method 100 provided by an embodiment of the present invention.
- the identity authentication method 100 provided by the embodiment of the present invention may include the following steps.
- M first feature points are extracted from a target identity feature of a target user during a process of identity authentication of the target user.
- the target user is a user who needs to be authenticated.
- a target user A needs to use an application A in an electronic device to perform transfer operation, and the identity authentication of the target user A needs to be performed before perform the identity transfer, so the feature points of the identity features of the target user A need to be extracted.
- the target identity feature refers to any identity feature that can represent the user's identity.
- the target identity feature may include fingerprint feature, facial feature and palmprint feature.
- the electronic device Before the user performs identity authentication, the electronic device needs to enter the user's target identity feature, and then the electronic device extracts M first feature points from the user's target identity feature. For example, if the user uses the user's facial feature for identity authentication, the user can use a camera device of the electronic device to photograph his own facial feature, so that the electronic device can extract feature points in the user's facial feature, and then authenticate the user.
- the user A uses his fingerprint feature for identity authentication, and the user A transmits the fingerprint feature of the user A to the electronic device through a fingerprint entry module on the electronic device. After receiving the fingerprint feature of the user A, the electronic device extracts M feature points from the fingerprint feature.
- N target shapes are generated according to the M first feature points.
- N target shapes are constructed.
- the M first feature points are connected to construct the N target shapes.
- the target shape may be a triangle.
- the target shape may also be a polygon such as a quadrilateral.
- the M first feature points are connected to construct multiple polygons.
- a parameter value of each target shape in the N target shapes is determined.
- the parameter value of the target shape is calculated.
- the parameter value may be a value of a perimeter or a value of an area.
- the parameter value may be a value of the perimeter of the triangle or a value of the area of the triangle.
- N asymmetric public and private keys are generated according to the parameter values of the N target shapes.
- asymmetric public and private keys corresponding to the parameter value is calculated.
- N asymmetric public and private keys can be obtained.
- an identity of the target user is authenticated according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is greater than a preset threshold, the identity authentication of the target user is passed.
- the private keys of the N asymmetric public and private keys are matched with the acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is greater than the preset threshold, the identity authentication of the target user is passed.
- the Q public keys may be multiple public keys generated in advance and saved in the electronic device.
- the public keys are public key of the asymmetric public and private keys generated according to parameter values of a target shapes; and the parameter values of the target shapes are determined by the W second feature points in the target identity feature of the target user.
- the embodiment of the present invention may include the following steps.
- the target identity feature is divided into regions to obtain I regions.
- W second feature points are extracted from each of the I regions respectively.
- P target shapes are generated according to the second feature points of each region.
- a parameter value of each target shape is calculated.
- Q asymmetric public and private keys are generated, and Q public keys are obtained.
- the user needs to save the identity feature in the electronic device.
- the target identity feature needs to be divided into regions to obtain I regions. For example, the fingerprint feature of the user is divided into 5 regions.
- W second feature points are extracted from each region.
- the W second feature points of each region are connected to construct P target shapes.
- the parameter value of each target shape is calculated.
- the parameter value may include a value of the perimeter of the target shape, a value of the area of the target shape, and the like.
- the shape of the target is a triangle, and after P triangles are determined, the perimeter of each triangle is calculated.
- the parameter value may also be a combination of angles, for example, three angles of the triangle are 90°, 45°, and 45°.
- I is a positive integer
- Q is greater than N.
- Q asymmetric public and private keys are generated based on the parameter value of each target shape, and then Q public keys are obtained.
- Q public keys are obtained.
- the private keys of the Q asymmetric public and private keys may also be destroyed.
- completion information of the user's target identity feature is converted into a digital form and saved in the electronic device, so that the user's identity authentication can be realized, the loss or leakage of the user's identity feature information can be avoided, and the security of the identity authentication mode can be improved.
- S105 in the identity authentication method 100 provided in the embodiment of the present invention specifically authenticates the N pieces of signature information in the following manner.
- a private key of each asymmetric public and private key is used to sign an acquired random number, so as to obtain N pieces of signature information;
- the N pieces of signature information are authenticated by using the acquired Q public keys, and when a number of the N pieces of signature information matched with the Q public keys is greater than a preset threshold, the identity authentication of the target user is passed.
- the private keys of the N asymmetric public and private keys are used to sign the acquired random number, and then obtain N pieces of signature information.
- the N pieces of signature information are authenticated by using Q public keys.
- the signature set is a set composed of the N pieces of signature information
- the target signature information is any information in the signature set.
- N pieces of signature information may be authenticated sequentially. In other words, the authenticated public key does not need to be authenticated again. After matching the public key with the respective signature information, it is determined that the target signature information in the signature set matches the public key, and then the target signature information is removed from the signature set to obtain an updated signature set.
- the target signature information is any signature information in the signature set.
- the public keys are ⁇ AB C D E F G H I J ⁇ respectively, and the signature set is ⁇ 1 2 3 4 5 6 7 ⁇ .
- the signature information is authenticated by using a public key A, where the public key A matches signature information 2, then the signature set is updated to ⁇ 1 3 4 5 6 7 ⁇ .
- the public key B is used to authenticate the signature information. Where the public key B matches the signature information 5, then the signature set is updated to ⁇ 1 3 4 6 7 ⁇ , and so on.
- the identity authentication method 100 can generate the parameter values of the feature parameters of the N target shape based on the M first feature points extracted from the target identity feature of the target user, and then generate asymmetric public and private keys based on the parameter values.
- the target user is authenticated based on private keys of the asymmetric public and private keys and the acquired Q public keys.
- the user's identity is authenticated with multiple feature points of the target identity feature input by the user.
- the identity authentication of the target user is passed.
- the public keys are the public keys of the asymmetric public and private keys generated according to the parameter values of the target shapes; and the parameter values of the target shapes are determined by the W second feature points in the target identity feature of the target user.
- the electronic device converts the user's identity feature information, such as facial feature, fingerprint feature, palmprint feature, etc., into digital representation, that is, the electronic device can authenticate the user's identity only by saving the public keys, without saving the original data of the user's identity features, thereby avoiding the loss or leakage of the user's identity information and improving the security of the identity authentication method.
- the user's identity features are saved in a form of numbers, without changing of the user's identity features, such as translation, rotation or scaling, which improves the efficiency of user identity authentication.
- the embodiment of the present invention also provides an identity authentication apparatus.
- the identity authentication apparatus will be described in detail below.
- Fig. 2 is a schematic structural diagram of an identity authentication apparatus 200 provided by an embodiment of the present invention.
- the identity authentication apparatus 200 provided in the embodiment of the present invention may include an extraction module 201, a generation module 202, a determination module 203, and an authentication module 204.
- the extraction module 201 is configured to extract M first feature points from a target identity feature of a target user during a process of identity authentication of the target user.
- the generation module 202 is configured to generate N target shapes according to the M first feature points.
- the determination module 203 is configured to determine a parameter value of each target shape in the N target shapes.
- the generation module 202 is further configured to generate N asymmetric public and private keys according to the parameter value of each target shape.
- the authentication module 204 is configured to authenticate an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, pass the identity authentication of the target user.
- the public keys are public keys of the asymmetric public and private key generated according to parameter values of the target shapes; and the parameter values of the target shapes are determined by the W second feature points in the target identity feature of the target user.
- M, N, Q, and W are positive integers.
- the authentication module 204 is specifically configured to perform the following steps:
- the apparatus further includes the following modules:
- a division module 205 which is configured to divide the target identity feature into regions to obtain I regions;
- an extraction module 206 which is further configured to extract W second feature points from each of the I regions respectively;
- the generation module 202 which is further configured to generate Q target shapes for each region according to second feature points of each region;
- a calculation module 207 which is configured to calculate a parameter value of each target shape
- the generation module 202 which is further configured to generate Q asymmetric public and private keys according to the parameter value of each target shape, and obtain Q public keys.
- the target shape is a triangle
- Q is greater than N, and I are all positive integers.
- the authentication module 204 is specifically configured to perform the following steps:
- the signature set is a set composed of the N pieces of signature information
- the target signature information is any information in the signature set.
- the parameter value of the target shape is a value of the circumference or a value of the area.
- the target identity feature includes one of the following items: fingerprint feature, facial feature, palmprint feature.
- the identity authentication apparatus 200 provided by the embodiment of the present invention performs various steps in the method 100 shown in Fig. 1, and can avoid the loss or leakage of the user identity feature information and improve the technical effect of the security of the identity authentication mode, and for the sake of concise description, it will not be described in detail here.
- parameter values of feature parameters of N target shapes can be generated based on M first feature points extracted from a target identity feature of a target user, and then asymmetric public and private keys can be generated based on the parameter values.
- the target user is authenticated based on private keys of the asymmetric public and private keys and acquired Q public keys.
- an identity of the user is authenticated according to a plurality of feature points of the target identity feature input by the user.
- the identity authentication of the target user is passed.
- the public keys are public keys of the asymmetric public and private keys generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user.
- the electronic device converts the user's identity feature information, such as facial feature, fingerprint feature, palmprint feature, etc., into digital representation, that is, the electronic device can authenticate the user's identity only by saving the public keys, without saving the original data of the user's identity features, thereby avoiding the loss or leakage of the user's identity information and improving the security of the identity authentication method.
- the user's identity features are saved in a form of numbers, without changing of the user's identity features, such as translation, rotation and scaling, which improves the efficiency of user identity authentication.
- Fig. 3 shows a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present invention.
- the electronic device may include a processor 301 and a memory 302 storing computer program instructions.
- the aforementioned processor 301 may include a central processing unit (CPU) , or an Application Specific Integrated Circuit (ASIC) , or may be configured as one or more integrated circuits for implementing the embodiments of the present invention.
- CPU central processing unit
- ASIC Application Specific Integrated Circuit
- the memory 302 may include a mass storage for data or instructions.
- the memory 302 may include a hard disk drive (Hard Disk Drive, HDD) , a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape or a universal serial bus (USB) drive, or a combination of two or more of these.
- the memory 302 may include removable or non-removable (or fixed) media.
- the memory 302 may be internal or external to the integrated gateway disaster tolerance device.
- the memory 302 is a non-volatile solid-state memory.
- the memory may include read-only memory (ROM) , random access memory (RAM) , magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical/tangible memory storage devices. Therefore, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors) , it is operable to execute the operations described with reference to the method according to an aspect of the present invention.
- the processor 301 reads and executes the computer program instructions stored in the memory 302 to implement any one of the identity authentication methods in the foregoing embodiments.
- the electronic device may further include a communication interface 303 and a bus 310.
- the processor 301, the memory 302, and the communication interface 303 are connected through the bus 310 and complete mutual communication.
- the communication interface 303 is mainly used to implement communication between various modules, apparatuses, units and/or devices in the embodiments of the present invention.
- the bus 310 includes hardware, software, or both, and couples the components of the identity authentication device to each other.
- the bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB) , hyper transfer (HT) interconnect, industry standard architecture (ISA) Bus, unlimited bandwidth interconnect, low pin count (LPC) bus, memory bus, microchannel architecture (MCA) bus, peripheral component interconnect (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology Attachment (SATA) bus, Video Electronics Standards Association Local (VLB) bus or other suitable bus or a combination of two or more of these.
- the bus 310 may include one or more buses.
- the embodiments of the present invention describe and show a specific bus, the present invention contemplates any suitable bus or interconnection.
- the electronic device can execute the identity authentication method in the embodiment of the present invention, thereby realizing the identity authentication method described in conjunction with Fig. 1 and the identity authentication apparatus described in Fig. 2.
- the embodiment of the present invention may provide a computer storage medium for implementation.
- the computer storage medium stores computer program instructions; and when the computer program instructions are executed by the processor, any one of the identity authentication methods in the foregoing embodiments is implemented.
- the functional blocks shown in the above-mentioned structural block diagram can be implemented as hardware, software, firmware, or a combination thereof.
- it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC) , appropriate firmware, a plug-in, a function card, etc.
- ASIC application specific integrated circuit
- the elements of the present invention are programs or code segments used to perform required tasks. Programs or code segments can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link through a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information.
- machine-readable media examples include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM) , floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and so on.
- the code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
- the exemplary embodiments mentioned in the present invention describe some methods or systems based on a series of steps or apparatuses.
- the present invention is not limited to the order of the above steps, that is, the steps may be performed in the order mentioned in the embodiments, or may be different from the order in the embodiments, or several steps may be performed at the same time.
- Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, an application-specific processor or a field programmable logic circuit. It can also be understood that each block in the block diagram and/or flowchart and combinations of blocks in the block diagram and/or flowchart can also be implemented by dedicated hardware that performs specified functions or actions, or by combinations of dedicated hardware and computer instructions.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Bioethics (AREA)
- Medical Informatics (AREA)
- Databases & Information Systems (AREA)
- Collating Specific Patterns (AREA)
Abstract
The invention discloses an identity authentication method, apparatus, device and storage medium. the method comprises extracting M first feature points from a target identity feature of a target user; generating N target shapes according to the M first feature points; determining a parameter value of each target shape of the N target shapes; generating N asymmetric public and private keys according to the parameter values of the N target shapes; and authenticating an identity of the target user according to private keys in the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user; wherein the public keys are public key of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user. According to the embodiment of the invention, the loss or leakage of user identity feature information can be avoided, and the security of an identity authentication mode can be improved.
Description
The invention belongs to the field of data security, and in particular, relates to an identity authentication method, apparatus, device and storage medium.
With the development of science and technology, in order to ensure the security of data stored in electronic devices, users must pass identity authentication before operating the electronic devices.
In related technologies, the electronic devices usually store the user's identity feature information in advance, and during identity authentication, it authenticates whether the input identity feature information matches the pre-stored identity feature information. When the input identity feature information matches the pre-stored identity feature information, the identity authentication is passed. However, in this identity authentication method, the pre-stored user identity feature information is at risk of being lost or leaked. Therefore, this identity authentication method does not have high security.
SUMMARY
Embodiments of the present invention provide an identity authentication method, apparatus, device and storage medium, which can avoid the loss or leakage of user identity feature information and improve the security of an identity authentication mode.
In a first aspect, an identity authentication method is provided, which includes the following steps:
extracting M first feature points from a target identity feature of a target user during a process of identity authentication of the target user;
generating N target shapes according to the M first feature points;
determining a parameter value of each target shape of the N target shapes;
generating N asymmetric public and private keys according to the parameter values of the N target shapes; and
authenticating an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user;
wherein the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user; and
wherein M, N, Q and W are positive integers.
In a possible implementation, the authenticating an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user specifically comprises the following steps:
using a private key of each asymmetric public and private key to sign an acquired random number so as to obtain N pieces of signature information; and
authenticating the N pieces of signature information by using the acquired Q public keys, and when a number of the N pieces of signature information matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user.
In a possible implementation, before extracting M first feature points from the target identity feature of the target user, the method further comprises the following steps:
dividing the target identity feature into regions to obtain I regions;
extracting W second feature points from each of the I regions respectively;
for each region, generating P target shapes according to second feature points of each region;
calculating a parameter value of each target shape; and
generating Q asymmetric public and private keys according to the parameter value of each target shape to obtain the Q public keys;
In a possible implementation, the target shape is a triangle;
a relationship between M and N satisfies the following formula:
a relationship between P and W satisfies the following formula:
a relationship among I, P and Q satisfies the following formula:
Q=I·P, and
wherein Q is greater than N.
In a possible implementation, the authenticating the N pieces of signature information by using the acquired Q public keys comprises the following steps:
performing the following steps for the Q public keys sequentially:
matching a public key with respective signature information in a signature set respectively; wherein the signature set is a set composed of the N pieces of signature information; and
when the public key matches a target signature information, removing the target signature information from the signature set to obtain an updated signature set; wherein the target signature information is any information in the signature set.
In a possible implementation, the parameter value of the target shape is a value of the circumference or a value of the area.
In a possible implementation, the target identity feature includes one of the following items: fingerprint feature, facial feature, palmprint feature.
In a second aspect, an identity authentication apparatus is provided, the identity authentication apparatus includes the following modules:
an extraction module, which is configured to extract M first feature points from a target identity feature of a target user during a process of identity authentication of the target user;
a generation module, which is configured to generate N target shapes according to the M first feature points;
a determination module, which is configured to determine a parameter value of each target shape of the N target shapes;
the generation module, which is further configured to generate N asymmetric public and private keys according to the parameter values of the N target shapes; and
an authentication module, which is configured to authenticate an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, pass the identity authentication of the target user;
wherein the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user; and
wherein M, N, Q and W are positive integers.
In a possible implementation, the authentication module is specifically configured to perform the following steps:
using a private key of each asymmetric public and private key to sign an acquired random number so as to obtain N pieces of signature information; and
authenticating the N pieces of signature information by using the acquired Q public keys, and when a number of the N pieces of signature information matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user.
In a possible implementation, the apparatus further includes the following modules:
a division module, which is configured to divide the target identity feature into regions to obtain I regions;
an extraction module, which is configured to extract W second feature points from each of the I regions respectively;
the generation module, which is also configured to generate Q target shapes for each region according to the second feature point of each region;
a calculation module, which is configured to calculate a parameter value of each target shape; and
the generation module, which is configured to generate Q asymmetric public and private keys according to the parameter value of each target shape to obtain the Q public keys.
In a possible implementation, the target shape is a triangle;
a relationship between M and N satisfies the following formula:
a relationship between I, Q and W satisfies the following formula:
wherein, Q is greater than N, and I are all positive integers.
In a possible implementation, the authentication module is specifically configured to perform the following steps:
performing the following steps for the Q public keys sequentially:
matching the public key with respective signature information in a signature set respectively; wherein the signature set is a set composed of the N pieces of signature information; and
when the public key matches a target signature information, removing the target signature information from the signature set to obtain an updated signature set; wherein the target signature information is any information in the signature set.
In a possible implementation, the parameter value of the target shape is a value of the circumference or a value of the area.
In a possible implementation, the target identity feature comprises one of the following items: fingerprint feature, facial feature and palmprint feature.
In a third aspect, an electronic device is provided, the device comprises a processor and a memory storing computer program instructions; and when the processor executes the computer program instructions, the method as in the first aspect or any possible implementation of the first aspect is implemented.
In a fourth aspect, a computer storage medium is provided. The computer storage medium stores computer program instructions. When the computer program instructions are executed by a processor, the method in the first aspect or any possible implementation of the first aspect is implemented.
Based on the provided identity authentication method, apparatus, device and storage medium, during a process of identity authentication of a target user, based on M first feature points extracted from a target identity feature of the target user, parameter values of feature parameters of N target shapes can be generated, and then asymmetric public and private keys can be generated based on the parameter values. The target user is authenticated based on private keys of the asymmetric public and private keys and acquired Q public keys. And an identity of the user is authenticated according to a plurality of feature points of the target identity feature input by the user. When a number of private keys of N private keys matched with the Q public keys is greater than a preset threshold, the identity authentication of the target user is passed. Herein, the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user. As a result, the electronic device converts the user's identity feature information, such as facial feature, fingerprint feature, palmprint feature, etc., into digital representation, that is, the electronic device can authenticate the user's identity only by saving the public keys, without saving the original data of the user's identity features, thereby avoiding the loss or leakage of the user's identity information and improving the security of the identity authentication method.
In order to explain the technical solutions of the embodiments of the present invention more clearly, the following will briefly introduce the drawings needed in the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to these drawings without paying creative labor.
Fig. 1 is a schematic flowchart of an identity authentication method provided by an embodiment of the present invention;
Fig. 2 is a schematic structural diagram of an identity authentication apparatus provided by an embodiment of the present invention; and
Fig. 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention.
The features and exemplary embodiments of various aspects of the present invention will be described in detail below. In order to make the object, technical scheme and advantages of the present invention clearer, the present invention will be further described in detail with reference to the drawings and specific embodiments. It should be understood that the specific embodiments described herein are only configured to explain the present invention, and are not configured to limit the present invention. It will be apparent to those skilled in the art that the present invention may be practiced without some of these specific details. The following description of the embodiments is only for providing a better understanding of the present invention by illustrating examples of the present invention.
It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "including" , "comprising" or any other variation thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article or device. Without further restrictions, the elements defined by the sentence "including... " do not exclude the existence of other identical elements in the process, method, article or device including the elements.
With the development of science and technology, in order to ensure the security of data stored in electronic devices, users must pass identity authentication before operating the electronic devices.
In related technologies, the electronic devices usually store the user's identity feature information in advance, and during a process of identity authentication, they authenticate whether input identity feature information matches pre-saved identity feature information. When the input identity feature information is matched with the pre-saved identity feature information, the identity authentication is passed. For example, when a user uses a fingerprint for identity authentication, a pre-stored user fingerprint template is used in related technologies to match the user fingerprint entered into the electronic device. The fingerprint template saves complete data of the user's fingerprint, but in the case of data leakage of the electronic device, it is easy to leak the complete data of the user's fingerprint, which will cause unnecessary loss to the user after the complete data of the user's fingerprint are used by criminals. Therefore, in the identity authentication methods in related technologies, the pre-stored user identity feature information is at risk of being lost or leaked. Therefore, this identity authentication method does not have high security.
In addition, in related technologies, during the process of identity authentication, it is necessary to translate, rotate, scale and other transformations of a fingerprint saved in electronic devices, so as to complete the identity authentication. However, the translation, rotation and scaling of the fingerprint reduce the efficiency of identity authentication of electronic devices.
In order to solve the technical problems in related technologies, the embodiment of the present invention provides an identity authentication method, apparatus, device and storage medium, which can avoid the loss or leakage of user identity feature information and improve the security of the identity authentication mode.
In order to facilitate understanding of the embodiments of the present invention, the identity authentication method provided by the embodiments of the present invention is described in detail below.
Fig. 1 shows a schematic flowchart of an identity authentication method 100 provided by an embodiment of the present invention. As shown in Fig. 1, the identity authentication method 100 provided by the embodiment of the present invention may include the following steps.
At S101, M first feature points are extracted from a target identity feature of a target user during a process of identity authentication of the target user.
Before authenticating the user’s identify, it is necessary to extract feature points of the user's identity feature, so as to complete the identity authentication of the user. The target user is a user who needs to be authenticated. For example, a target user A needs to use an application A in an electronic device to perform transfer operation, and the identity authentication of the target user A needs to be performed before perform the identity transfer, so the feature points of the identity features of the target user A need to be extracted. The target identity feature refers to any identity feature that can represent the user's identity. For example, the target identity feature may include fingerprint feature, facial feature and palmprint feature.
Before the user performs identity authentication, the electronic device needs to enter the user's target identity feature, and then the electronic device extracts M first feature points from the user's target identity feature. For example, if the user uses the user's facial feature for identity authentication, the user can use a camera device of the electronic device to photograph his own facial feature, so that the electronic device can extract feature points in the user's facial feature, and then authenticate the user.
As an example, the user A uses his fingerprint feature for identity authentication, and the user A transmits the fingerprint feature of the user A to the electronic device through a fingerprint entry module on the electronic device. After receiving the fingerprint feature of the user A, the electronic device extracts M feature points from the fingerprint feature.
At S102, N target shapes are generated according to the M first feature points.
Based on the extracted M first feature points, N target shapes are constructed. The M first feature points are connected to construct the N target shapes.
Here, the target shape may be a triangle.
Optionally, when the target shape is a triangle, a relationship between M and N satisfies the following formula (1) :
Here M and N are both positive integers.
In addition, the target shape may also be a polygon such as a quadrilateral. After the M first feature points are extracted, the M first feature points are connected to construct multiple polygons.
At S103, a parameter value of each target shape in the N target shapes is determined.
After the target shape is obtained, the parameter value of the target shape is calculated. Herein the parameter value may be a value of a perimeter or a value of an area. For example, if the target shape is a triangle, the parameter value may be a value of the perimeter of the triangle or a value of the area of the triangle.
At S104, N asymmetric public and private keys are generated according to the parameter values of the N target shapes.
Based on a parameter value of each target shape, asymmetric public and private keys corresponding to the parameter value is calculated. Thus, according to the parameter values of the N target shapes, N asymmetric public and private keys can be obtained.
At S105, an identity of the target user is authenticated according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is greater than a preset threshold, the identity authentication of the target user is passed.
The private keys of the N asymmetric public and private keys are matched with the acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is greater than the preset threshold, the identity authentication of the target user is passed.
The Q public keys may be multiple public keys generated in advance and saved in the electronic device. The public keys are public key of the asymmetric public and private keys generated according to parameter values of a target shapes; and the parameter values of the target shapes are determined by the W second feature points in the target identity feature of the target user.
Optionally, in an embodiment of the present invention, before S101, the embodiment of the present invention may include the following steps.
The target identity feature is divided into regions to obtain I regions.
W second feature points are extracted from each of the I regions respectively.
For each region, P target shapes are generated according to the second feature points of each region.
A parameter value of each target shape is calculated.
According to the parameter value of each target shape, Q asymmetric public and private keys are generated, and Q public keys are obtained.
The user needs to save the identity feature in the electronic device. In order to ensure that the identity feature of the user is not leaked, the target identity feature needs to be divided into regions to obtain I regions. For example, the fingerprint feature of the user is divided into 5 regions.
After the target identity feature is divided into regions, W second feature points are extracted from each region. The W second feature points of each region are connected to construct P target shapes. The parameter value of each target shape is calculated. The parameter value may include a value of the perimeter of the target shape, a value of the area of the target shape, and the like. For example, the shape of the target is a triangle, and after P triangles are determined, the perimeter of each triangle is calculated. When the target shape is a triangle, the parameter value may also be a combination of angles, for example, three angles of the triangle are 90°, 45°, and 45°.
Optionally, when the target shape is a triangle, a relationship between P and W satisfies the following formula (2) :
Both P and W are positive integers.
A relationship between I, P, and Q satisfies the following formula (3) :
Q=I·P (3) .
Here I is a positive integer, and Q is greater than N.
Q asymmetric public and private keys are generated based on the parameter value of each target shape, and then Q public keys are obtained. Here, In order to ensure the security of information, after Q asymmetric public and private keys are generated, the private keys of the Q asymmetric public and private keys may also be destroyed.
As a result, completion information of the user's target identity feature is converted into a digital form and saved in the electronic device, so that the user's identity authentication can be realized, the loss or leakage of the user's identity feature information can be avoided, and the security of the identity authentication mode can be improved.
Optionally, S105 in the identity authentication method 100 provided in the embodiment of the present invention specifically authenticates the N pieces of signature information in the following manner.
A private key of each asymmetric public and private key is used to sign an acquired random number, so as to obtain N pieces of signature information; and
The N pieces of signature information are authenticated by using the acquired Q public keys, and when a number of the N pieces of signature information matched with the Q public keys is greater than a preset threshold, the identity authentication of the target user is passed.
The private keys of the N asymmetric public and private keys are used to sign the acquired random number, and then obtain N pieces of signature information. The N pieces of signature information are authenticated by using Q public keys.
Optionally, the following steps are performed for Q public keys sequentially:
matching a public key with respective signature information in a signature set respectively; herein the signature set is a set composed of the N pieces of signature information; and
when the public key matches a target signature information, removing the target signature information from the signature set to obtain an updated signature set; herein the target signature information is any information in the signature set.
Take N pieces of signature information as a signature set. For Q public keys, N pieces of signature information may be authenticated sequentially. In other words, the authenticated public key does not need to be authenticated again. After matching the public key with the respective signature information, it is determined that the target signature information in the signature set matches the public key, and then the target signature information is removed from the signature set to obtain an updated signature set. The target signature information is any signature information in the signature set.
For example, the public keys are {AB C D E F G H I J} respectively, and the signature set is {1 2 3 4 5 6 7} . The signature information is authenticated by using a public key A, where the public key A matches signature information 2, then the signature set is updated to {1 3 4 5 6 7} . The public key B is used to authenticate the signature information. Where the public key B matches the signature information 5, then the signature set is updated to {1 3 4 6 7} , and so on.
When a number of signature information matched with the public key is greater than a preset threshold, the identity authentication of the target user is passed.
The identity authentication method 100 provided by the embodiment of the present invention can generate the parameter values of the feature parameters of the N target shape based on the M first feature points extracted from the target identity feature of the target user, and then generate asymmetric public and private keys based on the parameter values. The target user is authenticated based on private keys of the asymmetric public and private keys and the acquired Q public keys. And the user's identity is authenticated with multiple feature points of the target identity feature input by the user. When a number of private keys of the N private keys matched with Q public keys is greater than the preset threshold, the identity authentication of the target user is passed. Herein the public keys are the public keys of the asymmetric public and private keys generated according to the parameter values of the target shapes; and the parameter values of the target shapes are determined by the W second feature points in the target identity feature of the target user. As a result, the electronic device converts the user's identity feature information, such as facial feature, fingerprint feature, palmprint feature, etc., into digital representation, that is, the electronic device can authenticate the user's identity only by saving the public keys, without saving the original data of the user's identity features, thereby avoiding the loss or leakage of the user's identity information and improving the security of the identity authentication method.
Moreover, the user's identity features are saved in a form of numbers, without changing of the user's identity features, such as translation, rotation or scaling, which improves the efficiency of user identity authentication.
Based on the embodiment of the method 100 corresponding to Fig. 1, the embodiment of the present invention also provides an identity authentication apparatus. The identity authentication apparatus will be described in detail below.
Fig. 2 is a schematic structural diagram of an identity authentication apparatus 200 provided by an embodiment of the present invention. As shown in Fig. 2, the identity authentication apparatus 200 provided in the embodiment of the present invention may include an extraction module 201, a generation module 202, a determination module 203, and an authentication module 204.
The extraction module 201 is configured to extract M first feature points from a target identity feature of a target user during a process of identity authentication of the target user.
The generation module 202 is configured to generate N target shapes according to the M first feature points.
The determination module 203 is configured to determine a parameter value of each target shape in the N target shapes.
The generation module 202 is further configured to generate N asymmetric public and private keys according to the parameter value of each target shape.
The authentication module 204 is configured to authenticate an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, pass the identity authentication of the target user.
Herein, the public keys are public keys of the asymmetric public and private key generated according to parameter values of the target shapes; and the parameter values of the target shapes are determined by the W second feature points in the target identity feature of the target user.
Herein, M, N, Q, and W are positive integers.
In a possible implementation, the authentication module 204 is specifically configured to perform the following steps:
using a private key of each asymmetric public and private key to sign an acquired random number so as to obtain N pieces of signature information; and
authenticating the N pieces of signature information by using the acquired Q public keys, and when a number of the N pieces of signature information matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user.
In a possible implementation, the apparatus further includes the following modules:
a division module 205, which is configured to divide the target identity feature into regions to obtain I regions;
an extraction module 206, which is further configured to extract W second feature points from each of the I regions respectively;
the generation module 202, which is further configured to generate Q target shapes for each region according to second feature points of each region;
a calculation module 207, which is configured to calculate a parameter value of each target shape; and
the generation module 202, which is further configured to generate Q asymmetric public and private keys according to the parameter value of each target shape, and obtain Q public keys.
In a possible implementation, the target shape is a triangle;
a relationship between M and N satisfies the following formula:
a relationship between I, Q and W satisfies the following formula:
Herein, Q is greater than N, and I are all positive integers.
In a possible implementation, the authentication module 204 is specifically configured to perform the following steps:
performing the following steps for the Q public keys sequentially:
matching a public key with respective signature information in a signature set respectively; herein the signature set is a set composed of the N pieces of signature information; and
when the public key matches the target signature information, removing the target signature information from the signature set to obtain an updated signature set; herein the target signature information is any information in the signature set.
In a possible implementation, the parameter value of the target shape is a value of the circumference or a value of the area.
In a possible implementation, the target identity feature includes one of the following items: fingerprint feature, facial feature, palmprint feature.
The identity authentication apparatus 200 provided by the embodiment of the present invention performs various steps in the method 100 shown in Fig. 1, and can avoid the loss or leakage of the user identity feature information and improve the technical effect of the security of the identity authentication mode, and for the sake of concise description, it will not be described in detail here.
According to the identity authentication apparatus 200 provided by the embodiment of the present invention, parameter values of feature parameters of N target shapes can be generated based on M first feature points extracted from a target identity feature of a target user, and then asymmetric public and private keys can be generated based on the parameter values. The target user is authenticated based on private keys of the asymmetric public and private keys and acquired Q public keys. And an identity of the user is authenticated according to a plurality of feature points of the target identity feature input by the user. When a number of private keys of N private keys matched with the Q public keys is greater than the preset threshold, the identity authentication of the target user is passed. Herein, the public keys are public keys of the asymmetric public and private keys generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user. As a result, the electronic device converts the user's identity feature information, such as facial feature, fingerprint feature, palmprint feature, etc., into digital representation, that is, the electronic device can authenticate the user's identity only by saving the public keys, without saving the original data of the user's identity features, thereby avoiding the loss or leakage of the user's identity information and improving the security of the identity authentication method.
Moreover, the user's identity features are saved in a form of numbers, without changing of the user's identity features, such as translation, rotation and scaling, which improves the efficiency of user identity authentication.
Fig. 3 shows a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present invention.
The electronic device may include a processor 301 and a memory 302 storing computer program instructions.
Specifically, the aforementioned processor 301 may include a central processing unit (CPU) , or an Application Specific Integrated Circuit (ASIC) , or may be configured as one or more integrated circuits for implementing the embodiments of the present invention.
The memory 302 may include a mass storage for data or instructions. By way of example and not limitation, the memory 302 may include a hard disk drive (Hard Disk Drive, HDD) , a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 302 may include removable or non-removable (or fixed) media. Where appropriate, the memory 302 may be internal or external to the integrated gateway disaster tolerance device. In a particular embodiment, the memory 302 is a non-volatile solid-state memory.
The memory may include read-only memory (ROM) , random access memory (RAM) , magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical/tangible memory storage devices. Therefore, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors) , it is operable to execute the operations described with reference to the method according to an aspect of the present invention.
The processor 301 reads and executes the computer program instructions stored in the memory 302 to implement any one of the identity authentication methods in the foregoing embodiments.
In an example, the electronic device may further include a communication interface 303 and a bus 310. Herein, as shown in Fig. 3, the processor 301, the memory 302, and the communication interface 303 are connected through the bus 310 and complete mutual communication.
The communication interface 303 is mainly used to implement communication between various modules, apparatuses, units and/or devices in the embodiments of the present invention.
The bus 310 includes hardware, software, or both, and couples the components of the identity authentication device to each other. By way of example and not limitation, the bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB) , hyper transfer (HT) interconnect, industry standard architecture (ISA) Bus, unlimited bandwidth interconnect, low pin count (LPC) bus, memory bus, microchannel architecture (MCA) bus, peripheral component interconnect (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology Attachment (SATA) bus, Video Electronics Standards Association Local (VLB) bus or other suitable bus or a combination of two or more of these. Where appropriate, the bus 310 may include one or more buses. Although the embodiments of the present invention describe and show a specific bus, the present invention contemplates any suitable bus or interconnection.
The electronic device can execute the identity authentication method in the embodiment of the present invention, thereby realizing the identity authentication method described in conjunction with Fig. 1 and the identity authentication apparatus described in Fig. 2.
In addition, in combination with the identity authentication method in the foregoing embodiment, the embodiment of the present invention may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; and when the computer program instructions are executed by the processor, any one of the identity authentication methods in the foregoing embodiments is implemented.
It should be clear that the present invention is not limited to the specific configuration and processing described above and shown in the drawings. For brevity, a detailed description of the known method is omitted here. In the above embodiment, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present invention.
The functional blocks shown in the above-mentioned structural block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC) , appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform required tasks. Programs or code segments can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link through a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM) , floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
It should also be noted that the exemplary embodiments mentioned in the present invention describe some methods or systems based on a series of steps or apparatuses. However, the present invention is not limited to the order of the above steps, that is, the steps may be performed in the order mentioned in the embodiments, or may be different from the order in the embodiments, or several steps may be performed at the same time.
Aspects of the present invention have been described above with reference to the flowcharts and/or block diagrams of the methods, apparatuses (systems) and computer program products according to the embodiments of the present invention. It should be understood that each block in the flowcharts and/or block diagrams and combinations of blocks in the flowcharts and/or block diagrams can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, which are executed via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions/acts specified in one or more blocks of the flowchart and/or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, an application-specific processor or a field programmable logic circuit. It can also be understood that each block in the block diagram and/or flowchart and combinations of blocks in the block diagram and/or flowchart can also be implemented by dedicated hardware that performs specified functions or actions, or by combinations of dedicated hardware and computer instructions.
The above is only a specific embodiment of the present invention, and it can be clearly understood by those skilled in the art that for the convenience and conciseness of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be described in detail here. It should be understood that the protection scope of the present invention is not limited to this, and any person familiar with the technical field can easily think of various equivalent modifications or substitutions within the technical scope disclosed by the present invention, which should be covered within the protection scope of the present invention.
Claims (10)
- An identity authentication method, comprising:extracting M first feature points from a target identity feature of a target user during a process of identity authentication of the target user;generating N target shapes according to the M first feature points;determining a parameter value of each target shape of the N target shapes;generating N asymmetric public and private keys according to the parameter values of the N target shapes; andauthenticating an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user;wherein the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user; andwherein M, N, Q and W are positive integers.
- The method according to claim 1, wherein the authenticating an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user, specifically comprises:using a private key of each asymmetric public and private key to sign an acquired random number so as to obtain N pieces of signature information; andauthenticating the N pieces of signature information by using the acquired Q public keys, and when a number of the N pieces of signature information matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user.
- The method according to claim 1, wherein before extracting M first feature points from the target identity feature of the target user, the method further comprises:dividing the target identity feature into regions to obtain I regions;extracting W second feature points from each of the I regions respectively;for each region, generating P target shapes according to second feature points of each region;calculating a parameter value of each target shape; andgenerating Q asymmetric public and private keys according to the parameter value of each target shape to obtain the Q public keys;wherein I and P are positive integers.
- The method according to claim 3, wherein the target shape is a triangle;a relationship between M and N satisfies the following formula:a relationship between P and W satisfies the following formula:a relationship among I, P and Q satisfies the following formula:Q=I·P, andwherein Q is greater than N.
- The method according to claim 1, wherein the authenticating the N pieces of signature information by using the acquired Q public keys comprises:performing the following steps for the Q public keys sequentially:matching a public key with respective signature information in a signature set respectively; wherein the signature set is a set composed of the N pieces of signature information; andwhen the public key matches a target signature information, removing the target signature information from the signature set to obtain an updated signature set; wherein the target signature information is any information in the signature set.
- The method according to any one of claims 1-5, wherein the parameter value of the target shape is a value of perimeter or a value of area.
- The method according to any one of claims 1-5, wherein the target identity feature comprises one of the following items: fingerprint feature, facial feature and palmprint feature.
- An identity authentication apparatus, comprising:an extraction module, configured to extract M first feature points from a target identity feature of a target user during a process of identity authentication of the target user;a generation module, configured to generate N target shapes according to the M first feature points;a determination module, configured to determine a parameter value of each target shape of the N target shapes;the generation module, further configured to generate N asymmetric public and private keys according to the parameter values of the N target shapes; andan authentication module, configured to authenticate an identity of the target user according to private keys of the N asymmetric public and private keys and acquired Q public keys, and when a number of the private keys of the N private keys matched with the Q public keys is larger than a preset threshold, passing the identity authentication of the target user;wherein the public keys are public keys of the asymmetric public and private key generated according to parameter values of target shapes; and the parameter values of the target shapes are determined by W second feature points in the target identity feature of the target user; andwherein M, N, Q and W are positive integers.
- An electronic device, comprising: a processor and a memory storing computer program instructions; whereinwhen the processor executes the computer program instructions, the method according to any one of claims 1-7 is implemented.
- A computer storage medium having stored thereon computer program instructions which, when executed by a processor, implement the method according to any one of claims 1-7.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010720845.3 | 2020-07-24 | ||
| CN202010720845.3A CN111931146B (en) | 2020-07-24 | 2020-07-24 | Identity verification methods, devices, equipment and storage media |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022017452A1 true WO2022017452A1 (en) | 2022-01-27 |
Family
ID=73314535
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2021/107818 Ceased WO2022017452A1 (en) | 2020-07-24 | 2021-07-22 | Identity authentication method, apparatus, devices and storage media |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN111931146B (en) |
| WO (1) | WO2022017452A1 (en) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115314243A (en) * | 2022-06-23 | 2022-11-08 | 湖北鑫英泰系统技术股份有限公司 | Mobile operation and maintenance authentication method and gateway based on identity authentication |
| CN116668127A (en) * | 2023-06-02 | 2023-08-29 | 中国工商银行股份有限公司 | Method and device for determining data packet sending object |
| CN117592135A (en) * | 2023-11-27 | 2024-02-23 | 成都芯盛集成电路有限公司 | Disk data protection method, device, equipment and media based on GRUB |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111931146B (en) * | 2020-07-24 | 2024-01-19 | 捷德(中国)科技有限公司 | Identity verification methods, devices, equipment and storage media |
| CN115129229A (en) * | 2021-03-25 | 2022-09-30 | 北京奇虎科技有限公司 | Information storage method, device, storage medium and device |
| CN113282911A (en) * | 2021-05-12 | 2021-08-20 | 捷德(中国)科技有限公司 | Identity authentication method, device, equipment and computer storage medium |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101414903A (en) * | 2007-10-16 | 2009-04-22 | 吴显平 | Method for generating sharing cipher key, and enciphering and deciphering method |
| US20160071101A1 (en) * | 2014-09-09 | 2016-03-10 | Tyson York Winarski | Selfie financial security transaction system |
| CN108650266A (en) * | 2018-05-14 | 2018-10-12 | 平安科技(深圳)有限公司 | Server, the method for voice print verification and storage medium |
| CN110995410A (en) * | 2019-11-12 | 2020-04-10 | 杭州云萃流图网络科技有限公司 | Method, device, equipment and medium for generating public key and private key |
| CN111931146A (en) * | 2020-07-24 | 2020-11-13 | 捷德(中国)科技有限公司 | Identity authentication method, device, equipment and storage medium |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107231234B (en) * | 2016-03-25 | 2020-06-09 | 创新先进技术有限公司 | Identity registration method and device |
| US10938572B2 (en) * | 2018-01-10 | 2021-03-02 | International Business Machines Corporation | Revocable biometric-based keys for digital signing |
-
2020
- 2020-07-24 CN CN202010720845.3A patent/CN111931146B/en active Active
-
2021
- 2021-07-22 WO PCT/CN2021/107818 patent/WO2022017452A1/en not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101414903A (en) * | 2007-10-16 | 2009-04-22 | 吴显平 | Method for generating sharing cipher key, and enciphering and deciphering method |
| US20160071101A1 (en) * | 2014-09-09 | 2016-03-10 | Tyson York Winarski | Selfie financial security transaction system |
| CN108650266A (en) * | 2018-05-14 | 2018-10-12 | 平安科技(深圳)有限公司 | Server, the method for voice print verification and storage medium |
| CN110995410A (en) * | 2019-11-12 | 2020-04-10 | 杭州云萃流图网络科技有限公司 | Method, device, equipment and medium for generating public key and private key |
| CN111931146A (en) * | 2020-07-24 | 2020-11-13 | 捷德(中国)科技有限公司 | Identity authentication method, device, equipment and storage medium |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115314243A (en) * | 2022-06-23 | 2022-11-08 | 湖北鑫英泰系统技术股份有限公司 | Mobile operation and maintenance authentication method and gateway based on identity authentication |
| CN116668127A (en) * | 2023-06-02 | 2023-08-29 | 中国工商银行股份有限公司 | Method and device for determining data packet sending object |
| CN117592135A (en) * | 2023-11-27 | 2024-02-23 | 成都芯盛集成电路有限公司 | Disk data protection method, device, equipment and media based on GRUB |
Also Published As
| Publication number | Publication date |
|---|---|
| CN111931146B (en) | 2024-01-19 |
| CN111931146A (en) | 2020-11-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN111931146B (en) | Identity verification methods, devices, equipment and storage media | |
| US9722782B2 (en) | Information processing method, recording medium, and information processing apparatus | |
| US20260005861A1 (en) | Biometric matching method, terminal device, server, system, and medium | |
| CN105450411A (en) | Method, device and system for utilizing card characteristics to perform identity verification | |
| CN108242994B (en) | Key processing method and device | |
| US10963552B2 (en) | Method and electronic device for authenticating a user | |
| CN119005980A (en) | Block chain account generation method and system | |
| Gupta et al. | Design and implementation of an efficient fingerprint authentication algorithm using SHA-512 | |
| CN106357378A (en) | Key detection method applied to SM2 signature and system thereof | |
| KR20250057890A (en) | Object matching method, device, apparatus, system, medium and program product | |
| CN113282911A (en) | Identity authentication method, device, equipment and computer storage medium | |
| CN114978623B (en) | Face comparison method and device based on privacy protection | |
| US11586717B2 (en) | Method and electronic device for authenticating a user | |
| WO2019245437A1 (en) | Method and electronic device for authenticating a user | |
| CN116522370B (en) | Full homomorphic encryption authentication method, storage medium and electronic equipment | |
| CN113158150A (en) | Verification method, device and system | |
| KR100884743B1 (en) | Fingerprint matching method and device using fingerprint feature points and fingerprint binary image | |
| CN116186743A (en) | Data authorization method, system, equipment and storage medium based on two-dimension code | |
| CN103761509B (en) | Alignment-free fingerprint matching method based on encrypted circuit and computing circuit | |
| CN111106931B (en) | Authentication method, authentication device, terminal and computer-readable storage medium | |
| CN119624447B (en) | Information processing methods | |
| CN115211074B (en) | Method and system for processing reference face | |
| CN112398652B (en) | Information transmission method, device, equipment and storage medium | |
| CN115761035A (en) | A signature generation method, device, equipment and computer storage medium | |
| CN121883005A (en) | Automatic identification methods, devices and electronic equipment with multiple codes coexisting |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 21845725 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 21845725 Country of ref document: EP Kind code of ref document: A1 |