Strong identity authentication method and its application in online securities business

By employing a three-way collaborative authentication method involving securities firms, telecom operators, and banks, combined with mobile phone numbers and bank account information, this approach addresses the shortcomings of biometric identification and SIM card verification in securities transactions. It achieves clear identity authentication and efficient user identity verification, is applicable to various terminals and multi-SIM card scenarios, and meets the real-name registration and security certificate issuance requirements of securities transactions.

CN116861382BActive Publication Date: 2025-12-23QILU SECURITIES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310631012.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-29
Publication Date
2025-12-23
Estimated Expiration
2043-05-29

AI Technical Summary

Technical Problem

In existing securities business, biometric identification verification methods cannot provide clear identification results, posing information protection risks. Mobile phone SMS and SIM card verification cannot verify the user's identity, password verification has low strength, and there are difficulties in verifying identity in the issuance of digital certificates and dynamic passwords.

Method used

The system employs a three-party collaborative authentication method involving securities firms, telecom operators, and third-party custodian banks. It obtains temporary credentials via the operator's SDK through the user's mobile phone, combines them with the real mobile phone number and bank account information for identity verification, and achieves a clear authentication result. The system also synchronously changes the mobile phone number on the user's terminal and the bank account, and provides multiple connection methods to ensure the accuracy and efficiency of authentication.

Benefits of technology

It achieves clear identity authentication results, improves authentication strength and accuracy, reduces authentication time, enhances the issuance level of user identity credentials, is applicable to various user terminals and multi-SIM card scenarios, meets the real-name registration requirements of securities business, and provides a secure digital certificate issuance and password reset solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116861382B_ABST
    Figure CN116861382B_ABST
Patent Text Reader

Abstract

The application discloses a strong identity authentication method and application thereof in online securities business, belongs to the technical field of identity authentication, and is used for improving the identity authentication capability of securities companies on online securities system users, including authentication strength and authentication efficiency, and providing reliable technical support for securities business and customer service on the basis. The identity authentication method is a limited condition authentication method, is realized by fusing the resources of securities companies, banks and operators, needs three-party deposit binding of investors on a bank account, and reserves and uses the same mobile phone number in the securities company and the bank. The identity authentication method can comprehensively cover various SIM card and non-SIM card terminals such as mobile phones, PCs and pads and multi-SIM card application situations, and is universally applicable to various online securities business scenes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of identity authentication, in particular to a strong identity authentication method and application thereof in online securities business. BACKGROUND

[0002] In view of the late-development advantage of securities industry, the industry has adopted information technology in the early stage of construction. Today, most of securities business has been realized online. In actual production, the investor identity authentication and identification methods commonly used by securities companies mainly include: password (or called code, static password) verification, operator (mobile phone message, SIM card) verification, biometric (fingerprint, face, etc.) identification verification, digital certificate verification, dynamic password verification and combination application based on these technologies and methods.

[0003] Among them, the defects of biometric identification verification methods such as fingerprint and face are that the verification result can only give a matching probability, and cannot directly give "yes" or "no". At the same time, this technology has great risk hidden danger in personal information protection, and needs additional investment to prevent information leakage. The defects of operator verification methods such as mobile phone message verification and SIM card verification are that such verification methods can only verify the corresponding device, and cannot really verify the specific person, that is, cannot directly identify the person using the mobile phone number or SIM card device as the owner or card owner. Password verification is a weak identity authentication, which cannot be matched independently for important business applications. At the same time, biometric identification verification and mobile phone message verification need the participation of the verifier, and the verification time is longer due to human operation, and the verification efficiency is low. Digital certificate verification and dynamic password verification involve the issuance of digital certificate or dynamic password generator, and the issuance is also based on identity authentication, which again returns to the common problem of how to verify the identity of the investor online for securities companies mainly engaged in online business. SUMMARY

[0004] The embodiment of the present application provides a strong identity authentication method and application thereof in online securities business, which is used to solve the problems and deficiencies of the above-mentioned biometric identification verification methods such as fingerprint and face, operator verification methods such as mobile phone message and SIM card, and the low strength of password verification, and the investor identity verification problem in the issuance of digital certificate and dynamic password generator.

[0005] The embodiment of the present application adopts the following technical scheme:

[0006] The embodiment of the application provides a strong identity authentication method, which is realized by a three-party collaborative identification method of a securities company server, an operator server and a three-party custody bank server, and specifically comprises the following steps: a user's mobile phone performs a pre-number operation by means of an operator SDK, and after obtaining a temporary credential generated by the operator server, the user's mobile phone submits the temporary credential to the securities company server, and the securities company server obtains the user's real mobile phone number from the operator server according to the temporary credential; the securities company server searches / records the user's identity information and the three-party custody bank account information that has been bound or is to be bound in the securities company system according to the user's login information or provided information and the real mobile phone number; the securities company server initiates an information verification request to the corresponding three-party custody bank server according to the user's identity information, the three-party custody bank account information that has been bound or is to be bound and the real mobile phone number; if the feedback result of the three-party custody bank server indicates that the user is bound to a type I bank account, and the reserved mobile phone number of the type I bank account bound by the user is consistent with the real mobile phone number, then the identity identification of the user is passed, otherwise the identity identification of the user is not passed.

[0007] In order to achieve this goal, the method further comprises: the securities company makes an agreement with the investors by means of announcement and agreement signing; the agreement content is that the three-party custody account of the investor is bound to a type I bank account, and the mobile phone number reserved and used in the securities company system should be the same as the mobile phone number of the type I bank account reserved in the three-party custody bank, and when the mobile phone number is changed, the change should be synchronized in the three-party custody bank and the securities company system; in the daytime business, the securities company server checks whether the three-party custody account of the user is bound to a type I bank account and whether the mobile phone number reserved and used in the securities company system is the same as the mobile phone number of the type I bank account reserved in the three-party custody bank; when an exception is found, the securities company server pushes prompt information to the user and the related staff respectively, and provides an entry for modifying information for the user and the related staff respectively; after the business of the day or the period is completed, the securities company server counts the abnormal situation and abnormal processing situation of the user's three-party custody account not being bound to a type I bank account or the mobile phone number reserved and used in the securities company system being different from the mobile phone number of the type I bank account reserved in the three-party custody bank in the business of the day or the period, and forms a daily statistical report or a periodical statistical report; according to a preset strategy, the daily statistical report or the periodical statistical report is pushed to the related business department, the related personnel or the related user.

[0008] To achieve this goal, the three-party collaborative identification method further comprises: if the client device used by the user is a non-SIM card terminal, connecting the non-SIM card terminal with the user's reserved number mobile phone through a soft connection method or a hard connection method; wherein the soft connection method comprises: two-dimensional code connection, Token connection; the hard connection method comprises: USB interface connection; in the case of two-dimensional code connection, the user's non-SIM card terminal pops up a two-dimensional code with a first preset time limit; wherein the two-dimensional code is generated on the securities service side, and is associated with all or part of the following information: user account ID, user terminal IP, user terminal device feature information, APP version number; after the user scans the two-dimensional code using the reserved number mobile phone, the securities service side initiates and performs a three-party collaborative identification method based on the reserved mobile phone number for the user; after the three-party collaborative identification, the securities service side opens corresponding user permissions to the non-SIM card terminal within a second preset time limit; in the case of Token connection, after the user selects the Token connection method on the non-SIM card terminal, the system prompts the user to log in to the securities system for identity authentication through the reserved number mobile phone; the user logs in to the securities system using the reserved number mobile phone, and the securities service side initiates and performs a three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification is passed, the securities service side sends an authorized Token valid within a first preset time limit to the reserved number mobile phone, and after receiving the authorized Token input by the user through the non-SIM card terminal within a second preset time limit, opens corresponding user permissions to the non-SIM card terminal; in the case of user selecting USB interface connection, the system prompts the user to connect the reserved number mobile phone with the non-SIM card terminal through the USB interface; after the user selects the corresponding connection method, the securities service side initiates and performs a three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification is passed, the securities service side pushes an identification success message with a first preset time limit to the USB interface through the reserved number mobile phone; after receiving the identification success message returned by the non-SIM card terminal within a second preset time limit, the securities service side opens corresponding user permissions to the non-SIM card terminal.

[0009] To achieve this goal, the method further comprises: a user using a multi-SIM card application scenario of two or more SIM cards, including the following two scenarios: when the two or more SIM cards are both installed in a mobile phone, prompting the user to switch the SIM card corresponding to the reserved mobile phone number; after the user responds to the prompt and switches the SIM card by himself, the three-party collaborative identification method is executed again; when the two or more SIM cards are installed in a mobile phone and a non-mobile phone SIM card terminal respectively, the user's non-mobile phone SIM card terminal is connected to the reserved number mobile phone through a soft connection method or a hard connection method; wherein the non-mobile phone SIM card terminal at least includes a tablet computer; the soft connection method includes: two-dimensional code connection, Token connection; the hard connection method includes: USB interface connection; after the user selects the corresponding connection method, the three-party collaborative identification method based on the reserved mobile phone number is executed for the user.

[0010] The application embodiment further provides a series of applications of the strong identity authentication method in online securities business, and the strong identity authentication method is applied to the issuance of a digital certificate. The issuance method specifically comprises: after a user logs in a securities company system in a "static password" or "static password +" manner using a reserved number mobile phone, a securities company server automatically triggers or the user initiates a soft certificate application according to his own needs; the securities company server initiates, and executes the three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification is successfully passed, the securities company server opens the permission and executes a preset process to issue a soft certificate to the mobile phone used by the user; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

[0011] The issuance method of the digital certificate further comprises: after a user logs in a securities company system in a "static password" or "static password +" manner using a non-SIM card terminal, a securities company server automatically triggers or the user initiates a soft certificate application according to his own needs; after the user selects a soft connection method or a hard connection method of connecting the non-SIM card terminal with the reserved number mobile phone, the securities company server initiates, and executes the three-party collaborative identification method based on the reserved mobile phone number for the user; wherein the soft connection method includes: two-dimensional code connection, Token connection; the hard connection method includes: USB interface connection; if the three-party collaborative identification is successfully passed, the securities company server opens the permission and executes a preset process to issue a soft certificate to the non-SIM card terminal of the user; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

[0012] The method for issuing the digital certificate also includes the case that the user uses two or more SIM cards, specifically including the following two scenarios: when the two or more SIM cards are installed in a mobile phone, prompting the user to switch the SIM card corresponding to the reserved mobile phone number; after the user responds to the prompt and switches the SIM card by himself / herself, the three-party collaborative identification method is executed again; when the two or more SIM cards are installed in a mobile phone and a non-mobile phone SIM card terminal respectively, the non-mobile phone SIM card terminal and the mobile phone with the reserved mobile phone number are connected through a soft connection method or a hard connection method; wherein the non-mobile phone SIM card terminal at least includes a tablet computer; the soft connection method includes: two-dimensional code connection, Token connection; the hard connection method includes: USB interface connection; after the user selects the corresponding connection method, the securities service server initiates and executes the three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification is successfully passed, the securities service server opens the permission and executes the preset process to issue the soft certificate to the user terminal; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

[0013] The method for issuing the digital certificate also includes the case that the user uses two or more SIM cards, specifically including the following two scenarios: when the two or more SIM cards are installed in a mobile phone, prompting the user to switch the SIM card corresponding to the reserved mobile phone number; after the user responds to the prompt and switches the SIM card by himself / herself, the three-party collaborative identification method is executed again; when the two or more SIM cards are installed in a mobile phone and a non-mobile phone SIM card terminal respectively, the non-mobile phone SIM card terminal and the mobile phone with the reserved mobile phone number are connected through a soft connection method or a hard connection method; wherein the non-mobile phone SIM card terminal at least includes a tablet computer; the soft connection method includes: two-dimensional code connection, Token connection; the hard connection method includes: USB interface connection; after the user selects the corresponding connection method, the securities service server initiates and executes the three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification is successfully passed, the securities service server opens the permission and executes the preset process to issue the soft certificate to the user terminal; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

[0014] The application further provides an application of the strong identity authentication method in online securities business, and the strong identity authentication method is applied to password resetting, and the password resetting method specifically comprises the following steps: a user clicks a "three-party collaborative identification + bank-certificate transfer" password resetting option through a broker client, and starts a password resetting program; a broker server initiates and performs a three-party collaborative identification method based on a reserved mobile phone number for the user, and after the three-party collaborative identification is successful, the broker server prompts the user to transfer money (including money transfer of more than or equal to 0 yuan and money transfer and account offsetting after the money transfer) from a certain bank account of the same user subject to a corresponding account of the broker end or a designated special account of the broker end in order to assist in verifying the identity; if the user succeeds in the bank-certificate transfer, the broker server obtains the identity authentication method of the user at the bank end during the money transfer through a bank-certificate interface; if the identity authentication method is "password / password" or "password / password +", the broker server opens the permission within a preset time limit and allows the password resetting operation to be performed; if the user fails in the bank-certificate transfer or the identity authentication method is not "password / password" or "password / password +", the password resetting is not allowed, and corresponding prompt information is pushed to the user.

[0015] The password resetting method further comprises the following steps: a user clicks a "three-party collaborative identification + other password" password resetting option through a broker client, and starts a password resetting program; the broker server initiates and performs a three-party collaborative identification method based on a reserved mobile phone number for the user, and under the premise that the three-party collaborative identification is successful, the broker server shows a list of other passwords to the user; wherein the list of other passwords at least comprises any one or more of the following: a password of a three-party custodian bound bank account of the user, a certain bank account and password of the same subject identity of the user, and other passwords of the same user subject of the broker end; the broker server receives the input of the user in the form of a pop-up box and a preset bank card information OCR collection option according to the password type selected by the user in the list of other passwords (for example, in the embedded UnionPay SDK secure technical environment of the broker client, the bank card information provided by the user is automatically collected through the OCR technology, and the corresponding bank account password is manually input by the user), and verifies the password, including verification by means of the bank server (including the verification request of the embedded bank / UnionPay SDK of the broker client to the bank / UnionPay server).

[0016] The password resetting method further comprises: a user clicking a "three-party collaborative identification + two-way video" password resetting option through a broker client to start a password resetting procedure; the broker server initiates a three-party collaborative identification method based on the reserved mobile phone number and performs the method to the user, and further verifies the identity authenticity of the user through a two-way video mode; on the premise that the three-party collaborative identification is successful, if the two-way video verification is passed, the broker server opens the permission within a preset time limit to allow the password resetting operation; if the three-party collaborative identification is not successful or the two-way video verification is not passed, the password is not allowed to be reset, and corresponding prompt information is pushed to the user.

[0017] The application further provides an application of the strong identity authentication method in online securities business, characterized in that "password + three-party collaborative identification" is a strong identity authentication method universally applicable to various online securities business, including various important online securities business; the "password + three-party collaborative identification" specifically comprises: a user inputs a static password / password through a broker client to initiate a business appeal to the broker server; the business appeal comprises various online securities business; the broker server compares and verifies the received static password / password with a preset static password / password; meanwhile, the broker server initiates a three-party collaborative identification method based on the reserved mobile phone number to the user; if the static password / password and the three-party collaborative identification are both verified, the broker server opens any permission corresponding to the business appeal to the user within a certain time limit according to application needs.

[0018] Compared with the prior art, the strong identity authentication method and the application thereof in online securities business have the following beneficial effects:

[0019] 1. The three-party collaborative identification method can obtain a clear "yes" or "no" identification result, avoiding the shortcoming of the fingerprint, face and other biometric recognition verification technologies that can only give an identification result in the form of percentage such as similarity, compliance and matching probability.

[0020] 2. The three-party collaborative identification method integrates the resources of the broker, the bank and the operator, effectively improving the identity authentication strength of the user. On the basis of accurately verifying the mobile phone SIM card with the help of the operator resources, the user himself / herself is further identified with the help of the bank resources, improving the accuracy of the identification and being superior to the operator verification technologies and methods such as mobile phone short message / SIM card verification.

[0021] 3. The basic identification process is transparent to the user, and the identification time of several seconds to several minutes such as mobile phone short message verification and biometric information verification is improved to the network and system response level of tens of milliseconds.

[0022] 4. Refer to the Ministry of Public Security Institute of the White Paper on the eID digital identity system (2018), the technical solution with the bank of deposit and financing of the most strict financial real-name system management, through the implementation of "one person and one certificate authentication requirements" "on-site requirements" "issuance record retention requirements" and other requirements, the user digital identity certificate issued level from CIL2 level effectively improved to CIL4 level (top).

[0023] 5. The application provides a series of security measures to ensure the smooth implementation of three-party collaborative identification, including prior announcement, agreement with investors, and methods such as day-to-day, end-of-day, regular business, and abnormal processing of securities company systems.

[0024] 6. The application provides a method for three-party collaborative identification covering various types of user terminals, including the basic application method of "three-party collaborative identification" for "reserved number mobile phones", the cross-platform application method of "three-party collaborative identification" for "non-SIM card terminals", and the method of "three-party collaborative identification" for multi-SIM card application scenarios.

[0025] 7. The application provides a method for applying "three-party collaborative identification" in securities business, including: on the one hand, providing a solution for issuing secure digital certificates to users under the real-name system; providing a solution for improving the "password reset" method in the existing securities business by using "three-party collaborative identification+" technology. On the other hand, a strong identity authentication solution that can meet the identity authentication requirements of various securities business users is provided, namely the "password + three-party collaborative identification" method. According to the White Paper on the eID Digital Identity System (2018) of the Ministry of Public Security Institute, "password + three-party collaborative identification" has all the attribute characteristics of AAL3 level (top) authentication.

[0026] 8. The wide application of three-party collaborative identification technology will help to implement the real-name system for securities market accounts. BRIEF DESCRIPTION OF DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments described in the present application, and other drawings can also be obtained by those skilled in the art without creating any creative labor. In the drawings:

[0028] Figure 1 A strong identity authentication method provided by the embodiment of the present application is shown in the basic flowchart;

[0029] Figure 2 A three-party collaborative identification method provided by the embodiment of the present application is shown in the basic logic diagram;

[0030] Figure 3A daytime service processing flowchart provided for the embodiment of the present application;

[0031] Figure 4 An end-of-day, end-of-period service processing flowchart provided for the embodiment of the present application;

[0032] Figure 5 A two-dimensional code soft connection mode logic diagram provided for the embodiment of the present application;

[0033] Figure 6 A Token soft connection mode logic diagram provided for the embodiment of the present application;

[0034] Figure 7 A USB interface hard connection mode logic diagram provided for the embodiment of the present application;

[0035] Figure 8 A three-party collaborative identification logic diagram of a dual-card or multi-card mobile phone provided for the embodiment of the present application;

[0036] Figure 9 A logic diagram for applying for a soft certificate using a reserved number mobile phone provided for the embodiment of the present application;

[0037] Figure 10 A logic diagram for applying for a soft certificate using a non-SIM card terminal provided for the embodiment of the present application;

[0038] Figure 11 A logic diagram for applying for a soft certificate using a multi-SIM card mobile phone provided for the embodiment of the present application;

[0039] Figure 12 A logic diagram for applying for a soft certificate using a non-mobile phone SIM card terminal provided for the embodiment of the present application;

[0040] Figure 13 A logic diagram for remote downloading of a hard certificate to assist in strengthening user identity verification provided for the embodiment of the present application;

[0041] Figure 14 A "three-party collaborative identification + bank certificate transfer" password resetting logic diagram provided for the embodiment of the present application;

[0042] Figure 15 A "three-party collaborative identification + other password" password resetting logic diagram provided for the embodiment of the present application;

[0043] Figure 16 A "three-party collaborative identification + two-way video" password resetting logic diagram provided for the embodiment of the present application;

[0044] Figure 17A "password + three-party collaborative identification" authentication logic schematic diagram generally applicable to various strong identity authentication business scenarios is provided for the embodiments of the present application. DETAILED DESCRIPTION

[0045] In order for those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments.

[0046] It should be noted that the technical solutions have diversity in implementation, for example, the broker client and the bank client can be various terminal systems used by the user, such as a mobile phone, a PC, a Pad, etc.; the broker system and the operator system interact information in compliance with the principle of total-to-total, and the connection line can adopt operator direct connection or the technical solution of a related operator authorized service agency; the pre-fetching number and the obtaining of a temporary credential can adopt the technical solution of the operator or the technical solution of a related operator authorized service agency through the embedded broker client SDK; the pre-fetching number and the obtaining of a temporary credential can be implemented through the embedded SDK silent mode, or can be implemented through the H5 authorization confirmation page or the pop-up authorization prompt box after authorization confirmation; the broker system and the bank system interact information in compliance with the principle of total-to-total, and the connection line can adopt bank direct connection or connection through a China UnionPay intermediary service agency; the broker system and the bank system interact information in compliance with the principle of total-to-total, which can be in the bank active push / broker reading mode or in the broker active request / bank response mode; the broker system and the bank system interact information in compliance with the principle of total-to-total, which can be in the polling mode or in the concurrent execution mode; the bank end operation of the user can be performed through a bank application system such as an online bank or a mobile bank, or can be performed through the SDK of the bank or the China UnionPay embedded in the broker application system; the "password" of the "password + three-party collaborative identification" strong identity authentication generally refers to the password / password set by the user in the broker system, and if necessary, the valid password / password set by the same user in the bank system can also be used.

[0047] Based on the embodiments of the present specification, all other embodiments obtained by those skilled in the art without creative labor shall fall within the scope of protection of the present application. Meanwhile, in order to comply with the conventional usage or for the convenience of expression, the "password", "password", "static password" used in many places in the text all refer to the "Password" required for identity verification when logging into the broker system, the bank system or other related party system.

[0048] The embodiment of the application provides a strong identity authentication method, which is realized by a three-party collaborative identification method of a securities company server, an operator server and a three-party custody bank server. Before the three-party collaborative identification method is implemented, the securities company reaches an agreement with an investor and a bank in advance, so that the investor binds a three-party custody account to a type I bank account, and it is agreed that the mobile phone number reserved and used by the investor at the securities company should be the same mobile phone number of the type I account reserved by the investor at the bank, and the mobile phone number is synchronously changed at the bank and the securities company when the mobile phone number is changed.

[0049] Figure 1 A strong identity authentication method provided by the embodiment of the application is a basic flowchart of the three-party collaborative identification method, as shown in Figure 1 The three-party collaborative identification method comprises the following steps:

[0050] S101, a user's mobile phone performs a pre-number extraction operation by means of an operator SDK, submits a temporary credential generated by an operator server to a securities company server after the temporary credential is obtained, and the securities company server obtains the real mobile phone number of the user from the operator server according to the temporary credential.

[0051] S102, the securities company server searches / records the identity information of the user and the three-party custody bank account information bound / presented to be bound in the securities company system according to the login information or provided information of the user and the real mobile phone number.

[0052] S103, the securities company server initiates an information verification request to the corresponding three-party custody bank server according to the identity information of the user, the three-party custody bank account information bound / presented to be bound and the real mobile phone number.

[0053] S104, if the feedback result of the three-party custody bank server indicates that the user is bound to a type I bank account, and the reserved mobile phone number of the type I bank account bound by the user is consistent with the real mobile phone number, the identity identification of the user is passed, otherwise the identity identification of the user is not passed.

[0054] As a feasible implementation manner, Figure 2 A three-party collaborative identification method provided by the embodiment of the application is a basic logic diagram, as shown in Figure 2 The specific logic of the three-party collaborative identification method is as follows:

[0055] STEP1: the user initiates a business appeal, such as fund account login, account opening, etc.

[0056] STEP2: the securities company mobile phone APP extracts mobile network feature information to identify the operator;

[0057] STEP3: the securities company mobile phone APP calls the corresponding operator embedded SDK and initiates a pre-number extraction request to the corresponding operator server.

[0058] STEP4: The operator server responds to the pre-fetch number request and feeds back a temporary voucher;

[0059] STEP5: The broker mobile APP carries the temporary voucher to request business functions from the broker server;

[0060] STEP6: After receiving the temporary voucher, the broker server carries the temporary voucher to request the real mobile number from the operator server;

[0061] STEP7: The operator server verifies the temporary voucher, and if the verification is successful, the real mobile number information corresponding to the temporary voucher is returned; if the verification fails, the corresponding prompt information is pushed to the broker server;

[0062] STEP8: After receiving the real mobile number information, the broker server retrieves and organizes user information in the broker system according to the user's login information, or the provided identity information, bank card information, etc. or part of the information, and the real mobile number, records the relevant information, and carries the relevant information and verification request to initiate verification to the third-party custodian bank server; the relevant information includes user identity card number, bank card number, etc. or part of the information, and the real mobile number;

[0063] STEP9: The third-party custodian bank server compares the user's identity card number, bank card number, and reserved mobile number, and checks whether the user's corresponding bank account is a Class I personal bank account, etc., and feeds back the results;

[0064] STEP10: The broker server obtains the feedback results of the third-party custodian bank, and if the user's corresponding bank account is a Class I account and the mobile number is consistent, it is considered as successful identification and responds to the business function; otherwise, it is considered as failed identification and the corresponding prompt information is pushed to the user.

[0065] Further, in order to effectively implement the three-party collaborative identification method, the broker makes an agreement with the investor through announcement and agreement signing; the agreement content is: binding the investor's three-party custodian account to the Class I bank account, and the mobile number reserved and used in the broker system should be the same as the mobile number reserved in the Class I bank account of the third-party custodian bank, and when the mobile number is changed, it should be changed synchronously in the third-party custodian bank and the broker system.

[0066] It should be noted that, as mentioned above, it is a safeguard measure taken to improve the universality of the three-party collaborative identification method and effectively improve the success rate and implementation effect of the three-party collaborative identification method, and part of the investors do not have the conditions for three-party collaborative identification and do not apply the three-party collaborative identification method, which will not affect the verification quality and overall efficiency of the three-party collaborative identification method itself.

[0067] Figure 3 A day-to-day business processing flowchart provided for the embodiment of the present application is shown in Figure 3 The day-to-day business processing flow is as follows:

[0068] STEP1: The three-party custodian bank server returns the verification result;

[0069] STEP2: The broker server performs day-to-day business processing;

[0070] STEP3: The broker server determines whether the user's three-party custodian account is bound to a Class I bank account;

[0071] STEP4: When the user's three-party custodian account is not bound to a Class I bank account, the user is notified through the broker mobile APP message push or pop-up window prompt, and the relevant staff are notified through the broker employee outreach mobile APP so as to assist the user;

[0072] STEP5: The user decides to take relevant actions, such as contacting the broker / three-party custodian bank counter or authorized staff for handling, etc.;

[0073] STEP6: When the user's three-party custodian account is bound to a Class I bank account, the broker server determines whether the corresponding reserved mobile phone number is consistent;

[0074] STEP7: When the mobile phone number reserved / used by the user at the broker is consistent with the three-party custodian bank reserved mobile phone number, the subsequent business flow is entered;

[0075] STEP8: When the mobile phone number reserved / used by the user at the broker is not consistent with the three-party custodian bank reserved mobile phone number, the user is pushed with the corresponding prompt information, and is prompted to change the data flow SIM card through the mobile phone "system settings" to retry, and a "SIM card has been changed, start re-verification" selection button is displayed;

[0076] STEP9: After the user changes the data flow SIM card, clicks the "SIM card has been changed, start re-verification" selection button or logs in the system again, and the three-party collaborative identification process is executed again.

[0077] Further, Figure 4 A day-end / period-end business processing flowchart provided for the embodiment of the present application is shown in Figure 4 The day-end / period-end business processing flow is as follows:

[0078] STEP1: The broker server performs day-end / period-end business processing through the batch program;

[0079] STEP2: The broker server determines whether the user's three-party custodian account is bound to a Class I bank account through the batch program;

[0080] STEP3: The broker server runs the batch program to determine whether the reserved / used mobile phone number is consistent;

[0081] STEP4: When the user's three-party custodian account is not bound to a Class I bank account, or the reserved / used mobile phone number at the broker is inconsistent with the reserved mobile phone number at the three-party custodian bank, generate and save the daily and periodic statistical report;

[0082] STEP5: According to the established strategy, push the statistical report to the relevant business department, and push the necessary prompt information to the relevant user;

[0083] STEP6: The business department conducts work according to the daily and periodic statistical report, continuously strengthens standard management, and improves application experience;

[0084] STEP7: The user receives the prompt information and decides to take relevant actions, such as contacting the broker / three-party custodian bank counter or authorized staff for handling, etc.

[0085] It should be noted that the abnormality can be found in time through the daytime, daily, and periodic business processes, and the user can be notified through the broker's mobile APP, SMS, email, etc.; the relevant staff can be notified in time through the broker's employee's mobile APP, SMS, email, etc. to assist the user; through the daily and periodic business report, the relevant units can understand the situation in time, develop strategies and take measures to continuously improve the success rate of "three-party collaborative identification"; including collaborative bank to discover and handle user account abnormalities in time, continuously strengthen standard management, and improve user's convenience in daily business handling.

[0086] Further, Figure 5 A two-dimensional code soft connection method logic diagram provided by the embodiment of the present application is shown in Figure 5 The two-dimensional code soft connection method specifically includes the following steps:

[0087] STEP1: The user requests a business function through a "non-SIM card terminal" or actively clicks to trigger two-dimensional code (soft) connection three-party collaborative identification. First use of the terminal or expiration of authorization will also trigger cross-platform three-party collaborative identification;

[0088] STEP2: The broker server returns the two-dimensional code information, which is generated using the user account ID, user terminal IP, user terminal device feature information, and APP version number to ensure its uniqueness in the broker system, and to establish the association between the "non-SIM card terminal" and the reserved number mobile phone;

[0089] STEP3: The user scans the two-dimensional code on the "non-SIM card terminal" using the reserved number mobile phone;

[0090] STEP4: The user's reserved number mobile phone requests to perform "three-party collaborative identification";

[0091] STEP5: The securities service server initiates and performs "three-party collaborative identification" based on the reserved mobile number for the user, and returns the identification result to the user's reserved number mobile phone;

[0092] STEP6: If the identification is passed, the securities service server pushes the identification success information to the "non-SIM card terminal" and opens the corresponding permissions within the agreed time limit (such as previously agreed 30S effective);

[0093] STEP7: The user requests a business function through the "non-SIM card terminal" within the agreed time limit;

[0094] STEP8: The securities service server responds to the business function.

[0095] Figure 6 A Token soft connection method logic diagram provided for the embodiments of the present application is shown in FIG. 1, which specifically includes the following steps: Figure 6

[0096] STEP1: The user requests a business function through the "non-SIM card terminal" or actively clicks to trigger Token (soft) connection three-party collaborative identification. First use of the terminal or expiration of authorization will also trigger cross-platform three-party collaborative identification;

[0097] STEP2: The securities service server pushes a prompt "waiting for input Token" to the "non-SIM card terminal";

[0098] STEP3: After the user logs in using the reserved number mobile phone, the user's reserved number mobile phone requests to perform "three-party collaborative identification";

[0099] STEP4: The securities service server initiates and performs "three-party collaborative identification" based on the reserved mobile number for the user. If the identification is passed, a Token is generated and returned to the user's reserved number mobile phone;

[0100] STEP5: The user uses the "non-SIM card terminal" to input the Token within the agreed time limit and requests a business function;

[0101] STEP6: The securities service server opens the corresponding permissions of the "non-SIM card terminal" and responds to the business function.

[0102] Figure 7 A USB interface hard connection method logic diagram provided for the embodiments of the present application is shown in FIG. 2, which specifically includes the following steps: Figure 7

[0103] ​​STEP1: The user requests a service function through the "non-SIM card terminal" or actively clicks to trigger the USB interface (hard) connection three-party collaborative identification. First use of the terminal or expiration of authorization will also trigger cross-platform three-party collaborative identification.

[0104] STEP2: The broker server pushes a "waiting for connection device" prompt to the "non-SIM card terminal";

[0105] STEP3: The user uses a mobile phone multi-purpose charging line or other USB interface to connect the reserved number mobile phone and the "non-SIM card terminal";

[0106] STEP4: After the user logs in using the reserved number mobile phone, the user's reserved number mobile phone requests to perform "three-party collaborative identification";

[0107] STEP5: The broker server initiates and performs "three-party collaborative identification" based on the reserved mobile phone number for the user. If the identification is successful, it pushes the identification success information to the user's reserved number mobile phone;

[0108] STEP6: The user's reserved number mobile phone pushes the identification success information to the "non-SIM card terminal" through the USB interface;

[0109] STEP7: The "non-SIM card terminal" requests a service function within the agreed time limit (such as 30S valid);

[0110] STEP8: The broker server opens the corresponding permissions of the "non-SIM card terminal" and responds to the service function.

[0111] As a feasible implementation, the connection method of the client's reserved number mobile phone and the "non-SIM card terminal" can be included in the selection range if it meets the following two requirements: first, the connection between the reserved number mobile phone and the "non-SIM card terminal" requires the user's participation and is achieved through manual operation to prove that the user can control both terminals (such as NFC near field communication, etc.) at the same time; second, the connection between the reserved number mobile phone and the "non-SIM card terminal" should have features and preventive measures to resist hijacking and theft of the connection and related information.

[0112] Further, Figure 8 A three-party collaborative identification logic diagram of a dual-card or multi-card mobile phone provided by an embodiment of the present application is shown in Figure 8 The three-party collaborative identification logic of the dual-card or multi-card mobile phone is as follows:

[0113] STEP1: The user uses the mobile phone APP to log in to the broker system in "static password" or "static password +" mode;

[0114] STEP2: automatically execute the "three-party collaborative identification" basic process;

[0115] STEP3: if the "three-party collaborative identification" is not passed, prompt the user with relevant information (such as "if your mobile phone is configured with two or more SIM cards, in order to improve security and enjoy more convenient operation, please choose to use your reserved number SIM card");

[0116] STEP4: if the user selects "switch SIM card", then switch the SIM card by himself through the "system settings" of the mobile phone;

[0117] STEP5: if the user completes the SIM card switching operation and exits the APP login, then return to STEP1 to log in to the securities company system again; if not, go to STEP2 to automatically execute the "three-party collaborative identification" basic process again;

[0118] STEP6: if the user selects "continue to the next step", then use the existing identification technology;

[0119] STEP7: if the "three-party collaborative identification" is passed or the "three-party collaborative identification" is not passed and the existing identification technology is passed, then continue the subsequent business process.

[0120] Further, if the user uses other non-SIM card terminals such as Pad, as a feasible implementation manner, if the user uses the customized version of the client software of the corresponding device, the application strategy consistent with the "non-SIM card device" is adopted (such client software is designed to automatically execute the "three-party collaborative identification" basic process after user login; the cross-device "three-party collaborative identification" method is consistent with the cross-platform operation of "non-SIM card device"). If the user uses a general mobile phone APP or other client software, the software allows the user to select or configure after installation that "this terminal device does not execute local 'three-party collaborative identification' mode" during initial installation, and implements "three-party collaborative identification" in daily business in a cross-device operation mode consistent with the cross-platform operation of "non-SIM card device".

[0121] The above method further solves the problem of user's multi-SIM card application on the basis of solving the cross-platform application of "three-party collaborative identification" of non-SIM card terminal, and realizes the universal application of the technology in the process of securities business and services.

[0122] On the other hand, the strong identity authentication method provided by the embodiments of the present application also provides a series of applications in online securities business. Specifically, the strong identity authentication method can be applied to the issuance of digital certificates.

[0123] Figure 9 A logic diagram for applying for a soft certificate using a reserved number mobile phone provided by the embodiments of the present application is shown in FIG. 1.Figure 9 As shown in the figure, the specific steps are as follows:

[0124] STEP1: The user uses the reserved number mobile phone to log in to the securities company system in a "static password" or "static password +" manner;

[0125] STEP2: The user's reserved number mobile phone initiates a login request to the securities company server;

[0126] STEP3: The securities company server returns the login result to the user's reserved number mobile phone, and if the login is successful, it shows the user an application certificate button, and if the login fails, it pushes the corresponding prompt information to the user;

[0127] STEP4: The user clicks the application certificate button to initiate an application certificate request (the securities company server will also automatically trigger the application certificate request according to the established strategy, for example, when the "certificate expires" and the like occurs);

[0128] STEP5: The user's reserved number mobile phone requests to perform "three-party collaborative identification";

[0129] STEP6: The securities company server initiates and performs "three-party collaborative identification" based on the reserved mobile phone number to the user;

[0130] STEP7: If the "three-party collaborative identification" is successfully passed, the securities company server opens the permission and performs the corresponding process to issue a soft certificate to the user's reserved number mobile phone, and if the "three-party collaborative identification" is not successfully passed, it pushes the corresponding prompt information to the user.

[0131] Figure 10 A logic diagram for applying for a soft certificate using a non-SIM card terminal provided by an embodiment of the present application is shown in Figure 10 As shown in the figure, the specific steps are as follows:

[0132] STEP1: The user uses its desktop PC or other "non-SIM card terminal" to log in to the securities company system in a "static password" or "static password +" manner;

[0133] STEP2: The "non-SIM card terminal" initiates a login request to the securities company server;

[0134] STEP3: The securities company server returns the login result to the "non-SIM card terminal", and if the login is successful, it shows the user an application certificate button; if the login fails, it pushes the corresponding prompt information to the user;

[0135] STEP4: The user initiates an application certificate request (the securities company server will also automatically trigger the application certificate request according to the established strategy, for example, when the "certificate expires" and the like occurs);

[0136] STEP5: The user uses the reserved number mobile phone to participate in the "non-SIM card terminal" cross-platform "three-party collaborative identification" in the form of a two-dimensional code (soft) connection, a Token (soft) connection, a USB interface (hard) connection, etc. The broker server initiates and performs "three-party collaborative identification" based on the reserved mobile phone number for the user.

[0137] STEP6: If the "three-party collaborative identification" is successfully passed, the broker server opens the permission and executes the corresponding process to issue a soft certificate to the user "non-SIM card terminal". If the "three-party collaborative identification" is not successfully passed, the corresponding prompt information is pushed to the user.

[0138] Figure 11 A logic diagram for applying for a soft certificate by a multi-card mobile phone provided by an embodiment of the present application is shown in FIG. 1, and the specific steps are as follows: Figure 11

[0139] STEP1: The user uses a dual-card / multi-card mobile phone to log in to the broker system through the broker APP in the form of a "static password" or a "static password+";

[0140] STEP2: The "three-party collaborative identification" basic process is automatically executed.

[0141] STEP3: If the "three-party collaborative identification" is not passed, the user is prompted with relevant information (such as "If your mobile phone is configured with two or more SIM cards, in order to improve security and enjoy more operation convenience, please select to use your reserved number SIM card").

[0142] STEP4: If the user selects "switch SIM card", the user completes the switch SIM card operation through the mobile phone "system settings" by himself / herself.

[0143] STEP5: If the user completes the switch SIM card operation and exits the APP login, the user returns to STEP1 to log in to the broker system again. If not, the user enters STEP2 to automatically execute the "three-party collaborative identification" basic process again.

[0144] STEP6: If the user selects "continue to the next step", the user uses the existing identification technology.

[0145] STEP7: If the "three-party collaborative identification" is passed, or the "three-party collaborative identification" is not passed and the existing identification technology is used to pass, the user's mobile terminal is issued with a soft certificate, and the subsequent business process is continued.

[0146] Figure 12 A logic diagram for applying for a soft certificate by using a non-mobile phone SIM card terminal provided by an embodiment of the present application is shown in FIG. 2, and the specific steps are as follows: Figure 12

[0147] ​​STEP1: User uses Pad and other non-mobile "SIM card terminal" to log in to the broker system in "static password" or "static password +" mode;

[0148] STEP2: Non-mobile "SIM card terminal" initiates a login request to the broker server;

[0149] STEP3: The broker server returns the login result to the non-mobile "SIM card terminal", and if the login is successful, it shows the user the certificate application button; if the login fails, it pushes the corresponding prompt information to the user;

[0150] STEP4: The user initiates a certificate application request (the broker server will also automatically trigger the certificate application request according to the established strategy, such as when the "certificate expires" occurs);

[0151] STEP5: The user uses the reserved number mobile phone to participate in the non-mobile "SIM card terminal" cross-device "three-party collaborative identification" in the form of two-dimensional code (soft) connection, Token (soft) connection, USB interface (hard) connection, etc. The broker server initiates and executes the "three-party collaborative identification" based on the reserved mobile number for the user;

[0152] STEP6: If the "three-party collaborative identification" is successfully passed, the broker server opens the permission and executes the corresponding process to issue a soft certificate to the user's non-mobile "SIM card terminal"; if the "three-party collaborative identification" is not successfully passed, the corresponding prompt information is pushed to the user.

[0153] Figure 13 A logic diagram for assisting in strengthening user identity verification by remotely downloading a hard certificate provided by the embodiments of the present application is shown in Figure 13 The specific steps are as follows:

[0154] STEP1: User uses its desktop PC, laptop and other "non-SIM card terminal" to log in to the broker system in "static password" or "static password +" mode;

[0155] STEP2: "Non-SIM card terminal" initiates a login request to the broker server;

[0156] STEP3: The broker server returns the login result to the "non-SIM card terminal", and if the login is successful, it shows the user the certificate application button; if the login fails, it pushes the corresponding prompt information to the user;

[0157] STEP4: The user applies to download the Ukey digital certificate special for the hard carrier through the "non-SIM card terminal";

[0158] STEP5: The user inserts the digital certificate hard carrier special Ukey into the "non-SIM card terminal" USB interface, establishes a certificate secure download channel, and prepares for downloading the certificate;

[0159] STEP6: The user selects a reserved number mobile phone according to the system prompt and his own situation, and participates in the "non-SIM card terminal" cross-platform "three-party collaborative identification" in the form of two-dimensional code (soft) connection, Token (soft) connection, and USB interface (hard) connection; the broker server initiates and executes the "three-party collaborative identification" based on the reserved mobile phone number;

[0160] STEP7: If the "three-party collaborative identification" is successfully passed, the broker server opens the permission and executes the corresponding process, and issues a digital certificate to the user digital certificate hard carrier special Ukey through a secure channel; if the "three-party collaborative identification" is not successfully passed, the corresponding prompt information is pushed to the user.

[0161] The above method of issuing a digital certificate to an investor after identifying the investor by using "static password + three-party collaborative identification" (including the method of applying for a soft certificate in the application scenarios of a reserved number mobile phone, a non-SIM card terminal, and a multi-SIM card; and the method of strengthening user identity verification when applying for a hard certificate for remote download) solves the problem of insufficient performance of the RA (registration authority) in the registration link of the digital certificate, and achieves the ideal goal of issuing a digital certificate to an investor in a safe and controllable manner, a digital certificate in a safe and reliable manner, and a certificate signature in a safe and reliable manner. At the same time, when an investor applies for a digital certificate using a reserved number mobile phone and a broker issues a digital certificate to the investor, the investor can be transparent and non-invasive; and by means of two-dimensional code (soft) connection, Token (soft) connection, and USB interface (hard) connection, the broker can better achieve full coverage of all types of terminal devices for issuing a digital certificate to an investor. The above method lays a solid foundation for the effective use of digital certificates in various securities businesses, and makes digital certificates not only in form, but also in substance, truly play their due technical support role as strong identity authentication and electronic signature tools.

[0162] Further, the strong identity authentication method can also be applied to a password reset scenario, Figure 14 A "three-party collaborative identification + bank certificate transfer" password reset logic diagram provided by the embodiment of the present application is shown in Figure 14 The specific steps are as follows:

[0163] STEP1: The user clicks the "three-party collaborative identification + bank certificate transfer" password reset option through the broker client (including a SIM card terminal and a non-SIM card terminal) to propose a "password reset" request;

[0164] STEP2: The broker client requests the broker server to reset the password and simultaneously requests to perform three-party collaborative identification;

[0165] STEP3: The broker server initiates and performs three-party collaborative identification based on the reserved mobile phone number for the user; the broker server returns the identification result to the broker client;

[0166] STEP4: If the identification result is "pass", the user is prompted to assist in verifying the identity by transferring money (including transferring more than or equal to 0 yuan, and charging after transferring) from a certain bank Class I account to the broker account of the same user subject to be "reset password" or to the designated broker account; if the identification fails, the user is prompted with the corresponding information;

[0167] STEP5: The user requests to transfer money from a certain bank Class I account to the broker account of the same user subject to be "reset password" or to the designated broker account (including transferring more than or equal to 0 yuan, and charging after transferring);

[0168] STEP6: The bank server transfers money to the broker server, and if the user's bank transfer is successful, the bank and the broker exchange relevant information including the user's identity verification method when logging in to the bank system through the total-to-total private line;

[0169] STEP7: The broker server determines the user's identity verification method, and if the user's bank identity verification method is "password / password" or "password / password+", the broker server opens the permission within a certain time limit (such as 5 minutes) to allow the broker client to perform the "reset password" operation, if the user's bank transfer is unsuccessful, or the bank identity verification method is not "password / password" or "password / password+", the broker client is not allowed to perform the "reset password" operation;

[0170] STEP8: The broker server returns the transfer result to the bank server;

[0171] STEP9: The broker server pushes the bank transfer auxiliary verification result to the broker client and prompts the corresponding information;

[0172] STEP10: The user performs the password reset operation through the broker client within the agreed time limit;

[0173] STEP11: The broker server returns the password reset result to the broker client and prompts the corresponding information.

[0174] Figure 15 A "three-party collaborative identification + other password" password reset logic diagram provided for the embodiments of the present application is shown in Figure 15 The specific steps are as follows:

[0175] STEP1: The user clicks the "three-party collaborative identification + other password" password reset option through the broker client (including SIM card terminals and non-SIM card terminals) to submit a "password reset" request;

[0176] STEP2: The broker client requests password reset from the broker server and requests to perform three-party collaborative identification;

[0177] STEP3: The broker server initiates and performs three-party collaborative identification based on the reserved mobile phone number for the user. The broker server returns the three-party collaborative identification result to the broker client;

[0178] STEP4: When the result is "pass", the broker client shows the user a prompt box that can choose "other password" (including the user's three-party custody bound Class I bank account password, the same user's Class I bank account number and password, and other passwords set by the broker under the same user identity). If the identification is not passed, the user is prompted with the corresponding information;

[0179] STEP5: The user selects a password verification method in the prompt box;

[0180] STEP6: The broker client shows the user a password input box or an account number and password input box, as well as a pre-set bank card information OCR collection option;

[0181] STEP7: The user inputs the password or account number and password on the broker client, including automatically collecting the user-provided bank card information under the bank / unionpay SDK security technology environment embedded in the broker client, and manually inputting the corresponding Class I bank account password;

[0182] STEP8: The broker client initiates an other password verification request to the broker server, including verification through the bank / unionpay server;

[0183] STEP9: The broker server verifies the other password through the total-to-total bank certificate line, including the bank / unionpay SDK embedded in the broker client requesting verification from the bank / unionpay server, and the total-to-total verification result, or verifying the other password within the broker system;

[0184] STEP10: The broker server returns the other password verification result to the broker client;

[0185] STEP11: If the verification is passed, the broker server opens the permission within a certain time limit (such as 5 minutes) to allow the broker client to perform the "password reset" operation; the user performs the password reset operation through the broker client within the agreed time limit;

[0186] STEP 9: The broker server returns the password reset result to the broker client and prompts the corresponding information.

[0187] Figure 16 A "three-party collaborative identification + two-way video" password reset logic diagram provided by the embodiment of the application is shown in FIG. 1. Figure 16 The specific steps are as follows:

[0188] STEP 1: The user clicks the "three-party collaborative identification + two-way video" password reset option on the broker client (including a SIM card terminal and a non-SIM card terminal) to submit a "password reset" request.

[0189] STEP 2: The broker client requests the broker server to reset the password and perform three-party collaborative identification.

[0190] STEP 3: The broker server initiates and performs three-party collaborative identification based on the reserved mobile phone number for the user. The broker server returns the identification result to the broker client.

[0191] STEP 4: When the result is "pass", the user is prompted to enter the "two-way video" verification process. If the identification fails, the user is prompted with the corresponding information.

[0192] STEP 5: The user confirms to start "two-way video" through the broker client. The broker staff further verifies the identity authenticity of the user who intends to reset the password through the broker system.

[0193] STEP 6: The broker staff submits the "two-way video" verification result to the broker server.

[0194] STEP 7: The broker server returns the "two-way video" verification result to the broker client. When the "two-way video" verification passes, the broker server opens the permission within a certain time limit (for example, 5 minutes) to allow the broker client to perform the password reset operation. If the identification fails, the user is prompted with the corresponding information.

[0195] STEP 8: The user performs the password reset operation through the broker client within the agreed time limit.

[0196] STEP 9: The broker server returns the password reset result to the broker client and prompts the corresponding information.

[0197] As a feasible implementation, Figure 17 A "password + three-party collaborative identification" authentication logic diagram provided by the embodiment of the application is generally applicable to various strong identity authentication business scenarios. "Password + three-party collaborative identification" is a strong identity authentication method that can meet the identity identification requirements of various online securities businesses, including various important online securities business users, as shown in FIG. 2.Figure 17 As shown, the specific steps are as follows:

[0198] STEP1: the user inputs a static password to the broker client (including a SIM card terminal and a non-SIM card terminal) to initiate a business (including modifying a user account password, a contact address, a reserved phone number, an expired ID number, and applying for a digital certificate, etc. various online securities businesses) appeal;

[0199] STEP2: the broker client requests a business function to the broker server and simultaneously requests to perform three-party collaborative identification;

[0200] STEP3: the broker server compares and verifies the received static password with a preset static password; simultaneously, the broker server initiates and performs three-party collaborative identification based on the reserved mobile phone number of the user;

[0201] STEP4: if the static password and the three-party collaborative identification are both verified, the broker server opens any permission corresponding to the business appeal of the user within a certain time limit according to the application needs.

[0202] It should be noted that, if necessary, the "password / password" can also use the valid bank end password / password of the same user subject, such as in some embodiments of the above password resetting scenario, the user cooperates with the password / password or password / password + valid login, and the operation of a certain type I bank account. It should also be noted that when performing three-party collaborative identification, if a three-party custody type I bank account is used, the three-party custody binding relationship should be further implemented in subsequent business, such as when the user first opens an account, the three-party custody binding relationship should be further implemented in the account activation link to ensure the effectiveness of the three-party collaborative identification method.

[0203] Although the present application is proposed from the perspective of securities industry application, it is also applicable to futures industry, including banking industry and other industries such as third-party payment.

[0204] It should be noted that the "user" mentioned above is the general term of the user of the broker system, the customer of the broker client and the investor, and the customer who registers, invests and handles business in the broker system is also the user of the present application.

[0205] Each embodiment in the present application is described in a progressive manner, and the same and similar parts between each embodiment can be referred to each other, and each embodiment mainly explains the difference from other embodiments. Especially, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the related parts can be referred to the part of the method embodiment.

[0206] The above describes specific embodiments of the application. Other embodiments are within the scope of the following claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown or sequential order in order to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous or necessary.

[0207] The above merely provides example embodiments of the present application and is not intended to limit the present application. The example embodiments of the present application can be modified and changed by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the example embodiments of the present application shall be included in the scope of the claims of the present application.

Claims

1. A strong authentication method, characterized by, The method is realized by a three-party collaborative identification method of a broker server, an operator server and a three-party custody bank server, and the three-party collaborative identification method specifically comprises: The user's mobile phone performs a pre-fetching number operation by means of an operator SDK, obtains a temporary credential generated by the operator server, and then submits the temporary credential to the broker server, and the broker server acquires the user's real mobile phone number from the operator server according to the temporary credential; The broker server retrieves / records the user's identity information and the three-party custody bank account information that has been bound or is to be bound in the broker system according to the user's login information or provided information and the real mobile phone number; The broker server initiates an information verification request to the corresponding three-party custody bank server according to the user's identity information, the three-party custody bank account information that has been bound or is to be bound and the real mobile phone number; If the feedback result of the three-party custody bank server indicates that the user is bound to a Class I bank account, and the reserved mobile phone number of the Class I bank account bound by the user is consistent with the real mobile phone number, then the user's identity identification is passed, otherwise the user's identity identification is not passed.

2. The strong authentication method of claim 1, wherein, The method further comprises: The broker makes an agreement with the investor by means of announcement and agreement signing; the agreement content is that the investor's three-party custody account is bound to a Class I bank account, and the mobile phone number reserved and used in the broker system should be the same as the mobile phone number of the Class I bank account reserved in the three-party custody bank, and the mobile phone number should be changed synchronously in the three-party custody bank and the broker system when the mobile phone number is changed; In daytime business, the broker server checks whether the user's three-party custody account is bound to a Class I bank account and whether the mobile phone number reserved and used in the broker system is the same as the mobile phone number of the Class I bank account reserved in the three-party custody bank on a per-transaction basis; When an exception is found, the broker server pushes prompt information to the user and the relevant staff respectively, and provides an entry for modifying information for the user and the relevant staff respectively; After the business of the day or the period is completed, the broker server counts the abnormal situation and abnormal processing situation of the user's three-party custody account not being bound to a Class I bank account or the mobile phone number reserved and used in the broker system being different from the mobile phone number of the Class I bank account reserved in the three-party custody bank in the business of the day or the period, and forms a daily statistical report or a periodical statistical report; According to a preset strategy, the daily statistical report or the periodical statistical report is pushed to the relevant business department, the relevant personnel or the relevant user.

3. The strong authentication method of claim 1, wherein, The three-party collaborative identification method further comprises: If the client device used by the user is a non-SIM card terminal, the non-SIM card terminal is connected to the user's reserved number mobile phone through a soft connection mode or a hard connection mode; wherein the soft connection mode comprises a two-dimensional code connection and a Token connection; the hard connection mode comprises a USB interface connection. In the case of two-dimensional code connection, the non-SIM card terminal of the user pops up a two-dimensional code with a first preset time limit; wherein, the two-dimensional code is generated on the broker server, and is associated with all or part of the following information: user account ID, user terminal IP, user terminal device feature information, APP version number; after the user scans the two-dimensional code with the reserved mobile phone, the broker server initiates a three-party collaborative identification method based on the reserved mobile phone number for the user; after the three-party collaborative identification passes, the broker server opens the corresponding user permission to the non-SIM card terminal within a second preset time limit; In the case of Token connection, after the user selects the Token connection mode on the non-SIM card terminal, the system prompts the user to log in to the broker system for authentication of identity through the reserved mobile phone; the user logs in to the broker system using the reserved mobile phone, and the broker server initiates a three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification passes, the broker server sends an authorized Token valid within a first preset time limit to the reserved mobile phone, and after receiving the authorized Token input by the user through the non-SIM card terminal within a second preset time limit, opens the corresponding user permission to the non-SIM card terminal; In the case of user selecting USB interface connection, the system prompts the user to connect the reserved mobile phone with the non-SIM card terminal through the USB interface; after the user selects the corresponding connection mode, the broker server initiates a three-party collaborative identification method based on the reserved mobile phone number for the user; if the three-party collaborative identification passes, the broker server pushes an identification success message with a first preset time limit to the USB interface through the reserved mobile phone; after receiving the identification success message returned by the non-SIM card terminal within a second preset time limit, the broker server opens the corresponding user permission to the non-SIM card terminal.

4. The strong authentication method of claim 1, wherein, The method further comprises: the user uses a multi-SIM card application scenario of two or more SIM cards, including the following two scenarios: When the two or more SIM cards are installed in the mobile phone, the user is prompted to switch the SIM card corresponding to the reserved mobile phone number; after the user responds to the prompt and switches the SIM card by himself, the three-party collaborative identification method is executed again; When the two or more SIM cards are installed in the mobile phone and the non-mobile SIM card terminal respectively, the user's non-mobile SIM card terminal and the reserved mobile phone are connected through a soft connection mode or a hard connection mode; wherein, the non-mobile SIM card terminal at least includes a tablet computer; the soft connection mode includes two-dimensional code connection and Token connection; the hard connection mode includes USB interface connection; after the user selects the corresponding connection mode, the broker server initiates a three-party collaborative identification method based on the reserved mobile phone number for the user.

5. The use of a strong authentication method in online securities trading, characterized in that, The strong identity authentication method is applied to the issuance of digital certificates, and the issuance method specifically comprises: After the user logs in the broker system by using the reserved number mobile phone in the manner of "static password" or "static password+", the broker server automatically triggers or the user initiates the soft certificate application according to the user's own needs; The broker server initiates and performs the three-party collaborative identification method based on the reserved mobile phone number for the user; If the three-party collaborative identification is successfully passed, the broker server opens the permission and performs the preset process to issue the soft certificate to the mobile phone used by the user; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user; The three-party collaborative identification method specifically includes: The user's mobile phone performs the pre-fetching number operation by means of the operator SDK, obtains the temporary credential generated by the operator server, and submits the broker server, and the broker server obtains the real mobile phone number of the user from the operator server according to the temporary credential; The broker server retrieves / records the identity information of the user, the three-party custodian bank account information bound / planned to be bound in the broker system according to the user login information or the provided information and the real mobile phone number; The broker server initiates an information verification request to the corresponding three-party custodian bank server according to the identity information of the user, the three-party custodian bank account information bound / planned to be bound and the real mobile phone number; If the feedback result of the three-party custodian bank server indicates that the user is bound to a type I bank account, and the reserved mobile phone number of the type I bank account bound by the user is consistent with the real mobile phone number, the identity identification of the user is passed, otherwise the identity identification of the user is not passed.

6. The use of a strong authentication method according to claim 5 in online securities trading, characterized in that, The method for issuing the digital certificate further includes: After the user logs in the broker system by using the non-SIM card terminal in the manner of "static password" or "static password+", the broker server automatically triggers or the user initiates the soft certificate application according to the user's own needs; After the user selects the soft connection mode or the hard connection mode of connecting the non-SIM card terminal with the reserved number mobile phone, the broker server initiates and performs the three-party collaborative identification method based on the reserved mobile phone number for the user; wherein the soft connection mode includes two-dimensional code connection, Token connection; the hard connection mode includes USB interface connection; If the three-party collaborative identification is successfully passed, the broker server opens the permission and performs the preset process to issue the soft certificate to the non-SIM card terminal of the user; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

7. The use of a strong authentication method according to claim 5 in online securities trading, characterized in that, The method for issuing the digital certificate further includes the multi-SIM card application situation of the user using two or more SIM cards, specifically including the following two scenarios: When the two or more SIM cards are installed in the mobile phone, the user is prompted to switch the SIM card corresponding to the reserved mobile phone number; after the user responds to the prompt and switches the SIM card by himself, the three-party collaborative identification method is executed again; When the two or more SIM cards are installed in the mobile phone and the non-mobile phone SIM card terminal respectively, the non-mobile phone SIM card terminal of the user is connected with the mobile phone with the reserved number through a soft connection mode or a hard connection mode; wherein the non-mobile phone SIM card terminal at least includes a tablet computer; the soft connection mode includes a two-dimensional code connection and a Token connection; the hard connection mode includes a USB interface connection; after the user selects the corresponding connection mode, the broker server initiates and executes a three-party collaborative identification method based on the reserved mobile phone number for the user; If the three-party collaborative identification is successfully passed, the broker server opens the permission and executes a preset process to issue a soft certificate to the user terminal; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

8. The use of a strong authentication method according to claim 5 in online securities trading, characterized in that, The method for issuing the digital certificate further includes a method for assisting in strengthening user identity authentication when remotely downloading the hard certificate: After the user logs in the broker system by using a desktop PC in a "static password" or "static password +" manner, inserts a digital certificate hard carrier special Ukey into the USB interface of the PC, and establishes a certificate secure download channel, the broker server automatically triggers or the user initiates a hard certificate application according to the user's own needs; After the user selects a soft connection mode or a hard connection mode for connecting the PC with the mobile phone with the reserved number, the broker server initiates and executes a three-party collaborative identification method based on the reserved mobile phone number for the user; wherein the soft connection mode includes a two-dimensional code connection and a Token connection; the hard connection mode includes a USB interface connection; If the three-party collaborative identification is successfully passed, the broker server opens the permission and executes a preset process to issue a digital certificate to the user digital certificate hard carrier special Ukey through an agreed manner; if the three-party collaborative identification is not successfully passed, the corresponding prompt information is pushed to the user.

9. The use of a strong authentication method in online securities trading, characterized in that, The strong identity authentication method is applied to password reset, and the password reset method specifically includes: The user clicks a "three-party collaborative identification + bank certificate transfer" password reset option through the broker client to start a password reset program; The broker server initiates and executes a three-party collaborative identification method based on the reserved mobile phone number for the user, and after the three-party collaborative identification is successfully passed, the broker server prompts the user to verify the identity through a bank account I transfer mode from a same user subject to a corresponding account of the broker end or to a designated special account of the broker end, wherein the bank account I transfer mode includes a transfer of more than or equal to 0 yuan and a post-transfer charge-off; if the user bank certificate transfer is successful, the broker server obtains the identity authentication mode of the user in the bank server through a bank certificate interface when the transfer is performed; If the identity authentication mode is "password / pin" or "password / pin +", the broker server opens the permission within a preset time limit to allow the password reset operation to be performed; If the user bank certificate transfer is not successful, or the identity authentication mode is not "password / pin" or "password / pin +", the password reset is not allowed, and the corresponding prompt information is pushed to the user; The three-party collaborative identification method specifically includes: The user's mobile phone performs a pre-fetching number operation by means of an operator SDK, obtains a temporary credential generated by an operator server, and submits the temporary credential to a broker server, and the broker server acquires the user's real mobile phone number from the operator server according to the temporary credential; The broker server searches / reports the user's identity information and the information of the three-party custodian bank account bound or to be bound in the broker system according to the user's login information or provided information and the real mobile phone number; The broker server initiates an information verification request to the corresponding three-party custodian bank server according to the user's identity information, the information of the three-party custodian bank account bound or to be bound, and the real mobile phone number; If the feedback result of the three-party custodian bank server indicates that the user is bound to a Class I bank account, and the reserved mobile phone number of the Class I bank account bound by the user is consistent with the real mobile phone number, the identity authentication of the user is passed, otherwise the identity authentication of the user is not passed.

10. The use of a strong authentication method according to claim 9 in online securities trading, characterized in that, The password resetting method further comprises: The user clicks the "three-party collaborative authentication + other password" password resetting option through the broker client, and starts the password resetting program; The broker server initiates a three-party collaborative authentication method based on the reserved mobile phone number, and on the premise that the three-party collaborative authentication is successful, the broker server displays a list of other passwords to the user; wherein the list of other passwords at least includes any one or more of the following: the password of the Class I bank account bound by the user, the password of a Class I bank account of the same principal of the user, and other passwords of the same user principal of the broker; The broker server receives the user's input in the form of a pop-up box and a preset bank card information OCR collection option according to the password type selected by the user in the list of other passwords, and verifies the password, including verifying by means of the bank server; wherein in the embedded UnionPay SDK security technology environment of the broker client, the user-provided bank card information is automatically collected by OCR technology, and the corresponding Class I bank account password is manually input by the user, and the verification includes the way of requesting verification from the bank server by the embedded bank / UnionPay SDK of the broker client; if the verification is passed, the permission is opened within a preset time limit to allow the password resetting operation; if the verification is not passed, the password is not allowed to be reset, and the corresponding prompt information is pushed to the user.

11. The use of a strong authentication method according to claim 9 in online securities trading, characterized in that, The password resetting method further comprises: The user clicks the "three-party collaborative authentication + two-way video" password resetting option through the client device, and starts the password resetting program; The broker server initiates a three-party collaborative authentication method based on the reserved mobile phone number, and further verifies the identity authenticity of the user through a two-way video method; On the premise that the three-party collaborative authentication is successful, if the two-way video verification is passed, the broker server opens the permission within a preset time limit to allow the password resetting operation; if the three-party collaborative authentication is not successful or the two-way video verification is not passed, the password is not allowed to be reset, and the corresponding prompt information is pushed to the user.

12. A method for applying strong authentication to online securities trading, comprising the steps of: "Password + three-party collaborative identification" is a strong identity authentication method which is universally applicable to various online securities businesses, including various important online securities businesses; The "password + three-party collaborative identification" specifically includes: The user inputs a static password / passcode through a broker client and initiates a business appeal to a broker server; wherein the business appeal includes various online securities businesses; The broker server compares and verifies the received static password / passcode with a preset static password / passcode; Meanwhile, the broker server initiates a three-party collaborative identification method based on a reserved mobile phone number for the user; If both the static password / passcode and the three-party collaborative identification are verified, the broker server opens any corresponding rights of the business appeal to the user within a certain time limit according to application needs; The three-party collaborative identification method specifically includes: The user's mobile phone performs a pre-number operation with the help of an operator SDK, obtains a temporary credential generated by an operator server, and submits it to a broker server, and the broker server obtains the user's real mobile phone number from the operator server according to the temporary credential; The broker server retrieves / records the user's identity information and the information of the three-party custodian bank account bound or to be bound in the broker system according to the user's login information or provided information and the real mobile phone number; The broker server initiates an information verification request to the corresponding three-party custodian bank server according to the user's identity information, the information of the three-party custodian bank account bound or to be bound, and the real mobile phone number; If the feedback result of the three-party custodian bank server indicates that the user is bound to a Class I bank account, and the reserved mobile phone number of the Class I bank account bound by the user is consistent with the real mobile phone number, the user's identity identification is passed, otherwise the user's identity identification is not passed.

Citation Information

Patent Citations

  • Method for safety verifying financial business information in electronic business

    CN101051372A

  • User identity verification method and device and registration method and device

    CN108616360A