Real-time video identity authentication system and method based on telephone network
Patent Information
- Application Number
- CN202610113774.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-27
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2046-01-27
AI Technical Summary
该实现方式由于需要借助APP,因此,不仅需要用户在其移动电话中安装相应的APP,而且对互联网的网络情况依赖度通常较高,例如,在弱互联网环境、用户的移动电话没有流量、以及由于移动电话不支持而无法安装APP等情况下,身份可信认证的过程很难顺利完成
[0011]基于本公开上述实施例提供的基于电话网的实时视频身份可信认证系统、电话网身份认证平台、基于电话网的实时视频身份可信认证方法、存储介质以及电子设备,通过在电话网运营商侧设置电话网身份认证平台,并使电话网身份认证平台在业务平台与用户的语音通话过程中,基于业务平台随时产生并发送来的请求消息启动对用户的基于生物特征识别的身份可信认证流程,可以避免用户在与业务平台的语音通话过程中必须使用该业务平台的APP(如企业/政府部门的APP)才可以启动身份可信认证的现象,这不仅可以使用户无需执行启动身份可信认证的操作,而且可以避免用户需要在移动电话中安装相应APP的现象;通过利用电话网身份认证平台对用户与业务平台之间的语音通话进行调整控制,使该语音通话被拆分为用户和业务平台各自与电话网身份认证平台间的视频通话/语音通话,不仅有利于将用户与业务平台之间的语音通话过程无缝切换至对用户的身份可信认证过程,而且可以使身份可信认证过程基于电话网实现,这样即便是在弱互联网环境、用户的移动电话没有流量以及由于移动电话不支持而无法安装APP等情况下,仍然可以成功执行用户的身份可信认证,而且通过利用电话网并借助可信数字身份服务平台(如公安机关的可信数字身份服务平台)对用户进行身份可信认证,可以避免利用互联网进行身份可信认证所存在的易于被劫持以及认证可信度存在缺陷等现象;通过在身份可信认证完成后,由电话网身份认证平台将认证结果提供给业务平台,并将拆分后的两段通话合并为用户与业务平台的语音通话,使身份可信认证过程可以无缝插入在业务实现过程中,避免用户产生业务被身份可信认证中断的感觉。由此可知,本公开提供的技术方案有利于更安全便捷的实现基于生物特征识别的身份可信认证,并有利于提高用户体验。
Smart Images

Figure CN121907586B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to identity authentication technology, and in particular to a real-time video identity trusted authentication system based on a telephone network, a telephone network identity authentication platform, a real-time video identity trusted authentication method based on a telephone network, a storage medium, and an electronic device. Background Technology
[0002] In some business scenarios, it is often necessary to perform trusted identity authentication for users. For example, this can be done using SMS verification codes, or through video conferencing using biometric recognition technology. Compared to trusted authentication methods like SMS verification codes, trusted identity authentication using biometric recognition technology is widely used due to its advantages such as greater security, convenience, resistance to attacks, and lower maintenance costs.
[0003] Currently, biometric-based identity verification typically utilizes mobile apps (such as enterprise or government apps). For instance, during a voice call with a company, if video verification is required, the user usually needs to open the company's app on their mobile phone and use the app's authentication function to complete the process. Because this method relies on an app, it not only requires the user to install the app on their phone but also is highly dependent on internet connectivity. For example, in environments with weak internet, when the user's phone has no data, or when the phone cannot install the app, the authentication process is difficult to complete smoothly. Furthermore, users often need to interrupt their current voice call to perform the authentication within the app, which degrades the user experience.
[0004] How to achieve more secure and convenient biometric-based identity authentication during voice calls between users and enterprises, and improve user experience, is a technical issue that deserves attention. Summary of the Invention
[0005] This disclosure is made to address the aforementioned technical problems. Embodiments of this disclosure provide a real-time video identity trusted authentication system based on a telephone network, a telephone network identity authentication platform, a real-time video identity trusted authentication method based on a telephone network, a storage medium, and an electronic device.
[0006] According to a first aspect of the present disclosure, a real-time video identity trusted authentication system based on a telephone network is provided. The system includes: a telephone network identity authentication platform and at least one service platform; the service platform, during a voice call with a user, generates a request message to trigger biometric-based identity trusted authentication when it is determined that biometric-based identity trusted authentication of the user needs to be initiated, and sends this request message to the telephone network identity authentication platform; the telephone network identity authentication platform is located on the telephone network operator's side, and the telephone network identity authentication platform includes: a first interface module, configured to receive the request message for triggering biometric-based identity trusted authentication transmitted from the service platform; and a call adjustment module, configured to adjust the voice call between the user and the service platform to a call between the telephone network identity authentication platform and the user based on information carried in the request message received by the first interface module. The system includes: a video call between users and a voice call between the telephone network identity authentication platform and the business platform; an information acquisition module for acquiring information containing user biometrics based on the video call; a second interface module for requesting a trusted digital identity service platform to perform trusted identity authentication for the user based on the information containing user biometrics, and obtaining the trusted identity authentication result of the user based on the information returned by the trusted digital identity service platform; the first interface module is also used to provide the trusted identity authentication result of the user obtained by the second interface module to the business platform; and the call adjustment module is also used to adjust the video call between the telephone network identity authentication platform and the user, and the voice call between the telephone network identity authentication platform and the business platform, to a voice call between the user and the business platform when the second interface module obtains the trusted identity authentication result of the user.
[0007] According to a second aspect of the present disclosure, a telephone network identity authentication platform is provided, the platform being located on the side of a telephone network operator, and the platform comprising: a first interface module, configured to receive a request message transmitted from a service platform for triggering biometric-based trusted identity authentication; wherein the request message is generated when the service platform determines that it needs to initiate biometric-based trusted identity authentication for the user during a voice call between the user and the service platform; and a call adjustment module, configured to adjust the voice call between the user and the service platform to a video call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform, based on information carried in the request message received by the first interface module. The information acquisition module is used to acquire information including the user's biometric features based on the video call; the second interface module is used to request a trusted digital identity service platform to perform trusted identity authentication for the user based on the information including the user's biometric features, and to obtain the trusted identity authentication result of the user based on the information returned by the trusted digital identity service platform; the first interface module is also used to provide the trusted identity authentication result of the user obtained by the second interface module to the business platform; the call adjustment module is also used to adjust the video call between the telephone network identity authentication platform and the user, and the voice call between the telephone network identity authentication platform and the business platform to a voice call between the user and the business platform when the trusted identity authentication result of the user is obtained by the second interface module.
[0008] According to a third aspect of the present disclosure, a real-time video identity trusted authentication method based on a telephone network is provided. This method is executed by a telephone network identity authentication platform located on the telephone network operator's side, and includes the steps of: receiving a request message from a service platform to trigger biometric-based identity trusted authentication; wherein the request message is generated when the service platform determines that biometric-based identity trusted authentication of the user needs to be initiated during a voice call between the user and the service platform; adjusting the voice call between the user and the service platform to a video call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform, based on information carried in the request message; obtaining information containing the user's biometric features from the video call; requesting a trusted digital identity service platform to perform identity trusted authentication of the user based on the information containing the user's biometric features, and obtaining the user's identity trusted authentication result based on information returned by the trusted digital identity service platform; providing the user's identity trusted authentication result to the service platform, and adjusting the video call between the telephone network identity authentication platform and the user, and the voice call between the telephone network identity authentication platform and the service platform, to a voice call between the user and the service platform.
[0009] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, the storage medium storing a computer program for implementing any of the methods described above.
[0010] According to a fifth aspect of the present disclosure, an electronic device is provided, comprising: a processor; a memory for storing processor-executable instructions; the processor being configured to read the executable instructions from the memory and execute the instructions to implement any of the methods described above.
[0011] Based on the telephone network-based real-time video identity trusted authentication system, telephone network identity authentication platform, telephone network-based real-time video identity trusted authentication method, storage medium, and electronic device provided in the above embodiments of this disclosure, by setting up a telephone network identity authentication platform on the telephone network operator side, and enabling the telephone network identity authentication platform to initiate a biometric-based identity trusted authentication process for the user during voice calls between the service platform and the user, based on request messages generated and sent by the service platform at any time, it is possible to avoid the phenomenon that the user must use the service platform's APP (such as an enterprise / government department's APP) to initiate identity trusted authentication during voice calls with the service platform. This not only eliminates the need for the user to perform the operation of initiating identity trusted authentication, but also avoids the phenomenon that the user needs to install a corresponding APP on their mobile phone; by using the telephone network identity authentication platform to adjust and control the voice call between the user and the service platform, the voice call is split into separate calls between the user and the service platform and the telephone network identity authentication platform. Inter-platform video / voice calls not only facilitate seamless switching from voice calls between users and business platforms to trusted user authentication processes, but also allow for authentication based on the telephone network. This ensures successful authentication even in weak internet environments, when users' mobile phones lack data, or when apps cannot be installed due to phone incompatibility. Furthermore, utilizing the telephone network and a trusted digital identity service platform (such as a public security agency's platform) avoids the vulnerabilities to hijacking and reliability issues inherent in internet-based authentication. After authentication, the telephone network platform provides the result to the business platform, merging the two separate call segments into a single voice call between the user and the platform. This seamless integration of authentication into business processes prevents users from experiencing service interruptions. Therefore, the technical solution provided in this disclosure offers a more secure and convenient way to achieve biometric-based trusted authentication, and improves user experience.
[0012] The technical solutions of this disclosure will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0013] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.
[0014] Figure 1 This is a schematic diagram illustrating an application scenario of the real-time video identity trusted authentication technology method based on the telephone network disclosed herein.
[0015] Figure 2 This is a flowchart of an embodiment of the real-time video identity trusted authentication method based on the telephone network disclosed herein;
[0016] Figure 3 This is a schematic diagram of the structure of an embodiment of the real-time video identity trusted authentication system based on the telephone network disclosed herein;
[0017] Figure 4 This is a schematic diagram of the structure of an embodiment of the telephone network identity authentication platform disclosed herein;
[0018] Figure 5 This is a structural diagram of an electronic device provided in an exemplary embodiment of this disclosure. Detailed Implementation
[0019] Example embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. It is obvious that the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure, and it should be understood that this disclosure is not limited to the example embodiments described herein.
[0020] It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of this disclosure.
[0021] Those skilled in the art will understand that the terms "first," "second," etc., in the embodiments of this disclosure are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they indicate a necessary logical order between them.
[0022] It should also be understood that in the embodiments disclosed herein, "a plurality of" may refer to two or more, and "at least one" may refer to one, two or more.
[0023] It should also be understood that any component, data or structure mentioned in the embodiments of this disclosure can generally be understood as one or more unless expressly defined or given to the contrary in the context.
[0024] Furthermore, the term "and / or" in this disclosure is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this disclosure generally indicates that the preceding and following related objects have an "or" relationship.
[0025] It should also be understood that the description of the various embodiments in this disclosure emphasizes the differences between the various embodiments, and the similarities or similarities can be referred to each other. For the sake of brevity, they will not be described in detail.
[0026] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.
[0027] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit this disclosure or its application or use.
[0028] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.
[0029] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0030] The embodiments of this disclosure can be applied to electronic devices such as terminal devices, computer systems, and servers, and can operate with a wide range of other general-purpose or special-purpose computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, or servers include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments that include any of the above systems, etc.
[0031] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system executable instructions (such as program modules) executed by a computer system. Typically, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in a distributed cloud computing environment. In a distributed cloud computing environment, tasks can be performed by remote processing devices linked through a communication network. In a distributed cloud computing environment, program modules can reside on local or remote computing system storage media, including storage devices.
[0032] This disclosure outlines
[0033] In developing this disclosure, the inventors discovered that the telephone network used by mobile phones, namely the cellular mobile communication network, is a closed, dedicated communication network independently constructed and maintained by mobile communication operators. Because the design goals of the telephone network include enabling calls anytime, anywhere, it features wide coverage, high base station density, strong signal penetration, and a robust handover mechanism (such as seamless handover between cells). This makes the telephone network signal stronger and more stable, making it more suitable for real-time communications such as voice and video calls compared to the internet. Furthermore, the telephone network also features encrypted communication links (such as air interface encryption), a closed core network making it difficult for external attackers to access, strict number authentication, and strict access control of the signaling system. This makes the telephone network more secure and reliable, making it more suitable for highly sensitive communications (such as bank verification codes) compared to the internet.
[0034] Based on the aforementioned characteristics of the telephone network, during voice calls between users and business platforms (such as enterprise or government business platforms), when video authentication of the user's identity is required, adjusting and controlling the current voice call between the user and the business platform to seamlessly integrate the video call provided by the telephone network for biometric authentication can avoid the need for the user to switch to the business platform's app (enterprise / government app) during the voice call and use the app's authentication function to complete the authentication process step by step. This not only eliminates the need for the user to install the corresponding app on their mobile phone, but also ensures successful authentication even in weak internet environments, when the user's mobile phone has no data, or when the mobile phone cannot install the app due to incompatibility. Furthermore, since no user interaction with the app is required, it also improves the user experience.
[0035] Exemplary Overview
[0036] This disclosed technical solution for real-time video identity trusted authentication based on telephone networks can be applied to various application scenarios, such as self-service insurance business of insurance companies, self-service business of government departments, and self-service business of banks or securities companies. The following section combines... Figure 1 Taking the self-service insurance business of an insurance company as an example, the application scenarios of the technical solution disclosed herein will be explained.
[0037] Figure 1In this context, the insurance company 100 is equipped with an automated telephone service system 101, such as an IVR (Interactive Voice Response) system. The insurance company 100 provides hotline services to users through the automated telephone service system 101. Any user can call the insurance company 100's hotline to conduct various insurance services such as insurance consultation, policy inquiry, and policy information improvement / modification.
[0038] When user 110 needs to inquire about insurance policy information for themselves, user 110 uses their mobile phone 111 to call the insurance company 100's hotline. When the hotline is connected to the insurance company 100's automated telephone service system 101, and during the voice call between user 110 and the automated telephone service system 101 to inquire about their policy information, if user 110 triggers the identity authentication procedure set up by the insurance company 100 for policy inquiry services (e.g., user 110 clicks the corresponding keypad on mobile phone 111 according to the voice prompts of the automated telephone service system 101 or expresses agreement via voice), then the insurance company 100 initiates a biometric-based identity authentication process for user 110 using a video call over the telephone network. For example, insurance company 100 triggers telephone network identity authentication platform 120 set up on the telephone network operator side (i.e., mobile phone operator side) to perform biometric-based identity authentication on user 110. Based on the triggering by insurance company 100, telephone network identity authentication platform 120 requests to conduct identity authentication with user 110 through video call. If user 110 allows identity authentication through video call, the voice call between mobile phone 111 and automated telephone service system 101 is adjusted to: video call between mobile phone 111 and telephone network identity authentication platform 120, and voice call between automated telephone service system 101 and telephone network identity authentication platform 120. For example, with the permission of user 110, the camera access permission of mobile phone 111 is obtained, thereby activating the video of mobile phone 111, and routing the video stream of mobile phone 111 to telephone network identity authentication platform 120, instead of routing it to automated telephone service system 101 of insurance company 100.
[0039] The telephone network identity authentication platform 120 uses the video call to perform biometric-based trusted identity authentication on user 110. For example, the telephone network identity authentication platform 120 first performs a liveness detection on user 110 through the video call. After the liveness detection is successful, the telephone network identity authentication platform 120 interacts with the trusted digital identity service platform 130, providing the trusted digital identity service platform 130 with the information required for trusted authentication (such as the user's ID number, user name, and photo), and obtains the trusted identity authentication result provided by the trusted digital identity service platform 130. The telephone network identity authentication platform 120 then notifies the insurance company 100 of the trusted identity authentication result (e.g., notifying the automated telephone service system 101). Subsequently, the telephone network identity authentication platform 120 restores the video call between mobile phone 111 and the telephone network identity authentication platform 120, and the voice call between the automated telephone service system 101 and the telephone network identity authentication platform 120, into a single voice call between mobile phone 111 and the automated telephone service system 101.
[0040] If the trusted digital identity service platform 130's identity authentication result is successful, the automated telephone service system 101 will provide the user 110 with relevant policy information. If the liveness detection ultimately fails or the trusted digital identity service platform 130's identity authentication result is unsuccessful, the automated telephone service system 101 may refuse to provide the user 110 with relevant policy information and notify the user 110 of the reason for the refusal.
[0041] Exemplary methods
[0042] The real-time video identity trusted authentication method based on the telephone network disclosed herein is executed on the telephone network operator side. Specifically, this disclosure can set up a telephone network identity authentication platform on the telephone network operator side, and the telephone network identity authentication platform executes the steps in the method disclosed herein. The telephone network in this disclosure refers to a cellular mobile communication network, not the mobile internet built on top of a cellular mobile communication network. This telephone network can also be called a mobile communication network, for example, a telephone network based on IMS (IP Multimedia Subsystem). The telephone network operator in this disclosure is a mobile communication operator, for example, it can be China Mobile, China Unicom, or China Telecom, etc. The following is in conjunction with… Figure 2 The steps in the real-time video identity trusted authentication method based on the telephone network disclosed herein are explained.
[0043] Figure 2 This is a flowchart illustrating an embodiment of the real-time video identity trusted authentication method based on a telephone network disclosed herein. Figure 2The method shown mainly includes the following steps: S200, S201, S202, S203, and S204. The following section details... Figure 2 Each step in the process will be explained separately.
[0044] S200: Receives a request message from the service platform to trigger the execution of biometric-based trusted identity authentication.
[0045] In this disclosure, the business platform refers to a platform that provides corresponding services to users, and may also be called a service platform or management platform, etc. The services provided by the business platform to users may include: information inquiry services (such as policy inquiry services), information modification services (such as policy information modification services), and information creation services (such as self-service insurance application services), etc. This disclosure does not limit the specific form in which the services provided by the business platform to users are presented.
[0046] The business platforms disclosed herein may be provided by state-owned enterprises or private enterprises, government departments such as civil affairs departments, education departments, or transportation departments, or non-profit organizations such as hospitals or research institutes. This disclosure does not limit the entity to which the business platform belongs.
[0047] The biometric-based trusted identity authentication disclosed herein refers to using a user's biometric characteristics (such as facial features) to verify whether the user is the person they claim to be. Biometric-based trusted identity authentication typically includes: authoritative identity authentication, such as authoritative identity authentication performed by high-security departments like public security agencies. In one example, biometric-based trusted identity authentication may include liveness detection in addition to authoritative identity authentication.
[0048] The request message in this disclosure is a message generated by the service platform, and it is generated during a voice call between the user and the service platform. The voice call between the user and the service platform in this disclosure is a telephone network voice call, not an internet voice call (such as a voice call based on instant messaging tools). For example, the voice call between the user and the service platform in this disclosure could be a VoLTE (Voice over Long-Term Evolution) voice call or a VoNR (Voice over New Radio) voice call from a telephone network operator. The user can initiate a voice call between themselves and the service platform by dialing the service platform's hotline.
[0049] The request message disclosed herein is primarily used to instruct the telephone network identity authentication platform to initiate a biometric-based trusted identity authentication process for users. Specifically, when the business platform determines that trusted biometric-based identity authentication for users needs to be initiated based on the current business progress, it generates a request message and sends it to the telephone network identity authentication platform. This request message should carry information necessary for the telephone network identity authentication platform to initiate the trusted identity authentication process, such as user-related information and business platform-related information. The information carried in the request message in this disclosure can be configured according to the specific needs of the actual operations performed by the telephone network identity authentication platform.
[0050] In one example, the request message of this disclosure may be a SIP (Session Initiation Protocol) message, such as a SIP message used to modify the current voice call. The request message of this disclosure carries information including user identification information and service platform identification information. The user identification information is used not only to establish a video call between the user and the telephone network authentication platform, but also to perform reliable identity authentication of the user based on biometrics. The service platform identification information is mainly used to establish a voice call between the service platform and the telephone network authentication platform. For example, the user identification information may include: the user's currently used mobile phone number, the user's ID card number, and the user's name, etc., and the service platform identification information may be one or more of the following: the service platform's hotline phone number (such as a corporate hotline phone number, or a government department hotline phone number), the service platform name (such as a corporate name or a government department name), and the service platform code (such as a serial number set for a corporate or government department). When establishing a voice call between a business platform and a telephone network identity authentication platform requires the use of the business platform's hotline number, but the business platform identification information carried in the request message does not include the business platform's hotline number, the telephone network identity authentication platform disclosed herein can use the business platform name / business platform code and other information carried in the request message to search in the local maintenance information to obtain the business platform's hotline number.
[0051] In one example, the business platform disclosed herein has a pre-set identity authentication interface. When the business platform determines that it needs to initiate trusted identity authentication of users based on biometrics, it can generate a corresponding request message by calling the identity authentication interface, and the identity authentication interface sends the request message to the telephone network identity authentication platform.
[0052] This disclosure enables a business platform to support reliable biometric authentication of users by setting up an identity authentication interface within the platform and generating and sending request messages through this interface, without significantly altering the platform's original business processes. For example, by installing corresponding plugins or enabling value-added services on the platform, the business platform can support reliable biometric authentication of users, reducing the platform's access costs. This makes the technical solution provided in this disclosure more applicable and facilitates its widespread adoption across various business platforms.
[0053] In one example, the specific process by which the business platform generates a request message can be as follows:
[0054] First, when a service platform (such as an IVR within the platform) determines that the service it is providing to a user requires reliable identity authentication based on biometrics, it can ask the user via voice or text whether their current mobile phone number is a mobile phone number registered with the platform. For example, the platform can display a pop-up window on the user's mobile phone screen, with text messages such as: "For verification of this number, please press 1#; for verification of a number other than this number, please enter your ID number and press # to end."
[0055] Secondly, the business platform (such as the IVR within the business platform) waits for user responses (such as keypad or voice responses) within a predetermined time interval. If the business platform receives a response from the user within the predetermined time interval, and the response indicates that the user's current mobile phone number is a mobile phone number stored in the system (e.g., the response is "1#"), the business platform uses this mobile phone number to query the user's ID number and name from the information stored in the business platform (such as a CRM (Customer Relationship Management) system). If the business platform receives a response from the user within the predetermined time interval, and the response indicates that the user's current mobile phone number is not a mobile phone number stored in the system (e.g., the response is "ID number#"), the business platform obtains the user's ID number from the user's response and uses this ID number to query the user's name from the information stored in the business platform (such as a CRM system). If the business platform does not receive a response from the user within the predetermined time interval, it can ask the user again whether their current mobile phone number is a mobile phone number stored in the system or prompt the user to return to the previous menu, etc. If the business platform receives a reply from the user within a predetermined time interval, and the reply does not indicate that the user's current mobile phone number is a mobile phone number stored in the system, nor does it indicate that the user's current mobile phone number is not a mobile phone number stored in the system, then the business platform may ask the user again whether the user's current mobile phone number is a mobile phone number stored in the system, or prompt the user to return to the previous menu, etc.
[0056] Finally, the business platform (such as the IVR in the business platform) calls the identity authentication interface. For example, the business platform uses the user's current mobile phone number, user ID number, user name, and business platform identification information (such as the business platform's hotline number) as input parameters for the identity authentication interface. The identity authentication interface generates a request message containing all the current input parameters, and the identity authentication interface can send the request message to the telephone network identity authentication platform via the user's current mobile phone.
[0057] This disclosure utilizes a business platform to interact with users and obtains user ID numbers and names based on information stored on the business platform itself. This not only provides a simple, efficient, and secure way to obtain the essential information required for reliable identity authentication based on biometrics, enabling the identity authentication interface to quickly generate request messages, but also allows the business platform to initiate reliable identity authentication for users regardless of whether they are using a mobile phone registered with the business system. This improves the flexibility of reliable identity authentication and enhances the user experience.
[0058] S201. Based on the information carried in the request message, adjust the voice call between the user and the business platform to a video call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the business platform.
[0059] The video calls between the telephone network identity authentication platform and the user disclosed herein are telephone network video calls, not internet video calls (such as video calls based on instant messaging tools). The voice calls between the telephone network identity authentication platform and the service platform disclosed herein are telephone network voice calls, not internet voice calls (such as voice calls based on instant messaging tools). For example, the video calls between the telephone network identity authentication platform and the user disclosed herein could be VoLTE video calls or VoNR video calls of the telephone network operator, and the voice calls between the telephone network identity authentication platform and the service platform disclosed herein could be VoLTE voice calls or VoNR voice calls of the telephone network operator, etc.
[0060] The information carried in the request message of this disclosure should not only take into account the need to adjust and process voice calls between users and business platforms, but also the need for trusted digital identity service platforms to perform trusted identity authentication for users.
[0061] The telephone network identity authentication platform can use various methods to adjust and process voice calls between users and business platforms. For example, it can use call splitting processing technology to adjust and process voice calls between users and business platforms, so that the voice call between users and business platforms is split into two separate calls between each user and the telephone network identity authentication platform. The split calls between each user and the telephone network identity authentication platform can be regarded as two call legs.
[0062] In one example, the telephone network authentication platform can obtain the user's currently used mobile phone number and service platform identifier (such as the service platform's hotline number) from the information carried in the received request message. On one hand, the telephone network authentication platform uses the mobile phone number to perform signaling fork processing and media stream fork processing on the user's current voice call with the service platform, thereby forming a voice call between the user and the telephone network authentication platform. On the other hand, the telephone network authentication platform uses the service platform identifier to perform signaling fork processing and media stream fork processing on the user's current voice call with the service platform, thereby forming a voice call between the telephone network authentication platform and the service platform. Subsequently, the telephone network identity authentication platform should convert the voice call between itself and the user into a video call. For example, the platform can display a pop-up window on the user's mobile phone screen. The text in this pop-up window may include: "Currently, identity authentication is required. Please turn on the camera's video." The pop-up window also includes an "Allow" button for agreeing to turn on the camera's video and a "Deny" button for refusing to turn on the camera. The platform waits for the user's action within a predetermined time interval. If the user performs an action within the predetermined time interval that indicates agreement to turn on the camera's video, the user's video is activated, and the voice call between the user and the platform is converted into a video call. If the user performs an action within the predetermined time interval that indicates denial of turning on the camera's video, the platform can again display a pop-up window on the user's mobile phone screen or prompt the user to return to the voice call with the service platform.
[0063] In one example, the signaling fork processing in this disclosure refers to the routing processing of signaling that needs to be transmitted for voice calls between a user and a service platform. This routing processing is not signaling routing processing according to the original signaling transmission path, but signaling routing processing that changes the signaling transmission path. For example, this disclosure may route user-side signaling (such as signaling sent from the user side to the telephone network operator side) to a designated port of the telephone network authentication platform, and route signaling sent to the user side through a designated port of the telephone network authentication platform to the user side; as another example, this disclosure may route service platform-side signaling (such as signaling sent from the service platform side to the telephone network operator side) to another designated port of the telephone network authentication platform, and route signaling sent to the service platform side through another designated port of the telephone network authentication platform to the service platform side.
[0064] In one example, the media stream forking process in this disclosure refers to the routing process of media streams (such as audio streams) that need to be transmitted for voice calls between users and service platforms. This routing process is not media stream routing process that follows the original transmission path of the media stream, but rather media stream routing process that changes the transmission path of the media stream. For example, this disclosure may change the transmission path of user-side media streams (such as audio or video streams sent from the user side to the telephone network operator side) and route them to a designated port of the telephone network authentication platform. The media streams transmitted to the user side are routed to the user side through a designated port of the telephone network authentication platform. As another example, this disclosure may change the transmission path of service platform-side media streams (such as audio streams sent from the service platform side to the telephone network operator side) and route them to another designated port of the telephone network authentication platform. The media streams transmitted to the service platform side are routed to the service platform side through another designated port of the telephone network authentication platform.
[0065] By performing signaling and media stream forking on the voice calls between users and the business platform, new voice calls can be formed without the user's awareness. This is achieved by inserting two call legs into the existing voice call between the user and the business platform, creating separate voice calls between the telephone network identity authentication platform and the user, and between the telephone network identity authentication platform and the business platform. In this way, the user's voice call with the business platform is securely and seamlessly switched to the telephone network identity authentication platform's user authentication process. Furthermore, by upgrading the voice call between the user and the telephone network identity authentication platform to a video call, the platform can obtain real-time information containing the user's biometric features (such as facial images), thus preventing the forgery of biometric information and ensuring the reliability of the foundational information for trusted identity authentication.
[0066] In one example, since the business platform does not need to engage in voice interaction related to identity authentication with the telephone network identity authentication platform while waiting for the platform to return the user's trusted authentication result, this disclosure allows setting the voice call between the telephone network identity authentication platform and the business platform to a call hold state (e.g., the telephone network identity authentication platform sends a SIP message to the business platform to put the voice call on hold). This simplifies the signaling control and media stream control of the voice call by the telephone network identity authentication platform, reducing the operational difficulty of the platform. Furthermore, by continuously playing audio information (e.g., waiting music) to the business platform during the voice call between the telephone network identity authentication platform and the business platform, it helps prevent accidental disconnection of the voice call due to lack of sound.
[0067] S202. Obtain information containing the user's biometric characteristics based on the aforementioned video call.
[0068] The information containing user biometrics in this disclosure refers to information that contains the user's own physiological characteristics (such as face, facial features, eyes or iris) or behavioral characteristics (such as signature or walking posture) and can be used to identify an individual.
[0069] In one example, the information containing the user's biometric features could be a user's facial image. Of course, the information containing the user's biometric features could also be facial semantic features extracted from the user's facial image using a neural network. This disclosure does not limit the specific form in which the information containing the user's biometric features is presented.
[0070] In one example, this disclosure may first perform a liveness detection on the user based on a video call between the user and the telephone network authentication platform, and if the liveness detection is successful, obtain information containing the user's biometrics, such as obtaining the user's facial image.
[0071] A more concrete example could be that the user is first asked to position their face within a predetermined area on the mobile phone screen (such as within a circle displayed on the screen). Once the user's face is deemed to be in the correct position, voice prompts can be used to guide the user to blink, open their mouth, or turn their head, etc., and the system can assess whether the user has followed the voice prompts. If the user has not followed the prompts, voice prompts can be used again to guide the user to blink, open their mouth, or turn their head. If the number of times the user fails to follow the prompts reaches a predetermined number, both the user and the business platform can be notified: liveness detection failed, and the voice call between the user and the business platform can be terminated. Alternatively, the two calls can be restored to a single voice call between the user and the business platform. If the user has followed the prompts, voice prompts can be used to guide the user to remain still, allowing a clear video frame containing the user's facial features to be selected from the video media stream transmitted from the user's side. This video frame is then used as information containing the user's biometric features, i.e., the user's facial image.
[0072] Another more concrete example is that a text message (such as a risk warning and a request for video recording) can be sent to the user, who is then asked to read it aloud. The telephone network authentication platform can record the reading process. If the user does not read it correctly, they can be guided again to read the text aloud via voice. After the user reads it correctly, they can be asked to position their face within a predetermined area on the mobile phone screen (such as within a circle displayed on the screen). Once the user's face is determined to be in the correct position, they can be guided via voice to blink, open their mouth, or turn their head, etc., and the system can determine whether the user has performed the corresponding action as prompted by the voice. If the system determines that the user has not performed the action, the system will take further action. If the user performs the corresponding action as prompted by the voice, they can be guided again by voice to blink, open their mouth, or turn their head. If the number of times the user fails to perform the corresponding action as prompted by the voice reaches a predetermined number, or the number of times the user fails to read correctly reaches a predetermined number, the user and the business platform can be notified separately: "Liveness detection failed," and the voice call between the user and the business platform can be terminated. Alternatively, the two calls can be restored to the voice call between the user and the business platform. If it is determined that the user has performed the corresponding action as prompted by the voice, the user can continue to be guided by voice to remain still. A video frame with clear facial features can then be selected from the video media stream transmitted from the user's side and used as information containing the user's biometric features, i.e., the user's facial image.
[0073] This disclosure utilizes video calls for liveness detection, which can effectively prevent attacks that impersonate others using photos, masks, or screen captures, thereby helping to ensure the reliability of identity authentication results.
[0074] S203. Based on the information containing the user's biometrics, request the trusted digital identity service platform to perform trusted identity authentication for the user, and obtain the trusted identity authentication result for the user based on the information returned by the trusted digital identity service platform.
[0075] The trusted digital identity service platform disclosed herein can be an authentication platform provided by national security departments such as public security organs. The authentication request message sent by this disclosure to the trusted digital identity service platform can carry user identification information (such as user ID number and user name) and user facial image and other information required for authentication.
[0076] In one example, this disclosure can encrypt the information required for authentication by a trusted digital identity service platform, and then carry the encrypted information in an authentication request message, which is then transmitted to the trusted digital identity service platform. For instance, this disclosure can generate a key pair for this trusted identity authentication, and use the private key in the key pair to encrypt user identification information (such as the user's ID number and name) and the user's facial image. Then, the encrypted information and the public key from the key pair are carried together in an authentication request message, which is sent to the trusted digital identity service platform. By using a key pair for encryption during information transmission between the telephone network identity authentication platform and the trusted digital identity service platform, the security of trusted identity authentication is further guaranteed.
[0077] In one example, this disclosure can set up a corresponding interface in the telephone network identity authentication platform, and complete the request for the trusted digital identity service platform to perform trusted identity authentication operation on the user by calling the interface. Specifically, this disclosure can use the user's ID number, user name, and user facial image as input parameters of the interface, call the interface, and the interface generates a key pair in real time. The user's ID number, user name, and user facial image are encrypted using the private key in the key pair. Then, the encrypted information and the public key in the key pair are carried together in the authentication request message and sent to the trusted digital identity service platform.
[0078] If a user's identity is successfully authenticated, the trusted digital identity service platform will return an authentication result that includes an authentication success indicator and the authentication certificate. If the user's identity authentication fails, the trusted digital identity service platform will return an authentication failure indicator. Furthermore, the trusted digital identity service platform can encrypt the authentication result before sending the encrypted information to the telephone network identity authentication platform. For example, the trusted digital identity service platform can also use a key pair to encrypt the authentication result.
[0079] S204. Provide the user's trusted identity authentication result to the business platform, and change the video call between the telephone network identity authentication platform and the user, as well as the voice call between the telephone network identity authentication platform and the business platform, into a voice call between the user and the business platform.
[0080] The telephone network identity authentication platform disclosed herein can return the user's trusted identity authentication result to the identity authentication interface in the business platform. For example, the user's trusted identity authentication result can be carried in the response message of the aforementioned request message and sent to the business platform.
[0081] The telephone network identity authentication platform can use various methods to adjust and process video calls between the platform and users, as well as voice calls between the platform and business platforms. For example, it can use a merging technology that cancels the call leg to adjust and process the two calls, thereby re-forming a voice call between the user and the business platform.
[0082] In one example, the telephone network identity authentication platform can first convert the video call between the user and the telephone network identity authentication platform into a voice call. Then, it can use the call leg cancellation merging processing technology to perform signaling and media stream merging processing on the voice call between the telephone network identity authentication platform and the user, as well as the voice call between the telephone network identity authentication platform and the business platform, thereby forming the voice call between the user and the business platform again.
[0083] In one example, the telephone network authentication platform can send a request message (such as a SIP message) to the user to notify the user that the current video call needs to be switched to an audio call. For example, the telephone network authentication platform can use the request message to display a pop-up window on the user's mobile phone display interface. The text content of the pop-up window may include: "Current identity verification has ended, camera will be turned off soon." The pop-up window may also include: a button to turn off the camera immediately and a countdown button for turning off the camera. The telephone network authentication platform waits for the user's operation within a predetermined time interval. If the user performs an operation within the predetermined time interval, and the operation indicates agreement to turn off the camera immediately, then the user's camera is turned off, and the video call between the user and the telephone network authentication platform is switched to an audio call. If the user does not perform an operation within the predetermined time interval, or the operation performed by the user does not indicate agreement to turn off the camera immediately, then the telephone network authentication platform may turn off the camera by default when the countdown ends. In this case, the video call between the user and the telephone network authentication platform is switched to an audio call. In addition, this disclosure should also cancel the call hold status of the audio call between the service platform and the telephone network authentication platform.
[0084] In one example, the signaling merging process in this disclosure refers to the routing process of signaling that needs to be transmitted for a voice call between a user and the telephone network authentication platform, and the routing process of signaling that needs to be transmitted for a voice call between a service platform and the telephone network authentication platform, and the routing process is restored to the signaling routing process according to the original signaling transmission path. For example, this disclosure no longer routes user-side signaling (such as signaling sent from the user to the telephone network operator) to a designated port of the aforementioned telephone network authentication platform, but instead routes it to the service platform. Signaling transmitted to the user side is also no longer routed to the user side through a designated port of the telephone network authentication platform, but instead is routed to the user side according to the original routing method of voice calls between the user and the service platform. As another example, service platform-side signaling (such as signaling sent from the service platform to the telephone network operator) is no longer routed to another designated port of the aforementioned telephone network authentication platform, but instead routes it to the user. Signaling transmitted to the service platform side is also no longer routed to the service platform side through another designated port of the telephone network authentication platform, but instead is routed to the service platform side according to the original routing method of voice calls between the user and the service platform.
[0085] In one example, the media stream merging process in this disclosure refers to the routing process for media streams (such as audio streams) that need to be transmitted for voice calls between a user and a telephone network authentication platform, and the routing process for media streams (such as audio streams) that need to be transmitted for voice calls between a service platform and a telephone network authentication platform. Both routing processes are restored to the original media stream routing path. For example, this disclosure no longer routes user-side media streams (such as audio streams sent from the user to the telephone network operator) to a designated port of the aforementioned telephone network authentication platform, but instead routes them to the service platform according to the original routing method for voice calls between the user and the service platform. As another example, the service platform-side media streams (such as audio streams sent from the service platform to the telephone network operator) are no longer routed to another designated port of the aforementioned telephone network authentication platform, but instead routed to the user side according to the original routing method for voice calls between the user and the service platform.
[0086] The voice calls between users and service platforms formed after the consolidation process disclosed herein are also telephone network voice calls, not internet voice calls (such as voice calls based on instant messaging tools). For example, the voice calls between users and service platforms formed after the consolidation process disclosed herein could be VoLTE voice calls or VoNR voice calls from telephone network operators, etc.
[0087] By performing signaling merging and media stream merging on voice calls between users and the telephone network authentication platform, as well as voice calls between the business platform and the telephone network authentication platform, the original voice call can be restored without the user's awareness. This is achieved by removing the two call legs inserted into the voice call between the user and the business platform, thus forming a voice call between the user and the business platform. In this way, the user authentication process of the telephone network authentication platform is securely and seamlessly switched to the voice call between the user and the business platform. By notifying the user that their video call with the telephone network authentication platform has been downgraded to a voice call, the closure of the video call will not confuse the user, which helps to improve the user experience.
[0088] Exemplary System
[0089] The structure of one embodiment of the real-time video identity trusted authentication system based on the telephone network disclosed herein is as follows: Figure 3 As shown. Figure 3 The system shown mainly includes: a telephone network identity authentication platform 300 and at least one service platform 310. Figure 3 Three business platforms 310 are illustrated schematically. The telephone network identity authentication platform 300 is located on the telephone network operator's side and mainly includes: a first interface module 301, a call adjustment module 302, an information acquisition module 303, and a second interface module 304. The business platform 310 can be located on the enterprise side, the government department side, or the non-profit organization side, etc.
[0090] The business platform 310 is mainly used to generate a request message to trigger biometric-based trusted identity authentication when it is determined that a trusted identity authentication based on biometric recognition needs to be initiated during a voice call with a user, and then send it to the telephone network identity authentication platform 300.
[0091] The first interface module 301 is mainly used to receive a request message from the service platform 310 for triggering biometric-based trusted authentication. The specific information carried in the request message and the specific operations performed by the first interface module 301 can be found in the relevant description of step S200 in the above method embodiment, and will not be repeated here.
[0092] The call adjustment module 302 is mainly used to adjust the voice call between the user and the business platform 310 into a video call between the telephone network identity authentication platform 300 and the user, and a voice call between the telephone network identity authentication platform 300 and the business platform 310, based on the information carried in the request message received by the first interface module 301.
[0093] In one example, the call adjustment module 302 mainly includes: a signaling and media flow control submodule 3021 and an audio / video call switching submodule 3022.
[0094] The signaling and media stream control submodule 3021 is mainly used to perform signaling and media stream forking processing on the voice call between the user and the service platform 310 according to the information carried in the request message, forming a voice call between the telephone network identity authentication platform 300 and the user, and a voice call between the telephone network identity authentication platform 300 and the service platform 310. The signaling and media stream forking processing may include: routing the user-side signaling and user-side media stream to a designated port in the telephone network identity authentication platform, and routing the service platform-side signaling and service platform-side media stream to another designated port in the telephone network identity authentication platform.
[0095] The audio / video call switching submodule 3022 is mainly used to switch the voice call between the telephone network identity authentication platform 300 and the user to a video call.
[0096] The specific operations performed by the call adjustment module 302 and its included signaling and media flow control submodule 3021 and audio / video call switching submodule 3022 can be found in the relevant description in step S201 of the above method embodiment, and will not be repeated here.
[0097] The information acquisition module 303 is mainly used to acquire information containing the user's biometric characteristics based on the video call adjusted by the call adjustment module 302.
[0098] In one example, the information acquisition module 303 mainly includes a liveness detection submodule 3031 and an information acquisition submodule 3032. The liveness detection submodule 3031 is mainly used to perform liveness detection on the user based on the video call formed by the call adjustment module 302. The information acquisition submodule 3032 is mainly used to acquire the user's facial image if the liveness detection submodule 3031 successfully detects liveness. The facial image is a video frame from the video media stream in the video call, and the facial image is used as information containing the user's biometric features in this disclosure.
[0099] The specific operations performed by the information acquisition module 303 and its sub-modules, as well as the process by which the information acquisition module 303 acquires the user's facial image, can be found in the relevant description in the above method embodiment S202, and will not be repeated here.
[0100] The second interface module 304 is mainly used to request the trusted digital identity service platform to perform trusted identity authentication for the user based on the information including the user's biometric characteristics obtained by the information acquisition module 303, and to obtain the trusted identity authentication result of the user based on the information returned by the trusted digital identity service platform. The trusted digital identity service platform is typically located at a high-security department such as a public security agency. The specific information transmitted by the second interface module 304 to the trusted digital identity service platform can be found in the relevant description in the above method embodiment S203, and will not be repeated here.
[0101] The first interface module 301 is further configured to provide the user's trusted authentication result obtained by the second interface module 304 to the business platform 310. For details, please refer to the relevant description in the above method embodiment S304, which will not be repeated here.
[0102] The aforementioned call adjustment module 302 is also used to adjust the video call between the telephone network identity authentication platform 300 and the user, and the voice call between the telephone network identity authentication platform 300 and the business platform 310, into a voice call between the user and the business platform 310 when the second interface module 304 obtains the user's trusted identity authentication result.
[0103] In one example, the audio / video call switching submodule 3022 is also used to send a request message to the user to switch the current video call to an audio call during the process of performing signaling and media stream merging processing on the voice call between the telephone network authentication platform 300 and the user, and the voice call between the telephone network authentication platform 300 and the service platform 310 to form a voice call between the user and the service platform 310, and to receive a response message returned by the user. If the response message is a response message that allows the current video call to be switched to an audio call, the video call between the telephone network authentication platform 300 and the user is switched to an audio call between the telephone network authentication platform 300 and the user.
[0104] In one example, the signaling and media flow control submodule 3021 is also used to perform signaling and media flow merging processing on voice calls between the telephone network authentication platform 300 and the user, and voice calls between the telephone network authentication platform 300 and the service platform 310 (such as routing user-side signaling and user-side media flow to the service platform 310, and routing service platform 310-side signaling and service platform 310-side media flow to the user, forming a voice call between the user and the service platform 310).
[0105] The specific operations performed by the call adjustment module 302 and its sub-modules can be found in the relevant description in the above method embodiment S204, and will not be repeated here.
[0106] Exemplary device
[0107] The telephone network identity authentication platform disclosed herein can be referred to as a real-time video identity trusted authentication device based on a telephone network, and the structure of one embodiment of the telephone network identity authentication platform is as follows: Figure 4 As shown. The telephone network identity authentication platform of this embodiment can be used to implement the corresponding method embodiments and system embodiments of this disclosure. Figure 4 The telephone network identity authentication platform shown includes: a first interface module 301, a call adjustment module 302, an information acquisition module 303, and a second interface module 304.
[0108] The first interface module 301 is mainly used to receive a request message from the service platform to trigger biometric-based trusted identity authentication. This request message is generated when the service platform determines that biometric-based trusted identity authentication needs to be initiated during a voice call between the user and the service platform. The specific information carried in the request message and the specific operations performed by the first interface module 301 can be found in the relevant description in step S200 of the above method embodiment, and will not be repeated here.
[0109] The call adjustment module 302 is mainly used to adjust the voice call between the user and the business platform into a video call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the business platform, based on the information carried in the request message received by the first interface module 301.
[0110] In one example, the call adjustment module 302 mainly includes a signaling and media flow control submodule 3021 and an audio / video call switching submodule 3022. The specific operations performed by the call adjustment module 302 and its included signaling and media flow control submodule 3021 and audio / video call switching submodule 3022 can be found in step S201 of the above method embodiment and the relevant descriptions in the above system embodiment, and will not be repeated here.
[0111] The information acquisition module 303 is mainly used to acquire information containing the user's biometric characteristics based on the video call adjusted by the call adjustment module 302.
[0112] In one example, the information acquisition module 303 mainly includes a liveness detection submodule 3031 and an information acquisition submodule 3032. The specific operations performed by the information acquisition module 303 and its constituent submodules, as well as the process by which the information acquisition module 303 acquires user facial images, can be found in the relevant descriptions of the method embodiment S202 and the system embodiment described above, and will not be repeated here.
[0113] The second interface module 304 is mainly used to request the trusted digital identity service platform to perform trusted identity authentication for the user based on the information including the user's biometric features obtained by the information acquisition module 303, and to obtain the trusted identity authentication result of the user based on the information returned by the trusted digital identity service platform. The specific information transmitted by the second interface module 304 to the trusted digital identity service platform can be found in the relevant description in the above method embodiment S203, and will not be repeated here.
[0114] The first interface module 301 described above is also used to provide the user's trusted authentication result obtained by the second interface module 304 to the business platform. For details, please refer to the relevant descriptions in the method embodiment S304 and the system embodiment described above, which will not be repeated here.
[0115] The aforementioned call adjustment module 302 is also used to adjust video calls between the telephone network identity authentication platform and the user, and voice calls between the telephone network identity authentication platform and the service platform, into voice calls between the user and the service platform, when the second interface module 304 obtains the user's trusted authentication result. For details, please refer to the relevant descriptions in the above method embodiment S304 and system embodiments, which will not be repeated here.
[0116] Exemplary electronic devices
[0117] The following is for reference. Figure 5 To describe an electronic device according to embodiments of the present disclosure. Figure 5 A block diagram of an electronic device according to an embodiment of the present disclosure is shown. (As follows) Figure 5 As shown, the electronic device 41 includes one or more processors 411 and memory 412.
[0118] The processor 411 may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 41 to perform desired functions.
[0119] The memory 412 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, and flash memory. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 411 may execute the program instructions to implement the real-time video identity trusted authentication method based on the telephone network described in the various embodiments of this disclosure above, and / or other desired functions.
[0120] In one example, electronic device 41 may further include input device 413 and output device 414, etc., these components being interconnected via a bus system and / or other forms of connection mechanism (not shown). Furthermore, the input device 413 may also include, for example, a keyboard, mouse, etc. The output device 414 can output various information to the outside. The output device 414 may include, for example, a display, speaker, printer, and communication networks and their connected remote output devices, etc.
[0121] Of course, for the sake of simplicity, Figure 5 Only some of the components of the electronic device 41 relevant to this disclosure are shown, omitting components such as buses, input / output interfaces, etc. In addition, the electronic device 41 may include any other suitable components depending on the specific application.
[0122] Exemplary computer program products and computer-readable storage media
[0123] In addition to the methods and apparatus described above, embodiments of this disclosure may also be computer program products comprising computer program instructions that, when executed by a processor, cause the processor to perform the steps in the telephone network-based real-time video identity trusted authentication method according to various embodiments of this disclosure as described in the "Exemplary Methods" section above.
[0124] The computer program product can be written in any combination of one or more programming languages to perform the operations of the embodiments of this disclosure. The programming languages include object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on a user's computing device, partially on a user's computing device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0125] Furthermore, embodiments of this disclosure may also be computer-readable storage media having stored thereon computer program instructions that, when executed by a processor, cause the processor to perform the steps in the telephone network-based real-time video identity trusted authentication method according to various embodiments of this disclosure as described in the "Exemplary Methods" section above.
[0126] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (not an exhaustive list) may include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0127] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.
[0128] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0129] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0130] The methods and apparatus of this disclosure may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the methods is for illustrative purposes only, and the steps of the methods of this disclosure are not limited to the order specifically described above unless otherwise specifically stated. Furthermore, in some embodiments, this disclosure may also be implemented as a program recorded on a recording medium, the program including machine-readable instructions for implementing the methods according to this disclosure. Thus, this disclosure also covers recording media storing programs for performing the methods according to this disclosure.
[0131] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions to this disclosure.
[0132] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.
[0133] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A real-time video identity trusted authentication system based on a telephone network, characterized in that, The system includes: a telephone network identity authentication platform and at least one service platform; The service platform is used to generate a request message to trigger biometric authentication when it determines that biometric authentication of the user needs to be initiated during a voice call with the user, and sends the message to the telephone network authentication platform. The telephone network identity authentication platform is located on the telephone network operator's side, and the telephone network identity authentication platform includes: The first interface module is used to receive the request message transmitted from the business platform for triggering biometric-based identity trusted authentication; The call adjustment module is used to perform signaling and media stream forking processing on the voice call between the user and the service platform according to the information carried in the request message received by the first interface module, to form a voice call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform, and to adjust the voice call between the telephone network identity authentication platform and the user into a video call; The information acquisition module is used to acquire information including the user's biometric characteristics based on the video call; The second interface module is used to request the trusted digital identity service platform to perform trusted identity authentication for the user based on the information containing the user's biometric features, and to obtain the trusted identity authentication result of the user based on the information returned by the trusted digital identity service platform. The first interface module is also used to provide the trusted authentication result of the user's identity obtained by the second interface module to the business platform; The call adjustment module is further configured to adjust the video call between the telephone network identity authentication platform and the user, and the voice call between the telephone network identity authentication platform and the business platform, into a voice call between the user and the business platform when the second interface module obtains the user's trusted identity authentication result.
2. The system according to claim 1, characterized in that, The call adjustment module includes: The signaling and media stream control submodule is used to perform signaling and media stream forking processing on the voice call between the user and the service platform according to the information carried in the request message, so as to form a voice call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform. The audio / video call switching submodule is used to switch the voice call between the telephone network identity authentication platform and the user to a video call; The signaling and media stream forking process includes: routing user-side signaling and user-side media streams to a designated port in the telephone network authentication platform, and routing service platform-side signaling and service platform-side media streams to another designated port in the telephone network authentication platform.
3. The system according to claim 1 or 2, characterized in that, The information acquisition module includes: A liveness detection submodule is used to perform liveness detection on the user based on the video call. The information acquisition submodule is used to acquire the user's facial image when the liveness detection submodule successfully detects liveness. The facial image is a video frame in the video media stream of the video call, and the facial image is used as information containing the user's biometric features.
4. The system according to claim 2, characterized in that: The audio / video call switching submodule is also used to send a request message to the user to switch the current video call to an audio call, and to receive a response message returned by the user. If the response message is a response message that allows the current video call to be switched to an audio call, the video call between the telephone network identity authentication platform and the user is switched to an audio call between the telephone network identity authentication platform and the user. The signaling and media stream control submodule is also used to perform signaling and media stream merging processing on the voice calls between the telephone network authentication platform and the user, and the voice calls between the telephone network authentication platform and the service platform, to form the voice call between the user and the service platform; The signaling and media stream merging process includes: routing user-side signaling and user-side media streams to the service platform, and routing service platform-side signaling and service platform-side media streams to the user.
5. A telephone network identity authentication platform, characterized in that, The telephone network identity authentication platform is located on the telephone network operator's side, and the telephone network identity authentication platform includes: The first interface module is used to receive the request message transmitted from the business platform for triggering biometric-based trusted identity authentication; wherein, the request message is generated when the business platform determines that it needs to initiate biometric-based trusted identity authentication for the user during a voice call between the user and the business platform. The call adjustment module is used to perform signaling and media stream forking processing on the voice call between the user and the service platform according to the information carried in the request message received by the first interface module, to form a voice call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform, and to adjust the voice call between the telephone network identity authentication platform and the user into a video call; The information acquisition module is used to acquire information including the user's biometric characteristics based on the video call; The second interface module is used to request the trusted digital identity service platform to perform trusted identity authentication for the user based on the information containing the user's biometric features, and to obtain the trusted identity authentication result of the user based on the information returned by the trusted digital identity service platform. The first interface module is also used to provide the trusted authentication result of the user's identity obtained by the second interface module to the business platform; The call adjustment module is further configured to adjust the video call between the telephone network identity authentication platform and the user, and the voice call between the telephone network identity authentication platform and the business platform, into a voice call between the user and the business platform when the second interface module obtains the user's trusted identity authentication result.
6. A real-time video identity trusted authentication method based on a telephone network, characterized in that, The method is executed by a telephone network identity authentication platform located on the telephone network operator's side, and the method includes the following steps: The system receives a request message from the service platform to trigger biometric-based trusted identity authentication; wherein the request message is generated when the service platform determines that it needs to initiate biometric-based trusted identity authentication for the user during a voice call between the user and the service platform. Based on the information carried in the request message, the voice call between the user and the service platform is processed by signaling and media stream fork to form a voice call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform. The voice call between the telephone network identity authentication platform and the user is then converted into a video call. Information containing the user's biometrics is obtained based on the video call; Based on the information containing the user's biometric features, a trusted digital identity service platform is requested to perform trusted identity authentication for the user, and the trusted identity authentication result for the user is obtained based on the information returned by the trusted digital identity service platform. The user's trusted identity authentication result is provided to the business platform, and the video call between the telephone network identity authentication platform and the user, as well as the voice call between the telephone network identity authentication platform and the business platform, are adjusted to be a voice call between the user and the business platform.
7. The method according to claim 6, characterized in that, The request message is generated by the business platform when it determines that it needs to initiate biometric-based trusted identity authentication for the user by calling the identity authentication interface set on the business platform. The request message contains user identification information and business platform identification information; The user identification information is used to form the video call and the biometric-based identity authentication, and the business platform identification information is used to form the voice call between the business platform and the telephone network identity authentication platform.
8. The method according to claim 7, characterized in that, The process by which the business platform generates the request message includes: When the business platform determines that the user has used the mobile phone number stored on the business platform for trusted identity authentication, it obtains the user's ID number and name from its customer relationship management system based on the stored mobile phone number, and generates a request message containing the stored mobile phone number, user ID number, user name and business platform identification information by calling the identity authentication interface. If the business platform determines that the user has not used the mobile phone number stored on the business platform for trusted identity authentication, it retrieves the user's name from the customer relationship management system based on the user's ID number obtained from the user, and generates a request message containing the mobile phone number of the user's current voice call, the user's ID number, the user's name, and the business platform's identification information by calling the identity authentication interface.
9. The method according to claim 7, characterized in that, The signaling and media stream forking process includes: The user-side signaling and user-side media stream are routed to a designated port in the telephone network authentication platform, and the service platform-side signaling and service platform-side media stream are routed to another designated port in the telephone network authentication platform.
10. The method according to claim 9, characterized in that, The step of performing signaling and media stream forking processing on the voice call between the user and the service platform based on the information carried in the request message, forming a voice call between the telephone network identity authentication platform and the user, and a voice call between the telephone network identity authentication platform and the service platform, and adjusting the voice call between the telephone network identity authentication platform and the user into a video call, further includes: Set the voice call between the telephone network identity authentication platform and the business platform to a call hold state, and continuously play audio information to the business platform through the voice call between the telephone network identity authentication platform and the business platform.
11. The method according to claim 7, characterized in that, The step of obtaining information containing user biometrics based on the video call includes: Based on the video call, a liveness detection is performed on the user, and if the liveness detection is successful, the user's facial image is acquired; The facial image is a video frame in the video media stream of the video call, and the facial image is used as information containing the user's biometric features.
12. The method according to claim 11, characterized in that, The step of requesting a trusted digital identity service platform to perform trusted identity authentication for the user based on the information containing the user's biometrics includes: A key pair is generated for this identity authentication, and the private key in the key pair is used to encrypt the user identification information and the user facial image carried in the request message. The public key in the key pair and the encrypted information are transmitted to the trusted digital identity service platform.
13. The method according to any one of claims 7 to 12, characterized in that, The step of adjusting the video call between the telephone network identity authentication platform and the user, and the voice call between the telephone network identity authentication platform and the service platform, to a voice call between the user and the service platform includes: Send a request message to the user to switch the current video call to an audio call; Upon receiving a response message from the user allowing the current video call to be converted into a voice call, the video call between the telephone network authentication platform and the user is converted into a voice call between the telephone network authentication platform and the user. Signaling and media stream merging processing is then performed on the voice call between the telephone network authentication platform and the user, as well as the voice call between the telephone network authentication platform and the service platform, to form a voice call between the user and the service platform. The signaling and media stream merging process includes: routing user-side signaling and user-side media streams to the service platform, and routing service platform-side signaling and service platform-side media streams to the user.
14. A computer-readable storage medium storing a computer program for performing the method of any one of claims 6-13.
15. An electronic device, the electronic device comprising: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method of any one of claims 6-13.
Citation Information
Patent Citations
Call identity authentication method, terminal and computer readable storage medium
CN114040397A
Connection establishment method and system of SIP call center system, and storage medium
CN115604237A