Bidirectional identity authentication method and related device
Through the two-way identity authentication method, the identity authentication information is used to determine the hotspot password and perform authentication, which solves the adaptability and security problems of one-way identity authentication in the existing technology and realizes a more efficient and secure identity authentication process.
Patent Information
- Application Number
- CN202111473378.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-02
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2041-12-02
AI Technical Summary
The existing one-way identity authentication method cannot be adapted to some scenarios that require two-way authentication, and its security and authentication speed are insufficient, which cannot meet user security needs.
A two-way identity authentication method is adopted. By receiving the user information of the second terminal device sent by the server, the hotspot password is determined according to the identity authentication information and the hotspot is activated, identity authentication is performed, and the authentication result is fed back to the server to update the user status information.
It improves the security of the system and the speed of identity authentication, and can also track the current status of the objects being used to ensure user safety.
Smart Images

Figure CN114168919B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of electronic technology, and in particular to a method and related device for two-way identity authentication. Background Art
[0002] In recent years, with the rapid development of the Internet of Things (IoT), identity authentication has become widely used in our daily lives and work. Currently, identity authentication methods primarily rely on one-way identification, such as fingerprint recognition, facial recognition, and RFID card recognition. These authentication methods often rely on the user's permission. They are incompatible with specialized scenarios, such as when parents pick up their children from school, where two-way authentication is required, and they are also insecure. Therefore, a new authentication method is urgently needed to ensure user security. Summary of the Invention
[0003] The present invention provides a method and related apparatus for two-way identity authentication, which can realize two-way identity authentication based on identity verification information, thereby improving system security and identity authentication speed. At the same time, it can also track the current status of the object to ensure the safety of the user.
[0004] In a first aspect, an embodiment of the present application provides a bidirectional identity authentication method, applied to a first terminal device, the method comprising:
[0005] Receive user information corresponding to the second terminal device sent by the server, where the user information includes first identity authentication information of the second terminal device.
[0006] Determine the hotspot password based on the first identity authentication information of the second terminal device, and activate the hotspot;
[0007] In response to the hotspot connection request of the second terminal device, performing identity authentication on the second terminal device to obtain an authentication result;
[0008] The authentication result is fed back to the server so that the server can determine the status information of the user corresponding to the first terminal device.
[0009] In a second aspect, an embodiment of the present application provides a two-way identity authentication method, applied to a server, the method comprising:
[0010] receiving a query instruction sent by the first terminal device;
[0011] Determining user information corresponding to the query instruction;
[0012] Feedback the user information to the first terminal device;
[0013] receiving an authentication result fed back by the first terminal device;
[0014] According to the authentication result, the status information of the user corresponding to the first terminal device is updated.
[0015] In a third aspect, an embodiment of the present application provides a bidirectional identity authentication apparatus, applied to a first terminal device, the apparatus comprising:
[0016] A receiving unit, configured to receive user information corresponding to a second terminal device sent by a server, wherein the user information includes first identity authentication information of the second terminal device;
[0017] A setting unit, configured to determine a hotspot password based on the first identity authentication information of the second terminal device and activate the hotspot;
[0018] A feedback unit is used to feed back the authentication result to the server, so that the server can determine the status information of the user corresponding to the first terminal device.
[0019] In a fourth aspect, an embodiment of the present application provides a two-way identity authentication device, which is applied to a server, and the device includes:
[0020] A receiving unit, configured to receive a query instruction sent by a first terminal device and receive an authentication result fed back by the first terminal device;
[0021] a determining unit, configured to determine user information corresponding to the query instruction;
[0022] a feedback unit, configured to feed back the user information to the first terminal device;
[0023] A status updating unit is used to update the status information of the user corresponding to the first terminal device according to the authentication result.
[0024] In a fifth aspect, an embodiment of the present application provides an electronic device comprising a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the program comprises instructions for executing the steps of any method of the first aspect or the second aspect of the embodiment of the present application.
[0025] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the above-mentioned computer-readable storage medium stores a computer program for electronic data exchange, wherein the above-mentioned computer program enables a computer to execute part or all of the steps described in any method of the first aspect of the embodiment of the present application.
[0026] In a seventh aspect, embodiments of the present application provide a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to execute some or all of the steps described in any of the methods of the first or second aspects of the embodiments of the present application. The computer program product may be a software installation package.
[0027] It can be seen that the embodiment of the present application discloses a method and related apparatus for two-way identity authentication, the method comprising: receiving user information corresponding to a second terminal device sent by a server; determining the hotspot password and starting the hotspot based on the first identity authentication information of the second terminal device; performing identity authentication on the second terminal device in response to a hotspot connection request from the second terminal device to obtain an authentication result; feeding back the authentication result to the server for the server to determine the status information of the user corresponding to the first terminal device. In this way, through the method proposed in the embodiment of the present application, the function of two-way identity authentication can be realized based on the identity authentication information, thereby improving the security of the system and the speed of identity authentication. At the same time, it is also possible to track the current status of the object being used to ensure the safety of the user. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0029] Figure 1A This is a schematic diagram of a common Wi-Fi scenario provided by an embodiment of the present application;
[0030] Figure 1B This is a schematic diagram of an application scenario of a two-way identity authentication method provided in an embodiment of the present application;
[0031] Figure 2 This is a flowchart of a two-way identity authentication method provided by an embodiment of the present application;
[0032] Figure 3 This is a schematic diagram of an application scenario of information interaction of a first terminal device provided in an embodiment of the present application;
[0033] Figure 4 This is a flowchart of a two-way identity authentication method provided by an embodiment of the present application;
[0034] Figure 5 This is a schematic diagram of a fingerprint image partition provided by an embodiment of the present application;
[0035] Figure 6 This is a diagram of an authentication result prompt interface of a pick-up and drop-off management platform provided in an embodiment of the present application;
[0036] Figure 7 This is a flowchart of another two-way identity authentication method provided by an embodiment of the present application;
[0037] Figure 8 This is a schematic diagram of a process for updating user status by a server provided in an embodiment of the present application;
[0038] Figure 9 This is a schematic diagram of a two-way identity authentication campus application scenario process provided by an embodiment of the present application;
[0039] Figure 10 This is a schematic diagram of the device interaction flow of a two-way identity authentication method provided by an embodiment of the present application;
[0040] Figure 11 This is a schematic diagram of the interactive execution flow of three devices in a two-way identity authentication method provided by an embodiment of the present application;
[0041] Figure 12 This is a schematic diagram of the structure of a two-way identity authentication device provided in an embodiment of the present application;
[0042] Figure 13 This is a schematic diagram of the structure of another bidirectional identity authentication device provided in an embodiment of the present application;
[0043] Figure 14 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0044] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0045] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.
[0046] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0047] In order to better understand the solution of the embodiment of the present application, the following briefly introduces several common Wi-Fi scenarios, such as Figure 1A , Figure 1A This is a schematic diagram of a common Wi-Fi scenario provided by an embodiment of the present application;
[0048] The electronic devices involved in the embodiments of the present application may include various handheld devices with wireless communication functions, vehicle-mounted devices, wearable devices, computing devices, or other processing devices connected to a wireless modem, as well as various forms of user equipment (UE), mobile stations (MS), terminal devices, etc. In the embodiments of the present application, the electronic device may include the first terminal device, the second terminal device, and the server described in the embodiments of the present application.
[0049] A wireless router (Wireless Access Point, AP) is a network device that connects two or more network devices, acts as a gateway in the network, and supports routing and forwarding functions. Figure 1A AP1 and AP2 in.
[0050] A station (STA) is a terminal device with Wi-Fi support, such as a smartphone, tablet, watch, etc.
[0051] Hotspot / Soft AP (SAP) is similar to the function of a wireless router.
[0052] Access Control Server (AC), also known as Network Access Server (NAS) or Remote Access Server (RAS), is a remote access device located between the public telephone network (PSTN / ISDN) and the IP network.
[0053] See also Figure 1A As shown, wireless device A can access several terminal devices such as mobile phones, computers, and wireless router APs. Specific application scenarios are as follows:
[0054] Scenario 1: Wireless device A is connected to wireless router AP1. If Internet access is required, wireless router AP1 needs to be connected to wireless access control server AC, and Internet access is controlled by AC. Figure 1A Path 101 in.
[0055] Scenario 2: Wireless device A connects to the hotspot (i.e., SAP) provided by terminal device B. To access the Internet, terminal device B needs to open the LTE / 5G data network and then access the Internet. In this scenario, terminal device B needs to support SAP, STA, and data network. Figure 1A Path 102 in.
[0056] Scenario 3: Wireless device A connects to the hotspot (SAP) provided by terminal device C. To access the Internet, terminal device B needs to connect to another wireless router AP3, which in turn needs to connect to the Internet. This scenario requires terminal device B to support the coexistence of SAP and STA. Figure 1A Path 103.
[0057] Furthermore, the present application solution is based on the above scenario 3 to achieve two-way identity authentication. In order to better understand the actual application scenario of the present application embodiment, the following will be combined with Figure 1B The practical application scenarios of the embodiments of this application are described in detail:
[0058] See also Figure 1B , Figure 1B This is a schematic diagram of an application scenario of a two-way identity authentication method provided in an embodiment of the present application:
[0059] Specifically, in combination with an actual scenario, user A holds terminal device A, where terminal device A is a smartphone, for example. User B holds terminal device B, which can be a smartphone, a smartwatch, or a smart card.
[0060] Specific as Figure 1B The process shown:
[0061] When user B takes out terminal device B, he activates device B by identifying the user's identity information (e.g. Figure 1B 104), after connecting to the AP (such as Figure 1B 105), device B automatically turns on the hotspot (such as Figure 1B 106); At this time, user A enters the identity information on wireless device A and activates device A (such as Figure 1B 107), automatically turns on Wi-Fi, scans and connects to the specified hotspot (such as Figure 1B 108), if the connection is successful, A is a user that meets the preset conditions; if the connection is unsuccessful, A is a user that does not meet the preset conditions.
[0062] The present application is described in detail below with reference to specific embodiments.
[0063] See also Figure 2 , Figure 2 This is a flow chart of a two-way identity authentication method provided by the present application embodiment. Figure 2 As shown, the two-way identity authentication method in this application includes the following steps:
[0064] S201: Receive user information corresponding to a second terminal device sent by a server.
[0065] Specifically, the above-mentioned user information includes first identity authentication information of the second terminal device.
[0066] Specifically, after the first terminal device is activated, the Wi-Fi function will be automatically turned on and connected to the server in the area where the user is located. Take the campus as an example: before leaving school, the student verifies his or her personal identity information and activates the first terminal device; the first terminal device automatically turns on the Wi-Fi function and connects to the campus server to proceed to the next step. It should be further explained that the method in this solution can also be used in a variety of application scenarios, and is not limited to school areas, so no excessive restrictions are made here.
[0067] Specifically, the database of the above-mentioned server stores relevant information of the user, and the identity information includes one or more of the following: user name, gender, age, verification information, etc. At the same time, the database also stores the first identity authentication information of the second terminal device associated with the user. The first terminal device is connected to the server and transmits the above identity authentication information to the server via Wi-Fi; further, based on the identity authentication information, the database is searched and returned with the user's personal information (for example: if the user of the first terminal device is a student, the student's personal information is returned) and the user information of the second terminal device associated with it (for example: if the user of the second terminal device is the student's parent, the user information includes at least the user's first identity authentication information, and also includes one or more of the following information: name, phone number, avatar, etc.).
[0068] S202: Determine the hotspot password based on the first identity authentication information of the second terminal device, and start the hotspot.
[0069] Specifically, after step S201, the first terminal device receives user information corresponding to the second terminal device sent from the server, where the user information includes the first identity authentication information of the second terminal device.
[0070] Furthermore, the first identity authentication information of the second terminal device is encoded to obtain a password character string.
[0071] Furthermore, the first terminal device turns on the hotspot function and sets the password character string of the above encoding result as the password of the hotspot.
[0072] In another possible example, the first terminal device already stores the user's personal information and the user information of the associated second terminal device. Therefore, the first terminal device does not need to interact with the server to obtain relevant information. This approach can also avoid the subsequent authentication process being affected by a failure to connect to the server.
[0073] In a possible example, before determining the hotspot password according to the first authentication information of the second terminal device, please refer to Figure 3 ,like Figure 3 The embodiment of the present application provides a schematic diagram of an application scenario for information interaction with a first terminal device, wherein the method further includes the following steps:
[0074] S301 : In response to an activation success instruction for a target application, connecting to the server, wherein the activation success instruction includes second identity authentication information.
[0075] Specifically, the user verifies and activates the first terminal device through a preset target application APP of the first terminal device, and the first terminal device connects to the server in response to an activation success instruction for the preset target application APP.
[0076] Wherein, the activation success instruction includes second identity verification information.
[0077] In actual use, the user of the first terminal device opens a pre-set application software app on the first terminal device and enters the second identity verification information for personal identity verification. The second identity verification information includes, but is not limited to, fingerprint, voiceprint, iris, and other information. The app verifies the identity verification information. If the verification is successful, an activation success instruction is generated, and the first terminal device is activated.
[0078] For example, let's take a campus application scenario. The current user of the first terminal device is a student. Then, the first terminal device will be equipped with an app that facilitates student operation. Before leaving school, the student opens the app and enters their personal authentication information. The app recognizes this information and automatically activates the first terminal device.
[0079] Furthermore, after the first terminal device is activated, the Wi-Fi function will be automatically turned on and connected to the server.
[0080] S302: After successfully connecting to the server, send a query instruction to the server.
[0081] Wherein, the query instruction includes the second identity authentication information.
[0082] Specifically, taking the current application scenario as a campus, the server is a campus server. After the first terminal device connects to the campus server, it sends a query instruction to the campus server, which includes the second identity verification information entered in S301. The campus server's database stores user personal information corresponding to the second identity verification information. Since the second identity verification information corresponds to a user on a one-to-one basis, the corresponding user information can be quickly retrieved using the query instruction.
[0083] As can be seen, since the server pre-stores the first terminal device's user information, after the first terminal device is activated, it uses the first terminal device's second authentication information as a query instruction to query related information. Due to the uniqueness of the identity information, the user information of the first terminal device associated with the second authentication information can be accurately located, and the user of the second terminal device associated with the first terminal device can be further determined, ensuring system security and authentication efficiency.
[0084] S203: In response to the hotspot connection request of the second terminal device, perform identity authentication on the second terminal device to obtain an authentication result.
[0085] Specifically, after the first terminal device turns on the hotspot, it may receive several hotspot connection requests from the second terminal device. Therefore, the first terminal device needs to authenticate the hotspot connection requests and determine whether to establish a connection with the second terminal device based on the authentication result.
[0086] In one possible example, the hotspot connection request includes the encoding result of the third identity authentication information of the second terminal device, and the identity authentication of the second terminal device may include the following steps: if the encoding result of the third identity authentication information is consistent with the hotspot password, it is determined that the authentication of the second terminal device is successful; if the encoding result of the third identity authentication information is inconsistent with the hotspot password, it is determined that the authentication of the second terminal device has failed.
[0087] Specifically, in S202, the first terminal device encodes the first identity authentication information of the corresponding second terminal device, and uses the resulting encoding password string as the password of the hotspot of the first terminal device.
[0088] Exemplarily, the hotspot request information of the second terminal device includes the encoded result of the third identity authentication information of the second terminal device. If the encoded result of the current third identity authentication information is consistent with the encoded result of the first identity authentication information, the authentication result is: authentication successful, and a connection is successfully established between the first terminal device and the second terminal device.
[0089] For example, if the encoding result of the third identity authentication information carried in the current hotspot connection request is inconsistent with the encoding result of the first identity authentication information, the current authentication result is: authentication failed, and the first terminal device rejects the hotspot connection request of the current second terminal device. It can be seen that in this embodiment of the application, by authenticating the hotspot connection request with the encoding result of the first identity authentication information of the first terminal device, and determining whether to connect based on the authentication result, the security of the current connection between the first terminal device and the second terminal device can be guaranteed.
[0090] For a possible example, see Figure 4 As shown, Figure 4 The present invention provides a flow chart of a method for two-way identity authentication, wherein the first identity authentication information includes fingerprint information, and determining the hotspot password based on the first identity authentication information of the second terminal device may further include the following steps:
[0091] S401: Encode the fingerprint information according to a preset method to obtain a password string.
[0092] In practical applications, there are many types of information that can be used as user identity verification information, such as voice, iris, fingerprint, etc. In the examples of this application, only fingerprint information is used as an example for further explanation. However, it should be noted that this application does not limit the information used for identity verification to a single one.
[0093] Specifically, when the first terminal device receives the first identity authentication information and fingerprint information of the second terminal device returned by the server, the first terminal device encodes the fingerprint information into a unique character string according to a certain algorithm.
[0094] In another possible example, one way to encode fingerprint information is to encode the input fingerprint image with the processed fingerprint skeleton image and the extracted fingerprint type, fingerprint center point, triangulation point, bifurcation point, and endpoint to obtain a stable code of a certain length corresponding to the fingerprint image. The specific implementation method is as follows:
[0095] In practical applications, fingerprints obtained from the same finger of the same person may have different pressing methods, resulting in differences in fingerprint images. However, the relative positions of the absolute position coordinates of the fingerprint feature points of the same finger remain unchanged.
[0096] Please refer to the Figure 5 ,like Figure 5 As shown, Figure 5This is a schematic diagram of fingerprint image partitioning provided by an embodiment of the present application. After the fingerprint image is partitioned, the black portion represents the center origin selected through registration, which serves as a pixel on the image. Then, a series of squares are expanded outward at intervals of 3 pixels. The square closest to the farthest point is image area A, which gradually expands outward to areas B, C, and so on, until the edge of the fingerprint image is reached.
[0097] Furthermore, the center origin is set as 1, and the number of the low-zone feature point is smaller than that of the high-zone feature point. In the same square area, the horizontal coordinate X axis is used as the initial axis, and the feature points appearing in the counterclockwise direction are numbered sequentially. Finally, N feature points are numbered as P1, P2, P3 according to their positions. . . , P n .
[0098] Furthermore, the feature points obtained in the above steps are encoded. According to the preset encoding length requirement, several feature points are selected in sequence, for example, the first M feature points are selected from N, based on point P x For example (in the first round of coding, P x =P5), and each of the M feature points is sequentially written into an eight-bit code.
[0099] Furthermore, it is determined whether encoding is required again. If so, the reference point is moved back. If the reference point selected above is P5, then the next reference point P x = P6, and so on. After the encoding is completed, the encoding of each feature point in each round of encoding is connected together to form the final encoded string String-pw corresponding to the fingerprint image.
[0100] It should be noted that the above method for encoding fingerprint information is only an example. Other methods can be used to encode fingerprint information, which are not detailed here. The unique representation here is that the fingerprint information is calculated using an algorithm to obtain a fixed string, String-pw. This string is always calculated using the same fingerprint. The resulting string String-pw is then used as the password.
[0101] S402: Determine the user identity corresponding to the first terminal device.
[0102] Specifically, as described in S302 above, assuming the current application scenario is a campus. After successfully connecting to the campus server, the first terminal device sends a query instruction to the campus server, where the query instruction includes the second identity verification information. The server determines the current user information of the first terminal device based on the second identity verification information. The user identities corresponding to the first and second terminal devices may be students or pick-up personnel.
[0103] S403: After the user identity satisfies a preset identity, generate the hotspot password according to the password character string.
[0104] Furthermore, if the current user is a student, the server sends the current student information and the corresponding pick-up person information to the first terminal device. The pick-up person information includes the pick-up person's first identity verification information. The first terminal device encodes the first identity verification information to obtain String-pw.
[0105] Furthermore, the first terminal device currently sets the service set identifier (SSID) to the default, activates the hotspot function of the first terminal device, and uses string-pw as the authentication password for the current hotspot. SSID technology can divide a wireless local area network into several sub-networks that require different authentication methods. Each sub-network requires independent authentication, and only authenticated users can access the corresponding sub-network, preventing unauthorized users from accessing the network.
[0106] If the current user is a pickup person, the server sends the current student information to the first terminal device. This student information includes the student's facial image. After receiving the student information, the second terminal device activates its Wi-Fi module and sends a hotspot connection request to the first terminal device corresponding to the student information.
[0107] It can be seen that in the embodiment of the present application, there is different information feedback for the user identity of the terminal device, and the terminal device uses the encoding of the identity authentication information as the password of the hotspot. Based on the particularity of the identity authentication information, it can fully ensure the security of the hotspot and thus ensure the security of the hotspot connection and the stability of the system.
[0108] In a possible example, after the identity authentication of the second terminal device, the following steps may also be included: after the user identity meets the preset identity, the prompt method corresponding to the authentication result is determined, wherein the prompt method is used to prompt the user corresponding to the first terminal device of the authentication result of the second terminal device.
[0109] Specifically, after the first terminal device performs identity authentication on the hotspot link request of the second terminal device, a corresponding authentication result is generated, which includes: authentication success or authentication failure.
[0110] Furthermore, if the current authentication result is successful, after the second terminal device is connected to the first terminal device, the terminal interface of the second terminal device will receive a corresponding prompt message.
[0111] Specifically, see Figure 6 .like Figure 6 As shown, Figure 6 This is a diagram of an authentication result prompt interface of a pick-up and drop-off management platform provided in an embodiment of the present application.
[0112] like Figure 6 As shown on the left, if the first and second devices are successfully connected, the default interface on the second device will display: "Congratulations, connection successful. Please go to the school to pick up the student in the picture." along with the name and photo of the person picking up the student. The user of the second device can follow the prompt to pick up the person in the picture.
[0113] like Figure 6 As shown on the right, if the hotspot link request authentication of the current second terminal device fails, the second terminal device will receive a prompt message as shown in the figure: "Your current connection request failed!" Further, it will prompt: "The reason for the current authentication failure may be: the current authentication information is incorrect, please re-authenticate."
[0114] If the pick-up person enters their personal verification information again, the first terminal device will verify the hotspot connection request again and still fail. A prompt message will be received: If the current verification still fails to connect, please confirm whether your identity information is registered. It should be noted that a student may have multiple pick-ups, such as parents, grandparents, or nannies, but it is possible that only the parents' verification information is saved on the campus server, and the personal information of the other pick-ups is not entered.
[0115] Furthermore, if the current verification failure is caused by none of the above circumstances, the management platform will give a prompt message: "If it is not the above reasons, please contact the school administrator."
[0116] As can be seen, the embodiments of the present application provide corresponding solution prompts for different authentication results of hotspot connection requests. This can not only avoid the situation where authentication fails due to a wrong operation, but also provide corresponding solutions for different possible situations, making it easier for users to operate accordingly.
[0117] S204: Feedback the authentication result to the server, so that the server can determine the status information of the user corresponding to the first terminal device.
[0118] Specifically, after the first terminal device verifies the hotspot connection request, whether the authentication is successful or failed, the corresponding authentication result will be fed back to the server.
[0119] Furthermore, the server may update the status information of the user of the current first terminal device according to the current authentication result. Taking the current application scenario as a campus as an example, the user's status information is also the current student's leaving status information.
[0120] Specifically, if the information received by the current campus server is: authentication successful, the campus server updates the current student's filled information to: has completed the departure process, and stores the corresponding pick-up person information of the second terminal device.
[0121] If the current campus server receives the message "Authentication Failed," the student's status will remain "Not Leave." In one possible example, if the current campus server receives the "Authentication Failed" prompt three times in a row, it will send a prompt to the second terminal device of the student's corresponding pick-up person in the database: "Please confirm whether the current pick-up person is a legitimate pick-up person."
[0122] As can be seen, the embodiments of this application disclose a method for two-way identity authentication. Regardless of whether the authentication is successful, both the first and second terminal devices will feed back the authentication results to the server, which can then update the user's status based on the current authentication information. The server's update of the user status facilitates the confirmation of the user status of the first and second terminal devices, thereby ensuring user security.
[0123] For a possible example, see Figure 7 , Figure 7 This is a flowchart of another two-way identity authentication method provided by the embodiment of the present application. Figure 7 As shown, applied to the server, the two-way identity authentication method in this application includes the following steps:
[0124] S701: Receive a query instruction sent by a first terminal device.
[0125] Among them, the above server can be used with Figure 2The first terminal device shown in the figure performs information interaction, which can be used to provide query services for the first terminal device. The server can store user information of the second terminal device corresponding to the first terminal device in advance. For example, the user corresponding to the first terminal device is a student, and the second terminal device corresponds to the first terminal device one by one. For example, the user of the second terminal device is the student's parent, and the user information corresponding to the user of the second terminal device at least includes the user's identity authentication information (i.e., Figure 2 The first identity verification information described in the embodiment) may include one or more of the following information: name, phone number, avatar, etc.
[0126] Specifically, the query command is the same as the query instruction mentioned in S302 above, and will not be described in detail here.
[0127] S702: Determine user information corresponding to the query instruction.
[0128] Specifically, the above user information includes first identity authentication information pre-stored in a second terminal device corresponding to the first terminal device.
[0129] S703: Feedback the user information to the first terminal device;
[0130] Specifically, after receiving the query instruction from the first terminal device, the server searches the pre-stored data in the database according to the second identity verification information in the query instruction, and feeds back the search result to the first terminal device.
[0131] S704: Receive the authentication result fed back by the first terminal device.
[0132] The authentication result is used to indicate whether the authentication of the second terminal device is successful.
[0133] Specifically, as described in S204, after verifying the hotspot connection request of the second terminal device, the first terminal device will feed back the authentication result to the server regardless of whether the authentication result is successful.
[0134] S705: Update the status information of the user corresponding to the first terminal device according to the authentication result.
[0135] In one possible example, the status information includes: the status of leaving school in process and the status of having left school; the updating of the status information of the user corresponding to the first terminal device specifically includes: if the authentication result is successful, then updating the status information to the status of having left school; if the authentication result is failed, then updating the status information to the status of leaving school in process. Figure 8 Provide specific instructions, such as Figure 8 As shown, Figure 8 An embodiment of the present application provides a flow chart of a server updating a user status.
[0136] Specifically, the campus application scenario is used as an example. After the current first terminal device is successfully connected to the campus server, the campus server will feed back the first identity authentication information of the second terminal device corresponding to the first terminal device to the first terminal device. The first terminal device matches the corresponding pick-up person information and performs hotspot connection request authentication. If the current authentication is successful, it means that the current student matches the identity of the pick-up person, and the server updates the current student status to: left school. If the current authentication fails, the campus server still displays the student's status as: not left school.
[0137] For example, if the current first terminal device fails to connect to the campus server, the first terminal device does not match the corresponding pick-up person information. Then the current campus server displays the student's status as: not leaving school.
[0138] For the application scenarios described above, the following will be combined Figure 9 The overall solution of the embodiment of this application is described in detail in the campus application scenario. Figure 9 , Figure 9 This is a flow chart of a two-way identity authentication campus application scenario provided by an embodiment of the present application. It specifically includes the following steps:
[0139] Figure 9 The dotted box in the upper half is the APP 90 part. As we know, the first terminal device and the second terminal device both have the same APP installed. When the user opens the APP UI interface, the user identity may be a student or a pick-up person. When the user opens the APP, the APP determines whether the current user is a pick-up person:
[0140] If the current user is not a pick-up person, then the current user is a student. The first terminal device is activated based on the second identity verification information entered by the student (in this case, the fingerprint, i.e., the second fingerprint). When the first terminal device is activated, Wi-Fi is automatically turned on and connected to the school server;
[0141] If the current user identity is the pick-up person, the second terminal device is activated according to the fingerprint input by the pick-up person, the APP sets the user identity as the pick-up person and transmits the first fingerprint of the pick-up person to the fingerprint hotspot management module.
[0142] Further, enter Figure 9 The lower half of the overall frame is executed at 91:
[0143] Specifically, after the first terminal device turns on Wi-Fi, it determines whether it is successfully connected to the campus server:
[0144] If not, the "connection failed" message will be fed back;
[0145] If yes, the campus server searches the database for the corresponding identification information of the pick-up person based on the current student's second fingerprint, which includes the pick-up person's fingerprint information, i.e., the third fingerprint. The retrieved third fingerprint of the pick-up person is then transmitted to the fingerprint hotspot management module.
[0146] Furthermore, the hotspot setting transmits the first fingerprint input by the person picking up or sending the child from the APP end and the third fingerprint in the database search result to the fingerprint encoding module.
[0147] Furthermore, the fingerprint encoding module encodes the received first fingerprint and third fingerprint respectively to obtain a character string string-pw, and sends the generated character string string-pw to the fingerprint hotspot management module.
[0148] Furthermore, the fingerprint hotspot management module obtains the string-pw after the fingerprint is converted. Determine whether the current APP setting is a pick-up person:
[0149] If the current APP setting is to pick up the person, it means that the character string received by the current fingerprint hotspot management module is the first fingerprint entered by the pick up person through the APP UI interface. Further, the Wi-Fi function of the second terminal device at the current pick up person is turned on, and the currently connectable network with SSID "student" and password "string-pw" is scanned;
[0150] If the current app setting is not for a pick-up person, indicating that the current user is a student, the fingerprint hotspot management module receives the third fingerprint string contained in the search results returned by the campus server. Furthermore, the first terminal device sets the current SSID to the default "student" and the password to "string-pw" before opening the hotspot. Waiting for the pick-up person to request authentication for hotspot access.
[0151] It can be seen that the embodiment of the present application discloses a method for two-way identity authentication. The first terminal device and the second terminal device can be activated through the same preset APP, and at the same time as the activation, the terminal device also obtains the corresponding user information. The first terminal device retrieves the corresponding information from the server based on the user information and encodes the identity information in the query result as the hotspot password. At the same time, the identity authentication information of the second terminal device is also encoded to obtain a unique string. The security and stability of the two-way identity authentication are ensured based on the uniqueness of the encoding result.
[0152] The following will be combined Figure 10 To specifically describe some or all steps of any two-way identity authentication method described in the two-way identity authentication method embodiment. Figure 10As shown, Figure 10 This is a schematic diagram of the device interaction flow of a two-way identity authentication method provided in an embodiment of the present application.
[0153] S1001: The second terminal device sends a hotspot connection request to the first terminal device.
[0154] Specifically, the second terminal device sends a hotspot connection request to the first terminal device, wherein the hotspot connection request includes the first identity authentication information of the second terminal device.
[0155] S1002: Receive user information corresponding to the second terminal device sent by the server.
[0156] Specifically, after being activated by the user's second identity authentication information, the first terminal device sends a query instruction to the server, wherein the query instruction includes the second identity authentication information.
[0157] S1003: The server receives a query instruction sent by the first terminal device.
[0158] Specifically, the server receives a query instruction including the second identity authentication information and performs information query.
[0159] S1004: The server responds to the query instruction sent by the first terminal device.
[0160] S1005: The server determines user information corresponding to the first identity authentication information.
[0161] Specifically, the server retrieves the corresponding user information from the database according to the query instruction.
[0162] S1006: The server feeds back the user information to the first terminal device.
[0163] S1007, the first terminal device determines the hotspot password based on the first identity authentication information of the second terminal device, and starts the hotspot.
[0164] Specifically, the server sends user information corresponding to the second terminal device to the first terminal device, wherein the user information includes first identity authentication information. The first terminal device determines the hotspot password based on the first identity authentication information and then activates the hotspot.
[0165] S1008: The first terminal device performs identity authentication on the second terminal device in response to the hotspot connection request of the second terminal device, and obtains an authentication result.
[0166] S1009: The first terminal device feeds back the authentication result to the server, so that the server can determine the status information of the user corresponding to the first terminal device.
[0167] S1010: The server receives the authentication result fed back by the first terminal device.
[0168] The authentication result is used to indicate whether the authentication of the second terminal device is successful.
[0169] Specifically, no matter whether the verification result of the first terminal device for the hotspot connection request of the second terminal device is authentication success or authentication failure, the authentication result will be fed back to the server.
[0170] S1011. The server updates the status information of the user corresponding to the first terminal device according to the authentication result.
[0171] Specifically, the server updates the current user status information based on the current authentication result. If the current connection between the first terminal device and the second terminal device is successful, the default interface of the second terminal device will display: "Congratulations, connection successful. Please go to the school to pick up the student in the picture." along with the name and photo of the person picking up the student. The user of the second terminal device can follow the prompt to pick up the person in the picture. If the current hotspot connection request of the second terminal device fails to authenticate, the second terminal device will receive a prompt message as shown in the figure: "Your current connection request failed!" Furthermore, it will prompt: "The reason for the current authentication failure may be: The current authentication information is incorrect. Please re-authenticate." If the person picking up the student again enters their personal authentication information, the first terminal device will authenticate the hotspot connection request again, and if it still fails, the prompt message will be: "If the current authentication still fails, please confirm whether your identity information is registered." It should be noted that a student may have multiple persons picking up the student, such as parents, grandparents, or a babysitter. However, it is possible that the campus server only stores the parents' authentication information, while the personal information of the other persons picking up the student is not recorded.
[0172] Furthermore, if the current verification failure is caused by none of the above circumstances, the management platform will give a prompt message: "If it is not the above reasons, please contact the school administrator."
[0173] To better understand the above Figure 10 The device interaction process described below will be specifically combined with Figure 11 To expand the description. Figure 11 As shown, Figure 11 This is a schematic diagram of the interactive execution flow of three devices in a two-way identity authentication method provided in an embodiment of the present application.
[0174] S1101. Press the second fingerprint.
[0175] Specifically, when students are ready to leave school after school, they first press the second fingerprint on the APP on the first terminal device to activate the first terminal device (the APP design process Figure 9 APP 90 described, student fingerprints and devices are mapped one to one);
[0176] S1102. Automatically turn on Wi-Fi to connect to the campus AP.
[0177] Specifically, when the first terminal device is activated, it automatically turns on Wi-Fi and connects to the campus AP (the prerequisite for automatically connecting to the campus network is that it only needs to be connected once before, and it will be saved. Subsequently, you only need to turn on Wi-Fi and walk into the coverage area of the campus network to achieve automatic connection).
[0178] Furthermore, after connecting to the campus network, the first terminal device can upload the student's fingerprint to the school's server, and then search and return the student's personal information and the corresponding personal information of the pick-up person in the school's database (for example, if the pick-up person is the parent, the specific information includes the parent's fingerprint, photo, mobile phone number, ID number and other personal information).
[0179] At the same time, if the current connection to the campus AP fails, the campus AP will also feedback the corresponding connection result to the first terminal device. Therefore, in the campus AP, the networking status of the first terminal device can be: connected to the network, connection failed, etc.
[0180] Furthermore, the school server can also update the student's status, such as not leaving school, in the process of leaving school, or having left school.
[0181] S1103. Return the query result.
[0182] First, when the first terminal device connects to the campus AP, it first determines whether the connection is established. After the campus AP returns the connection result as successful, the first terminal device sends a request to query the pick-up person to the campus AP, and determines whether the corresponding pick-up person information is found.
[0183] Furthermore, after the first terminal device receives the pick-up person information returned by the school, it processes the identification information of the pick-up person. The specific processing flow is as follows: Figure 9 The contents of the overall framework 91 are described.
[0184] Taking fingerprints as an example, the fingerprint of the pick-up person is encoded into a unique string according to the algorithm. After the fingerprint is calculated by the algorithm, the string String-pw is obtained. This String-pw is fixed. Every time the same fingerprint is calculated by the algorithm, the string obtained is the same String-pw.
[0185] S1104. Obtain the encoded string; set the SSID to student and the password to string-pw; and open the hotspot.
[0186] Specifically, the first terminal device uses the obtained string String-pw as the password, and the SSID can be set to the default, such as SSID Student (it is known that the second terminal device that picks up the person will also install the same APP, which will connect to the SSID by default), and the Security, Channel and other information use the default values.
[0187] At this time, the hotspot connection request sent by the pick-up person through the second terminal device is received. Specifically, the pick-up person presses his fingerprint on the APP corresponding to the second terminal device (the APP is the same APP as the APP in step 1, as shown above). Figure 9 After the setting is completed, the hotspot of the first terminal device is automatically turned on based on the user type, such as a student. After the hotspot of the first terminal device is turned on, a blue icon may be displayed on the interface to indicate that the hotspot is turned on.
[0188] Furthermore, the first terminal device sends a message to the campus server that the hotspot has been turned on, and the campus server can update the student's status to waiting for parent pick-up.
[0189] If the current first terminal device fails to connect to the campus AP, the authentication fails, and the interface displays the words "Authentication Failed" in red, or a sound prompt is emitted; the first terminal device will also have a similar authentication result display.
[0190] S1105 , using the encoded string as a query request password; automatically turning on Wi-Fi; scanning and connecting to a network with an SSID of student and a password of string-pw.
[0191] The specific process is as follows: first, the fingerprint of the pick-up person is encoded to obtain String-pw; then, based on the user type being the pick-up person, the Wi-Fi is automatically turned on, and the hotspot with SSID "Student" and password "String-pw" is scanned and connected.
[0192] Furthermore, the second terminal device determines whether it is connected to the hotspot of the first terminal device. If the received return connection result is a successful connection, the APP of the second terminal device will display a green "Authentication Passed" and display the corresponding student avatar and other information.
[0193] If the result of the connection is that the connection fails, the current result will be fed back to the campus server.
[0194] It can be seen that the embodiment of the present application discloses a method and related apparatus for two-way identity authentication, the method comprising: receiving user information corresponding to a second terminal device sent by a server; determining the hotspot password and starting the hotspot based on the first identity authentication information of the second terminal device; performing identity authentication on the second terminal device in response to a hotspot connection request from the second terminal device to obtain an authentication result; feeding back the authentication result to the server for the server to determine the status information of the user corresponding to the first terminal device. In this way, through the method proposed in the embodiment of the present application, the function of two-way identity authentication can be realized based on the identity authentication information, thereby improving the security of the system and the speed of identity authentication. At the same time, it is also possible to track the current status of the object being used to ensure the safety of the user.
[0195] The above mainly introduces the solution of the embodiment of the present application from the perspective of the execution process of the method side. It is understandable that, in order to realize the above functions, the electronic device includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiment provided herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0196] The embodiment of the present application can divide the functional units of the electronic device according to the above method example. For example, each functional unit can be divided according to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.
[0197] and Figure 2 For details, please refer to Figure 12 , Figure 12 This is a schematic diagram of the structure of a two-way identity authentication device provided in an embodiment of the present application. Figure 12 As shown, the above-mentioned two-way identity authentication device 1200 includes:
[0198] The receiving unit 1201 is configured to receive user information corresponding to a second terminal device sent by a server, where the user information includes first identity authentication information of the second terminal device.
[0199] The setting unit 1202 is configured to determine a hotspot password according to the first identity authentication information of the second terminal device and start the hotspot.
[0200] The feedback unit 1203 is configured to feed back the authentication result to the server, so that the server can determine the status information of the user corresponding to the first terminal device.
[0201] It can be seen that the embodiment of the present application discloses a two-way identity authentication device, which receives the user information of the second terminal device sent by the server through the receiving unit, and the setting unit encodes the first identity information in the user information, uses the encoding result as the hotspot password, and starts the hotspot. The second terminal device requests to connect to the hotspot of the first terminal device. Regardless of the current authentication result, the feedback unit will feedback to the server for the server to determine the status information of the user corresponding to the first terminal device. In this way, the device proposed in the embodiment of the present application can realize the function of two-way identity authentication based on the identity authentication information based on the collaboration of each unit, thereby improving the security of the system and the speed of identity authentication. At the same time, it can also track the current status of the object being used to ensure the safety of the user.
[0202] In a possible example, the data receiving unit 1201 specifically performs the following steps:
[0203] Receive user information corresponding to the second terminal device sent by the server, where the user information includes first identity authentication information of the second terminal device.
[0204] The steps specifically performed by the setting unit 1202 are as follows:
[0205] Determine the hotspot password based on the first identity authentication information of the second terminal device, and activate the hotspot;
[0206] In response to the hotspot connection request of the second terminal device, identity authentication is performed on the second terminal device to obtain an authentication result.
[0207] In a possible example, before determining the hotspot password according to the first identity authentication information of the second terminal device, the setting unit 1202 specifically performs the following steps:
[0208] connecting to the server in response to an activation success instruction for the target application, wherein the activation success instruction includes second identity authentication information;
[0209] After successfully connecting to the server, a query instruction is sent to the server, wherein the query instruction includes the second identity authentication information.
[0210] In a possible example, the hotspot connection request includes an encoding result of the third identity authentication information of the second terminal device;
[0211] The steps of performing identity authentication on the second terminal device by the setting unit 1202 are as follows:
[0212] If the encoding result of the third identity authentication information is consistent with the hotspot password, it is determined that the second terminal device is successfully authenticated;
[0213] If the encoding result of the third identity authentication information is inconsistent with the hotspot password, it is determined that the authentication of the second terminal device has failed.
[0214] In a possible example, the first identity authentication information includes fingerprint information, and the hotspot password is determined based on the first identity authentication information of the second terminal device. The setting unit 1202 specifically performs the following steps:
[0215] Encode the fingerprint information according to a preset method to obtain a password string;
[0216] Determining a user identity corresponding to the first terminal device;
[0217] After the user identity meets the preset identity, the hotspot password is generated according to the password character string.
[0218] In a possible example, after performing identity authentication on the second terminal device, the setting unit 1202 specifically performs the following steps:
[0219] After the user identity satisfies a preset identity, a prompting method corresponding to the authentication result is determined, wherein the prompting method is used to prompt the user corresponding to the first terminal device of the authentication result of the second terminal device.
[0220] The feedback unit 1203 is specifically configured to feed back the authentication result to the server, so that the server can determine the status information of the user corresponding to the first terminal device.
[0221] As can be seen, the electronic device described in the embodiment of this application can obtain the required information by sending a query command to the server through the first terminal device, and set a unique string password based on the obtained information to ensure the security of the current electronic device. At the same time, it can also promptly feedback the authentication results to the server to ensure that the server can promptly monitor the current user's status information.
[0222] and Figure 2 For details, please refer to Figure 13 , Figure 13This is a schematic diagram of the structure of another bidirectional identity authentication device provided in an embodiment of the present application. Figure 13 As shown, applied to the server, such as Figure 13 The illustrated two-way identity authentication apparatus 1300 includes:
[0223] The receiving unit 1301 is configured to receive a query instruction sent by a first terminal device and receive an authentication result fed back by the first terminal device;
[0224] A determining unit 1302 is configured to determine user information corresponding to the query instruction;
[0225] The feedback unit 1303 is configured to feed back the user information to the first terminal device;
[0226] The status updating unit 1304 is configured to update the status information of the user corresponding to the first terminal device according to the authentication result.
[0227] In a possible example, the receiving unit 1301 specifically performs the following steps:
[0228] receiving a query instruction sent by the first terminal device;
[0229] Receive the authentication result fed back by the first terminal device.
[0230] In a possible example, after receiving the query instruction sent by the first terminal device, the determining unit 1302 specifically performs the following steps:
[0231] Determine user information corresponding to the query instruction.
[0232] In a possible example, after determining the user information corresponding to the query instruction, the feedback unit 1303 specifically performs the following steps:
[0233] Feedback the user information to the first terminal device.
[0234] In a possible example, after receiving the authentication result fed back by the first terminal device, the status updating unit 1304 specifically performs the following steps:
[0235] According to the authentication result, the status information of the user corresponding to the first terminal device is updated.
[0236] It can be seen that the embodiment of the present application discloses a two-way identity authentication device, which receives the query instruction sent by the first terminal device through the receiving unit, promptly determines the information required by the first terminal device through the determining unit, and returns the query result to the first terminal device through the feedback unit, so that the first terminal device can encode the first identity authentication information in the query result, and then use the encoded result as the hotspot password and start the hotspot. Regardless of the current authentication result, the receiving unit will transmit the information fed back by the first terminal device to the status update unit for the server to determine the status information of the user corresponding to the first terminal device. In this way, the device proposed in the embodiment of the present application can realize the function of two-way identity authentication based on the identity authentication information based on the collaboration of each unit, thereby improving the security of the system and the speed of identity authentication. At the same time, it can also track the current status of the object being used to ensure the safety of the user.
[0237] With the above Figure 2 For details on the embodiment shown, please refer to Figure 14 , Figure 14 is a structural diagram of an electronic device provided in an embodiment of the present application, such as Figure 11 As shown, the electronic device includes a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor.
[0238] In a possible example, if the electronic device includes a first terminal device, the one or more programs include instructions for executing the following steps:
[0239] Receive user information corresponding to the second terminal device sent by the server, where the user information includes first identity authentication information of the second terminal device.
[0240] Determine the hotspot password based on the first identity authentication information of the second terminal device, and activate the hotspot;
[0241] In response to the hotspot connection request of the second terminal device, performing identity authentication on the second terminal device to obtain an authentication result;
[0242] The authentication result is fed back to the server so that the server can determine the status information of the user corresponding to the first terminal device.
[0243] It can be seen that the electronic device described in the embodiment of the present application can receive the user information corresponding to the second terminal device sent by the server; determine the hotspot password and start the hotspot based on the first identity authentication information of the second terminal device; respond to the hotspot connection request of the second terminal device, authenticate the second terminal device and obtain an authentication result; and feed the authentication result back to the server so that the server can determine the status information of the user corresponding to the first terminal device. In this way, the method proposed in the embodiment of the present application can realize the function of two-way identity authentication based on the identity authentication information, thereby improving the security of the system and the speed of identity authentication. At the same time, it can also track the current status of the object being used to ensure the safety of the user.
[0244] In one possible example, the program includes instructions for executing the following steps:
[0245] Receive user information corresponding to the second terminal device sent by the server, where the user information includes first identity authentication information of the second terminal device.
[0246] Determine the hotspot password based on the first identity authentication information of the second terminal device, and activate the hotspot;
[0247] In response to the hotspot connection request of the second terminal device, performing identity authentication on the second terminal device to obtain an authentication result;
[0248] The authentication result is fed back to the server so that the server can determine the status information of the user corresponding to the first terminal device.
[0249] In one possible example, before determining the hotspot password based on the first identity authentication information of the second terminal device, the program includes instructions for performing the following steps:
[0250] connecting to the server in response to an activation success instruction for the target application, wherein the activation success instruction includes second identity authentication information;
[0251] After successfully connecting to the server, a query instruction is sent to the server, wherein the query instruction includes the second identity authentication information.
[0252] In one possible example, the hotspot connection request includes an encoding result of the third identity authentication information of the second terminal device; and the identity authentication of the second terminal device is performed, and the program includes instructions for executing the following steps:
[0253] If the encoding result of the third identity authentication information is consistent with the hotspot password, it is determined that the second terminal device is successfully authenticated;
[0254] If the encoding result of the third identity authentication information is inconsistent with the hotspot password, it is determined that the authentication of the second terminal device has failed.
[0255] In one possible example, the first identity authentication information includes fingerprint information, and the hotspot password is determined based on the first identity authentication information of the second terminal device. The program includes instructions for performing the following steps:
[0256] Encode the fingerprint information according to a preset method to obtain a password string;
[0257] Determining a user identity corresponding to the first terminal device;
[0258] After the user identity meets the preset identity, the hotspot password is generated according to the password character string.
[0259] In a possible example, after authenticating the second terminal device, the program includes instructions for executing the following steps:
[0260] After the user identity satisfies a preset identity, a prompting method corresponding to the authentication result is determined, wherein the prompting method is used to prompt the user corresponding to the first terminal device of the authentication result of the second terminal device.
[0261] In a possible example, after authenticating the second terminal device, the program includes instructions for executing the following steps:
[0262] receiving a query instruction sent by the first terminal device;
[0263] Determining user information corresponding to the query instruction;
[0264] Feedback the user information to the first terminal device;
[0265] receiving an authentication result fed back by the first terminal device;
[0266] According to the authentication result, the status information of the user corresponding to the first terminal device is updated.
[0267] In one possible example, the status information includes: a status of being in the process of leaving school and a status of having left school; and the updating of the status information of the user corresponding to the first terminal device includes instructions for executing the following steps:
[0268] If the authentication result is successful, updating the status information to the status of having left school;
[0269] If the authentication result is authentication failure, the status information is updated to the status of processing departure.
[0270] An embodiment of the present application provides a computer-readable storage medium, which stores a computer program for electronic data exchange. The computer program includes execution instructions, and the execution instructions are used to execute part or all of the steps of any two-way identity authentication method described in the above-mentioned two-way identity authentication method embodiment. The above-mentioned computer includes an electronic terminal device.
[0271] An embodiment of the present application provides a computer program product, wherein the computer program product includes a computer program, and the computer program is operable to enable a computer to perform part or all of the steps of any two-way identity authentication method recorded in the above method embodiments. The computer program product can be a software installation package.
[0272] It should be noted that for any of the aforementioned embodiments of the two-way identity authentication method, for the sake of simplicity, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by this application.
[0273] The above is a detailed introduction to the embodiments of the present application. Specific examples are used in this article to illustrate the principles and implementation methods of a two-way identity authentication method and related devices of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, based on the idea of a two-way identity authentication method and related devices of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
[0274] The present application is described with reference to the flowcharts and / or block diagrams of the methods, hardware products, and computer program products of the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0275] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, such that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device that implements the functions specified in one or more flow charts and / or one or more blocks in the block diagrams. Memory may include a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0276] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality of components or steps. The fact that certain measures are recited in different dependent claims does not mean that these measures cannot be combined to produce good results.
[0277] A person skilled in the art can understand that all or part of the steps in the various methods of any of the above-mentioned embodiments of the two-way identity authentication method can be completed by instructing the relevant hardware through a program, and the program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (English: Read-Only Memory, abbreviated as: ROM), a random access memory (English: Random Access Memory, abbreviated as: RAM), a disk or an optical disk, etc.
[0278] It can be understood that any product that is controlled or configured to execute the processing method of the flowchart described in an embodiment of a two-way identity authentication method of the present application, such as the device and computer program product in the above flowchart, falls within the scope of the related products described in this application.
[0279] Obviously, those skilled in the art may make various modifications and variations to the bidirectional identity authentication method and apparatus provided herein without departing from the spirit and scope of this application. Thus, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A two-way identity authentication method, applied to a first terminal device, characterized in that: Methods include: Searching a database of a server for user information of a second terminal device associated with the first terminal device according to the identity authentication information of the first terminal device, wherein the user information includes the first identity authentication information of the second terminal device; Determine the hotspot password based on the first identity authentication information of the second terminal device, and activate the hotspot; In response to the hotspot connection request of the second terminal device, performing identity authentication on the second terminal device to obtain an authentication result; The authentication result is fed back to the server so that the server can determine the status information of the user corresponding to the first terminal device.
2. The method according to claim 1, characterized in that Before determining the hotspot password according to the first identity authentication information of the second terminal device, the method further includes: In response to an activation success instruction for the target application, connecting to the server; After successfully connecting to the server, a query instruction is sent to the server, wherein the query instruction includes the second identity authentication information.
3. The method according to claim 1 or 2, characterized in that The hotspot connection request includes an encoding result of the third identity authentication information of the second terminal device; The performing identity authentication on the second terminal device includes: If the encoding result of the third identity authentication information is consistent with the hotspot password, it is determined that the second terminal device is successfully authenticated; If the encoding result of the third identity authentication information is inconsistent with the hotspot password, it is determined that the authentication of the second terminal device has failed.
4. The method according to claim 3, characterized in that The first identity authentication information includes fingerprint information, and determining the hotspot password based on the first identity authentication information of the second terminal device includes: Encode the fingerprint information according to a preset method to obtain a password string; Determining a user identity corresponding to the first terminal device; After the user identity meets the preset identity, the hotspot password is generated according to the password character string.
5. The method according to claim 4, characterized in that After performing identity authentication on the second terminal device, the method further includes: After the user identity meets the preset identity, a prompting method corresponding to the authentication result is determined, wherein the prompting method is used to prompt the user corresponding to the first terminal device of the authentication result of the second terminal device.
6. A method for two-way identity authentication, characterized in that: Applied to the server, the methods include: receiving a query instruction sent by the first terminal device; Determine user information corresponding to the query instruction, the user information including first identity authentication information of a second terminal device associated with the first terminal device, the first identity authentication information being used by the first terminal device to determine a hotspot password and activate the hotspot; Feedback the user information to the first terminal device; receiving an authentication result fed back by the first terminal device, where the authentication result is obtained by the first terminal device performing identity authentication on the second terminal device in response to the hotspot connection request of the second terminal device; According to the authentication result, the status information of the user corresponding to the first terminal device is updated.
7. The method according to claim 6, characterized in that The status information includes: the status of being in the process of leaving school and the status of having left school; The updating of the status information of the user corresponding to the first terminal device includes: If the authentication result is successful, updating the status information to the status of having left school; If the authentication result is authentication failure, the status information is updated to the status of being in the process of leaving school.
8. A two-way identity authentication device, characterized in that: Applied to a first terminal device, the apparatus includes: a receiving unit, configured to receive user information of a second terminal device associated with the first terminal device, the user information being obtained by the first terminal device through searching in a database of a server based on the identity authentication information of the first terminal device, the user information including the first identity authentication information of the second terminal device; A setting unit, configured to determine a hotspot password based on the first identity authentication information of the second terminal device and activate the hotspot; A feedback unit is used to respond to the hotspot connection request of the second terminal device, perform identity authentication on the second terminal device, obtain an authentication result, and feed back the authentication result to the server so that the server can determine the status information of the user corresponding to the first terminal device.
9. An electronic device, characterized in that: The method comprises a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the programs include instructions for executing the steps in the method according to any one of claims 1 to 5 or 6 to 7.
10. A computer-readable storage medium, characterized in that A computer program for electronic data exchange is stored, wherein the computer program enables a computer to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Certificate managing method and device
CN106888087A