Visitor identity verification method and system

Through the encrypted transmission mechanism of dynamic verification codes and negotiated keys, the problems of identity information leakage and low efficiency in visitor identity review are solved, and safe and efficient visitor identity review is achieved.

CN114218542BActive Publication Date: 2025-10-21CHINA CONSTRUCTION BANK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111547818.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-10-21
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

While existing visitor identity verification methods improve security performance, they also pose the risk of identity information leakage. Visitor information review wastes manpower and time, resulting in low access efficiency.

Method used

An encrypted transmission mechanism of dynamic verification codes and negotiated keys is adopted. The visitor and the visited party negotiate the key to generate and decrypt the dynamic verification code, and the visited party performs identity verification to generate a pass.

Benefits of technology

It improves the security performance of visitor identity verification, avoids identity information leakage, reduces manpower waste, and improves access efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114218542B_ABST
    Figure CN114218542B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a visitor identity auditing method and system. The method comprises: based on the access request of the visitor terminal obtained, after receiving the dynamic verification code generation trigger signal, generating the corresponding dynamic verification code, and sending the encrypted dynamic verification code to the visitor terminal; recycling the feedback information of the visitor terminal; wherein the feedback information includes the dynamic verification code returned by the visitor terminal and the corresponding visitor information; based on the feedback information, the visitor identity is audited; if the visitor identity audit is passed, the access credential is sent to the corresponding visitor. The present application improves the data transmission security performance of the visitor identity online auditing method, thereby avoiding the risk of identity information leakage of the visited person.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of identity authentication technology, and specifically to a visitor identity verification method, a visitee-side device, a visitor-side device, and a visitor identity verification system. Background Art

[0002] In financial institutions, government agencies, and important office buildings, outside visitors often need to access someone. Because security management is crucial in these settings, without proper identity control, unauthorized intrusion by unauthorized individuals can negatively impact support efficiency and easily lead to the leakage of commercial secrets. While visitor identity verification significantly improves visitor management security, reviewing visitor information wastes significant manpower and time, resulting in low access efficiency.

[0003] The main steps of the existing automatic visitor management method are: first, the visitor submits his or her identity information and access target information, and then sends the information to the visited party. The visited party uses the information received on his or her own visited party to verify the visitor's identity. After the review is passed, he or she clicks the allow access instruction. Based on the run access instruction, a pass is sent to the visitor, and the visitor accesses the gate based on the pass. This method improves the efficiency of visitor identity verification, but there is also a risk of identity information leakage. During the application process, once the visitor's user information is obtained by a third party, the third party can initiate an access request based on the visitor's user information. Based on the initiated access request, the identity information of any visitor in the system can be read, resulting in the leakage of the visitor's information. Even if the identity information of other visitors is not leaked, the information of the current visitor may still be intercepted in the access application and leaked.

[0004] In order to solve the security loopholes in the existing automatic visitor identity verification method, a new visitor identity verification method needs to be created. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a visitor identity verification method, a visited person-side device, a visitor-side device, and a system.

[0006] In order to achieve the above-mentioned purpose, the first aspect of the present application provides a visitor identity review method, which is executed by the visited party, including: based on the access request obtained from the visitor party, after receiving the trigger signal for generating a dynamic verification code, generating a corresponding dynamic verification code; in response to the negotiation key request initiated by the visitor party, negotiating a key with the corresponding visitor party, and encrypting the dynamic verification code based on the negotiated key; sending the encrypted dynamic verification code to the visitor party; recovering the feedback information from the visitor party; wherein, the feedback information includes the dynamic verification code returned by the visitor party and the corresponding visitor information; performing visitor identity review based on the feedback information; if the visitor identity review is passed, sending a pass to the corresponding visitor.

[0007] In an embodiment of the present application, the method further includes: obtaining an access request initiated by a visitor terminal through a preset port; wherein the preset port is a selected port of the visitee, and each preset port corresponds to a visitee; wherein the preset port only contains a mapping relationship of the visitee terminal connection and is not bound to the visitee's identity information; the visitee terminal receives the access request initiated by the visitor terminal through the corresponding preset port; determines that the access request initiated by the visitor terminal is obtained, and outputs a reminder message.

[0008] In an embodiment of the present application, the reminder information stops being output after the corresponding dynamic verification code is generated; the method also includes: if the trigger signal for generating the dynamic verification code is not received after a preset reminder time, a request failure signal is output, and the request failure signal is sent to the visitor end.

[0009] In the embodiment of the present application, the dynamic verification code is unique and time-sensitive.

[0010] In an embodiment of the present application, the visitor identity review based on the feedback information includes: determining whether the dynamic verification code recovered from the visitor end is the dynamic verification code issued to the visitor end; if not, outputting the review failure information; if so, displaying the visitor information recovered from the visitor end on the visited end, and opening the review success / failure trigger option; based on the option triggered by the visited end, recovering the visitor end review success / failure trigger signal, and sending the visitor end review success / failure signal.

[0011] The second aspect of the present application provides a visitor identity verification method, which is executed by the visitor end, including: initiating an access request and recovering the encrypted dynamic verification code fed back by the visited end; decrypting the encrypted dynamic verification code based on a preset negotiated key to obtain the dynamic verification code; opening the dynamic code input function, and in response to a dynamic verification code input completion trigger signal, opening the visitor information input function; recovering and sending the input dynamic verification code and visitor information to the visited end; and recovering the pass issued by the visited end in response to a successful review signal from the visited end.

[0012] In an embodiment of the present application, the method also includes: obtaining the preset negotiation key, including: determining whether the current visitor is a historical visitor, if the current visitor is a historical visitor, extracting the historical negotiation key as the preset negotiation key to decrypt the dynamic verification code; if the current visitor is a new visitor, based on the request initiated by the visited end to negotiate a key with the visitor end, generating the same negotiation key simultaneously with the visited end, and decrypting the dynamic verification code based on the negotiation key.

[0013] In an embodiment of the present application, the method further includes: after receiving a request initiated by the visited end to conduct key negotiation with the visitor end, determining whether the key negotiation communication path is the communication path for initiating the access request, and stopping the key negotiation if it is determined that the key negotiation communication path is different from the communication path for initiating the access request.

[0014] In the embodiment of the present application, the visitor identity information includes at least basic identity information and brief information about the purpose of the visit.

[0015] The third aspect of the present application provides a visited-side device, including: a dynamic verification code generation module, which is used to generate a corresponding dynamic verification code based on the access request obtained from the visitor side after receiving a trigger signal for generating a dynamic verification code; an encryption module, which is used to perform key negotiation with the corresponding visitor side in response to a negotiation key request initiated by the visitor side, and encrypt the dynamic verification code based on the negotiated key; a communication module, which is used to send the encrypted dynamic verification code to the visitor side and recover feedback information from the visitor side; wherein the feedback information includes the dynamic verification code returned by the visitor side and the corresponding visitor information; a processing module, which is used to perform visitor identity review based on the feedback information; and the communication module is also used to send a pass to the corresponding visitor after the processing module confirms that the visitor identity review has passed.

[0016] The fourth aspect of the present application provides a visitor-end device, including: a communication module for initiating an access request and recovering an encrypted dynamic verification code fed back by the visited end; a decryption module for decrypting the encrypted dynamic verification code based on a preset negotiated key to obtain the dynamic verification code; an acquisition module for opening a dynamic code input function and, in response to a dynamic verification code input completion trigger signal, opening a visitor information input function; recovering and sending the input dynamic verification code and visitor information to the visited end; the communication module is also used to recover the pass issued by the visited end in response to a successful review signal from the visited end.

[0017] A fifth aspect of the present application provides a visitor identity verification system, which includes the above-mentioned visitor-side device and visitor-side device.

[0018] In a sixth aspect, the present application provides a machine-readable storage medium having instructions stored thereon. When the instructions are executed by a processor, the processor is configured to execute the above-mentioned visitor identity verification method.

[0019] In a seventh aspect, the present application provides a computer program product, comprising a computer program, which implements the above-mentioned visitor identity verification method when executed by a processor.

[0020] With this technical solution, a visitor needs to obtain consent from the person being visited after initiating a visit. Upon consent, a dynamic verification code is issued, which the visitor uses to initiate detailed access. The dynamic verification code is encrypted before transmission, ensuring the secure transmission of access credentials and preventing third-party interception and potential leakage of user information, thus improving the security of the visitor identity verification process.

[0021] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the following detailed description, they are used to explain the embodiments of the present application but do not constitute a limitation on the embodiments of the present application. In the accompanying drawings:

[0023] Figure 1 A flowchart schematically illustrates the steps of a visitor identity verification method according to an embodiment of the present application;

[0024] Figure 2 The following schematically shows a structural diagram of a device on the visitor's side according to an embodiment of the present application;

[0025] Figure 3 The structure diagram of the visitor terminal device according to the embodiment of the present application is schematically shown;

[0026] Figure 4 The internal structure diagram of a computer device according to an embodiment of the present application is schematically shown. DETAILED DESCRIPTION

[0027] To make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the specific implementation methods described herein are only used to illustrate and explain the embodiments of the present application and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0028] It should be noted that if the embodiments of the present application involve directional indications (such as up, down, left, right, front, back, etc.), the directional indications are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.

[0029] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the fact that they can be implemented by ordinary technicians in this field. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0030] The visitor identity verification method provided in this application can be applied to visitor identity management applications in environments with strict security regulations. In financial institutions, government agencies, and important office buildings, situations often arise where outside visitors need to access someone. Because security management levels are high in these scenarios, without proper personnel identity control, unauthorized outsiders can arbitrarily intrude, impacting support efficiency and easily leaking commercial secrets. While visitor identity verification significantly improves visitor management security, reviewing visitor information wastes significant manpower and time, resulting in low access efficiency. Existing automated visitor management methods primarily involve the following steps: First, the visitor submits their identity information and access target information, which is then sent to the visitee's terminal. The visitee then uses their terminal to verify the visitor's identity based on the received information. After the verification is passed, they click on the "Allow Access" command. Based on the access command, a pass is sent to the visitor, and the visitor then accesses the gate using the pass. This method improves visitor identity verification efficiency, but also carries the risk of identity information leakage. During the application process, if a visitor's user information is obtained by a third party, the third party can initiate an access request based on the visitor's user information. The access request initiated based on this can read the identity information of any visitor in the system, resulting in the leakage of the visitor's information. Even if the identity information of other visitors is not leaked, the information of the current visitor may still be intercepted during the access request and leaked.

[0031] Figure 1 The following schematically shows a flow chart of a visitor identity verification method according to an embodiment of the present application. Figure 1As shown, in one embodiment of the present application, a visitor identity verification method is provided, comprising the following steps:

[0032] Step S10: The visitor initiates an access request.

[0033] Specifically, during an actual visit, whether out of custom or business courtesy, the visitor and the person being visited will establish contact beforehand, and then the visit will take place at the agreed time. The visitor arrives at the person's location during the agreed time period and selects the person they wish to follow up with through a pre-set interface on the visitor's client. This pre-set interface only corresponds to the person being visited and does not include their personal information. Therefore, even if the pre-set interface is clicked, the person's information will not be leaked. After the visitor selects the person being visited, the visitor's communication module sends the requested access request to the person being visited.

[0034] Step S20: The visited party generates a corresponding dynamic verification code based on the visitor's access request after receiving a trigger signal for generating a dynamic verification code, and encrypts the dynamic verification code and sends it to the visitor.

[0035] Specifically, the preset port has a unique communication path, the target end of which is the visitor's device. Upon receiving the visitor's request, the visitor's device triggers a reminder message. Preferably, the reminder message includes a device ringtone and vibration, thereby increasing the probability that the visitor will receive the reminder message. After receiving the reminder message, the visitor decides whether to accept the visit based on their convenience and willingness. If they do not accept the visit, they directly click the "Reject Access" command. The reminder message stops, and a rejection signal is fed back to the visitor's device, which is also displayed on the visitor's device. For example, a reminder message such as "The visitor is not available for access at this time" is displayed on the visitor's device, informing the visitor that access is not available at this time. If the visitor is willing to accept the visit, they click the "Generate Dynamic Verification Code" command. In response to the "Generate Dynamic Verification Code" trigger signal, the visitor generates a dynamic verification code. This dynamic verification code is unique and has a certain timeliness. For example, the dynamic verification code is valid for 3 minutes, and the visitor can only use it to initiate specific access requests within 3 minutes. This prevents visitors from repeatedly initiating access requests based on the dynamic verification code after obtaining it. This also prevents third parties from stealing the dynamic verification code and initiating malicious access. By setting a dynamic verification code, the uniqueness of the access path can be guaranteed, preventing access through identity information alone. While ensuring access security, it also provides the user with the right to choose whether to access, thereby improving user satisfaction.

[0036] In one embodiment, if the visitee fails to receive the reminder message, meaning that the visitee is currently out of the office and unavailable, then even if a dynamic verification code is issued, the visit cannot be successfully completed. Instead, it will pointlessly increase the visitor's subsequent filling steps. To avoid this, preferably, the reminder message has a preset time. If the preset time has passed and the visitee still does not click the "Generate Dynamic Verification Code" instruction, the reminder message will stop outputting and an access failure signal will be output to the visitor terminal. The visitor terminal will display a reminder signal such as "The visitee is currently unavailable for access," informing the visitor that access is currently unavailable.

[0037] Step S30: The visitor terminal decrypts the encrypted dynamic verification code based on the preset negotiated key to obtain the dynamic verification code.

[0038] Specifically, if a third party intercepts the dynamic verification code and has previously learned the visitor's identity information, it can initiate an access request based on the dynamic verification code and the visitor's identity information. Because subsequent interviewees are reviewed based on the dynamic verification code and the visitor's information, there is no guarantee that the visitor is the intended interviewee. To prevent malicious interception of information and malicious access, the dynamic verification code is preferably encrypted before transmission. Even if the dynamic verification code is intercepted, it cannot be directly retrieved, and malicious access requests cannot be initiated.

[0039] In order to ensure that the visitor side has the unique ability to decrypt the encrypted dynamic verification code, the visitor side needs to negotiate a key with the visited side. The key obtained by the negotiation is the negotiation key between the two. The negotiation key is only held by the unique visitor side and the unique visited side. After the visitor side receives the encrypted dynamic verification code, the visitor side initiates a request for key negotiation with the visited side. During the request process, there are two judgment steps. The first is to determine whether the device that currently initiates the key negotiation request is the device that previously initiated the user request, that is, to determine whether the communication path used for the key negotiation is the communication path that previously initiated the access request. If the communication path currently initiating the key negotiation is different from the path that previously initiated the access request, it means that the dynamic verification code has been intercepted by a third party, and a third-party device attempting to negotiate the key has appeared. At this time, the key negotiation is stopped to prevent the dynamic verification code from being obtained by a third party.

[0040] Determine whether the guest terminal involved in the key negotiation is a historical guest terminal. If so, it indicates that the device has been trusted. To reduce the delay caused by key generation, it is preferred to directly extract the historical key for dynamic verification code decryption. If the current guest terminal is a new visitor, a negotiation key is generated simultaneously on the verified guest terminal and the visitee terminal. The guest terminal decrypts the dynamic verification code based on the negotiated key to obtain a complete dynamic verification code.

[0041] Step S40: The visitor terminal enables the dynamic code input function, and in response to the dynamic verification code input completion trigger signal, enables the visitor information input function.

[0042] Specifically, after the visitor obtains the complete dynamic verification code, it is displayed on the visitor side and the dynamic verification code input function is opened. The visitor enters the corresponding dynamic verification code in the dynamic verification code input window. In response to the trigger signal of the dynamic verification code input completion, the visitor side opens the visitor information input function, and the visitor enters his or her identity information and a brief description of the purpose of the visit into the corresponding information input window. For example, the visitor enters his or her name and a brief description of the purpose of the visit (for example, coming here today to discuss contract details). The visitor side collects and recycles the visitor information and transmits this information back to the visitee side.

[0043] Step S50: The visited party performs visitor identity verification based on the feedback information, and sends a pass to the corresponding visitor after the visitor identity verification is passed.

[0044] Specifically, after obtaining the recovered dynamic verification code and visitor information, the visited party first compares the recovered dynamic verification code with the previously issued dynamic verification code to see if they are the same. If the two do not match, it is determined that someone has initiated a malicious visit, and the access failure instruction is directly output to the visitor side. If the two match, the visitor side identity review is completed, and then the visitor's own identity information review is required. The visited party directly displays the recovered user basic information and a brief description of the purpose of the visit. The visited party makes a subjective judgment based on this information to determine whether the visitor information is the visitor information agreed with him / her. If the visitor information review is passed, the visited party triggers a signal of successful review. Based on the successful review trigger signal, the visited party issues a pass to the visitor side. The visitor proves his / her identity based on the pass and starts subsequent visits.

[0045] In one embodiment, because there is a certain time interval between generating a dynamic verification code and recovering the verification code, in order to avoid the visitee having to stare at the visitee terminal and wait for the recovered information, preferably, after completing the visitor information collection and recovery, the visitee terminal outputs a reminder message again to inform the visitor to conduct a visitor identity review, thereby improving the visitor's satisfaction with the use.

[0046] like Figure 2, an embodiment of the present application provides a visited person-side device for executing the visitor identity review method described above, the visited person-side device includes a dynamic verification code generation module for generating a corresponding dynamic verification code based on an access request obtained from the visitor side after receiving a trigger signal for generating a dynamic verification code; an encryption module for encrypting the dynamic verification code; a communication module for sending the encrypted dynamic verification code to the visitor side and recovering feedback information from the visitor side; wherein the feedback information includes the dynamic verification code returned by the visitor side and the corresponding visitor information; a processing module for performing visitor identity review based on the feedback information; the communication module is also used to send a pass to the corresponding visitor after the processing module confirms that the visitor identity review has passed.

[0047] like Figure 3 , an embodiment of the present application provides a visitor-end device for executing the above-mentioned visitor identity verification method, the visitor-end device including: a communication module for initiating an access request and recovering the encrypted dynamic verification code fed back by the visited end; a decryption module for decrypting the encrypted dynamic verification code based on a preset negotiated key to obtain the dynamic verification code; an acquisition module for opening a dynamic code input function, and opening a visitor information input function in response to a dynamic verification code input completion trigger signal; recovering and sending the input dynamic verification code and visitor information to the visited end; the communication module is also used to recover the pass issued by the visited end in response to a successful review signal from the visited end.

[0048] The processor includes a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be set, and the visitor identity verification method can be implemented by adjusting the kernel parameters.

[0049] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0050] An embodiment of the present application provides a storage medium on which a program is stored. When the program is executed by a processor, the above-mentioned visitor identity verification method is implemented.

[0051] In one embodiment, a computer device is provided. The computer device can be a visitor-side device or a visitee-side device. The internal structure diagram thereof can be as follows: Figure 4As shown. The computer device includes a processor A01, a network interface A02, a display screen A04, an input device A05 and a memory (not shown in the figure) connected via a system bus. Among them, the processor A01 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes an internal memory A03 and a non-volatile storage medium A06. The non-volatile storage medium A06 stores an operating system B01 and a computer program B02. The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A06. The network interface A02 of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor A01, a visitor identity verification method is implemented. The display screen A04 of the computer device can be a liquid crystal display or an electronic ink display, and the input device A05 of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse.

[0052] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0053] The present application also provides a computer program product, including a computer program, which implements the above-mentioned visitor identity verification method when executed by a processor.

[0054] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0055] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0056] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0057] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0058] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0059] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0060] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0061] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0062] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A visitor identity verification method, characterized in that: The method is executed by the interviewee, and includes: Based on the access request obtained from the visitor, after receiving the trigger signal for generating a dynamic verification code, a corresponding dynamic verification code is generated; wherein, Obtain access requests initiated by the visitor through the preset port; The preset port is the selected port of the visitee, and each preset port corresponds to one visitee; the visitee receives the access request initiated by the visitor through the corresponding preset port; wherein the preset port only contains the mapping relationship of the visitee connection and is not bound to the visitee's identity information; Determine whether the access request initiated by the visitor is obtained and output a reminder message; In response to the negotiation key request initiated by the guest terminal, a key negotiation is performed with the corresponding guest terminal, and the dynamic verification code is encrypted based on the negotiated key; wherein, Before negotiating a key with the corresponding guest, determine whether the communication path used for the key negotiation request is the same as the communication path used to initiate the previous access request. If the communication path currently used to initiate the key negotiation is different from the path used to initiate the previous access request, terminate the key negotiation. Sending the encrypted dynamic verification code to the visitor terminal; Recovering feedback information from the visitor terminal; wherein the feedback information includes the dynamic verification code returned by the visitor terminal and corresponding visitor information; Perform visitor identity review based on the feedback information; If the visitor's identity is verified, a pass will be sent to the corresponding visitor.

2. The method according to claim 1, characterized in that The reminder information stops being output after the corresponding dynamic verification code is generated; The method further comprises: If the trigger signal for generating a dynamic verification code is not received after the preset reminder time, a request failure signal is output and sent to the visitor terminal.

3. The method according to claim 1, characterized in that The dynamic verification code is unique and time-sensitive.

4. The method according to claim 1, wherein The performing visitor identity verification based on the feedback information includes: Determining whether the dynamic verification code recovered from the visitor terminal is the dynamic verification code issued to the visitor terminal; If not, the audit failure information is output; If yes, the visitor information collected from the visitor terminal is displayed on the visitee terminal, and an audit success / failure trigger option is opened; Based on the option triggered by the interviewee, the trigger signal of the interviewee's audit success / failure is recovered, and the interviewee's audit success / failure signal is sent.

5. A visitor identity verification method, characterized in that: The method is executed by a visitor terminal, and includes: Initiate an access request and receive the encrypted dynamic verification code from the user. Decrypting the encrypted dynamic verification code based on a preset negotiated key to obtain the dynamic verification code; Enable the dynamic code input function, and in response to the dynamic verification code input completion trigger signal, enable the visitor information input function; Recover and send the input dynamic verification code and visitor information to the visitor terminal; wherein, The visited client obtains the access request initiated by the visitor client through the preset port; The preset port is the selected port of the visitee, and each preset port corresponds to one visitee; the visitee receives the access request initiated by the visitor through the corresponding preset port; wherein the preset port only contains the mapping relationship of the visitee connection and is not bound to the visitee's identity information; Determine whether the access request initiated by the visitor is obtained and output a reminder message; The corresponding visitor's terminal is configured as: Before negotiating a key with the corresponding guest, determine whether the communication path used for the key negotiation request is the same as the communication path used to initiate the access request. If the communication path currently used to initiate the key negotiation is different from the path used to initiate the access request, terminate the key negotiation. In response to a signal indicating a successful audit by the visited party, the pass issued by the visited party is recovered.

6. The method according to claim 5, characterized in that The method further comprises: Obtaining the preset negotiated key includes: Determine whether the current visitor is a historical visitor. If the current visitor is a historical visitor, extract the historical negotiation key as the preset negotiation key to decrypt the dynamic verification code; If the current visitor is a new visitor, based on the request initiated by the visited party to negotiate a key with the visitor party, the same negotiation key is generated simultaneously with the visited party, and the dynamic verification code is decrypted based on the negotiation key.

7. The method according to claim 6, characterized in that The method further comprises: After receiving the key negotiation request initiated by the visited terminal with the visitor terminal, it is determined whether the key negotiation communication path is the communication path for initiating the access request, and key negotiation is stopped if it is determined that the key negotiation communication path is different from the communication path for initiating the access request.

8. The method according to claim 7, characterized in that The visitor information includes at least basic identity information and a brief description of the visit purpose.

9. A device at the visitor's end, characterized in that: Used to execute the visitor identity verification method according to any one of claims 1 to 4, the visited person terminal device comprises: A dynamic verification code generation module is used to generate a corresponding dynamic verification code based on the access request obtained from the visitor terminal and after receiving a dynamic verification code generation trigger signal; an encryption module, configured to perform key negotiation with the corresponding guest terminal in response to a key negotiation request initiated by the guest terminal, and encrypt the dynamic verification code based on the negotiated key; A communication module, configured to send the encrypted dynamic verification code to the visitor terminal and retrieve feedback information from the visitor terminal; wherein the feedback information includes the dynamic verification code returned by the visitor terminal and the corresponding visitor information; A processing module, configured to perform visitor identity verification based on the feedback information; The communication module is further configured to send a pass to the corresponding visitor after the processing module confirms that the visitor's identity has passed the review.

10. A visitor terminal device, characterized in that: Used to execute the visitor identity verification method according to any one of claims 5 to 8, the visitor terminal device comprises: The communication module is used to initiate an access request and retrieve the encrypted dynamic verification code fed back by the visitee; A decryption module, configured to decrypt the encrypted dynamic verification code based on a preset negotiated key to obtain the dynamic verification code; The acquisition module is used to enable the dynamic code input function and, in response to a trigger signal indicating that the dynamic verification code input is completed, enable the visitor information input function; and recover and send the input dynamic verification code and visitor information to the visitor terminal; The communication module is further configured to retrieve the pass issued by the visited party in response to a verification success signal from the visited party.

11. A visitor identity verification system, characterized in that: The system comprises the visited-side device according to claim 9 and the visitor-side device according to claim 10.

12. A machine-readable storage medium having instructions stored thereon, characterized in that: When the instruction is executed by a processor, the processor is configured to execute the visitor identity verification method according to any one of claims 1 to 8.

13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the visitor identity verification method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Visitor authentication method and apparatus, equipment and computer readable storage medium

    CN111833507A