Verification processing method and apparatus
By receiving and verifying biometric verification requests from login terminals and querying and verifying the associated user set of authorized users, the problem of authorized users being unable to verify their identities in person during online service processing is solved. This achieves efficient and secure biometric verification, improving service success rate and user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-10
- Publication Date
- 2026-04-03
Smart Images

Figure CN114238905B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of data processing technology, and in particular to a verification processing method and apparatus. Background Technology
[0002] With the continuous development of internet technology, more and more users are choosing to handle services online. The internet has provided convenience for users' lives and work, becoming a widely used technology. Due to busy work schedules, users may also choose to entrust other users to handle certain services for them. However, for information security reasons, information verification may be required during the service handling process to ensure the validity of the authorization. Summary of the Invention
[0003] This specification provides one or more embodiments of a verification processing method applied to a server, comprising: receiving a biometric verification request submitted by a login terminal for accessing a service; the biometric verification request carrying an application account; querying a set of associated users authorized by the application account for biometric verification of the access service, and returning the set to the login terminal; receiving biometric features collected and submitted by the login terminal, and performing biometric verification based on a target associated user selected from the set of associated users; and synchronizing the verification result of the biometric verification to the access service.
[0004] This specification provides one or more embodiments of another verification processing method applied to a login terminal, comprising: generating a biometric verification request carrying the application account and sending it to a server based on a biometric verification instruction submitted by the login user for accessing the service; receiving a set of associated users corresponding to the application account authorized by the server for biometric verification authorization for the access service; determining the target associated user selected by the login user in the set of associated users, collecting biometric features and uploading them to the server for biometric verification.
[0005] This specification provides one or more embodiments of a verification processing apparatus, running on a server, comprising: a verification request receiving module configured to receive a biometric verification request submitted by a login terminal for accessing a service; the biometric verification request carrying an application account; an associated user set query module configured to query an associated user set of authorized users corresponding to the application account who have authorized biometric verification for the access service, and return the query result to the login terminal; a biometric verification module configured to receive biometric features collected and submitted by the login terminal, and perform biometric verification based on a target associated user selected from the associated user set; and a verification result synchronization module configured to synchronize the biometric verification result to the access service.
[0006] This specification provides one or more embodiments of another verification processing apparatus, operating on a login terminal, including: a verification request generation module, configured to generate a biometric verification request carrying an application account and send it to a server based on a biometric verification instruction submitted by a login user for accessing a service; an associated user set receiving module, configured to receive an associated user set returned by the server, representing authorized users corresponding to the application account who have authorized biometric verification for the access service; and a biometric feature collection module, configured to determine the target associated user selected by the login user in the associated user set, collect biometric features, and upload them to the server for biometric verification.
[0007] This specification provides one or more embodiments of a verification processing device, including: a processor; and a memory configured to store computer-executable instructions, which, when executed, cause the processor to: receive a biometric verification request submitted by a login terminal for an access service; the biometric verification request carrying an application account; query a set of associated users corresponding to the application account who have authorized biometric verification for the access service, and return the set to the login terminal; receive biometric features collected and submitted by the login terminal, and perform biometric verification based on a target associated user selected from the set of associated users; and synchronize the verification result of the biometric verification to the access service.
[0008] This specification provides one or more embodiments of another verification processing device, including: a processor; and a memory configured to store computer-executable instructions, which, when executed, cause the processor to: generate a biometric verification request carrying an application account based on a biometric verification instruction submitted by a logged-in user for accessing a service, and send it to a server; receive a set of associated users corresponding to the application account authorized for biometric verification of the access service, returned by the server; determine a target associated user selected by the logged-in user in the associated user set, collect biometric features, and upload them to the server for biometric verification.
[0009] This specification provides one or more embodiments of a storage medium for storing computer-executable instructions, which, when executed by a processor, implement the following process: receiving a biometric verification request submitted by a login terminal for an access service; the biometric verification request carries an application account. Querying a set of associated users corresponding to the application account who have authorized biometric verification for the access service, and returning the set to the login terminal. Receiving biometric features collected and submitted by the login terminal, and performing biometric verification based on a target associated user selected from the associated user set. Synchronizing the biometric verification result to the access service.
[0010] This specification provides one or more embodiments of another storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process: Based on a biometric verification instruction submitted by a logged-in user for accessing a service, generate a biometric verification request carrying the application account and send it to a server. Receive a set of associated users corresponding to the application account, returned by the server, authorizing biometric verification for the access service. Determine the target associated user selected by the logged-in user from the associated user set, collect biometric features, and upload them to the server for biometric verification. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in one or more embodiments of this specification or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 A flowchart illustrating a verification process provided in one or more embodiments of this specification;
[0013] Figure 2 A timing diagram illustrating a verification processing method applied to a sub-service scenario, provided in one or more embodiments of this specification.
[0014] Figure 3 A timing diagram illustrating a verification processing method for an application service scenario provided in one or more embodiments of this specification;
[0015] Figure 4 A flowchart illustrating another verification process provided in one or more embodiments of this specification;
[0016] Figure 5A schematic diagram of a verification processing device provided for one or more embodiments of this specification;
[0017] Figure 6 A schematic diagram of another verification processing apparatus provided in one or more embodiments of this specification;
[0018] Figure 7 A schematic diagram of the structure of a verification processing device provided in one or more embodiments of this specification;
[0019] Figure 8 This is a schematic diagram of another verification processing device provided in one or more embodiments of this specification. Detailed Implementation
[0020] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.
[0021] This specification provides an example of a verification processing method:
[0022] Reference Figure 1 It shows a flowchart of a verification processing method provided in this embodiment, with reference to... Figure 2 It shows a timing diagram of a verification processing method applied to a sub-service scenario provided in this embodiment, referring to... Figure 3 The diagram shows a timing diagram of a verification processing method for application service scenarios provided in this embodiment.
[0023] Reference Figure 1 The verification processing method provided in this embodiment specifically includes steps S102 to S108.
[0024] Step S102: Receive the biometric verification request submitted by the login terminal for accessing the service.
[0025] The verification processing method provided in this embodiment, in cooperation with the login terminal, after generating an authorization record for authorized users to authorize biometric verification for access to services from applicant users, receives biometric verification requests submitted by the login terminal. Based on the application account carried in the request, it queries the set of associated users for biometric verification authorization for access to services by the corresponding authorized users, and then performs biometric verification based on the biometrics collected by the login terminal and the target associated users. The obtained verification results are synchronized to access services. This not only protects the privacy and security of authorized users, but also reduces the difficulty and cost of service proxy for associated users, improves the success rate and efficiency of service proxy, and enhances the user experience.
[0026] In specific implementation, the access service includes at least one of the following: a sub-service of the application service, or the application service itself. For example, if the applicant knows the application account and password of the authorized user, they can log in to the application account of the authorized user's application service (such as social security service or housing provident fund service). During the login process, they may encounter situations requiring identity verification (such as collecting biometric data for verification). Similarly, when entering the application service and executing a sub-service within it (such as the sub-service for querying social security payment records in the social security service or the sub-service for querying housing provident fund payment records in the housing provident fund service), identity verification may also be required. To ensure the application service or... To improve the success rate of sub-service execution and prevent service failures caused by authorized users not being able to personally verify their identity, authorized users can authorize biometric verification for application services or sub-services to requesting users. This generates an authorization record for biometric verification, which is stored in an authorization relationship database. The requesting user is then listed as an associated user, allowing the associated user to perform biometric verification on behalf of the authorized user, ensuring smooth service execution. The authorization record includes at least one of the following: a sub-service authorization record for biometric verification authorization granted to an associated user for a sub-service of the application service, and an application service authorization record for biometric verification authorization granted to an associated user for the application service.
[0027] Authorized users are users who entrust others to handle relevant service matters and authorize the biometric verification required during the service handling process; applicant users are users who apply for authorization to authorize biometric verification for accessing services; associated users are users who have obtained authorization from authorized users to perform biometric verification for accessing services; biometric features include fingerprint features, facial image features, iris features, etc.
[0028] In addition, other access services are also covered by this plan, which will not be listed here.
[0029] In the specific execution process, based on the authorization records of authorized users and associated users, the login terminal generates a biometric verification request carrying the application account according to the biometric verification instruction submitted by the login user for accessing the service and sends it to the server. Correspondingly, the server receives the biometric verification request sent by the login terminal, which carries the application account to which the access service belongs. Among them, the login user of the login terminal can be an associated user authorized by the authorized user to perform biometric verification for accessing the service, a target associated user selected from the following set of associated users to perform biometric verification for accessing the service, a user to which the login terminal belongs, or an access user who only accesses the service.
[0030] Step S104: Query the set of associated users who have authorized the application account to perform biometric verification authorization for the access service, and return the set to the login terminal.
[0031] Based on the above-mentioned receiving of a biometric verification request carrying the application account submitted by the login terminal for accessing the service, this embodiment queries the associated user set of the authorized user corresponding to the application account for biometric verification authorization for accessing the service, and returns it to the login terminal.
[0032] In practice, authorized users and associated users may correspond to more than one authorization record. To facilitate information management, the authorization records generated above for authorized users to perform biometric verification for access services can be stored in an authorization relationship database. Based on this, this embodiment searches for associated users in the authorization relationship database. In an optional implementation of this embodiment, during the process of querying the set of associated users for biometric verification authorization of the authorized user corresponding to the application account to access services, the following operations are performed:
[0033] Based on the application account, query the authorization relationship database for the associated users who have performed biometric verification authorization for the access service;
[0034] Filter the associated users obtained from the query to those whose authorization status is valid, and construct the associated user set.
[0035] Specifically, based on the application account carried in the biometric verification request, the system searches the authorization relationship database for the associated users of the application account who have performed biometric verification authorization for accessing the service. If the authorization records are not deleted, they need to be distinguished by authorization status. Therefore, the system can filter out the associated users with the authorization status of valid authorization from the obtained associated users and construct an associated user set. Then, the system can specify the target associated user in the associated user set for biometric verification to eliminate the execution obstacles to accessing the service.
[0036] It should be noted that an authorized user may authorize one or more applicant users to perform biometric verification for access to the service. Therefore, the associated user who obtains authorization may be one or more, and the associated user set may also contain one or more associated users.
[0037] In addition, after filtering the associated users whose authorization status is valid, associated users whose authorization period has expired can be removed to obtain the removed associated users and construct the associated user set.
[0038] In practical applications, after querying the set of associated users authorized by the application account for biometric verification authorization of access services and returning it to the login terminal, in order to improve the execution efficiency of access services, it is also possible to determine the target associated user selected by the login user of the login terminal from the associated user set, and verify whether the instruction parameters of the login terminal match according to the authorization content contained in the authorization record. If they match, the detection is determined to have passed; if they do not match, the detection is determined to have failed. In an optional implementation provided in this embodiment, after querying the set of associated users authorized by the application account for biometric verification authorization of access services and returning it to the login terminal, the following operations are performed:
[0039] Determine the target associated user selected from the set of associated users, and read the authorization record for the access service corresponding to the target associated user;
[0040] Detect whether the command parameters of the login terminal match the authorization content contained in the authorization record;
[0041] If yes, synchronize the detection result to the login terminal; otherwise, do nothing.
[0042] For example, if the identified target user is user u, the authorization record for accessing the service corresponding to user u is read. The authorization record contains the authorization content of a transfer limit of 2000 yuan. If the login user on the login terminal is detected to have entered a transfer amount of 1800 yuan, then the instruction parameter of the login terminal, i.e., the transfer amount, is lower than the authorization content, i.e., the transfer limit, and the detection result is synchronized to the login terminal.
[0043] In the specific execution process, during the biometric verification authorization process between the authorized user and the applicant user for access to the service, in order to comprehensively meet the diverse needs of users, two methods of biometric verification authorization are provided: the applicant user performs biometric verification for the authorized user during the application process for access to the service, and the authorized user actively authorizes the applicant user to perform biometric verification for the application process for access to the service. In the first optional implementation method provided in this embodiment, the following operations are performed during the biometric verification authorization process:
[0044] Obtain the authorization information submitted by the user terminal for biometric verification in connection with the access service;
[0045] An authorization application reminder is generated based on the authorization information and sent to the authorized user terminal to which the authorized user belongs;
[0046] If a confirmation response is detected from the authorized user terminal in response to the authorization request reminder, verify whether the logged-in user of the authorized user terminal is the same as the authorized user;
[0047] If they match, an authorization record is generated for the authorized user to perform biometric verification for the requesting user regarding the access service;
[0048] If there is a discrepancy, no action will be taken.
[0049] Specifically, if an applicant wants to obtain authorization for biometric verification to access the service, they can configure the authorization information sending server through their terminal. The server generates an authorization request reminder based on the authorization information and sends it to the authorized user's terminal. If the authorized user's terminal submits a confirmation response to the authorization request reminder, it means that the authorized user agrees to the applicant's biometric verification for accessing the service. In addition, to prevent the applicant from logging into the authorized user's application account and granting themselves all operation permissions of the application account without the authorized user's knowledge, thus abusing authorization, the system can verify whether the user logged in using the authorized user's terminal is the authorized user. If so, an authorization record is generated for the authorized user to perform biometric verification for accessing the service to the applicant; otherwise, no action is taken.
[0050] In the process of generating authorization records, to distinguish between them, the applicant user can be designated as the authorized user, and an authorization relationship between the associated user and the authorized user can be established. The authorization status is then marked, authorization records are created, and the authorization relationship database is updated. In one optional implementation of this embodiment, the following operations are performed during the process of generating the authorization record for the authorized user to perform biometric verification for accessing the service from the applicant user:
[0051] The applicant is designated as an associated user, and an authorization relationship is established between the associated user and the authorized user for biometric verification.
[0052] Based on the aforementioned authorization relationship, the authorization status is marked as valid.
[0053] The authorization record is created based on the authorization information and the authorization validity status, and the authorization relationship database is updated.
[0054] The authorization information includes at least one of the following: authorized user identifier, associated user identifier, authorized service, authorization type, authorization creation time, authorization period, authorization status, and authorization content.
[0055] For example, an authorization record can be displayed as "Authorized User ID: 100000001; Associated User ID: 100000002; Authorized Service: Social Security Service; Authorization Type: Long-term; Authorization Creation Time: 2021-10-28; Authorization Period: 24h; Authorization Status: Authorization Valid; Authorization Content: None"; Another example is an authorization record displayed as "Authorized User ID: 100000003; Associated User ID: 100000004; Authorized Service: Transfer Sub-service in Online Banking; Authorization Type: Single; Authorization Creation Time: 2021-10-28; Authorization Period: 1h; Authorization Status: Authorization Valid; Authorization Content: Transfer Limit 2000 yuan".
[0056] It should be noted that the user identifier in the authorized user identifier and associated user identifier can be a user account or a user identity identifier code, etc. After the authorization relationship is established and the authorization validity status is marked, an authorization record can also be created based on either the authorization information or the authorization validity status, and the authorization relationship database can be updated.
[0057] In addition to the aforementioned method where the applicant authorizes the authorized user to participate in the biometric verification process during the access service application process, the authorized user can also proactively authorize the applicant to participate in the biometric verification process during the access service application process. In the second optional implementation provided in this embodiment, the following operations are performed during the biometric verification authorization process:
[0058] Receive authorization information for biometric verification collected by the access service from the user terminal to which the authorized user belongs, and send it to the applicant user;
[0059] Detect whether the logged-in user of the user terminal matches the authorized user;
[0060] If so, the applicant user is designated as an associated user, and an authorization record is generated for the authorized user to perform biometric verification for the associated user regarding the access service.
[0061] If not, no action will be taken.
[0062] Specifically, authorized users actively configure authorization information for biometric verification of access services through their user terminals and send it to the server. The server then sends the authorization information to the applicant user based on the applicant user identifier contained in the authorization information. Accordingly, to prevent the applicant user from logging into the authorized user's application account and granting all operation permissions of the application account to themselves without the authorized user's knowledge, thus abusing authorization, the system can verify whether the user terminal logged in using the authorized user is indeed the authorized user. If so, the applicant user is designated as an associated user, and an authorization record is generated for the authorized user to perform biometric verification of access services to the associated user. If not, no action is taken.
[0063] Step S106: Receive the biometric features collected and submitted by the login terminal, and perform biometric verification based on the target associated user selected in the associated user set.
[0064] As described above, the system queries the set of associated users for which the authorized user corresponding to the application account has performed biometric verification authorization for accessing the service, and returns the results to the login terminal. After the results are returned, the login terminal determines the target associated user based on the associated user set and collects biometric features and uploads them to the server. Accordingly, in this step, the system receives the biometric features collected and submitted by the login terminal and performs biometric verification based on the target associated user selected in the associated user set.
[0065] In practice, during biometric verification, identity data and biometric features can be combined for verification to ensure accuracy and reliability. In one optional implementation method provided in this embodiment, the following operations are performed during biometric verification:
[0066] Read the identity data corresponding to the biometric features;
[0067] Call a third-party verification interface to verify whether the biometric features and identity data match the biometric features and identity data of the target associated user;
[0068] If a match is found, the verification result is determined as successful.
[0069] If there is no match, the verification result is determined to be verification failed.
[0070] Specifically, the third-party verification interface stores the biometrics and identity data (such as name and ID number) of users registered with the application service. During the biometric verification process, based on the collected biometrics, the corresponding identity data is further read. The third-party verification interface is used to verify whether the collected biometrics are consistent with the biometrics of the target associated user, and whether the identity data corresponding to the collected biometrics are consistent with the identity data of the target associated user. If they are consistent, the verification result is determined to be successful; if they are inconsistent, the verification result is determined to be unsuccessful.
[0071] Step S108: Synchronize the biometric verification result with the access service.
[0072] As mentioned above, the result of biometric verification is either successful or unsuccessful. The verification result is synchronized to the access service. The purpose of synchronization is to enable the access service to perform service execution based on the verification result. Specifically, if the verification fails, biometric verification is performed again. If the verification succeeds, and the access service is a sub-service of an application service (e.g., the application service includes group buying, food delivery, and online banking services, and the sub-services of the application service include payment sub-services in food delivery services and transfer sub-services in online banking services), then the access service will only grant access to the sub-services within the authorization period. If the access service is an application service, then the access service will grant access to the entire application service within the authorization period.
[0073] In one optional implementation of this embodiment, if the verification result is successful, the access service performs the following operations:
[0074] Based on the first authorization period, access permission is granted to the login terminal for the sub-service; the sub-service is executed according to the granted access permission, and the execution result is returned to the login terminal; wherein, the first authorization period is included in the authorization record for the sub-service corresponding to the target associated user.
[0075] Specifically, since the access service is a sub-service of the application service, if the verification result is successful, the authorization record of the sub-service of the application service corresponding to the target associated user in the authorization relationship database is read. According to the first authorization period contained in the authorization record, the access permission for the sub-service within the authorization period is granted to the login terminal. Then, based on the access permission obtained, the sub-service is executed and the execution result is returned to the login terminal, that is, the execution result of successful execution or execution failure. The login terminal receives the execution result returned by the access service.
[0076] Continuing with the previous example, if biometric verification is successful, the authorization record for "transfer in online banking service" corresponding to the target associated user u will be "Authorized User ID: 100000003; Associated User ID: 100000004; Authorized Service: Transfer sub-service in online banking service; Authorization Type: Single; Authorization Creation Time: 2021-10-28; Authorization Period: 1h; Authorization Status: Authorization Valid; Authorization Content: Transfer Limit 2000 yuan". Therefore, the login terminal will be granted access to the "transfer sub-service in online banking service" for 1 hour, and the transfer will be processed within 1 hour, returning the successful transfer result to the login terminal.
[0077] Accordingly, if the verification result is successful, the login terminal will perform the following operations:
[0078] Receive the execution result returned by the access service; the execution result is obtained by performing execution processing on the sub-service after the access permission for the sub-service is granted.
[0079] In another optional implementation provided in this embodiment, if the verification result is successful, the access service performs the following operations:
[0080] Based on the second authorization period, access permissions are granted to the login terminal for the application service; service data of the application service is obtained based on the access permissions granted and sent to the login terminal; wherein, the second authorization period is included in the authorization record for the application service corresponding to the target associated user.
[0081] If the verification result is successful, access permissions are granted to the sub-services of the application service. Similarly, if the service to be accessed is the application service, access permissions are granted to the application service within the second authorization period if the verification result is successful, and the execution result is returned to the login terminal after the application service is executed.
[0082] Using the previous example, if the biometric verification is successful, the authorization record for "Social Security Service" corresponding to the target associated user z is read as follows: "Authorized User ID: 100000001; Associated User ID: 100000002; Authorized Service: Social Security Service; Authorization Type: Long-term; Authorization Creation Time: 2021-10-28; Authorization Period: 24h; Authorization Status: Valid; Authorization Content: None". Then, access permission for "Social Security Service" is granted to the login terminal for 24 hours, the Social Security Service is executed within 24 hours, and the successful execution result is returned to the login terminal.
[0083] Accordingly, if the verification result is successful, the login terminal will perform the following operations:
[0084] Receive service data for the application service issued by the access service; the service data is obtained after the access permission for the application service is granted.
[0085] In practical applications, after performing biometric verification and synchronizing the verification results to the access service, it is possible to detect whether the authorization type for biometric verification authorization of the target associated user by the access service is the target authorization type. Specifically, in an optional implementation provided in this embodiment, after synchronizing the biometric verification results to the access service, the following operations are performed:
[0086] Read the authorization record for the access service corresponding to the target associated user;
[0087] Detect whether the authorization type contained in the authorization record is the target authorization type;
[0088] If so, terminate the authorization relationship between the authorized user and the target associated user, and change the authorization status contained in the authorization record to an authorization invalidation status;
[0089] If not, check whether the authorization period contained in the authorization record has expired;
[0090] If the authorization period expires, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization invalidation status. If the authorization period has not expired, no action is taken.
[0091] The authorization types include long-term authorization and single-time authorization. Long-term authorization means that after being authorized, biometric verification can be performed repeatedly within the authorized period. Single-time authorization means that after being authorized, biometric verification can only be performed once within the authorized period. Continuing with the previous example, "Authorized Service: Social Security Service; Authorization Type: Long-term; Authorization Period: 24h;" means that the target user z can repeatedly perform biometric verification within the Social Security Service within 24 hours. However, "Authorized Service: Transfer Sub-service in Online Banking Service; Authorization Type: Single; Authorization Period: 1h;" means that the target user u can only perform biometric verification once within the Transfer Sub-service in Online Banking Service within 1 hour.
[0092] Therefore, in order to reasonably control the authorization permissions of login terminals during the specific implementation process, after biometric verification, the authorization type contained in the authorization record can be judged. If it is a single authorization type, since a single authorization type can only successfully complete biometric verification once within the authorization period, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status is changed from authorized valid to authorized invalid. If it is not a single authorization type, i.e., a long-term authorization type, since a long-term authorization type can repeatedly perform biometric verification within the access service within the authorization period, it is checked whether the authorization period has expired. If it has expired, it means that the authorization period has reached, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status is changed from authorized valid to authorized invalid. If it has not expired, it means that the authorization period has not reached, and no action is taken to ensure the data security of authorized users and to promptly revoke the service access permissions of login terminals after biometric verification.
[0093] The following description uses the application of a verification processing method provided in this embodiment in a sub-service scenario as an example to further illustrate the verification processing method provided in this embodiment. (See also...) Figure 2 The verification processing method applied to sub-service scenarios includes the following steps.
[0094] Step S204: Based on the application account carried in the biometric verification request sent by the login terminal, query the authorization relationship database for the associated user who authorized the application service for biometric verification of the sub-service.
[0095] Previously, the login terminal generated a biometric verification request carrying the application account and sent it to the server based on the biometric verification instruction submitted by the target associated user for the sub-service of the application service.
[0096] Step S206: Filter the associated users whose authorization status is valid from the associated users obtained by the query, and construct the associated user set.
[0097] Step S208: Return the constructed and obtained associated user set to the login terminal.
[0098] After that, the login terminal receives the set of associated users returned by the server, determines the target associated user, selects the target associated user from the set of associated users, and submits it to the server.
[0099] Step S212: Read the authorization record for biometric verification authorization of the sub-service of the application service corresponding to the target associated user.
[0100] Step S214: Check whether the command parameters of the login terminal match the authorization content contained in the authorization record;
[0101] If so, proceed with steps S216, S220, and S222;
[0102] If not, no action will be taken.
[0103] Step S216: Synchronize the detection pass result to the login terminal.
[0104] Subsequently, based on the detection results synchronized with the server, the login terminal collects the biometrics of the target associated user and uploads them to the server.
[0105] Step S220: Receive the biometric data uploaded by the login terminal and read the identity data corresponding to the biometric data.
[0106] Step S222: Call a third-party verification interface to verify whether the biometric features and identity data match the biometric features and identity data of the target associated user;
[0107] If a match is found, proceed to steps S224 and S226.
[0108] If there is no match, no action will be taken.
[0109] Step S224: Determine the verification result as successful and synchronize the successful verification result to the access service.
[0110] Subsequently, based on the first authorization period, the access service grants access permissions to the login terminal for the sub-service, executes the sub-service according to the granted access permissions, and returns the execution result to the login terminal.
[0111] Step S226: Read the authorization record of the sub-service corresponding to the application service of the target associated user, and check whether the authorization type contained in the authorization record is a single authorization type;
[0112] If so, revoke the authorization relationship between the authorized user and the target associated user, and change the authorization status contained in the authorization record to authorization invalid.
[0113] If not, proceed to step S228.
[0114] Step S228: Check whether the authorization period contained in the authorization record has expired;
[0115] If so, proceed to step S230;
[0116] If not, no action will be taken.
[0117] Step S230: Release the authorization relationship between the authorized user and the target associated user, and change the authorization status contained in the authorization record to the authorization invalidation status.
[0118] The following description uses the application of the verification processing method provided in this embodiment in an application service scenario as an example to further illustrate the verification processing method provided in this embodiment. (See also...) Figure 3 The verification processing method applied to application service scenarios includes the following steps.
[0119] Step S304: Based on the application account carried in the biometric verification request sent by the login terminal, query the associated user set of the corresponding authorized user who has authorized biometric verification for the application service.
[0120] Previously, the login terminal would generate a biometric verification request carrying the application account and send it to the server based on the biometric verification instruction submitted by the login user for the sub-service of the application service.
[0121] Step S306: Return the set of associated users obtained from the query to the login terminal.
[0122] Subsequently, the login terminal receives the set of associated users returned by the server, determines the target associated user selected by the login user in the set of associated users, collects biometric features and uploads them to the server.
[0123] Among them, the logged-in user is the user who operates the login terminal and is not the same person as the target associated user. In addition, the logged-in user can also be the user to which the login terminal belongs, any associated user in the associated user set, the target associated user, or an access user who only accesses the service. The logged-in user and the target associated user may or may not be the same person.
[0124] Step S310: Receive the biometric features uploaded by the login terminal and verify whether the biometric features match the biometric features of the target associated user;
[0125] If a match is found, proceed to steps S312 and S314.
[0126] If there is no match, no action will be taken.
[0127] Step S312: Determine the verification result as successful and synchronize the successful verification result to the application service.
[0128] Step S314: Read the authorization record of the sub-service corresponding to the application service for the target associated user, and check whether the authorization type contained in the authorization record is the target authorization type;
[0129] If so, revoke the authorization relationship between the authorized user and the target associated user, and change the authorization status contained in the authorization record to authorization invalid.
[0130] If not, proceed to step S316.
[0131] Step S316: Check whether the authorization period contained in the authorization record has expired;
[0132] If so, proceed to step S318;
[0133] If not, no action will be taken.
[0134] Step S318: Release the authorization relationship between the authorized user and the target associated user, and change the authorization status contained in the authorization record to the authorization invalidation status.
[0135] In summary, the verification processing method provided in this embodiment first receives a biometric verification request carrying the application account submitted by the login terminal for accessing the service. Based on the application account, it queries the authorization relationship database for the associated users of the corresponding authorized user who has authorized the biometric verification for accessing the service. Among the associated users obtained by the query, it filters the associated users whose authorization status is valid, constructs an associated user set, and returns the associated user set to the login terminal.
[0136] Secondly, determine the target associated user selected from the associated user set, and read the authorization record for accessing the service corresponding to the target associated user. Check whether the command parameters of the login terminal match the authorization content contained in the authorization record. If not, do not process; if yes, synchronize the detection result to the login terminal.
[0137] Next, based on the successful detection result, the system receives the biometric features collected and submitted by the login terminal, reads the identity data corresponding to the biometric features, and calls a third-party verification interface to verify whether the biometric features and identity data match the biometric features and identity data of the target associated user. If they do not match, no action is taken; if they match, the verification result is determined as successful, and the successful biometric verification result is synchronized to the access service.
[0138] Finally, the authorization record for accessing the service corresponding to the target associated user is read, and it is checked whether the authorization type contained in the authorization record is the target authorization type. If so, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization expired. If not, it is checked whether the authorization period contained in the authorization record has expired. If not, no action is taken. If so, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization expired. This not only protects the privacy and security of the authorized user, but also reduces the difficulty and cost of service proxy for associated users, improves the success rate and efficiency of service proxy, and enhances the user experience.
[0139] The verification processing methods for the two application scenarios of sub-services and application services provided above are executed by the server. The verification processing methods for the two application scenarios of sub-services and application services provided in the following method embodiments are executed by the login terminal. The two cooperate with each other during execution. Therefore, please refer to the corresponding content of the following method embodiments to read the above implementation process.
[0140] Another verification processing method embodiment provided in this specification:
[0141] Reference Figure 4 It shows a flowchart of a verification processing method provided in this embodiment, with reference to... Figure 2 It shows a timing diagram of a verification processing method applied to a sub-service scenario provided in this embodiment, referring to... Figure 3 The diagram shows a timing diagram of a verification processing method for application service scenarios provided in this embodiment.
[0142] The verification processing method provided in this embodiment is applied to the login terminal, while the verification processing method provided in the above method embodiment is applied to the server. The two cooperate with each other during execution. Therefore, please refer to the corresponding content of the above method embodiment when reading this embodiment. This embodiment will not be described in detail here.
[0143] Reference Figure 4 The verification processing method provided in this embodiment specifically includes steps S402 to S406.
[0144] Step S402: Based on the biometric verification instruction submitted by the logged-in user for accessing the service, generate a biometric verification request carrying the application account and send it to the server.
[0145] The verification processing method provided in this embodiment, by cooperating with the server, obtains the biometric verification instruction submitted by the logged-in user for accessing the service, generates a biometric verification request carrying the application account based on the biometric verification instruction and sends it to the server, and then determines the target associated user selected by the logged-in user from the set of associated users who are authorized users corresponding to the application account for accessing the service through biometric verification, collects biometric features and uploads them to the server so that the server can perform biometric verification. This not only protects the privacy and security of authorized users, but also reduces the difficulty and cost of associated users acting as agents for services, improves the success rate and efficiency of service agency, and enhances the user experience.
[0146] In specific implementation, the access service includes at least one of the following: a sub-service of the application service, or the application service itself. For example, if the applicant knows the application account and password of the authorized user, they can log in to the application account of the authorized user's application service (such as social security service or housing provident fund service). During the login process, they may encounter situations requiring identity verification (such as collecting biometric data for verification). Similarly, when entering the application service and executing a sub-service within it (such as the sub-service for querying social security payment records in the social security service or the sub-service for querying housing provident fund payment records in the housing provident fund service), identity verification may also be required. To ensure the application service or... To improve the success rate of sub-service execution and prevent service failures caused by authorized users not being able to personally verify their identity, authorized users can authorize biometric verification for application services or sub-services to requesting users. This generates an authorization record for biometric verification, which is stored in an authorization relationship database. The requesting user is then listed as an associated user, allowing the associated user to perform biometric verification on behalf of the authorized user, ensuring smooth service execution. The authorization record includes at least one of the following: a sub-service authorization record for biometric verification authorization granted to an associated user for a sub-service of the application service, and an application service authorization record for biometric verification authorization granted to an associated user for the application service.
[0147] Authorized users are users who entrust others to handle relevant service matters and authorize the biometric verification required during the service handling process; applicant users are users who apply for authorization to authorize biometric verification for accessing services; associated users are users who have obtained authorization from authorized users to perform biometric verification for accessing services; biometric features include fingerprint features, facial image features, iris features, etc.
[0148] In addition, other access services are also covered by this plan, which will not be listed here.
[0149] In this embodiment, based on the authorization records of authorized users and associated users, a biometric verification request carrying the application account is generated and sent to the server according to the biometric verification instruction submitted by the logged-in user for accessing the service. Correspondingly, the server receives the biometric verification request sent by the logged-in terminal, which carries the application account to which the access service belongs. The logged-in user of the login terminal can be an associated user authorized by the authorized user to perform biometric verification for accessing the service, a target associated user selected from the set of associated users to perform biometric verification for accessing the service, a user to which the login terminal belongs, or an access user who only accesses the service.
[0150] In practical applications, after receiving a biometric verification request with the application account submitted by the login terminal for accessing the service, the server queries the associated user set of authorized users corresponding to the application account for biometric verification authorization for accessing the service, and returns it to the login terminal.
[0151] In the specific execution process, authorized users and associated users may correspond to more than one authorization record. To facilitate information management, the authorization records generated above, which authorize users to perform biometric verification for access services, can be stored in an authorization relationship database. Based on this, the server searches for associated users in the authorization relationship database and sends the found set of associated users to the login terminal. In an optional implementation of this embodiment, the set of associated users is constructed in the following way:
[0152] Based on the application account, query the authorization relationship database for the associated users who have performed biometric verification authorization for the access service;
[0153] Filter the associated users obtained from the query to those whose authorization status is valid, and construct the associated user set.
[0154] Specifically, based on the application account carried in the biometric verification request, the server searches the authorization relationship database for the associated users of the application account who have performed biometric verification authorization for accessing the service. If the authorization record is not deleted, it is necessary to distinguish them by authorization status. Therefore, the associated users with the authorization status of valid authorization can be filtered out from the associated users obtained by the query, and an associated user set is constructed. The target associated user is specified in the associated user set for biometric verification, thereby eliminating the execution obstacles to accessing the service.
[0155] It should be noted that an authorized user may authorize one or more applicant users to perform biometric verification for access to the service. Therefore, the associated user who obtains authorization may be one or more, and the associated user set may also contain one or more associated users.
[0156] In addition, after filtering the associated users whose authorization status is valid, the server can also remove the associated users whose authorization period has expired, obtain the removed associated users, and construct the associated user set.
[0157] Step S404: Receive the set of associated users returned by the server, which are authorized users corresponding to the application account who have performed biometric verification authorization for accessing the service.
[0158] As described above, the server searches the authorization database for the associated users of the application account corresponding to the application account that have performed biometric verification authorization for accessing the service, based on the application account carried in the biometric verification request, and constructs an associated user set to send to the login terminal. Correspondingly, this embodiment receives the associated user set returned by the server.
[0159] In the specific execution process, during the biometric verification authorization process between the authorized user and the applicant user for access to the service, in order to comprehensively meet the diverse needs of users, the server provides two methods for biometric verification authorization: the applicant user performs biometric verification on behalf of the authorized user during the application process for access to the service, and the authorized user actively authorizes the applicant user to perform biometric verification on behalf of the applicant user during the access to the service process. In the first optional implementation method provided in this embodiment, the biometric verification authorization is implemented in the following way:
[0160] Obtain the authorization information submitted by the user terminal for biometric verification in connection with the access service;
[0161] An authorization application reminder is generated based on the authorization information and sent to the authorized user terminal to which the authorized user belongs;
[0162] If a confirmation response is detected from the authorized user terminal in response to the authorization request reminder, verify whether the logged-in user of the authorized user terminal is the same as the authorized user;
[0163] If they match, an authorization record is generated for the authorized user to perform biometric verification for the requesting user regarding the access service;
[0164] If there is a discrepancy, no action will be taken.
[0165] Specifically, if an applicant wants to obtain authorization for biometric verification to access the service, they can configure the authorization information sending server through their terminal. The server generates an authorization request reminder based on the authorization information and sends it to the authorized user's terminal. If the authorized user's terminal submits a confirmation response to the authorization request reminder, it means that the authorized user agrees to the applicant's biometric verification for accessing the service. In addition, to prevent the applicant from logging into the authorized user's application account and granting themselves all operation permissions of the application account without the authorized user's knowledge, thus abusing authorization, the system can verify whether the user logged in using the authorized user's terminal is the authorized user. If so, an authorization record is generated for the authorized user to perform biometric verification for accessing the service to the applicant; otherwise, no action is taken.
[0166] In the process of generating authorization records, in order to distinguish between authorization records, the server can treat the applicant user as the authorized user, establish an authorization relationship between the associated user and the authorized user, mark the authorization status, create authorization records, and update the authorization relationship database. In an optional implementation of this embodiment, in the process of generating the authorization record for the authorized user to perform biometric verification for accessing the service to the applicant user, the server performs the following operations:
[0167] The applicant is designated as an associated user, and an authorization relationship is established between the associated user and the authorized user for biometric verification.
[0168] Based on the aforementioned authorization relationship, the authorization status is marked as valid.
[0169] The authorization record is created based on the authorization information and the authorization validity status, and the authorization relationship database is updated.
[0170] The authorization information includes at least one of the following: authorized user identifier, associated user identifier, authorized service, authorization type, authorization creation time, authorization period, authorization status, and authorization content.
[0171] For example, an authorization record can be displayed as "Authorized User ID: 100000001; Associated User ID: 100000002; Authorized Service: Social Security Service; Authorization Type: Long-term; Authorization Creation Time: 2021-10-28; Authorization Period: 24h; Authorization Status: Authorization Valid; Authorization Content: None"; another example is an authorization record displayed as "Authorized User ID: 100000003; Associated User ID: 100000004; Authorized Service: Transfer Sub-service in Online Banking; Authorization Type: Single; Authorization Creation Time: 2021-10-28; Authorization Period: 1h; Authorization Status: Authorization Valid; Authorization Content: Transfer Limit 2000 yuan".
[0172] It should be noted that the user identifier in the authorized user identifier and associated user identifier can be a user account or a user identity identifier code, etc. After the authorization relationship is established and the authorization validity status is marked, the server can also create an authorization record based on either the authorization information or the authorization validity status, and update the authorization relationship database.
[0173] In addition to the above-mentioned authorization method where the applicant authorizes the authorized user to participate in the biometric verification process during the access service application process, the authorized user can also proactively authorize the applicant to participate in the biometric verification process during the access service application process. In the second optional implementation provided in this embodiment, the biometric verification authorization is implemented in the following way: receiving authorization information for biometric verification collected by the access service from the user terminal to which the authorized user belongs, and sending it to the applicant user;
[0174] Detect whether the logged-in user of the user terminal matches the authorized user;
[0175] If so, the applicant user is designated as an associated user, and an authorization record is generated for the authorized user to perform biometric verification for the associated user regarding the access service.
[0176] If not, no action will be taken.
[0177] Specifically, authorized users actively configure authorization information for biometric verification of access services through their user terminals and send it to the server. The server, based on the applicant user identifier contained in the authorization information, sends the authorization information to the applicant user. Accordingly, to prevent applicant users from logging into the authorized user's application account and granting themselves all operation permissions of the application account without the authorized user's knowledge, thus abusing authorization, the server can verify whether the user terminal logged in using the authorized user is the authorized user. If so, the applicant user is designated as an associated user, and an authorization record is generated for the authorized user to perform biometric verification of access services to the associated user. If not, no action is taken.
[0178] Step S406: Determine the target associated user selected by the logged-in user in the associated user set, collect biometric features and upload them to the server for biometric verification.
[0179] Based on the aforementioned set of associated users for which the authorized users corresponding to the application account returned by the server authorize biometric verification for accessing the service, in order to ensure the success rate of service execution, the target associated user selected by the logged-in user in the associated user set can be determined. First, the target associated user for biometric verification is selected, then biometric data is collected, and the user identifier of the selected target associated user and the collected biometric data are uploaded to the server for biometric verification.
[0180] It should be noted that the user identifier of the target associated user selected from the associated user set can be sent to the server after selection, or it can be sent to the server simultaneously with the collected biometrics after collection. This diversified data transmission method can improve data transmission efficiency in case of emergencies.
[0181] In practice, after the server queries the set of associated users for biometric verification authorization of the application account's authorized users for accessing the service and returns it to the login terminal, the login terminal's user selects a target associated user from the associated user set. Correspondingly, the server can determine the target associated user selected by the login terminal's user from the associated user set and verify whether the login terminal's instruction parameters match the authorization content contained in the authorization record. If they match, the detection is deemed successful; otherwise, the detection is deemed unsuccessful. Specifically, after the server queries the set of associated users for biometric verification authorization of the application account's authorized users for accessing the service and returns it to the login terminal, it performs the following operations:
[0182] Determine the target associated users selected from the associated user set, and read the authorization records for accessing services corresponding to the target associated users;
[0183] Check whether the command parameters of the login terminal match the authorization content contained in the authorization record;
[0184] If yes, synchronize the detection result to the login terminal; otherwise, do nothing.
[0185] For example, if the identified target user is user u, the authorization record for accessing the service corresponding to user u is read. The authorization record contains the authorization content of a transfer limit of 2000 yuan. If the login user on the login terminal is detected to have entered a transfer amount of 1800 yuan, then the instruction parameter of the login terminal, i.e., the transfer amount, is lower than the authorization content, i.e., the transfer limit, and the detection result is synchronized to the login terminal.
[0186] In practical applications, during biometric verification, the server can combine identity data and biometric features for verification to ensure accuracy and reliability. Specifically, the server performs the following operations during biometric verification:
[0187] Read identity data corresponding to biometric features;
[0188] Call a third-party verification interface to verify whether the biometric features and identity data match those of the target user.
[0189] If a match is found, the verification result will be considered successful.
[0190] If there is no match, the verification result is determined to be verification failed.
[0191] Specifically, the third-party verification interface stores the biometric features and identity data (such as name and ID number) of users registered with the application service. During the biometric verification process, the server, based on the collected biometric features, further reads the identity data corresponding to the biometric features and verifies whether the collected biometric features are consistent with the biometric features of the target associated user and whether the identity data corresponding to the collected biometric features are consistent with the identity data of the target associated user. If they are consistent, the verification result is determined to be successful; if they are inconsistent, the verification result is determined to be unsuccessful.
[0192] As described above, the result of biometric verification is either successful or unsuccessful. The verification result is synchronized to the access service. The purpose of synchronization is to enable the access service to perform service execution based on the verification result. Specifically, if the verification fails, biometric verification is performed again. If the verification succeeds, and the access service is a sub-service of an application service (e.g., the application service includes group buying, food delivery, and online banking services, and the sub-services of the application service include payment sub-services in food delivery services and transfer sub-services in online banking services), then the access service will only grant access to the sub-services within the authorized period. It will then perform the sub-service execution based on the granted access and return the execution result to the login terminal, which will receive the result. If the access service is an application service, then the access service will grant access to the entire application service within the authorized period. It will then obtain the application service data based on the granted access and distribute it to the login terminal, which will receive the application service data distributed by the access service.
[0193] Specifically, if the verification result is successful, the service will perform the following operations:
[0194] Based on the first authorization period, access permissions are granted to the login terminal for the sub-service; the sub-service is executed according to the granted access permissions, and the execution result is returned to the login terminal; wherein, the first authorization period is included in the authorization record for the sub-service corresponding to the target associated user.
[0195] Specifically, since the access service is a sub-service of the application service, if the verification result is successful, the authorization record of the sub-service of the application service corresponding to the target associated user in the authorization relationship database is read. According to the first authorization period contained in the authorization record, the access permission for the sub-service within the authorization period is granted to the login terminal. Then, based on the access permission obtained, the sub-service is executed and the execution result is returned to the login terminal, that is, the execution result of successful execution or execution failure. The login terminal receives the execution result returned by the access service.
[0196] Continuing with the previous example, if biometric verification is successful, the authorization record for "transfer in online banking service" corresponding to the target associated user u will be "Authorized User ID: 100000003; Associated User ID: 100000004; Authorized Service: Transfer sub-service in online banking service; Authorization Type: Single; Authorization Creation Time: 2021-10-28; Authorization Period: 1h; Authorization Status: Authorization Valid; Authorization Content: Transfer Limit 2000 yuan". Therefore, the login terminal will be granted access to the "transfer sub-service in online banking service" for 1 hour, and the transfer will be processed within 1 hour, returning the successful transfer result to the login terminal.
[0197] Accordingly, in one optional implementation of this embodiment, if the verification result is successful, the login terminal performs the following operations:
[0198] The execution result returned by the access service is received; the execution result is obtained by performing execution processing on the sub-service after the access permission for the sub-service is granted.
[0199] In addition, if the accessed service is an application service, and the verification result is successful, the accessed service performs the following operations: based on the second authorization period, grant access permissions to the login terminal for the application service; obtain the service data of the application service according to the access permissions granted, and send it to the login terminal; wherein, the second authorization period is included in the authorization record for the application service corresponding to the target associated user.
[0200] If the verification result is successful, access permissions are granted to the sub-services of the application service. Similarly, if the access service is an application service, access permissions are granted to the application service within the authorized period if the verification result is successful. After executing the application service, the execution result is returned to the login terminal, and the login terminal receives the execution result returned by the access service.
[0201] Following the previous example, if biometric verification is successful, the authorization record for "Social Security Service" corresponding to the target associated user z will be "Authorized User ID: 100000001; Associated User ID: 100000002; Authorized Service: Social Security Service; Authorization Type: Long-term; Authorization Creation Time: 2021-10-28; Authorization Period: 24h; Authorization Status: Valid; Authorization Content: None". Then, access to "Social Security Service" will be granted to the login terminal within 24 hours, the Social Security Service will be executed within 24 hours, and the successful execution result will be returned to the login terminal.
[0202] Accordingly, in another optional implementation provided in this embodiment, if the verification result is successful, the login terminal performs the following operations:
[0203] Receive service data of the application service issued by the access service; the service data is obtained after the access permission for the application service is granted.
[0204] In practical applications, after performing biometric verification and synchronizing the verification results to the access service, the server can check whether the authorization type used to authorize biometric verification of the target associated user through the access service is the target authorization type. Specifically, after synchronizing the biometric verification results to the access service, the server performs the following operations:
[0205] Read the authorization records for accessing services corresponding to the target user;
[0206] Check whether the authorization type contained in the authorization record is the target authorization type;
[0207] If so, revoke the authorization relationship between the authorized user and the target associated user, and change the authorization status contained in the authorization record to authorization invalid.
[0208] If not, check whether the authorization period contained in the authorization record has expired;
[0209] If the authorization period expires, the authorization relationship between the authorized user and the target associated user will be terminated, and the authorization status contained in the authorization record will be changed to authorization expired. If the authorization period has not expired, no action will be taken.
[0210] The authorization types include long-term authorization and single-time authorization. Long-term authorization means that after being authorized, biometric verification can be performed repeatedly within the authorized period. Single-time authorization means that after being authorized, biometric verification can only be performed once within the authorized period. Continuing with the previous example, "Authorized Service: Social Security Service; Authorization Type: Long-term; Authorization Period: 24h;" means that the target user z can repeatedly perform biometric verification within the Social Security Service within 24 hours. However, "Authorized Service: Transfer Sub-service in Online Banking Service; Authorization Type: Single; Authorization Period: 1h;" means that the target user u can only perform biometric verification once within the Transfer Sub-service in Online Banking Service within 1 hour.
[0211] Therefore, in order to reasonably control the authorization permissions of login terminals during the specific execution process, the server can determine the authorization type contained in the authorization record after biometric verification. If it is a single-time authorization type, since a single-time authorization type can only successfully complete biometric verification once within the authorization period, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status is changed from valid authorization to invalid authorization. If it is not a single-time authorization type, i.e., a long-term authorization type, since a long-term authorization type can repeatedly perform biometric verification within the access service within the authorization period, the server checks whether the authorization period has expired. If it has expired, it means that the authorization period has reached, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status is changed from valid authorization to invalid authorization. If it has not expired, it means that the authorization period has not reached, and no action is taken. This ensures the data security of authorized users and allows for the timely revocation of service access permissions for login terminals after biometric verification.
[0212] The following description uses the application of a verification processing method provided in this embodiment in a sub-service scenario as an example to further illustrate the verification processing method provided in this embodiment. (See also...) Figure 2 The verification processing method applied to sub-service scenarios includes the following steps.
[0213] Step S202: Based on the biometric verification instruction submitted by the target associated user for the sub-service of the application service, generate a biometric verification request carrying the application account and send it to the server.
[0214] Subsequently, based on the application account carried in the biometric verification request sent by the login terminal, the server queries the authorization relationship database for the corresponding authorized user to perform biometric verification authorization for the sub-service of the application service. From the obtained associated users, the server filters the associated users whose authorization status is valid, constructs an associated user set, and returns the constructed associated user set to the login terminal.
[0215] Step S210: Receive the set of associated users returned by the server, determine the target associated user, and submit the target associated user selected in the set of associated users to the server.
[0216] Subsequently, the server reads the authorization record for biometric verification of the sub-service of the application service corresponding to the target associated user, and checks whether the command parameters of the login terminal match the authorization content contained in the authorization record; if not, no action is taken, and if so, the detection result is synchronized to the login terminal.
[0217] Step S218: Based on the detection pass result synchronized with the server, collect the biometric features of the target associated user and upload them to the server.
[0218] Subsequently, the server receives the biometric data uploaded by the login terminal, reads the identity data corresponding to the biometric data, and calls a third-party verification interface to verify whether the biometric data and identity data match the biometric data and identity data of the target associated user. If they do not match, no action is taken. If they match, the verification result is determined as successful, and the successful verification result is synchronized to the access service.
[0219] The access service grants access permissions to the login terminal for the sub-service based on the first authorization period, executes the sub-service according to the granted access permissions, and returns the execution result to the login terminal; the login terminal receives the execution result returned by the access service.
[0220] The server then reads the authorization record of the sub-service corresponding to the application service for the target associated user and checks whether the authorization type contained in the authorization record is a single authorization type. If so, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization expired. If not, the server checks whether the authorization period contained in the authorization record has expired. If not, no action is taken; if so, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization expired.
[0221] The following description uses the application of the verification processing method provided in this embodiment in an application service scenario as an example to further illustrate the verification processing method provided in this embodiment. (See also...) Figure 3 The verification processing method applied to application service scenarios includes the following steps.
[0222] Step S302: Based on the biometric verification instruction submitted by the logged-in user for the sub-service of the application service, generate a biometric verification request carrying the application account and send it to the server.
[0223] Subsequently, based on the application account carried in the biometric verification request sent by the login terminal, the server queries the associated user set of the corresponding authorized user who has authorized biometric verification for the application service, and returns the obtained associated user set to the login terminal.
[0224] Step S308: Receive the associated user set returned by the server, determine the target associated user selected by the logged-in user in the associated user set, collect the biometric features of the target associated user and upload them to the server.
[0225] Subsequently, the server receives the biometric data uploaded by the logged-in terminal and verifies whether the biometric data matches the biometric data of the target associated user. If they do not match, no action is taken; if they match, the verification result is confirmed as successful, and the successful verification result is synchronized to the application service. The server reads the authorization record of the sub-service corresponding to the application service for the target associated user and checks whether the authorization type contained in the authorization record is the target authorization type. If yes, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization expired. If no, the server checks whether the authorization period contained in the authorization record has expired. If no, no action is taken; if yes, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the authorization record is changed to authorization expired.
[0226] In summary, the verification processing method provided in this embodiment first generates a biometric verification request carrying the application account based on the biometric verification instruction submitted by the logged-in user for accessing the service, and sends it to the server. It then receives a set of associated users corresponding to the application account, authorized for biometric verification of the access service. Next, it determines the target associated user selected by the logged-in user from the associated user set, collects biometric data, and uploads it to the server for biometric verification. Finally, it receives the execution result returned by the sub-service; the execution result is obtained by executing the sub-service after access permissions are granted. Alternatively, it receives service data from the application service; the service data is obtained after access permissions are granted to the application service. This method not only protects the privacy and security of authorized users but also reduces the difficulty and cost of service delegation for associated users, improves the success rate and efficiency of service delegation, and enhances the user experience.
[0227] An embodiment of a verification processing device provided in this specification is as follows:
[0228] In the above embodiments, a verification processing method is provided and applied to a server. Correspondingly, a verification processing device is also provided and runs on the server. The following description is in conjunction with the accompanying drawings.
[0229] Reference Figure 5 The diagram shows a verification processing device provided in this embodiment.
[0230] Since the apparatus embodiments correspond to the method embodiments, the descriptions are relatively simple. For relevant parts, please refer to the corresponding descriptions of the method embodiments provided above. The apparatus embodiments described below are merely illustrative.
[0231] This embodiment provides a verification processing device, which runs on a server and includes:
[0232] The verification request receiving module 502 is configured to receive a biometric verification request submitted by the login terminal for accessing the service; the biometric verification request carries the application account.
[0233] The associated user set query module 504 is configured to query the associated user set of the authorized user corresponding to the application account who has performed biometric verification authorization for the access service, and return it to the login terminal.
[0234] The biometric verification module 506 is configured to receive biometric features collected and submitted by the login terminal, and to perform biometric verification based on the target associated user selected in the associated user set.
[0235] The verification result synchronization module 508 is configured to synchronize the verification result of the biometric verification to the access service.
[0236] Another embodiment of the verification processing device provided in this specification is as follows:
[0237] In the above embodiments, a verification processing method is provided for use on a login terminal. Correspondingly, a verification processing device is also provided for use on the login terminal. The following description is in conjunction with the accompanying drawings.
[0238] Reference Figure 6 The diagram shows a verification processing device provided in this embodiment.
[0239] Since the apparatus embodiments correspond to the method embodiments, the descriptions are relatively simple. For relevant parts, please refer to the corresponding descriptions of the method embodiments provided above. The apparatus embodiments described below are merely illustrative.
[0240] This embodiment provides a verification processing device that operates on a login terminal, including:
[0241] The verification request generation module 602 is configured to generate a biometric verification request carrying the application account and send it to the server based on the biometric verification instruction submitted by the logged-in user for accessing the service.
[0242] The associated user set receiving module 604 is configured to receive the associated user set returned by the server, which is the set of authorized users corresponding to the application account who have performed biometric verification authorization for accessing the service.
[0243] The biometric acquisition module 606 is configured to determine the target associated user selected by the logged-in user in the associated user set, collect biometric features and upload them to the server for biometric verification.
[0244] An embodiment of a verification processing device provided in this specification is as follows:
[0245] Corresponding to the verification processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a verification processing device for executing the verification processing method provided above. Figure 7 This is a schematic diagram of the structure of a verification processing device provided for one or more embodiments of this specification.
[0246] This embodiment provides a verification processing device, including:
[0247] like Figure 7 As shown, the verification processing device can vary significantly due to differences in configuration or performance. It may include one or more processors 701 and memory 702, where one or more application programs or data may be stored. The memory 702 may be temporary or persistent storage. The application programs stored in the memory 702 may include one or more modules (not shown), each module including a series of computer-executable instructions from the verification processing device. Furthermore, the processor 701 may be configured to communicate with the memory 702 and execute the series of computer-executable instructions stored in the memory 702 on the verification processing device. The verification processing device may also include one or more power supplies 703, one or more wired or wireless network interfaces 704, one or more input / output interfaces 705, one or more keyboards 706, etc.
[0248] In one specific embodiment, the verification processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the verification processing device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0249] Receive a biometric verification request submitted by the login terminal for accessing the service; the biometric verification request carries the application account;
[0250] Query the set of associated users whose authorized users have performed biometric verification authorization for accessing the service, corresponding to the application account, and return the set to the login terminal;
[0251] Receive biometric features collected and submitted by the login terminal, and perform biometric verification based on the target associated user selected in the associated user set;
[0252] The biometric verification result is synchronized to the access service.
[0253] Another embodiment of the verification processing device provided in this specification is as follows:
[0254] Corresponding to the other verification processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a verification processing device for performing the verification processing method provided above. Figure 8 This is a schematic diagram of the structure of a verification processing device provided for one or more embodiments of this specification.
[0255] This embodiment provides a verification processing device, including:
[0256] like Figure 8 As shown, the verification processing device can vary significantly due to differences in configuration or performance. It may include one or more processors 801 and memory 802, where one or more application programs or data may be stored. The memory 802 may be temporary or persistent storage. The application programs stored in the memory 802 may include one or more modules (not shown), each module including a series of computer-executable instructions from the verification processing device. Furthermore, the processor 801 may be configured to communicate with the memory 802 and execute the series of computer-executable instructions stored in the memory 802 on the verification processing device. The verification processing device may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, one or more keyboards 806, etc.
[0257] In one specific embodiment, the verification processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the verification processing device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0258] Based on the biometric verification command submitted by the logged-in user for accessing the service, generate a biometric verification request carrying the application account and send it to the server.
[0259] Receive the set of associated users whose authorized users corresponding to the application account have performed biometric verification authorization for accessing the service, returned by the server;
[0260] The login user selects a target associated user from the associated user set, collects biometric features, and uploads them to the server for biometric verification.
[0261] This specification provides an example of a storage medium as follows:
[0262] Corresponding to the verification processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a storage medium.
[0263] The storage medium provided in this embodiment is used to store computer-executable instructions, which, when executed by a processor, implement the following process:
[0264] Receive a biometric verification request submitted by the login terminal for accessing the service; the biometric verification request carries the application account;
[0265] Query the set of associated users whose authorized users have performed biometric verification authorization for accessing the service, corresponding to the application account, and return the set to the login terminal;
[0266] Receive biometric features collected and submitted by the login terminal, and perform biometric verification based on the target associated user selected in the associated user set;
[0267] The biometric verification result is synchronized to the access service.
[0268] It should be noted that the embodiments concerning the storage medium in this specification and the embodiments concerning the verification processing method in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.
[0269] Another embodiment of the storage medium provided in this specification is as follows:
[0270] In response to another verification method described above, and based on the same technical concept, one or more embodiments of this specification also provide a storage medium.
[0271] The storage medium provided in this embodiment is used to store computer-executable instructions, which, when executed by a processor, implement the following process:
[0272] Based on the biometric verification command submitted by the logged-in user for accessing the service, generate a biometric verification request carrying the application account and send it to the server.
[0273] Receive the set of associated users whose authorized users corresponding to the application account have performed biometric verification authorization for accessing the service, returned by the server;
[0274] The login user selects a target associated user from the associated user set, collects biometric features, and uploads them to the server for biometric verification.
[0275] It should be noted that the embodiments concerning the storage medium in this specification and the embodiments concerning the verification processing method in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can be referred to the implementation of the corresponding method described above, and the repeated parts will not be described again.
[0276] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0277] In the 1930s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many improvements to the methodology today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that an improvement to the methodology cannot be implemented using a hardware physical module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0278] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, ASICs, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0279] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0280] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0281] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0282] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable verification processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable verification processing apparatus, produce a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0283] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable verification processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0284] These computer program instructions may also be loaded onto a computer or other programmable verification processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0285] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0286] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0287] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0288] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0289] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0290] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0291] The above description is merely an embodiment of this document and is not intended to limit the scope of this document. Various modifications and variations can be made to this document by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this document should be included within the scope of the claims of this document.
Claims
1. A verification processing method, applied to a server, comprising: Receive biometric verification requests submitted by the login terminal for accessing the service; The biometric verification request carries the application account; The system queries the set of associated users for the authorized user corresponding to the application account who have performed biometric verification authorization for the access service, and returns the set to the login terminal. The biometric verification authorization includes generating an authorization application reminder based on the authorization information configured on the applicant user terminal and sending it to the authorized user terminal. If the authorized user terminal submits a confirmation response to the authorization application reminder and verifies that the login user of the authorized user terminal is consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for the applicant user for the access service. Receive biometric features collected and submitted by the login terminal, and perform biometric verification based on the target associated user selected in the associated user set; The biometric verification result is synchronized to the access service.
2. The verification processing method according to claim 1, wherein generating the authorization record for the authorized user to perform biometric verification on the requesting user for accessing the service includes: The applicant is designated as an associated user, and an authorization relationship is established between the associated user and the authorized user for biometric verification. Based on the aforementioned authorization relationship, the authorization status is marked as valid. The authorization record is created based on the authorization information and the authorization validity status, and the authorization relationship database is updated.
3. The verification processing method according to claim 1, wherein querying the associated user set of the authorized user corresponding to the application account for biometric verification authorization for accessing the service includes: Based on the application account, query the authorization relationship database for the associated users who have performed biometric verification authorization for the access service; Filter the associated users obtained from the query to those whose authorization status is valid, and construct the associated user set.
4. The verification processing method according to claim 3, wherein the access service includes at least one of the following: a sub-service of the application service, and the application service; The authorization relationship database stores authorization records; the authorization records stored in the authorization relationship database include at least one of the following: sub-service authorization records for biometric verification authorization of associated users by sub-services of the application service, and application service authorization records for biometric verification authorization of associated users by the application service.
5. According to the verification processing method of claim 4, if the verification result is successful, the access service grants access permission to the login terminal for the sub-service based on the first authorization period; The sub-service is executed based on the access permissions obtained, and the execution result is returned to the login terminal; wherein, the first authorization period is included in the authorization record for the sub-service corresponding to the target associated user; or, The access service, based on a second authorization period, grants access permissions to the login terminal for the application service; it then obtains the service data of the application service according to the granted access permissions and sends it to the login terminal; wherein, the second authorization period is included in the authorization record for the application service corresponding to the target associated user.
6. The verification processing method according to claim 1, after the step of querying the associated user set of the authorized user corresponding to the application account for biometric verification authorization of the access service and returning to the login terminal, and before the step of receiving the biometric features collected and submitted by the login terminal and performing biometric verification based on the target associated user selected in the associated user set, further includes: Determine the target associated user selected from the set of associated users, and read the authorization record for the access service corresponding to the target associated user; Detect whether the command parameters of the login terminal match the authorization content contained in the read authorization record; If so, synchronize the detection result to the login terminal.
7. The verification processing method according to claim 1, wherein the biometric verification based on the target associated user selected in the associated user set includes: Read the identity data corresponding to the biometric features; Call a third-party verification interface to verify whether the biometric features and identity data match the biometric features and identity data of the target associated user; If a match is found, the verification result is determined as successful.
8. The verification processing method according to claim 1, after the step of synchronizing the verification result of the biometric verification to the access service is performed, it further includes: Read the authorization record for the access service corresponding to the target associated user; Check whether the authorization type contained in the read authorization record is the target authorization type; If so, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the read authorization record is changed to authorization invalidation status.
9. The verification processing method according to claim 8, if the execution result after the operation of detecting whether the authorization type contained in the read authorization record is the target authorization type is no, the following operation is performed: Check whether the authorization period contained in the read authorization record has expired; If so, the authorization relationship between the authorized user and the target associated user is terminated, and the authorization status contained in the read authorization record is changed to authorization invalidation status.
10. An authentication processing method applied to a login terminal, comprising: Based on the biometric verification command submitted by the logged-in user for accessing the service, generate a biometric verification request carrying the application account and send it to the server. The server receives a set of associated users whose application accounts are authorized to perform biometric verification authorization for accessing the service. The biometric verification authorization includes generating an authorization request reminder based on the authorization information configured on the requesting user's terminal and sending it to the authorized user's terminal. If the authorized user's terminal submits a confirmation response to the authorization request reminder and the login user of the authorized user's terminal is verified to be consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for accessing the service to the requesting user. The login user selects a target associated user from the associated user set, collects biometric features, and uploads them to the server for biometric verification.
11. The verification processing method according to claim 10, wherein generating the authorization record for the authorized user to perform biometric verification for the requesting user regarding the access service comprises: The applicant is designated as an associated user, and an authorization relationship is established between the associated user and the authorized user for biometric verification. Based on the aforementioned authorization relationship, the authorization status is marked as valid. The authorization record is created based on the authorization information and the authorization validity status, and the authorization relationship database is updated.
12. The verification processing method according to claim 10, wherein the associated user set is constructed in the following manner: Based on the application account, query the authorization relationship database for the associated users who have performed biometric verification authorization for the access service; Filter the associated users obtained from the query to those whose authorization status is valid, and construct the associated user set.
13. The verification processing method according to claim 12, wherein the access service includes at least one of the following: a sub-service of the application service, and the application service; The authorization relationship database stores authorization records; the authorization records stored in the authorization relationship database include at least one of the following: sub-service authorization records for biometric verification authorization of associated users by sub-services of the application service, and application service authorization records for biometric verification authorization of associated users by the application service.
14. The verification processing method according to claim 13, after the steps of determining the target associated user selected by the logged-in user in the associated user set, collecting biometric features and uploading them to the server for biometric verification are executed, it further includes: Receive the execution result returned by the access service; The execution result is obtained by performing execution processing on the sub-service after granting access permissions to the sub-service. or, Receive service data of the application service issued by the access service; the service data is obtained after the access permission for the application service is granted.
15. A verification processing apparatus, operating on a server, comprising: The verification request receiving module is configured to receive biometric verification requests submitted by the login terminal for accessing the service. The biometric verification request carries the application account; The associated user set query module is configured to query the associated user set of the authorized user corresponding to the application account who has performed biometric verification authorization for the access service, and return it to the login terminal; the biometric verification authorization includes generating an authorization application reminder based on the authorization information configured on the applicant user terminal and sending it to the authorized user terminal; if the authorized user terminal submits a confirmation response to the authorization application reminder and verifies that the login user of the authorized user terminal is consistent with the authorized user, an authorization record of the authorized user performing biometric verification for the access service to the applicant user is generated; The biometric verification module is configured to receive biometric features collected and submitted by the login terminal, and to perform biometric verification based on the target associated user selected in the associated user set. The verification result synchronization module is configured to synchronize the verification result of the biometric verification to the access service.
16. A verification processing device, operating on a login terminal, comprising: The verification request generation module is configured to generate a biometric verification request carrying the application account and send it to the server based on the biometric verification instruction submitted by the logged-in user for accessing the service. The associated user set receiving module is configured to receive the associated user set returned by the server, which represents the set of authorized users corresponding to the application account who have performed biometric verification authorization for the access service. The biometric verification authorization includes generating an authorization application reminder based on the authorization information configured on the applicant user's terminal and sending it to the authorized user terminal. If the authorized user terminal submits a confirmation response to the authorization application reminder and verifies that the logged-in user of the authorized user terminal is consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for the applicant user for the access service. The biometric data collection module is configured to determine the target associated user selected by the logged-in user in the associated user set, collect biometric data, and upload it to the server for biometric verification.
17. A verification processing apparatus, comprising: processor; And, a memory configured to store computer-executable instructions, which, when executed, cause the processor to: Receive a biometric verification request submitted by the login terminal for accessing the service; the biometric verification request carries the application account; The system queries the set of associated users for the authorized user corresponding to the application account who have performed biometric verification authorization for the access service, and returns the set to the login terminal. The biometric verification authorization includes generating an authorization application reminder based on the authorization information configured on the applicant user terminal and sending it to the authorized user terminal. If the authorized user terminal submits a confirmation response to the authorization application reminder and verifies that the login user of the authorized user terminal is consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for the applicant user for the access service. Receive biometric features collected and submitted by the login terminal, and perform biometric verification based on the target associated user selected in the associated user set; The biometric verification result is synchronized to the access service.
18. A verification processing apparatus, comprising: processor; And, a memory configured to store computer-executable instructions, which, when executed, cause the processor to: Based on the biometric verification command submitted by the logged-in user for accessing the service, generate a biometric verification request carrying the application account and send it to the server. The server receives a set of associated users whose application accounts are authorized to perform biometric verification authorization for accessing the service. The biometric verification authorization includes generating an authorization request reminder based on the authorization information configured on the requesting user's terminal and sending it to the authorized user's terminal. If the authorized user's terminal submits a confirmation response to the authorization request reminder and the login user of the authorized user's terminal is verified to be consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for accessing the service to the requesting user. The login user selects a target associated user from the associated user set, collects biometric features, and uploads them to the server for biometric verification.
19. A storage medium for storing computer-executable instructions, which, when executed by a processor, perform the following process: Receive a biometric verification request submitted by the login terminal for accessing the service; the biometric verification request carries the application account; The system queries the set of associated users for the authorized user corresponding to the application account who have performed biometric verification authorization for the access service, and returns the set to the login terminal. The biometric verification authorization includes generating an authorization application reminder based on the authorization information configured on the applicant user terminal and sending it to the authorized user terminal. If the authorized user terminal submits a confirmation response to the authorization application reminder and verifies that the login user of the authorized user terminal is consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for the applicant user for the access service. Receive biometric features collected and submitted by the login terminal, and perform biometric verification based on the target associated user selected in the associated user set; The biometric verification result is synchronized to the access service.
20. A storage medium for storing computer-executable instructions, which, when executed by a processor, perform the following process: Based on the biometric verification command submitted by the logged-in user for accessing the service, generate a biometric verification request carrying the application account and send it to the server. The server receives a set of associated users whose application accounts are authorized to perform biometric verification authorization for accessing the service. The biometric verification authorization includes generating an authorization request reminder based on the authorization information configured on the requesting user's terminal and sending it to the authorized user's terminal. If the authorized user's terminal submits a confirmation response to the authorization request reminder and the login user of the authorized user's terminal is verified to be consistent with the authorized user, an authorization record is generated in which the authorized user performs biometric verification for accessing the service to the requesting user. The login user selects a target associated user from the associated user set, collects biometric features, and uploads them to the server for biometric verification.
Citation Information
Patent Citations
Authorization method, device, equipment and system based on verifiable declaration
CN110768968A
Account management method, system and device and storage medium
CN110992186A