Remote Authentication Method and Remote Authentication Device

Through the remote agent device, the user's multiple ID images and facial information is verified, which solves the problem of insufficient remote identity authentication in the prior art, and improves the accuracy of identity authentication and the security of the system.

CN114240443BActive Publication Date: 2025-06-13CHINA CONSTRUCTION BANK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111547803.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-16
Publication Date
2025-06-13
Estimated Expiration
2041-12-16

AI Technical Summary

Technical Problem

The existing remote identity authentication method has problems such as insufficient identity authentication when handling high-risk services, resulting in inaccurate authentication results and low system security.

Method used

The user's multiple ID images are obtained through the remote seat device, including the ID images uploaded by the user, the ID images pre-stored in the database, and the ID images collected in real time, and the image recognition algorithm is compared. Verify the user face information obtained by real-time interaction, and perform identity authentication after meeting the preset threshold.

Benefits of technology

It improves the accuracy of remote identity authentication, reduces the risk of identity impersonation in high-risk business processing, and enhances the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114240443B_ABST
    Figure CN114240443B_ABST
Patent Text Reader

Abstract

The present application provides a remote identity authentication method and a remote identity authentication device, which are applied to the field of security technology and are beneficial to improving the security of remotely handling high-risk services. The method includes: obtaining a first document image, a second document image, and a third document image; based on an image recognition algorithm, pairwise comparing the first document image, the second document image, and the third document image; when the similarity of the first document image, the second document image, and the third document image meets a first preset threshold, real-time collecting a face image of the user from the user device through video; when the similarity between the real-time collected face image of the user and the face image in the first document image, the second document image, or the third document image meets a second preset threshold, the remote seat device authenticates the identity of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security technology, and more specifically, to a remote identity authentication method and a remote identity authentication device. Background Art

[0002] Generally, bank users can handle various services on different occasions. For example, they can conduct transactions through bank cards or modify the limits of bank cards. High-risk services can be considered as those with relatively large transaction amounts or significant limit modification ranges.

[0003] Taking the limit modification service as an example, each bank sets a fixed single-transaction limit for users' transactions. When users conduct transactions using terminal devices, they may be restricted by the fixed limit, which causes inconvenience to users. Currently, there are many remote service handling channels in banks for users to modify limits, such as telephone banking and WeChat self-service banking. During the process of remotely modifying the limit service, users are required to provide identity card information for verification.

[0004] The above-mentioned identity authentication process for handling high-risk services remotely is not rigorous enough, resulting in inaccurate identity authentication results and low system security. Summary of the Invention

[0005] This application provides a remote identity authentication method and a remote identity authentication device, which are beneficial to improving the accuracy of remote identity authentication and thus enhancing the security of the system.

[0006] In a first aspect, a remote identity authentication method is provided, which is applied to a system including a user device and a remote agent device. The method includes: the remote agent device obtains a first certificate image, a second certificate image, and a third certificate image. Among them, the first certificate image is the certificate image uploaded by the user through the user device, the second certificate image is the certificate image of this user pre-stored in the database, and the third certificate image is the certificate image of this user collected in real time by the remote agent device through video from the user device. The remote agent device performs pairwise comparison on the first certificate image, the second certificate image, and the third certificate image based on an image recognition algorithm. When the similarity of the first certificate image, the second certificate image, and the third certificate image meets a first preset threshold, the remote agent device collects the face image of this user in real time through video from the user device. When the similarity between the face image collected in real time of this user and the face image in the first certificate image, the second certificate image, or the third certificate image meets a second preset threshold, the remote agent device passes the identity authentication of this user.

[0007] In this application, the remote agent device can compare the first document image, the second document image, and the third document image obtained in different ways pairwise, which helps to improve the accuracy of document image authentication. And in the case where the document image verification is passed, the user is further authenticated based on the user's face information, which helps to reduce the risk of remotely handling high-risk services and improve the security of the user's property.

[0008] In combination with the first aspect, in some implementation manners of the first aspect, before the remote agent device obtains the first document image, the second document image, and the third document image, the method further includes: when the user uses the user device to pass the self-service identity authentication, the remote agent device receives an authentication request from the user device, and the authentication request is used to request remote identity authentication of the user. The remote agent device obtaining the first document image, the second document image, and the third document image includes: the remote agent device obtaining the first document image, the second document image, and the third document image based on the authentication request.

[0009] In combination with the first aspect, in some implementation manners of the first aspect, the user using the user device to pass the self-service identity authentication includes: the user using the user device to pass the authentication of the bank card transaction password. The user using the user device to pass the authentication of the dynamic SMS verification code. And the user using the user device to pass the authentication of the face information.

[0010] In combination with the first aspect, in some implementation manners of the first aspect, after the remote agent device passes the identity authentication of the user, the method further includes: the remote agent device sending the service handling content to the user device. The remote agent device receiving the service handling confirmation information from the user device. The remote agent device handling the service for the user based on the service handling confirmation information, and sending the service handling result to the user device.

[0011] In combination with the first aspect, in some implementation manners of the first aspect, the method further includes: the remote agent device turning on video recording during the process of the user handling the service through the user device to obtain video recording materials. The remote agent device saving the video recording materials.

[0012] In a second aspect, a remote identity authentication device is provided for executing the method in any one of the possible implementation manners of the first aspect. Specifically, the device includes a module for executing the method in any one of the possible implementation manners of the first aspect.

[0013] In a third aspect, a remote identity authentication device is provided, including a processor coupled to a memory and operative to execute instructions in the memory to implement the method in any possible implementation manner of the first aspect above. Optionally, the device further includes a memory. Optionally, the device further includes a communication interface, and the processor is coupled to the communication interface.

[0014] In a fourth aspect, a processor is provided, including: an input circuit, an output circuit, and a processing circuit. The processing circuit is operative to receive a signal through the input circuit and transmit a signal through the output circuit, such that the processor executes the method in any possible implementation manner of the first aspect above.

[0015] In a specific implementation process, the above-mentioned processor may be a chip, the input circuit may be an input pin, the output circuit may be an output pin, and the processing circuit may be transistors, gate circuits, flip-flops, and various logic circuits, etc. The input signal received by the input circuit may be received and input by, for example but not limited to, a receiver, and the signal output by the output circuit may be output to, for example but not limited to, a transmitter and transmitted by the transmitter. Moreover, the input circuit and the output circuit may be the same circuit, which serves as the input circuit and the output circuit at different times respectively. The present application does not limit the specific implementation manners of the processor and various circuits.

[0016] In a fifth aspect, a processing device is provided, including a processor and a memory. The processor is operative to read instructions stored in the memory, and may receive a signal through a receiver and transmit a signal through a transmitter to execute the method in any possible implementation manner of the first aspect above.

[0017] Optionally, there is one or more processors and one or more memories.

[0018] Optionally, the memory may be integrated with the processor, or the memory and the processor are separately arranged.

[0019] In a specific implementation process, the memory may be a non-transitory memory, such as a read only memory (ROM), which may be integrated with the processor on the same chip or may be separately arranged on different chips. The present application does not limit the type of the memory and the setting manner of the memory and the processor.

[0020] It should be understood that relevant data interaction processes, such as sending indication information, may be a process of outputting indication information from the processor, and receiving capability information may be a process of the processor receiving input capability information. Specifically, the data output by the processing may be output to the transmitter, and the input data received by the processor may come from the receiver. Among them, the transmitter and the receiver may be collectively referred to as a transceiver.

[0021] The processing device in the above fifth aspect may be a chip, and the processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor that realizes its functions by reading software code stored in a memory. The memory can be integrated in the processor or can exist independently outside the processor.

[0022] In a sixth aspect, a computer program product is provided. The computer program product includes a computer program (which can also be referred to as code or instructions). When the computer program is run, it causes a computer to execute the method in any one of the possible implementation manners in the above first aspect.

[0023] In a seventh aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (which can also be referred to as code or instructions). When it runs on a computer, it causes the computer to execute the method in any one of the possible implementation manners in the above first aspect. Description of the Drawings

[0024] Figure 1 It is a schematic diagram of a remote identity authentication system provided by an embodiment of the present application;

[0025] Figure 2 It is a schematic flowchart of a remote identity authentication method provided by an embodiment of the present application;

[0026] Figure 3 It is a schematic flowchart of a self-service identity authentication method provided by an embodiment of the present application;

[0027] Figure 4 It is a schematic flowchart of another remote identity authentication method provided by an embodiment of the present application;

[0028] Figure 5 It is a schematic block diagram of a remote identity authentication device provided by an embodiment of the present application;

[0029] Figure 6 It is a schematic block diagram of another remote identity authentication device provided by an embodiment of the present application. Detailed Embodiments

[0030] For ease of understanding, the terms related to the embodiments of the present application are briefly introduced first.

[0031] 1. Video call: A communication method based on the Internet and mobile Internet, which enables real-time transmission of human voices and images (such as the user's bust, photos, items, etc.) between communication devices.

[0032] 2. Face recognition: A biometric identification technology that identifies a person's identity based on their facial feature information. A series of related technologies that use a camera or webcam to capture images or video streams containing human faces, automatically detect and track human faces in the images, and then perform facial recognition on the detected human faces.

[0033] 3. User device self-service authentication: According to the preset authentication procedures, users can complete some authentication processes on the mobile banking app by themselves, such as SMS verification codes, faces, fingerprints, transaction passwords, etc.

[0034] 4. Remote operator device verification: The process in which a user uses a user device to make a video call with a remote operator device, and the remote operator device remotely verifies the user's identity and document information through methods such as face comparison through identity information online verification, asking the user to present documents and account media, and question-and-answer verification.

[0035] Before introducing the remote identity authentication method and remote identity authentication device provided by the embodiments of the present application, the following points are explained first.

[0036] First, in the embodiments shown below, each term and English abbreviation, such as remote operator device, user device, document image, etc., are exemplary examples given for convenience of description and should not constitute any limitation to the present application. The present application does not exclude the possibility of defining other terms that can achieve the same or similar functions in existing or future protocols.

[0037] Second, in the embodiments shown below, the first, second, and various numerical numbers are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. For example, to distinguish different document images, different thresholds, etc.

[0038] Third, "at least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the preceding and following associated objects. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (item) or multiple items (items). For example, at least one (item) of a, b, and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b, and c, where a, b, and c can be single or multiple.

[0039] In the case where a user urgently needs to make a large - amount transfer, the existing adjustment of the mobile banking transfer limit can be handled through remote service channels such as telephone banking and WeChat self - service banking. Limited by risk control factors, there are certain risks in remotely verifying the user's identity in the existing methods, which may affect the user's property safety.

[0040] In view of this, the embodiments of the present application provide a remote identity authentication method and a remote identity authentication device. In this remote identity authentication method, the remote agent device can perform multiple verifications on the certificate information of the user handling high - risk services remotely, and combine it with the user's face information obtained through real - time interaction for verification, which is beneficial to improving the accuracy of verifying the user's certificate information when handling high - risk services remotely, and thus improving the security of the user's property.

[0041] In the technical solution of the present application, the collection, storage, use, processing, transmission, provision, and disclosure of information such as financial data or user data comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0042] Figure 1 FIG. 100 is a schematic diagram of a remote identity authentication system 100 provided by an embodiment of the present application. The system 100 includes a user device 101 and a remote agent device 102.

[0043] Among them, the user device 101 is used to implement operations such as certificate information collection, SMS verification code verification, transaction password verification, and face information verification. The remote agent device 102 is used to implement operations such as certificate information verification, face information verification, and service handling.

[0044] Optionally, the remote identity authentication system 100 further includes a backend device 103, which is used to verify the user's transaction password, dynamic SMS verification code, and face information.

[0045] It should be understood that the remote agent device 102 and the backend device 103 can be two independent devices or two logically divided devices set inside the same device. The embodiments of the present application do not make any limitations in this regard.

[0046] The user equipment and / or the remote agent equipment in the embodiments of the present application may be a mobile phone, a tablet computer (pad), a computer with wireless transceiver function, a VR terminal, an AR terminal, an MR terminal, an XR terminal, a holographic display terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, or other processing equipment connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal in a fifth-generation mobile communication technology (5G) network, or a terminal in a future evolved network, etc. The embodiments of the present application do not limit this.

[0047] Figure 2 FIG. 4 is a schematic flowchart of a remote identity authentication method 200 provided by an embodiment of the present application. The method 200 may be applied to the above-mentioned remote identity authentication system 100. The steps of the method 200 may be executed by the remote agent equipment, but the embodiments of the present application do not limit this. The method 200 includes the following steps:

[0048] S201, obtain a first certificate image, a second certificate image, and a third certificate image, where the first certificate image is a certificate image uploaded by the user through the user equipment, the second certificate image is a certificate image of the user pre-stored in the database, and the third certificate image is a certificate image of the user collected in real time by the remote agent equipment through video from the user equipment.

[0049] S202, based on an image recognition algorithm, compare the first certificate image, the second certificate image, and the third certificate image pairwise.

[0050] S203, when the similarity of the first certificate image, the second certificate image, and the third certificate image meets a first preset threshold, collect the face image of the user in real time through video from the user equipment.

[0051] S204, when the similarity between the face image of the user collected in real time and the face image in the first certificate image, the second certificate image, or the third certificate image meets a second preset threshold, pass the identity authentication of the user.

[0052] In the embodiments of the present application, the user can remotely handle high-risk services through mobile banking. For example, for the limit modification service. During the process of handling high-risk services, the remote agent equipment can perform cross-verification on multiple certificate images uploaded by the user to verify the correctness of the user's certificate information, and compare the face image in the certificate information with the face image collected in real time, and confirm again whether it is the user himself who remotely handles high-risk services, which can improve the accuracy of certificate verification.

[0053] In addition, the access of the remote agent device can effectively ensure the consistency of the materials before and after handling high-risk business remotely, ensure the basic principle of handling business by the user himself, effectively prevent the risk of impersonation or being coerced to handle business, and is conducive to improving the security of the user's property.

[0054] It should be understood that in the embodiments of the present application, the user can handle high-risk business at any time and place in a scenario with a mobile network without being restricted by many conditions.

[0055] As an optional embodiment, before S201, it includes: when the user uses the user device to perform self-service identity authentication, the remote agent device receives an authentication request from the user device, and the authentication request is used to request remote identity authentication of the user. S201 includes: based on the authentication request, obtaining a first document image, a second document image, and a third document image.

[0056] In the embodiments of the present application, before the remote agent device performs remote identity authentication on the user, the user can also authenticate the user's identity information based on the self-service identity authentication of the user device. In this way, the dual authentication mechanism of self-service identity authentication and remote identity authentication is beneficial to ensuring the accuracy of identity authentication and can be applied to many business operation scenarios with strict financial risk control.

[0057] Figure 3 It is a schematic flowchart of a self-service identity authentication method 300 provided by the embodiments of the present application. The method 300 can be applied to the above-mentioned remote identity authentication system 100. The steps of the method 300 can be executed before the steps of the method 200, but the embodiments of the present application do not limit this. The method 300 includes the following steps:

[0058] S301, the user device displays a transaction password input box.

[0059] In this step, the user can input the transaction password in the transaction password input box of the user device. Optionally, the user device can display the transaction password in a desensitized manner.

[0060] S302, the user device encrypts the transaction password input by the user.

[0061] Exemplarily, the user device can encrypt the transaction password according to the dynamically negotiated encryption rule. The embodiments of the present application do not limit the encryption method.

[0062] S303, the user device sends the encrypted transaction password to the backend device. Correspondingly, the backend device receives the encrypted transaction password.

[0063] S304, The backend device decrypts and authenticates the encrypted transaction password. If the authentication is successful, S305 is executed; if the authentication fails, S301 is returned.

[0064] Exemplarily, the user can enter the transaction password three times. If all three authentications fail, the service is terminated.

[0065] S305, The backend device sends a dynamic SMS verification code to the user device. Correspondingly, the user device receives the dynamic SMS verification code.

[0066] S306, The user device displays a verification code input box.

[0067] S307, The user device sends the dynamic SMS verification code entered by the user to the backend device. Correspondingly, the backend device receives the dynamic SMS verification code.

[0068] S308, The backend device authenticates the dynamic SMS verification code. If the authentication is successful, S309 is executed; if the authentication fails, S305 is returned.

[0069] Exemplarily, the user can enter the dynamic SMS verification code three times. If all three authentications fail, the service handling is terminated.

[0070] S309, The user device collects the user's face information.

[0071] In this step, the user device collects the user's face information through the camera. Exemplarily, the user makes corresponding body movements in a well-lit place according to the prompts, including facing the camera directly, blinking, nodding up and down, shaking the head left and right, opening and closing the mouth, etc.

[0072] S310, The user device sends the user's face information to the backend device. Correspondingly, the backend device receives the user's face information.

[0073] S311, The backend device performs face recognition to obtain the face similarity.

[0074] In this step, the backend device can compare the face information obtained based on S310 with the pre-stored face information of this user in the background database through a face recognition algorithm to obtain the face similarity.

[0075] S312, The backend device determines the user's identity based on the face similarity and a preset threshold.

[0076] In this step, the backend device can judge whether the face information obtained based on S310 and the pre-stored face information of this user correspond to the same user based on the face similarity obtained in S311 and the preset threshold. If so, S313 is executed; if not, the service handling is terminated.

[0077] S313, the backend device detects whether the acquired face information is a photo through a three-dimensional face detection algorithm. If not, S314 is executed, and if yes, the service processing is terminated.

[0078] S314, the backend device sends a self-service identity authentication success message to the user device. Correspondingly, the user device receives the self-service identity authentication success message.

[0079] It should be understood that the self-service identity authentication in the embodiments of the present application may include authenticating the user's bank card transaction password, authenticating the dynamic SMS verification code, and authenticating the facial information. During the self-service identity authentication process, it can be performed in the order of authenticating the transaction password, authenticating the dynamic SMS verification code, and authenticating the facial information, or it can be performed in the order of authenticating the dynamic SMS verification code, authenticating the transaction password, and authenticating the facial information. In the embodiments of the present application, the authentication order of the transaction password, dynamic SMS verification code, and facial information is not limited.

[0080] The above method 300 introduces the process of a user completing self-service identity authentication through a user device. After the self-service identity authentication is successful, the user device can send an authentication request to the remote agent device, and the authentication request is used to request remote identity authentication for the user.

[0081] Figure 4 4 is a schematic flow chart of another remote identity authentication method 400 provided in an embodiment of the present application. The method 400 can be applied to the above-mentioned remote identity authentication system 100, and the steps of the method 400 can be performed in the steps of the method 300, but the embodiment of the present application does not limit this. The method 400 includes the following steps:

[0082] S401, the user equipment collects the user's certificate information.

[0083] For example, the user can log in to the mobile banking application (APP) in the user device to handle the limit modification service. After the user chooses to handle the limit modification service, the mobile banking APP can call the camera of the user device, and the user can use the user device to place the ID card, bank card and other documents in the scanning frame of the camera in turn. The built-in software of the user device can automatically scan the documents and add a watermark "Only for lifting the mobile banking transfer limit service yyyy-mm-ddh:mm:ss" to the scanned image to obtain the first document image. At the same time, the user device scans and extracts the document number information, including the ID card number on the ID card and the bank card number on the bank card.

[0084] S402: The user device sends a first ID image and ID number information to a remote agent device. Correspondingly, the remote agent device receives the first ID image and ID number information.

[0085] S403, the remote agent device obtains the second ID image.

[0086] In this step, the remote agent device can obtain the second ID image of the user from the database through the network.

[0087] S404, the remote agent device obtains the third ID image.

[0088] In this step, the remote agent device can prompt the user to hold IDs such as ID cards and bank cards, and display the ID information on the real-time interaction interface. The remote agent device can trigger the system to automatically capture the image information of the user holding the ID in the real-time interaction interface to obtain the third ID image.

[0089] S405, the remote agent device compares the first ID image, the second ID image, and the third ID image through an image recognition algorithm. If the comparison is successful, S406 is executed; if the comparison fails, it is considered that there is an error in the ID information provided by the user, and there is a risk in the business operation, and the business handling is terminated.

[0090] In this step, the remote agent device can compare the ID information in the first ID image, the ID information in the second ID image, and the ID information in the third ID image pairwise through an image recognition algorithm. Such cross-verification is conducive to improving the accuracy of ID information authentication.

[0091] When the similarity between the first ID image and the second ID image, the similarity between the first ID image and the third ID image, and the similarity between the second ID image and the third ID image all meet the first preset threshold, then the ID information verification passes.

[0092] S406, the remote agent device captures the user's face image in real time.

[0093] In this step, the remote agent device can trigger the system to automatically capture the face image information in the real-time interaction interface.

[0094] S407, the remote agent device performs face recognition. If the face recognition is successful, S408 is executed; if the face recognition fails, the business handling is terminated.

[0095] In this step, the remote agent device can compare the face image of the user captured in real time with the face image in the first ID image, the second ID image, or the third ID image through face recognition technology, and judge whether the similarity of face recognition meets the second preset threshold. Only when it meets can the remote identity authentication pass. This is conducive to ensuring that the user himself / herself is carrying the user's valid ID to handle the business, which is conducive to improving the security of the user's property.

[0096] Optionally, method 400 further includes S408: The remote agent device sends the content of business handling to the user device. Correspondingly, the user device receives the content of business handling.

[0097] Exemplarily, the content of business handling may include modifying the transaction limit.

[0098] Optionally, method 400 further includes S409: The user device sends a confirmation message to the remote agent device.

[0099] In this step, the user himself / herself faces the camera of the user device and confirms the business handling. The user device sends a confirmation message to the remote agent device in response to the user's operation of confirming the business handling. Correspondingly, the remote agent device receives the confirmation message.

[0100] Optionally, method 400 further includes S410: The remote agent device performs online real-time approval based on the confirmation message. If the approval is passed, S411 is executed; if the approval fails, the business handling is terminated.

[0101] Exemplarily, the remote agent device may send an approval request to the backend device for online real-time approval.

[0102] Optionally, method 400 further includes S411: The remote agent device sends the approval result to the user device. Correspondingly, the user device receives the approval result.

[0103] Optionally, method 400 further includes S412: The remote agent device starts video recording during the process of the user handling business through the user device and obtains video recording materials.

[0104] Optionally, method 400 further includes S413: The remote agent device saves the video recording materials.

[0105] In the embodiments of the present application, the remote agent device can perform triple cross-comparison verification of the identity document information based on the identity document images uploaded by the user himself / herself, the identity document images obtained from the database through networking, and the identity document images collected from the real-time interaction interface, and perform face recognition in combination with the face information of the user obtained in the real-time interaction interface. This is conducive to improving the accuracy of identity document information verification, effectively ensuring the consistency of the information before and after during the long-term handling of remote services, further ensuring the basic principle of the user handling business by himself / herself, and can effectively reduce the risk of impersonation or being coerced to handle business, making it possible to remotely and real-time handle high-risk services such as limit adjustment.

[0106] Optionally, before the steps of method 400, the user device may display a prompt page, which includes notes for prompting remote authentication. The user can access the remote agent device by clicking the "Enter Remote Authentication" option displayed on the user device, and the customer service representative performs identity authentication processing through the remote agent device. The system can push the image data uploaded by the user in the self-service identity authentication session to the remote agent device in advance, and the remote agent device reviews whether the uploaded image data meets the requirements. If it does not meet the requirements, it will return to the link where it does not meet the requirements to re-upload the data. After the user re-uploads the image data, the user can directly access the remote agent device and give priority to connecting to the original customer service representative. After the customer service representative reviews the image data through the remote agent device and finds it correct, the remote identity authentication begins.

[0107] In some possible scenarios, a user's mobile banking may be bound to multiple user devices. In such a scenario, if the user needs to modify the limit, then the user first needs to unbind the multiple user devices. For example, if the user's mobile banking is bound to two mobile phones and the user wants to increase the limit, the user needs to first unbind the old mobile phone and wait for 15 minutes before conducting the transaction.

[0108] To unbind the old mobile phone, the user can go to the bank branch with the user's valid ID card, the signed account, and the new mobile phone to handle the unbinding. Or the user can log in to the mobile banking on the old mobile phone to unbind. Or the user can use the online banking shield to log in to the personal online banking to unbind. However, the user may not have the conditions for self-service handling. For example, the user has not opened or does not carry the online banking shield, the online banking shield is lost, the old mobile phone cannot be used, it is inconvenient to use the computer and there is an urgent need to transfer money. Therefore, the unbinding operation will bring inconvenience to the user and affect the user experience.

[0109] The remote identity authentication method provided by the embodiments of the present application is not limited by the number of user devices bound to the mobile banking. Even in the case of binding multiple user devices, there is no need to perform an unbinding operation, which is convenient for the user to carry out business in a timely manner and is beneficial to improving the convenience and timeliness of the user's business operations.

[0110] In the above text, in combination with Figures 1 to 4 , the remote identity authentication method according to the embodiments of the present application has been described in detail. Next, in combination with Figure 5 and Figure 6 the remote identity authentication device according to the embodiments of the present application will be described in detail.

[0111] Figure 5 FIG. shows a schematic block diagram of a remote identity authentication device 500 provided by an embodiment of the present application. The device 500 includes an acquisition module 510 and a processing module 520.

[0112] Among them, the acquisition module 510 is used to: acquire a first certificate image, a second certificate image, and a third certificate image, where the first certificate image is a certificate image uploaded by the user through the user device, the second certificate image is a certificate image of the user pre-stored in the database, and the third certificate image is a certificate image of the user acquired in real time from the user device through a video. The processing module 520 is used to: perform pairwise comparison on the first certificate image, the second certificate image, and the third certificate image based on an image recognition algorithm; when the similarity of the first certificate image, the second certificate image, and the third certificate image meets a first preset threshold, acquire the face image of the user in real time from the user device through a video; and when the similarity between the face image of the user acquired in real time and the face image in the first certificate image, the second certificate image, or the third certificate image meets a second preset threshold, authenticate the identity of the user.

[0113] Optionally, the device 500 further includes a receiving module, configured to receive an authentication request from the user device when the user uses the user device to perform self-service identity authentication, where the authentication request is used to request remote identity authentication for the user. The acquisition module 510 is used to: acquire a first certificate image, a second certificate image, and a third certificate image based on the authentication request.

[0114] Optionally, the user uses the user device to perform self-service identity authentication, including: the user uses the user device to authenticate through the bank card transaction password. The user uses the user device to authenticate through the dynamic SMS verification code. And the user uses the user device to authenticate through the face information.

[0115] Optionally, the device 500 further includes a sending module, configured to send service handling content to the user device. The receiving module is used to: receive the service handling confirmation information from the user device. The processing module 520 is used to: handle the service for the user based on the service handling confirmation information. The sending module is used to: send the service handling result to the user device.

[0116] Optionally, the acquisition module 510 is used to: start video recording during the process of the user handling the service through the user device, and acquire the recording materials. The processing module 520 is used to: save the recording materials.

[0117] In an alternative example, those skilled in the art can understand that the device 500 may specifically be the remote seat device in the above embodiment, or the functions of the remote seat device in the above embodiment may be integrated in the device 500. The above functions may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. The device 500 may be used to execute each process and / or step corresponding to the remote seat device in the above method embodiment.

[0118] It should be understood that the device 500 herein is embodied in the form of functional modules. The term "module" herein may refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a proprietary processor or a group of processors, etc.) for executing one or more software or firmware programs, and a memory, a combined logic circuit and / or other suitable components that support the described functions. In the embodiments of the present application, Figure 5 the device 500 in may also be a chip or a chip system, for example: a system on chip (SoC).

[0119] Figure 6 FIG. is a schematic block diagram of another remote identity authentication device 600 provided by the embodiments of the present application. The device 600 includes a processor 610, a transceiver 620 and a memory 630. Among them, the processor 610, the transceiver 620 and the memory 630 communicate with each other through an internal connection path. The memory 630 is used to store instructions, and the processor 610 is used to execute the instructions stored in the memory 630 to control the transceiver 620 to send signals and / or receive signals.

[0120] It should be understood that the device 600 may specifically be the remote agent device in the above embodiments, or the functions of the remote agent device in the above embodiments may be integrated in the device 600. The device 600 may be used to execute the respective steps and / or processes corresponding to the remote agent device in the above method embodiments. Optionally, the memory 630 may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type. The processor 610 may be used to execute the instructions stored in the memory, and when the processor executes the instructions, the processor may execute the respective steps and / or processes corresponding to the remote agent device in the above method embodiments.

[0121] It should be understood that in the embodiments of the present application, the processor 610 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0122] In the implementation process, the steps of the above method can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or can be executed and completed by the combination of the hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor executes the instructions in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0123] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by the combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0124] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0125] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.

[0126] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0127] In addition, the functional units in each embodiment of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0128] When the above-mentioned functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0129] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claimed rights.

Claims

1. A remote identity authentication method, characterized in that, applied to a system including a user device, a remote agent device and a backend device, the method comprising: When the user uses the user device to perform self-service identity authentication and the remote agent device receives an authentication request from the user device, the remote agent device acquires a first certificate image, a second certificate image and a third certificate image, wherein the first certificate image is a certificate image uploaded by the user through the user device, the second certificate image is a pre-stored certificate image of the user in the database, and the third certificate image is a certificate image of the user collected in real time by the remote agent device through video from the user device; wherein, the self-service identity authentication is an authentication performed by the backend device on the user's bank card transaction password, dynamic SMS verification code and face information using the user device; the authentication request is used to request remote identity authentication of the user; the remote agent device performs pairwise comparison on the first certificate image, the second certificate image and the third certificate image based on an image recognition algorithm; When the similarity of the first certificate image, the second certificate image and the third certificate image meets a first preset threshold, the remote agent device collects the user's face image in real time through video from the user device; When the similarity of the face image collected in real time of the user and the face image in the first certificate image, the second certificate image or the third certificate image meets a second preset threshold, the remote agent device passes the user's identity authentication.

2. The method according to claim 1, characterized in that, the remote agent device acquiring the first certificate image, the second certificate image and the third certificate image includes: The remote agent device acquires the first certificate image, the second certificate image and the third certificate image based on the authentication request.

3. The method according to claim 2, characterized in that, the user using the user device to perform self-service identity authentication includes: the user using the user device to perform authentication through the bank card transaction password; the user using the user device to perform authentication through the dynamic SMS verification code; and, the user using the user device to perform authentication through the face information.

4. The method according to any one of claims 1 to 3, characterized in that, after the remote agent device passes the user's identity authentication, the method further includes: the remote agent device sends business handling content to the user device; the remote agent device receives business handling confirmation information from the user device; the remote agent device handles the business for the user based on the business handling confirmation information and sends a business handling result to the user device.

5. The method according to claim 4, characterized in that, the method further includes: the remote agent device starts video recording during the process of the user handling business through the user device to obtain video materials; the remote agent device saves the video materials.

6. A remote identity authentication device, characterized in that, it is applied to a remote agent device, and the device includes: a receiving module, configured to receive an authentication request from the user device when the user uses the user device to perform self-service identity authentication; the authentication request is used to request remote identity authentication of the user; an obtaining module, configured to obtain a first certificate image, a second certificate image, and a third certificate image when the receiving module receives the authentication request from the user device, wherein the first certificate image is a certificate image uploaded by the user through the user device, the second certificate image is a pre-stored certificate image of the user in the database, and the third certificate image is a certificate image of the user collected in real time from the user device through video; wherein, the self-service identity authentication is an authentication performed by the backend device on the user's bank card transaction password, dynamic SMS verification code, and face information of the user using the user device; a processing module, configured to perform pairwise comparison on the first certificate image, the second certificate image, and the third certificate image based on an image recognition algorithm; the processing module is further configured to: when the similarity of the first certificate image, the second certificate image, and the third certificate image meets a first preset threshold, collect the face image of the user in real time from the user device through video; the processing module is further configured to: when the similarity between the face image of the user collected in real time and the face image in the first certificate image, the second certificate image, or the third certificate image meets a second preset threshold, pass the user's identity authentication.

7. The device according to claim 6, characterized in that, the obtaining module is specifically configured to: based on the authentication request, obtain the first certificate image, the second certificate image, and the third certificate image.

8. The device according to claim 7, characterized in that, the user uses the user device to perform self-service identity authentication, including: the user uses the user device to perform authentication through the bank card transaction password; the user uses the user device to perform authentication through the dynamic SMS verification code; and, the user uses the user device to perform authentication through the face information.

9. The device according to claim 7 or 8, characterized in that, the device further includes a sending module, configured to: send business handling content to the user device; the receiving module is configured to: receive business handling confirmation information from the user device; the processing module is further configured to: handle the business for the user based on the business handling confirmation information; the sending module is further configured to: send a business handling result to the user device.

10. The device according to claim 9, characterized in that, the obtaining module is configured to: start video recording during the process of the user handling the business through the user device, and obtain video materials; the processing module is configured to: save the video materials.

11. A remote identity authentication device, characterized in that, it includes: A processor, the processor being coupled to a memory, the memory being configured to store a computer program, and when the processor invokes the computer program, causing the device to perform the method according to any one of claims 1 to 5.

12. A computer-readable storage medium, characterized in that it is configured to store a computer program, the computer program including instructions for implementing the method according to any one of claims 1 to 5.

13. A computer program product, characterized in that it includes a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Remote account opening method and system based on identity information verification

    CN107016608A