Verification processing method, device, electronic device and storage medium

By silently performing the second biometric acquisition and verification after the first verification is passed, the security risks caused by the identity identification system in the prior art are solved, and the security and efficiency of sensitive operations are improved.

CN114519177BActive Publication Date: 2025-07-18TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011301152.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-11-19
Publication Date
2025-07-18
Estimated Expiration
2040-11-19

AI Technical Summary

Technical Problem

The existing identity identification system remains authorized for a long time after verification, which affects user security and privacy, especially in devices that respond to sensitive operations, which poses security risks.

Method used

After the first verification is passed, a second unsensed biometric collection is carried out to ensure the safety of sensitive operations. The second biometric collection is collected and verified through silent mode to improve safety.

Benefits of technology

Without affecting the user experience, secondary verification is performed silently, which improves the safety and efficiency of sensitive operations and ensures the legality and reliability of operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114519177B_ABST
    Figure CN114519177B_ABST
Patent Text Reader

Abstract

The present invention provides a verification processing method, apparatus, electronic device, and computer-readable storage medium. The method includes: in response to a trigger operation for an entry of a first operation, presenting a first acquisition preview area to acquire a first biometric feature, and when the verification of the first biometric feature is passed, presenting an execution result of the first operation; in response to a trigger operation for an entry of a second operation, acquiring a second biometric feature in a silent manner, and when the verification of the second biometric feature is passed, presenting an execution result of the second operation; wherein both the first operation and the second operation are sensitive operations that can only be executed when authorized, and the first operation precedes the second operation. Through the present invention, the security of sensitive operations can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to artificial intelligence and security technologies, and in particular, to a verification processing method, apparatus, electronic device, and computer-readable storage medium. Background Art

[0002] Artificial Intelligence (AI) is to use a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, and is a theory, method, technology, and application system that can perceive the environment, acquire knowledge, and use knowledge to obtain the best results. Artificial intelligence is a comprehensive technology in computer science. It attempts to understand the essence of intelligence and produce a new intelligent machine that can react in a way similar to human intelligence. Artificial intelligence also studies the design principles and implementation methods of various intelligent machines to enable the machines to have the functions of perception, reasoning, and decision-making.

[0003] Identity recognition is a typical application of artificial intelligence. For example, a user's identity is authenticated through an authorized face. Typically, for a device that responds to sensitive operations, such as a payment collection device, the security of funds and the security of privacy information are the main concerns of users when using the payment collection device. The identity of the user is recognized, and whether to respond to a sensitive operation is determined based on whether the user is an authorized user.

[0004] Currently, devices that respond to sensitive operations have been widely used in scenarios such as shopping malls and supermarkets. However, current identity recognition systems remain authorized for a long time after a certain verification, and the security and privacy of users are inevitably affected. Summary of the Invention

[0005] Embodiments of the present application provide a verification processing method, apparatus, electronic device, and computer-readable storage medium, which can improve the security of sensitive operations.

[0006] The technical solution of the embodiments of the present application is implemented as follows:

[0007] Embodiments of the present application provide a verification processing method, which is applied to an electronic device and includes:

[0008] In response to a trigger operation for an entry of a first operation, presenting a first acquisition preview area to acquire a first biometric feature, and when the verification of the first biometric feature is passed, presenting an execution result of the first operation;

[0009] In response to a trigger operation for an entry of a second operation, acquiring a second biometric feature in a silent manner, and when the verification of the second biometric feature is passed, presenting an execution result of the second operation;

[0010] Among them, both the first operation and the second operation are sensitive operations that can only be executed when authorized, and the first operation precedes the second operation.

[0011] An embodiment of the present application provides a verification processing device, which is applied to an electronic device and includes:

[0012] A first processing module, configured to present a first acquisition preview area to acquire a first biometric feature in response to a trigger operation for an entry of the first operation, and present an execution result of the first operation when the verification of the first biometric feature is passed;

[0013] A second processing module, configured to acquire a second biometric feature in a silent manner in response to a trigger operation for an entry of the second operation, and present an execution result of the second operation when the verification of the second biometric feature is passed;

[0014] Among them, both the first operation and the second operation are sensitive operations that can only be executed when authorized, and the first operation precedes the second operation.

[0015] In the above solution, when the verification method of the first biometric feature is network verification, the first processing module is further configured to: send the acquired first biometric feature to a server, so that the server performs the following processing: match the first biometric feature with multiple authorized biometric features to determine the identity information corresponding to the matched authorized biometric feature; present the execution result obtained by performing the first operation based on the identity information.

[0016] In the above solution, when the verification method of the first operation is offline verification, the first processing module is further configured to: match the acquired first biometric feature with at least one authorized biometric feature stored in the electronic device to obtain the identity information corresponding to the matched authorized biometric feature; present the execution result of performing the first operation based on the identity information.

[0017] In the above solution, after presenting the first acquisition preview area to acquire the first biometric feature, the first processing module is further configured to: present an area for receiving a first auxiliary verification operation when the verification of the first biometric feature fails; present first input information of the first auxiliary verification operation in the area in response to the first auxiliary verification operation; present the execution result of the first operation when the verification of the first input information is passed.

[0018] In the above solution, the first processing module is further configured to: perform a risk detection on the first operation; when there is a risk in the first operation, present an area for receiving a second auxiliary verification operation; in response to the second auxiliary verification operation, present second input information of the second auxiliary verification operation in the area; when the verification of the second input information is passed, present the execution result of the first operation.

[0019] In the above solution, before collecting the second biometric feature in a silent manner, the second processing module is further configured to: perform a risk detection on the second operation; when there is a risk in the second operation, determine to collect the second biometric feature in a silent manner for verification; when there is no risk in the second operation, determine not to collect the second biometric feature in a silent manner for verification, and determine to directly present the execution result of the second operation.

[0020] In the above solution, the second processing module is further configured to: determine that the second operation has a risk when at least one of the following risk conditions is met: the matching degree obtained when verifying the first biometric feature is lower than the matching degree threshold; the historical security level of the identity information obtained when verifying the first biometric feature is lower than the security level threshold; the time interval between the second operation and the first operation is greater than the time interval threshold.

[0021] In the above solution, the second processing module is further configured to: obtain the scenario data of the scenario to which the second operation belongs to extract the risk features of the scenario; call a neural network model based on the risk features to predict the risk level of the second operation; wherein, the training samples of the neural network model include historical scenario data, and the labeled data of the training samples include the risk levels of the scenarios corresponding to the historical scenario data.

[0022] In the above solution, the second processing module is further configured to: call the biometric feature collection function in the electronic device to collect the second biometric feature, and control the second collection preview area corresponding to the biometric feature collection function to be in a hidden state.

[0023] In the above solution, the second processing module is further configured to: call the biometric feature collection function in the electronic device to collect biometric feature data in real time; perform a live detection process and a quality detection process on the biometric feature data; when the live detection process and the quality detection process on the biometric data are passed, extract the second biometric feature from the real-time biometric data.

[0024] In the above solution, the second processing module is further configured to: when the in-living detection process or the quality detection process of the biological data fails, present a third acquisition preview area corresponding to the biometric acquisition function to acquire a third biometric feature; perform network verification on the third biometric feature, and when the network verification fails, present a prompt message rejecting the second operation.

[0025] In the above solution, after the second biometric feature is acquired in a silent manner, the second processing module is further configured to: during the verification process of the second biometric feature, keep presenting the entry of the second operation and present a first identifier indicating that the second biometric feature is being verified; when the verification of the second biometric feature passes, update the first identifier to a second identifier indicating verification passed; in response to the end of the verification process of the second biometric feature, present a prompt message for prompting to obtain the execution result of the second operation.

[0026] In the above solution, after the second biometric feature is acquired in a silent manner, the second processing module is further configured to: when the verification of the second biometric feature fails, present a fourth acquisition preview area corresponding to the biometric acquisition function to acquire a fourth biometric feature.

[0027] In the above solution, after the second biometric feature is acquired in a silent manner, the second processing module is further configured to: in response to the verification of the second biometric feature passing, cache the second biometric feature in the electronic device to replace the first biometric feature cached in the electronic device; in response to the verification of the second biometric feature failing and the verification of the fourth biometric feature passing, cache the fourth biometric feature in the electronic device to replace the first biometric feature cached in the electronic device; wherein, the first biometric feature cached in the electronic device is cached when the first biometric feature passes the verification.

[0028] In the above solution, after the second biometric feature is acquired, the second processing module is further configured to: compare the second biometric feature with the first biometric feature cached in the electronic device; wherein, the first biometric feature cached in the electronic device is cached when the first biometric feature passes the verification.

[0029] An embodiment of the present application provides an electronic device, including:

[0030] A memory for storing executable instructions;

[0031] A processor for implementing the verification processing method provided by the embodiment of the present application when executing the executable instructions stored in the memory.

[0032] An embodiment of the present application provides a computer-readable storage medium storing executable instructions, which are used to implement the verification processing method provided by the embodiment of the present application when executed by a processor.

[0033] The embodiment of the present application has the following beneficial effects:

[0034] In the case where verification in response to a sensitive operation (the first operation) has been performed, if a new sensitive operation (the second operation) needs to be responded to, silent re-verification is required. Since biometric features are collected in a silent manner, efficient verification can be performed without perception, taking into account both verification efficiency and the security of sensitive operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 is a schematic diagram of the interface of face recognition payment in the related art;

[0036] Figures 2A - 2B is a schematic structural diagram of the verification processing system provided by the embodiment of the present application;

[0037] Figure 3 is a schematic structural diagram of the electronic device provided by the embodiment of the present application;

[0038] Figures 4A - 4D is a schematic flowchart of the verification processing method provided by the embodiment of the present application;

[0039] Figures 5A - 5B is a schematic diagram of the interface of the verification processing method provided by the embodiment of the present application;

[0040] Figures 6A - 6B is a schematic diagram of the interface of the verification processing method provided by the embodiment of the present application;

[0041] Figure 7 is a schematic diagram of the interface of the verification processing method provided by the embodiment of the present application;

[0042] Figure 8 is a logical flowchart of the verification processing method provided by the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0044] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it is understood that "some embodiments" may be the same subset or different subsets of all possible embodiments, and may be combined with each other without conflict.

[0045] In the following description, the terms "first / second / third" are only used to distinguish similar users and do not represent a specific order for the users. It is understood that "first / second / third" can be interchanged in a specific order or sequence when permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0046] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present invention.

[0047] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are described, and the nouns and terms involved in the embodiments of the present application are applicable to the following explanations.

[0048] 1) Identity recognition: The process of matching at least one of the user's biometric features (including face, fingerprint, voiceprint, iris) with the biometric features of an authorized user to determine whether the user is an authorized user and which specific authorized user the user is.

[0049] 2) Identity recognition device: An electronic device used for barcode recognition and face recognition, having the ability to connect to a cash register to provide payment capabilities.

[0050] 3) Payment client mode: A mode in which the payment client runs on a device in the form of a client (such as an instant messaging client like WeChat) to provide payment services. The payment client can be automatically started and run exclusively on the electronic device, independently providing services for the user.

[0051] 4) Payment software development kit (SDK) mode: The payment client runs on an electronic device in the form of an SDK. The payment client is not automatically started and does not run exclusively. It is passively started and provides services by being called through an application programming interface by a client (such as an instant messaging client like WeChat).

[0052] 5) Sensitive operation: An operation that may involve changes to the user's funds or leakage of privacy information, such as payment operations, service activation operations, mini-program login operations, etc.

[0053] 6) Preferred Image: A face image screened by a face recognition preference algorithm. "Preference" refers to liveness detection, quality score detection, etc., used to resist face recognition attack methods such as photos and masks.

[0054] 7) In response to, which is used to indicate the conditions or states on which the executed operations depend. When the dependent conditions or states are met, one or more of the executed operations can be real-time or can have a set delay; without special instructions, there is no restriction on the execution order of the multiple executed operations.

[0055] See Figure 1 , Figure 1 is a schematic diagram of the interface for face recognition payment in the related art. In the face recognition payment process of the related art, the payment client in the electronic device receives a payment request from the user, that is, a trigger operation for the control 303 is received on the page 301. The payment client in the electronic device performs face recognition on the user and jumps to the face recognition page 302. A prompt message for the user to perform face recognition is displayed on the page 302, and the collected face data of the user is presented and it is shown that the processing is in progress on the page 302. After face recognition, it directly jumps to the account confirmation page 305. After receiving a trigger operation for the confirmation control 308, it jumps to the payment in progress page 307 or performs auxiliary verification after face recognition. After performing auxiliary verification based on the mobile phone number through the page 304 or the page 305, it jumps to the payment in progress page 307. Furthermore, the electronic device displays the payment result page 309. After the user triggers the face recognition process, the mobile phone number verification process can be assisted for identity recognition. After the identity is confirmed, in response to the payment operation of the user directly clicking the "Confirm Payment" button, the payment process can be completed, that is, there is only one face recognition process in the above entire process. In the related art, after entering the page for sensitive operations (such as payment, service activation, etc.) after recognition, for the sake of user experience, the waiting time for automatic exit without operation is relatively long, but there is a possibility that the current operator is not the same person as the face recognition user who has been authorized, so there are security risks. In order to improve the security during the face recognition payment process, when a sensitive operation is triggered, the identity of the current operator can be further verified in a lightweight manner to ensure that the operation is indeed initiated by the face recognition user who has been authorized, thereby improving the security of the face recognition payment process.

[0056] The embodiments of the present application provide a verification processing method, apparatus, electronic device, and storage medium, which can improve the security of sensitive operations. The following describes an exemplary application of the electronic device provided by the embodiments of the present application. The electronic device provided by the embodiments of the present application can be implemented as various types of user terminals such as laptop computers, tablet computers, desktop computers, set-top boxes, mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable game devices), or can also be implemented as a server.

[0057] To facilitate the description of the embodiments of the present application, first, the electronic device provided by the embodiments of the present application is described. In some embodiments, the verification processing method provided by the embodiments of the present application can be applied to the offline verification of the terminal and the online verification of the server. Refer to Figure 2A , Figure 2A which is a schematic structural diagram of the verification processing system provided by the embodiments of the present application. The terminal 400-1 is connected to the server 200-1 through the network 300. The network 300 can be a wide area network, a local area network, or a combination of the two. In the verification processing method provided by the embodiments of the present application, there is a collaborative processing method for offline verification and online verification. The terminal 400-1 collects the first biometric feature of the user in response to the first operation of the user, and sends it to the server 200-1 for online matching with the features in the feature library 500-1 to perform online verification of the first biometric feature, and sends the collected user data to the server 200-1. The server 200-1 responds to the first operation according to the recognition result, and returns the execution result of the first operation and the recognition result to the terminal 400-1 for presentation. The terminal 400-1 collects the second biometric feature of the user in response to the second operation of the user, and performs offline matching with the first biometric feature in the terminal 400-1 to perform offline verification of the second biometric feature, and sends the recognition result to the server 200-1. The server 200-1 responds to the second operation according to the recognition result, and returns the execution result of the second operation to the terminal 400-1 for presentation.

[0058] In other embodiments, the verification processing method provided by the embodiments of the present application can also be applied to the offline verification of the terminal. Correspondingly, refer to Figure 2B, which is a schematic structural diagram of the verification processing system provided by the embodiments of the present application. The terminal 400-2 is connected to the server 200-2 through the network 300. The network 300 can be a wide area network, a local area network, or a combination of the two. In the verification processing method provided by the embodiments of the present application, only the offline verification processing method is involved. The terminal 400-2 responds to the user's first operation, collects the user's first biometric feature, and performs offline matching with the features in the feature library 500-2 in the terminal 400-2 to perform offline verification on the first biometric feature, and sends the recognition result to the server 200-2. The server 200-2 responds to the first operation according to the recognition result and returns the execution result of the first operation to the terminal 400-2 for presentation. The terminal 400-2 responds to the user's second operation, collects the user's second biometric feature, and performs offline matching with the first biometric feature in the terminal 400-2 to perform offline verification on the second biometric feature, and sends the recognition result to the server 200-2. The server 200-2 responds to the second operation according to the recognition result and returns the execution result of the second operation to the terminal 400-2 for presentation.

[0059] In some embodiments, the terminal 400-1 and the terminal 400-2 can implement the verification processing method provided by the embodiments of the present application by running a computer program. For example, the computer program can be a native program or software module in the operating system; it can be a local (Native) application (APP, Application), that is, a program that needs to be installed in the operating system to run, such as a payment APP; it can also be a small program, that is, a program that only needs to be downloaded to the browser environment to run; it can also be a small program that can be embedded in any APP. In short, the above computer program can be any form of application program, module or plug-in.

[0060] The embodiments of the present application can be implemented by means of cloud technology. Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or a local area network to achieve data calculation, storage, processing, and sharing. Cloud technology is the general term for network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model, and can form a resource pool, which can be used on demand and is flexible and convenient. Cloud computing technology will become an important support. The background services of the technical network system require a large amount of computing and storage resources.

[0061] As an example, the server 200 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal 400 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal 400 and the server 200 can be directly or indirectly connected through wired or wireless communication methods, which are not limited in the embodiments of the present application.

[0062] See Figure 3 , Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Taking the electronic device as a terminal as an example, Figure 3 The terminal 400-1 shown in the figure includes: at least one processor 410, a memory 450, at least one network interface 420, and a user interface 430. Each component in the terminal 400-1 is coupled together through a bus system 440. It can be understood that the bus system 440 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 440 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 3 all kinds of buses are labeled as the bus system 440.

[0063] The processor 410 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0064] The user interface 430 includes one or more output devices 431 that enable the presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 430 also includes one or more input devices 432, including user interface components that assist the user in input, such as a keyboard, a mouse, a microphone, a touch screen display, a camera, other input buttons, and controls.

[0065] The memory 450 can be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memories, hard disk drives, optical disk drives, etc. The memory 450 optionally includes one or more storage devices that are physically located away from the processor 410.

[0066] The memory 450 includes volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be a read-only memory (ROM), and the volatile memory may be a random access memory (RAM). The memory 450 described in the embodiments of the present application is intended to include any suitable type of memory.

[0067] In some embodiments, the memory 450 is capable of storing data to support various operations. Examples of such data include programs, modules, and data structures, or subsets or supersets thereof, which are described below by way of example.

[0068] The operating system 451 includes system programs for handling various basic system services and performing hardware-related tasks, such as a framework layer, a core library layer, a driver layer, etc., for implementing various initial services and handling hardware-based tasks;

[0069] The network communication module 452 is used to reach other computing devices via one or more (wired or wireless) network interfaces 420. Exemplary network interfaces 420 include: Bluetooth, wireless fidelity (WiFi), and universal serial bus (USB), etc.;

[0070] The presentation module 453 is used to enable the presentation of information (e.g., a user interface for operating peripheral devices and displaying content and information) via one or more output devices 431 associated with the user interface 430 (e.g., a display screen, a speaker, etc.).

[0071] The input processing module 454 is used to detect and translate one or more user inputs or interactions from one of one or more input devices 432.

[0072] The verification processing device provided by the embodiments of the present application is described below. In some embodiments, the verification processing device provided by the embodiments of the present application may be implemented in software, which includes a series of modules. For Figures 2A - 2B the illustrated verification processing system, when the modules in the verification processing device are implanted in the terminal and the server, the verification processing method provided by the embodiments of the present application can be implemented.

[0073] As an example, Figure 3The verification processing device 455 stored in the memory 450 is shown, which can be software in the form of programs and plugins, etc., and includes the following software modules: a first processing module 4551 and a second processing module 4552. These modules are logical, so they can be arbitrarily combined or further split according to the implemented functions. The functions of each module will be described below.

[0074] Next, taking the verification processing method provided by the embodiments of the present application executed by the terminal 400-1 in Figure 2A as an example for illustration. Refer to Figure 4A , Figure 4A is a schematic flowchart of the verification processing method provided by the embodiments of the present application, which will be described in combination with Figure 4A the steps shown.

[0075] Refer to Figure 4A , Figure 4A is a schematic flowchart of the verification processing method provided by the embodiments of the present application, which will be described in combination with Figure 4A the steps 101-104 shown. The steps in steps 101-104 are applied to an electronic device.

[0076] In step 101, in response to a trigger operation for the entry of the first operation, a first acquisition preview area is presented to acquire a first biometric feature.

[0077] As an example, in response to a trigger operation for the entry of the first operation, a first acquisition preview area corresponding to the biometric feature acquisition function in the electronic device is presented to acquire a first biometric feature. The first operation is a sensitive operation that requires authorization. For example, the first operation can be a payment operation, a login operation, an unlocking operation, an asset viewing operation, etc. The first biometric feature is a feature that comes from the initiator of the first operation and can represent the identity of the first operation initiator before authorizing the first operation. For example, a facial feature extracted from the initiator's facial data, a fingerprint feature extracted from the initiator's fingerprint data, an iris feature extracted from the initiator's iris data, etc.

[0078] As an example, the first acquisition preview area can be an area of any shape. For example, a circular area in the electronic device interface. In the circular area displayed in the interface, the real-time biometric data of the initiator will be presented. For example, the facial data is obtained by shooting with the camera of the electronic device. A prompt message can be presented in the interface to prompt the user to make self-adjustments so that the required real-time biometric data is within the circular area. When the required real-time biometric data is within the circular area, the electronic device acquires the real-time biometric data within the circular area, and then extracts the first biometric feature therefrom, such as a facial feature.

[0079] In step 102, when the first biometric verification is passed, the execution result of the first operation is presented.

[0080] In some embodiments, presenting the execution result of the first operation in step 102 can be achieved through the following technical solution: performing a risk detection on the first operation; when there is a risk in the first operation, presenting a region for receiving a second auxiliary verification operation; in response to the second auxiliary verification operation, presenting second input information of the second auxiliary verification operation in the region; when the verification of the second input information is passed, presenting the execution result of the first operation.

[0081] As an example, the user feature (feature to be verified) of the user to be authorized obtained based on the second auxiliary verification operation is a biometric feature or a non-biometric feature different from the first biometric feature. When the first biometric verification is passed, a risk verification can be performed on the first operation. The risk verification is not only for the first operation itself, but also for the initiator of the first operation. For example, the first operation can be an operation directly involving money such as a payment operation, or an operation involving user privacy such as a query operation. The risk of an operation involving money is higher than that of an operation involving user privacy. For various first operations with different risk levels (including the case of no risk in the risk level), different levels of auxiliary verification can be performed. When there is no risk in the first operation, the execution result of the first operation can be directly presented, that is, no auxiliary verification is performed. The higher the risk level of the first operation, the higher the security level of the auxiliary verification adopted. For example, if the first operation is a payment operation, the verification method adopted is the fingerprint verification method. In the fingerprint verification method, the second input information submitted by the user through the second auxiliary verification operation is a fingerprint. After the verification of the fingerprint is passed, the execution result of the first operation is presented, such as the execution result of performing a payment operation.

[0082] In some embodiments, referring to Figure 4B , based on Figure 4A , Figure 4B is a schematic flowchart of the verification processing method provided by the embodiments of the present application. After presenting the first acquisition preview area to acquire the first biometric feature in step 101, the following steps 105-107 can also be executed.

[0083] In step 105, when the verification of the first biometric feature fails, a region for receiving a first auxiliary verification operation is presented.

[0084] As an example, the user characteristics (characteristics to be verified) of the user to be authorized obtained based on the first auxiliary verification operation are biometric characteristics or non-biometric characteristics different from the first biometric characteristic. The first auxiliary verification operation can be an operation of inputting the initiator's phone number, the last four digits of the initiator's phone number, the fingerprint of the initiator, the verification code received by the initiator's phone number, the iris of the initiator, etc. The area for receiving the first auxiliary verification operation can be a specific area for receiving the fingerprint of the initiator or the area for receiving the phone number input by the initiator. Through the auxiliary verification corresponding to the first auxiliary verification operation, when the verification of the first biometric characteristic fails, the first operation can still be verified and authorized through the auxiliary verification corresponding to the first auxiliary verification operation, so that the user can continue to use the service in response to the first operation.

[0085] In step 106, in response to the first auxiliary verification operation, the first input information of the first auxiliary verification operation is presented in the area for receiving the first auxiliary verification operation.

[0086] As an example, if the first auxiliary verification operation is the fingerprint input operation of the initiator, the received first input information, that is, the received fingerprint, can be presented in the area. If the first auxiliary verification operation is to input the initiator's phone number, the received first input information, that is, the received initiator's phone number, can be presented in the area.

[0087] In step 107, when the verification of the first input information passes, the execution result of the first operation is presented.

[0088] In some embodiments, when the verification method of the first biometric characteristic is network verification, in step 102, when the verification of the first biometric characteristic passes, the execution result of the first operation can be presented through the following technical solution: The collected first biometric characteristic is sent to the server so that the server performs the following processing: matching the first biometric characteristic with multiple authorized biometric characteristics to determine the identity information corresponding to the matched authorized biometric characteristic; presenting the execution result obtained by performing the first operation based on the identity information.

[0089] As an example, the collected first biometric characteristic is sent to the server so that the server performs the following processing: matching the first biometric characteristic with multiple authorized biometric characteristics in the user characteristic library to determine the identity information corresponding to the matched authorized biometric characteristic. For example, login state information bound to the identity information is generated; according to the login state information returned by the server, the execution result obtained by performing the first operation based on the identity information is presented, such as the page logged in based on the identity information.

[0090] In some embodiments, when the verification method of the first operation is offline verification, when the first biometric feature is verified successfully in step 102, the execution result of the first operation is presented, which can be achieved through the following technical solution: matching the collected first biometric feature with at least one authorized biometric feature stored in the electronic device to obtain the identity information corresponding to the matched authorized biometric feature; presenting the execution result of the first operation based on the identity information.

[0091] As an example, offline verification is local verification of an electronic device, that is, matching the collected first biometric feature with at least one authorized biometric feature stored in the electronic device. The authorized biometric feature is a biometric feature that has been authorized and authenticated and stored in the operating system of the electronic device, such as facial features, fingerprint features, etc. stored in the operating system of the electronic device. Each authorized and authenticated biometric feature has corresponding identity information, and then presents the execution result of the first operation based on the identity information. For example, the first operation is a login operation requiring login to account A, and the identity information identified by the first biometric feature is the identity information bound to account A. In this case, account A is successfully logged in based on the identity information. If the identity information identified by the first biometric feature is not the identity information bound to account A, account A cannot be successfully logged in based on the identity information, and a prompt message refusing to respond to the first operation is presented.

[0092] In some embodiments, when the first operation is a login page operation based on the first biometric, the second operation is a payment operation based on the second biometric; when the first operation is a payment operation based on the first biometric, the second operation is a merchant mini program login operation based on the second biometric.

[0093] In some embodiments, the first operation may be a login operation of a logged-in member, and the login page of the logged-in member may be the main page of any client after login in the terminal or a page of a sub-function thereof, for example, the main page of a third-party payment client, or a page of a payment function therein, and the login status information is obtained after the member is successfully logged in. After the user successfully logs in, the background will generate a specific information (which may be a string), and this string is a token, which is a mark of identity and status. When the user subsequently receives an operation with the login identity, the client does not need to carry a password, but only needs to carry this token. The background verifies this token to determine whether the subsequent request is a real request of the user himself.

[0094] In step 103, in response to a trigger operation for an entry of a second operation, a second biometric feature is collected in a silent manner.

[0095] As an example, both the first operation and the second operation are sensitive operations that can only be executed when authorized. The first operation precedes the second operation, and the second operation is a sensitive operation that requires authorization. For example, the second operation can be a payment operation, a login operation, an unlocking operation, an asset viewing operation, etc. The second biometric feature is a feature that comes from the initiator of the second operation and can represent the identity of the second operation initiator before authorization for the second operation. For example, a facial feature extracted from the initiator's facial data, a fingerprint feature extracted from the initiator's fingerprint data, an iris feature extracted from the initiator's iris data, etc. The process of collecting the second biometric feature in a silent manner is imperceptible to the user, thus providing a smooth interaction experience for the user while ensuring the security during service usage.

[0096] In some embodiments, silent collection can be the collection of a human face, fingerprints, or voiceprints. Generally, when the second operation is initiated, the position of a person does not change significantly compared to the position when the first operation occurred. Therefore, face data can be directly collected. For fingerprint data, silent fingerprint collection can be performed based on the fingerprints input by the user during the operation on the screen during the second operation, or silent voiceprint collection can be performed based on the voice emitted by the user during the second operation.

[0097] In some embodiments, before performing step 103 to collect the second biometric feature in a silent manner, the following technical solution can also be executed: perform a risk detection on the second operation; when the second operation has a risk, determine to collect the second biometric feature in a silent manner for verification; when the second operation has no risk, determine not to collect the second biometric feature in a silent manner for verification and determine to directly present the execution result of the second operation.

[0098] In some embodiments, risk detection can be not performed, and it can be directly defaulted that all second operations have risks. Thus, once the second operation is received, the second biometric feature is collected in a silent manner. Through this implementation method, the reliability of the operation can be fully ensured. It can also be configured that no risk monitoring is performed for all second operations, and the execution result is directly presented in response to the second operation.

[0099] In some embodiments, the server will detect in real time the real-time data corresponding to various operations returned by the electronic device. Through the real-time data, it can be determined whether it is necessary to perform verification of the second operation based on the second biometric feature. When it is determined according to the real-time data that it is necessary to perform verification of the second operation based on the second biometric feature, obtain the verification configuration file sent by the server, read and execute the sent verification configuration file. Among them, the specific verification method for verifying the second operation is defined in the verification configuration file. When it is determined according to the real-time data that it is not necessary to perform verification of the second operation based on the second biometric feature, the server will not send the verification configuration file.

[0100] As an example, before collecting the second biometric feature in a silent manner, perform a risk detection on the second operation; it is determined that there are risks, at least in the following two situations. When the second operation has a first-level risk, it is determined that the second biometric feature will be collected in a silent manner for verification; when the second operation has a second-level risk, it is determined that the second biometric feature will be collected in a perception manner for verification, that is, the second biometric feature will be collected and verified through a collection and verification implementation method similar to that of authorizing the first operation; when the second operation has no risk, it is not necessary to collect the second biometric feature in a silent manner, and the execution result of the second operation can be presented directly in response to the trigger operation on the entry of the second operation.

[0101] As an example, in the above risk detection of the second operation, by detecting that different conditions are met, it is further determined whether the second operation has risks, and further the risk level of the second operation is determined.

[0102] In some embodiments, the above risk detection of the second operation can be implemented through the following technical solutions: when at least one of the following risk conditions is met, it is determined that the second operation has risks: the matching degree obtained during the verification of the first biometric feature is lower than the matching degree threshold (the first matching degree threshold); the historical security level of the identity information obtained during the verification of the first biometric feature is lower than the security level threshold (the first security level threshold); the time interval between the second operation and the first operation is greater than the time interval threshold (the first time interval threshold).

[0103] As an example, when at least one of the following first risk conditions is met, it is determined that the second operation has a first-level risk: the matching degree obtained during the verification of the first biometric feature is lower than the first matching degree threshold and higher than the second matching degree threshold; the historical security level of the identity information obtained during the verification of the first biometric feature is lower than the first security level threshold and higher than the second security level threshold; the time interval between the second operation and the first operation is greater than the first time interval threshold and less than the second time interval threshold.

[0104] As an example, when at least one of the following second risk conditions is met, it is determined that there is a second-level risk for the second operation: the matching degree obtained during the verification of the first biometric is not higher than the second matching degree threshold; the historical security level of the identity information obtained during the verification of the first biometric is not higher than the second security level threshold; the time interval between the second operation and the first operation is not less than the second time interval threshold.

[0105] As an example, when at least one of the following third risk conditions is met, it is determined that there is no risk for the second operation: the matching degree obtained during the verification of the first biometric is not lower than the first matching degree threshold; the historical security level of the identity information obtained during the verification of the first biometric is not lower than the first security level threshold; the time interval between the second operation and the first operation is not greater than the first time interval threshold.

[0106] In some embodiments, the above-mentioned risk detection for the second operation can be achieved through the following technical solution: obtaining the scenario data of the scenario to which the second operation belongs to extract the risk characteristics of the scenario; calling a neural network model based on the risk characteristics to predict the risk level of the second operation; among them, the neural network model can be trained in a supervised manner, and the training samples used include historical scenario data, and the labeled data of the training samples includes the risk level of the scenario corresponding to the historical scenario data.

[0107] As an example, the scenario data of the usage scenario where the second operation is located can be collected, the risk characteristics can be extracted from the scenario data, and then the neural network model can be called to predict the risk probability corresponding to the risk characteristics. Different risk probabilities correspond to different risk levels. For example, if the risk probability is greater than 70%, it indicates a risk. When the risk probability is greater than 80%, it indicates that the second operation not only has a risk but also has a second-level risk. The risk characteristics include the location where the second operation is initiated, the network access type (such as public network, mobile network, etc.), the version of the software / operating system, the security level of the software, etc.

[0108] In some embodiments, the second biometric can be collected in a silent manner in step 103 through the following technical solution: calling the biometric collection function in the electronic device to collect the second biometric, and controlling the second collection preview area corresponding to the biometric collection function to be in a hidden state.

[0109] As an example, when collecting the second biometric feature, there is no need to present a collection preview area. Only the biometric feature collection function in the electronic device needs to be called to collect the second biometric feature. Since it is a silent method, that is, the second biometric feature is collected in a way that the user is unaware of, the second collection preview area corresponding to the biometric feature collection function is controlled to be in a hidden state, and no information related to collecting the second biometric feature and verifying based on the second biometric feature needs to be presented. Thus, the secondary verification based on the second biometric feature can be completed without the user's awareness, which not only improves the user experience but also enhances security.

[0110] In some embodiments, the above-mentioned calling of the biometric feature collection function in the electronic device to collect the second biometric feature can be achieved through the following technical solutions: Call the biometric feature collection function in the electronic device to collect biometric data in real time; perform liveness detection processing and quality detection processing on the biometric data; when the liveness detection processing and quality detection processing of the biometric data are passed, extract the second biometric feature from the real-time biometric data.

[0111] As an example, the process of collecting the second biometric feature is actually a process of silently obtaining an optimal figure. For example, if the biometric data is face data, perform liveness detection processing and face image quality score detection processing on the face data, so as to determine whether the detected face data comes from real live data, so as to avoid presenting photos and masks in front of the camera, thus deceiving the verification processing system and illegally obtaining authorization for the second operation.

[0112] In some embodiments, the following technical solutions can also be executed: When the liveness detection processing and / or quality detection processing of the biometric data fails, present a third collection preview area corresponding to the biometric feature collection function to collect the third biometric feature; perform network verification on the third biometric feature. When the network verification is passed, present the execution result of the second operation. When the network verification fails, present a prompt message rejecting the second operation.

[0113] As an example, if the liveness detection fails, it indicates that the verified face data is the face data in the photo. If the result of the face image quality score detection is less than the quality score threshold, it indicates that the face is unstable or the light is dim, etc. When the liveness detection process for biometric data fails and / or the quality detection process fails, a third acquisition preview area corresponding to the biometric acquisition function is presented to acquire the third biometric. The third biometric is network-verified through a verification method similar to authorizing the first operation, that is, the acquired third biometric is sent to the server for network verification, so that the server performs the following processing: matching the third biometric with multiple authorized biometrics to determine the identity information corresponding to the matched authorized biometric; presenting the execution result obtained by performing the second operation based on the identity information, that is, equivalent to skipping the process of identifying based on the second biometric. When the network verification fails, a prompt message rejecting the second operation is presented. For example, a prompt message is displayed to prompt the user to perform re-verification. Through the above implementation, the flexibility and security of the verification process can be improved, and multiple verification methods can be provided to the user as much as possible while meeting the operation security, ensuring that the user's operations can be legally responded to without dead ends.

[0114] In some embodiments, referring to Figure 4C , based on Figure 4A , Figure 4C is a schematic flowchart of the verification processing method provided by the embodiments of the present application. After collecting the second biometric in a silent manner in step 103, the following steps 108-109 can also be executed.

[0115] In step 108, during the process of verifying the second biometric, the entry of the second operation is kept presented and a first identifier indicating that the second biometric is being verified is presented; when the verification of the second biometric passes, the first identifier is updated to a second identifier indicating verification passed.

[0116] In step 109, in response to the end of the process of verifying the second biometric, a prompt message for prompting that the execution result of the second operation is being obtained is presented.

[0117] As an example, during the verification of the second biometric feature, the entry for presenting the second operation is maintained and a first identifier indicating that the second biometric feature is being verified is presented; when the verification of the second biometric feature is passed, the first identifier is updated to a second identifier indicating that the verification is passed. Since the verification of the second biometric feature is also a silent and unperceived verification, there is no need to present a collection preview area when collecting the second biometric feature, and no information related to collecting the second biometric feature and verifying based on the second biometric feature needs to be presented. When performing the verification, there is no need to present a verification waiting page either. Only the entry for presenting the second operation is maintained, or the first identifier is displayed on the basis of maintaining the entry for presenting the second operation. For example, a loading pop-up window is used to indicate that the second biometric feature is being verified. Usually, the loading pop-up window does not make the user perceive that a secondary verification is being performed and is used for prompting during the page jump process or the operation response process, so that the secondary verification based on the second biometric feature can be completed without the user's awareness. When the verification of the second biometric feature is passed, the first identifier is updated to the second identifier. For example, a loading pop-up window is used to indicate that the verification is passed. In response to the end of the process of verifying the second biometric feature, a prompt message for prompting that the execution result of the second operation is being obtained is presented, which is equivalent to jumping to a new page (execution result waiting page), improving both the user experience and security.

[0118] In some embodiments, after collecting the second biometric feature in a silent manner in step 103, the following technical solution may further be executed: comparing the second biometric feature with a first biometric feature cached in the electronic device; wherein, the first biometric feature cached in the electronic device is cached when the first biometric feature is verified to be passed.

[0119] In some embodiments, comparing the second biometric feature with the first biometric feature cached in the electronic device may be directly comparing the original biometric data corresponding to the second biometric feature with the original biometric data corresponding to the first biometric feature. For example, comparing the source captured image of the second biometric feature with the source captured image of the first biometric feature.

[0120] As an example, after the first biometric feature is verified to be passed through the foregoing implementation manner, it will be cached in the electronic device within a preset time range. When the cached time exceeds the preset time range, the first biometric feature is deleted from the electronic device, so as to ensure that the cache in the electronic device can be effectively utilized instead of being occupied by biometric features that have lost timeliness.

[0121] In some embodiments, the collected second biometric feature may also be sent to the server, so that the server performs the following processing: matching the second biometric feature with multiple authorized biometric features in the user feature library to determine the identity information corresponding to the matched authorized biometric feature. For example, generating login state information bound to the identity information; presenting the execution result obtained by performing the second operation based on the identity information, such as a login page based on the identity information. This ensures the accuracy of verifying the second biometric feature.

[0122] In step 104, when the verification of the second biometric feature passes, present the execution result of the second operation.

[0123] As an example, both the first operation and the second operation are sensitive operations that can only be performed when authorized, and the first operation is earlier than the second operation.

[0124] In some embodiments, when the verification of the second biometric feature fails, present a fourth collection preview area corresponding to the biometric feature collection function to collect the fourth biometric feature.

[0125] As an example, when the verification of the second biometric feature fails, present a fourth collection preview area corresponding to the biometric feature collection function to collect the fourth biometric feature, and perform network verification on the fourth biometric feature through a verification method similar to authorizing the first operation, that is, sending the collected fourth biometric feature to the server for network verification, so that the server performs the following processing: matching the fourth biometric feature with multiple authorized biometric features to determine the identity information corresponding to the matched authorized biometric feature; presenting the execution result obtained by performing the second operation based on the identity information, and presenting a prompt message rejecting the second operation when the network verification fails. For example, display a prompt message to prompt the user to perform re-verification. Through the above embodiments, the flexibility of the verification process can be improved, and as many verification methods as possible can be provided for the user while meeting the operation security, ensuring that the user's operations can be legally responded to without dead ends.

[0126] In some embodiments, refer to Figure 4D , based on Figure 4A , Figure 4D is a schematic flowchart of the verification processing method provided by the embodiments of the present application. After collecting the second biometric feature in a silent manner in step 103, the following steps 110-111 may also be performed.

[0127] In step 110, in response to the verification of the second biometric feature passing, cache the second biometric feature in the electronic device to replace the first biometric feature cached in the electronic device.

[0128] In step 111, in response to the failure of the second biometric verification and the success of the fourth biometric verification, the fourth biometric is cached in the electronic device to replace the first biometric cached in the electronic device.

[0129] As an example, the first biometric cached in the electronic device is cached when the first biometric is verified successfully. In response to the success of the second biometric verification, the second biometric is cached in the electronic device to replace the first biometric cached in the electronic device. In response to the failure of the second biometric verification and the success of the fourth biometric verification, the fourth biometric is cached in the electronic device to replace the first biometric cached in the electronic device. When subsequent verification is performed, the first biometric used for comparison cached in the electronic device is the most recently obtained biometric, thus ensuring the security and reliability of fast secondary verification offline.

[0130] Next, an exemplary application of the verification processing method provided in the embodiments of the present application in an actual application scenario will be described.

[0131] In some embodiments, refer to Figure 5A , Figure 5A which is a schematic diagram of the interface of the verification processing method provided in the embodiments of the present application. The payment client in the electronic device receives a request from the user to log in to the merchant membership, that is, a trigger operation (the first operation) on the control 502A is received in the page 501A. The payment client in the electronic device performs face recognition on the user and jumps to the face recognition page 503A. A prompt message for the user to perform face recognition is displayed in the page 503A. The face data of the user collected (from which the first biometric is extracted) is presented in the area 504A of the page 503A and it is displayed that the processing is in progress. After face recognition, the user directly logs in to the merchant membership successfully, or after face recognition, auxiliary verification is performed. The auxiliary verification based on the mobile phone number is performed through the page 506A or the page 505A. After the auxiliary verification is passed, the user logs in to the merchant membership successfully and jumps to the page 507A (merchant membership page). The electronic device displays the merchant membership page. If an operation of the user clicking the "confirm payment" button is received in the membership page, in response to the trigger operation (the second operation) on the control 508A in the page 507A, fast secondary verification will be performed. Continue to refer to Figure 5B , Figure 5BIt is a schematic diagram of the interface of the verification processing method provided by the embodiments of the present application. In response to a trigger operation on the control 508B on the page 507B, before paying using the merchant membership balance, a loading pop-up window 509B without preview is first popped up on the page 507B. At this time, the second biometric feature is silently collected. For example, the face data at this time is compared with the face obtained from the previous face recognition within a preset time (such as 2 seconds) (compared with the first biometric feature. For example, it can be compared with the face at the first face recognition cached locally Figure 1 :1 comparison). If the comparison passes, a prompt message 513B indicating successful verification is presented on the page 507B, and the subsequent payment process is continued, that is, it jumps to the page 514B. The payment result is being queried is presented on the page 514B. When the payment is successful, it jumps to the payment success page 515B. If the comparison fails or the comparison score does not meet the standard, the initiator of the payment operation is re-identified by face recognition, and it jumps from the page 507B to the page 510B. A prompt message prompting the user to perform face recognition is displayed on the page 507B. The collected user face data is presented in the area 512B of the page 507B and it is shown that the processing is in progress. After face recognition, the subsequent operations are directly performed in the identity of the initiator of the payment operation, or after face recognition, auxiliary verification is performed. The auxiliary verification based on the mobile phone number is performed through the page 511B. After the auxiliary verification passes, the subsequent operations are performed in the identity of the initiator of the payment operation.

[0132] In some embodiments, refer to Figure 6A , Figure 6A It is a schematic diagram of the interface of the verification processing method provided by the embodiments of the present application. The payment client in the electronic device receives the user's payment request, that is, a trigger operation (the first operation) on the control 603A is received on the page 601A. The payment client in the electronic device performs face recognition on the user (extracting the first biometric feature) and jumps to the face recognition page 602A. A prompt message prompting the user to perform face recognition is displayed on the page 602A. The collected user face data is presented in the page 602A and it is shown that the processing is in progress. After face recognition, it directly jumps to the account confirmation page 606A. After receiving a trigger operation on the confirmation control 607A, it jumps to the payment in progress page 608A or after face recognition, auxiliary verification is performed. After the auxiliary verification based on the mobile phone number is performed through the page 604A or the page 605A, it jumps to the payment in progress page 608A. Furthermore, the electronic device displays the payment result page 609A. After face recognition payment, the user can log in to the merchant mini-program in the identity of the face recognition person and perform subsequent operations. Continue to refer to Figure 6B , Figure 6BIt is a schematic diagram of the interface of the verification processing method provided by the embodiments of the present application. In response to the trigger operation (the second operation) on the control 611B in the page 609B, that is, in response to the electronic device receiving the user's request to click to log in to the applet, a loading pop-up window 614B without preview is first popped up in the page 609B (pop up the loading pop-up window without preview). At this time, the second biometric feature is silently collected. For example, the face data at this time. It is completed within a preset time (for example, 2 seconds) to compare with the face obtained by the previous face recognition (compare with the first biometric feature. For example, compare with the face at the first face recognition cached locally Figure 1 :1 comparison). If the comparison passes, a verification passed prompt message 615B is presented in the page 609B, and the subsequent process is continued, that is, it jumps to the page 616B (the merchant applet page). If the comparison fails or the comparison score does not meet the standard, the initiator of the operation to log in to the applet is re-recognized by face. It jumps from the page 609B to the page 612B. A prompt message for prompting the user to perform face recognition is displayed in the page 612B. The collected user face data is presented in the page 612B and it is displayed that the processing is in progress. After face recognition, the subsequent operation is directly executed in the identity of the operation initiator, or after face recognition, auxiliary verification is performed. The auxiliary verification based on the mobile phone number is performed through the page 613B. After the auxiliary verification passes, the subsequent operation is executed in the identity of the operation initiator.

[0133] In some embodiments, refer to Figure 7 , Figure 7It is a schematic diagram of the interface of the verification processing method provided by an embodiment of the present application. The merchant client in the electronic device receives a request from the user to log in to the merchant membership. The merchant client in the electronic device performs face recognition on the user. After successful face recognition, the user logs in to the merchant membership, and the electronic device displays the merchant membership page. The payment client supports running in the SDK mode in the merchant client. After the user completes face recognition and logs in to the merchant client, the user can further directly make a payment with the current identity. To enhance security, in the process of post-login payment in the SDK mode, a quick secondary verification process is also inserted. If an operation (the second operation) of the user clicking the "face recognition payment" button is received on the membership page 701, before making a payment, a loading pop-up window 702 without preview is popped up on the membership page 701. At this time, the second biometric feature is silently collected. For example, the face data at this time is compared with the face obtained from the previous face recognition within a preset time (such as 2 seconds) (compared with the first biometric feature). If the comparison passes, the subsequent payment process is continued, and the page 705 is jumped to prompt the user that the payment result is being queried. After the payment is completed, the page 706 is jumped to. If the comparison fails, the face recognition of the initiator of the payment operation is performed again, and the page 703 is jumped to. A prompt message for the user to perform face recognition is displayed on the page 703A, and the collected face data of the user is presented on the page 703A and it is shown that the processing is in progress. After face recognition, it directly jumps to the page 705 to prompt the user that the payment result is being queried. After the payment is completed, the page 706 is jumped to, or after face recognition, auxiliary verification is performed. After the auxiliary verification based on the mobile phone number is performed through the page 704, it jumps to the page 705 to prompt the user that the payment result is being queried. After the payment is completed, the page 706 is jumped to.

[0134] In some embodiments, refer to Figure 8 , Figure 8It is a schematic flowchart of the verification processing method provided by an embodiment of the present application. The above rapid secondary verification process includes two core steps: 1. Compare whether the current operator and the previous face-swiping user have the same identity on the client side (without interacting with the background); 2. When the comparison fails, perform face recognition based on background interaction again, confirm the identity of the current operator with the help of the background, and perform subsequent operations with the identity of the current operator. The logical process of rapid secondary verification is described by a finite state machine. After the user triggers a sensitive operation (such as payment, service activation, mini-program login, etc.), the payment client or merchant client enters a "certain critical state". For risk control, "whether secondary verification is required" is optional, and it is determined by the running configuration content whether to enable or disable secondary verification. If secondary verification is required, the camera is turned on to obtain the user's preferred image. During the process of "silently obtaining the preferred image", steps such as live detection and face image quality score detection are performed to avoid the risks of photo verification and mask verification. During the process of "silent recognition", etc., the currently captured face is compared with the face corresponding to the user identity before entering the "critical state". If the similarity is greater than the preset threshold, it is determined that the comparison is successful; otherwise, it enters the "secondary recognition" step, that is, the ordinary face recognition process. The ordinary face recognition process has a preview page, that is, this process is perceivable.

[0135] Next, the implementation of the verification processing device 455 provided by an embodiment of the present application as a software module will be further described. In some embodiments, as Figure 3 shown, the software module stored in the verification processing device 455 in the memory 450 may include: a first processing module 4551, configured to present a first acquisition preview area to acquire a first biometric feature in response to a trigger operation for an entry of a first operation, and present an execution result of the first operation when the verification of the first biometric feature is passed; a second processing module 4552, configured to acquire a second biometric feature in a silent manner in response to a trigger operation for an entry of a second operation, and present an execution result of the second operation when the verification of the second biometric feature is passed; wherein, both the first operation and the second operation are sensitive operations that can only be executed when authorized, and the first operation precedes the second operation.

[0136] In some embodiments, when the verification method of the first biometric feature is network verification, the first processing module 4551 is further configured to: send the acquired first biometric feature to the server, so that the server performs the following processing: match the first biometric feature with multiple authorized biometric features to determine the identity information corresponding to the matched authorized biometric feature; present the execution result obtained by performing the first operation based on the identity information.

[0137] In some embodiments, when the verification method of the first operation is offline verification, the first processing module 4551 is further configured to: match the collected first biometric feature with at least one authorized biometric feature stored in the electronic device to obtain the identity information corresponding to the matched authorized biometric feature; present the execution result of the first operation based on the identity information.

[0138] In some embodiments, after presenting the first acquisition preview area to acquire the first biometric feature, the first processing module 4551 is further configured to: when the verification of the first biometric feature fails, present an area for receiving a first auxiliary verification operation; in response to the first auxiliary verification operation, present the first input information of the first auxiliary verification operation in the area; when the verification of the first input information passes, present the execution result of the first operation.

[0139] In some embodiments, the first processing module 4551 is further configured to: detect the risk of the first operation; when the first operation has a risk, present an area for receiving a second auxiliary verification operation; in response to the second auxiliary verification operation, present the second input information of the second auxiliary verification operation in the area; when the verification of the second input information passes, present the execution result of the first operation.

[0140] In some embodiments, before collecting the second biometric feature in a silent manner, the second processing module 4552 is further configured to: detect the risk of the second operation; when the second operation has a risk, determine to collect the second biometric feature in a silent manner for verification; when the second operation has no risk, determine not to collect the second biometric feature in a silent manner for verification and determine to directly present the execution result of the second operation.

[0141] In some embodiments, the second processing module 4552 is further configured to: determine that the second operation has a risk when at least one of the following risk conditions is met: the matching degree obtained when verifying the first biometric feature is lower than the matching degree threshold; the historical security level of the identity information obtained when verifying the first biometric feature is lower than the security level threshold; the time interval between the second operation and the first operation is greater than the time interval threshold.

[0142] In some embodiments, the second processing module 4552 is further configured to: obtain the scene data of the scene to which the second operation belongs to extract the risk features of the scene; call a neural network model based on the risk features to predict the risk level of the second operation; wherein the training samples of the neural network model include historical scene data, and the labeled data of the training samples include the risk levels of the scenes corresponding to the historical scene data.

[0143] In some embodiments, the second processing module 4552 is further configured to: call the biometric acquisition function in the electronic device to acquire a second biometric, and control the second acquisition preview area corresponding to the biometric acquisition function to be in a hidden state.

[0144] In some embodiments, the second processing module 4552 is further configured to: call the biometric acquisition function in the electronic device to acquire biometric data in real time; perform liveness detection processing and quality detection processing on the biometric data; and extract a second biometric from the real-time biometric data when the liveness detection processing and the quality detection processing on the biometric data are passed.

[0145] In some embodiments, the second processing module 4552 is further configured to: when the liveness detection processing and / or the quality detection processing on the biometric data fails, present a third acquisition preview area corresponding to the biometric acquisition function to acquire a third biometric; perform network verification on the third biometric, and present a prompt message for rejecting the second operation when the network verification fails.

[0146] In some embodiments, after acquiring the second biometric in a silent manner, the second processing module 4552 is further configured to: during the verification of the second biometric, keep presenting the entry of the second operation and present a first identifier indicating that the second biometric is being verified; when the verification of the second biometric is passed, update the first identifier to a second identifier indicating that the verification is passed; and in response to the end of the verification process of the second biometric, present a prompt message for prompting to obtain the execution result of the second operation.

[0147] In some embodiments, after acquiring the second biometric in a silent manner, the second processing module 4552 is further configured to: when the verification of the second biometric fails, present a fourth acquisition preview area corresponding to the biometric acquisition function to acquire a fourth biometric.

[0148] In some embodiments, after acquiring the second biometric in a silent manner, the second processing module 4552 is further configured to: in response to the verification of the second biometric being passed, cache the second biometric in the electronic device to replace the first biometric cached in the electronic device; in response to the verification of the second biometric failing and the verification of the fourth biometric being passed, cache the fourth biometric in the electronic device to replace the first biometric cached in the electronic device; wherein the first biometric cached in the electronic device is cached when the first biometric is verified to be passed.

[0149] In some embodiments, after the second biometric feature is collected, the second processing module 4552 is further configured to: compare the second biometric feature with the first biometric feature cached in the electronic device; wherein, the first biometric feature cached in the electronic device is cached when the first biometric feature is verified successfully.

[0150] An embodiment of the present application provides a computer-readable storage medium storing executable instructions, where the executable instructions, when executed by a processor, cause the processor to execute the verification processing method provided by the embodiment of the present application. For example, as Figures 4A - 4D the verification processing method shown.

[0151] In some embodiments, the storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc, or CD-ROM; or may be various devices including one or any combination of the above memories.

[0152] In some embodiments, the executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including being deployed as an independent program or being deployed as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0153] As an example, the executable instructions may or may not correspond to a file in the file system, may be stored as part of a file that stores other programs or data, for example, in one or more scripts in a Hypertext Markup Language (HTML) document, stored in a single file dedicated to the program in question, or stored in multiple cooperating files (for example, files that store one or more modules, subroutines, or code portions).

[0154] As an example, the executable instructions may be deployed to execute on one computing device, or on multiple computing devices located at one location, or on multiple computing devices distributed at multiple locations and interconnected by a communication network.

[0155] In summary, in the embodiment of the present application, in the case where verification in response to a sensitive operation (the first operation) has been performed, if a new sensitive operation needs to be responded to, silent re-verification is required. Since the biometric feature is collected in a silent manner, secondary verification can be quickly performed without the user's awareness, that is, the security of responding to sensitive operations again is improved while maintaining a good user experience.

[0156] The above are only embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the present invention are all included in the protection scope of the present invention.

Claims

1. A verification processing method, characterized in that, Applied to an electronic device, the method includes: In response to a trigger operation for an entry of a first operation, presenting a first acquisition preview area to acquire a first biometric feature. When the verification of the first biometric feature passes, presenting the execution result of the first operation; In response to a trigger operation for an entry of a second operation, acquiring a second biometric feature in a silent manner, comparing the second biometric feature with the first biometric feature to verify the second biometric feature. When the verification of the second biometric feature passes, presenting the execution result of the second operation; Wherein, both the first operation and the second operation are sensitive operations that can only be executed when authorized, and the first operation precedes the second operation; When the verification of the second biometric feature fails, presenting a fourth acquisition preview area corresponding to the biometric feature acquisition function to acquire a fourth biometric feature; Matching the fourth biometric feature with multiple authorized biometric features to determine the identity information corresponding to the matched authorized biometric feature; presenting the execution result obtained by executing the second operation based on the identity information.

2. The method according to claim 1, wherein When the verification method of the first biometric feature is network verification, the step of presenting the execution result of the first operation when the verification of the first biometric feature passes includes: Sending the acquired first biometric feature to a server so that the server performs the following processing: Matching the first biometric feature with multiple authorized biometric features to determine the identity information corresponding to the matched authorized biometric feature; Presenting the execution result obtained by executing the first operation based on the identity information.

3. The method according to claim 1, characterized in that, Before acquiring the second biometric feature in a silent manner, the method further includes: Performing a risk detection on the second operation; When the second operation has a risk, determining to acquire the second biometric feature in a silent manner for verification; When the second operation has no risk, determining not to acquire the second biometric feature in a silent manner for verification and determining to directly present the execution result of the second operation.

4. The method according to claim 3, wherein The performing a risk detection on the second operation includes: When at least one of the following risk conditions is met, determining that the second operation has a risk: The matching degree obtained when verifying the first biometric feature is lower than the matching degree threshold; The historical security level of the identity information obtained when verifying the first biometric feature is lower than the security level threshold; The time interval between the second operation and the first operation is greater than the time interval threshold.

5. The method according to claim 3, characterized in that, The performing a risk detection on the second operation includes: Obtaining the scene data of the scene to which the second operation belongs to extract the risk features of the scene; Invoking a neural network model based on the risk features to predict the risk level of the second operation; Wherein, the training samples of the neural network model include historical scene data, and the labeled data of the training samples include the risk levels of the scenes corresponding to the historical scene data.

6. The method according to claim 1, characterized in that The acquiring the second biometric feature in a silent manner includes: Invoke the biometric collection function in the electronic device to collect a second biometric, and control the second collection preview area corresponding to the biometric collection function to be in a hidden state.

7. The method according to claim 6, characterized in that, The invoking the biometric collection function in the electronic device to collect a second biometric includes: Invoking the biometric collection function in the electronic device to collect biometric data in real time; Performing a liveness detection process and a quality detection process on the biometric data; When the liveness detection process and the quality detection process on the biometric data pass, extracting a second biometric from the biometric data.

8. The method according to claim 7, wherein The method further includes: When the liveness detection process and / or the quality detection process on the biometric data fails, presenting a third collection preview area corresponding to the biometric collection function to collect a third biometric; Performing network verification on the third biometric, and when the network verification fails, presenting a prompt message rejecting the second operation.

9. The method according to claim 1, wherein After collecting the second biometric in a silent manner, the method further includes: During the process of verifying the second biometric, keep presenting the entry of the second operation and presenting a first identifier indicating that the second biometric is being verified; when the verification of the second biometric passes, update the first identifier to a second identifier indicating verification passed; In response to the end of the process of verifying the second biometric, presenting a prompt message for prompting the execution result of the second operation being obtained.

10. The method according to claim 1, characterized in that, After collecting the second biometric in a silent manner, the method further includes: In response to the verification of the second biometric passing, caching the second biometric in the electronic device to replace the first biometric cached in the electronic device; In response to the verification of the second biometric failing and the verification of the fourth biometric passing, caching the fourth biometric in the electronic device to replace the first biometric cached in the electronic device; Wherein, the first biometric cached in the electronic device is cached when the first biometric passes the verification.

11. The method according to claim 1, characterized in that, The comparing the second biometric and the first biometric includes: Comparing the second biometric with the first biometric cached in the electronic device; Wherein, the first biometric cached in the electronic device is cached when the first biometric passes the verification.

12. A verification processing device, characterized in that, Applied to an electronic device, it includes: A first processing module, configured to, in response to a trigger operation for an entry of a first operation, present a first collection preview area to collect a first biometric, and when the verification of the first biometric passes, present the execution result of the first operation; A second processing module, configured to, in response to a trigger operation for an entry of a second operation, collect a second biometric in a silent manner, compare the second biometric and the first biometric to verify the second biometric, and when the verification of the second biometric passes, present the execution result of the second operation; Wherein, the first operation and the second operation are both sensitive operations that can only be executed when authorized, and the first operation precedes the second operation; when the second biometric verification fails, a fourth acquisition preview area corresponding to the biometric acquisition function is presented to acquire a fourth biometric; the fourth biometric is matched with a plurality of authorized biometrics to determine the identity information corresponding to the matched authorized biometric; and an execution result obtained by executing the second operation based on the identity information is presented.

13. An electronic device, characterized in that, Comprising: a memory for storing executable instructions; a processor, which, when executing the executable instructions stored in the memory, implements the verification processing method according to any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that, Stored with executable instructions, which, when executed by a processor, implement the verification processing method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Application access method and device

    CN108647510A

  • Face recognition method and device, terminal and server

    CN110705451A