An identity authentication method, device and system

By scanning surrounding terminal devices to obtain identity information and type, and judging the credibility of the environment, password-free payment is realized, which solves the problem of repeated verification when making payments on different terminal devices within the application, and improves user experience and payment security.

CN114648333BActive Publication Date: 2025-12-09PETAL CLOUD TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202011516393.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-21
Publication Date
2025-12-09
Estimated Expiration
2040-12-21

AI Technical Summary

Technical Problem

Different types of terminal devices have the problem of repeatedly verifying user identity when making in-app payments, which affects the user experience. In particular, mobile phones require verification every time, and smartwatches and large-screen display devices require cumbersome operation by relying on mobile phones.

Method used

The first terminal device scans nearby connected second terminal devices to obtain user identity information and device type, and determines the credibility of the device usage environment. If the environment is credible, the password-free payment process is executed; otherwise, it is pushed to the third terminal device to execute the non-password-free payment process.

Benefits of technology

Reduce the number of times users need to manually verify their identity, improve the payment experience, and ensure payment security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114648333B_ABST
    Figure CN114648333B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides an identity authentication method, device and system. When detecting that a user submits a commodity payment request, a first terminal device scans at least one second terminal device connected therewith; the first terminal device acquires user identity information of the at least one second terminal device; the first terminal device determines whether a current device use environment is trusted according to the user identity information and the device type of the at least one second terminal device; if the current device use environment is trusted, the first terminal device executes a password-free payment process, or pushes a payment process to a third terminal device; if the current device use environment is not trusted, the first terminal device executes a non-password-free payment process. Thus, the identity authentication method provided by the embodiment of the present application can reduce the number of times of manual identity authentication of a user, or reduce the number of times of manual scanning of a two-dimensional code by the user to switch a payment device, improve the payment experience of the user, and guarantee the payment security of the user.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of terminal, and in particular, to an identity verification method, device and system. BACKGROUND

[0002] There are various kinds of terminal devices in the Internet of Things, and each kind of terminal device has different focuses in function. Therefore, when performing some functions, some terminal devices can perform independently, and some terminal devices need to be assisted by other devices interconnected therewith to perform. Taking an in-app purchase (IAP) function as an example: a terminal device such as a mobile phone can generally complete an in-app purchase process independently. For example, when a user operates the mobile phone to purchase goods in an application program, the application program will invoke the in-app purchase program of the mobile phone; the in-app purchase program will guide the user to perform identity verification such as fingerprint or password, and after the identity verification is passed, the application program will submit a payment request to a payment server and receive a payment result returned by the payment server, thereby completing the payment process. However, a smart watch and a large-screen display device generally convert a payment uniform resource locator (URL) into a two-dimensional code and display the two-dimensional code on a display screen. The user can use a scanning function of a mobile payment application to scan the two-dimensional code on the smart watch or the large-screen display device, so as to transmit the payment URL to the mobile phone, and complete the payment process on the mobile phone.

[0003] It can be seen that the implementation manners of in-app purchase for different kinds of terminal devices are different. However, no matter which implementation manner is used, there is a problem of affecting user experience. For example: the terminal device such as the mobile phone needs to verify the user identity every time the in-app purchase is performed, which causes repeated verification and affects user payment experience; and the smart watch and the large-screen display device need to be assisted by the mobile phone to perform the in-app purchase, which involves starting a payment application on the mobile phone, using a scanning function of the payment application to scan the two-dimensional code on the smart watch or the large-screen display device, and performing identity verification in the payment application, and the operation is too cumbersome, which affects user experience. SUMMARY

[0004] Embodiments of the present application provide an identity verification method, device and system, to solve the problem that the user needs to manually perform identity verification too many times in the prior art, which affects user payment experience.

[0005] In a first aspect, an identity verification method is provided, which includes: when detecting that a user submits a commodity payment request, a first terminal device scans at least one second terminal device connected therewith in a surrounding; the first terminal device acquires user identity information of the at least one second terminal device; the first terminal device determines whether a current device use environment is trustworthy according to the user identity information and a device type of the at least one second terminal device, wherein the device type is acquired from the second terminal device when the first terminal device establishes a connection with the second terminal device; if the current device use environment is trustworthy, the first terminal device executes a password-free payment process, or the first terminal device pushes a payment process to a third terminal device, so that the third terminal device executes a non-password-free payment process in place of the first terminal device; if the current device use environment is not trustworthy, the first terminal device executes a non-password-free payment process.

[0006] In the embodiments of the present application, the first device may, for example, be a mobile phone or a large-screen display device, the second device may, for example, be a mobile phone, a smart watch, a large-screen display device, a smart speaker, a gateway device, a smart appliance or the like connected with the second device in a surrounding of the second device, and the user identity information may, for example, be a user account. When a user uses the first device to purchase a commodity and needs to make a payment, the first device may determine whether a current device use environment is trustworthy according to user accounts and device types of the surrounding second devices. For example, if there are multiple second devices whose user accounts are the same as that of the first device and the device types of the second devices can represent that the user is in a relatively safe environment such as at home, the current device use environment is trustworthy. The first device may execute a password-free payment process when it is determined that the current device use environment is trustworthy. For example, if the first device is a mobile phone, the password-free payment process may be directly executed on the mobile phone, so that the user does not need to manually perform identity verification. If the first device is a large-screen display device, the payment process may be actively pushed to a mobile phone of the user, and then the password-free payment process is executed on the mobile phone. Thus, the identity verification method provided in the embodiments of the present application can reduce the number of times of manual identity verification of the user and improve the user payment experience while ensuring the payment security of the user.

[0007] In an implementation manner, the first terminal device stores weight values of at least one device type, each device type includes a first weight value and a second weight value, and the first weight value of each device type is greater than the second weight value.

[0008] In an implementation manner, the first terminal device determines whether the current device usage environment is trusted according to the user identity information and the device type of the at least one second terminal device, comprising: the first terminal device determines trusted devices with the same user identity information as itself from the at least one second terminal device; the first terminal device respectively determines a weight value of each trusted device according to the device type of the trusted device; the first terminal device adds the weight values of all the trusted devices to obtain a current device usage environment score; and the first terminal device determines whether the current device usage environment is trusted according to the current device usage environment score.

[0009] In an implementation manner, the weight value of the trusted device is a first weight value of the device type to which the trusted device belongs.

[0010] In an implementation manner, the first terminal device determines whether the current device usage environment is trusted according to the user identity information and the device type of the at least one second terminal device, comprising: the first terminal device respectively determines a weight value of each second terminal device according to the user identity information and the device type of the second terminal device; the first terminal device adds the weight values of all the second terminal devices to obtain a current device usage environment score; and the first terminal device determines whether the current device usage environment is trusted according to the current device usage environment score.

[0011] In an implementation manner, the first terminal device respectively determines a weight value of each second terminal device according to the user identity information and the device type of the second terminal device, comprising: when the user identity information of the first terminal device is the same as that of the second terminal device, the weight value of the second terminal device is equal to a first weight value of the device type of the second terminal device; and when the user identity information of the first terminal device is different from that of the second terminal device, the weight value of the second terminal device is equal to a second weight value of the device type of the second terminal device.

[0012] In an implementation manner, the first terminal device determines whether the current device usage environment is trusted according to the current device usage environment score, comprising: if the current device usage environment score is in a first score interval, the first terminal device determines that the current device usage environment is trusted; and if the current device usage environment score is in a second score interval, the first terminal device determines that the current device usage environment is not trusted; wherein the first score interval is higher than the second score interval. In this way, the first terminal device can score the current device usage environment according to the user identity information, the type, the number and the weight value of the second terminal device, the higher the current device usage environment score is, the higher the trustworthiness of the current device usage environment is, and when the score reaches the first score interval, it is determined that the current device usage environment is trusted.

[0013] In an implementation manner, the device types at least include one or more of a large-screen display device, a smart watch, a mobile phone, a smart speaker and a notebook computer, wherein the first weight value of the large-screen display device is greater than the first weight values of the remaining device types.

[0014] In an implementation manner, the second weight value of each device type is 0.

[0015] In an implementation manner, the first terminal device pushes the payment process to the third terminal device, including: the first terminal device sends messenger information to the third terminal device, and the messenger information is used to instruct the third terminal device to execute the non-password-free payment process. In this way, the method of the embodiment of the present application can reduce the number of times that the user switches the payment device by manually scanning the two-dimensional code, and improve the user payment experience through the payment process pushing manner.

[0016] In an implementation manner, the third terminal device is determined by the first terminal device from at least one second terminal device, and the third terminal device includes a device of a specified type, or a device specified by a user in advance, or a device currently in an active state.

[0017] In an implementation manner, the first terminal device scans at least one second terminal device connected thereto around when detecting that the user submits a commodity payment request, including: the first terminal device scans at least one second terminal device connected thereto around when detecting that the user submits a commodity payment request according to a merchant authentication result of a payment server.

[0018] In an implementation manner, the first terminal device scans at least one second terminal device connected thereto around when detecting that the user submits a commodity payment request according to a merchant authentication result of a payment server, including: the first terminal device sends merchant authentication information to the payment server when detecting that the user submits a commodity payment request, so that the payment server performs legality verification on the merchant according to a signature of the merchant authentication information to obtain a merchant authentication result, and the merchant authentication result includes merchant legal and merchant illegal; the first terminal device receives the merchant authentication result sent by the payment server; and the first terminal device scans at least one second terminal device connected thereto around when the received merchant authentication result is merchant legal. In this way, the first terminal device only scans the second terminal device in the case of merchant legal, avoiding unnecessary scanning processes.

[0019] In an implementation manner, the first terminal device scans at least one second terminal device connected thereto around, including: the first terminal device scans at least one second terminal device connected thereto around through a wireless communication module.

[0020] In an implementation manner, the wireless communication module comprises a wireless fidelity (Wi-Fi) module and / or a Bluetooth module, and the first terminal device scans at least one second terminal device around the first terminal device and wirelessly connected to the first terminal device, comprising: the first terminal device invokes the Wi-Fi module to scan at least one second terminal device around the first terminal device and wirelessly connected to the first terminal device via Wi-Fi, and / or the first terminal device invokes the Bluetooth module to scan at least one second terminal device around the first terminal device and wirelessly connected to the first terminal device via Bluetooth.

[0021] In an implementation manner, the first terminal device acquires user identity information of the at least one second terminal device, comprising: the first terminal device sends user identity request information to each second terminal device respectively; and the first terminal device receives user identity information sent by each second terminal device in response to the user identity request information.

[0022] In an implementation manner, when the first terminal device is a mobile phone and the current device usage environment is trusted, the first terminal device performs a password-free payment process.

[0023] In an implementation manner, when the first terminal device is a large-screen display device and the current device usage environment is trusted, the first terminal device pushes a payment process to a third terminal device.

[0024] In a second aspect, the embodiments of the present application provide an identity verification apparatus used as a first terminal device, comprising a processor and a memory, a transceiver, the memory and the processor; wherein the memory comprises program instructions, and the program instructions are run by the processor to enable the first terminal device to perform the method of the first aspect and each implementation manner thereof.

[0025] In a third aspect, the embodiments of the present application provide an identity verification system, comprising: a first terminal device and at least one second terminal device; the first terminal device is configured to scan at least one second terminal device connected therewith when detecting that a user submits a commodity payment request; the first terminal device is further configured to send user identity request information to each of the scanned second terminal devices respectively; the second terminal device is configured to send its own user identity information to the first terminal device in response to the user identity request information; the first terminal device is further configured to determine whether a current device usage environment is trustworthy according to user identity information and a device type of the at least one scanned second terminal device, wherein the device type is obtained from the second terminal device when the first terminal device establishes a connection with the second terminal device; the first terminal device is further configured to execute a password-free payment process when the current device usage environment is trustworthy, or push a payment process to a third terminal device, so that the third terminal device takes over the first terminal device to execute a non-password-free payment process; and the first terminal device is further configured to execute a non-password-free payment process when the current device usage environment is untrustworthy.

[0026] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores instructions, and when the instructions are run on a computer, the computer is caused to execute the method of the above aspects and various implementation manners thereof.

[0027] In a fifth aspect, the embodiments of the present application further provide a computer program product containing instructions, and when the instructions are run on a computer, the computer is caused to execute the method of the above aspects and various implementation manners thereof.

[0028] In a sixth aspect, the embodiments of the present application further provide a chip system, which comprises a processor configured to support the functions involved in the above aspects, for example, generating or processing the information involved in the above method. BRIEF DESCRIPTION OF DRAWINGS

[0029] Figure 1 FIG. 1 is a schematic diagram of an identity verification interface according to an embodiment of the present application;

[0030] Figure 2 FIG. 2 is a schematic diagram of a smart watch or a large-screen display device completing an in-application payment process by means of a mobile phone according to an embodiment of the present application;

[0031] Figure 3 FIG. 3 is a schematic diagram of a large-screen display device displaying a two-dimensional code according to an embodiment of the present application;

[0032] Figure 4 FIG. 4 is a schematic diagram of a hardware structure of a terminal device according to an embodiment of the present application;

[0033] Figure 5 is a networking scenario diagram of an IoT network shown by an embodiment of the present application;

[0034] Figure 6 is a schematic diagram of a software architecture of a terminal device shown by an embodiment of the present application;

[0035] Figure 7 is a schematic diagram of a user purchasing goods in an application shown by an embodiment of the present application;

[0036] Figure 8 is a schematic diagram of a payment page shown by an embodiment of the present application;

[0037] Figure 9 is a timing diagram of a terminal device independently completing an in-application payment process shown by an embodiment of the present application;

[0038] Figure 10 is a flowchart of step S101 of an identity verification method provided by an embodiment of the present application;

[0039] Figure 11 is a flowchart of step S102 of an identity verification method provided by an embodiment of the present application;

[0040] Figure 12 is a schematic diagram of a user purchasing goods in an application shown by an embodiment of the present application;

[0041] Figure 13 is a timing diagram of a terminal device completing an in-application payment process with the aid of other devices shown by an embodiment of the present application;

[0042] Figure 14 is a flowchart of an identity verification method provided by an embodiment of the present application for a password modification or password retrieval scenario;

[0043] Figure 15 is a flowchart of an identity verification method provided by an embodiment of the present application for a scenario of receiving sensitive information;

[0044] Figure 16 is a schematic diagram of an identity verification apparatus provided by an embodiment of the present application. DETAILED DESCRIPTION

[0045] With the development of Internet of Things (IoT) technology, the number and variety of terminal devices owned by users or households are increasing. For example, a user's terminal devices may include: traditional devices such as mobile phones and tablets; wearable devices such as wristbands and smartwatches; audio interaction devices such as smart speakers; large-screen display devices such as smart TVs and smart screens; security devices such as smart door locks and smart cameras; and smart gateway devices. These terminal devices are interconnected through one or more communication protocols such as wireless networks, Wi-Fi, Bluetooth, Bluetooth mesh, and Zigbee to exchange commands and data, thereby jointly realizing the functions of a wide range of IoT scenarios.

[0046] Generally, different types of terminal devices have different physical forms and focus on different functions. For example, mobile phones are highly portable and powerful, and can independently perform many functions, but functions such as heart rate monitoring and blood glucose monitoring still require the assistance of other wearable devices; smartwatches are highly portable, but their screens are small and not as convenient to operate as mobile phones and other terminal devices; smart screens have large screen sizes and strong home-use features, making them suitable for watching audio and video content, but they are not convenient to operate.

[0047] Because different types of terminal devices have different functional focuses, some terminal devices can perform certain functions independently, while others need the assistance of other interconnected devices to perform them.

[0048] Taking in-app payment (IAP) function as an example:

[0049] Mobile devices and other terminal devices can generally complete in-app payment processes independently. For example, when a user uses their mobile phone to purchase goods within an application, that application will invoke the phone's in-app payment program; the in-app payment program will then display a pop-up message such as... Figure 1 The interface shown prompts the user to enter a payment password or verify their fingerprint. After the user enters the payment password or verifies their fingerprint, the application submits a payment request to the payment server and receives the payment result returned by the payment server, thus completing the payment process.

[0050] For smartwatches and large-screen display devices, in-app payment processes may require the use of connected terminal devices. Figure 2is a schematic diagram of a smart watch or a large-screen display device completing an in-application payment process by means of a mobile phone. Among them, the smart watch generally completes the in-application payment process by means of a mobile phone and other terminal devices due to the small size of the display screen. When a user opens an application program in the smart watch, selects and confirms to purchase a commodity in the application program, the smart watch can send a purchase request to the server of the application program as shown in Figure 2 The server of the application program receives the purchase request, generates a corresponding order, and then returns the payment uniform resource locator (URL) corresponding to the order to the smart watch. The smart watch converts the payment URL into a two-dimensional code and displays it on the display screen. At this time, the user can use the code scanning function of the mobile phone payment application to scan the two-dimensional code on the smart watch to transmit the payment URL to the mobile phone side. The mobile phone generates order information such as commodity name and price according to the payment URL, and displays the order information to the user. After the user confirms the commodity information and price, the user can click the payment button (such as continue payment, confirm payment, etc.) in the payment application program page. At this time, the payment application requires the user to perform identity verification, such as inputting a payment password or verifying a fingerprint. After the identity verification is passed, the mobile phone submits a payment request to the payment server corresponding to the payment application, and the payment server returns the payment result to the smart watch after completing the payment processing.

[0051] In addition, the large-screen display device is operated by a remote controller, and it is very inconvenient to use the remote controller to select a commodity and input a payment password (such as inputting numbers and letters, etc.). Therefore, it is also common to use a method similar to the smart watch to complete the in-application payment process by means of a mobile phone and other terminal devices. For example Figure 3 As shown in

[0052] As can be seen, the implementation methods of in-application payment for different types of terminal devices are different, but there are problems affecting user experience in any implementation method, for example: the terminal device such as a mobile phone needs to verify the user's identity every time the in-application payment is performed, which causes repeated verification and affects the user's payment experience; and the smart watch and the large-screen display device need to use a mobile phone to implement in-application payment, which involves starting a payment application on the mobile phone, using the code scanning function of the payment application to scan the two-dimensional code of the smart watch and the large-screen display device, and performing identity verification in the payment application, which is too cumbersome and affects the user experience.

[0053] In order to improve the user experience of the in-application payment process, the embodiments of the present application provide an identity verification method, which can be applied to a terminal device, for example, a mobile phone, a tablet computer, a large-screen display device, a notebook computer, a desktop personal computer, a workstation, a smart speaker with a display screen, a smart alarm clock with a display screen, an electric appliance device with a display screen (for example, a smart refrigerator), an augmented reality (AR) device, a virtual reality (VR) device, a mixed reality (MR) device, and the like.

[0054] Figure 4 is a schematic diagram of the hardware structure of the terminal device shown in the embodiments of the present application. As shown in Figure 4 the terminal device 100 can include a processor 110, a memory 120, a mobile communication module 130, a wireless communication module 140, a camera 150, a display screen 160, a touch sensor 170, and the like.

[0055] The processor 110 can include one or more processing units, for example, the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), and the like. Among them, different processing units can be independent devices, or can be integrated in one or more processors, for example, integrated in a system on a chip (SoC).

[0056] The memory 120 can be configured to store data and computer-executable program codes. The computer-executable program codes can include instructions. The memory 120 can include one or more memory units. For example, the memory 120 can include a volatile memory, such as a dynamic random access memory (DRAM), a static random access memory (SRAM), or the like, and / or a non-volatile memory, such as a read-only memory (ROM), a flash memory, or the like. The processor 110 can perform various functions of the terminal device 100 by executing instructions stored in the memory 120 and / or instructions stored in the memory disposed in the processor.

[0057] The mobile communication module 130 can provide solutions for cellular mobile communication, including 2G / 3G / 4G / 5G, and the like, applied to the terminal device 100. The mobile communication module 130 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), and the like. The mobile communication module 130 can receive electromagnetic waves by the antenna 141, and perform filtering, amplification, and the like on the received electromagnetic waves, and transmit the processed electromagnetic waves to the modem processor for demodulation. In some embodiments, at least part of the functional modules of the mobile communication module 130 can be disposed in the processor 110. In some embodiments, at least part of the functional modules of the mobile communication module 130 and at least part of the modules of the processor 110 can be disposed in the same device.

[0058] The modem processor can include a modulator and a demodulator. The modulator can be configured to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator can be configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator can transmit the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor can be transmitted to the application processor. The application processor can output a sound signal through an audio device (including but not limited to a speaker, a receiver, and the like), or display an image or a video through the display screen 160. In some embodiments, the modem processor can be a separate device. In other embodiments, the modem processor can be independent of the processor 110, and disposed in the same device as the mobile communication module 130 or other functional modules.

[0059] The wireless communication module 140 can include a Wi-Fi module, a Bluetooth module, a global navigation satellite system (GNSS) module, a near field communication (NFC) module, an infrared (IR) module, and the like. The wireless communication module 140 can be one or more devices that integrate at least one of the above modules.

[0060] The camera 150 is configured to capture still images or videos. The camera 150 includes a lens and a photosensitive element. An object projects an optical image through the lens to the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, which is then transmitted to an ISP to be converted into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into an image signal in a standard format, such as RGB, YUV, RYYB, and the like. In some embodiments, the terminal device 100 can include one or N cameras 150, where N is a positive integer greater than 1.

[0061] The display screen 160 is configured to display images, videos, and the like. The display screen 160 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-OLED, a quantum dot light emitting diode (QLED), and the like. In some embodiments, the terminal device 100 can include one or N display screens 160, where N is a positive integer greater than 1.

[0062] The touch sensor 170 can be disposed on the display screen 160, and the touch sensor 170 and the display screen 160 together form a touch screen, also referred to as a "touch panel". The touch sensor 170 is configured to detect a touch operation acting on or near the touch sensor 170. The touch sensor 170 can transmit the detected touch operation to the application processor to determine a touch event type. A visual output related to the touch operation can be provided through the display screen 160. In some other embodiments, the touch sensor 170 can also be disposed on the surface of the terminal device 100, at a position different from the position of the display screen 160.

[0063] It can be understood that the structure shown in the embodiments of the present application does not constitute a specific limitation on the terminal device 100. In some other embodiments of the present application, the terminal device can include more or fewer components than shown, or combine certain components, or split certain components, or different component arrangements. The components shown can be implemented in hardware, software, or a combination of software and hardware.

[0064] Figure 5 is a networking scenario diagram of an IoT network shown in the embodiments of the present application. As shown in Figure 5 , the IoT network can include one or more terminal devices 100, and some or all of the terminal devices 100 can access the same Wi-Fi network through a router 200 or the like, or can be interconnected through one or more communication protocols such as Bluetooth, Bluetooth mesh, zigbee, etc., to exchange instructions and data. In addition, some terminal devices 100 can access the Internet 300 through a Wi-Fi network or a cellular mobile network, and establish a communication connection with a server 400 or the like in the Internet. Among them, the terminal device used to implement the identity verification method provided in the embodiments of the present application can be any one of the terminal devices 100 in the IoT network described above.

[0065] Figure 6 is a schematic diagram of a software architecture of a terminal device shown in the embodiments of the present application. The software architecture can run in the terminal device, and is used to implement the identity verification method provided in the embodiments of the present application. As shown in Figure 6 , the software architecture can include, from bottom to top, an operating system, an IAP service, and a merchant application. Among them:

[0066] The merchant application can include various application programs providing commodity purchase functions, game applications, browser web pages, fast applications, and other implementation forms, etc. For example, a video application program providing functions such as pay-per-view and video membership, a game application program providing functions such as in-game card recharge and virtual item purchase, etc.

[0067] The IAP service is used to implement an in-application payment function of a terminal device. When a user purchases a product in an application of a merchant, the application completes a judgment and decision process in a payment process through an application programming interface (API) provided by the IAP service, including identity verification.

[0068] Figure 6 A logical architecture of the IAP service is also exemplarily shown. The IAP service can include an in-application payment checkout module and an environment perception module. In addition, as an exemplary implementation, the environment perception module can further include a policy management unit, a factor management unit, a trusted computing unit, an account device management unit, a scanning management unit, and a decision routing unit, and the like. The embodiments of the present application do not make specific limitations on the unit composition of the environment perception module. In some other implementation, the environment perception module can include fewer units or more units, or the functions of multiple units can be concentrated in one unit for implementation, which does not exceed the protection scope of the embodiments of the present application.

[0069] It needs to be supplemented that the IAP service of the embodiments of the present application can be part of a system service provided by a terminal device, which can be, for example, huawei mobile services (HMS), google mobile services (GMS), and the like, which is not limited in the embodiments of the present application.

[0070] An operating system is used to manage hardware resources, software resources, and user accounts of a computer. Different kinds and different manufacturers of terminal devices can run different operating systems, such as Harmony OS, Google fuchsia, Android, iOS, and the like. The embodiments of the present application do not make limitations thereon.

[0071] It needs to be supplemented that the in-application payment in the embodiments of the present application can support at least three types of products, which are consumable products, non-consumable products, and subscription products, as shown in Table 1 below:

[0072]

[0073] The identity verification method provided by the embodiments of the present application will be specifically described below in combination with specific application scenarios. It needs to be explained here that in the embodiments of the present application, the terminal device corresponds to the first terminal device in the claims, the other device corresponds to the second terminal device in the claims, and the target device corresponds to the third terminal device in the claims.

[0074] Embodiment One

[0075] Embodiment one of the present application is applied to the scenario that the terminal device independently completes the in-application payment process.

[0076] For example, when the merchant application is a game application, the user purchases a virtual item in the game, such as Figure 7 As shown, the user can click 11 the icon 12 of the virtual item in the game interface to select the virtual item; next, the user can click 13 the "purchase" button 14 in the options popped up in the game interface, at which time the game application invokes the IAP service through the API provided by the IAP service, and passes the information such as the product name, the amount, the payment currency, the user ID, and the merchant ID to the IAP service. After the IAP service is invoked, an order is generated according to the received information, and a to-be-paid page of the order is displayed on the display screen of the terminal device.

[0077] Figure 8 is a schematic diagram of the to-be-paid page shown in the embodiments of the present application. As shown Figure 8 The to-be-paid page may, for example, include information such as the product name, the product amount, the coupon information, the to-be-paid amount, and selectable payment method information, such as Huawei Pay payment, flower coin payment, and bank card payment. When the IAP service detects that the user has selected a payment method on the to-be-paid page and clicked 15 the "confirm payment" 16, it means that the IAP service has detected that the user has submitted a product payment request.

[0078] Based on Figure 6 the logical architecture of the IAP service shown, the functions of the IAP service of generating an order, displaying a to-be-paid page, and detecting a user's submission of a product payment request can be implemented by an in-application payment checkout module. For example, when the user clicks the "purchase" button in the game interface, the game application invokes the in-application payment checkout module of the IAP service through the API provided by the IAP service; the in-application payment checkout module displays the to-be-paid page on the display screen of the terminal device according to the information passed by the game application, and then, when the in-application payment checkout detects that the user has selected a payment method on the to-be-paid page and clicked "confirm payment", it means that the in-application payment checkout has detected that the user has submitted a product payment request.

[0079] Figure 9 is a timing diagram of the terminal device independently completing the in-application payment process according to the embodiments of the present application.

[0080] As shown Figure 9 The terminal device independently completing the in-application payment process can include the following steps S101-S109:

[0081] When the IAP service of the terminal device detects that the user has submitted a product payment request, the IAP service sends merchant authentication information to the payment server.

[0082] In a specific implementation, step S101 can be performed by an IAP service of the terminal device. When the IAP service detects a user-submitted payment request for a product, the IAP service sends merchant authentication information to the payment server, where the merchant authentication information can be generated by an in-application payment cash register module of the IAP service and sent to the payment server.

[0083] The merchant authentication information may, for example, include one or more of a product name, an amount, a payment currency, a user ID, a merchant ID, a terminal device type, and a device ID, which can be used by the payment server to verify the legality of the merchant and report the specific content of the user's purchase of the product to the merchant server associated with the merchant ID to request the merchant server to issue the product, and the like.

[0084] In an implementation, to improve the security of in-application payment, the terminal device and the payment server can use an encrypted manner to transmit data, for example, using a transport layer security (TLS) protocol to encrypt the transmission of data. Taking the IAP service sending merchant authentication information to the payment server as an example, an in-application payment cash register module in the IAP service can use an asymmetric encryption algorithm (such as an RSA algorithm) or a symmetric encryption algorithm (such as an AES algorithm) to encrypt and sign the merchant authentication information, and then send the signed merchant authentication information to the payment server, which can ensure that the merchant request information cannot be intercepted and tampered with during transmission.

[0085] In a specific implementation, the payment server can pre-allocate a set of keys to each merchant, and different merchants have different keys, which can be symmetric keys or asymmetric keys. Taking the asymmetric key as an example, a set of keys includes a public key and a private key. The payment server can pre-distribute the private keys of various merchants to the terminal device, and itself save the public key. When the IAP service detects a payment request for a product, the IAP service can determine the corresponding private key according to the merchant ID, and then use the private key to encrypt and sign the merchant authentication information, and then send it to the payment server.

[0086] Step S102, after receiving the merchant authentication information, the payment server verifies the legality of the merchant according to the merchant authentication information.

[0087] In practice, the payment server can verify whether a merchant is already registered with the payment server based on the merchant ID. When the merchant authentication information is signed and encrypted, the payment server can verify the merchant's legitimacy by performing a signature verification on the merchant authentication information. For example, when the merchant authentication information is signed using the RSA algorithm, the payment server can use its public key to decrypt the merchant authentication information. If the merchant ID and other information are successfully decrypted, and the merchant ID confirms that the merchant is already registered with the payment server, then the merchant is authenticated as legitimate. After completing the merchant legitimacy verification, the payment server can send the verified merchant authentication result to the terminal device.

[0088] Step S103: The terminal device receives the merchant authentication result sent by the payment server.

[0089] Understandably, merchant authentication results can fall into two categories: either the merchant is legitimate or the merchant is illegitimate. When the authentication result is that the merchant is illegitimate, the terminal device displays a payment failure message on the screen. This payment failure message can be generated by the in-app payment checkout module.

[0090] In step S104, when the terminal device receives the merchant's legitimate authentication result sent by the payment server, it scans at least one other device connected to it in the vicinity.

[0091] In practice, the terminal device can use its Wi-Fi module to scan for other devices in the vicinity that it connects to via Wi-Fi, and / or its Bluetooth module to scan for other devices in the vicinity that it connects to via Bluetooth. If a device connected to it via Wi-Fi or another device connected to it via Bluetooth is detected, information such as the device's identifier and device type can be recorded. It should be noted that connecting the terminal device to other devices via Wi-Fi can include the terminal device and other devices accessing the same wireless access point (WAP), or the terminal device connecting to other devices via Wi-Fi Direct.

[0092] Further as Figure 9 As shown, in one implementation, step S104 can be implemented by the terminal device's IAP service, operating system, and other software modules, as well as hardware modules such as Wi-Fi and / or Bluetooth modules. Specifically, it may include the following steps S201-S203:

[0093] In step S201, when the IAP service receives a valid authentication result from the merchant, it can send a request instruction to the operating system to obtain user identity information of other nearby devices.

[0094] In an implementation, step S201 can be performed by a scanning management unit of the IAP service.

[0095] In step S202, when the operating system receives the request instruction from the IAP service, the operating system can call the Wi-Fi module of the terminal device to scan other devices in the surrounding area that are connected to the terminal device via Wi-Fi, and / or can call the Bluetooth module to scan other devices in the surrounding area that are connected to the terminal device via Bluetooth.

[0096] In step S203, the Wi-Fi module and / or the Bluetooth module of the terminal device performs the scanning process and sends the scanning result to the operating system.

[0097] In a specific implementation, the Wi-Fi module and / or the Bluetooth module of the terminal device can scan whether there are other devices in the surrounding area that have Wi-Fi and / or Bluetooth hardware functions turned on and are connected to the terminal device by sending or receiving frame signals.

[0098] Optionally, the scanning result can include the device identifier and the device type of the other device connected to the terminal device.

[0099] The device identifier can be, for example, a terminal model, such as HUAWEI Mate 40Pro, HUAWEI WATCH GT, Huawei Smart Screen V65, HUAWEI Sound, HUAWEI AX3 Pro, HUAWEI MateBook, etc. In addition to the terminal model, the device identifier can also be other information used to distinguish different devices, such as a MAC address, a user-defined phone name, etc.

[0100] The device type can include, for example, one or more of a mobile phone, a tablet computer, a large-screen display device, a smart watch, a smart bracelet, a smart speaker, a notebook computer, a smart home device, and other types of devices. The application does not make a specific limitation on the division method of the device type. For example, some embodiments can include more device types, such as gateway devices, etc., or can include fewer device types. For example, in some other embodiments, the device type can be divided into a coarser granularity, such as a smart watch and a smart bracelet being divided into a smart wearable device, or can be divided into a finer granularity, such as a smart home device being specifically divided into a smart air conditioner, a smart fan, etc.

[0101] In some implementations, the operating system can generate a first device list according to the scanning result returned by the Wi-Fi module and / or the Bluetooth module. The first device list can include the device identifier and the device type information of all other devices scanned by the terminal device. For example, as shown in Table 1:

[0102] Device ID Device Type HUAWEI Mate 40Pro Mobile Phone HUAWEI WATCH GT Smart Watch Huawei Smart Screen V65 Large-screen Display Device HUAWEI Sound Smart Speaker HUAWEI AX3 Pro Router HUAWEI MateBook Laptop … …

[0103] Table 1

[0104] It should be noted that, according to the number of other devices connected to the terminal device, the terminal device can scan one or more other devices, or no other device, and when the terminal device does not scan the other device, the terminal device performs a non-password-free payment process. In the non-password-free payment process, the terminal device guides the user to perform identity verification through fingerprint verification, payment password input, or face verification, and after identity verification, the payment process is completed.

[0105] In a specific implementation, if the Wi-Fi module and / or the Bluetooth module does not scan the other device, the Wi-Fi module and / or the Bluetooth module returns empty data to the operating system, and the operating system can notify the IAP service that no other device is scanned. When the IAP service receives the result of not scanning the other device, the non-password-free payment process is performed.

[0106] In step S105, the terminal device obtains user identity information of the scanned at least one other device.

[0107] In a specific implementation, the terminal device can send a user identity request message to each scanned other device respectively. After receiving the user identity request message, the other device sends its own user identity information to the terminal device.

[0108] The format and specific content of the user identity request message can be pre-configured by the terminal device and the other device, for example, configured in the operating system of the device before the device is manufactured, or configured in the operating system through subsequent system upgrade, and the present application does not make specific limitation thereto, as long as the message can be recognized by the other device as a message for obtaining its user identity information.

[0109] The user identity information refers to information for identifying which user the device belongs to, and different users have different user identity information. When the same user has multiple devices, the devices have the same user identity information.

[0110] Usually, a user registers and logs in an account on the terminal device in order to use the functions and services provided by the terminal device, and the account can be, for example, a Huawei account for using HMS services provided by Huawei Company, a Google account for using GMS services provided by Google Company, and an Apple ID for using services provided by Apple Company. In the present application, these accounts can be used as user identity information.

[0111] Further as Figure 9As shown, in an implementation, step S105 can be implemented by a software module such as an operating system and a hardware module such as a Wi-Fi module and / or a Bluetooth module. Specifically, it can include the following steps S204-S205:

[0112] In step S204, the operating system sends a user identity request message to each of the scanned other devices respectively.

[0113] In a specific implementation, the operating system sends the user identity request message based on the Wi-Fi or Bluetooth connection between the terminal device and each of the other devices. For example, when the terminal device and the other device are connected through Wi-Fi, the operating system invokes the Wi-Fi module to send the user identity request message to the other device; the other device receives the user identity request message through the Wi-Fi module and reports it to its own operating system. For another example, when the terminal device and the other device are connected through Bluetooth, the operating system invokes the Bluetooth module to send the user identity request message to the other device; the other device receives the user identity request message through the Bluetooth module and reports it to its own operating system.

[0114] In step S205, the operating system of the other device sends its own user identity information to the terminal device in response to the user identity request message.

[0115] In a specific implementation, the operating system of the other device sends the user identity information based on the Wi-Fi or Bluetooth connection between the terminal device and the other device. For example, when the terminal device and the other device are connected through Wi-Fi, the operating system of the other device invokes its own Wi-Fi module to send the user identity information to the terminal device; the terminal device receives the user identity information through its own Wi-Fi module and reports it to its own operating system. For another example, when the terminal device and the other device are connected through Bluetooth, the operating system of the other device invokes the Bluetooth module to send the user identity information to the terminal device; the terminal device receives the user identity information through its own Bluetooth module and reports it to its own operating system.

[0116] In some implementations, the operating system of the terminal device can generate a second device list according to the received user identity information. The second device list can include the device identifiers, device type information and user identity information of all the other devices scanned by the terminal device. When the user identity information is a Huawei account, the second device list is shown in Table 2, for example:

[0117] Device ID Device Type Huawei Account HUAWEI Mate 40Pro Mobile Phone USER01 HUAWEI WATCH GT Smart Watch USER01 Huawei Smart Screen V65 Large-screen Display Device USER01 HUAWEI Sound Smart Speaker USER01 HUAWEI MateBook Laptop USER01 Figure 9 Device ID Device Type … …

[0118] Table 2

[0119] Step S106, the terminal device determines whether the current device usage environment is trusted according to the user identity information and the device type of the scanned at least one other device.

[0120] In specific implementation, the terminal device can score the current device usage environment of the terminal device according to the device type and the user identity information of the other device based on the pre-configured decision rule; if the score of the current device usage environment is located in a preset first score interval, it is determined that the current device usage environment is trusted; if the score of the current device usage environment is located in a preset second score interval, it is determined that the current device usage environment is untrusted, wherein the first score interval and the second score interval can be different score intervals.

[0121] Further as shown in Huawei Account in an implementation manner, step S106 can be implemented by the IAP service, operating system and other software modules of the terminal device. Specifically, it can include the following steps S206-S210:

[0122] Step S206, the operating system of the terminal device matches the user identity information of each scanned other device with the user identity information of the terminal device respectively, to determine the trusted device with the same user identity information as the terminal device from the other devices.

[0123] It can be understood that when the user identity information of one or more other devices is the same as the user identity information of the terminal device, the operating system of the terminal device can determine one or more trusted devices; when there is no other device with the same user identity information as the terminal device, the operating system of the terminal device can determine that the number of trusted devices is 0. When the operating system of the terminal device determines that the number of trusted devices is 0, it can notify the IAP service that the number of trusted devices is 0, and the IAP service can directly determine that the current device usage environment is untrusted when receiving the information that the number of trusted devices is 0.

[0124] In an implementation manner, the operating system of the terminal device can generate a third device list according to the matching result of the user identity information of the other devices and the terminal device. The third device list can include the device identifier, device type information and user identity information of the trusted device, etc. When the user identity information is a Huawei account, the device list is shown in Table 3, for example:

[0125] HUAWEI Mate 40Pro Mobile Phone USER01 HUAWEI WATCH GT Smart Watch USER01 Huawei Smart Screen V65 Large-screen Display Device USER01 HUAWEI Sound Smart Speaker USER01 HUAWEI MateBook Laptop USER01 Figure 6 Figure 10 Figure 11 … …

[0126] Table 3

[0127] Step S207, the operating system of the terminal device sends the device type and other information of the trusted device to the IAP service.

[0128] In an implementation manner, the operating system of the terminal device can send the third device list to the IAP service.

[0129] In step S208, the IAP service scores the current device usage environment according to the device type of the trusted device and the preset weight value corresponding to the device type.

[0130] In an implementation manner, the user information management unit of the IAP service is configured to receive and record information such as the device type of the trusted device, for example, receive and save the third device list.

[0131] In an implementation manner, the factor management unit can pre-configure the weight value of each device type, each device type can include a first weight value and a second weight value, and the first weight value of each device type is greater than the second weight value. For example, the first weight value of the large-screen display device is 10, and the second weight value is 0; the first weight value of the smart watch is 3, and the second weight value is 0. Among them, the first weight value is used when the user identity information of the terminal device and other devices is the same (such as the same account login), and the second weight value is used when the user identity information of the terminal device and other devices is different (such as different account login). Generally, the first weight value of each device type can be greater than 0, and the second weight value of each device type can be equal to 0 or any value less than the first weight value.

[0132] In an implementation manner, considering that the large-screen display device is generally fixedly arranged and has the characteristic of strong attribution, for example, it is arranged in the user's home, therefore, the first weight value of the large-screen display device is higher than the first weight value of other device types.

[0133] Taking the Huawei account as an example, the weight value information configured by the factor management unit can be implemented by the following code, wherein the corresponding first weight value of each device type is under the "same account login" field, and the corresponding second weight value of each device type is under the "different account login" field:

[0134]

[0135]

[0136] In an implementation manner, the strategy management unit can be pre-configured with different payment scenarios and different payment strategies in each scenario corresponding to the score of the current device usage environment.

[0137] For example, the payment scenario can include a scenario in which the terminal device independently completes the in-application payment, and a scenario in which the terminal device completes the in-application payment with the aid of other devices.

[0138] The terminal device independently completes the application payment scene can include a "password-free payment strategy", and the terminal device completes the application payment scene by means of other devices can include a "checkout push strategy". Since the embodiment of the present application corresponds to the terminal device independently completing the application payment scene, only the payment strategy in the terminal device independently completing the application payment scene is discussed here, and the terminal device completing the application payment scene by means of other devices will be specifically described in the second embodiment of the present application.

[0139] For example, the payment scene configured by the policy management unit can be implemented by the following code:

[0140] { "terminal device independently completes the application payment scene": "password-free payment strategy",

[0141] "terminal device completes the application payment scene by means of other devices": "checkout push strategy"

[0142] }

[0143] In an implementation mode, based on the weight value information configured by the factor management unit, in the "password-free payment strategy", the score of the current device usage environment can be calculated by the trusted computing unit.

[0144] For example, when the trusted device only includes one large-screen display device, the weight value of the large-screen display device takes the first weight value as 10, so the score of the current device usage environment is 10 points; when the trusted device includes a smart watch and a mobile phone, the weight value of the smart watch takes the first weight value as 3, and the weight value of the mobile phone takes the first weight value as 2, so the score of the current device usage environment is 3+2=5 points; when the trusted device includes a smart watch and a smart speaker, the weight value of the smart watch takes the first weight value as 3, and the weight value of the smart speaker takes the first weight value as 5, so the score of the current device usage environment is 3+5=8 points; when no trusted device is scanned, the score of the current device usage environment is 0 points.

[0145] Step S209, if the score of the current device usage environment is in the first score interval, the IAP service determines that the current device usage environment is trusted.

[0146] Step S210, if the score of the current device usage environment is in the second score interval, the IAP service determines that the current device usage environment is not trusted.

[0147] In an implementation mode, steps S209 and S210 can be executed by the policy management unit of the IAP service according to the payment strategy configured thereby.

[0148] For example, the payment strategy configured by the policy management unit can be implemented by the following code:

[0149] {“Password-free payment strategy”:

[0150] {“0-5”: “Stop”, “5-”: “Go”},

[0151] “Cashier push strategy”:

[0152] {“0-5”: “Stop”, “5-”: “Go”},

[0153] }

[0154] In the “password-free payment strategy”, “0-5”: “Stop” indicates that when the score of the current device usage environment is between 0-5 (corresponding to the second score interval), the policy management unit determines that the current device usage environment is not trusted; “5-”: “Go” indicates that when the score of the current device usage environment is greater than 5 (corresponding to the first score interval), the policy management unit determines that the current device usage environment is trusted. It can be seen here that the first score interval can be higher than the second score interval.

[0155] Step S107, if the current device usage environment is trusted, the terminal device executes the password-free payment process.

[0156] Step S108, if the current device usage environment is not trusted, the terminal device executes the non-password-free payment process.

[0157] In an implementation manner, based on Figure 6 The logical architecture of the IAP service is shown, and step S107 can be executed by the decision routing unit and the in-application payment cashier module of the IAP service.

[0158] Specifically, the decision routing unit obtains the decision result of the policy management unit on whether the current device usage environment is trusted; if the current device usage environment is trusted, the decision routing unit sends a password-free payment instruction to the in-application payment cashier module; if the current device usage environment is not trusted, the decision routing unit sends a non-password-free payment instruction to the in-application payment cashier module.

[0159] When the in-app payment cash register module receives the password-free payment indication, it executes the password-free payment process, i.e., skips the fingerprint verification interface, the payment password input interface, or the face verification, and does not display the interface for guiding the user to perform identity verification, but directly submits a payment settlement request to the payment server. When the in-app payment cash register module receives the non-password-free payment indication, it executes the non-password-free payment process, first generates a fingerprint verification interface, a payment password input interface, or a face verification interface to guide the user to perform identity verification by verifying a fingerprint, inputting a payment password, or verifying a face, and after the user identity verification is passed, the in-app payment cash register module submits a payment settlement request to the payment server, and if the user identity verification is not passed, the in-app payment cash register module terminates the payment process and displays a payment failure message.

[0160] When the wallet server receives the payment settlement request, it completes the payment subsequent payment processing steps and notifies the in-app payment cash register module and the application program server of the payment result. The in-app payment cash register module receives the payment result and can further notify the application program of the payment result. Next, the application program can initiate a purchase status query request to the application server to make the application program server return the purchase status of the goods, such as the issuance status of consumable goods and non-consumable goods, the subscription status of subscription products, etc.

[0161] From the above technical solutions, it can be seen that the identity verification method provided by the first embodiment of the present application can be applied to the scene where the terminal device independently completes the in-app payment. When the terminal device detects that the user has submitted a payment request for goods, it scans other devices connected around it and obtains the user identity information of these devices. Then, the terminal device determines whether the current device usage environment is trusted according to the user identity information and the device type of the other devices. If it is trusted, the password-free payment process is executed. Thus, the identity verification method provided by the present application can reduce the number of times the user manually performs identity verification and improve the user payment experience while ensuring the security of user payment.

[0162] In some implementations, the scanning management unit of the IAP service can configure multiple scanning strategies for the operating system, for example:

[0163] a. Indicating the operating system to determine whether the user identity information of the terminal device and the other devices is the same after scanning the other devices, and then only returning the information of the trusted devices with the same user identity information as the terminal device to the IAP service, i.e., instructing the operating system to execute step S206 and step S207.

[0164] b. Indicating the operating system to return the information of all other devices after scanning the other devices, without determining whether the user identity information is the same, and then the operating system does not execute step S206 and step S207.

[0165] c. instructing the terminal device to scan only one or more specified types of other devices, such as only scanning large-screen display devices or only scanning large-screen display devices and smart watches, etc.

[0166] d. instructing the operating system to scan only other devices within a specified distance around the terminal device, wherein the distance between the terminal device and the other devices can be determined by measuring the signal flight time, etc.

[0167] When the scanning management unit varies the scanning strategy configured by the operating system, the implementation of the IAP service scoring the current device usage environment of the terminal device also varies, and those skilled in the art can make flexible changes according to the different scanning strategies, and the embodiments of the present application do not make specific limitations.

[0168] For example, when the scanning strategy b is adopted, the operating system can send the information of all scanned other devices, such as the second device list, to the user information management unit of the IAP service, so that the user information management unit can save the second device list.

[0169] The trusted computing unit calculates the score of the current device usage environment based on the weight value information configured by the factor management unit, and considers the weight values of other devices with the same user identity information and other devices with different user identity information of the terminal device.

[0170] For example, when the user identity information is a Huawei account, assuming that the Huawei account logged in by the terminal device is USER01, the other devices scanned by the terminal device include a large-screen display device logged in by the Huawei account USER01 and a smart watch logged in by the Huawei account USER01, and based on the weight value information exemplified above, the weight value of the large-screen display device is 10 and the weight value of the smart watch is 3, so the terminal device adds the weight values of all other devices to obtain a score of 10+3=13 for the current device usage environment.

[0171] For example, when the user identity information is a Huawei account, assuming that the Huawei account logged in by the terminal device is USER01, the other devices scanned by the terminal device include a smart speaker logged in by the Huawei account USER02 and a smart watch logged in by the Huawei account USER01, and based on the weight value information exemplified above, the weight value of the smart speaker is 0 and the weight value of the smart watch is 3, so the score of the current device usage environment is 0+3=3.

[0172] Then, the IAP service executes subsequent steps S209 and S210, etc. according to the score of the current device usage environment obtained by the trusted computing unit.

[0173] In an implementation, the terminal device can set a maximum scanning duration Tscan when performing step S104. The terminal device starts timing when the Wi-Fi module and / or the Bluetooth module starts scanning, and stops scanning and generates the scanning result when the timing reaches the maximum scanning duration Tscan.

[0174] In a specific implementation, as shown in Figure 6 Step S104 can include the following steps:

[0175] Step S301, when the IAP service receives the legal authentication result of the merchant, the IAP service can send a request instruction for obtaining the user identity information of other devices in the surrounding to the operating system, and the request instruction contains the maximum scanning duration Tscan.

[0176] Step S302, when the operating system receives the request instruction from the IAP service, the operating system can call the Wi-Fi module of the terminal device to scan other devices in the surrounding that are connected through Wi-Fi, and / or can call the Bluetooth module to scan other devices in the surrounding that are connected through Bluetooth, and at the same time, the operating system starts the timer timer=Tscan and starts timing.

[0177] Step S303, the Wi-Fi module and / or the Bluetooth module of the terminal device performs the scanning process before the timer timer reaches zero, and sends the scanning result to the operating system.

[0178] During this period, the Wi-Fi module and / or the Bluetooth module can report the device identity and device type of each other device scanned to the operating system until the timer timer reaches zero and stops scanning. Alternatively, the Wi-Fi module and / or the Bluetooth module do not report the scanning result during the scanning process, but stop scanning after the timer timer reaches zero and report the scanning result to the operating system.

[0179] In this way, by setting the maximum scanning duration Tscan, the time consumed by the terminal device in performing step S104 can be limited, and the continuity of the in-application payment process can be avoided due to the long time consumed in step S104, and the user payment experience can be improved.

[0180] In an implementation, the terminal device can set a maximum waiting duration Twait when performing step S102. The terminal device starts timing when sending the user identity request message to other devices, and stops receiving the user identity information from other devices when the timing reaches the maximum waiting duration Twait.

[0181] In a specific implementation, as shown in Figure 12 Step S105 can include the following steps:

[0182] Step S401, the operating system sends a user identity request message to each other device respectively, and meanwhile, the operating system starts a timer timer=Twait and begins timing.

[0183] Step S402, the operating system of the other device sends its own user identity information to the terminal device in response to the user identity request message.

[0184] Step S403, the operating system receives the user identity information returned by the other device before the timer timer expires, and stops receiving the user identity information after the timer timer expires.

[0185] It can be understood that when the operating system stops receiving the user identity information, the operating system can have received the user identity information of all the other devices or received the user identity information of part of the other devices. If a user identity information is not returned by an other device, it is considered that the user identity information of the other device is different from that of the terminal device.

[0186] In this way, by setting the maximum waiting time Twait, the time consumed by the terminal device in performing step S105 can be limited, and the continuity of the in-application payment process is avoided from being affected due to the long time consumption of step S105, and the user payment experience is improved.

[0187] Embodiment Two

[0188] Embodiment Two of the present application is applied to a scenario in which a terminal device completes an in-application payment process with the help of other devices. In Embodiment Two of the present application, the terminal device and the other devices can both be internally provided with an IAP service. The logical architecture of the IAP service of the terminal device can be as shown in Figure 13 The IAP service of the other device can include an in-application payment checkout module in Figure 13 .

[0189] The content not specifically described in Embodiment Two of the present application is referred to the implementation of Embodiment One of the present application.

[0190] As shown in Figure 13 , when the terminal device is a large-screen display device and the merchant application is a video application, if a user wants to purchase a video membership in the video application, the user will use a remote controller to select the corresponding membership goods, time length and other information, and then operate the remote controller to click a "payment" button 17. At this time, the video application will arouse the IAP service through the API provided by the IAP service, and pass the goods payment request to the in-application payment checkout module of the IAP service.

[0191] Figure 13is a timing diagram of a terminal device completing an in-application payment process with the aid of other devices according to an embodiment of the present application.

[0192] As shown in Figure 8 , the terminal device completing the in-application payment process with the aid of other devices can include the following steps S501-S509:

[0193] Step S501, when the IAP service of the terminal device detects that a user submits a commodity payment request, the IAP service sends merchant authentication information to a payment server.

[0194] Step S501 is the same as step S101 in the first embodiment of the present application, and can be implemented by referring to step S101, which will not be described here.

[0195] Step S502, after receiving the merchant authentication information, the payment server performs legality verification on the merchant according to the merchant authentication information.

[0196] In a specific implementation, the payment server can verify whether the merchant is a merchant that has been registered in the payment server according to the merchant ID, etc. When the merchant authentication information is signed encrypted information, the payment server can verify the legality of the merchant by performing signature verification on the merchant authentication information. If the merchant is legal, the payment server generates a corresponding order and sends an order token for identifying the order, i.e., an order Token, to the IAP service of the terminal device, which can be implemented by a URL. The order Token can include, for example, an order number of the order, an order channel, a merchant ID, an application ID, a commodity name, an order time, etc., and a payment URL called by the order, etc. After completing the legality verification of the merchant, the payment server can send the merchant authentication result obtained by the verification to the terminal device, and when the merchant authentication result is that the merchant is legal, the merchant authentication result also includes the order Token.

[0197] Step S503, the terminal device receives the merchant authentication result sent by the payment server.

[0198] Step S504, when the terminal device receives the merchant authentication result sent by the payment server, the terminal device scans at least one other device connected thereto.

[0199] Step S504 is the same as step S104 in the first embodiment of the present application, and can be implemented by referring to step S104, which will not be described here.

[0200] Step S505, the terminal device obtains user identity information of the scanned at least one other device.

[0201] Step S505 is the same as step S105 in the first embodiment of the present application, and can be implemented by referring to step S105, which will not be described here.

[0202] Step S506, the terminal device determines whether the current device usage environment of the terminal device is trusted according to the user identity information and the device type of the scanned at least one other device.

[0203] Step S506 is the same as step S106 in the first embodiment of the present application, and can be implemented by referring to step S106.

[0204] For example, when the user identity information is a Huawei account, assuming that the Huawei account logged in by the terminal device is USER01, the other devices scanned by the terminal device include a mobile phone with a Huawei account logged in as USER01, and a smart watch with a Huawei account logged in as USER02, and based on the weight value information exemplified above, the weight value of the mobile phone is the first weight value 2, and the weight value of the smart watch is the first weight value 3, so the score of the current device usage environment is 2+3=5 points.

[0205] For example, when the user identity information is a Huawei account, assuming that the Huawei account logged in by the terminal device is USER01, the other devices scanned by the terminal device include a smart speaker with a Huawei account logged in as USER01, a smart watch with a Huawei account logged in as USER02, and a mobile phone with a Huawei account logged in as USER01, and based on the weight value information exemplified above, the weight value of the smart speaker is the first weight value 5, the weight value of the smart watch is the second weight value 0, and the weight value of the mobile phone is the first weight value 2, so the score of the current device usage environment is 5+0+3=8 points.

[0206] Step S507, when the current device usage environment is trusted, the terminal device performs a checkout counter pushing process to push a payment task to a target device.

[0207] In the checkout counter pushing process, the terminal device can specifically include the following steps S601-S602 as shown in the following table: Figure 14

[0208] Step S601, when the current device usage environment is trusted, the IAP service of the terminal device generates messenger information.

[0209] In an implementation manner, the messenger information can be generated by a decision routing unit.

[0210] The messenger information may, for example, include one or more of the product payment request and / or the information contained in the order token; the messenger information may, for example, include: product name, amount, payment currency, user ID, merchant ID, terminal device type and device ID, order number, order channel, application ID, order time, and payment URL called by the order, and the like. ​

[0211] For example, in the Android system, the messenger information can be an Android Intent object.

[0212] In step S602, the IAP service of the terminal device instructs the operating system to send the messenger information to the target device.

[0213] In an implementation manner, step S602 can be performed by the decision routing unit.

[0214] The target device is a device determined by the IAP service from all trusted devices scanned by the terminal device to assist the terminal device to complete the in-application payment process. The target device can be a device of a specified type such as a mobile phone. When there are multiple devices of the specified type such as mobile phones, the target device can be a device specified by the user in advance. If the user does not specify the device in advance, the target device can be a device closest to the terminal device or a device currently in an active state, for example, a device unlocking state, an active network connection state, and the like.

[0215] In step S508, when the current device usage environment of the terminal device is untrusted, the terminal device performs a non-cashier push process to convert the messenger information into a two-dimensional code and display the two-dimensional code on the display screen.

[0216] Next, the user can use the code scanning function of the payment application of the handheld target device to scan the two-dimensional code, and the messenger information is transmitted to the target device.

[0217] As can be seen, whether the current device usage environment of the terminal device is trusted or untrusted, the target device needs to obtain information from the terminal device. The difference lies in that when the current device usage environment of the terminal device is trusted, the terminal device actively pushes the information to the target device. When the current device usage environment of the terminal device is untrusted, the terminal device displays the messenger information in the form of a two-dimensional code on the display screen, and the user needs to use the code scanning function of the payment application of the target device to scan the two-dimensional code, and the messenger information is transmitted to the target device.

[0218] When the target device receives the messenger information, the target device can perform the subsequent in-application payment process according to the content contained in the messenger information. In an implementation manner, as shown in FIG. 7, the target device can perform the following steps S701-S704: Figure 15

[0219] In step S701, the target device sends the merchant authentication information to the payment server according to the messenger information.

[0220] ​In a specific implementation, the operating system of the target device can invoke the IAP service through an API provided by the IAP service, and pass the messenger information to the in-application payment checkout module of the IAP service; the in-application payment checkout module sends the merchant authentication information to the payment server according to the information passing. The merchant authentication information may, for example, include information such as the product name, the amount, the payment currency, the user ID, the merchant ID, the terminal device type, and the device ID obtained from the messenger information.

[0221] In step S702, the target device generates a to-be-paid page upon receiving the merchant legal authentication result sent by the server.

[0222] The to-be-paid page may, for example, Figure 4 Details are not described herein again.

[0223] In step S703, the target device sends a payment settlement request to the payment server upon detecting that the user has submitted a product payment request on the to-be-paid page.

[0224] In a specific implementation, when the in-application payment checkout module of the IAP service of the target device detects that the user has selected a payment method on the to-be-paid page and clicked Confirm Payment, it means that the terminal device detects that the user has submitted a product payment request.

[0225] In an implementation, upon detecting that the user has submitted a product payment request, the target device can first generate a user identity verification interface such as a fingerprint verification interface, a payment password input interface, or a face verification interface, to guide the user to perform identity verification through a verification fingerprint, input a payment password, or verify a face, and after the user identity verification is passed, the in-application payment checkout module submits a payment settlement request to the payment server, and if the user identity verification is not passed, the in-application payment checkout module terminates the payment process and displays payment failure information.

[0226] In step S704, the target device sends the payment result to the terminal device upon receiving the payment result sent by the payment server.

[0227] As can be seen from the above technical solutions, the identity verification method provided in Embodiment Two of the present application can be applied to a scenario in which the terminal device completes an in-application payment process with the aid of other devices. Upon detecting that the user has submitted a product payment request, the terminal device scans other devices connected around the terminal device and obtains user identity information of the devices; then, the terminal device determines whether the current device usage environment is trustworthy according to the user identity information and the device type of the other devices; if so, the checkout push process is performed. Thus, the identity verification method provided in the present application can reduce the number of times that the user switches payment devices by manually scanning a two-dimensional code and improve the user payment experience while ensuring the user payment security.

[0228] It should be noted that the identity verification method provided by the embodiments of the present application can be applied to other scenarios requiring identity verification in addition to the payment scenario. Some common scenarios are listed below to illustrate the feasibility of applying the method provided by the embodiments of the present application to other scenarios.

[0229] In one embodiment, the identity verification method provided by the embodiments of the present application can be applied to the scenario where a user modifies or retrieves an account password on a terminal device.

[0230] Generally speaking, when a user needs to modify or retrieve a password on a terminal device, the terminal device will require the user to perform identity verification, such as mobile phone verification code verification, secret protection question verification, email verification, etc. In the mobile phone verification code process, the terminal device sends a verification code request message to the code sending server after the user clicks "send verification code"; the code sending server sends the verification code to the terminal device in the form of a short message; after the user inputs the correct verification code, the terminal device displays a page for the user to input a new password. In the secret protection question verification process, the terminal device will first display the secret protection question set by the user in advance; after the user inputs the correct secret protection answer, the terminal device displays a page for the user to input a new password. In the email verification process, the terminal device sends an email verification request message to the email verification server after the user clicks "verify secure email"; the email verification server sends a verification link to the email set by the user in advance; next, the user can click the verification link in the email and input a new password in the opened link page to complete the password modification or retrieval process.

[0231] As can be seen, the identity verification operation to be completed is relatively complex when a user modifies or retrieves a password on a terminal device, which reduces the user experience.

[0232] If the identity verification method provided by the embodiments of the present application is adopted, as shown in Figure 16 the terminal device can perform the following steps S801-S805 when a user modifies or retrieves a password (for example, when the terminal device detects that the user clicks "modify password" or "retrieve password").

[0233] Step S801, the terminal scans at least one other device connected thereto.

[0234] Step S801 can be implemented with reference to step S104, and will not be described here.

[0235] Step S802 is the same as step S105, and step S803 is the same as step S106, which will not be described here.

[0236] Step S804, when the current device usage environment of the terminal device is trusted, the terminal device performs a password modification or password recovery process without verification.

[0237] In the password modification or password recovery process without verification, the terminal device no longer requires the user to perform identity verification in the manner of mobile phone verification, secret protection question verification, email verification, etc., but directly displays a page for the user to input a new password, thereby eliminating the cumbersome operation process.

[0238] Step S805, when the current device usage environment of the terminal device is not trusted, the terminal device performs a password modification or password recovery process with verification.

[0239] In the password modification or password recovery process with verification, considering that the person operating the terminal device at this time may not be the user himself, the terminal device performs mobile phone verification, secret protection question verification, email verification, etc. in the traditional manner of identity verification.

[0240] According to the technical solution above, the identity verification method provided in the embodiments of the present application can be applied to the scenario in which the user modifies an account password or recovers an account password on a terminal device, and can reduce user operations and improve user experience when the current device usage environment is trusted.

[0241] In another embodiment, the identity verification method provided in the embodiments of the present application can be applied to the scenario in which the terminal device displays sensitive information.

[0242] Generally, when using a terminal device, the user receives some short messages containing verification codes, bank card numbers, bank card balances or intimate words, which are displayed in the notification bar of the operating system. The content involved in these short messages involves the user's property safety and privacy safety, and is usually not desired to be seen by others. However, when the user is in a place with dense flow of people such as a subway, a bus, a station, a shopping mall or a party, once this information is displayed on the display screen, it is easy to be seen by others.

[0243] If the identity verification method provided in the embodiments of the present application is adopted, as shown in FIG. 9, when the terminal device receives a short message containing sensitive information, the following steps S901-S905 can be performed: ​

[0244] Step S901, the terminal scans at least one other device connected thereto.

[0245] Step S901 can be implemented with reference to step S104, and will not be described here.

[0246] Step S902 is the same as step S105, and step S903 is the same as step S106, and will not be described here. ​

[0247] Step S904, when the current device usage environment of the terminal device is trusted, the terminal device directly displays the short message on the notification bar.

[0248] Step S905, when the current device usage environment of the terminal device is not trusted, the terminal device desensitizes the sensitive information in the short message and then displays the short message on the notification bar.

[0249] In a specific implementation, the terminal device can replace the sensitive information in the short message with some special symbols.

[0250] For example, when the original content of the short message is:

[0251] You credit card with tail number 6955, consumption of RMB 800 yuan.

[0252] If the star * is used for replacement, the desensitized short message content is:

[0253] You credit card with tail number ****, consumption of RMB **** yuan.

[0254] In this way, even if someone around the user sees the short message, no sensitive information can be obtained from the short message, and the property safety and privacy safety of the user are protected.

[0255] In the embodiments provided in the present application, the identity authentication method provided in the present application is introduced from the perspective of the terminal device itself and the interaction between devices. It can be understood that each device, for example, the terminal device described above, contains a hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed in the present application, the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0256] For example, the terminal device described above realizes the corresponding functions through a hardware module.

[0257] In one embodiment, as ​As shown, the identity authentication apparatus for implementing the terminal device function includes a processor 110 and a memory 120, a transceiver, the memory 120 and the processor 110; the memory 120 includes program instructions, which, when executed by the processor 110, cause the terminal device to perform the following steps: when detecting that a user submits a commodity payment request, scanning at least one other device connected thereto; obtaining user identity information of the at least one other device; determining whether a current device use environment is trusted according to the user identity information of the at least one other device and a device type, wherein the device type is obtained from the other device when the terminal device establishes a connection with the other device; if the current device use environment is trusted, performing a password-free payment process, or pushing a payment process to a target device to cause the target device to perform a non-password-free payment process in place of the terminal device; and if the current device use environment is not trusted, performing a non-password-free payment process.

[0258] In this way, when detecting that a user submits a commodity payment request, the terminal device scans other devices connected thereto and obtains user identity information of the devices; then, the terminal device determines whether a current device use environment is trusted according to the user identity information of the other devices and the device type; if so, a password-free payment process is performed. Thus, the identity authentication method provided by the embodiments of the present application can reduce the number of times of manual identity authentication by the user and improve user payment experience while ensuring user payment security.

[0259] Optionally, the memory 120 stores weight values of at least one device type, each device type including a first weight value and a second weight value, and the first weight value of each device type being greater than the second weight value.

[0260] Optionally, the program instructions further cause the terminal device to perform the following steps to determine whether a current device use environment is trusted according to the user identity information of the at least one other device and the device type: determining trusted devices with the same user identity information as itself from the at least one other device; determining weight values of the respective trusted devices according to the device types of the trusted devices; adding the weight values of all the trusted devices to obtain a current device use environment score; if the current device use environment score is in a first score interval, determining that the current device use environment is trusted; and if the current device use environment score is in a second score interval, determining that the current device use environment is not trusted, wherein the first score interval is higher than the second score interval. In this way, the terminal device can score the current device use environment according to the user identity information, types, quantities and weight values of the other devices; the higher the current device use environment score, the higher the trustworthiness of the current device use environment; and when the score reaches the first score interval, it is determined that the current device use environment is trusted.

[0261] Optionally, the weight value of the trusted device is a first weight value of a device type to which the trusted device belongs.

[0262] Optionally, the program instructions further cause the terminal device to perform the following steps to determine whether the current device usage environment is trusted according to the user identity information and the device type of the at least one other device: determine a weight value of each of the other devices according to the user identity information and the device type of the other device respectively; add the weight values of all the other devices to obtain a current device usage environment score; if the current device usage environment score is in a first score interval, determine that the current device usage environment is trusted; and if the current device usage environment score is in a second score interval, determine that the current device usage environment is not trusted, wherein the first score interval is higher than the second score interval. In this way, the terminal device can score the current device usage environment according to the user identity information, the type, the number and the weight value of the other devices. The higher the current device usage environment score is, the higher the trustworthiness of the current device usage environment is. When the score reaches the first score interval, it is determined that the current device usage environment is trusted.

[0263] Optionally, the program instructions further cause the terminal device to perform the following steps to determine the weight value of each of the other devices according to the user identity information and the device type of the other device: when the user identity information of the terminal device is the same as that of the other device, the weight value of the other device is equal to a first weight value of the device type of the other device; and when the user identity information of the terminal device is different from that of the other device, the weight value of the other device is equal to a second weight value of the device type of the other device.

[0264] Optionally, the device types include at least one or more of a large-screen display device, a smart watch, a mobile phone, a smart speaker and a notebook computer, and the first weight value of the large-screen display device is greater than the first weight values of the remaining device types.

[0265] Optionally, the second weight value of each device type is 0.

[0266] Optionally, the program instructions further cause the terminal device to perform the following steps to push the payment process to the target device: send messenger information to the target device, the messenger information being used to instruct the target device to perform the non-password-free payment process. In this way, the method of the embodiments of the present application can reduce the number of times that the user switches the payment device by manually scanning the two-dimensional code, and improve the user payment experience by pushing the payment process.

[0267] Optionally, the target device is determined by the terminal device from at least one other device, and the target device includes a device of a specified type, or a device specified by the user in advance, or a device currently in an active state.

[0268] Optionally, the program instructions further cause the terminal device to perform the following steps to achieve scanning at least one other device connected thereto in the periphery when detecting that the user submits the commodity payment request: scanning at least one other device connected thereto in the periphery according to a merchant authentication result of the payment server when detecting that the user submits the commodity payment request.

[0269] Optionally, the program instructions further cause the terminal device to perform the following steps to achieve scanning at least one other device connected thereto in the periphery according to a merchant authentication result of the payment server when detecting that the user submits the commodity payment request: sending merchant authentication information to the payment server when detecting that the user submits the commodity payment request, so that the payment server performs legality verification on the merchant according to a signature of the merchant authentication information to obtain a merchant authentication result, the merchant authentication result including that the merchant is legal and that the merchant is illegal; receiving the merchant authentication result sent by the payment server; and scanning at least one other device connected thereto in the periphery when the received merchant authentication result is that the merchant is legal. In this way, the terminal device only scans other devices in the case that the merchant is legal, avoiding unnecessary scanning processes.

[0270] Optionally, the program instructions further cause the terminal device to perform the following steps to achieve scanning at least one other device connected thereto in the periphery: scanning at least one other device connected thereto in the periphery through a wireless communication module.

[0271] Optionally, the wireless communication module includes a wireless fidelity (Wi-Fi) module and / or a Bluetooth module, and the program instructions further cause the terminal device to perform the following steps to achieve scanning at least one other device connected thereto in the periphery through the wireless communication module: calling the Wi-Fi module to scan at least one other device connected thereto in the periphery through Wi-Fi, and / or calling the Bluetooth module to scan at least one other device connected thereto in the periphery through Bluetooth.

[0272] Optionally, the program instructions further cause the terminal device to perform the following steps to achieve obtaining user identity information of the at least one other device: sending user identity request information to each other device respectively; and receiving user identity information sent by each other device in response to the user identity request information.

[0273] For example, the terminal device described above is implemented by a software module to realize corresponding functions.

[0274] In one embodiment, as shown in ​ the identity authentication apparatus for realizing the functions of the terminal device described above includes:

[0275] The environment perception module 801 is configured to scan at least one other device connected therewith when detecting that the user submits a commodity payment request, and acquire user identity information of the at least one other device, and determine whether a current device use environment is trusted according to the user identity information of the at least one other device and a device type, wherein the device type is acquired from the other device when the terminal device establishes a connection with the other device; the in-application payment checkout module 802 is configured to execute a password-free payment process when the current device use environment is trusted, or push a payment process to a target device to enable the target device to execute a non-password-free payment process in place of the terminal device, and is configured to execute a non-password-free payment process when the current device use environment is not trusted.

[0276] In this way, the terminal device scans other devices connected therewith around when detecting that the user submits a commodity payment request, and acquires user identity information of the devices, and then determines whether a current device use environment is trusted according to the user identity information of the other devices and a device type, and executes a password-free payment process if the current device use environment is trusted. Thus, the identity verification method provided in the embodiments of the present application can reduce the number of times of manual identity verification of the user and improve user payment experience while ensuring user payment security.

[0277] Optionally, the environment perception module 801 is further configured to send messenger information to the target device, the messenger information including the commodity payment request, to enable the target device to send a merchant authentication request to a payment server according to the messenger information, and execute a non-password-free payment process when receiving an authentication result of the merchant sent by the payment server. In this way, the terminal device scans other devices connected therewith around when detecting that the user submits a commodity payment request, and acquires user identity information of the devices, and then determines whether a current device use environment is trusted according to the user identity information of the other devices and a device type, and executes a checkout pushing process if the current device use environment is trusted. Thus, the identity verification method provided in the embodiments of the present application can reduce the number of times of manual scanning of a two-dimensional code by the user to switch a payment device and improve user payment experience while ensuring user payment security.

[0278] The embodiments of the present application further provide a computer storage medium, which stores computer instructions, and when the computer instructions are run on a computer, the computer executes the method of each aspect.

[0279] The embodiments of the present application further provide a computer program product including instructions, and when the computer program product is run on a computer, the computer executes the method of each aspect.

[0280] The application also provides a chip system. The chip system includes a processor for supporting the functions involved in the above-mentioned aspects, such as generating or processing the information involved in the above-mentioned methods, of the above-mentioned apparatus or device. In a possible design, the chip system further includes a memory for storing necessary program instructions and data of the above-mentioned apparatus or device. The chip system can be composed of a chip, or can include a chip and other discrete devices.

[0281] The above detailed description sets forth the purpose, technical solutions, and beneficial effects of the present application. It should be understood that the above is only a specific implementation of the present application, and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made on the basis of the technical solutions of the present application shall be included in the protection scope of the present application.

Claims

1. An identity verification method, characterized by, The method comprises the following steps: When a user submits a payment request for a commodity, a first terminal device scans at least one second terminal device connected thereto; The first terminal device acquires user identity information of the at least one second terminal device; The first terminal device determines whether a current device use environment is trustworthy according to the user identity information and the device type of the at least one second terminal device, wherein the device type is acquired from the second terminal device when the first terminal device establishes a connection with the second terminal device; whether the current device use environment is trustworthy is determined based on a current device use environment score; the current device use environment score is determined based on a weight value of at least one trustworthy device; the weight value of the at least one trustworthy device is a first weight value corresponding to the device type of the trustworthy device, and the trustworthy device is a second terminal device in the at least one second terminal device whose user identity information is the same as that of the first terminal device; or the current device use environment score is determined based on a weight value of at least one second terminal device, and when the user identity information of the first terminal device is the same as that of the second terminal device, the weight value of the second terminal device is equal to a first weight value of the device type thereof, and when the user identity information of the first terminal device is different from that of the second terminal device, the weight value of the second terminal device is equal to a second weight value of the device type thereof, and the first weight value of the device type is greater than the second weight value; When the current device use environment is trustworthy, the first terminal device performs a password-free payment process, or the first terminal device pushes a payment process to a third terminal device, so that the third terminal device takes over the first terminal device to perform a non-password-free payment process; When the current device use environment is not trustworthy, the first terminal device performs a non-password-free payment process.

2. The method of claim 1, wherein, The first terminal device determines whether a current device use environment is trustworthy according to the user identity information and the device type of the at least one second terminal device, comprising: The first terminal device determines trustworthy devices with the same user identity information as itself from the at least one second terminal device; The first terminal device respectively determines a weight value of each trustworthy device according to the device type of the trustworthy device; The first terminal device adds the weight values of all the trustworthy devices to obtain a current device use environment score; The first terminal device determines whether the current device use environment is trustworthy according to the current device use environment score.

3. The method of claim 1, wherein, The first terminal device determines whether a current device use environment is trustworthy according to the user identity information and the device type of the at least one second terminal device, comprising: The first terminal device respectively determines a weight value of each second terminal device according to the user identity information and the device type of the second terminal device; The first terminal device adds the weight values of all the second terminal devices to obtain a current device use environment score; The first terminal device determines whether the current device usage environment is trustworthy according to the current device usage environment score.

4. The method according to any one of claims 2-3, characterized in that, The first terminal device determines whether the current device usage environment is trustworthy according to the current device usage environment score, including: If the current device usage environment score is in a first score interval, the first terminal device determines that the current device usage environment is trustworthy. If the current device usage environment score is in a second score interval, the first terminal device determines that the current device usage environment is untrustworthy.

5. The method of claim 1, wherein, The device types at least include one or more of a large-screen display device, a smart watch, a mobile phone, a smart speaker, and a notebook computer, wherein the first weight value of the large-screen display device is greater than the first weight values of the remaining device types.

6. The method of claim 5, wherein, The second weight values of the respective device types are all 0.

7. The method of claim 1, wherein, The first terminal device pushes the payment process to a third terminal device, including that the first terminal device sends messenger information to the third terminal device, and the messenger information is used to instruct the third terminal device to execute the non-password-free payment process.

8. The method of claim 1, wherein, The third terminal device is determined by the first terminal device from the at least one second terminal device, and the third terminal device includes a device of a specified type, or a device specified by a user in advance, or a device currently in an active state.

9. The method of claim 1, wherein, The first terminal device scans at least one second terminal device connected thereto in the periphery when detecting that a user submits a commodity payment request, including that the first terminal device scans at least one second terminal device connected thereto in the periphery according to a merchant authentication result of a payment server when detecting that the user submits the commodity payment request.

10. The method of claim 9, wherein, The first terminal device scans at least one second terminal device connected thereto in the periphery according to a merchant authentication result of a payment server when detecting that a user submits a commodity payment request, including: The first terminal device sends merchant authentication information to the payment server when detecting that a user submits the commodity payment request, so that the payment server performs legality verification on a merchant according to a signature of the merchant authentication information to obtain the merchant authentication result, and the merchant authentication result includes merchant legality and merchant illegality. The first terminal device receives the merchant authentication result sent by the payment server. The first terminal device scans at least one second terminal device connected thereto in the periphery when the received merchant authentication result is merchant legality.

11. The method of claim 1, wherein, The first terminal device scans at least one second terminal device connected thereto in the periphery, including that the first terminal device scans at least one second terminal device connected thereto in the periphery through a wireless communication module.

12. The method of claim 11, wherein, The wireless communication module comprises a wireless fidelity (Wi-Fi) module and / or a Bluetooth module, and the first terminal device scans at least one second terminal device around the first terminal device and wirelessly connected to the first terminal device through the wireless communication module, including: the first terminal device calling the Wi-Fi module to scan at least one second terminal device around the first terminal device and wirelessly connected to the first terminal device through Wi-Fi, and / or the first terminal device calling the Bluetooth module to scan at least one second terminal device around the first terminal device and wirelessly connected to the first terminal device through Bluetooth.

13. The method of claim 1, wherein, The first terminal device acquires user identity information of the at least one second terminal device, including: The first terminal device sends user identity request information to each of the second terminal devices respectively; The first terminal device receives user identity information sent by each of the second terminal devices in response to the user identity request information.

14. The method of claim 1, wherein, When the first terminal device is a mobile phone and the current device usage environment is trusted, the first terminal device performs a password-free payment process.

15. The method of claim 1, wherein, When the first terminal device is a large-screen display device and the current device usage environment is trusted, the first terminal device pushes a payment process to the third terminal device.

16. An identity verification apparatus characterized by comprising: The apparatus is used as a first terminal device, and comprises a processor and a memory; wherein the memory comprises program instructions, and the program instructions are run by the processor, so that the first terminal device is used to execute the method in any one of claims 1-15.

17. An identity verification system characterized by, including: a first terminal device and at least one second terminal device; The first terminal device is configured to scan at least one second terminal device connected to the first terminal device around the first terminal device when detecting that a user submits a commodity payment request; The first terminal device is further configured to send user identity request information to each of the scanned second terminal devices respectively; The second terminal device is configured to send user identity information of the second terminal device to the first terminal device in response to the user identity request information; The first terminal device is further configured to determine whether a current device usage environment is trustworthy according to user identity information and a device type of the scanned at least one second terminal device, wherein the device type is obtained from the second terminal device when the first terminal device establishes a connection with the second terminal device; whether the current device usage environment is trustworthy is determined based on a current device usage environment score; the current device usage environment score is determined based on a weight value of at least one trustworthy device; the weight value of the at least one trustworthy device is a first weight value corresponding to a device type of the trustworthy device, and the trustworthy device is a second terminal device in the at least one second terminal device, whose user identity information is the same as that of the first terminal device; or the current device usage environment score is determined based on a weight value of at least one second terminal device, when the user identity information of the first terminal device is the same as that of the second terminal device, the weight value of the second terminal device is equal to a first weight value of a device type of the second terminal device, and when the user identity information of the first terminal device is different from that of the second terminal device, the weight value of the second terminal device is equal to a second weight value of a device type of the second terminal device, and the first weight value of the device type is greater than the second weight value; The first terminal device is further configured to execute a password-free payment process when the current device usage environment is trustworthy, or push a payment process to a third terminal device, so that the third terminal device takes over the first terminal device to execute a non-password-free payment process. The first terminal device is further configured to execute a non-password-free payment process when the current device usage environment is untrustworthy.

18. A chip system, characterized by The chip system comprises a memory and a processor, the memory stores computer program instructions, and the program instructions are executed by the processor to enable the chip system to realize the functions of any terminal device in any one of claims 1-15. ​

Citation Information

Patent Citations

  • Payment method and apparatus

    CN106779701A

  • Payment method and device

    US20190354983A1

  • Transaction Method, Payment Device, Verification Device, And Server

    US20200065806A1