An identity authentication method, device, equipment and system
By establishing a wireless connection between the PC terminal and the mobile terminal and using the mobile terminal's biological authentication method for identity authentication, the problem of low security of PC identity authentication is solved, and efficient and secure identity verification and service processing are achieved.
Patent Information
- Application Number
- CN202210283340.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-22
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-03-22
AI Technical Summary
The existing PC identity authentication methods have low security and are prone to attacks, especially in paperless offices and online services. Traditional password and SMS authentication methods are difficult to meet the needs of efficient and secure identity verification.
By establishing a wireless connection between the PC terminal and the mobile terminal, identity authentication is performed using the mobile terminal's biological authentication methods (such as fingerprints, faces, etc.), and service processing is triggered based on the authentication results, reducing intermediate links and improving security.
It realizes efficient and secure identity authentication in the PC environment, reduces the possibility of gray-black attacks, and improves the security and reliability of business processing.
Smart Images

Figure CN114867017B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of computer technology, and particularly to an identity authentication method, apparatus, device, and system. Background Art
[0002] With the advancement of the digital trend, more and more organizations have started to implement paperless office. The internal OA (Office Automation) system, ERP (Enterprise Resource Planning) system, CRM (Customer Relationship Management) system, etc. of the organization all need to authenticate the users who are operating. In addition, many online services also need to authenticate the users who request the service.
[0003] Currently, most of the methods for authenticating user identities on personal computers (PCs) are passwords, SMS, TOTP (Time-based One-time Password algorithm), etc. The identity authentication methods on mobile devices have developed to biometric authentication methods (such as fingerprint authentication, face authentication, voiceprint authentication, etc.). The above authentication methods can verify user identities very accurately and efficiently. Obviously, the identity authentication methods on the PC side are relatively backward and there are also risks such as loss or theft of authentication information. Therefore, it is necessary to provide a technical solution that can improve the identity authentication technical means in the current PC environment, thereby reducing the possibility of being attacked by gray and black production. Summary of the Invention
[0004] The purpose of the embodiments of this specification is to provide a technical solution that can improve the identity authentication technical means in the current PC environment, thereby reducing the possibility of being attacked by gray and black production.
[0005] In order to achieve the above technical solution, the embodiments of this specification are implemented as follows:
[0006] An identity authentication method provided by the embodiments of this specification is applied to a first terminal. The method includes: sending a user's identity authentication request to a preset service server. Receiving an identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Establishing a wireless connection with the second terminal, and sending the identity authentication instruction to the second terminal through the wireless connection. Receiving the user's identity authentication result sent by the second terminal, and triggering the service server to perform business processing on the target business based on the identity authentication result.
[0007] An identity authentication method provided by an embodiment of this specification is applied to a service server. The method includes: receiving an identity authentication request of a user sent by a first terminal of the user. Based on the identity authentication request, sending an identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with a second terminal, and sending the identity authentication instruction to the second terminal through the wireless connection. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal. Receiving the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, performing service processing on a target service.
[0008] An identity authentication system provided by an embodiment of this specification includes a server, a first terminal, and a second terminal. Among them: The first terminal sends an identity authentication request of a user to the server. The server, based on the identity authentication request, sends an identity authentication instruction of the user to the first terminal. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal. The first terminal establishes a wireless connection with the second terminal and sends the identity authentication instruction to the second terminal through the wireless connection. The second terminal authenticates the user's identity based on the identity authentication instruction to obtain the identity authentication result of the user. The first terminal receives the identity authentication result of the user sent by the second terminal and triggers the service server to perform service processing on a target service based on the identity authentication result.
[0009] An identity authentication device provided by an embodiment of this specification includes: an authentication request module that sends an identity authentication request of a user to a preset service server. An authentication instruction module that receives an identity authentication instruction sent by the service server. The identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. A wireless connection module that establishes a wireless connection with the second terminal and sends the identity authentication instruction to the second terminal through the wireless connection. A service processing module that receives the identity authentication result of the user sent by the second terminal and triggers the service server to perform service processing on a target service based on the identity authentication result.
[0010] An identity authentication device provided by an embodiment of this specification, the device includes: a request receiving module, which receives the identity authentication request of the user sent by the first terminal of the user. An instruction sending module, based on the identity authentication request, sends the identity authentication instruction of the user to the first terminal, so as to trigger the first terminal to establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection, and the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal. A service processing module, which receives the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, performs service processing on the target service.
[0011] An identity authentication device provided by an embodiment of this specification, the identity authentication device includes: a processor; and a memory arranged to store computer-executable instructions, and when the executable instructions are executed, the processor: sends an identity authentication request of the user to a preset service server. Receives the identity authentication instruction sent by the service server, and the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal. Establishes a wireless connection with the second terminal, and sends the identity authentication instruction to the second terminal through the wireless connection. Receives the identity authentication result of the user sent by the second terminal, and based on the identity authentication result, triggers the service server to perform service processing on the target service.
[0012] An identity authentication device provided by an embodiment of this specification, the identity authentication device includes: a processor; and a memory arranged to store computer-executable instructions, and when the executable instructions are executed, the processor: receives the identity authentication request of the user sent by the first terminal of the user. Based on the identity authentication request, sends the identity authentication instruction of the user to the first terminal, so as to trigger the first terminal to establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection, and the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal. Receives the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, performs service processing on the target service.
[0013] An embodiment of this specification also provides a storage medium for storing computer-executable instructions, which, when executed by a processor, implement the following process: sending an identity authentication request of a user to a preset service server; receiving an identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal; establishing a wireless connection with the second terminal, and sending the identity authentication instruction to the second terminal through the wireless connection; receiving the identity authentication result of the user sent by the second terminal, and triggering the service server to perform business processing on a target business based on the identity authentication result.
[0014] An embodiment of this specification also provides a storage medium for storing computer-executable instructions, which, when executed by a processor, implement the following process: receiving the identity authentication request of the user sent by the user's first terminal; based on the identity authentication request, sending the identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal, and sending the identity authentication instruction to the second terminal through the wireless connection, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal; receiving the identity authentication result of the user sent by the second terminal, and performing business processing on the target business when receiving the identity authentication result of the user sent by the first terminal. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following briefly introduces the accompanying drawings required for describing the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 This is an embodiment of an identity authentication method in this specification;
[0017] Figure 2 This is a schematic structural diagram of an identity authentication system in this specification;
[0018] Figure 3 This is another embodiment of an identity authentication method in this specification;
[0019] Figure 4 This is a schematic diagram of an identity authentication process in this specification;
[0020] Figure 5 This is yet another embodiment of an identity authentication method in this specification;
[0021] Figure 6 This is another embodiment of the identity authentication method in this specification;
[0022] Figure 7 This is the structural schematic diagram of another identity authentication system in this specification;
[0023] Figure 8 This is an embodiment of an identity authentication device in this specification;
[0024] Figure 9 This is another embodiment of the identity authentication device in this specification;
[0025] Figure 10 This is an embodiment of an identity authentication device in this specification. Detailed implementation manners
[0026] The embodiments of this specification provide an identity authentication method, device, equipment and system.
[0027] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.
[0028] Embodiment 1
[0029] As Figure 1 shown, the embodiments of this specification provide an identity authentication method. The execution subject of this method can be a first terminal. Among them, the first terminal can be a computer device such as a notebook computer or a desktop computer, or it can also be an IoT device (specifically such as a smart watch, a vehicle-mounted device, etc.). This method can specifically include the following steps:
[0030] In step S102, send a user's identity authentication request to a preset service server.
[0031] Among them, the service server can be the back-end server of any service (which can be the target service). The service server can be an independent server or a server cluster composed of multiple servers, etc. The target service can be any service, such as biometric identification services, financial services (such as payment services, transfer services, lending services, or insurance services, etc.), which can be specifically set according to the actual situation, and the embodiments of this specification do not limit this. The identity authentication request can be a request for authenticating the identity of a user. In actual applications, the identity authentication request can be an authentication request triggered along with other requests or instructions. For example, when performing a payment service, when sending a payment request to the corresponding server, the identity verification request of the user can be triggered first, and the payment process can be executed after the authentication is passed. In actual applications, in addition to the above situations, there can also be various different scenarios, which can be specifically set according to the actual situation, and the embodiments of this specification do not limit this.
[0032] In practice, with the advancement of the digital trend, more and more organizations have started to implement paperless office. The internal OA systems, ERP systems, CRM systems, etc. of organizations all need to authenticate the identity of the users who are operating. In addition, many online services also need to authenticate the identity of the users who request the service. Currently, most of the ways to authenticate the identity of users on personal computers (PCs) are using passwords, text messages, TOTP, etc., while the identity authentication methods on mobile devices have developed to biometric authentication methods (such as fingerprint authentication method, face authentication method, voiceprint authentication method, etc.). The above authentication methods can verify the identity of users very accurately and efficiently. Obviously, the identity authentication method on the PC side is relatively backward and there are also risks such as loss and theft of authentication information. Therefore, it is necessary to provide a technical solution that can improve the identity authentication technical means in the current PC environment, thereby reducing the possibility of being attacked by gray and black industries. The embodiments of this specification provide a feasible technical solution, which can specifically include the following content:
[0033] In actual applications, when a certain user needs to execute a certain service (i.e., the target service), the user can trigger the execution of the target service through the corresponding application installed in the first terminal. When the first terminal determines that the user needs to execute the target service, it can detect whether identity authentication is required before executing the target service. If it is determined that identity authentication is required before executing the target service, the first terminal can obtain the relevant information of the user (such as the identifier of the user (such as account number, code, etc.)) and the relevant information of the first terminal (such as the identifier of the first terminal (such as the name of the first terminal, MAC address, IP address, etc.)), etc. Then, an identity authentication request for the user can be generated based on the obtained information, and the identity authentication request of the user can be sent to the service server.
[0034] In step S104, an identity authentication instruction sent by the service server is received. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal.
[0035] Among them, the second terminal can be a terminal capable of performing a certain identity authentication method, such as a mobile phone, a tablet computer, etc. The identity authentication method can include multiple types, such as fingerprint authentication method, face authentication method, voiceprint authentication method, etc., which can be specifically set according to the actual situation, and the embodiments of this specification do not limit this.
[0036] In implementation, as Figure 2 shown, after the service server receives the user's identity authentication request, it can determine whether the target service requires the user's identity to be authenticated through another terminal (i.e., the second terminal). If so, it can obtain relevant information (such as the relevant information of the above user and the relevant information of the first terminal, etc.), generate an identity authentication instruction based on the obtained relevant information. The identity authentication instruction can be used to instruct the user to authenticate the user's identity through the second terminal, and the identity authentication instruction can be sent to the first terminal, and the first terminal can receive the identity authentication instruction sent by the service server.
[0037] In step S106, a wireless connection with the second terminal is established, and the above identity authentication instruction is sent to the second terminal through the wireless connection.
[0038] Among them, the wireless connection can include multiple types. For example, the wireless connection can be implemented by means of Bluetooth connection, or by means of near field communication NFC, etc., which can be specifically set according to the actual situation, and the embodiments of this specification do not limit this.
[0039] In implementation, after the first terminal receives the user's identity authentication instruction, it can start the component corresponding to the wireless connection method it has locally. For example, if the first terminal includes a Bluetooth component, at this time, the Bluetooth component can be started, and the Bluetooth signals of other terminals can be searched through the Bluetooth component of the first terminal. The Bluetooth signal of the user's other terminal can be selected from the searched Bluetooth signals. After the selection is completed, the terminal corresponding to the selected Bluetooth signal can be used as the second terminal. At this time, the first terminal can establish a wireless connection with the second terminal through Bluetooth. After the establishment is completed, the above identity authentication instruction can be sent to the second terminal through the wireless connection.
[0040] In step S108, the identity authentication result of the user sent by the second terminal is received, and the service server is triggered to perform service processing on the target service based on the identity authentication result.
[0041] In implementation, after receiving the identity authentication instruction through a wireless connection, the second terminal can invoke the identity authentication method set in the second terminal. For example, if the identity authentication method set in the second terminal is the fingerprint authentication method, the fingerprint authentication method set in the second terminal can be invoked. At this time, the user can press a finger on the fingerprint input component, and the fingerprint input component can collect the fingerprint data of the user and compare the collected fingerprint data with the fingerprint data stored in the second terminal. If the collected fingerprint data matches the fingerprint data stored in the second terminal, it is determined that the identity authentication result of the user is passed. If the collected fingerprint data does not match the fingerprint data stored in the second terminal, it is determined that the identity authentication result of the user is not passed. If the identity authentication result of the user is passed, subsequent processing can be performed, that is, based on the identity authentication result, the service server is triggered to perform business processing on the target business. For example, based on the identity authentication result, it can be determined that the user can log in to the internal OA system of the organization. At this time, the user can use the OA system.
[0042] An embodiment of this specification provides an identity authentication method, which is applied to a first terminal. By sending a user's identity authentication request to a preset service server and receiving an identity authentication instruction sent by the service server, the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Then, a wireless connection with the second terminal can be established, and the identity authentication instruction can be sent to the second terminal through the wireless connection. Finally, based on the user's identity authentication result, the service server is triggered to perform business processing on the target business. In this way, when a user operates on a target business on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to a second terminal of the user, such as a mobile phone or a tablet computer, with which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target business on the PC can be automatically advanced and the business processing can be finally completed, thereby reducing the intermediate links of business processing, ensuring the reliable delivery of messages, and improving the security of business processing.
[0043] Embodiment 2
[0044] As Figure 3 As shown, an embodiment of this specification provides an identity authentication method. The execution subject of this method can be a first terminal. Among them, the first terminal can be a computer device such as a notebook computer or a desktop computer, or it can also be an IoT device (specifically, such as a smart watch, a vehicle-mounted device, etc.). This method can specifically include the following steps:
[0045] In step S302, send a user's identity authentication request to a preset service server.
[0046] In implementation, as Figure 4 shown, an application program for executing a certain service (i.e., the target service) can be installed in the first terminal. A triggering mechanism for the target service can be set in the application program. When the user performs a service operation through the application program, the service of the target service will request identity authentication. At this time, the first terminal can obtain relevant information of the user and relevant information of the first terminal, etc. Then, an identity authentication request for the user can be generated based on the obtained information, and the identity authentication request for the user can be sent to the service server.
[0047] In step S304, obtain the current operating environment information.
[0048] In implementation, an SDK for identity authentication can be set in the first terminal. Through this SDK, relevant information of the user's first terminal can be collected. Specifically, for example, it can be collected whether there are Bluetooth components, NFC components, etc. in the first terminal. In addition, Bluetooth signals and / or NFC signals, etc. existing around the first terminal can be obtained through the Bluetooth component or NFC component, etc. of the first terminal, and it can be determined whether the Bluetooth signals and / or NFC signals, etc. existing around are signals sent by another terminal of the user. The relevant information obtained through the above methods can be used as the current operating environment information.
[0049] In step S306, send the above operating environment information to the service server. The operating environment information is used to trigger the service server to determine whether the user's identity can be authenticated through the second terminal. If so, send the identity authentication instruction to the first terminal.
[0050] In implementation, the first terminal can send the above operating environment information to the service server. The service server can start or trigger the processing mechanism of the corresponding identity verification service. Then, it can be determined whether the user's identity can be authenticated through the second terminal based on the above operating environment information. If the user's identity can be authenticated through the second terminal, the identity authentication instruction can be sent to the first terminal. The generation method of the identity authentication instruction can refer to the above relevant content and will not be elaborated here.
[0051] In step S308, receive the identity authentication instruction sent by the service server. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal.
[0052] In step S310, search for the currently broadcast wireless signals.
[0053] In implementation, after the service server returns the identity authentication instruction to the first terminal, the first terminal can launch the identity authentication front-end component through the above-mentioned identity authentication SDK, and the identity authentication front-end component will search for the currently broadcast wireless signals (including Bluetooth signals or NFC signals, etc.).
[0054] In step S312, based on the searched wireless signals, establish a wireless connection with the second terminal by means of Bluetooth connection or near-field communication.
[0055] In implementation, the first terminal can monitor the pairing connection status of the Bluetooth component or NFC component. When not connected, it will prompt the user "Please bring the second terminal closer to the first terminal". Then, it can select the wireless signal sent by the second terminal from the searched wireless signals. Furthermore, the first terminal establishes a wireless connection with the second terminal.
[0056] In practical applications, when specifically establishing a wireless connection, it can also be implemented through the following steps A2 to A8:
[0057] In step A2, obtain the identifier of the user.
[0058] Among them, the identifier of the user can include the user's account, code, etc., and can be specifically set according to the actual situation. The embodiments of this specification do not limit this.
[0059] In step A4, determine the device information of the terminal device corresponding to the identifier of the user.
[0060] In implementation, a corresponding relationship between the identifier of the user and the device information of the terminal device can be established in advance. The same user can correspond to the device information of multiple different terminal devices. Based on this, through the obtained identifier of the user, the device information of the terminal device corresponding to the identifier of the user can be obtained from the pre-established corresponding relationship between the identifier of the user and the device information of the terminal device.
[0061] In step A6, based on the determined device information, determine the device information of the second terminal.
[0062] In implementation, a device information can be randomly selected from the determined device information as the device information of the second terminal, or a device information with the strongest performance of a terminal device can also be selected from the determined device information as the device information of the second terminal, etc. It can be specifically set according to the actual situation. The embodiments of this specification do not limit this.
[0063] In step A8, based on the device information of the second terminal, establish a wireless connection with the second terminal.
[0064] In step S314, send the above-mentioned identity authentication instruction to the second terminal through the above-mentioned wireless connection.
[0065] In step S316, receive the identity authentication result of the user sent by the second terminal, and send a service processing request for the target service to the service server, where the service processing request includes the above identity authentication result.
[0066] In implementation, the user can click on the identity authentication instruction received by the second terminal. At this time, the second terminal can open its own identity authentication module, which can be pre-configured according to the actual situation. Through this identity authentication module, the fingerprint, face, digital certificate, etc. of the user can be verified, so as to achieve the purpose of identity authentication. The user collects the biometric data of the user (such as facial feature data or fingerprint data, etc.) through the identity authentication module. Then, the collected biometric data can be encrypted, and the encrypted biometric data can be submitted to the service server for identity authentication with the user's authorization. After the identity authentication is completed, the service server can return the identity authentication result of the user to the second terminal, and the second terminal can send the identity authentication result of the user to the first terminal. Or, the user collects the biometric data of the user (such as facial feature data or fingerprint data, etc.) through the identity authentication module. Then, the collected biometric data can be matched with the corresponding pre-stored biometric data to obtain the identity authentication result of the user, and the second terminal can send the identity authentication result of the user to the first terminal and the service server.
[0067] The first terminal can analyze the identity authentication result of the user. If the identity authentication result is authentication passed, it can further obtain the relevant service data of the target service, and can generate a service processing request for the target service based on the obtained service data and the above identity authentication result, and send the service processing request for the target service to the service server.
[0068] In step S318, receive the data corresponding to the service processing request sent by the service server, where the data corresponding to the service processing request is sent by the service server when it determines that the identity authentication result is authentication passed, and the identity authentication result of the user sent by the second terminal is stored in the service server, and the identity authentication result sent by the second terminal is authentication passed.
[0069] An embodiment of this specification provides an identity authentication method, which is applied to a first terminal. By sending a user's identity authentication request to a preset service server and receiving an identity authentication instruction sent by the service server, the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Then, a wireless connection with the second terminal can be established, and the identity authentication instruction can be sent to the second terminal through this wireless connection. Finally, based on the user's identity authentication result, the service server is triggered to perform business processing on the target business. In this way, when a user operates a target business on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to the second terminal of the user, such as a mobile phone or a tablet computer, with which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target business on the PC can be automatically advanced and the business processing can be finally completed, thereby reducing the intermediate links of business processing, ensuring the reliable delivery of messages, and improving the security of business processing.
[0070] Embodiment III
[0071] As Figure 5 As shown in the figure, an embodiment of this specification provides an identity authentication method. The execution subject of this method can be a service server. Among them, the service server can be an independent server, or a server cluster composed of multiple servers, etc. The service server can be a background server for financial business or online shopping business, etc., or a background server of a certain application program, or a management server of an internal system of a certain organization, etc. This method can specifically include the following steps:
[0072] In step S502, receive the user's identity authentication request sent by the user's first terminal.
[0073] In step S504, based on the above identity authentication request, send the user's identity authentication instruction to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through this wireless connection. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal.
[0074] In step S506, receive the user's identity authentication result sent by the second terminal, and when receiving the user's identity authentication result sent by the first terminal, perform business processing on the target business.
[0075] For the specific processing procedures of the above steps S502 to S506, reference can be made to the relevant content above, and details will not be repeated here.
[0076] An embodiment of this specification provides an identity authentication method, which is applied to a service server. By sending a user's identity authentication request to a preset service server and receiving an identity authentication instruction sent by the service server, the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Then, a wireless connection with the second terminal can be established, and the identity authentication instruction can be sent to the second terminal through this wireless connection. Finally, based on the user's identity authentication result, the service server is triggered to perform service processing on the target service. In this way, when the user operates the target service on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to the second terminal of the user, such as a mobile phone or a tablet computer, to which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target service on the PC can be automatically advanced and the service processing can be finally completed, thereby reducing the intermediate links of the service processing, ensuring the reliable delivery of messages, and improving the security of the service processing.
[0077] Embodiment 4
[0078] As Figure 6 As shown, an embodiment of this specification provides an identity authentication method. The execution subject of this method can be a service server and a first terminal. Among them, the first terminal can be a computer device such as a laptop or a desktop computer, or it can also be an IoT device (specifically, such as a smart watch, a vehicle-mounted device, etc.). The service server can be an independent server, or it can also be a server cluster composed of multiple servers. The service server can be a background server for financial services or online shopping services, etc., or it can also be a background server of a certain application program, or it can also be a management server of the internal system of an organization, etc. The method can specifically include the following steps:
[0079] In step S602, the service server receives the user's identity authentication request sent by the first terminal.
[0080] In step S604, the first terminal obtains the current operating environment information.
[0081] In step S606, the service server receives the operating environment information sent by the first terminal.
[0082] In step S608, based on the above operating environment information, the service server determines whether the user's identity can be authenticated through the second terminal.
[0083] In step S610, if so, the service server sends the user's identity authentication instruction to the first terminal based on the above identity authentication request.
[0084] In step S612, the first terminal establishes a wireless connection with the second terminal and sends the identity authentication instruction to the second terminal through the wireless connection.
[0085] In step S614, the first terminal receives the identity authentication result of the user sent by the second terminal.
[0086] In step S616, the service server receives the service processing request for the target service sent by the first terminal, and the service processing request includes the above identity authentication result.
[0087] In step S618, if the above identity authentication result is authentication passed, and the identity authentication result of the user sent by the second terminal is stored locally, and the identity authentication result sent by the second terminal is authentication passed, then the service server processes the target service to obtain the data corresponding to the service processing request.
[0088] In step S620, the service server sends the data corresponding to the service processing request to the first terminal.
[0089] For the specific processing procedures of the above steps S602 to S620, reference may be made to the above relevant content and will not be elaborated here.
[0090] The embodiment of the present specification provides an identity authentication method. By sending an identity authentication request of a user to a preset service server and receiving an identity authentication instruction sent by the service server, the identity authentication instruction is used to instruct the user to authenticate the identity of the user through a second terminal. Then, a wireless connection with the second terminal can be established, and the identity authentication instruction is sent to the second terminal through the wireless connection. Finally, based on the identity authentication result of the user, the service server is triggered to process the target service. In this way, when a user operates a target service on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to a second terminal of the user, such as a mobile phone or a tablet computer, to which a wireless connection has been established. The user can authenticate the identity of the user through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target service on the PC can be automatically advanced and the service processing is finally completed, thereby reducing the intermediate links of the service processing, ensuring the reliable delivery of messages, and improving the security of the service processing.
[0091] Embodiment Five
[0092] The above is the identity authentication method provided by the embodiment of the present specification. Based on the same idea, the embodiment of the present specification also provides an identity authentication system, as Figure 7As shown in the figure, the identity authentication system includes a server 701, a first terminal 702, and a second terminal 703, where:
[0093] The first terminal 702 sends a user identity authentication request to the server 701;
[0094] Based on the identity authentication request, the server 701 sends a user identity authentication instruction to the first terminal 702, and the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal 703;
[0095] The first terminal 702 establishes a wireless connection with the second terminal 703 and sends the identity authentication instruction to the second terminal 703 through the wireless connection;
[0096] The second terminal 703 authenticates the user's identity based on the identity authentication instruction to obtain the user's identity authentication result;
[0097] The first terminal 702 receives the user's identity authentication result sent by the second terminal 703 and triggers the server 701 to perform service processing on the target service based on the identity authentication result.
[0098] In the embodiments of this specification, the second terminal 703 authenticates the user's identity based on the identity authentication instruction through any of the following identity authentication methods to obtain the user's identity authentication result: fingerprint authentication method, palmprint authentication method, iris authentication method, face authentication method, and voiceprint authentication method.
[0099] In the embodiments of this specification, the second terminal 703 obtains target data required for authenticating the user's identity based on the identity authentication instruction, encrypts the target data, and sends the encrypted target data to the server 701;
[0100] The server 701 decrypts the encrypted target data, authenticates the user's identity based on the decrypted target data to obtain the user's identity authentication result, and sends the user's identity authentication result to the second terminal 703.
[0101] For the specific processing procedures of the above server 701, first terminal 702, and second terminal 703, reference may be made to the above relevant content and will not be elaborated here.
[0102] An embodiment of this specification provides an identity authentication system. By sending a user's identity authentication request to a preset server and receiving an identity authentication instruction sent by the server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Then, a wireless connection with the second terminal can be established, and the identity authentication instruction can be sent to the second terminal through the wireless connection. Finally, based on the user's identity authentication result, the server is triggered to perform business processing on the target business. In this way, when a user operates on a target business on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to a second terminal of the user, such as a mobile phone or a tablet computer, with which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target business on the PC can be automatically advanced and the business processing can be finally completed, thereby reducing the intermediate links of business processing, ensuring the reliable delivery of messages, and improving the security of business processing.
[0103] Embodiment Six
[0104] The above is the identity authentication system provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an identity authentication device, as Figure 8 shown.
[0105] The identity authentication device includes: an authentication request module 801, an authentication instruction module 802, a wireless connection module 803, and a business processing module 804, where:
[0106] The authentication request module 801 sends a user's identity authentication request to a preset business server;
[0107] The authentication instruction module 802 receives the identity authentication instruction sent by the business server, and the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal;
[0108] The wireless connection module 803 establishes a wireless connection with the second terminal and sends the identity authentication instruction to the second terminal through the wireless connection;
[0109] The business processing module 804 receives the user's identity authentication result sent by the second terminal and triggers the business server to perform business processing on the target business based on the identity authentication result.
[0110] In the embodiments of this specification, the authentication instruction module 802 includes:
[0111] An environment information acquisition unit that acquires the current operation environment information;
[0112] An information sending unit that sends the operation environment information to the service server, where the operation environment information is used to trigger the service server to determine whether the identity of the user can be authenticated through a second terminal. If so, the identity authentication instruction is sent to the first terminal;
[0113] An instruction receiving unit that receives the identity authentication instruction sent by the service server.
[0114] In an embodiment of the present specification, the wireless connection module 803 includes:
[0115] An identifier obtaining unit that obtains an identifier of the user;
[0116] A first information determining unit that determines device information of a terminal device corresponding to the identifier of the user;
[0117] A second information determining unit that determines device information of the second terminal based on the determined device information;
[0118] A first wireless connection unit that establishes a wireless connection with the second terminal based on the device information of the second terminal.
[0119] In an embodiment of the present specification, the wireless connection module 803 includes:
[0120] A signal searching unit that searches for currently broadcast wireless signals;
[0121] A second wireless connection unit that establishes a wireless connection with the second terminal based on the searched wireless signals by means of Bluetooth connection or near-field communication.
[0122] In an embodiment of the present specification, the service processing module 804 includes:
[0123] A service request unit that sends a service processing request for the target service to the service server, where the service processing request includes the identity authentication result;
[0124] A data receiving unit that receives data corresponding to the service processing request sent by the service server, where the data corresponding to the service processing request is sent when the service server determines that the identity authentication result is authentication passed, and the service server stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed.
[0125] An embodiment of this specification provides an identity authentication device. By sending a user's identity authentication request to a preset service server and receiving an identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Then, a wireless connection with the second terminal can be established, and the identity authentication instruction can be sent to the second terminal through the wireless connection. Finally, based on the user's identity authentication result, the service server is triggered to perform service processing on the target service. In this way, when a user operates the target service on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to the user's second terminal, such as a mobile phone or a tablet computer, to which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target service on the PC can be automatically advanced and the service processing can be finally completed, thereby reducing the intermediate links of the service processing, ensuring the reliable delivery of messages, and improving the security of the service processing.
[0126] Embodiment Seven
[0127] Based on the same idea, an embodiment of this specification also provides an identity authentication device, as Figure 9 shown.
[0128] This identity authentication device includes: a request receiving module 901, an instruction sending module 902, and a service processing module 903, where:
[0129] The request receiving module 901 receives the user's identity authentication request sent by the user's first terminal;
[0130] The instruction sending module 902, based on the identity authentication request, sends the user's identity authentication instruction to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal and send the identity authentication instruction to the second terminal through the wireless connection. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal;
[0131] The service processing module 903 receives the user's identity authentication result sent by the second terminal and performs service processing on the target service when receiving the user's identity authentication result sent by the first terminal.
[0132] In an embodiment of this specification, the request receiving module 901 includes:
[0133] An environment information receiving unit that receives the operation environment information sent by the first terminal;
[0134] A determination unit that determines whether the identity of the user can be authenticated through the second terminal based on the operation environment information;
[0135] A request receiving unit that, if so, sends an identity authentication instruction for the user to the first terminal based on the identity authentication request.
[0136] In the embodiments of the present specification, the service processing module 903 includes:
[0137] A service processing request unit that receives a service processing request for the target service sent by the first terminal, where the service processing request includes the identity authentication result;
[0138] A service processing unit that, if the identity authentication result is authentication passed, and the identity authentication result of the user sent by the second terminal is locally stored and the identity authentication result sent by the second terminal is authentication passed, then performs service processing on the target service to obtain data corresponding to the service processing request;
[0139] A data sending unit that sends the data corresponding to the service processing request to the first terminal.
[0140] The embodiments of the present specification provide an identity authentication device. By sending an identity authentication request of a user to a preset service server and receiving an identity authentication instruction sent by the service server, the identity authentication instruction is used to instruct the user to authenticate the identity of the user through a second terminal. Then, a wireless connection can be established with the second terminal, and the identity authentication instruction is sent to the second terminal through the wireless connection. Finally, based on the identity authentication result of the user, the service server is triggered to perform service processing on the target service. In this way, when the user operates the target service on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to the second terminal of the user, such as a mobile phone or a tablet computer, with which a wireless connection has been established. The user can authenticate the identity of the user through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target service on the PC can be automatically advanced and the service processing is finally completed, thereby reducing the intermediate links of service processing, ensuring the reliable delivery of messages, and improving the security of service processing.
[0141] Embodiment Eight
[0142] The above is the identity authentication device provided by the embodiments of the present specification. Based on the same idea, the embodiments of the present specification also provide an identity authentication device, such as Figure 10 shown.
[0143] The identity authentication device may be the first device or the service server provided in the above embodiments, etc.
[0144] Identity authentication devices can vary significantly due to differences in configuration or performance. They can include one or more processors 1001 and a memory 1002. One or more stored application programs or data can be stored in the memory 1002. Among them, the memory 1002 can be transient storage or persistent storage. The application programs stored in the memory 1002 can include one or more modules (not shown in the figure), and each module can include a series of computer-executable instructions for the identity authentication device. Further, the processor 1001 can be set to communicate with the memory 1002 and execute a series of computer-executable instructions in the memory 1002 on the identity authentication device. The identity authentication device can also include one or more power supplies 1003, one or more wired or wireless network interfaces 1004, one or more input / output interfaces 1005, and one or more keyboards 1006.
[0145] Specifically, in this embodiment, the identity authentication device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs can include one or more modules. Each module can include a series of computer-executable instructions for the identity authentication device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions for:
[0146] Sending a user's identity authentication request to a preset service server;
[0147] Receiving the identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal;
[0148] Establishing a wireless connection with the second terminal and sending the identity authentication instruction to the second terminal through the wireless connection;
[0149] Receiving the identity authentication result of the user sent by the second terminal and triggering the service server to perform service processing on the target service based on the identity authentication result.
[0150] In the embodiments of this specification, the receiving the identity authentication instruction sent by the identity authentication device includes:
[0151] Obtaining the current operating environment information;
[0152] Send the operation environment information to the service server, where the operation environment information is used to trigger the service server to determine whether the identity of the user can be authenticated through the second terminal. If so, send the identity authentication instruction to the first terminal;
[0153] Receive the identity authentication instruction sent by the service server.
[0154] In the embodiments of this specification, establishing a wireless connection with the second terminal includes:
[0155] Obtain the identifier of the user;
[0156] Determine the device information of the terminal device corresponding to the identifier of the user;
[0157] Based on the determined device information, determine the device information of the second terminal;
[0158] Based on the device information of the second terminal, establish a wireless connection with the second terminal.
[0159] In the embodiments of this specification, establishing a wireless connection with the second terminal includes:
[0160] Search for currently broadcast wireless signals;
[0161] Based on the searched wireless signals, establish a wireless connection with the second terminal by means of Bluetooth connection or near-field communication.
[0162] In the embodiments of this specification, triggering the service server to perform service processing on the target service based on the identity authentication result includes:
[0163] Send a service processing request for the target service to the service server, where the service processing request includes the identity authentication result;
[0164] Receive the data corresponding to the service processing request sent by the service server, where the data corresponding to the service processing request is sent when the service server determines that the identity authentication result is authentication passed, and the service server stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed.
[0165] In addition, specifically in this embodiment, the identity authentication device includes a memory and one or more programs, where one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the identity authentication device, and is configured to execute the one or more programs by one or more processors, and the one or more programs include computer-executable instructions for performing the following:
[0166] Receiving the identity authentication request of the user sent by the first terminal of the user;
[0167] Based on the identity authentication request, sending the identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal, and sending the identity authentication instruction to the second terminal through the wireless connection, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal;
[0168] Receiving the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, performing service processing on the target service.
[0169] In the embodiment of the present specification, the sending the identity authentication instruction of the user to the first terminal based on the identity authentication request includes:
[0170] Receiving the operation environment information sent by the first terminal;
[0171] Based on the operation environment information, determining whether the identity of the user can be authenticated through the second terminal;
[0172] If so, sending the identity authentication instruction of the user to the first terminal based on the identity authentication request.
[0173] In the embodiment of the present specification, the performing service processing on the target service when receiving the identity authentication result of the user sent by the first terminal includes:
[0174] Receiving the service processing request of the target service sent by the first terminal, where the service processing request includes the identity authentication result;
[0175] If the identity authentication result is authentication passed, and the identity authentication result sent by the second terminal is stored locally and the identity authentication result sent by the second terminal is authentication passed, then performing service processing on the target service to obtain the data corresponding to the service processing request;
[0176] Send the data corresponding to the service processing request to the first terminal.
[0177] An embodiment of this specification provides an identity authentication device. By sending a user's identity authentication request to a preset service server and receiving an identity authentication instruction sent by the service server, the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal. Then, a wireless connection can be established with the second terminal, and the identity authentication instruction can be sent to the second terminal through the wireless connection. Finally, based on the user's identity authentication result, the service server is triggered to perform service processing on the target service. In this way, when the user operates the target service on the PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to the second terminal of the user, such as a mobile phone or a tablet computer, with which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target service on the PC can be automatically advanced and the service processing can be finally completed, thereby reducing the intermediate links of the service processing, ensuring the reliable delivery of messages, and improving the security of the service processing.
[0178] Embodiment Nine
[0179] Further, based on the above Figures 1 to 6 shown method, one or more embodiments of this specification also provide a storage medium for storing computer-executable instruction information. In a specific embodiment, the storage medium can be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following processes can be realized:
[0180] Send a user's identity authentication request to a preset service server;
[0181] Receive the identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal;
[0182] Establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection;
[0183] Receive the identity authentication result of the user sent by the second terminal, and trigger the service server to perform service processing on the target service based on the identity authentication result.
[0184] In the embodiment of this specification, the receiving the identity authentication instruction sent by the identity authentication device includes:
[0185] Obtain the current operation environment information;
[0186] Send the operation environment information to the service server, where the operation environment information is used to trigger the service server to determine whether the identity of the user can be authenticated through a second terminal. If so, send the identity authentication instruction to the first terminal;
[0187] Receive the identity authentication instruction sent by the service server.
[0188] In an embodiment of the present specification, establishing a wireless connection with the second terminal includes:
[0189] Obtain the identifier of the user;
[0190] Determine the device information of the terminal device corresponding to the identifier of the user;
[0191] Based on the determined device information, determine the device information of the second terminal;
[0192] Based on the device information of the second terminal, establish a wireless connection with the second terminal.
[0193] In an embodiment of the present specification, establishing a wireless connection with the second terminal includes:
[0194] Search for currently broadcast wireless signals;
[0195] Based on the searched wireless signals, establish a wireless connection with the second terminal by means of Bluetooth connection or near-field communication.
[0196] In an embodiment of the present specification, triggering the service server to perform service processing on a target service based on the identity authentication result includes:
[0197] Send a service processing request for the target service to the service server, where the service processing request includes the identity authentication result;
[0198] Receive the data corresponding to the service processing request sent by the service server, where the data corresponding to the service processing request is sent when the service server determines that the identity authentication result is authentication passed, and the service server stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed.
[0199] In addition, in another specific embodiment, the storage medium may be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be implemented:
[0200] Receive the identity authentication request of the user sent by the first terminal of the user;
[0201] Based on the identity authentication request, send the identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal;
[0202] Receive the identity authentication result of the user sent by the second terminal, and perform service processing on the target service when receiving the identity authentication result of the user sent by the first terminal.
[0203] In the embodiments of this specification, the sending the identity authentication instruction of the user to the first terminal based on the identity authentication request includes:
[0204] Receive the operation environment information sent by the first terminal;
[0205] Based on the operation environment information, determine whether the user's identity can be authenticated through the second terminal;
[0206] If so, send the identity authentication instruction of the user to the first terminal based on the identity authentication request.
[0207] In the embodiments of this specification, the performing service processing on the target service when receiving the identity authentication result of the user sent by the first terminal includes:
[0208] Receive the service processing request of the target service sent by the first terminal, where the service processing request includes the identity authentication result;
[0209] If the identity authentication result is authentication passed, and the identity authentication result sent by the second terminal is locally stored and the identity authentication result sent by the second terminal is authentication passed, then perform service processing on the target service to obtain the data corresponding to the service processing request;
[0210] Send the data corresponding to the service processing request to the first terminal.
[0211] An embodiment of this specification provides a storage medium. By sending an identity authentication request of a user to a preset service server and receiving an identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through a second terminal, then, a wireless connection with the second terminal can be established, and the identity authentication instruction can be sent to the second terminal through the wireless connection. Finally, based on the identity authentication result of the user, the service server is triggered to perform service processing on a target service. In this way, when the user operates a target service on a PC and needs to authenticate their identity, the identity verification service will send an identity verification instruction to a second terminal of the user, such as a mobile phone or a tablet computer, with which a wireless connection has been established. The user can authenticate the user's identity through the identity authentication method set in the second terminal (specifically, identity authentication can be performed through biometric features such as face, fingerprint, palmprint, iris, etc.). When the user passes the identity verification, the target service on the PC can be automatically advanced and the service processing can be finally completed, thereby reducing the intermediate links of the service processing, ensuring the reliable delivery of messages, and improving the security of the service processing.
[0212] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.
[0213] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented using a hardware entity module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system onto a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL), and there is not just one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into an integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.
[0214] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or the structures within the hardware component.
[0215] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0216] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0217] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0218] Embodiments of the present specification are described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present specification. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable serial-parallel devices for fraud cases to generate a machine, such that the instructions executed by the processor of the computer or other programmable serial-parallel devices for fraud cases generate means for implementing the functions specified in the process Figure One one process or multiple processes and / or blocks Figure One or means for implementing the functions specified in multiple blocks.
[0219] These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable serial-parallel devices for fraud cases to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in the process Figure One one process or multiple processes and / or blocks Figure One or means for implementing the functions specified in multiple blocks.
[0220] These computer program instructions can also be loaded onto a computer or other programmable serial-parallel devices for fraud cases, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in the process Figure One one process or multiple processes and / or blocks Figure One or means for implementing the functions specified in multiple blocks.
[0221] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0222] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0223] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0224] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0225] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, one or more embodiments of this specification may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0226] One or more embodiments of this specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. One or more embodiments of this specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0227] Each embodiment in this specification is described in a progressive manner. For the identical or similar parts among the embodiments, reference can be made to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.
[0228] The above is only the embodiment of this specification and is not used to limit this application. For those skilled in the art, various changes and modifications can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. An identity authentication method, applied to a first terminal, the method comprising: Sending a user's identity authentication request to a preset service server; Receiving an identity authentication instruction sent by the service server, the identity authentication instruction being used to instruct the user to authenticate the user's identity through a second terminal and call an identity authentication method set in the second terminal, the identity authentication method including a digital certificate authentication method, a fingerprint authentication method, and a face authentication method; Establishing a wireless connection with the second terminal, and sending the identity authentication instruction to the second terminal through the wireless connection; Receiving the identity authentication result of the user sent by the second terminal, and triggering the service server to perform business processing on a target business when the identity authentication result is authentication passed, and the service server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server performing identity authentication processing on the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user; The receiving the identity authentication instruction sent by the service server includes: Obtaining current operating environment information, the operating environment information including whether there is a Bluetooth component or a near-field communication component in the user's first terminal collected by an authenticated software development kit, obtaining Bluetooth signals and / or near-field communication component signals existing around the first terminal through the Bluetooth component or near-field communication component of the first terminal, and determining whether there is relevant information about signals sent by another terminal of the user in the existing Bluetooth signals and / or near-field communication signals around; Sending the operating environment information to the service server, the operating environment information being used to trigger the service server to determine whether the user's identity can be authenticated through the second terminal. If so, sending the identity authentication instruction to the first terminal; The establishing a wireless connection with the second terminal includes: Obtaining the identifier of the user; Determining the device information of the terminal device corresponding to the identifier of the user; Based on the determined device information, determining the device information of the second terminal; Based on the device information of the second terminal, establishing a wireless connection with the second terminal.
2. The method according to claim 1, wherein the triggering the service server to perform business processing on the target business based on the identity authentication result includes: Sending a business processing request for the target business to the service server, the business processing request including the identity authentication result; Receive the data corresponding to the service processing request sent by the service server, where the data corresponding to the service processing request is sent by the service server when it determines that the identity authentication result is authentication passed, and the service server stores the identity authentication result of the user sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed.
3. An identity authentication method applied to a service server, the method comprising: Receive an identity authentication request of a user sent by a first terminal of the user; Based on the identity authentication request, send an identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with a second terminal, and send the identity authentication instruction to the second terminal through the wireless connection, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call an identity authentication method set in the second terminal, and the identity authentication method includes a digital certificate authentication method, a fingerprint authentication method, and a face authentication method; Receive the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, perform service processing on a target service when the identity authentication result is authentication passed, and the service server locally stores the identity authentication result of the user sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server performing identity authentication processing on encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user; The sending the identity authentication instruction of the user to the first terminal based on the identity authentication request includes: Receive the operation environment information sent by the first terminal, where the operation environment information includes information collected by a software development kit that has passed identity authentication on whether there is a Bluetooth component and a near field communication component in the first terminal of the user, obtaining Bluetooth signals and / or near field communication component signals existing around the first terminal through the Bluetooth component or near field communication component of the first terminal, and determining whether there are signals sent by another terminal of the user among the existing Bluetooth signals and / or near field communication signals around; Based on the operation environment information, determine whether the user's identity can be authenticated through the second terminal; If so, send the identity authentication instruction of the user to the first terminal based on the identity authentication request; The first terminal establishing a wireless connection with the second terminal includes: Obtain the identifier of the user; Determine the device information of the terminal device corresponding to the identifier of the user; Based on the determined device information, determine the device information of the second terminal; Establish a wireless connection with the second terminal based on the device information of the second terminal.
4. The method according to claim 3, wherein when receiving the identity authentication result of the user sent by the first terminal, performing service processing on the target service, comprising: Receiving a service processing request for the target service sent by the first terminal, where the service processing request includes the identity authentication result; If the identity authentication result is authentication passed, and the identity authentication result of the user sent by the second terminal is locally stored and the identity authentication result sent by the second terminal is authentication passed, then perform service processing on the target service to obtain data corresponding to the service processing request; Send the data corresponding to the service processing request to the first terminal.
5. An identity authentication system, the identity authentication system comprising a server, a first terminal, and a second terminal, wherein: The first terminal sends an identity authentication request of a user to the server; The server, based on the identity authentication request, sends an identity authentication instruction for the user to the first terminal, where the identity authentication instruction is used to instruct the user to authenticate the identity of the user through the second terminal. The sending of the identity authentication instruction for the user to the first terminal based on the identity authentication request includes: receiving the operation environment information sent by the first terminal, where the operation environment information includes whether there is a Bluetooth component or a near field communication component in the first terminal of the user collected by a software development kit that has passed identity authentication, obtaining Bluetooth signals and / or near field communication component signals existing around the first terminal through the Bluetooth component or the near field communication component of the first terminal, and determining whether there is relevant information of a signal sent by another terminal of the user in the existing Bluetooth signals and / or near field communication signals around. Based on the operation environment information, determining whether the identity of the user can be authenticated through the second terminal. If so, based on the identity authentication request, send the identity authentication instruction for the user to the first terminal; The first terminal establishes a wireless connection with the second terminal and sends the identity authentication instruction to the second terminal through the wireless connection. The establishment of the wireless connection with the second terminal includes: obtaining the identifier of the user, determining the device information of the terminal device corresponding to the identifier of the user, determining the device information of the second terminal based on the determined device information, and establishing a wireless connection with the second terminal based on the device information of the second terminal; The second terminal authenticates the identity of the user based on the identity authentication instruction and by invoking the identity authentication method set in the second terminal, and obtains the identity authentication result of the user. The identity authentication method includes digital certificate authentication method, fingerprint authentication method, and face authentication method. The identity authentication result is obtained by the service server through identity authentication processing on the encrypted biometric data submitted by the second terminal with the user's authorization. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user; The first terminal receives the identity authentication result of the user sent by the second terminal, and based on the identity authentication result, triggers the service server to perform business processing on the target business when the identity authentication result is authentication passed, and the service server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed.
6. The system according to claim 5, wherein the second terminal authenticates the identity of the user based on the identity authentication instruction by any one of the following identity authentication methods to obtain the identity authentication result of the user: fingerprint authentication method, palmprint authentication method, iris authentication method, face authentication method, and voiceprint authentication method.
7. The system according to claim 5, wherein the second terminal, based on the identity authentication instruction, obtains the target data required for authenticating the identity of the user, encrypts the target data, and sends the encrypted target data to the server; The server decrypts the encrypted target data, authenticates the identity of the user based on the decrypted target data, obtains the identity authentication result of the user, and sends the identity authentication result of the user to the second terminal.
8. An identity authentication device, the device comprising: An authentication request module that sends an identity authentication request of a user to a preset service server; The authentication instruction module receives the identity authentication instruction sent by the service server. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call the identity authentication method set in the second terminal. The identity authentication method includes digital certificate authentication method, fingerprint authentication method, and face authentication method. The receiving of the identity authentication instruction sent by the service server includes: obtaining the current operating environment information, where the operating environment information includes whether there is a Bluetooth component and a near-field communication component in the user's first terminal collected by the software development kit that has passed the identity authentication, obtaining the Bluetooth signal and / or near-field communication component signal existing around the first terminal through the Bluetooth component or near-field communication component of the first terminal, and determining whether there is relevant information of the signal sent by another terminal of the user in the Bluetooth signal and / or near-field communication signal existing around; sending the operating environment information to the service server, and the operating environment information is used to trigger the service server to determine whether the user's identity can be authenticated through the second terminal. If so, send the identity authentication instruction to the first terminal; The wireless connection module establishes a wireless connection with the second terminal and sends the identity authentication instruction to the second terminal through the wireless connection. The establishment of the wireless connection with the second terminal includes: obtaining the identifier of the user, determining the device information of the terminal device corresponding to the identifier of the user, based on the determined device information, determining the device information of the second terminal, and establishing a wireless connection with the second terminal based on the device information of the second terminal; The service processing module receives the identity authentication result of the user sent by the second terminal, and based on the identity authentication result, triggers the service server to perform service processing on the target service when the identity authentication result is authentication passed, and the service server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server performing identity authentication processing on the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user.
9. An identity authentication device, the device includes: The request receiving module receives the identity authentication request of the user sent by the user's first terminal; An instruction sending module, based on the identity authentication request, sends the user's identity authentication instruction to the first terminal, so as to trigger the first terminal to establish a wireless connection with a second terminal, and send the identity authentication instruction to the second terminal through the wireless connection. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call the identity authentication method set in the second terminal. The identity authentication method includes a digital certificate authentication method, a fingerprint authentication method, and a face authentication method. The sending the user's identity authentication instruction to the first terminal based on the identity authentication request includes: receiving the operation environment information sent by the first terminal, where the operation environment information includes whether there is a Bluetooth component and a near field communication component in the user's first terminal collected by a software development kit that has passed identity authentication, obtaining the Bluetooth signal and / or near field communication component signal existing around the first terminal through the Bluetooth component or near field communication component of the first terminal, and determining whether there is information related to the signal sent by another terminal of the user in the Bluetooth signal and / or near field communication signal existing around. Based on the operation environment information, determining whether the user's identity can be authenticated through the second terminal; if so, sending the user's identity authentication instruction to the first terminal based on the identity authentication request; the first terminal establishing a wireless connection with the second terminal includes: obtaining the identifier of the user, determining the device information of the terminal device corresponding to the identifier of the user, determining the device information of the second terminal based on the determined device information, and establishing a wireless connection with the second terminal based on the device information of the second terminal; A service processing module, receives the user's identity authentication result sent by the second terminal, and when receiving the user's identity authentication result sent by the first terminal, performs service processing on the target service in the case where the identity authentication result is authentication passed, and the service server locally stores the user's identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server performing identity authentication processing on the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user.
10. An identity authentication device, the device includes a trusted execution environment, and the identity authentication device includes: A processor; And A memory arranged to store computer-executable instructions, and the executable instructions, when executed, cause the processor to: Send a user's identity authentication request to a preset service server; Receive the identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call the set identity authentication method in the second terminal. The identity authentication methods include digital certificate authentication method, fingerprint authentication method, and face authentication method. The receiving the identity authentication instruction sent by the service server includes: obtaining the current operating environment information, where the operating environment information includes whether there is a Bluetooth component and a near field communication component in the user's first terminal collected by the software development kit that has passed the identity authentication, obtaining the Bluetooth signal and / or near field communication component signal existing around the first terminal through the Bluetooth component or near field communication component of the first terminal, and determining whether there is relevant information of the signal sent by another terminal of the user in the existing Bluetooth signal and / or near field communication signal around; sending the operating environment information to the service server, where the operating environment information is used to trigger the service server to determine whether the user's identity can be authenticated through the second terminal. If so, send the identity authentication instruction to the first terminal; Establish a wireless connection with the second terminal and send the identity authentication instruction to the second terminal through the wireless connection. The establishing the wireless connection with the second terminal includes: obtaining the identifier of the user, determining the device information of the terminal device corresponding to the identifier of the user, determining the device information of the second terminal based on the determined device information, and establishing a wireless connection with the second terminal based on the device information of the second terminal; Receive the identity authentication result of the user sent by the second terminal, and trigger the service server to process the target service when the identity authentication result is authentication passed, and the service server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server through identity authentication processing of the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the set identity authentication method in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user.
11. An identity authentication device, the device includes a trusted execution environment, and the identity authentication device includes: A processor; And A memory arranged to store computer-executable instructions, and the executable instructions, when executed, cause the processor to: Receive the identity authentication request of the user sent by the user's first terminal; Based on the identity authentication request, send the identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call the identity authentication method set in the second terminal. The identity authentication method includes a digital certificate authentication method, a fingerprint authentication method, and a face authentication method. The step of sending the identity authentication instruction of the user to the first terminal based on the identity authentication request includes: receiving the operation environment information sent by the first terminal. The operation environment information includes whether there are Bluetooth components and near-field communication components in the first terminal of the user collected by the software development kit that has passed the identity authentication. Obtain the Bluetooth signal and / or near-field communication component signal existing around the first terminal through the Bluetooth component or near-field communication component of the first terminal, and determine whether there is relevant information about the signal sent by another terminal of the user in the existing Bluetooth signal and / or near-field communication signal around. Based on the operation environment information, determine whether the user's identity can be authenticated through the second terminal. If so, based on the identity authentication request, send the identity authentication instruction of the user to the first terminal. The first terminal establishing a wireless connection with the second terminal includes: obtaining the identifier of the user, determining the device information of the terminal device corresponding to the identifier of the user, based on the determined device information, determining the device information of the second terminal, and establishing a wireless connection with the second terminal based on the device information of the second terminal; Receive the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, when the identity authentication result is authentication passed, and the business server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed, perform business processing on the target business. The identity authentication result is obtained by the business server performing identity authentication processing on the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user.
12. A storage medium, which is used to store computer-executable instructions. When the executable instructions are executed by a processor, the following process is implemented: Send a user's identity authentication request to a preset business server; Receive the identity authentication instruction sent by the service server, where the identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call the identity authentication method set in the second terminal. The identity authentication method includes a digital certificate authentication method, a fingerprint authentication method, and a face authentication method. The receiving of the identity authentication instruction sent by the service server includes: Obtain the current operating environment information, where the operating environment information includes whether there are Bluetooth components and near-field communication components in the user's first terminal collected by an authenticated software development kit, obtain the Bluetooth signals and / or near-field communication component signals existing around the first terminal through the Bluetooth component or near-field communication component of the first terminal, and determine whether there is relevant information about signals sent by another terminal of the user in the Bluetooth signals and / or near-field communication signals existing around; send the operating environment information to the service server, and the operating environment information is used to trigger the service server to determine whether the user's identity can be authenticated through the second terminal. If so, send the identity authentication instruction to the first terminal; Establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection. The establishment of the wireless connection with the second terminal includes: obtaining the identifier of the user, determining the device information of the terminal device corresponding to the identifier of the user, based on the determined device information, determining the device information of the second terminal, and based on the device information of the second terminal, establishing a wireless connection with the second terminal; Receive the identity authentication result of the user sent by the second terminal, and based on the identity authentication result, trigger the service server to perform business processing on the target business when the identity authentication result is authentication passed, and the service server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server performing identity authentication processing on the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user.
13. A storage medium, which is used to store computer-executable instructions, and the executable instructions, when executed by a processor, implement the following process: Receive the identity authentication request of the user sent by the first terminal; Based on the identity authentication request, send the identity authentication instruction of the user to the first terminal to trigger the first terminal to establish a wireless connection with the second terminal, and send the identity authentication instruction to the second terminal through the wireless connection. The identity authentication instruction is used to instruct the user to authenticate the user's identity through the second terminal and call the identity authentication method set in the second terminal. The identity authentication method includes a digital certificate authentication method, a fingerprint authentication method, and a face authentication method. The sending the identity authentication instruction of the user to the first terminal based on the identity authentication request includes: Receive the operating environment information sent by the first terminal. The operating environment information includes whether there are Bluetooth components and near-field communication components in the user's first terminal collected by an authenticated software development kit, obtain the Bluetooth signals and / or near-field communication component signals existing around the first terminal through the Bluetooth component or near-field communication component of the first terminal, and determine whether there is relevant information about signals sent by another terminal of the user in the Bluetooth signals and / or near-field communication signals existing around. Based on the operating environment information, determine whether the user's identity can be authenticated through the second terminal. If so, based on the identity authentication request, send the identity authentication instruction of the user to the first terminal; The ways for the first terminal to establish a wireless connection with the second terminal include: obtaining the device information of the terminal device corresponding to the user's identifier from the pre-established correspondence between the user's identifier and the device information of the terminal device, or obtaining the device information of the terminal device corresponding to the user's identifier from the pre-established correspondence between the user's identifier and the device information of the terminal device and through Bluetooth connection or near-field communication; Receiving the identity authentication result of the user sent by the second terminal, and when receiving the identity authentication result of the user sent by the first terminal, performing service processing on the target service in the case where the identity authentication result is authentication passed, the service server locally stores the identity authentication result sent by the second terminal, and the identity authentication result sent by the second terminal is authentication passed. The identity authentication result is obtained by the service server performing identity authentication processing on the encrypted biometric data submitted by the second terminal under the authorization of the user. The encrypted biometric data is obtained by encrypting the biometric data collected by the second terminal through the identity authentication method set in the second terminal. The second terminal is the device with the strongest performance among multiple different terminal devices corresponding to the user.
Citation Information
Patent Citations
Mobile authentication method using near field communication technology
KR1020170053893A