A system for implementing unified identity authentication
By integrating multiple authentication methods through a unified identity authentication platform, the problem of SSO platforms failing to meet the security and identity verification requirements of the financial industry has been solved, achieving a unified and secure identity authentication process and improving user experience and compliance.
Patent Information
- Application Number
- CN202210141676.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-16
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2042-02-16
AI Technical Summary
Existing SSO platforms cannot meet the security requirements of industries such as finance, cannot effectively verify the authenticity of customer identification documents, and have inconsistent authentication standards among banks, resulting in a poor user experience.
By connecting multiple third-party identity authentication platforms and backends through a unified identity authentication platform, the appropriate authentication method can be selected according to business needs. The identity authentication page is integrated, the customer selects the authentication method and enters information, the unified identity authentication platform performs the authentication and returns the result, and the backend confirms the completeness and accuracy of the identity information.
It achieves compliance and security of unified identity authentication, improves user experience, meets regulatory requirements of different industries, and ensures the privacy protection of customer identity information.
Smart Images

Figure CN114925340B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of identity authentication. BACKGROUND
[0002] The authentication method of the current SSO (Single Sing On, single sign-on) platform can be used for all systems after one-time login, but this cannot meet the security requirements of many industries (for example, the financial industry). If a bank customer logs in once, all businesses can be handled, which will easily cause complaints. If a credit card is handled, a credit card is also applied for, so a business needs to be handled, and identity authentication needs to be performed once. The People's Bank requires that the customer's identity card must be checked when certain businesses are handled. The SSO cannot ensure the authenticity of the certificate, and can only use the short message verification, the identity card OCR (optical character recognition) + face recognition… method, which can only confirm the identity but cannot distinguish the certificate. A unified standard is needed to realize the identity authentication of the electronic channel. At present, each bank has its own standard, and the scheme is often not in compliance. In addition, users often do not know what to do, and the authentication standards of each bank are different. Some are too complicated, and some are too simple. A unified operation interface and method are needed. SUMMARY
[0003] The purpose of the present application is to provide a system for realizing unified identity authentication, which effectively realizes unified identity authentication.
[0004] The technical solution for realizing the above purpose is:
[0005] A system for realizing unified identity authentication, comprising: a plurality of third-party identity authentication platforms, a unified identity authentication platform, a plurality of electronic channel application ends and a plurality of backends, wherein,
[0006] The electronic channel application end sends the business selected by the customer to the corresponding backend, the backend judges the identity authentication strength and the security level according to the business provided by the customer, and sends the identity authentication strength and the security level to the unified identity authentication platform via the corresponding backend;
[0007] The unified identity authentication platform selects a method meeting the identity authentication strength and the security level requirements of the corresponding transaction from a plurality of authentication methods of the plurality of third-party identity authentication platforms according to the identity authentication strength and the security level, integrates an identity authentication page, and returns the corresponding identity authentication page to the corresponding electronic channel application end via the backend;
[0008] The customer selects an identity authentication method from an identity authentication page and inputs relevant information, the unified identity authentication platform obtains information required for identity authentication, sends the information to the corresponding third-party identity authentication platform for authentication, and transmits the obtained customer identity information or authentication result back to the corresponding background, the background compares the customer identity information or authentication result, and sends the corresponding electronic channel application end to the user for further business operation process.
[0009] Preferably, it further comprises:
[0010] The unified identity authentication platform obtains customer certificate information and transmits the encrypted information to the corresponding background after the authentication is passed according to the authentication result;
[0011] The background obtains customer certificate information after decryption, confirms whether the customer identity information is complete and accurate, and opens the corresponding business of the customer after confirmation.
[0012] Preferably, the background judges the required identity authentication strength and security level according to the industry supervision conditions of the selected business, the requirements of the competent authority, relevant regulations, and customer privacy protection.
[0013] Preferably, the electronic channel application end is a financial industry electronic channel application end, and the background is a financial industry background; the business is a financial business.
[0014] Preferably, the identity authentication method includes electronic certificate cloud reading, eID authentication, three elements of network joint inquiry, live detection, face recognition, CFCA authentication, CA authentication, SIMeID shield, three elements of mobile phone number, three elements of bank card, and four elements of bank card.
[0015] The three elements of network joint inquiry refer to name, ID number, and real-time photos of the face of the person taken by the mobile phone;
[0016] The three elements of mobile phone number refer to name, ID number, and mobile phone number.
[0017] The three elements of bank card refer to name, ID number, and bank card number.
[0018] The four elements of bank card refer to name, ID number, bank card number, and mobile phone number.
[0019] Preferably, the unified identity authentication platform collects customer information in the identity authentication page according to the identity verification requirements and process required by the third-party identity authentication platform, and submits the information to the third-party authentication platform for authentication.
[0020] Preferably, the business includes electronic channel login, large amount transfer, device binding, information update, security application, securities purchase, financing purchase, insurance purchase and payment, beneficiary authentication or change.
[0021] Preferably, the third-party identity authentication platform comprises: a provincial big data center, a legal credit investigation agency, China UnionPay, Unicom, Mobile, and Telecom.
[0022] Preferably, the customer selects an identity authentication mode from the identity authentication page and inputs related information to obtain information required for identity authentication, including:
[0023] The user inputs related information according to the third-party identity authentication requirement process, including an ID card number, a name, a mobile phone number, a bank card number, face recognition, living body detection, fingerprint recognition, iris recognition, and / or an SMS verification code, or provides an electronic ID card, a digital certificate, and a biological feature shield that can be read by an electronic channel application end.
[0024] The present application has the beneficial effects that: the present application can effectively realize unified identity authentication by setting a unified identity authentication platform to connect a third-party identity authentication platform and a background, is simple and effective, and has high security. BRIEF DESCRIPTION OF DRAWINGS
[0025] Figure 1 is a structure diagram of the system for realizing unified identity authentication of the present application;
[0026] Figure 2 is a process schematic diagram of the unified identity authentication in the present application. DETAILED DESCRIPTION
[0027] The present application will be further described below in combination with the drawings.
[0028] Many industries (for example, the financial industry) cannot disclose their customer data or provide it to a third party due to regulatory requirements, so the SSO cannot obtain customer information. According to the traditional method, the SSO needs to be connected with the customer system of the bank to know that the account exists, but generally the bank cannot be connected with the third party, and the account and password will be known by the third party, so a new method is needed to obtain customer identity information by the third party, and then store or update it. Under the national policy, a legal and compliant third-party operator can obtain customer identity information, such as China UnionPay, the rural credit clearing center, and its audited operators.
[0029] Please refer to Figures 1-2 The system for realizing unified identity authentication of the present application comprises: a plurality of third-party identity authentication platforms 1, a unified identity authentication platform 2, a plurality of electronic channel application ends 3, and a plurality of backgrounds 4. In this embodiment, the financial industry is taken as an example, such as Figure 1 The electronic channel application end 3 is a financial industry electronic channel application end, and the background 4 is a financial industry background.
[0030] The electronic channel application end 3 sends the selected service of the customer to the corresponding background 4, the background 4 judges the identity authentication strength and security level according to the service provided by it, and sends it to the unified identity authentication platform 2 through the corresponding background 4. Specifically, the background 4 judges the identity authentication strength and security level required according to the industry supervision conditions, requirements of the competent authority, relevant regulations, and customer privacy protection of the selected service.
[0031] The unified identity authentication platform 2 selects the method that meets the requirements of the identity authentication strength and security level corresponding to this transaction from the multiple authentication methods of the third-party identity authentication platform 1 according to the identity authentication strength and security level, integrates the identity authentication page, and returns the corresponding identity authentication page to the corresponding electronic channel application end 3 through the background 4. The customer selects the identity authentication method from the identity authentication page and inputs the related information, and the unified identity authentication platform obtains the information required for identity authentication. The identity authentication page is directly provided by the unified identity authentication platform, and the parameters of the user operation are directly obtained. The user inputs the related information according to the third-party identity authentication requirement process: identity card number, name, mobile phone number, bank card number, face recognition, live detection, fingerprint recognition, iris recognition, and / or SMS verification code, or provides electronic identity cards, digital certificates, and biological feature shields that can be read by the electronic channel application end.
[0032] Specifically, several common identity authentication methods are as follows: electronic certificate cloud reading, eID (eID is a network identity identification issued to citizens based on cryptographic technology and intelligent security chip, which can identify identity online remotely without revealing identity information) authentication, three elements of network joint check, live detection, face recognition, CFCA (China Financial Authentication Center) authentication, CA (Certificate Authority) authentication, SIMeID (citizen network electronic identity identification) shield, three elements of mobile phone number, three elements of bank card, and four elements of bank card.
[0033] Electronic certificate cloud reading: through NFC (near field communication) mobile phone or NFC function machine, electronic certificate is placed in NFC induction area, sent to the background for decoding, and the electronic certificate information is returned to the unified identity card platform, and the unified identity card platform transmits the electronic certificate information to the background for real certificate comparison. Or the photo stored in the electronic certificate chip is compared with the real-time photo taken by the mobile phone camera, and the high security level of real person and real certificate can be realized. eID authentication: based on PKI technology, the network electronic identity information of the request party is authenticated by verifying the consistency of the identity information signed by the eID private key and the eID identity. The three elements of network association check refer to: name, ID number, and real-time photo of the face of the person taken by the mobile phone; the three elements of mobile phone refer to: name, ID number, and mobile phone number; the three elements of bank card refer to: name, ID number, and bank card number; the four elements of bank card refer to: name, ID number, bank card number, and mobile phone number.
[0034] The unified identity authentication platform 2 sends the information required for identity authentication to the corresponding third-party identity authentication platform 1 for authentication, and transmits the obtained customer identity information or authentication result back to the corresponding background. The background compares the customer identity information or authentication result, and sends it to the corresponding electronic channel application end 3 after success. The user continues the business operation process.
[0035] The unified identity authentication platform 2 judges whether the authentication is passed according to the authentication result, obtains the customer certificate information, and transmits it to the corresponding background 4 after encryption; the background 4 obtains the customer certificate information after decryption, confirms whether the customer identity information is complete and accurate, and opens the corresponding business of the customer after confirmation.
[0036] Identity information is private data and cannot be leaked, so it is not suitable for clear text transmission, so the background and the unified identity authentication platform must be encrypted for transmission. An encryption method is agreed between the two platforms. Because customers must leave their identity information and submit certificate information when handling business, the background can compare it by itself.
[0037] The unified identity authentication platform 2 collects the information of the customer in the identity authentication page according to the identity verification requirements and process required by the third-party identity authentication platform 1, and submits it to the third-party authentication platform 1 for authentication.
[0038] Business: electronic channel login, large amount transfer, device binding (new mobile phone), information update, safe entry (credit card application, loan application, financial purchase…), securities purchase, financing purchase, insurance purchase and payment, beneficiary authentication or change.
[0039] Electronic channel includes mobile phone bank client, online bank, WeChat bank, applet, direct selling bank, bank points mall, and community bank.
[0040] The third-party identity authentication platform includes: each provincial big data center, a legal credit investigation agency, China UnionPay, Unicom, Mobile, Telecom, etc.
[0041] The above examples are only for illustrating the present application, and are not a limitation of the present application. Those skilled in the art can make various changes or modifications without departing from the spirit and scope of the present application. Therefore, all equivalent technical solutions should belong to the scope of the present application, which is defined by the claims.
Claims
1. A system for implementing unified identity authentication, characterized by, Comprise: A plurality of third-party identity authentication platforms, a unified identity authentication platform, a plurality of electronic channel application ends and a plurality of backends, wherein, The electronic channel application end sends the business selected by the customer to the corresponding backend, and the backend judges the identity authentication strength and security level according to the business it provides, and sends it to the unified identity authentication platform via the corresponding backend; The unified identity authentication platform selects the method that meets the requirements of identity authentication strength and security level corresponding to this transaction from a plurality of authentication methods of a plurality of third-party identity authentication platforms according to the identity authentication strength and security level, integrates the identity authentication page, and returns the corresponding identity authentication page to the corresponding electronic channel application end via the backend; The customer selects the identity authentication method from the identity authentication page and inputs the related information, the unified identity authentication platform obtains the information required for identity authentication, sends it to the corresponding third-party identity authentication platform for authentication, and transmits the obtained customer identity information or authentication result back to the corresponding backend, which compares the customer identity information or authentication result, and sends it to the corresponding electronic channel application end after success, and the user continues the business operation process; Further comprise: The unified identity authentication platform judges whether the authentication is passed according to the authentication result, obtains the customer's certificate information, and transmits it to the corresponding backend after encryption; The backend obtains the customer's certificate information after decryption, confirms whether the customer's identity information is complete and accurate, and opens the corresponding business of the customer after confirmation; The backend judges the identity authentication strength and security level required according to the industry supervision conditions, the requirements of the competent authority, the relevant regulations, and the customer privacy protection of the selected business; The identity authentication method includes: electronic certificate cloud reading, eID authentication, three elements of network joint check, live detection, face recognition, CFCA authentication, CA authentication, SIMeID shield, three elements of mobile phone number, three elements of bank card, four elements of bank card; The three elements of network joint check refer to: name, ID number, and real-time photos of the person's face taken by mobile phone; Three elements of mobile phone number refer to: name, ID number, and mobile phone number; Three elements of bank card refer to: name, ID number, and bank card number; Four elements of bank card refer to: name, ID number, bank card number, and mobile phone number.
2. The system for implementing uniform identity authentication according to claim 1, wherein, The unified identity authentication platform collects the customer's information in the identity authentication page according to the identity verification requirements and process required by the third-party identity authentication platform, and submits it to the third-party authentication platform for authentication.
3. The system for implementing uniform identity authentication according to claim 1, wherein, The business includes: electronic channel login, large amount transfer, device binding, information update, security entry, securities purchase, financing purchase, insurance purchase and payment, beneficiary authentication or change.
4. The system for implementing unified identity authentication according to claim 1, wherein, The third-party identity authentication platform includes: provincial big data center, legal credit investigation agency, China UnionPay, Unicom, Mobile, Telecom.
5. The system for implementing unified identity authentication according to claim 1, wherein, The customer selects the identity authentication method from the identity authentication page and inputs the related information, obtains the information required for identity authentication, including: The user inputs relevant information according to the third-party identity authentication requirement process: ID card number, name, mobile phone number, bank card number, face recognition, liveness detection, fingerprint recognition, iris recognition and / or SMS verification code, or provides an electronic ID card, a digital certificate and a biological feature shield that can be read by an electronic channel application end.
6. The system for implementing unified identity authentication according to claim 1, wherein, The electronic channel application end is a financial industry electronic channel application end, and the background is a financial industry background; the business is a financial business.
Citation Information
Patent Citations
Identity authentication method and identity authentication system
CN112003818A
Authentication method for authenticating a user of a terminal
WO2018015481A1