Resource transfer method, device and equipment

Through the dual biometric mechanism, the accuracy of identity authentication and user intention are ensured in scenarios where multiple people share an account, which solves the problem of resource loss caused by minors or unintended users using relatives' accounts, and improves the accuracy of identity authentication and user experience.

CN115545713BActive Publication Date: 2025-09-12ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211166973.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-23
Publication Date
2025-09-12
Estimated Expiration
2042-09-23

AI Technical Summary

Technical Problem

When multiple people share an account, when minors or unexpected users use their relatives' accounts to make purchases, the existing identity authentication methods can be easily bypassed, resulting in resource loss and user complaints, and the existing password reminder methods can be easily forgotten.

Method used

A dual biometric mechanism is adopted, which is first verified through the preset first biometric mechanism. If the risk is higher than the threshold, the second biometric mechanism is triggered for identity authentication, including facial recognition and fingerprint recognition, to ensure the accuracy of identity authentication and user willingness.

Benefits of technology

It effectively reduces the risk of unexpected operations, improves the accuracy of identity authentication and user experience, avoids the problem of forgotten security passwords, and enhances the security of resource transfer and user perception.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115545713B_ABST
    Figure CN115545713B_ABST
Patent Text Reader

Abstract

The embodiments of this specification disclose a resource transfer method, apparatus, and device, the method comprising: receiving a resource transfer request sent by a terminal device, the resource transfer request including a user identification, and then obtaining resource transfer environment information corresponding to the resource transfer request; if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identification, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device, the terminal device performs identity authentication through the second biometric recognition mechanism, receives first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism; if the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of computer technology, and in particular to a resource transfer method, device and equipment. Background Art

[0002] In many scenarios, minors use their relatives' accounts to handle certain transactions, such as playing games for long periods of time, giving gifts to live streamers, and making commodity transactions in payment scenarios. For example, in payment scenarios, minors often have their biometric information (such as fingerprints or facial images) entered on their terminal devices for payment. This can lead to minors using their parents' or other relatives' accounts to make purchases, resulting in accidental purchases of large-value items. In this case, if the payment risk control system detects such risks, it often uses facial recognition to verify identity. However, there are also cases where minors use terminal devices to directly scan their facial images in front of their parents or other relatives. In this case, their parents or other relatives may not notice, resulting in resource loss. This situation sometimes causes some users to complain and has a negative impact. Similarly, there are many such situations when couples, minors and parents, and parents and elderly people share accounts. Therefore, it is necessary to provide an identity authentication method that can better solve the above-mentioned problem of multiple people sharing accounts, and can ensure that the actual owner of the account has strong identity authentication operations and willingness, thereby reducing the risk of unexpected operations. Summary of the Invention

[0003] The purpose of the embodiments of this specification is to provide an identity authentication method that can better solve the above-mentioned problem of multiple people sharing an account, and can ensure that the actual owner of the account has strong identity authentication operations and intentions, thereby reducing unexpected operational risks.

[0004] In order to implement the above technical solution, the embodiments of this specification are implemented as follows:

[0005] Embodiments of this specification provide a resource transfer method, comprising: receiving a resource transfer request sent by a terminal device, the resource transfer request including a user identifier; obtaining resource transfer context information corresponding to the resource transfer request; and if, based on the resource transfer context information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, sending a second biometric verification instruction to the terminal device, the second biometric verification instruction instructing the terminal device to perform identity authentication using a second biometric recognition mechanism; receiving first signature information sent by the terminal device, and verifying the first signature information to verify a signature in the first signature information and biometric information corresponding to the second biometric recognition mechanism. The first signature information is obtained by the terminal device initiating identity authentication using the second biometric recognition mechanism based on the second biometric verification instruction. After identity authentication is successful, obtaining biometric information corresponding to the second biometric recognition mechanism and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, performing resource transfer processing based on the resource transfer request.

[0006] Embodiments of this specification provide a resource transfer method, comprising: sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request; generating a second biometric verification instruction if, based on the resource transfer environment information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and if the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold; receiving the second biometric verification instruction; initiating identity authentication using a second biometric recognition mechanism based on the second biometric verification instruction; obtaining biometric information corresponding to the second biometric recognition mechanism after identity authentication is successful; and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; sending the first signature information to the server, the first signature information being used to trigger the server to verify the first signature information, thereby verifying the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism; and performing resource transfer processing based on the resource transfer request if the verification of the first signature information is successful.

[0007] Embodiments of this specification provide a resource transfer system, comprising a terminal device and a server, wherein: the terminal device is configured to send a resource transfer request to the server, the resource transfer request including a user identifier. The server is configured to obtain resource transfer context information corresponding to the resource transfer request. If, based on the resource transfer context information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, the server is configured to send a second biometric recognition verification instruction to the terminal device. The terminal device is configured to initiate identity authentication using a second biometric recognition mechanism based on the second biometric recognition verification instruction, and after successful identity authentication, obtain biometric information corresponding to the second biometric recognition mechanism, perform signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information, and send the first signature information to the server. The server is configured to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information succeeds, the server performs resource transfer processing based on the resource transfer request.

[0008] An embodiment of this specification provides a resource transfer device, comprising: a first request module for receiving a resource transfer request sent by a terminal device, the resource transfer request including a user identifier; a detection module for obtaining resource transfer environment information corresponding to the resource transfer request; and if, based on the resource transfer environment information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device, the second biometric recognition verification instruction being used to instruct the terminal device to perform identity authentication using a second biometric recognition mechanism; a verification module for receiving first signature information sent by the terminal device and verifying the first signature information to verify a signature in the first signature information and biometric information corresponding to the second biometric recognition mechanism. The first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, and after successful identity authentication, obtaining biometric information corresponding to the second biometric recognition mechanism and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism; and a resource transfer module for performing resource transfer processing based on the resource transfer request if the verification of the first signature information succeeds.

[0009] Embodiments of this specification provide a resource transfer device, comprising: a first request module that sends a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request; and if, based on the resource transfer environment information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, generating a second biometric verification instruction; an identity authentication module that receives the second biometric verification instruction, initiates identity authentication using a second biometric recognition mechanism based on the second biometric verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; and a resource transfer triggering module that sends the first signature information to the server, the first signature information being used to trigger the server to verify the first signature information, thereby verifying the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0010] An embodiment of this specification provides a resource transfer device, comprising: a processor; and a memory configured to store computer-executable instructions. When executed, the executable instructions cause the processor to: receive a resource transfer request sent by a terminal device, the resource transfer request including a user identifier; obtain resource transfer context information corresponding to the resource transfer request; and if, based on the resource transfer context information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, send a second biometric verification instruction to the terminal device, the second biometric verification instruction instructing the terminal device to perform identity authentication using a second biometric recognition mechanism; receive first signature information sent by the terminal device, and verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. The first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction. After the identity authentication is successful, the processor obtains the biometric information corresponding to the second biometric recognition mechanism and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, the processor performs resource transfer processing based on the resource transfer request.

[0011] Embodiments of this specification provide a resource transfer device, comprising: a processor; and a memory configured to store computer-executable instructions. When executed, the executable instructions cause the processor to: send a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request triggering the server to obtain resource transfer environment information corresponding to the resource transfer request; if, based on the resource transfer environment information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, generate a second biometric recognition verification instruction; receive the second biometric recognition verification instruction, initiate identity authentication using the second biometric recognition mechanism based on the second biometric recognition verification instruction, obtain biometric information corresponding to the second biometric recognition mechanism after identity authentication is successful, perform signature processing on the biometric information corresponding to the second biometric recognition mechanism, and obtain first signature information; send the first signature information to the server, the first signature information triggering the server to verify the first signature information, thereby verifying the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism; and if the verification of the first signature information is successful, perform resource transfer processing based on the resource transfer request.

[0012] Embodiments of this specification also provide a storage medium for storing computer-executable instructions that, when executed by a processor, implement the following process: receiving a resource transfer request sent by a terminal device, the resource transfer request including a user identifier; obtaining resource transfer context information corresponding to the resource transfer request; and if, based on the resource transfer context information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, sending a second biometric verification instruction to the terminal device, the second biometric verification instruction instructing the terminal device to perform identity authentication using a second biometric recognition mechanism; receiving first signature information sent by the terminal device, and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. The first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction. After the identity authentication is successful, obtaining the biometric information corresponding to the second biometric recognition mechanism and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, performing resource transfer processing based on the resource transfer request.

[0013] Embodiments of this specification also provide a storage medium for storing computer-executable instructions, which, when executed by a processor, implement the following process: sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request triggering the server to obtain resource transfer environment information corresponding to the resource transfer request; if, based on the resource transfer environment information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism exceeds a preset risk threshold, generating a second biometric recognition verification instruction; receiving the second biometric recognition verification instruction; initiating identity authentication using the second biometric recognition mechanism based on the second biometric recognition verification instruction; and after identity authentication is successful, obtaining biometric information corresponding to the second biometric recognition mechanism, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; sending the first signature information to the server, the first signature information triggering the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism; and if the verification of the first signature information is successful, performing resource transfer processing based on the resource transfer request. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0015] Figure 1A This is an embodiment of a resource transfer method of this specification;

[0016] Figure 1B This is a schematic diagram of a resource transfer process in this manual;

[0017] Figure 2 This is a schematic diagram of another resource transfer process in this specification;

[0018] Figure 3 This is another schematic diagram of a resource transfer process in this specification;

[0019] Figure 4 This is another schematic diagram of a resource transfer process in this specification;

[0020] Figure 5A This is another resource transfer method embodiment of this specification;

[0021] Figure 5B This is another schematic diagram of a resource transfer process in this specification;

[0022] Figure 6 This is another schematic diagram of a resource transfer process in this specification;

[0023] Figure 7 This is an embodiment of a resource transfer system of this specification;

[0024] Figure 8 This is another resource transfer system embodiment of the present specification;

[0025] Figure 9 This is an embodiment of a resource transfer device in this specification;

[0026] Figure 10 This is an embodiment of a resource transfer device in this specification;

[0027] Figure 11 This is an embodiment of a resource transfer device in this specification. DETAILED DESCRIPTION

[0028] The embodiments of this specification provide a resource transfer method, apparatus, and device.

[0029] To help those skilled in the art better understand the technical solutions in this specification, the following will provide a clear and complete description of the technical solutions in the embodiments of this specification, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. All other embodiments derived by those skilled in the art based on the embodiments in this specification without creative effort shall fall within the scope of protection of this specification.

[0030] Example 1

[0031] like Figure 1A and Figure 1B As shown, the embodiments of this specification provide a resource transfer method. The execution subject of this method can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers. The server can be a backend server for financial services or online shopping services, or a backend server for an application. The method can specifically include the following steps:

[0032] In step S102, a resource transfer request sent by a terminal device is received, where the resource transfer request includes a user identifier.

[0033] Among them, the terminal device can be a mobile terminal device such as a mobile phone, tablet computer, or a computer device such as a laptop or desktop computer. In this embodiment, the terminal device can be a device equipped with at least two different biometric recognition mechanisms, which can be set according to actual conditions. A resource transfer request can be a request to transfer the ownership rights of a certain number of resources in a resource account to another resource account. The resource transfer request can specifically include an offline payment request, an online payment request, a transfer request, etc. Offline payment can specifically include payment by scanning a graphic code (such as a QR code or barcode, etc.), etc., which can be set according to actual conditions and is not limited in this embodiment of the present specification. The user identifier can be a user name, user nickname, user account number, etc., which can be set according to actual conditions.

[0034] In practice, in many scenarios, minors may use their relatives' accounts to handle certain businesses, such as playing games for a long time in game scenarios, giving gifts to anchors in live video scenarios, and trading goods in payment scenarios. Taking the payment scenario as an example, in the payment scenario, usually, minors have entered biometric information for payment (such as fingerprints or facial images, etc.) on the terminal device. In this way, minors may use the accounts of their parents and other relatives to make purchases, resulting in accidental purchases of large-value consumer goods. At this time, if the payment risk control system discovers such risks, it will often authenticate their identity through facial recognition. However, there will also be cases where minors use terminal devices to directly scan facial images in front of their parents and other relatives. At this time, their parents and other relatives may not notice, resulting in resource loss. The above situation sometimes causes complaints from some users, causing adverse effects. Similarly, there are many such situations when couples, underage children and parents, and parents and elderly people share accounts.

[0035] Usually, obvious text prompts will be added to the facial recognition page, such as using large red fonts to prompt the purchased goods and amount on the facial recognition page. However, the above method may also have the problem that users do not notice the text prompts. For example, when a minor takes the phone to his parents without his parents noticing or even without touching it, he scans his face directly to pass facial recognition. In addition, a secure password can be set. This password is different from the payment password and is used for the above-mentioned operation scenarios that are not performed by the user himself. However, this method requires the user to remember another password, which is easy for the user to forget. For this reason, it is necessary to provide an identity authentication method that can better solve the above-mentioned problem of multiple people sharing an account, and can ensure that the actual owner of the account has strong identity authentication operations and intentions, thereby reducing the risk of unexpected operations. The embodiments of this specification provide a feasible technical solution, and please refer to the following content for details.

[0036] For the convenience of subsequent description, the multiple users corresponding to the shared account can be divided into two parts, namely, a supervisory party and a supervised party. The supervisory party can be a user who supervises and manages the use of the shared account, such as a parent in a relationship between a minor and a parent, or a parent in a relationship between a parent and an elderly person, etc. The supervised party can be a user who can be supervised and managed by the supervisory party in the process of using the shared account, such as a minor, an elderly person, etc., and the specific settings can also be made according to actual conditions. When a user (who can be the supervised party) needs to perform resource transfer processing (such as payment or transfer, etc.), the corresponding application installed in the terminal device can be started. The application can be provided with an entry for resource transfer processing (such as a hyperlink or button, etc.), and the resource transfer processing can be performed through the entry. At this time, the terminal device can obtain the user identification and can generate a resource transfer request based on the user identification. The terminal device can send the resource transfer request to the server.

[0037] In step S104, the resource transfer environment information corresponding to the above-mentioned resource transfer request is obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric mechanism is higher than the preset risk threshold, a second biometric verification instruction is sent to the terminal device, and the second biometric verification instruction is used to instruct the terminal device to perform identity authentication through the second biometric mechanism.

[0038] Among them, the resource transfer environment information can be information about the environment during the resource transfer process. The resource transfer environment information can include information about the current user (specifically, the current user's facial information, fingerprint information, etc.), information about the surrounding environment of the current user (specifically, noise conditions, the number of surrounding users, etc.), etc., which can be set according to actual conditions, and the embodiments of this specification do not limit this. The first biometric recognition mechanism can be any mechanism for biometric recognition. Specifically, for example, the first biometric recognition mechanism can be a facial recognition mechanism, a fingerprint recognition mechanism, a palm print recognition mechanism, or an iris recognition mechanism, etc., which can be set according to actual conditions. The second biometric recognition mechanism can be a biometric recognition mechanism different from the first biometric recognition mechanism. For example, the first biometric recognition mechanism can be a facial recognition mechanism, and the second biometric recognition mechanism can be a fingerprint recognition mechanism. For another example, the first biometric recognition mechanism can be a fingerprint recognition mechanism, and the second biometric recognition mechanism can be a facial recognition mechanism, etc.

[0039] In implementation, considering that the terminal device (or account, etc.) is a device shared by multiple people, it is necessary to set up another biometric mechanism for the terminal device that is different from the biometric mechanism used for resource transfer. For example, the biometric mechanism used for resource transfer can be a facial recognition mechanism, and the other biometric mechanism can be a fingerprint recognition mechanism, wherein the fingerprint recognition mechanism can be set to register the fingerprint of the user's less frequently used finger (such as the fingerprint of the ring finger, etc.), etc. Based on this, the above-mentioned user as the supervisory party can set up a fingerprint recognition mechanism in the terminal device, and can use the fingerprint of the user's less frequently used finger to register the fingerprint recognition mechanism. In order to ensure the security of the registration process, in the process of activating the fingerprint recognition mechanism, a variety of different identity authentication methods (such as facial recognition identity authentication + mobile phone text message identity authentication, etc.) can be used to verify that the current user is the supervisory user, and finally another biometric mechanism (i.e., the second biometric mechanism) can be set in the terminal device.

[0040] When a terminal device sends a resource transfer request to a server, it may also activate a camera component to capture a facial image of the current user, or activate a fingerprint capture component to capture the current user's fingerprint information, and may compare the captured biometric information with the biometric information registered in the terminal device. The terminal device may then send the above information as resource transfer context information to the server. The server may obtain the resource transfer context information corresponding to the resource transfer request, obtain information about the initiating user of the resource transfer request from the resource transfer context information, obtain the target user corresponding to the user identifier, and compare the initiating user with the target user to determine whether the initiating user is the same as the target user. Furthermore, the server may analyze the process of performing identity authentication using a preset first biometric recognition mechanism to determine whether the risk associated with performing identity authentication using the preset first biometric recognition mechanism exceeds a preset risk threshold. If, based on the resource transfer context information, it is determined that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk associated with performing identity authentication using the preset first biometric recognition mechanism exceeds the preset risk threshold, then this indicates that the current user is not the user acting as the supervisory party and requires further identity authentication using a second biometric recognition mechanism. In this case, the server may send a second biometric verification instruction to the terminal device.

[0041] The terminal device can execute the second biometric recognition mechanism. At this time, the terminal device can start the corresponding component, and can use the component to collect biometric information corresponding to the second biometric recognition mechanism, and can match the collected biometric information with the biometric information pre-registered for the second biometric recognition mechanism. If the two match, it is determined that the identity authentication through the second biometric recognition mechanism is successful. If the two do not match, it is determined that the identity authentication through the second biometric recognition mechanism is unsuccessful. If the identity authentication is successful, the biometric information corresponding to the second biometric recognition mechanism can be obtained, and the biometric information corresponding to the second biometric recognition mechanism can be signed to obtain the first signature information. Specifically, a signature key can be pre-set. The signature key can include one key, a key pair, or two keys, such as a public key and a private key. The signature key can be used to sign the biometric information corresponding to the second biometric recognition mechanism to obtain the first signature information. The terminal device can send the first signature information to the server.

[0042] In step S106, the first signature information sent by the terminal device is received, and the first signature information is verified to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. The first signature information is obtained by the terminal device starting the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, and after the identity authentication is passed, obtaining the biometric information corresponding to the second biometric recognition mechanism, and signing the biometric information corresponding to the second biometric recognition mechanism.

[0043] In implementation, after receiving the first signature information, the server can verify the signature in the first signature information. If the verification is successful, it indicates that the first signature information is accurate or that the first signature information has not been tampered with. At this time, identity authentication can be performed based on the biometric information corresponding to the second biometric mechanism. Specifically, the biometric information corresponding to the second biometric mechanism can be matched with the biometric information pre-registered for the second biometric mechanism. If the two match, it is determined that the identity authentication through the second biometric mechanism is successful. If the two do not match, it is determined that the identity authentication through the second biometric mechanism is unsuccessful.

[0044] In step S108, if the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0045] In implementation, if the verification of the first signature information is passed, the object that needs to be transferred resources (such as the goods to be purchased, etc.) and the resource information required by the object (such as the amount, etc.) can be obtained from the above-mentioned resource transfer request. Then, the total resource information required can be calculated, and then the resource transfer process can be performed. After the resource transfer is successful, a notification message of the successful resource transfer can be sent to the terminal device.

[0046] An embodiment of the present specification provides a resource transfer method, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier. Then, resource transfer environment information corresponding to the resource transfer request can be obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device initiates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0047] Example 2

[0048] like Figure 2 As shown, the embodiments of this specification provide a resource transfer method. The execution subject of this method can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers. The server can be a backend server for financial services or online shopping services, or a backend server for an application. The method can specifically include the following steps:

[0049] In step S202, a request for activating a second biometric identification mechanism sent by a terminal device is received.

[0050] During implementation, considering that the terminal device (or account, etc.) is a device shared by multiple people, it is necessary to set up a second biometric mechanism for the terminal device that is different from the first biometric mechanism used for resource transfer, so as to facilitate the user as the supervisory party to supervise and manage the resource transfer requests made by the supervised party. Based on this, the user as the supervisory party can use the terminal device to initiate an activation request for the second biometric mechanism. At this time, the server can receive the activation request for the second biometric mechanism sent by the terminal device.

[0051] In step S204, activation verification information corresponding to the activation request is generated, and the activation verification information is signed to obtain second signature information, and the second signature information is sent to the terminal device.

[0052] The activation verification information may be verification information used to activate the second biometric recognition mechanism. The activation verification information may include various types, such as a verification password. In practical applications, the activation verification information may include a challenge code and / or a session identifier. The challenge code, also known as a challenge password, may refer to a set of encrypted passwords generated using the Handshake Authentication Protocol (CHAP) to ensure that the user's actual password is not disclosed during transmission. CHAP is an encrypted authentication method that avoids transmitting the user's actual password when establishing a connection. CHAP no longer sends the plaintext password directly over the link, but instead uses a challenge code to encrypt the password using a hash algorithm. Because the plaintext password is stored on the server, the server can repeat the operation performed by the client and compare the result with the password returned by the user. CHAP generates a random challenge string for each authentication to prevent replay attacks. Throughout the connection process, CHAP will periodically send the challenge code to the client to prevent impersonation attacks by third parties. The session identifier may be an identifier for the current session established between the terminal device and the server. The session identifier may be a code or text, and may be set according to actual circumstances.

[0053] In step S206, an identity authentication request corresponding to the activation request sent by the terminal device is received. The identity authentication request is information sent by the terminal device after verifying the second signature information. The identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism.

[0054] In implementation, after receiving the second signature information, the terminal device may verify the second signature information. Specifically, the terminal device may use the signature verification key to verify the second signature information. For example, the terminal device may use the signature verification key to decrypt the second signature information. If the decryption is successful, the signature verification is successful; if the decryption fails, the signature verification fails. If the signature verification is successful or passes, the terminal device may send an identity authentication request corresponding to the activation request to the server.

[0055] In step S208, if the identity authentication result corresponding to the identity authentication request is passed, a setting instruction for the reference biometric information corresponding to the second biometric recognition mechanism is sent to the terminal device.

[0056] In step S210, the third signature information sent by the terminal device is received. The third signature information is obtained after the terminal device signs the activation verification information and the baseline biometric information. The third signature information is the information sent after the terminal device verifies the baseline biometric information in the trusted execution environment and generates the third signature information in the trusted execution environment.

[0057] In implementation, after receiving the setting instruction of the baseline biometric information corresponding to the second biometric recognition mechanism, the terminal device can obtain the baseline biometric information and activation verification information corresponding to the second biometric recognition mechanism, and can pass the above-mentioned baseline biometric information and activation verification information to a trusted execution environment through a trusted application. The trusted execution environment can be a TEE (Trusted Execution Environment). The trusted execution environment can be implemented by a program written in a predetermined programming language (that is, it can be implemented in the form of software), or it can be implemented by a hardware device and a pre-written program (that is, it can be implemented in the form of hardware + software), etc. The trusted execution environment can be a secure operating environment for data processing. In the trusted execution environment, the baseline biometric information can be verified. If the verification is passed, the activation verification information and the baseline biometric information are signed in the trusted execution environment to generate a third signature information, thereby ensuring that the information therein cannot be tampered with or exported. After the signature processing, the terminal device is guaranteed to be a safe and trustworthy device. Then, the third signature information can be sent to the server, and the server can receive the third signature information sent by the terminal device.

[0058] In step S212, the third signature information is verified. If the verification is successful, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification is successful, the second biometric recognition mechanism is set based on the baseline biometric information.

[0059] The second biometric recognition mechanism based on the above settings may perform the following resource transfer process, which may specifically include the following steps S214 to S220.

[0060] In step S214, a resource transfer request sent by the terminal device is received, where the resource transfer request includes a user identifier.

[0061] In step S216, the resource transfer environment information corresponding to the above-mentioned resource transfer request is obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric mechanism is higher than the preset risk threshold, a second biometric verification instruction is sent to the terminal device, and the second biometric verification instruction is used to instruct the terminal device to perform identity authentication through the second biometric mechanism.

[0062] In step S218, the first signature information sent by the terminal device is received, and the first signature information is verified to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. The first signature information is obtained by the terminal device starting the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, and after the identity authentication is passed, obtaining the biometric information corresponding to the second biometric recognition mechanism, and signing the biometric information corresponding to the second biometric recognition mechanism.

[0063] In actual applications, the biometric information corresponding to the second biometric recognition mechanism may include one or more of a biometric information index (i.e., the index of the biometric information) and a modification time of the biometric information. The specific processing of verifying the biometric information corresponding to the first signature information may include: if the biometric information index corresponding to the first signature information is the same as the pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information, then it is determined that the verification of the first signature information is passed.

[0064] The index of the biometric information can refer to the index generated after the biometric information is set to the terminal device, which can ensure that the index of the biometric information on one terminal device is different from that of others. During the comparison, the index of the biometric information will be compared. If the index is consistent, the last modification time of this index will be compared with the registration time (that is, whether the modification time of the biometric information corresponding to the first signature information is consistent with the effective time of the benchmark biometric information). If they are inconsistent, the verification will fail. This prevents the user from adding new biometric information or modifying the biometric information after deleting the biometric information, which may result in the biometric information being set by the non-supervising user.

[0065] In step S220, if the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0066] The specific processing of the above steps S214 to S220 can be found in the relevant content of the above embodiment and will not be repeated here.

[0067] An embodiment of the present specification provides a resource transfer method, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier. Then, resource transfer environment information corresponding to the resource transfer request can be obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device initiates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0068] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0069] Example 3

[0070] like Figure 3 As shown, an embodiment of this specification provides a resource transfer method, the execution subject of this method can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers, etc. The server can be a backend server for financial services or online shopping services, etc., or a backend server for an application, etc. In order to distinguish it from the subsequent authentication server, the execution subject server in this embodiment can be a business server, which can serve as a backend server for one or more services. The method can specifically include the following steps:

[0071] In step S302, a request for activating a second biometric identification mechanism sent by a terminal device is received.

[0072] In step S304, activation verification information corresponding to the activation request is generated and sent to the authentication server. The activation verification information is used to trigger the authentication server to sign the activation verification information to obtain second signature information.

[0073] Wherein, opening verification information may include challenge code and / or session identification, and the challenge code may be randomly generated UUID (Universally Unique Identifier, universal unique identifier), and the purpose of anti-replay may be achieved by opening verification information. The second signature information is obtained after the second signature key for opening request setting by certification server carries out signature processing to opening verification information, and in practical applications, the second signature key may be the key (specifically private key or public key etc.) pre-set in certification server for signing. Certification server may be the server for carrying out Internet finance identity authentication, and in practical applications, certification server may be IFAA (Internet Finance Authentication Alliance, Internet Finance Identity Authentication Alliance) server, IFAA servers are the Internet Finance Identity Authentication Alliance formed in order to solve Andorid system fragmentation, ecological chain collaborative demand, mobile phone security problem, and formulate IFAA agreements (i.e., biometric authentication unified protocol), solve industrial chain collaborative problem, realize providing the purpose of more convenient and safe biometric services for the public.

[0074] In implementation, Figure 4 Shown, with the first biometric identification mechanism as the biometric identification mechanism based on facial recognition, the second biometric identification mechanism is the biometric identification mechanism based on fingerprint recognition as an example, and resource transfer is taken as payment as an example, and business server can generate the corresponding opening verification information of above-mentioned opening request, and will send the opening verification information to certification server.With certification server as IFAA server as an example, IFAA signature key (specifically such as IFAA private key etc.) can be pre-set in certification server, and IFAA signature key can be used to open verification information and carry out signature process, obtain the second signature information, like this, by IFAA signature key, opening verification information is signed, it is possible to ensure the safety and reliability of service end.

[0075] In step S306, the second signature information sent by the authentication server is received, and the second signature information is sent to the terminal device.

[0076] In step S308, an identity authentication request corresponding to the activation request sent by the terminal device is received. The identity authentication request is information sent by the terminal device after verifying the second signature information. The identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism.

[0077] In implementation, based on the above content, for verifying the second signature information signed by the IFAA signature key, in the IFAA agreement, it will be negotiated with the terminal device manufacturer to preset an IFAA verification key (specifically such as IFAA public key, etc.) when the terminal device leaves the factory. The terminal device verifies the second signature information through the IFAA verification key, and after the verification is passed, sends the identity authentication request corresponding to the above-mentioned activation request to the business server.

[0078] It should be noted that the above-mentioned identity authentication request can be an authentication request combining multiple different identity authentication methods, such as a combination of a password authentication method, a facial recognition authentication method, and a mobile phone text message authentication method. Only after all three of the above-mentioned identity authentication methods are passed can the identity authentication result corresponding to the above-mentioned identity authentication request be determined to be passed. At this point, the subsequent activation operation can be performed. In addition, in actual applications, the combination of the above-mentioned identity authentication methods is not necessarily a combination of three identity authentication methods, but can also be other combinations, such as a combination of two identity authentication methods or a combination of three or more identity authentication methods. The specific setting can be based on actual conditions and is not limited in the embodiments of this specification.

[0079] In step S310, if the identity authentication result corresponding to the identity authentication request is passed, a setting instruction for the reference biometric information corresponding to the second biometric recognition mechanism is sent to the terminal device.

[0080] In step S312, the third signature information sent by the terminal device is received. The third signature information is obtained after the terminal device signs the activation verification information and the baseline biometric information. The third signature information is the information sent after the terminal device verifies the baseline biometric information in the trusted execution environment and generates the third signature information in the trusted execution environment.

[0081] Among them, the third signature information is obtained by signing the activation verification information and the baseline biometric information through the first signature key of the terminal device. In actual application, the first signature key can be the device private key set in the IFAA protocol, etc.

[0082] In step S314, the third signature information is sent to the authentication server. The third signature information is used to trigger the authentication server to perform signature verification on the third signature information to obtain a signature verification result.

[0083] In step S316, the signature verification result sent by the authentication server is received. If the signature verification passes, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification passes, the second biometric recognition mechanism is set based on the baseline biometric information.

[0084] The second biometric recognition mechanism based on the above setting can perform the following resource transfer processing, such as Figure 4 As shown, taking the first biometric recognition mechanism as a biometric recognition mechanism based on facial recognition, the second biometric recognition mechanism as a biometric recognition mechanism based on fingerprint recognition as an example, and taking payment as an example of resource transfer, the specific processing may include the following steps S318 to S326.

[0085] In step S318, a resource transfer request sent by the terminal device is received, where the resource transfer request includes a user identifier.

[0086] In step S320, the resource transfer environment information corresponding to the above-mentioned resource transfer request is obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric mechanism is higher than the preset risk threshold, a second biometric verification instruction is sent to the terminal device, and the second biometric verification instruction is used to instruct the terminal device to perform identity authentication through the second biometric mechanism.

[0087] In step S322, the first signature information sent by the terminal device is received and sent to the authentication server. The first signature information is used to trigger the authentication server to verify the first signature information. The first signature information is obtained by the terminal device starting the second biometric mechanism for identity authentication based on the second biometric verification instruction, and after the identity authentication is passed, obtaining the biometric information corresponding to the second biometric mechanism, and signing the biometric information corresponding to the second biometric mechanism.

[0088] Among them, the first signature information is obtained by signing the biometric information corresponding to the second biometric recognition mechanism using the first signature key preset by the terminal device. In actual application, the first signature key can be the device private key set in the IFAA protocol, etc.

[0089] In step S324, a notification message sent by the authentication server indicating that the first signature information has been verified successfully is received, and the biometric information corresponding to the first signature information is verified. If the verification succeeds, it is determined that the verification of the first signature information has succeeded.

[0090] In step S326, resource transfer processing is performed based on the resource transfer request.

[0091] The specific processing of the above steps S318 to S326 can be found in the relevant content of the above embodiment and will not be repeated here.

[0092] An embodiment of the present specification provides a resource transfer method, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier. Then, resource transfer environment information corresponding to the resource transfer request can be obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device initiates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0093] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0094] Example 4

[0095] like Figure 5A and Figure 5B As shown, the embodiments of this specification provide a resource transfer method, the execution subject of which can be a terminal device, wherein the terminal device can be a mobile terminal device such as a mobile phone, a tablet computer, a computer device such as a laptop computer or a desktop computer, or an IoT device (specifically, a smart watch, an in-vehicle device, etc.). The method can specifically include the following steps:

[0096] In step S502, a resource transfer request is sent to the server, which includes a user identifier. The resource transfer request is used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric mechanism is higher than the preset risk threshold, a second biometric verification instruction is generated.

[0097] In step S504, a second biometric verification instruction is received, and a second biometric mechanism is started to perform identity authentication based on the second biometric verification instruction. After the identity authentication is passed, the biometric information corresponding to the second biometric mechanism is obtained, and the biometric information corresponding to the second biometric mechanism is signed to obtain the first signature information.

[0098] In step S506, the first signature information is sent to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0099] The specific processing of the above steps S502 to S506 can be found in the relevant content of the above embodiment and will not be repeated here.

[0100] An embodiment of the present specification provides a resource transfer method, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier. Then, resource transfer environment information corresponding to the resource transfer request can be obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device initiates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0101] Example 5

[0102] like Figure 6 As shown, the embodiments of this specification provide a resource transfer method, the execution subject of which can be a terminal device, wherein the terminal device can be a mobile terminal device such as a mobile phone, a tablet computer, a computer device such as a laptop computer or a desktop computer, or an IoT device (specifically, a smart watch, an in-vehicle device, etc.). The method can specifically include the following steps:

[0103] In step S602, an activation request for the second biometric recognition mechanism is sent to the server. The activation request is used to trigger the server to generate activation verification information corresponding to the activation request, and sign the activation verification information to obtain second signature information.

[0104] In step S604, the second signature information sent by the server is received and the second signature information is verified. If the verification is successful, an identity authentication request corresponding to the activation request is sent to the server, and the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism.

[0105] In step S606, a setting instruction of the reference biometric information corresponding to the second biometric recognition mechanism sent by the server is received. The setting instruction is sent by the server when the server determines that the identity authentication result corresponding to the identity authentication request is passed.

[0106] In step S608, the baseline biometric information is obtained and verified in the trusted execution environment. If the verification is successful, the activation verification information and the baseline biometric information are signed in the trusted execution environment to obtain third signature information, and the third signature information is sent to the server. The third signature information is used to trigger the server to verify the third signature information. If the verification is successful, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification is successful, the second biometric recognition mechanism is set based on the baseline biometric information.

[0107] During implementation, the terminal device can collect the user's biometric information (such as fingerprints or facial images, etc.), and use it as baseline biometric information. The baseline biometric information can be transmitted to the trusted execution environment (TEE) of the terminal device through a trusted application. The baseline biometric information can be verified in the trusted execution environment. If the baseline biometric information is determined to be correct, the activation verification information can be obtained and transmitted to the trusted execution environment of the terminal device. In the trusted execution environment, the activation verification information and the baseline biometric information can be signed to obtain third signature information.

[0108] A Trusted Execution Environment (TEE) can be a secure data processing environment isolated from other environments. That is, the processing performed within the TEE, as well as the data generated during data processing, cannot be accessed by other execution environments or applications outside the TEE. A TEE can be implemented by creating a small operating system that can run independently within a trusted zone (such as TrustZone). The TEE can directly provide services through system calls (e.g., directly processed by the TrustZone kernel). Terminal devices can include a Rich Execution Environment (REE) and a TEE. The REE can run the terminal device's installed operating system, such as Android, iOS, Windows, and Linux. REEs are characterized by powerful functionality, openness, and scalability, providing upper-layer applications with all the terminal device's functions, such as camera and touchscreen functionality. However, REEs present numerous security risks. For example, while the operating system can access all the data of an application, it is difficult to verify whether the operating system or application has been tampered with. If tampered with, user information would be significantly compromised. This requires a TEE within the terminal device to address this issue. The TEE has its own execution space, meaning it also hosts an operating system. TEE offers a higher level of security than the REE. The software and hardware resources in the terminal device accessible by the TEE are separate from the REE. However, the TEE can directly access REE information, while the REE cannot. The TEE can perform authentication and other processing through the provided interfaces, ensuring that user information (such as payment details and private information) is not tampered with, passwords are not hijacked, and fingerprints or facial information are not misused.

[0109] A trusted application can be a pre-designated trusted application that can be used to execute data and transfer it to a trusted execution environment. A trusted application can be an application that needs to be installed in a terminal device, or a code program pre-implanted in a hardware device of the terminal device, or a program that runs in the background of the terminal device's operating system in the form of a plug-in, etc. The specific settings can be based on actual conditions. The trusted application can be pre-set with a security interface, and correspondingly, the TEE of the terminal device can also be set with a corresponding security interface. Through the security interface between the trusted application and the TEE, a secure data transmission channel can be established between the trusted application and the TEE. The trusted application can pass the data to be transferred to the TEE of the terminal device through the above-mentioned security interface and data transmission channel. The security of the data during transmission can be guaranteed by setting the first trusted application, security interface, and data transmission channel.

[0110] It should be noted that in order to reduce the size of data transmission, other relevant information of the baseline biometric information can be obtained to replace the biometric information such as fingerprints or facial images in the baseline biometric information with a larger data volume. For example, the biometric information index of the baseline biometric information (i.e., the biometric information index) can be obtained, and the activation verification information and the biometric information index of the baseline biometric information can be signed in a trusted execution environment to obtain a third signature information.

[0111] The second biometric recognition mechanism based on the above registration may perform the following resource transfer process, which may specifically include the following steps S610 to S614.

[0112] In step S610, a resource transfer request is sent to the server, which includes a user identifier. The resource transfer request is used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric mechanism is higher than the preset risk threshold, a second biometric verification instruction is generated.

[0113] In step S612, a second biometric verification instruction is received, and a second biometric mechanism is started to perform identity authentication based on the second biometric verification instruction. After the identity authentication is passed, the biometric information corresponding to the second biometric mechanism is obtained, and the biometric information corresponding to the second biometric mechanism is signed to obtain the first signature information.

[0114] In step S614, the first signature information is sent to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0115] The specific processing of the above steps S610 to S614 can be found in the relevant content of the above embodiment and will not be repeated here.

[0116] An embodiment of the present specification provides a resource transfer method, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier. Then, resource transfer environment information corresponding to the resource transfer request can be obtained. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device initiates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0117] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0118] Example 6

[0119] like Figure 7 As shown, an embodiment of this specification provides a resource transfer system, which includes a terminal device 710 and a server 720, wherein the terminal device can be a mobile terminal device such as a mobile phone, a tablet computer, or a computer device such as a laptop or a desktop computer, or an IoT device (specifically, a smart watch, a car device, etc.). The server can be an independent server or a server cluster composed of multiple servers. The server can be a backend server for a financial service or an online shopping service, or a backend server for an application. Among them:

[0120] The terminal device 710 is configured to send a resource transfer request to the server 720, where the resource transfer request includes a user identifier;

[0121] The server 720 is configured to obtain resource transfer environment information corresponding to the resource transfer request, and if it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric recognition mechanism is higher than a preset risk threshold, send a second biometric recognition verification instruction to the terminal device 710;

[0122] The terminal device 710 is configured to initiate a second biometric recognition mechanism to perform identity authentication based on the second biometric recognition verification instruction, obtain biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, perform signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information, and send the first signature information to the server 720;

[0123] The server 720 is configured to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, the resource transfer process is performed based on the resource transfer request.

[0124] In an embodiment of the present specification, the biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. The server 720 is configured to determine that the verification of the first signature information is successful if the biometric information index corresponding to the first signature information is the same as the pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information.

[0125] In the embodiment of this specification, the first biometric recognition mechanism is a biometric recognition mechanism based on facial recognition, and the second biometric recognition mechanism is a biometric recognition mechanism based on fingerprint recognition.

[0126] The above processes can be found in Figure 4 The specific processing process or the aforementioned related content will not be repeated here.

[0127] In the embodiment of this specification, the terminal device 710 is configured to send an activation request of the second biometric recognition mechanism to the server 720;

[0128] The server 720 is configured to generate activation verification information corresponding to the activation request, and sign the activation verification information to obtain second signature information;

[0129] The terminal device 710 is configured to receive the second signature information sent by the server 720, perform signature verification on the second signature information, and if the signature verification passes, send an identity authentication request corresponding to the activation request to the server 720, where the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0130] The server 720 is configured to send a setting instruction of the reference biometric information corresponding to the second biometric recognition mechanism to the terminal device 710 if the identity authentication result corresponding to the identity authentication request is passed;

[0131] The terminal device 710 is configured to obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification is successful, the terminal device 710 signs the activation verification information and the baseline biometric information in the trusted execution environment to obtain third signature information, and sends the third signature information to the server 720.

[0132] Server 720 is configured to verify the third signature information. If the verification is successful, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification is successful, the second biometric recognition mechanism is set based on the baseline biometric information.

[0133] In the embodiment of this specification, the activation verification information includes a challenge code and / or a session identifier.

[0134] In the embodiments of this specification, Figure 8 As shown, the server 720 may include a business server 721 and an authentication server 722, wherein the authentication server 722 may be an IFAA server, wherein the registration process of the second biometric recognition mechanism may be as follows:

[0135] The terminal device 710 is configured to send an activation request for the second biometric recognition mechanism to the service server 721;

[0136] The service server 721 is configured to generate activation verification information corresponding to the activation request and send the activation verification information to the authentication server 722;

[0137] The authentication server 722 is configured to perform signature processing on the activation verification information to obtain second signature information, and send the second signature information to the service server 721;

[0138] The service server 721 is configured to send the second signature information to the terminal device 710;

[0139] The terminal device 710 is configured to verify the second signature information. If the verification is successful, the terminal device 710 sends an identity authentication request corresponding to the activation request to the service server 721. The identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism.

[0140] The service server 721 is configured to perform identity authentication processing corresponding to the identity authentication request, and if it is determined that the identity authentication result corresponding to the identity authentication request is passed, send a setting instruction for the baseline biometric information corresponding to the second biometric recognition mechanism to the terminal device 710;

[0141] The terminal device 710 is configured to obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification is successful, the terminal device 710 signs the activation verification information and the baseline biometric information in the trusted execution environment to obtain third signature information, and sends the third signature information to the service server 721.

[0142] The business server 721 is configured to send the third signature information to the authentication server 722;

[0143] The authentication server 722 is configured to perform signature verification on the third signature information, obtain a signature verification result, and send the signature verification result to the business server 721;

[0144] The business server 721 is configured to verify the activation verification information in the third signature information based on the locally stored activation verification information if the signature verification is successful, and set the second biometric recognition mechanism based on the baseline biometric information if the verification is successful.

[0145] In addition, for the above resource transfer process, the following parts can be included:

[0146] In the embodiment of this specification, the business server 721 is configured to send the first signature information to the authentication server 722;

[0147] The authentication server 722 is configured to perform signature verification on the first signature information, and if the signature verification passes, send a notification message to the business server 721 indicating that the signature verification of the first signature information has passed;

[0148] The business server 721 is configured to verify the biometric information corresponding to the first signature information, and if the verification is successful, it is determined that the verification of the first signature information is successful.

[0149] In the embodiment of this specification, the first signature information is obtained by signing the biometric information corresponding to the second biometric recognition mechanism with the first signature key preset by the terminal device 710, the second signature information is obtained by signing the activation verification information with the second signature key set by the authentication server 722 for the activation request, and the third signature information is obtained by signing the activation verification information and the baseline biometric information with the first signature key of the terminal device 710.

[0150] The above processes can be found in Figure 4 The specific processing process or the aforementioned related content will not be repeated here.

[0151] An embodiment of the present specification provides a resource transfer system, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and then obtains resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device activates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, and after the identity authentication is successful, obtains biometric information corresponding to the second biometric recognition mechanism and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0152] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0153] Example 7

[0154] The above is a resource transfer system provided by the embodiment of this specification. Based on the same idea, the embodiment of this specification also provides a resource transfer device, such as Figure 9 shown.

[0155] The resource transfer device includes: a first request module 901, a detection module 902, a verification module 903 and a resource transfer module 904, wherein:

[0156] A first request module 901 receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier;

[0157] The detection module 902 obtains resource transfer environment information corresponding to the resource transfer request, and if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric recognition mechanism is higher than a preset risk threshold, sends a second biometric recognition verification instruction to the terminal device, where the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication using the second biometric recognition mechanism;

[0158] a verification module 903 receiving first signature information sent by the terminal device and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism;

[0159] The resource transfer module 904 performs resource transfer processing based on the resource transfer request if the verification of the first signature information is passed.

[0160] In the embodiment of this specification, the verification module 903 includes:

[0161] a sending unit, configured to send the first signature information to an authentication server, where the first signature information is used to trigger the authentication server to perform signature verification on the first signature information;

[0162] The verification unit receives a notification message sent by the authentication server indicating that the verification of the first signature information is successful, verifies the biometric information corresponding to the first signature information, and determines that the verification of the first signature information is successful if the verification is successful.

[0163] In an embodiment of the present specification, the biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. The verification module 903 determines that the verification of the first signature information is successful if the biometric information index corresponding to the first signature information is the same as a pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information.

[0164] In the embodiment of this specification, the first biometric recognition mechanism is a biometric recognition mechanism based on facial recognition, and the second biometric recognition mechanism is a biometric recognition mechanism based on fingerprint recognition.

[0165] In the embodiment of this specification, the device further includes:

[0166] A second request module receives an activation request for the second biometric recognition mechanism sent by the terminal device;

[0167] a signature module, generating activation verification information corresponding to the activation request, signing the activation verification information to obtain second signature information, and sending the second signature information to the terminal device;

[0168] an authentication request module, receiving an identity authentication request corresponding to the activation request sent by the terminal device, the identity authentication request being information sent by the terminal device after verifying the second signature information, the identity authentication request including at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0169] a setting instruction module, configured to send a setting instruction for the baseline biometric information corresponding to the second biometric recognition mechanism to the terminal device if the identity authentication result corresponding to the identity authentication request is passed;

[0170] a receiving module, receiving third signature information sent by the terminal device, the third signature information being obtained by the terminal device after signing the activation verification information and the reference biometric information, and the third signature information being sent after the terminal device verifies the reference biometric information in a trusted execution environment and generates the third signature information in the trusted execution environment;

[0171] The setting module verifies the third signature information. If the verification passes, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification passes, the second biometric recognition mechanism is set based on the baseline biometric information.

[0172] In the embodiment of this specification, the activation verification information includes a challenge code and / or a session identifier.

[0173] In the embodiment of this specification, the signature module includes:

[0174] a sending unit, configured to send the activation verification information to the authentication server, wherein the activation verification information is used to trigger the authentication server to perform signature processing on the activation verification information to obtain second signature information;

[0175] The signature receiving unit receives the second signature information sent by the authentication server.

[0176] In the embodiment of this specification, the first signature information is obtained by signing the biometric information corresponding to the second biometric recognition mechanism with the first signature key preset by the terminal device, the second signature information is obtained by signing the activation verification information with the second signature key set by the authentication server for the activation request, and the third signature information is obtained by signing the activation verification information and the baseline biometric information with the first signature key of the terminal device.

[0177] In the embodiment of this specification, the setting module includes:

[0178] a sending unit, configured to send the third signature information to the authentication server, where the third signature information is used to trigger the authentication server to perform signature verification on the third signature information to obtain a signature verification result;

[0179] The signature verification result receiving unit receives the signature verification result sent by the authentication server.

[0180] An embodiment of the present specification provides a resource transfer apparatus, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and then obtains resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device activates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0181] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0182] Example 8

[0183] Based on the same idea, the embodiment of this specification also provides a resource transfer device, such as Figure 10 shown.

[0184] The resource transfer device includes: a first request module 1001, an identity authentication module 1002 and a resource transfer triggering module 1003, wherein:

[0185] A first request module 1001 sends a resource transfer request to a server, wherein the resource transfer request includes a user identifier and is used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is generated;

[0186] The identity authentication module 1002 receives the second biometric authentication instruction, initiates the second biometric authentication mechanism to perform identity authentication based on the second biometric authentication instruction, obtains biometric information corresponding to the second biometric authentication mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric authentication mechanism to obtain first signature information;

[0187] The resource transfer trigger module 1003 sends the first signature information to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request.

[0188] In the embodiment of this specification, the device further includes:

[0189] a second request module, which sends an activation request for the second biometric recognition mechanism to a server, wherein the activation request is used to trigger the server to generate activation verification information corresponding to the activation request, and to sign the activation verification information to obtain second signature information;

[0190] a signature verification module, receiving the second signature information sent by the server, performing signature verification on the second signature information, and if the signature verification passes, sending an identity authentication request corresponding to the activation request to the server, wherein the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0191] an instruction receiving module for receiving, from the server, an instruction for setting the reference biometric information corresponding to the second biometric recognition mechanism, wherein the instruction is sent by the server when the server determines that the identity authentication result corresponding to the identity authentication request is passed;

[0192] A trigger module is set to obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification is successful, the activation verification information and the baseline biometric information are signed in the trusted execution environment to obtain third signature information, and the third signature information is sent to the server. The third signature information is used to trigger the server to verify the third signature information. If the verification is successful, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification is successful, the second biometric recognition mechanism is set based on the baseline biometric information.

[0193] An embodiment of the present specification provides a resource transfer apparatus, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and then obtains resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device activates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0194] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0195] Embodiment 9

[0196] The above is a resource transfer device provided in the embodiment of this specification. Based on the same idea, the embodiment of this specification also provides a resource transfer device, such as Figure 11 shown.

[0197] The resource transfer device may provide a terminal device or a server, etc. for the above embodiment.

[0198] Resource transfer devices may vary significantly due to different configurations or performance, and may include one or more processors 1101 and memory 1102. Memory 1102 may store one or more applications or data. Memory 1102 may be either ephemeral or persistent. Applications stored in memory 1102 may include one or more modules (not shown), each of which may include a series of computer-executable instructions for the resource transfer device. Furthermore, processor 1101 may be configured to communicate with memory 1102 to execute the series of computer-executable instructions in memory 1102 on the resource transfer device. The resource transfer device may also include one or more power supplies 1103, one or more wired or wireless network interfaces 1104, one or more input / output interfaces 1105, and one or more keyboards 1106.

[0199] Specifically, in this embodiment, the resource transfer device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the resource transfer device, and the one or more programs are configured to be executed by one or more processors, including computer-executable instructions for performing the following:

[0200] receiving a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier;

[0201] Obtaining resource transfer environment information corresponding to the resource transfer request, and if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, sending a second biometric recognition verification instruction to the terminal device, where the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication through a second biometric recognition mechanism;

[0202] receiving first signature information sent by the terminal device, and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism;

[0203] If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0204] In the embodiment of this specification, the verification of the first signature information includes:

[0205] Sending the first signature information to an authentication server, where the first signature information is used to trigger the authentication server to verify the first signature information;

[0206] A notification message sent by the authentication server indicating that the first signature information has been verified successfully is received, and the biometric information corresponding to the first signature information is verified. If the verification succeeds, it is determined that the verification of the first signature information has been successful.

[0207] In the embodiment of this specification, the biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information, and verifying the biometric information corresponding to the first signature information includes:

[0208] If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

[0209] In the embodiment of this specification, the first biometric recognition mechanism is a biometric recognition mechanism based on facial recognition, and the second biometric recognition mechanism is a biometric recognition mechanism based on fingerprint recognition.

[0210] In the embodiment of this specification, it also includes:

[0211] receiving an activation request for the second biometric recognition mechanism sent by the terminal device;

[0212] Generate activation verification information corresponding to the activation request, sign the activation verification information to obtain second signature information, and send the second signature information to the terminal device;

[0213] receiving an identity authentication request corresponding to the activation request sent by the terminal device, the identity authentication request being information sent by the terminal device after verifying the second signature information, the identity authentication request including at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0214] If the identity authentication result corresponding to the identity authentication request is passed, sending a setting instruction of the baseline biometric information corresponding to the second biometric recognition mechanism to the terminal device;

[0215] receiving third signature information sent by the terminal device, the third signature information being obtained by the terminal device signing the activation verification information and the baseline biometric information, and being sent after the terminal device verifies the baseline biometric information in a trusted execution environment and generates the third signature information in the trusted execution environment;

[0216] The third signature information is subjected to signature verification. If the signature verification passes, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification passes, the second biometric recognition mechanism is set based on the baseline biometric information.

[0217] In the embodiment of this specification, the activation verification information includes a challenge code and / or a session identifier.

[0218] In the embodiment of this specification, the signing process of the activation verification information to obtain the second signature information includes:

[0219] Sending the activation verification information to the authentication server, where the activation verification information is used to trigger the authentication server to sign the activation verification information to obtain second signature information;

[0220] Receive the second signature information sent by the authentication server.

[0221] In the embodiment of this specification, the first signature information is obtained by signing the biometric information corresponding to the second biometric recognition mechanism with the first signature key preset by the terminal device, the second signature information is obtained by signing the activation verification information with the second signature key set by the authentication server for the activation request, and the third signature information is obtained by signing the activation verification information and the baseline biometric information with the first signature key of the terminal device.

[0222] In the embodiment of this specification, the verification process of the third signature information includes:

[0223] Sending the third signature information to the authentication server, where the third signature information is used to trigger the authentication server to verify the third signature information and obtain a verification result;

[0224] Receive the signature verification result sent by the authentication server.

[0225] Furthermore, specifically in this embodiment, the resource transfer device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the resource transfer device, and the one or more programs are configured to be executed by one or more processors, including computer-executable instructions for performing the following:

[0226] Sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request, and generating a second biometric verification instruction if it is determined, based on the resource transfer environment information, that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and if a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold;

[0227] receiving the second biometric verification instruction, initiating the second biometric recognition mechanism to perform identity authentication based on the second biometric verification instruction, obtaining biometric information corresponding to the second biometric recognition mechanism after the identity authentication is passed, and signing the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information;

[0228] The first signature information is sent to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0229] In the embodiment of this specification, it also includes:

[0230] Sending an activation request for the second biometric recognition mechanism to a server, wherein the activation request is used to trigger the server to generate activation verification information corresponding to the activation request, and sign the activation verification information to obtain second signature information;

[0231] receiving the second signature information sent by the server, and performing signature verification on the second signature information; if the signature verification passes, sending an identity authentication request corresponding to the activation request to the server, wherein the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0232] receiving a setting instruction for the reference biometric information corresponding to the second biometric recognition mechanism sent by the server, wherein the setting instruction is sent by the server when the server determines that the identity authentication result corresponding to the identity authentication request is passed;

[0233] Obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification passes, sign the activation verification information and the baseline biometric information in the trusted execution environment to obtain third signature information, and send the third signature information to the server. The third signature information is used to trigger the server to verify the third signature information. If the verification passes, verify the activation verification information in the third signature information based on the locally stored activation verification information. If the verification passes, set the second biometric recognition mechanism based on the baseline biometric information.

[0234] An embodiment of the present specification provides a resource transfer device, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and then obtains resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device. The terminal device activates a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism. The server obtains the first signature information, receives the first signature information sent by the terminal device, and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0235] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0236] Example 10

[0237] Furthermore, based on the above Figures 1A to 6 In one or more embodiments of the present specification, a storage medium is provided for storing computer-executable instruction information. In a specific embodiment, the storage medium may be a USB flash drive, an optical disk, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be implemented:

[0238] receiving a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier;

[0239] Obtaining resource transfer environment information corresponding to the resource transfer request, and if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, sending a second biometric recognition verification instruction to the terminal device, where the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication through a second biometric recognition mechanism;

[0240] receiving first signature information sent by the terminal device, and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism;

[0241] If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0242] In the embodiment of this specification, the verification of the first signature information includes:

[0243] Sending the first signature information to an authentication server, where the first signature information is used to trigger the authentication server to verify the first signature information;

[0244] A notification message sent by the authentication server indicating that the first signature information has been verified successfully is received, and the biometric information corresponding to the first signature information is verified. If the verification succeeds, it is determined that the verification of the first signature information has been successful.

[0245] In the embodiment of this specification, the biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information, and verifying the biometric information corresponding to the first signature information includes:

[0246] If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

[0247] In the embodiment of this specification, the first biometric recognition mechanism is a biometric recognition mechanism based on facial recognition, and the second biometric recognition mechanism is a biometric recognition mechanism based on fingerprint recognition.

[0248] In the embodiment of this specification, it also includes:

[0249] receiving an activation request for the second biometric recognition mechanism sent by the terminal device;

[0250] Generate activation verification information corresponding to the activation request, sign the activation verification information to obtain second signature information, and send the second signature information to the terminal device;

[0251] receiving an identity authentication request corresponding to the activation request sent by the terminal device, the identity authentication request being information sent by the terminal device after verifying the second signature information, the identity authentication request including at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0252] If the identity authentication result corresponding to the identity authentication request is passed, sending a setting instruction of the baseline biometric information corresponding to the second biometric recognition mechanism to the terminal device;

[0253] receiving third signature information sent by the terminal device, the third signature information being obtained by the terminal device signing the activation verification information and the baseline biometric information, and being sent after the terminal device verifies the baseline biometric information in a trusted execution environment and generates the third signature information in the trusted execution environment;

[0254] The third signature information is subjected to signature verification. If the signature verification passes, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification passes, the second biometric recognition mechanism is set based on the baseline biometric information.

[0255] In the embodiment of this specification, the activation verification information includes a challenge code and / or a session identifier.

[0256] In the embodiment of this specification, the signing process of the activation verification information to obtain the second signature information includes:

[0257] Sending the activation verification information to the authentication server, where the activation verification information is used to trigger the authentication server to sign the activation verification information to obtain second signature information;

[0258] Receive the second signature information sent by the authentication server.

[0259] In the embodiment of this specification, the first signature information is obtained by signing the biometric information corresponding to the second biometric recognition mechanism with the first signature key preset by the terminal device, the second signature information is obtained by signing the activation verification information with the second signature key set by the authentication server for the activation request, and the third signature information is obtained by signing the activation verification information and the baseline biometric information with the first signature key of the terminal device.

[0260] In the embodiment of this specification, the verification process of the third signature information includes:

[0261] Sending the third signature information to the authentication server, where the third signature information is used to trigger the authentication server to verify the third signature information and obtain a verification result;

[0262] Receive the signature verification result sent by the authentication server.

[0263] Furthermore, in another specific embodiment, the storage medium may be a USB flash drive, an optical disk, a hard disk, etc., and the computer executable instruction information stored in the storage medium, when executed by the processor, can implement the following process:

[0264] Sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request, and generating a second biometric verification instruction if it is determined, based on the resource transfer environment information, that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and if a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold;

[0265] receiving the second biometric verification instruction, initiating the second biometric recognition mechanism to perform identity authentication based on the second biometric verification instruction, obtaining biometric information corresponding to the second biometric recognition mechanism after the identity authentication is passed, and signing the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information;

[0266] The first signature information is sent to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request.

[0267] In the embodiment of this specification, it also includes:

[0268] Sending an activation request for the second biometric recognition mechanism to a server, wherein the activation request is used to trigger the server to generate activation verification information corresponding to the activation request, and sign the activation verification information to obtain second signature information;

[0269] receiving the second signature information sent by the server, and performing signature verification on the second signature information; if the signature verification passes, sending an identity authentication request corresponding to the activation request to the server, wherein the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism;

[0270] receiving a setting instruction for the reference biometric information corresponding to the second biometric recognition mechanism sent by the server, wherein the setting instruction is sent by the server when the server determines that the identity authentication result corresponding to the identity authentication request is passed;

[0271] Obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification passes, sign the activation verification information and the baseline biometric information in the trusted execution environment to obtain third signature information, and send the third signature information to the server. The third signature information is used to trigger the server to verify the third signature information. If the verification passes, verify the activation verification information in the third signature information based on the locally stored activation verification information. If the verification passes, set the second biometric recognition mechanism based on the baseline biometric information.

[0272] An embodiment of the present specification provides a storage medium, which receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identification, and then obtains resource transfer environment information corresponding to the resource transfer request. If it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identification, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, a second biometric recognition verification instruction is sent to the terminal device, and the terminal device starts a second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, and after the identity authentication is passed, obtains the biometric information corresponding to the second biometric recognition mechanism, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism, thereby obtaining a biometric information corresponding to the second biometric recognition mechanism. To the first signature information, the server receives the first signature information sent by the terminal device and verifies the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is passed, resource transfer processing is performed based on the resource transfer request. In this way, by setting a second biometric recognition mechanism, in a scenario where multiple people share a terminal device or account, for high-risk operations by non-supervisory users and when the first biometric recognition mechanism may be bypassed, identity authentication is further completed through the second biometric recognition mechanism, so that users have a stronger sense of resource transfer, reduce resource risks, and still use the biometric recognition mechanism for identity authentication for the second time, which has a better interactive experience and does not cause the problem of forgetting the security password.

[0273] In addition, by setting a fingerprint that has been authenticated by a real person (i.e., the second biometric mechanism), this fingerprint identity authentication is used in scenarios where the payment is not made by the real person and the real person's face swiping may be bypassed. Since the fingerprint authentication operation requires obvious subconscious contact and pressing operations, it has a higher perception than face swiping, allowing users to have a strong perception of the identity authentication operation. In addition, in some specific scenarios, it can also replace real person face swiping. For example, at night, when the light is very poor, the real person authenticated security fingerprint can replace the real person's face swiping, thereby improving the user experience.

[0274] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0275] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures such as diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to hire a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly done using "logic compiler" software. This is similar to the software compiler used when developing programs. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that by simply programming the method flow in one of these hardware description languages ​​and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.

[0276] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code format, the controller can be implemented in the form of logic gates, switches, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the means for implementing various functions included therein can also be considered as structures within the hardware component. Or even, the means for implementing various functions can be considered as both a software module implementing the method and a structure within the hardware component.

[0277] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0278] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0279] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0280] The embodiments of this specification are described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable serial and parallel device to produce a machine, so that the instructions executed by the processor of the computer or other programmable serial and parallel device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0281] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable serial and parallel device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0282] These computer program instructions may also be loaded onto a computer or other programmable fraud case serial and parallel device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0283] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0284] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0285] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0286] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0287] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, one or more embodiments of this specification may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0288] One or more embodiments of this specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. One or more embodiments of this specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0289] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

[0290] The foregoing is merely an example of the present invention and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of this specification are intended to be included within the scope of the claims of this specification.

Claims

1. A resource transfer method, comprising: receiving a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and the terminal device is a device shared by multiple people; Obtaining resource transfer environment information corresponding to the resource transfer request; if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, sending a second biometric recognition verification instruction to the terminal device, where the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication through a second biometric recognition mechanism, and the resource transfer environment information is information about the environment during the resource transfer process, and the resource transfer environment information includes information about the current user and information about the surrounding environment of the current user; receiving first signature information sent by the terminal device, and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism; If the verification of the first signature information is successful, performing resource transfer processing based on the resource transfer request; The biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. Verifying the biometric information corresponding to the first signature information includes: If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

2. The method according to claim 1, wherein verifying the first signature information comprises: Sending the first signature information to an authentication server, where the first signature information is used to trigger the authentication server to verify the first signature information; A notification message sent by the authentication server indicating that the first signature information has been verified successfully is received, and the biometric information corresponding to the first signature information is verified. If the verification succeeds, it is determined that the verification of the first signature information has been successful. 3 . The method according to claim 2 , wherein the first biometric recognition mechanism is a biometric recognition mechanism based on facial recognition, and the second biometric recognition mechanism is a biometric recognition mechanism based on fingerprint recognition.

4. The method according to claim 1, further comprising: receiving an activation request for the second biometric recognition mechanism sent by the terminal device; Generate activation verification information corresponding to the activation request, sign the activation verification information to obtain second signature information, and send the second signature information to the terminal device; receiving an identity authentication request corresponding to the activation request sent by the terminal device, the identity authentication request being information sent by the terminal device after verifying the second signature information, the identity authentication request including at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism; If the identity authentication result corresponding to the identity authentication request is passed, sending a setting instruction of the baseline biometric information corresponding to the second biometric recognition mechanism to the terminal device; receiving third signature information sent by the terminal device, the third signature information being obtained by the terminal device signing the activation verification information and the baseline biometric information, and being sent after the terminal device verifies the baseline biometric information in a trusted execution environment and generates the third signature information in the trusted execution environment; The third signature information is subjected to signature verification. If the signature verification passes, the activation verification information in the third signature information is verified based on the locally stored activation verification information. If the verification passes, the second biometric recognition mechanism is set based on the baseline biometric information. 5 . The method according to claim 4 , wherein the activation verification information includes a challenge code and / or a session identifier.

6. The method according to claim 4, wherein the signing process is performed on the activation verification information to obtain the second signature information, comprising: Sending the activation verification information to an authentication server, where the activation verification information is used to trigger the authentication server to sign the activation verification information to obtain second signature information; Receive the second signature information sent by the authentication server.

7. According to the method according to claim 6, the first signature information is obtained by signing the biometric information corresponding to the second biometric recognition mechanism with the first signature key preset by the terminal device, the second signature information is obtained by signing the activation verification information with the second signature key set by the authentication server for the activation request, and the third signature information is obtained by signing the activation verification information and the baseline biometric information with the first signature key of the terminal device.

8. The method according to claim 4, wherein the verification of the third signature information comprises: Sending the third signature information to the authentication server, where the third signature information is used to trigger the authentication server to verify the third signature information and obtain a verification result; Receive the signature verification result sent by the authentication server.

9. A resource transfer method, applied to a terminal device, wherein the terminal device is a device shared by multiple people, the method comprising: Sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request, and generating a second biometric verification instruction if it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and if a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, the resource transfer environment information is information about the environment during the resource transfer process, and includes information about the current user and information about the surrounding environment of the current user; receiving the second biometric verification instruction, initiating the second biometric recognition mechanism to perform identity authentication based on the second biometric verification instruction, and after the identity authentication is passed, obtaining biometric information corresponding to the second biometric recognition mechanism, and signing the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; The first signature information is sent to the server, and the first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request. The biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. The biometric information corresponding to the first signature information is verified, including: if the biometric information index corresponding to the first signature information is the same as a pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information, then it is determined that the verification of the first signature information is successful.

10. The method according to claim 9, further comprising: Sending an activation request for the second biometric recognition mechanism to a server, wherein the activation request is used to trigger the server to generate activation verification information corresponding to the activation request, and sign the activation verification information to obtain second signature information; receiving the second signature information sent by the server, and performing signature verification on the second signature information; if the signature verification passes, sending an identity authentication request corresponding to the activation request to the server, wherein the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism; receiving a setting instruction for the reference biometric information corresponding to the second biometric recognition mechanism sent by the server, wherein the setting instruction is sent by the server when the server determines that the identity authentication result corresponding to the identity authentication request is passed; Obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification passes, sign the activation verification information and the baseline biometric information in the trusted execution environment to obtain third signature information, and send the third signature information to the server. The third signature information is used to trigger the server to verify the third signature information. If the verification passes, verify the activation verification information in the third signature information based on the locally stored activation verification information. If the verification passes, set the second biometric recognition mechanism based on the baseline biometric information.

11. A resource transfer system, comprising a terminal device and a server, wherein the terminal device is a device shared by multiple people, wherein: The terminal device is configured to send a resource transfer request to the server, wherein the resource transfer request includes a user identifier; The server is configured to obtain resource transfer environment information corresponding to the resource transfer request, and if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, then send a second biometric verification instruction to the terminal device, wherein the resource transfer environment information is information about the environment during the resource transfer process, and the resource transfer environment information includes information about the current user and information about the surrounding environment of the current user; The terminal device is configured to initiate the second biometric recognition mechanism to perform identity authentication based on the second biometric recognition verification instruction, and after the identity authentication is passed, obtain biometric information corresponding to the second biometric recognition mechanism, perform signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information, and send the first signature information to the server; The server is configured to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request. The biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. The biometric information corresponding to the first signature information is verified, including: if the biometric information index corresponding to the first signature information is the same as a pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information, then it is determined that the verification of the first signature information is successful.

12. The system according to claim 11, wherein the server comprises a business server and an authentication server, wherein: The business server is configured to send the first signature information to the authentication server; The authentication server is configured to perform signature verification on the first signature information, and if the signature verification succeeds, send a notification message to the business server indicating that the signature verification of the first signature information succeeds; The business server is configured to verify the biometric information corresponding to the first signature information, and if the verification is successful, determine that the verification of the first signature information is successful.

13. The system according to claim 12, wherein the terminal device is configured to send an activation request for the second biometric recognition mechanism to the service server; The service server is configured to generate activation verification information corresponding to the activation request and send the activation verification information to the authentication server; The authentication server is configured to perform signature processing on the activation verification information to obtain second signature information, and send the second signature information to the service server; The service server is configured to send the second signature information to the terminal device; The terminal device is configured to verify the second signature information, and if the verification is successful, send an identity authentication request corresponding to the activation request to the service server, wherein the identity authentication request includes at least the biometric information to be authenticated corresponding to the first biometric recognition mechanism; The service server is configured to perform identity authentication processing corresponding to the identity authentication request, and if it is determined that the identity authentication result corresponding to the identity authentication request is passed, send a setting instruction for the baseline biometric information corresponding to the second biometric recognition mechanism to the terminal device; The terminal device is configured to obtain the baseline biometric information and verify the baseline biometric information in a trusted execution environment. If the verification is successful, the terminal device is configured to sign the activation verification information and the baseline biometric information in the trusted execution environment to obtain third signature information, and send the third signature information to the service server. The business server is configured to send the third signature information to the authentication server; The authentication server is configured to perform signature verification on the third signature information, obtain a signature verification result, and send the signature verification result to the business server; The service server is configured to verify the activation verification information in the third signature information based on the locally stored activation verification information if the signature verification is successful, and to set the second biometric recognition mechanism based on the baseline biometric information if the verification is successful.

14. A resource transfer device, comprising: A first request module receives a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and the terminal device is a device shared by multiple people; a detection module, which obtains resource transfer environment information corresponding to the resource transfer request, and if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using the preset first biometric recognition mechanism is higher than a preset risk threshold, sends a second biometric recognition verification instruction to the terminal device, wherein the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication through the second biometric recognition mechanism, and the resource transfer environment information is information about the environment during the resource transfer process, and the resource transfer environment information includes information about the current user and information about the surrounding environment of the current user; a verification module, receiving first signature information sent by the terminal device and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism; a resource transfer module, configured to perform resource transfer processing based on the resource transfer request if verification of the first signature information is successful; The biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. Verifying the biometric information corresponding to the first signature information includes: If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

15. A resource transfer device, the device being a device shared by multiple people, comprising: a first request module, sending a resource transfer request to a server, wherein the resource transfer request includes a user identifier, and the resource transfer request is used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request; if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, then generating a second biometric verification instruction, wherein the resource transfer environment information is information about the environment during the resource transfer process, and the resource transfer environment information includes information about the current user and information about the surrounding environment of the current user; an identity authentication module that receives the second biometric verification instruction, activates the second biometric recognition mechanism to perform identity authentication based on the second biometric verification instruction, obtains biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performs signature processing on the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; The resource transfer trigger module sends the first signature information to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, the resource transfer processing is performed based on the resource transfer request; the biometric information corresponding to the second biometric recognition mechanism includes one or more of the biometric information index and the modification time of the biometric information. The biometric information corresponding to the first signature information is verified, including: if the biometric information index corresponding to the first signature information is the same as the pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information, then it is determined that the verification of the first signature information is successful.

16. A resource transfer device, comprising: processor; as well as a memory arranged to store computer-executable instructions which, when executed, cause the processor to: receiving a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and the terminal device is a device shared by multiple people; Obtaining resource transfer environment information corresponding to the resource transfer request; if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, sending a second biometric recognition verification instruction to the terminal device, where the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication through a second biometric recognition mechanism, and the resource transfer environment information is information about the environment during the resource transfer process, and the resource transfer environment information includes information about the current user and information about the surrounding environment of the current user; receiving first signature information sent by the terminal device, and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism; If the verification of the first signature information is successful, performing resource transfer processing based on the resource transfer request; The biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. Verifying the biometric information corresponding to the first signature information includes: If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

17. A resource transfer device, the resource transfer device being a device shared by multiple people, the resource transfer device comprising: processor; as well as a memory arranged to store computer-executable instructions which, when executed, cause the processor to: Sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request, and generating a second biometric verification instruction if it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and if a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, the resource transfer environment information is information about the environment during the resource transfer process, and includes information about the current user and information about the surrounding environment of the current user; receiving the second biometric verification instruction, initiating the second biometric recognition mechanism to perform identity authentication based on the second biometric verification instruction, and after the identity authentication is passed, obtaining biometric information corresponding to the second biometric recognition mechanism, and signing the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; The first signature information is sent to the server, and the first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request; the biometric information corresponding to the second biometric recognition mechanism includes one or more of the biometric information index and the modification time of the biometric information. The biometric information corresponding to the first signature information is verified, including: if the biometric information index corresponding to the first signature information is the same as the pre-stored benchmark biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the benchmark biometric information, then it is determined that the verification of the first signature information is successful.

18. A storage medium for storing computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the following process: receiving a resource transfer request sent by a terminal device, wherein the resource transfer request includes a user identifier, and the terminal device is a device shared by multiple people; Obtaining resource transfer environment information corresponding to the resource transfer request; if it is determined based on the resource transfer environment information that the initiator of the resource transfer request is different from the target user corresponding to the user identifier, and the risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, sending a second biometric recognition verification instruction to the terminal device, where the second biometric recognition verification instruction is used to instruct the terminal device to perform identity authentication through a second biometric recognition mechanism, and the resource transfer environment information is information about the environment during the resource transfer process, and the resource transfer environment information includes information about the current user and information about the surrounding environment of the current user; receiving first signature information sent by the terminal device, and verifying the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric recognition mechanism, wherein the first signature information is obtained by the terminal device initiating the second biometric recognition mechanism for identity authentication based on the second biometric recognition verification instruction, obtaining the biometric information corresponding to the second biometric recognition mechanism after the identity authentication is successful, and performing signature processing on the biometric information corresponding to the second biometric recognition mechanism; If the verification of the first signature information is successful, performing resource transfer processing based on the resource transfer request; The biometric information corresponding to the second biometric recognition mechanism includes one or more of a biometric information index and a modification time of the biometric information. Verifying the biometric information corresponding to the first signature information includes: If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

19. A storage medium for storing computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the following process: Sending a resource transfer request to a server, the resource transfer request including a user identifier, the resource transfer request being used to trigger the server to obtain resource transfer environment information corresponding to the resource transfer request, and generating a second biometric verification instruction if it is determined based on the resource transfer environment information that the initiating user of the resource transfer request is different from the target user corresponding to the user identifier, and if a risk of identity authentication using a preset first biometric recognition mechanism is higher than a preset risk threshold, the resource transfer environment information is information about the environment during the resource transfer process, and includes information about the current user and information about the surrounding environment of the current user; receiving the second biometric verification instruction, initiating the second biometric recognition mechanism to perform identity authentication based on the second biometric verification instruction, and after the identity authentication is passed, obtaining biometric information corresponding to the second biometric recognition mechanism, and signing the biometric information corresponding to the second biometric recognition mechanism to obtain first signature information; The first signature information is sent to the server. The first signature information is used to trigger the server to verify the first signature information to verify the signature in the first signature information and the biometric information corresponding to the second biometric identification mechanism. If the verification of the first signature information is successful, resource transfer processing is performed based on the resource transfer request. The biometric information corresponding to the second biometric identification mechanism includes one or more of a biometric information index and a modification time of the biometric information. Verifying the biometric information corresponding to the first signature information includes: If the biometric information index corresponding to the first signature information is the same as the pre-stored reference biometric information index, and / or the modification time of the biometric information corresponding to the first signature information is the effective time of the reference biometric information, it is determined that the verification of the first signature information is successful.

Citation Information

Patent Citations

  • Identity authentication method and device

    CN106487511A

  • Authentication method and electronic equipment

    CN113641981A