Identity authentication method and device, computer device and storage medium
By performing hash calculations and comparisons on facial features through the application front end, the security issues in the transmission and storage of facial information are solved, enabling an identity authentication method that does not require backend storage and improving the security of personal information.
Patent Information
- Application Number
- CN202210985896.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-16
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2042-08-16
AI Technical Summary
The lack of encryption protection during the transmission and storage of facial information leads to high risks to personal information security, and once leaked, it is difficult to delete or modify.
The application front end performs hash calculations on the facial features captured by the camera to generate a message digest, and compares it with the digest returned by the digital wallet to ensure that the features have not been modified. At the same time, the hash algorithm is used to encrypt and improve transmission security, so the back end does not need to store the user's facial information.
It enables local facial recognition authentication, avoiding the need for the application backend to store user facial information, thus improving the security and privacy protection of personal information.
Smart Images

Figure CN115567240B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to an identity authentication method, apparatus, computer device, and storage medium. Background Technology
[0002] Facial recognition is a biometric technology that identifies individuals based on their facial features. It involves using cameras or webcams to capture images or video streams containing faces, automatically detecting and tracking faces within the images, and then performing facial recognition on the detected faces. This technology is also commonly referred to as portrait recognition or face recognition.
[0003] Currently, when users use an app, they typically need to register a user account to log in. To enhance account security and login convenience, many apps use facial recognition to verify user identity and log in to their accounts.
[0004] However, facial information is a biometric feature, unique and difficult to alter, posing a significant risk if leaked. Users need to upload photos to register their facial information for identity verification. However, this information is often not encrypted or protected during transmission. After verification, the app's backend server often doesn't delete the collected facial information and may even retain it for extended periods for other purposes. If facial information is leaked at any stage, it is very difficult to completely delete or modify, posing a substantial personal information security risk. Summary of the Invention
[0005] Therefore, it is necessary to provide an identity authentication method, apparatus, computer equipment, and storage medium to address the aforementioned technical problems.
[0006] An authentication method, applied to an application, includes:
[0007] The application's front end sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera.
[0008] The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0009] When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature;
[0010] The current user's identity is authenticated when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0011] In one embodiment, the method further includes:
[0012] The application's backend obtains the current user's DID (decentralized identity identifier) sent by the digital wallet;
[0013] The backend obtains the corresponding DID document based on the DID;
[0014] The backend obtains the public key based on the DID document;
[0015] The backend encrypts a random number based on the public key to obtain the encryption result;
[0016] The backend sends the encrypted result to the digital wallet.
[0017] In one embodiment, the step of verifying the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold includes:
[0018] If the similarity between the first facial feature and the second facial feature is not less than a set threshold, then the facial recognition matching of the current user is successful.
[0019] The front end sends the result of the current user's face recognition matching to the digital wallet;
[0020] The backend receives the plaintext returned by the digital wallet and compares the plaintext with the random number;
[0021] When the plaintext and the random number are the same, the DID is a valid identity identifier, and the current user's identity authentication is successful.
[0022] In one embodiment, after the step where the DID is a valid identity identifier when the plaintext and the random number are the same, and the current user's identity authentication is successful, the method further includes:
[0023] The front end obtains the result of the current user's identity authentication and logs in based on the DID.
[0024] In one embodiment, before the step of sending a face recognition request to the digital wallet from the front end of the application and obtaining the first facial features of the current user captured by the camera, the method further includes:
[0025] The front-end obtains the session identifier and application login address from the back-end based on the DID login request initiated by the current user, and uses them to authorize the DID login initiated by the current user through the digital wallet.
[0026] In one embodiment, the first facial feature is captured by the camera and sent to the front end by the digital wallet.
[0027] An authentication method applied to digital wallets includes:
[0028] Receive face recognition requests from the application's front end;
[0029] Send the current user's second facial features and first information digest.
[0030] An identity authentication device includes:
[0031] The first acquisition module is used by the application's front end to send a face recognition request to the digital wallet and acquire the first facial features of the current user captured by the camera.
[0032] The second acquisition module is used by the front end to perform a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0033] The comparison module is used to compare the first facial feature and the second facial feature when the first information digest is the same as the second information digest;
[0034] The identity authentication module is used to verify the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0035] An identity authentication device includes:
[0036] The receiving module is used to receive face recognition requests from the application's front end;
[0037] The sending module is used to send the current user's second facial features and first information digest.
[0038] A computer device includes a memory and a processor, the memory storing a computer program, characterized in that the processor executes the computer program to perform the following steps:
[0039] The application's front end sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera.
[0040] The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0041] When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature;
[0042] The current user's identity is authenticated when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0043] A computer device includes a memory and a processor, the memory storing a computer program, characterized in that the processor executes the computer program to perform the following steps:
[0044] Receive face recognition requests from the application's front end;
[0045] Send the current user's second facial features and first information digest.
[0046] A computer-readable storage medium having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0047] The application's front end sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera.
[0048] The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0049] When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature;
[0050] The current user's identity is authenticated when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0051] A computer-readable storage medium having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0052] Receive face recognition requests from the application's front end;
[0053] Send the current user's second facial features and first information digest.
[0054] The aforementioned authentication method, device, computer equipment, and storage medium involve the application's front end sending a facial recognition request to the digital wallet. The digital wallet then returns the current user's facial features and a digest to the application. The application's front end performs a hash operation on the received facial features to obtain a digest, which is then compared with the original digest to ensure the received facial features have not been modified. Furthermore, the hash algorithm encryption enhances the security of facial feature transmission. The application's front end then compares the current user's facial features captured by the camera with the received facial features. If the similarity is not less than a set threshold, the facial recognition is successful, the user's identity is authenticated, and they can log in to the application. This authentication method eliminates the need to store the user's facial features on the application's backend, preventing the application from collecting and retaining user facial information for other purposes and significantly improving personal information security. Attached Figure Description
[0055] Figure 1 This is a schematic diagram illustrating an application scenario of an identity authentication method in one embodiment;
[0056] Figure 2 This is a flowchart illustrating an identity authentication method in one embodiment;
[0057] Figure 3 This is a flowchart illustrating an identity authentication method in one embodiment;
[0058] Figure 4 This is a schematic diagram of the interaction process of an identity authentication method in one embodiment;
[0059] Figure 5 This is a structural block diagram of an identity authentication device in one embodiment;
[0060] Figure 6 This is a structural block diagram of an identity authentication device in one embodiment;
[0061] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0062] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0063] Example 1
[0064] The authentication method provided in this application can be applied to, for example... Figure 1In the application environment shown, terminal 102 communicates with server 104 via a network. Terminal 102 can be, but is not limited to, various personal computers, servers, laptops, smartphones, tablets, and portable wearable devices. Server 104 can be implemented as a standalone server or a server cluster consisting of multiple servers. Server 104 can be the backend server for multiple apps.
[0065] Terminal 102 contains several apps and digital wallets with different functions. The digital wallet is an application that manages a user's DID (Decentralized Identifier), used not only for basic financial transactions but also for verifying the holder's credentials. Users can use the digital wallet to generate their own DID, manage data and permissions, and issue / verify DID-related claims. A DID is an identity certificate that a user generates, manages, and controls independently of an institution or government, possessing global uniqueness, high availability, resolvability, and cryptographic verifiability. DIDs can be used to identify people, organizations, and things, and implement numerous security and privacy protection guarantees. Individuals and trusted third-party identity verification agencies generate DIDs and DID documents respectively, then store the DID as the key and the DID document as the value in a decentralized system. The backend of the digital wallet is a decentralized system (such as blockchain, distributed ledger, distributed file system, etc.). The DID is registered on the decentralized system, and the DID document can be retrieved from the decentralized system upon user request to obtain the user's stored information.
[0066] The authentication method of this application involves the application front-end of terminal 102 sending a face recognition request to the digital wallet. The digital wallet then returns the current user's facial features and a digest to the application. The application front-end performs a hash operation on the received facial features to obtain a digest, which is then compared with the original digest to ensure that the received facial features have not been modified. Furthermore, the hash algorithm encryption enhances the security of facial feature transmission. The application front-end compares the current user's facial features captured by the camera with the received facial features. If the similarity is not less than a set threshold, the face recognition is successful, the current user's identity is authenticated, and they can log in to the application. This face recognition-based authentication method is implemented locally on terminal 102. The application only needs to obtain the user's facial features managed by the digital wallet to complete the current user's face recognition, eliminating the need to store the user's facial features on the application's back-end. This avoids the application collecting and retaining user facial information for other purposes, significantly improving the security of personal information.
[0067] Example 2
[0068] In this embodiment, as Figure 2 As shown, an authentication method is provided for application, which includes:
[0069] Step 210: The front end of the application sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera.
[0070] Specifically, a digital wallet is an application that conducts electronic payment transactions and manages users' DIDs. The application using the authentication method in this embodiment can enter into a trust agreement with the digital wallet, thereby establishing communication and authorizing DID login. When a user selects the DID login function, the application's front end can send a facial recognition request to the digital wallet.
[0071] Step 220: The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet.
[0072] Step 230: When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature.
[0073] Step 240: When the similarity between the first facial feature and the second facial feature is not less than a set threshold, the current user's identity authentication is successful.
[0074] Specifically, the second facial feature sent by the digital wallet is encrypted using a hash algorithm, which can effectively improve the security during transmission. Furthermore, the application's front end performs a hash operation on the second facial feature to obtain a second information digest, which is then compared and verified with the first information digest (original information digest). If they are the same, it indicates that the second facial feature has not been modified, thus improving the authenticity and validity of the transmitted data.
[0075] It should be understood that the second facial feature is personal information already stored by the user in their digital wallet. This second facial feature can be extracted from a user's authenticated photo (such as an ID card), and after hashing, a message digest is generated and placed in the credentialsubject field of the VC (Verifiable Credential). When the application's front-end sends a facial recognition request to the digital wallet, it can be considered as requesting a VC from the digital wallet, and the digital wallet then sends the VC, including the second facial feature and the first message digest, to the application's front-end.
[0076] In the aforementioned authentication method, the application's front-end sends a facial recognition request to the digital wallet. The digital wallet then returns the current user's facial features and a digest to the application. The application's front-end performs a hash operation on the received facial features to obtain a digest, which is then compared to the original digest to ensure the received facial features have not been modified. The hash algorithm also enhances the security of facial feature transmission. Finally, the application's front-end compares the current user's facial features captured by the camera with the received facial features. If the similarity is not less than a set threshold, the facial recognition is successful, the user's identity is authenticated, and they can log in to the application. This authentication method eliminates the need to store the user's facial features on the application's back-end, preventing the application from collecting and retaining user facial information for other purposes and significantly improving personal information security.
[0077] In one embodiment, before the step of the application's front end sending a face recognition request to the digital wallet and obtaining the first facial feature of the current user captured by the camera, the method further includes: the front end obtaining a session identifier and application login address from the back end based on the DID login request initiated by the current user, for use in authorizing the digital wallet to initiate DID login by the current user.
[0078] Specifically, the session identifier (loginID) is the identifier used by a user to log in to the application, distinguishing users; the application login URL (Uniform Resource Locator) is used to provide digital wallets with identification of the application and to locate the application's backend. In other words, when a user selects DID login on the application frontend, the frontend will trigger the retrieval of the loginID and URL from the backend.
[0079] In one embodiment, the application's front end can initiate a redirect to a digital wallet, allowing the digital wallet to initiate an authorized DID login.
[0080] In another embodiment, the application's front end can generate and display a barcode based on the loginID and URL. The information carried in the barcode includes the loginID and URL. The user can save the barcode and scan it in a digital wallet. The digital wallet can then obtain the user's loginID and URL and send the user's DID to the back end of the application located at that URL.
[0081] In one embodiment, the digital wallet also sends the loginID to the application's backend so that the application's backend can determine the loginID corresponding to the user's DID and establish a correspondence.
[0082] In one embodiment, the barcode may include, but is not limited to, one-dimensional barcodes, two-dimensional barcodes, and hexadecimal codes.
[0083] To further enhance security, in one embodiment, the method further includes:
[0084] The application's backend obtains the current user's DID (decentralized identity identifier) sent by the digital wallet;
[0085] The backend obtains the corresponding DID document based on the DID;
[0086] The backend obtains the public key based on the DID document;
[0087] The backend encrypts a random number based on the public key to obtain the encryption result;
[0088] The backend sends the encrypted result to the digital wallet.
[0089] Specifically, the application backend, based on the obtained DID of the current user, can request a DID from the DID service. The DID parser in the DID service can locate the corresponding DID document based on the DID and request the DID document from the blockchain. Once the DID service obtains the DID document, it returns it to the application backend. The application can then use the public key stored in the DID document to encrypt a random number and send the encrypted result to the digital wallet, i.e., initiate a challenge. It is important to understand that the challenge initiated by the application is the "challenge" in the challenge-response mechanism. The digital wallet, on the other hand, must "respond" after receiving the challenge. Specifically, the digital wallet possesses the private key corresponding to the user's DID. After receiving the encrypted result, the digital wallet can use the private key to decrypt the encrypted result to obtain the plaintext of the aforementioned random number. The digital wallet sends the plaintext back to the application backend, which compares it with the original random number. If they match, it indicates that the information transmission was secure. This mechanism can prevent information from being eavesdropped on or leaked during transmission, further improving security.
[0090] It should be understood that digital wallets, DID services, and blockchain belong to a decentralized system. Digital wallets and the other applications mentioned above are independent and separate applications, not part of the same system. Because different vendors developing these applications do not trust each other, safeguards are needed to ensure that their data is not leaked. Applications need to establish trust with the digital wallet beforehand so that the application's backend can communicate with the DID service.
[0091] The steps for initiating a challenge in the above embodiments can be performed before the face recognition request is initiated in the application front end, after the face recognition request is initiated in the application front end, or simultaneously, which will not be elaborated here.
[0092] In one embodiment, the first facial feature is captured by the camera when the application's front end calls the camera. That is, when the application's front end sends a facial recognition request to the digital wallet, it also calls the device's camera within the application to capture the current user's face and extract facial features for facial recognition.
[0093] To further enhance the security of personal information, in another embodiment, the first facial feature is captured by the digital wallet using the camera and sent to the front end. Specifically, upon receiving a facial recognition request from the application's front end, the digital wallet uses the device's camera to take a picture of the current user's face, extracts facial features from the photo, and sends these features to the application's front end. In other words, the digital wallet sends facial features, not the original image, to the application's front end. This prevents the application's front end from obtaining the user's complete image or facial features, thus discouraging the application from incentivizing it to save or collect user images. This embodiment separates the facial recognition extraction and comparison processes, further enhancing the security of personal information and preventing information leakage.
[0094] Understandably, a digital wallet can send the first facial feature, the second facial feature, and the first message digest simultaneously; it can also send the first facial feature first, followed by the second facial feature and the first message digest; or it can send the second facial feature and the first message digest first, followed by the first facial feature. In one example, the first facial feature can carry an identifier indicating that the facial feature is extracted from a user's headshot captured by a camera.
[0095] In one embodiment, the step of verifying the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold includes:
[0096] If the similarity between the first facial feature and the second facial feature is not less than a set threshold, then the facial recognition matching of the current user is successful.
[0097] The front end sends the result of the current user's face recognition matching to the digital wallet;
[0098] The backend receives the plaintext returned by the digital wallet and compares the plaintext with the random number;
[0099] When the plaintext and the random number are the same, the DID is a valid identity identifier, and the current user's identity authentication is successful.
[0100] In this embodiment, after the face recognition match is successful, the application frontend sends the matching result to the digital wallet to trigger the digital wallet to send a "response". It is understood that if the face recognition match result is unsuccessful, the digital wallet does not need to send a "response" to save resources.
[0101] In one embodiment, after the step of "when the plaintext and the random number are the same, the DID is a valid identity identifier and the current user's identity authentication is successful", the method further includes: the front end obtains the result of the current user's identity authentication being successful and logs in based on the DID.
[0102] At this point, the current user has completed the login process using their DID in the application's front end and can now use the application normally.
[0103] To improve user experience, in one embodiment, after completing DID login, the application's front-end receives and saves the session token sent by the application's back-end. This way, when a user subsequently logs into the application, the application's front-end will determine that the session token is stored and that the current login time is within the time range set by the session token (i.e., the session token has not expired). Therefore, there is no need to perform DID verification again, thus eliminating the need for the user to perform DID login every time they open the application, thereby improving user experience.
[0104] Example 3
[0105] In this embodiment, as Figure 3 As shown, correspondingly, an identity authentication method is provided for digital wallets, including:
[0106] Step 310: Receive a face recognition request from the application's front end;
[0107] Step 320: Send the current user's second facial features and first information digest.
[0108] In one embodiment, the method further includes:
[0109] The digital wallet obtains the current user's facial photo captured by the camera;
[0110] The digital wallet extracts the first facial feature from the face photo and sends it to the front end of the application.
[0111] In one embodiment, the method further includes:
[0112] Send the current user's decentralized identity identifier (DID) to the backend of the application;
[0113] The system receives an encryption result sent by the backend, which is obtained by the backend from the corresponding DID document based on the DID, the public key based on the DID document, and the encryption of a random number based on the public key.
[0114] It should be understood that the digital wallet in the above embodiments corresponds to the digital wallet in the application authentication method of Embodiment 2, and will not be described again here.
[0115] Example 4
[0116] In this embodiment, as Figure 4 The diagram illustrates the interaction process of an identity authentication method. The app front-end and back-end are the same app; the digital wallet, DID service, and blockchain are components of a decentralized system. The app can communicate with the decentralized system via a network.
[0117] Step 401: The user selects DID login on the login screen at the front end of the APP.
[0118] Step 402: The APP front-end obtains the session identifier (loginID) and the APP login address (URL) from the APP back-end, and displays a QR code on the APP front-end. The QR code carries the loginID and URL information.
[0119] Step 403: The user uses the digital wallet on the terminal. The digital wallet scans the QR code to obtain the loginID and URL, and authorizes the APP to log in using the DID.
[0120] Step 404: The digital wallet sends the loginID and the user's DID to the URL.
[0121] Step 405: After receiving the loginID and DID, the APP backend sends the DID to the DID resolver in the DID service.
[0122] Step 406: The DID parser parses and locates the DID document corresponding to the DID, and requests the DID document from the blockchain.
[0123] Step 407: Based on the parsing result sent by the DID parser, obtain the DID document corresponding to the DID from the blockchain, and check the document integrity by comparing the hash values.
[0124] Step 408: The blockchain returns the DID document to the DID service.
[0125] Step 409: The DID service returns the DID document to the APP backend, and the APP backend obtains the public key from the DID document.
[0126] Step 410: The APP backend uses this public key to initiate a challenge, encrypts a random number using the public key to obtain the encrypted result, and sends the encrypted result to the digital wallet.
[0127] Step 411: The digital wallet uses the private key corresponding to the DID to decrypt the received encrypted result and obtain the plaintext of the aforementioned random number.
[0128] Step 412: The APP front-end initiates a facial recognition request to the digital wallet.
[0129] Step 413: The digital wallet calls the device's camera to obtain the current user's profile picture and extracts the first facial features from the profile picture, as well as the second facial features from the user's authenticated photos (such as ID cards) stored in the digital wallet.
[0130] Step 414: The digital wallet transmits the first facial feature, the second facial feature, and the information digest to the APP front end.
[0131] Step 415: The APP front-end performs a hash operation on the second face feature to obtain an information digest, and compares it with the original information digest. If they are the same, it is confirmed that the second face feature has not been modified. Then, an image recognition algorithm is used to compare the received first face feature and second face feature.
[0132] Step 416: When the similarity between the two is not less than the set threshold, the face matching is successful, and the APP front-end sends the matching result and session identifier to the digital wallet and APP back-end.
[0133] It is understandable that the APP backend mainly completes DID verification, while the user's facial features are transmitted to the APP frontend for comparison and recognition, but not to the APP backend. The APP backend does not retain the user's facial features, which can effectively prevent the APP backend from collecting and retaining the user's facial information for other purposes, and greatly improve the security of personal information.
[0134] Step 417: The digital wallet sends the plaintext of the aforementioned random number and the session identifier to the APP backend.
[0135] Step 418: The APP backend verifies the challenge result by comparing the received plaintext with the original random number. If the two are equal, the challenge-response is successful, the DID is a valid identity identifier, and the identity authentication is successful. The APP backend sets the DID to the verification status.
[0136] In step 419, the APP frontend polls to obtain the identity authentication result, and the APP backend sends a session token to the frontend, indicating successful login. At this point, the APP frontend has successfully logged in using the DID and verified that the current user is the one verified by the DID.
[0137] It should be understood that, although Figure 2-4 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 2-4 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.
[0138] Example 5
[0139] In this embodiment, as Figure 5 As shown, an identity authentication device is provided, comprising:
[0140] The first acquisition module 510 is used for the application's front end to send a face recognition request to the digital wallet and acquire the first facial features of the current user captured by the camera.
[0141] The second acquisition module 520 is used by the front end to perform a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0142] The comparison module 530 is used to compare the first facial feature and the second facial feature when the first information digest is the same as the second information digest;
[0143] The identity authentication module 540 is used to verify the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0144] In one embodiment, the apparatus further includes:
[0145] The third acquisition module is used by the backend of the application to acquire the decentralized identity identifier (DID) of the current user sent by the digital wallet;
[0146] The fourth acquisition module is used by the backend to acquire the corresponding DID document based on the DID;
[0147] The fifth acquisition module is used by the backend to obtain the public key based on the DID document;
[0148] The encryption module is used by the backend to encrypt a random number based on the public key to obtain an encryption result;
[0149] The first sending module is used for the backend to send the encrypted result to the digital wallet.
[0150] In one embodiment, the identity authentication module includes:
[0151] A face recognition unit is configured to determine if the face recognition of the current user is successful when the similarity between the first face feature and the second face feature is not less than a set threshold.
[0152] The sending unit is used for the front end to send the result of the current user's face recognition matching to the digital wallet;
[0153] The comparison unit is used for the backend to receive the plaintext fed back by the digital wallet and compare the plaintext with the random number;
[0154] An identity authentication unit is used to determine that if the plaintext and the random number are the same, then the DID is a valid identity identifier and the current user's identity authentication is successful.
[0155] In one embodiment, the apparatus further includes:
[0156] The login module is used by the front end to obtain the result of the current user's identity authentication and to log in based on the DID.
[0157] In one embodiment, the apparatus further includes:
[0158] The sixth acquisition module is used by the front end to obtain the session identifier and application login address from the back end based on the DID login request initiated by the current user, and is used to provide the digital wallet with authorization for the DID login initiated by the current user.
[0159] In one embodiment, the first facial feature is captured by the camera and sent to the front end by the digital wallet.
[0160] Example 6
[0161] In this embodiment, as Figure 6 As shown, another identity authentication device is provided, including:
[0162] The receiving module 610 is used to receive face recognition requests from the front end of the application.
[0163] The sending module 620 is used to send the second facial feature and the first information digest of the current user.
[0164] For specific limitations regarding the authentication device, please refer to the limitations on the authentication method above, which will not be repeated here. Each module and unit in the aforementioned authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. Each of these units can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of these units.
[0165] Example 7
[0166] In this embodiment, a computer device is provided. Its internal structure diagram can be shown as follows: Figure 7 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores an operating system and computer programs, and also contains a database for storing user behavior data and user profiles. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with other computer devices that have deployed application software. When the processor executes the computer program, it implements a method for processing goods in / out data. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0167] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0168] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to perform the following steps:
[0169] The application's front end sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera.
[0170] The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0171] When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature;
[0172] The current user's identity is authenticated when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0173] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0174] The application's backend obtains the current user's DID (decentralized identity identifier) sent by the digital wallet;
[0175] The backend obtains the corresponding DID document based on the DID;
[0176] The backend obtains the public key based on the DID document;
[0177] The backend encrypts a random number based on the public key to obtain the encryption result;
[0178] The backend sends the encrypted result to the digital wallet.
[0179] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0180] The step of verifying the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold includes:
[0181] If the similarity between the first facial feature and the second facial feature is not less than a set threshold, then the facial recognition matching of the current user is successful.
[0182] The front end sends the result of the current user's face recognition matching to the digital wallet;
[0183] The backend receives the plaintext returned by the digital wallet and compares the plaintext with the random number;
[0184] When the plaintext and the random number are the same, the DID is a valid identity identifier, and the current user's identity authentication is successful.
[0185] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0186] After the step where the DID is a valid identity identifier when the plaintext and the random number are the same, and the current user's identity authentication is successful, the method further includes:
[0187] The front end obtains the result of the current user's identity authentication and logs in based on the DID.
[0188] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0189] Before the step of sending a face recognition request to the digital wallet from the front end of the application and obtaining the first facial feature of the current user captured by the camera, the method further includes:
[0190] The front-end obtains the session identifier and application login address from the back-end based on the DID login request initiated by the current user, and uses them to authorize the DID login initiated by the current user through the digital wallet.
[0191] In one embodiment, the first facial feature is captured by the camera and sent to the front end by the digital wallet.
[0192] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0193] The digital wallet receives a facial recognition request from the application's front end;
[0194] The digital wallet sends the current user's second facial features and first message digest.
[0195] Example 8
[0196] In this embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it performs the following steps:
[0197] The application's front end sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera.
[0198] The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet;
[0199] When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature;
[0200] The current user's identity is authenticated when the similarity between the first facial feature and the second facial feature is not less than a set threshold.
[0201] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0202] The application's backend obtains the current user's DID (decentralized identity identifier) sent by the digital wallet;
[0203] The backend obtains the corresponding DID document based on the DID;
[0204] The backend obtains the public key based on the DID document;
[0205] The backend encrypts a random number based on the public key to obtain the encryption result;
[0206] The backend sends the encrypted result to the digital wallet.
[0207] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0208] The step of verifying the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold includes:
[0209] If the similarity between the first facial feature and the second facial feature is not less than a set threshold, then the facial recognition matching of the current user is successful.
[0210] The front end sends the result of the current user's face recognition matching to the digital wallet;
[0211] The backend receives the plaintext returned by the digital wallet and compares the plaintext with the random number;
[0212] When the plaintext and the random number are the same, the DID is a valid identity identifier, and the current user's identity authentication is successful.
[0213] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0214] After the step where the DID is a valid identity identifier when the plaintext and the random number are the same, and the current user's identity authentication is successful, the method further includes:
[0215] The front end obtains the result of the current user's identity authentication and logs in based on the DID.
[0216] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0217] Before the step of sending a face recognition request to the digital wallet from the front end of the application and obtaining the first facial feature of the current user captured by the camera, the method further includes:
[0218] The front-end obtains the session identifier and application login address from the back-end based on the DID login request initiated by the current user, and uses them to authorize the DID login initiated by the current user through the digital wallet.
[0219] In one embodiment, the first facial feature is captured by the camera and sent to the front end by the digital wallet.
[0220] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0221] The digital wallet receives a facial recognition request from the application's front end;
[0222] The digital wallet sends the current user's second facial features and first message digest.
[0223] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0224] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0225] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. An identity authentication method, characterized in that, Applied to applications, including: The application's front end sends a face recognition request to the digital wallet and obtains the first facial features of the current user captured by the camera. The front end performs a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet; When the first information digest is the same as the second information digest, the front end compares the first facial feature and the second facial feature; When the similarity between the first facial feature and the second facial feature is not less than a set threshold, the current user's identity authentication is successful. The first facial feature is generated when the digital wallet receives a facial recognition request from the application's front end, calls the camera to capture and photograph the current user's face, extracts facial features from the captured photo, and sends it to the front end.
2. The method according to claim 1, characterized in that, Also includes: The application's backend obtains the current user's DID (decentralized identity identifier) sent by the digital wallet; The backend obtains the corresponding DID document based on the DID; The backend obtains the public key based on the DID document; The backend encrypts a random number based on the public key to obtain the encryption result; The backend sends the encrypted result to the digital wallet.
3. The method according to claim 2, characterized in that, The step of verifying the identity of the current user when the similarity between the first facial feature and the second facial feature is not less than a set threshold includes: If the similarity between the first facial feature and the second facial feature is not less than a set threshold, then the facial recognition matching of the current user is successful. The front end sends the result of the current user's face recognition matching to the digital wallet; The backend receives the plaintext returned by the digital wallet and compares the plaintext with the random number; When the plaintext and the random number are the same, the DID is a valid identity identifier, and the current user's identity authentication is successful.
4. The method according to claim 3, characterized in that, After the step where the DID is a valid identity identifier when the plaintext and the random number are the same, and the current user's identity authentication is successful, the method further includes: The front end obtains the result of the current user's identity authentication and logs in based on the DID.
5. The method according to any one of claims 1 to 4, characterized in that, Before the step of sending a face recognition request to the digital wallet from the front end of the application and obtaining the first facial feature of the current user captured by the camera, the method further includes: The front-end obtains the session identifier and application login address from the back-end based on the DID login request initiated by the current user, and uses them to authorize the DID login initiated by the current user through the digital wallet.
6. An identity authentication method, characterized in that, The authentication method applied to a digital wallet is connected to an application for performing the authentication method according to any one of claims 1-5, wherein the authentication method applied to the digital wallet includes: Receive face recognition requests from the application's front end; Send the current user's second facial features and first information digest.
7. An identity authentication device, characterized in that, include: The first acquisition module is used by the application's front end to send a face recognition request to the digital wallet and acquire the first facial features of the current user captured by the camera. The second acquisition module is used by the front end to perform a hash operation on the second facial feature to obtain the second information digest based on the second facial feature and the first information digest of the current user sent by the digital wallet; The comparison module is used to compare the first facial feature and the second facial feature when the first information digest is the same as the second information digest; The identity authentication module is used to ensure that the current user's identity is authenticated when the similarity between the first facial feature and the second facial feature is not less than a set threshold. The first facial feature is generated when the digital wallet receives a facial recognition request from the application's front end, calls the camera to capture and photograph the current user's face, extracts facial features from the captured photo, and sends it to the front end.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Digital identity verification method, device and equipment and storage medium
CN111277577A
Biometric identity verification and protection software solution
US20210089635A1