An identity authentication method and device, an electronic device, and a storage medium

By obtaining the unique identifier and target identity ID of the communication software through the identity authentication mini-program and binding them using the identity mapping relationship, the problem of not being able to realize the identity authentication of communication accounts and multiple application accounts in the existing technology is solved, and the identity authentication of multiple application accounts is realized.

CN116389140BActive Publication Date: 2026-07-28CSC FINANCIAL CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CSC FINANCIAL CO LTD
Filing Date
2023-04-19
Publication Date
2026-07-28

AI Technical Summary

Technical Problem

Existing technologies cannot authenticate the identity of a communication account and multiple application accounts, making it impossible to verify the user identity represented by multiple application accounts and the user identity represented by a communication account as the same user identity.

Method used

The identity authentication mini-program obtains the unique identifier and target identity ID assigned to the user by the communication software, and binds them using the identity mapping relationship to realize the identity authentication of multiple application accounts corresponding to the communication account.

Benefits of technology

It implements identity authentication for multiple application accounts corresponding to a communication account, ensuring that the user identity represented by the various application accounts of the target enterprise and the user identity represented by the communication account are authenticated as the same user identity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389140B_ABST
    Figure CN116389140B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an identity authentication method and device, electronic equipment and storage medium, and belong to the technical field of computers. The specific implementation scheme is: after the identity authentication applet is started, a specified unique identifier allocated by the communication software to a user with a target communication account is obtained; display to-be-confirmed information; when an instruction representing that the user confirms the to-be-confirmed information is received, a target identity ID is obtained; the target identity ID is bound with the specified unique identifier, and identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account is completed. It can be seen that, through the present scheme, identity authentication of multiple application accounts corresponding to a communication account can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to an authentication method, apparatus, electronic device, and storage medium. Background Technology

[0002] Company staff often add users' communication software accounts, such as WeChat accounts, to provide services. However, sometimes staff are unaware of the user's specific information within the company. Since the user has an application account—an account related to the company's applications—it's typically necessary to bind a unique identifier corresponding to the user's communication account to the application account. This achieves identity authentication of the application account associated with the communication account, verifying that the user identity represented by the application account and the user identity represented by the communication account are the same. Therefore, information about the user's application account within the company can be obtained using the user's communication account. The unique identifier corresponding to the user's communication account is a unique identifier pre-assigned to the user by the communication software, distinguishing the uniqueness of the user's communication account. For example, for WeChat, the WeChat UnionId can serve as the unique identifier.

[0003] In existing technology, after a company employee successfully adds any user's communication account on a communication software, they can send an authentication link to that user's communication account. The user can then open the authentication link and log in to any application account within the company. The corresponding mini-program of the authentication link then binds a unique identifier corresponding to the user's communication account to the application account, thereby achieving identity authentication.

[0004] However, a user may have multiple application accounts across multiple applications from the same company, while a single communication account for a communication software can only be bound to one application account from that company. This leads to the following problems:

[0005] When a user has multiple application accounts from the same enterprise, existing technologies cannot achieve identity authentication for multiple application accounts corresponding to a communication account. In other words, it is impossible to authenticate the user identity represented by multiple application accounts and the user identity represented by the communication account as the same user identity. Summary of the Invention

[0006] The purpose of this application is to provide an identity authentication method, apparatus, electronic device, and storage medium to achieve identity authentication of multiple application accounts corresponding to a communication account. The specific technical solution is as follows:

[0007] Firstly, this application provides an identity authentication method applied to an identity authentication applet running in communication software; the method includes:

[0008] After the identity authentication mini-program is launched, the unique identifier assigned by the communication software to the user with the target communication account is obtained; wherein, the target communication account is the communication account logged into the communication software when the identity authentication mini-program is launched;

[0009] Displaying information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service;

[0010] When an instruction is received indicating that the user confirms the information to be confirmed, the target identity ID is obtained; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise;

[0011] The target identity ID is bound to the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account.

[0012] Optionally, before the step of binding the target identity ID with the specified unique identifier, the method further includes:

[0013] Detect whether the target identity ID is already bound to another specified unique identifier; wherein, the other specified unique identifier is different from the obtained specified unique identifier;

[0014] If so, a verification code is sent to the communication number associated with the target identity ID, and an input interface for the verification code is displayed;

[0015] If the verification code entered in the input interface is found to be correct, the binding between the target identity ID and the other specified unique identifier is released, and the step of binding the target identity ID with the specified unique identifier is executed.

[0016] Optionally, the identity authentication mini-program is launched based on a target mini-program link, and the target mini-program link carries at least the target identity ID;

[0017] When receiving an instruction indicating that the user has confirmed the information to be confirmed, obtaining the target identity ID includes:

[0018] When an instruction is received indicating that the user needs to confirm the information to be confirmed, the target identity ID is obtained by parsing from the target mini-program link;

[0019] The methods for generating the target mini-program link include:

[0020] When the management platform of the target enterprise detects a generation instruction for the target mini-program link, it obtains any application account owned by the user to whom the target mini-program link is to be shared;

[0021] Based on the identity mapping relationship and any of the application accounts, the target identity ID is determined;

[0022] Generate a mini-program link carrying the target identity ID, and obtain the target mini-program link.

[0023] Optionally, obtaining the target identity ID when receiving an instruction indicating that the user has confirmed the information to be confirmed includes:

[0024] When an instruction is received indicating that the user needs to confirm the information to be confirmed, an application account login window for the target enterprise is displayed;

[0025] After detecting that the user has successfully logged in, the target identity ID is determined based on the application account used during login and the identity mapping relationship.

[0026] Optionally, the target identity ID is generated by a management platform or application software related to the target enterprise; wherein, the generation method of the target identity ID includes:

[0027] Based on the identity information provided by the user when registering their account for the first time, a target identity ID corresponding to the identity information is generated;

[0028] The methods for generating the identity mapping relationship include:

[0029] After the user registers any application account for each application software of the target enterprise, the target identity ID corresponding to the identity information provided by the user when registering the application account is obtained, and an identity mapping relationship between the application account and the target identity ID is established.

[0030] Optionally, the identity authentication mini-program is launched based on a target mini-program link, and the target mini-program link carries at least information that provides specified benefits to the user;

[0031] After binding the target identity ID with the specified unique identifier and completing the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account, the method further includes:

[0032] The rights and interests interface displays the specified rights and interests.

[0033] Secondly, this application provides an identity authentication device for use in an identity authentication applet running in communication software; the device includes:

[0034] The first acquisition module is used to acquire, after the identity authentication mini-program is launched, a designated unique identifier assigned by the communication software to a user with a target communication account; wherein, the target communication account is the communication account logged into the communication software when the identity authentication mini-program is launched;

[0035] The first display module is used to display information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service;

[0036] The second acquisition module acquires a target identity ID when it receives an instruction indicating that the user has confirmed the information to be confirmed; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise;

[0037] The authentication module is used to bind the target identity ID with the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account.

[0038] Optionally, prior to the authentication module, the device further includes:

[0039] The first detection module is used to detect whether the target identity ID has been bound to another specified unique identifier; wherein the other specified unique identifier is different from the obtained specified unique identifier;

[0040] If so, a verification code is sent to the communication number associated with the target identity ID, and an input interface for the verification code is displayed;

[0041] The second detection module is used to detect that the verification code entered in the input interface is correct, then unbind the target identity ID from the other specified unique identifier, and perform the step of binding the target identity ID with the specified unique identifier.

[0042] Thirdly, this application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0043] Memory, used to store computer programs;

[0044] The processor, when executing a program stored in memory, implements any of the above authentication methods.

[0045] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the above-described authentication methods.

[0046] Beneficial effects of the embodiments in this application:

[0047] This application provides an identity authentication method. Since the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise, after binding the designated unique identifier assigned by the communication software to the user with the target communication account with the target identity ID, the user identities represented by the user's various application accounts in the target enterprise and the user identities represented by the communication account can all be authenticated as the same user identity. Therefore, the proposed solution can achieve identity authentication of multiple application accounts corresponding to a communication account.

[0048] Of course, implementing any product or method of this application does not necessarily require achieving all of the advantages described above at the same time. Attached Figure Description

[0049] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other embodiments can be obtained based on these drawings.

[0050] Figure 1 A flowchart illustrating an identity authentication method provided in this application embodiment;

[0051] Figure 2 A schematic diagram of the interaction process for implementing an identity authentication method provided in an embodiment of this application;

[0052] Figure 3 A schematic diagram of the interaction process for another identity authentication method provided in an embodiment of this application;

[0053] Figure 4 This is a schematic diagram of the structure of an identity authentication device provided in an embodiment of this application;

[0054] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0055] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art based on this application are within the scope of protection of this application.

[0056] To achieve identity authentication of multiple application accounts corresponding to a communication account, embodiments of this application provide an identity authentication method, apparatus, electronic device, and storage medium.

[0057] The following first describes an identity authentication method provided in an embodiment of this application. This identity authentication method is applied to an identity authentication applet running in communication software. The identity authentication applet running in the communication software is applied to a terminal device; in specific applications, the terminal device can be a mobile phone, tablet computer, desktop computer, etc.; this application does not limit it to this.

[0058] In the technical solution of this application, the acquisition, storage, use, processing, transmission, provision and disclosure of user personal information are all carried out with the user's authorization.

[0059] The identity authentication method provided in this application embodiment may include:

[0060] After the identity authentication mini-program is launched, the unique identifier assigned by the communication software to the user with the target communication account is obtained; wherein, the target communication account is the communication account logged into the communication software when the identity authentication mini-program is launched;

[0061] Displaying information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service;

[0062] When an instruction is received indicating that the user confirms the information to be confirmed, the target identity ID is obtained; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise;

[0063] The target identity ID is bound to the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account.

[0064] In this solution, the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise. Therefore, after binding the unique identifier assigned by the communication software to the user with the target communication account to the target identity ID, the user identities represented by the user's various application accounts within the target enterprise and the user identity represented by this communication account can all be authenticated as the same user identity. Thus, the proposed solution can achieve identity authentication for multiple application accounts corresponding to a communication account.

[0065] The following description, in conjunction with the accompanying drawings, introduces an identity authentication method provided by an embodiment of this application.

[0066] like Figure 1 As shown, the authentication method may include the following steps:

[0067] S101, after the identity authentication applet is launched, obtain the designated unique identifier assigned by the communication software to the user with the target communication account; wherein, the target communication account is the communication account logged into the communication software when the identity authentication applet is launched;

[0068] The communication software can be any software with mini-program functionality and communication capabilities, such as WeChat, Alipay, and Douyin. The designated unique identifier is a unique identifier used by the communication software to identify the user's identity corresponding to any account on the communication software. It should be understood that this identifier is only used to identify the uniqueness of the user's identity corresponding to the account associated with that identifier, and does not involve other accounts of the user on the communication software. When a user has multiple accounts on the same communication software, the communication software will assign a designated unique identifier corresponding to each of the user's communication accounts.

[0069] While most users register for messaging apps using their mobile phone numbers, which serve as login credentials and user identification, this method is insecure and can lead to privacy breaches. Therefore, messaging apps assign unique identifiers to users. For example, WeChat assigns unique identifiers like OpenID and UnionId. OpenID is a secure identifier generated for each user's WeChat account by a public account or mini-program. To protect user privacy and data security, different public accounts or mini-programs generate different OpenIDs for the same WeChat account. These IDs can be stored for user identification upon subsequent logins or linked to the user's existing accounts in third-party applications for identity verification and data interaction. UnionId also identifies users, but unlike OpenID, the same UnionId is assigned to the same WeChat user when logging into multiple mini-programs or public accounts under the same developer. Therefore, using UnionId allows developers of multiple mini-programs or public accounts to easily identify users.

[0070] Both OpenID and UnionId can be used in this solution. However, as a development entity, an enterprise may have multiple mini-programs or official accounts. Therefore, for better user identification, UnionId can be preferred as the designated unique identifier in this application. UnionId is a designated unique identifier assigned to users by the WeChat platform. It is known that other communication software may also have corresponding designated unique identifiers with similar functions to UnionId; their names may differ, but the actual functions are the same. Therefore, this solution does not limit the designated unique identifier; any designated unique identifier assigned by any communication software to a user with an account on that communication software can be used in this application.

[0071] The designated unique identifier can be silently obtained by the identity authentication mini-program because it is only available after the user logs in to the communication software. The privacy policy and terms of service for this identifier during login specify its usage and have been agreed upon by the user. Therefore, silently obtaining the designated unique identifier is compliant. Furthermore, this designated unique identifier has the following characteristics: each mini-program or official account records the designated unique identifier corresponding to any communication software account after login. Subsequent times, when a user opens a mini-program or official account that has been logged in with that communication software account, regardless of whether the user chooses to log in, the logged-in mini-program or official account can obtain the designated unique identifier of that communication software account. As a mini-program, the identity authentication mini-program can obtain the unique identifier of the communication software account itself. Of course, it can also obtain this unique identifier from other mini-programs or official accounts, for example, using APIs. Typically, for a target enterprise, the identity authentication mini-program can obtain the unique identifier of the communication software account from the mini-programs or official accounts under that enterprise and bind it to the user's target identity ID within that enterprise in subsequent steps. Therefore, for each mini-program or official account, the user only needs to grant non-silent authorization upon first login to the communication software account. After the initial authorization, subsequent authorizations can be obtained silently from authorized mini-programs or official accounts regarding the unique identifier of the communication software account. Thus, the solution in this application does not require user intervention when obtaining the unique identifier of the communication software account from authorized mini-programs or official accounts, simplifying the identity authentication process.

[0072] Optionally, before displaying the information to be confirmed, steps A1-A2 are also included;

[0073] Step A1 displays information prompting the user to confirm that the currently logged-in communication software account belongs to them;

[0074] Step A2: After receiving confirmation from the user that the currently logged-in communication software account belongs to the user, the process of displaying the pending confirmation information is executed.

[0075] The authentication method in this application is designed to authenticate the user's current communication software account with the user's multiple application accounts in the target enterprise. Therefore, it is necessary to ensure that the currently logged-in account is the one the user wants to authenticate. Thus, the above method is used to remind the user to confirm, in order to prevent the user from logging in with the wrong communication software account.

[0076] S102, Displaying information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service;

[0077] The privacy policy and terms of service outline how this plan handles the collected user data. With the user's consent, this application plan strictly adheres to the terms of service and privacy policy in its use of user data. This step is also to comply with legal regulations and protect user privacy.

[0078] S103, when receiving an instruction indicating that the user confirms the information to be confirmed, obtain the target identity ID; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise;

[0079] Optionally, the target identity ID is generated by a management platform or application software related to the target enterprise; wherein, the generation method of the target identity ID includes:

[0080] Based on the identity information provided by the user when registering their account for the first time, a target identity ID corresponding to the identity information is generated;

[0081] The methods for generating the identity mapping relationship include:

[0082] After the user registers any application account for each application software of the target enterprise, obtain the target identity ID corresponding to the identity information provided by the user when registering the application account, and establish an identity mapping relationship between the application account and the target identity ID.

[0083] The target enterprise application software all have a registration function. When a user registers for the first time, a target identity ID can be generated based on the identity information provided by the user. The identity information can be information such as ID card information and passport information used to represent the uniqueness of a natural person's identity. It can be seen that the management platform or application software under the same enterprise can connect to the database storing the enterprise's user information. Therefore, the enterprise can store the target identity ID generated when a user registers for the first time in the database as a unique identifier of the user's identity within the company.

[0084] By establishing an identity mapping relationship between the target identity ID and all of the user's application accounts within the enterprise, the complex account system of the enterprise can be resolved. Regardless of how many application software the enterprise has or how many application accounts the user has with the enterprise, the target identity ID can be used to identify the user's identity.

[0085] When a user registers an account on any application software of the company for the first time, upon subsequent registrations, the company's management platform or application software will obtain the user's target identity ID using the identity information provided by the user. After the account registration is completed, the company's management platform or application software will automatically establish an identity mapping relationship between the newly registered account and the user's target identity ID. Therefore, each user only needs one target identity ID within the same company to authenticate multiple application accounts of that company. In other words, it can be definitively determined that multiple accounts belong to the same user.

[0086] In this solution, different methods are used to obtain the target identity ID in different scenarios.

[0087] Optionally, when the user's specific identity information is unknown, upon receiving an instruction indicating that the user confirms the information to be confirmed, an application account login window for the target enterprise can be displayed.

[0088] After detecting that the user has successfully logged in, the target identity ID is determined based on the application account used during login and the identity mapping relationship.

[0089] When the target company does not know the user's specific identity information, or when the user actively performs identity authentication, the user needs to manually log in to the account, thereby using the user's logged-in account information to determine the target identity ID.

[0090] When the user's specific identity information is known, the target identity ID can optionally be determined through the known user identity information. The specific implementation method will be described in detail in the following embodiments and will not be repeated here.

[0091] Optionally, before the step of binding the target identity ID with the specified unique identifier, the method further includes steps B1-B3;

[0092] Step B1: Detect whether the target identity ID has been bound to another specified unique identifier; wherein, the other specified unique identifier is different from the obtained specified unique identifier;

[0093] Step B2: If yes, send a verification code to the communication number associated with the target identity ID and display an input interface for the verification code;

[0094] Step B3: If the verification code entered in the input interface is correct, the binding between the target identity ID and the other specified unique identifier is released, and the step of binding the target identity ID with the specified unique identifier is executed.

[0095] To ensure user privacy and data security, a user's target identity ID is bound to only one unique identifier for that user's account within the same communication software across all enterprises. When a user needs to use their currently logged-in communication software account for authentication across multiple application accounts, if it is discovered that the user's target identity ID is bound to other communication accounts within the same software, then the solution described in this embodiment must be implemented to unbind the target identity ID from the other unique identifiers. Only after unbinding can the step of binding the target identity ID to the unique identifier be performed.

[0096] Furthermore, in this scheme, the target identity ID being bound to other designated unique identifiers means that the target identity ID is bound to the designated unique identifiers of other accounts of the same user in the same communication software. When the target identity ID is bound to designated unique identifiers of different communication software, it will not affect this scheme and there is no need to unbind it.

[0097] S104, bind the target identity ID with the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account.

[0098] Since the target identity ID has an identity mapping relationship with the user's various application accounts in the target enterprise, binding the target identity ID with the specified unique identifier can authenticate the user identity represented by the target user's various application accounts in the target enterprise and the user identity represented by the communication account as the same user identity. Thus, the identity authentication of the user's multiple application accounts in the target enterprise corresponding to the user's communication account can be realized.

[0099] Furthermore, corresponding to the content of the designated unique identifier of the communication software account obtained from other mini-programs or public accounts besides the identity authentication mini-program introduced in S101, after the identity authentication mini-program binds the designated unique identifier with the user's target identity ID in the target enterprise, it can not only realize the identity authentication of the user's multiple application accounts in the target enterprise corresponding to the user's communication account, but also further realize the user identity of the user in other mini-programs or public accounts under the communication account and the user's multiple application accounts in the target enterprise. That is, it authenticates the user identity represented by the multiple application accounts of the target enterprise and the user identity of the user in other mini-programs or public accounts under the target communication account as the same user identity.

[0100] As can be seen, in this scheme, the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise. Therefore, after binding the unique identifier assigned by the communication software to the user with the target communication account with the target identity ID, the user identities represented by the user's various application accounts within the target enterprise and the user identity represented by this communication account can all be authenticated as the same user identity. Thus, the proposed scheme can achieve identity authentication for multiple application accounts corresponding to a communication account.

[0101] Optionally, the identity authentication mini-program is launched based on the target mini-program link.

[0102] Due to the convenience of communication software, users or staff can share target mini-programs using target mini-program links. These links can not only open the target mini-program but also carry information. Of course, the information can be displayed directly or hidden.

[0103] In one implementation, the target mini-program link carries at least the target identity ID;

[0104] When the target mini-program link carries the target identity ID, it can be hidden and not displayed in plaintext. For security reasons, the target identity ID information can also be encrypted. When the target identity ID needs to be obtained in subsequent steps, it can be obtained by a predetermined method, such as decryption.

[0105] At this time, the step of obtaining the target identity ID when receiving an instruction representing the user's confirmation of the information to be confirmed includes:

[0106] When an instruction is received indicating that the user needs to confirm the information to be confirmed, the target identity ID is obtained by parsing from the target mini-program link.

[0107] In one implementation, the target mini-program link carries at least information that provides specified benefits to the user;

[0108] Target mini-programs can not only provide identity verification functions, but also offer users certain benefits. For example, a securities company's target mini-program can provide users with benefits such as user manager services. Users may not be aware that the target mini-program has these functions, so the target mini-program link can display some useful information for users to read. For example, the target mini-program can display the benefits of user manager services after authentication, so that users know about them.

[0109] At this point, after binding the target identity ID with the specified unique identifier and completing the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account, the method further includes:

[0110] The rights and interests interface displays the specified rights and interests.

[0111] After a user completes authentication, the company can provide the user with benefits, such as user manager services and discounts on company products. These benefits can be displayed on the benefits interface for the user to choose from.

[0112] The methods for generating the target mini-program link include:

[0113] When the management platform of the target enterprise detects a generation instruction for the target mini-program link, it obtains any application account owned by the user to whom the target mini-program link is to be shared;

[0114] Based on the identity mapping relationship and any of the application accounts, the target identity ID is determined;

[0115] Generate a mini-program link carrying the target identity ID, and obtain the target mini-program link.

[0116] The target company's management platform can receive instructions from staff and complete the operations represented by those instructions. For example, if a staff member wants to generate a target mini-program link for user A, then, knowing user A's identity, the target company's management platform, upon receiving the instruction, can generate a mini-program link carrying user A's target identity ID based on any of user A's application accounts (a, b, c, and d) within the target company, and according to the identity mapping relationship between that application account and user A's target identity ID. Furthermore, any user who actively wants to authenticate can proactively trigger the target company's management platform to generate a target mini-program link carrying that user's target identity ID.

[0117] If staff do not know the user's specific identity, they can issue an instruction to generate a non-targeted mini-program link. Any user can use this link to authenticate their identity. However, in this scenario, the target identity ID is obtained in the way that requires the user to log in to the application account, as described in the above embodiment.

[0118] This embodiment introduces the generation method of target mini-program links for different scenarios and different users, as well as the method of obtaining the target identity ID for different scenarios and different users. Therefore, identity authentication can be performed for different scenarios and different users. Thus, this solution is applicable to many scenarios and has wide practicality.

[0119] To better understand this solution, the following examples illustrate the identity authentication method through two different scenarios of user interaction with the identity authentication mini-program.

[0120] In the specific embodiments described below, the target enterprise is a securities company, the communication software is WeChat, and the scenarios are applicable to account opening processes, sending identity verification mini-program links to users via SMS / application software, etc. Specifically, in the account opening process scenario, the account opening page can display a pop-up window guiding the user to add a user manager or claim benefits. If the user is opening an account for the first time, the account opening steps are the same as those in the above embodiments where the user provides identity information during initial account registration, generating a target identity ID corresponding to that identity information. A target identity ID corresponding to the user will be generated. After account opening is completed, a target mini-program link can be sent to the user. At this time, the securities company's staff, the securities company's management platform, or the application software will know the user's target identity ID.

[0121] It can be known that when securities company staff, the securities company's management platform, or application software send an identity verification mini-program link to a user via SMS, they already know the user's mobile phone number. Therefore, the securities company staff, the securities company's management platform, or application software already know the target user's target identity ID.

[0122] When a securities company sends an identity verification mini-program link to a user through its application software, since the user has already logged into the securities company's application software account, the securities company's staff, management platform, or application software can determine the user's target identity ID based on the identity mapping relationship between the user's logged-in securities company application software account and the target identity ID.

[0123] Therefore, in the above three scenarios, the securities company knows the target user's target identity ID before identity authentication, and can send the target user a target identity authentication mini-program link that carries at least the target identity ID to perform identity authentication.

[0124] like Figure 2 As shown, from the perspective of user interaction with securities company staff, management platforms or applications, and identity verification mini-programs, the identity authentication process may include the following steps:

[0125] S201, Securities company staff, management platforms, or application software obtain user identification mini-program links.

[0126] Since the user's target identity ID is already known in this embodiment, the identity authentication mini-program link carrying the target identity ID is generated using the same method described in the previous embodiment. After generating the identity authentication mini-program link carrying the target identity ID, the securities company's staff, management platform, or application software can obtain the mini-program link carrying the target identity ID. Therefore, the securities company's staff, management platform, or application software can send the identity authentication mini-program link carrying the target identity ID to the user corresponding to the target identity ID via WeChat, SMS, or in-app distribution.

[0127] S202, the user obtains the short link.

[0128] The short link mentioned is an identity authentication mini-program link carrying the target identity ID. After the identity authentication mini-program link carrying the target identity ID is generated, the securities company can send it to the user corresponding to the target identity ID in various ways. For example, if the user is already a WeChat friend, the identity authentication mini-program link can be sent through WeChat Work. Mini-programs in communication software are highly open; therefore, the mini-program link can be opened not only when using the communication software, but also quickly in most other scenarios. Therefore, when a user uses the securities company's application, the identity authentication mini-program link can be pushed to the user on the application page. The user can open the identity authentication mini-program through this link, or the user can open the identity authentication mini-program link sent via SMS. There are multiple ways for users to obtain the mini-program link, and this application does not limit this.

[0129] S203: When a user clicks the button, the mini-program is launched.

[0130] After obtaining the identity verification mini-program link, users can open the mini-program by clicking the button, which is essentially clicking the identity verification mini-program link. S201-S203 serve as preparatory steps before identity verification.

[0131] After a user opens the mini-program, the mini-program will silently execute the step of obtaining the unique identifier assigned by the communication software to the user with the target communication account after the identity authentication mini-program is launched. Here, the WeChat UnionId will be silently obtained, which is the unique identifier.

[0132] S204, User confirms if the current WeChat account belongs to the user.

[0133] This step corresponds to steps A1-A2 above, and is to prevent users from logging in to their WeChat accounts incorrectly.

[0134] S205, the identity verification mini-program confirms whether the current WeChat account has been verified.

[0135] After the user confirms that the current WeChat account belongs to them, the identity verification mini-program checks whether the current WeChat account has already been verified with the user's target identity ID at the securities company. Since the purpose of this solution is to verify the current WeChat account with the user's target identity ID at the target securities company, if it has been verified, no further verification is needed, and the user can be directly redirected to the mini-program's personal information page. On this page, the user can see their account information and use the rights and services provided by the user. If it has not been verified, proceed to step S206.

[0136] S206, Users confirm their personal information and check the privacy agreement and terms of service.

[0137] Corresponding to S102-S103 above, in order to protect user privacy and ensure the compliance of this solution, after the user confirms personal information and checks the privacy agreement and terms of service, the identity authentication mini-program will obtain the user's target identity ID. Because the identity authentication mini-program link in this embodiment carries the target identity ID, the identity authentication mini-program can directly obtain the user's target identity ID by parsing the identity authentication mini-program link.

[0138] S207, the identity authentication mini-program confirms whether the target identity ID has been authenticated.

[0139] Corresponding to steps B1-B3 in the above embodiments, if the user's target identity ID has not been authenticated, it is directly bound to the WeChat UnionId of the current WeChat account to achieve identity authentication. If the user's target identity ID has already been authenticated, the identity authentication mini-program automatically executes the re-authentication process, or the identity authentication mini-program provides the user with an option to choose whether to re-authenticate. When the user confirms to re-authenticate, the identity authentication mini-program executes the re-authentication process. The re-authentication process includes: unbinding the user's target identity ID from the WeChat UnionId of other WeChat accounts bound to the target identity ID; after unbinding, the user's target identity ID is then bound to the WeChat UnionId of the current WeChat account to achieve identity authentication. The specific implementation method of the re-authentication process is the same as steps B1-B3 in the above embodiments, and will not be elaborated here.

[0140] S208, authentication successful. The user can add the account manager's WeChat account to claim benefits.

[0141] After successful identity authentication, the user can be provided with benefits in the manner described in the above embodiment, which displays the specified benefits interface. The benefits interface can provide the account manager's WeChat ID, and the user can enjoy the account manager's services by adding the account manager's WeChat. The interface also includes other benefits, such as coupons, which the user can click on the corresponding module to claim.

[0142] In the specific embodiments described below, the target securities company is a securities company, and the communication software is WeChat. This is applicable to scenarios where securities companies reach users through WeChat one-on-one chats / group chats / Moments, etc., and guide users to complete identity verification through operational activities. In this scenario, the staff of the securities company do not know the user's identity information at the target securities company.

[0143] like Figure 3 As shown, from the perspective of user interaction with securities company staff and the identity verification mini-program, the identity authentication process can include the following steps:

[0144] S301, the user obtains the identity authentication mini-program link.

[0145] The method for generating the identity verification mini-program link is the same as in the above embodiments. It can be generated using the target securities company's management platform. In this embodiment, the user's identity is unknown, so the method used in the above embodiments to generate a non-targeted mini-program link is employed to generate the identity verification mini-program link. Users can open the identity verification mini-program through links displayed in staff members' WeChat Moments or links sent by staff members via WeChat / SMS. Because the mini-program link in this embodiment is non-targeted, any user can open the identity verification mini-program and perform identity verification by clicking the link in any scenario.

[0146] S302, the user confirms whether the current WeChat account belongs to the user.

[0147] The same as S204 in the above embodiment will not be repeated here.

[0148] S303, the identity verification mini-program confirms whether the current WeChat account has been verified.

[0149] The same as S205 in the above embodiment will not be repeated here.

[0150] S304, the user checks the privacy agreement and terms of service, and logs in with their securities account and password.

[0151] The steps for users to check the privacy agreement and terms of service correspond to S102-S103 above, in order to protect user privacy and ensure the compliance of this solution. The login process for the securities account and password is the same as the scheme for obtaining the target identity ID when the user's specific identity information is unknown, as described in the previous embodiment. The purpose is to allow users to log in to any securities account, which is the application account of the target securities company. The identity authentication mini-program then obtains the user's target identity ID based on the identity mapping relationship between the securities account and the user's target identity ID within that securities company.

[0152] S305, the identity authentication mini-program confirms whether the user has completed the login.

[0153] After a user logs in, the system can obtain the user's target identity ID based on the identity mapping relationship between the user's securities account and the target identity ID at the securities company. After confirming that the user has logged in and obtaining the user's target identity ID, step S306 is executed.

[0154] S306, the identity authentication mini-program confirms whether the target identity ID has been authenticated.

[0155] The same as S207 in the above embodiment will not be repeated here.

[0156] S307, the identity verification mini-program has completed the verification.

[0157] S308 users can claim their benefits and continue participating in the activity.

[0158] S306-S308 correspond to S207-S208 in the above embodiments, and the steps are similar, so they will not be described in detail here.

[0159] The two embodiments described above introduce two different schemes for identity authentication in two different scenarios: when the user's identity is known and when the user's identity is unknown. Therefore, this scheme has strong applicability.

[0160] Furthermore, both of the above-mentioned solutions, through certain process and technical optimizations, can increase user participation in authentication by providing users with benefits and reduce their psychological resistance to logging into their securities accounts in unfamiliar environments, effectively improving the user authentication rate. In these solutions, when the user's identity is known, in most scenarios only a one-click operation is required, without the need for account login or other operations, resulting in a superior user experience.

[0161] Furthermore, this embodiment uses WeChat UnionId, which has the characteristic that when logging into multiple mini-programs or official accounts under the same development entity, the assigned UnionId is the same. When the securities company is the development entity, the WeChat UnionId is bound to the user's target identity ID. Therefore, multiple mini-programs and official accounts under the development entity are also bound to the user's target identity ID. Thus, through a single binding, not only is identity authentication achieved for multiple application accounts corresponding to the communication account, but also identity authentication is achieved for multiple mini-programs and official accounts of the same securities company corresponding to the communication account. In other words, it is possible to authenticate the user's multiple securities company application accounts and the user's multiple mini-programs and official accounts of the same securities company corresponding to the user's communication account as the same user identity.

[0162] Based on the above embodiments of the identity authentication method, this disclosure also provides an identity authentication device. Figure 4 This is a schematic diagram of the structure of an identity authentication device provided in an embodiment of this disclosure, as shown below. Figure 4 As shown, the identity authentication device may include:

[0163] The first acquisition module 401 is used to acquire, after the identity authentication applet is launched, a designated unique identifier assigned by the communication software to a user with a target communication account; wherein, the target communication account is the communication account logged into the communication software when the identity authentication applet is launched.

[0164] The first display module 402 is used to display information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service;

[0165] The second acquisition module 403 is used to acquire a target identity ID when it receives an instruction indicating that the user has confirmed the information to be confirmed; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise;

[0166] The authentication module 404 is used to bind the target identity ID with the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account.

[0167] In this solution, the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise. Therefore, after binding the unique identifier assigned by the communication software to the user with the target communication account to the target identity ID, the user identities represented by the user's various application accounts within the target enterprise and the user identity represented by this communication account can all be authenticated as the same user identity. Thus, the proposed solution can achieve identity authentication for multiple application accounts corresponding to a communication account.

[0168] Optionally, prior to the authentication module, the device further includes:

[0169] The first detection module detects whether the target identity ID has been bound to another specified unique identifier; wherein, the other specified unique identifier is different from the obtained specified unique identifier;

[0170] If so, a verification code is sent to the communication number associated with the target identity ID, and an input interface for the verification code is displayed;

[0171] The second detection module is used to detect that the verification code entered in the input interface is correct, then unbind the target identity ID from the other specified unique identifier, and perform the step of binding the target identity ID with the specified unique identifier.

[0172] Optionally, the identity authentication mini-program is launched based on a target mini-program link, and the target mini-program link carries at least the target identity ID;

[0173] The second acquisition module includes:

[0174] The parsing unit is used to parse the target identity ID from the target mini-program link when it receives an instruction representing the user's confirmation of the information to be confirmed;

[0175] The methods for generating the target mini-program link include:

[0176] When the management platform of the target enterprise detects a generation instruction for the target mini-program link, it obtains any application account owned by the user to whom the target mini-program link is to be shared;

[0177] Based on the identity mapping relationship and any of the application accounts, the target identity ID is determined;

[0178] Generate a mini-program link carrying the target identity ID, and obtain the target mini-program link.

[0179] Optionally, the second acquisition module includes:

[0180] The display unit is used to display an application account login window for the target enterprise when it receives an instruction indicating that the user has confirmed the information to be confirmed.

[0181] The detection unit is used to determine the target identity ID based on the application account used during login and the identity mapping relationship after detecting that the user has successfully logged in.

[0182] Optionally, the target identity ID is generated by a management platform or application software related to the target enterprise; wherein, the generation method of the target identity ID includes:

[0183] Based on the identity information provided by the user when registering their account for the first time, a target identity ID corresponding to the identity information is generated;

[0184] The methods for generating the identity mapping relationship include:

[0185] After the user registers any application account for each application software of the target enterprise, the target identity ID corresponding to the identity information provided by the user when registering the application account is obtained, and an identity mapping relationship between the application account and the target identity ID is established.

[0186] Optionally, the identity authentication mini-program is launched based on a target mini-program link, and the target mini-program link carries at least information that provides specified benefits to the user;

[0187] Following the authentication module, the device further includes:

[0188] The second display module is used to display the rights interface of the specified rights.

[0189] This application also provides an electronic device, such as... Figure 5 As shown, it includes a processor 501, a communication interface 502, a memory 503, and a communication bus 504, wherein the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504.

[0190] Memory 503 is used to store computer programs;

[0191] The processor 501, when executing the program stored in the memory 503, implements any of the aforementioned authentication methods.

[0192] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0193] The communication interface is used for communication between the aforementioned electronic devices and other devices.

[0194] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0195] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0196] In another embodiment provided in this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements the steps of any of the above-described authentication methods.

[0197] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to perform any of the authentication methods described above.

[0198] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).

[0199] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0200] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. The above descriptions are merely preferred embodiments of this application and are not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the scope of protection of this application.

Claims

1. An identity authentication method, characterized by, An identity authentication applet applied to communication software; the method includes: After the identity authentication mini-program is launched, the unique identifier assigned by the communication software to the user with the target communication account is obtained; wherein, the target communication account is the communication account logged into the communication software when the identity authentication mini-program is launched; the unique identifier is the identifier in the communication software used to identify the unique identity of the user corresponding to the target communication account. Displaying information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service; When an instruction is received indicating that the user confirms the information to be confirmed, the target identity ID is obtained; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise; Bind the target identity ID to the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account; The target identity ID is generated by the management platform or application software of the target enterprise; wherein, the generation method of the target identity ID includes: Based on the identity information provided by the user when registering their account for the first time, a target identity ID corresponding to the identity information is generated; The methods for generating the identity mapping relationship include: After the user registers any application account for each application software of the target enterprise, the target identity ID corresponding to the identity information provided by the user when registering the application account is obtained, and an identity mapping relationship between the application account and the target identity ID is established.

2. The method of claim 1, wherein, Before the step of binding the target identity ID with the specified unique identifier, the method further includes: Detect whether the target identity ID is already bound to another specified unique identifier; wherein, the other specified unique identifier is different from the obtained specified unique identifier; If so, a verification code is sent to the communication number associated with the target identity ID, and an input interface for the verification code is displayed; If the verification code entered in the input interface is found to be correct, the binding between the target identity ID and the other specified unique identifier is released, and the step of binding the target identity ID with the specified unique identifier is executed.

3. The method of claim 1, wherein, The identity authentication mini-program is launched based on the target mini-program link, and the target mini-program link carries at least the target identity ID; When receiving an instruction indicating that the user has confirmed the information to be confirmed, obtaining the target identity ID includes: When an instruction is received indicating that the user needs to confirm the information to be confirmed, the target identity ID is obtained by parsing from the target mini-program link; The methods for generating the target mini-program link include: When the management platform of the target enterprise detects a generation instruction for the target mini-program link, it obtains any application account owned by the user to whom the target mini-program link is to be shared; Based on the identity mapping relationship and any of the application accounts, the target identity ID is determined; Generate a mini-program link carrying the target identity ID, and obtain the target mini-program link.

4. The method according to claim 1, characterized in that, When receiving an instruction indicating that the user has confirmed the information to be confirmed, obtaining the target identity ID includes: When an instruction is received indicating that the user needs to confirm the information to be confirmed, an application account login window for the target enterprise is displayed; After detecting that the user has successfully logged in, the target identity ID is determined based on the application account used during login and the identity mapping relationship.

5. The method according to claim 1, characterized in that, The identity authentication mini-program is launched based on a target mini-program link, and the target mini-program link carries at least information that provides specified benefits to the user; After binding the target identity ID with the specified unique identifier and completing the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account, the method further includes: The rights and interests interface displays the specified rights and interests.

6. An identity authentication device, characterized in that, An identity authentication applet applied to communication software; the device includes: The first acquisition module is used to acquire, after the identity authentication mini-program is launched, a designated unique identifier assigned by the communication software to a user with a target communication account; wherein, the target communication account is the communication account logged into the communication software when the identity authentication mini-program is launched; and the designated unique identifier is a unique identifier in the communication software used to identify the user identity corresponding to the target communication account. The first display module is used to display information to be confirmed; wherein, the information to be confirmed includes privacy agreement information and terms of service; The second acquisition module acquires a target identity ID when it receives an instruction indicating that the user has confirmed the information to be confirmed; wherein, the target identity ID is the user's unique identity identifier for the target enterprise, and the target identity ID has an identity mapping relationship with each of the user's application accounts related to the target enterprise; The authentication module is used to bind the target identity ID with the specified unique identifier to complete the identity authentication of each application account belonging to the identity mapping relationship corresponding to the communication account; The target identity ID is generated by the management platform or application software of the target enterprise; wherein, the generation method of the target identity ID includes: Based on the identity information provided by the user when registering their account for the first time, a target identity ID corresponding to the identity information is generated; The methods for generating the identity mapping relationship include: After the user registers any application account for each application software of the target enterprise, the target identity ID corresponding to the identity information provided by the user when registering the application account is obtained, and an identity mapping relationship between the application account and the target identity ID is established.

7. The apparatus according to claim 6, characterized in that, Prior to the authentication module, the device further includes: The first detection module is used to detect whether the target identity ID has been bound to another specified unique identifier; wherein, the other specified unique identifier is different from the obtained specified unique identifier; If so, a verification code is sent to the communication number associated with the target identity ID, and an input interface for the verification code is displayed; The second detection module is used to detect that the verification code entered in the input interface is correct, then unbind the target identity ID from the other specified unique identifier, and perform the step of binding the target identity ID with the specified unique identifier.

8. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the method described in any one of claims 1-5.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method described in any one of claims 1-5.