Object identity authentication method and device based on target application, and storage medium

The identity verification method, which uses a near-field communication module and multi-party system verification, solves the problem that biometric technology is easily forged and achieves higher accuracy in identity verification.

CN117150458BActive Publication Date: 2026-08-04GUANGZHOU TENCENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGZHOU TENCENT TECH CO LTD
Filing Date
2022-05-23
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

Existing biometric technologies are easily forged, affecting the accuracy of identity verification.

Method used

The document is detected by activating the near-field communication module of the terminal device, the encrypted information of the document is obtained, and the legality of the identity information is confirmed by multiple verifications through the confidence decoding system and the document query service system.

Benefits of technology

This effectively prevents the falsification of identity information and improves the accuracy of identity verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117150458B_ABST
    Figure CN117150458B_ABST
Patent Text Reader

Abstract

The application discloses a target application-based object identity authentication method and device and a storage medium, and can be applied to the field of maps. A near field communication module is used for certificate detection; then, certificate encrypted information detected by the near field communication module is sent to a belief decoding system to obtain identity information; identity information sent by a certificate query service system is received; and then, the identity information is compared with registered information corresponding to a target object in a service background corresponding to a target application, so that an identity authentication result is determined. Thus, a target application-based object identity authentication process is realized. Since the near field communication is used for belief certificate detection, and the identity information is verified through multiple systems, the generation of false identity information can be effectively avoided, and the accuracy of identity authentication is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to object identity authentication methods, apparatus, and storage media based on target applications. Background Technology

[0002] With the rapid development of internet technology, people have increasingly higher requirements for identity verification. For example, identity verification can be used in games to prevent minors from becoming addicted.

[0003] Generally, biometric technology is used to obtain the target's identity information (such as face or fingerprint), and then compared with the identity information of the target's registered account to check the consistency between the two in order to identify the true identity of the target.

[0004] However, identity information obtained through biometrics is easily forged, and forged identity information can easily pass identity verification, affecting the accuracy of identity verification. Summary of the Invention

[0005] In view of this, this application provides an object identity authentication method based on the target application, which can effectively improve the accuracy of identity authentication.

[0006] The first aspect of this application provides a target application-based object identity authentication method, which can be applied to a system or program in a terminal device that includes target application-based object identity authentication functionality, specifically including:

[0007] In response to the initiation of the identity authentication process for the target object in the target application, the near-field communication module of the terminal device is activated to perform document detection;

[0008] Obtain the encrypted document information detected by the near-field communication module;

[0009] The encrypted document information is sent to the confidence decoding system, so that the confidence decoding system generates a decryption receipt in response to the encrypted document information. The decryption receipt is used to trigger the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain the identity information. The identity information is obtained by sending a query request containing the decryption receipt to the confidence decoding system through the document query service system.

[0010] Receive the identity information sent by the document inquiry service system;

[0011] The identity information is compared with the registration information corresponding to the target object in the service backend of the target application to determine the identity authentication result.

[0012] Optionally, in some possible implementations of this application, the step of waking up the near-field communication module of the terminal device to perform document detection in response to the initiation of the identity authentication process for the target object in the target application includes:

[0013] In response to the initiation of the identity authentication process for the target object in the target application, the hardware environment corresponding to the target application is detected through the near-field module detection interface;

[0014] If the hardware environment supports near-field communication, then the startup status of the near-field communication module is detected;

[0015] If the activation status of the near-field communication module indicates that the near-field communication module is enabled, then the near-field communication module is set to card reader mode to activate the near-field communication module for document detection.

[0016] Optionally, in some possible implementations of this application, the method further includes:

[0017] If the activation status of the near-field communication module indicates that the near-field communication module is not enabled, an activation reminder will be sent via system broadcast.

[0018] If the near-field communication module is not activated, the system will enter the switch configuration page for the near-field communication module to enable it.

[0019] Optionally, in some possible implementations of this application, the step of responding to the initiation of the identity authentication process for the target object in the target application and detecting the hardware environment corresponding to the target application through the near-field module detection interface includes:

[0020] Obtain the login information entered by the target object in the target application;

[0021] The login information is uploaded to the verification backend of the target application to verify the login information.

[0022] If the login verification is successful, the identity authentication process for the target object will be initiated.

[0023] The hardware environment corresponding to the target application is detected through the near-field module detection interface.

[0024] Optionally, in some possible implementations of this application, the step of detecting the hardware environment corresponding to the target application through the near-field module detection interface includes:

[0025] The time information when the target object inputs the login information is determined based on the running process corresponding to the target application;

[0026] Obtain the identification time period set for the target object;

[0027] The time information is compared with the identification time period;

[0028] If the time indicated by the time information is within the identification period, the hardware environment corresponding to the target application is detected through the near-field module detection interface.

[0029] Optionally, in some possible implementations of this application, obtaining the identification time period set for the target object includes:

[0030] Determine the date information corresponding to the time information;

[0031] Based on the date information, a preset date comparison is performed to determine the idle status corresponding to the date information;

[0032] The identification period set for the target object is obtained based on the idle state.

[0033] Optionally, in some possible implementations of this application, obtaining the document encryption information detected by the near-field communication module includes:

[0034] In response to the near-field communication module detecting the proximity of the detected object, a connection is established between the near-field communication module and the object tag corresponding to the detected object;

[0035] Read the tag data contained within the object tag;

[0036] The tag data is packaged into near-field communication events to distribute the near-field communication events to the event detector;

[0037] The object type of the detected object is determined by the event detector;

[0038] If the object type is a preset type, the target data segment in the tag data is parsed to obtain the document encryption information.

[0039] Optionally, in some possible implementations of this application, if the object type is a preset type, then parsing the target data segment in the tag data to obtain the document encryption information includes:

[0040] If the object type is a preset type, then determine the data record sequence corresponding to the tag data;

[0041] The data record sequence is parsed to determine the identifier data segment and the target data segment;

[0042] The payload information in the target data segment is parsed to obtain the document encryption information.

[0043] Optionally, in some possible implementations of this application, sending the encrypted document information to the trust decoding system, so that the trust decoding system generates a decryption receipt in response to the encrypted document information, includes:

[0044] The encrypted information of the document is packaged into a decoding request;

[0045] The decoding request is sent to the confidence decoding system so that the confidence decoding system can verify the decoding request;

[0046] If the verification passes, the confidence decoding system generates the decryption receipt based on the encrypted information of the document;

[0047] The receipt of the identity information sent by the document inquiry service system includes:

[0048] Obtain the decryption receipt returned by the confidence decoding system;

[0049] The decryption receipt is sent to the service backend corresponding to the target application, so that the service backend corresponding to the target application forwards the decryption receipt to the document query service system.

[0050] The document inquiry service system performs legality verification based on the decryption receipt;

[0051] If the legality verification passes, the decryption receipt is forwarded to the confidence decoding system for information decoding to obtain the identity information;

[0052] Receive the identity information sent by the document inquiry service system.

[0053] Optionally, in some possible implementations of this application, the step of verifying the identity information against the registration information corresponding to the target object in the service backend of the target application includes:

[0054] In response to the acquisition of the identity information, a verification page is opened in the target application;

[0055] Based on the identity information, key information used to indicate the target object is determined;

[0056] The key information is encrypted and transmitted to the service backend corresponding to the target application through the verification page, so that the key information and the registration information corresponding to the target object are identified in the service backend corresponding to the target application;

[0057] The step of outputting the identity verification result corresponding to the target object to the target application includes:

[0058] Receive the identity authentication result of the target object from the service backend corresponding to the target application.

[0059] Optionally, in some possible implementations of this application, the method further includes:

[0060] Determine the identity identifier corresponding to the target object based on the identity authentication results;

[0061] Bind the identity identifier to the target object;

[0062] The identity identifier is broadcast so that the associated application receives the binding relationship between the identity identifier and the target object;

[0063] In response to the target object triggering the associated application, the target object's identity is authenticated based on the identity identifier.

[0064] Optionally, in some possible implementations of this application, broadcasting the identity identifier so that the associated application receives the binding relationship between the identity identifier and the target object includes:

[0065] The description information corresponding to the target application is parsed to determine the application type corresponding to the application managed by the target application;

[0066] The application traversal is performed based on the application type to determine the associated application;

[0067] The identity identifier is broadcast so that the associated application receives the binding relationship between the identity identifier and the target object.

[0068] A second aspect of this application provides an object identity authentication device based on a target application, comprising:

[0069] The acquisition unit is used to respond to the initiation of the identity authentication process for the target object in the target application and to wake up the near-field communication module of the terminal device to perform document detection;

[0070] The acquisition unit is also used to acquire the document encryption information detected by the near-field communication module;

[0071] The sending unit is used to send the encrypted document information to the trust decoding system, so that the trust decoding system generates a decryption receipt in response to the encrypted document information. The decryption receipt is used to trigger the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain identity information. The identity information is obtained by sending a query request containing the decryption receipt to the trust decoding system through the document query service system.

[0072] A receiving unit is configured to receive the identity information sent by the document inquiry service system;

[0073] An authentication unit is used to authenticate the identity information against the registration information corresponding to the target object in the service backend of the target application.

[0074] The acquisition unit is also used to output the identity authentication result corresponding to the target object to the target application.

[0075] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface in response to the initiation of the identity authentication process for the target object in the target application.

[0076] The acquisition unit is specifically used to detect the startup status of the near-field communication module if the hardware environment supports near-field communication.

[0077] The acquisition unit is specifically used to set the near-field communication module to card reader mode if the startup status of the near-field communication module indicates that the near-field communication module is turned on, so as to wake up the near-field communication module to perform document detection.

[0078] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to send an activation reminder via system broadcast if the activation status of the near-field communication module indicates that the near-field communication module is not activated;

[0079] The acquisition unit is specifically used to enter the switch configuration page for the near-field communication module if the near-field communication module is not activated, so as to enable the near-field communication module.

[0080] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to acquire the login information entered by the target object in the target application;

[0081] The acquisition unit is specifically used to upload the login information to the verification backend of the target application to perform login verification on the login information;

[0082] The acquisition unit is specifically used to initiate an identity authentication process for the target object if the login verification is successful.

[0083] The acquisition unit is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface.

[0084] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to determine the time information when the target object inputs the login information based on the running process corresponding to the target application;

[0085] The acquisition unit is specifically used to acquire the identification time period set for the target object;

[0086] The acquisition unit is specifically used to compare the time information with the identification time period;

[0087] The acquisition unit is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface if the time indicated by the time information is within the identification period.

[0088] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to determine the date information corresponding to the time information;

[0089] The acquisition unit is specifically used to perform a preset date comparison based on the date information in order to determine the idle state corresponding to the date information.

[0090] The acquisition unit is specifically used to acquire the identification time period set for the target object based on the idle state.

[0091] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to establish a connection between the near-field communication module and the object tag corresponding to the detected object in response to the near-field communication module detecting the proximity of the detected object;

[0092] The acquisition unit is specifically used to read the tag data contained in the object tag;

[0093] The acquisition unit is specifically used to package the tag data into near-field communication events, so as to distribute the near-field communication events to the event detector;

[0094] The acquisition unit is specifically used to determine the object type of the detected object through the event detector;

[0095] The acquisition unit is specifically used to parse the target data segment in the tag data to obtain the document encryption information if the object type is a preset type.

[0096] Optionally, in some possible implementations of this application, the acquisition unit is specifically used to determine the data record sequence corresponding to the tag data if the object type is a preset type;

[0097] The acquisition unit is specifically used to parse the data record sequence to determine the identifier data segment and the target data segment;

[0098] The acquisition unit is specifically used to parse the load information in the target data segment to obtain the document encryption information.

[0099] Optionally, in some possible implementations of this application, the sending unit is specifically used to package the document encryption information into a decoding request;

[0100] The sending unit is specifically used to send the decoding request to the confidence decoding system so that the confidence decoding system can verify the decoding request;

[0101] The sending unit is specifically used to generate the decryption receipt based on the document encryption information if the verification passes.

[0102] The receiving unit is specifically used to obtain the decryption receipt fed back by the confidence decoding system;

[0103] The receiving unit is specifically used to send the decryption receipt to the service backend corresponding to the target application, so that the service backend corresponding to the target application forwards the decryption receipt to the document query service system.

[0104] The receiving unit is specifically used by the document query service system to perform legality verification based on the decryption receipt;

[0105] The receiving unit is specifically used to forward the decryption receipt to the confidence decoding system to decode the information and obtain the identity information if the legality verification is successful.

[0106] The receiving unit is specifically used to receive the identity information sent by the document inquiry service system.

[0107] Optionally, in some possible implementations of this application, the authentication unit is specifically used to open a verification page in the target application in response to the acquisition of the identity information;

[0108] The identification unit is specifically used to determine key information for indicating the target object based on the identity information;

[0109] The authentication unit is specifically used to encrypt and transmit the key information through the verification page to the service backend corresponding to the target application, so that the key information and the registration information corresponding to the target object are authenticated in the service backend corresponding to the target application.

[0110] The authentication unit is specifically used to receive the identity authentication result of the target object from the service backend corresponding to the target application.

[0111] Optionally, in some possible implementations of this application, the authentication unit is specifically used to determine the identity identifier corresponding to the target object based on the identity authentication result;

[0112] The authentication unit is specifically used to bind the identity identifier to the target object;

[0113] The authentication unit is specifically used to broadcast the identity identifier so that the associated application receives the binding relationship between the identity identifier and the target object;

[0114] The authentication unit is specifically used to authenticate the identity of the target object based on the identity identifier in response to the target object triggering the associated application.

[0115] Optionally, in some possible implementations of this application, the identification unit is specifically used to parse the description information corresponding to the target application in order to determine the application type corresponding to the application managed by the target application;

[0116] The identification unit is specifically used to perform application traversal based on the application type to determine the associated application.

[0117] The authentication unit is specifically used to broadcast the identity identifier so that the associated application receives the binding relationship between the identity identifier and the target object.

[0118] A third aspect of this application provides a computer device, comprising: a memory, a processor, and a bus system; the memory is used to store program code; the processor is used to execute the object identity authentication method based on a target application as described in the first aspect or any one of the first aspects according to the instructions in the program code.

[0119] The fourth aspect of this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the object identity authentication method based on a target application as described in the first aspect or any one of the first aspects.

[0120] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the object authentication method based on a target application provided in the first aspect or various optional implementations thereof.

[0121] As can be seen from the above technical solutions, the embodiments of this application have the following advantages:

[0122] By responding to the initiation of the identity authentication process for the target object in the target application, the near-field communication module of the terminal device is activated to perform document detection. Then, the encrypted document information detected by the near-field communication module is acquired and sent to the trusted decoding system. The trusted decoding system then generates a decryption receipt in response to the encrypted document information. This decryption receipt triggers the service backend of the target application to initiate an identity information query to the document query service system to obtain the identity information. This identity information is obtained by the document query service system sending a query request containing the decryption receipt back to the trusted decoding system. The system also receives the identity information sent by the document query service system and compares the identity information with the registration information of the target object in the service backend of the target application to determine the identity authentication result. This achieves object identity authentication based on the target application. Because near-field communication is used for trusted document detection and identity information is verified through multiple systems, the generation of forged identity information can be effectively avoided, improving the accuracy of identity authentication. Attached Figure Description

[0123] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0124] Figure 1 This is a network architecture diagram for an object identity authentication system based on a target application.

[0125] Figure 2 A flowchart illustrating an object identity authentication process based on a target application, provided in this application embodiment;

[0126] Figure 3 A flowchart illustrating an object identity authentication method based on a target application, provided in this application embodiment;

[0127] Figure 4A schematic diagram illustrating a scenario for an object identity authentication method based on a target application, provided in an embodiment of this application;

[0128] Figure 5 A schematic diagram illustrating another object identity authentication method based on a target application provided in this application embodiment;

[0129] Figure 6 A flowchart of another object identity authentication method based on a target application provided in this application embodiment;

[0130] Figure 7 A schematic diagram illustrating another object identity authentication method based on a target application provided in this application embodiment;

[0131] Figure 8 A flowchart of another object identity authentication method based on a target application provided in this application embodiment;

[0132] Figure 9 A flowchart of another object identity authentication method based on a target application provided in this application embodiment;

[0133] Figure 10 A schematic diagram illustrating another object identity authentication method based on a target application provided in this application embodiment;

[0134] Figure 11 A flowchart illustrating another object identity authentication method based on a target application provided in this application embodiment;

[0135] Figure 12 A flowchart illustrating another object identity authentication method based on a target application provided in this application embodiment;

[0136] Figure 13 A schematic diagram of the structure of an object identity authentication device based on a target application provided in this application embodiment;

[0137] Figure 14 This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application;

[0138] Figure 15 This is a schematic diagram of the structure of a server provided in an embodiment of this application. Detailed Implementation

[0139] This application provides a method and related apparatus for object identity authentication based on a target application. It can be applied to systems or programs in terminal devices that include object identity authentication functionality based on the target application. By responding to the initiation of an identity authentication process for a target object in the target application, the near-field communication module of the terminal device is activated to perform document detection. Then, the encrypted document information detected by the near-field communication module is acquired. This encrypted document information is sent to a trusted decoding system, which generates a decryption receipt in response. This decryption receipt triggers the service backend of the target application to initiate an identity information query to the document query service system to obtain the identity information. This identity information is obtained by the document query service system sending a query request containing the decryption receipt back to the trusted decoding system. The system also receives the identity information sent by the document query service system. Finally, the identity information is compared with the registration information corresponding to the target object in the service backend of the target application to determine the identity authentication result. This achieves object identity authentication based on the target application. Because near-field communication is used for trusted document detection and identity information is verified through multiple systems, the generation of forged identity information can be effectively avoided, improving the accuracy of identity authentication.

[0140] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “corresponding to,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0141] First, some terms that may appear in the embodiments of this application will be explained.

[0142] NFC: A near-field communication technology. A key difference between NFC and other data transmission technologies like Wi-Fi, Bluetooth, and infrared is that its effective range is generally limited to 4cm. It has various application modes, with the reader mode primarily used for access control, IC cards, and item tags, where information stored in the medium is retrieved upon close contact.

[0143] NDEF: A standardized data format used to exchange information between any compatible NFC device and another NFC device or tag. The data format consists of NDEF messages and NDEF records. This standard is maintained by the NFC Forum and is freely available for reference, but a license agreement is required to download it.

[0144] JSBridge is a bridge built using JavaScript, connecting the web on one end and native code on the other. Our goal in building this bridge is simple: to allow native code to call JavaScript code on the web, and to allow the web to "call" native code.

[0145] It should be understood that the target application-based object identity authentication method provided in this application can be applied to systems or programs in terminal devices that include target application-based object identity authentication functionality, such as mobile phone security software. Specifically, the target application-based object identity authentication system can run on systems such as... Figure 1 In the network architecture shown, such as Figure 1 The diagram shows the network architecture of an application-based object authentication system. As can be seen, this system can provide object authentication with multiple information sources. Specifically, it acquires the identity information of the target object performing the operation via near-field communication through a triggering operation on the terminal side, thereby performing authentication. This can be understood as... Figure 1 The document illustrates various terminal devices, which can be computer devices. In real-world scenarios, more or fewer types of terminal devices may participate in the object identification process based on the target application. The specific number and types depend on the actual scenario and are not limited here. Figure 1 The image shows one server, but in real-world scenarios, multiple servers can be involved, with the specific number depending on the actual situation.

[0146] In this embodiment, the server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud security, data security, identity authentication, game player identification, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, smart voice interaction device, smart home appliance, in-vehicle terminal, etc., but is not limited to these. The terminal and server can be directly or indirectly connected via wired or wireless communication, and the terminal and server can be connected to form a blockchain network; this application does not impose any restrictions.

[0147] It is understood that the aforementioned target application-based object identity authentication system can run on a personal mobile terminal, such as a mobile phone manager application, or it can run on a server, or it can run on a third-party device to provide target application-based object identity authentication in order to obtain the target application-based object identity authentication processing result of the information source. Specifically, the target application-based object identity authentication system can run in the aforementioned device as a program, or it can run as a system component in the aforementioned device, or it can run as a cloud service program. This embodiment can be applied to cloud technology, autonomous driving, and other scenarios. The specific operating mode depends on the actual scenario and is not limited here.

[0148] With the rapid development of internet technology, people have increasingly higher requirements for identity verification. For example, identity verification can be used in games to prevent minors from becoming addicted.

[0149] Generally, biometric technology is used to obtain the target's identity information (such as face or fingerprint), and then compared with the identity information of the target's registered account to check the consistency between the two in order to identify the true identity of the target.

[0150] However, identity information obtained through biometrics is easily forged, and forged identity information can easily pass identity verification, affecting the accuracy of identity verification.

[0151] To address the aforementioned issues, this application proposes an object identity authentication method based on the target application. This method is applied to... Figure 2 In the process framework shown for object identity authentication based on the target application, such as Figure 2 The diagram shown is a flowchart of an object identity authentication process based on a target application, provided in an embodiment of this application. The target object sends its identity information to the server via near-field communication through the interactive operation of the terminal. The server performs multi-platform information verification and then decodes the credible information to obtain the identity authentication result.

[0152] Specifically, it can be applied to the identification of game players. This involves using the NFC module on a smart device to read the legal documents held by the game player, and then comparing the obtained legal document information with the real-name registration information of the game player's account to identify the player's true identity.

[0153] It is understood that the method provided in this application can be a program written as processing logic in a hardware system, or it can be an object identity authentication device based on a target application, implemented in an integrated or external manner. As one implementation, this object identity authentication device based on the target application, in response to the initiation of the identity authentication process for the target object in the target application, awakens the near-field communication module of the terminal device to perform document detection; then, it acquires the encrypted document information detected by the near-field communication module; and sends the encrypted document information to the confidence decoding system, causing the confidence decoding system to generate a decryption receipt in response to the encrypted document information. This decryption receipt triggers the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain identity information. This identity information is obtained by the document query service system sending a query request containing the decryption receipt back to the confidence decoding system; and the device receives the identity information sent by the document query service system; then, it compares the identity information with the registration information corresponding to the target object in the service backend corresponding to the target application to determine the identity authentication result. This enables object identity authentication based on the target application. By using near-field communication for trusted document detection and verifying identity information through multiple systems, the generation of forged identity information can be effectively avoided, thus improving the accuracy of identity authentication.

[0154] Based on the above process architecture, the object identity authentication method based on the target application in this application will be described below. Please refer to [link / reference]. Figure 3 , Figure 3 The flowchart illustrates an object identity authentication method based on a target application, provided in this application embodiment. This management method can be executed by a terminal or a server, and this application embodiment includes at least the following steps:

[0155] 301. In response to the start of the identity authentication process for the target object in the target application, the near-field communication module of the terminal device is invoked to perform document detection.

[0156] In this embodiment, the target application can be an application for identity authentication management, a game application configured with a plugin for identity authentication management, or a cloud-based identity authentication application initiated, for example, when the game starts. The specific form depends on the actual scenario.

[0157] In one possible scenario, such as game login or payment, when a game application determines that the target is suspected to be a minor, the game will prompt the target to perform identity verification. Only after the verification is completed can the game continue; otherwise, the game cannot continue.

[0158] This embodiment involves document reading, document decryption, and identity verification. These three parts are connected in series to form an identity recognition system, which is used to verify the real identity of game players. Specifically, as follows... Figure 4 As shown, Figure 4 This is a schematic diagram of a scenario for an object identity authentication method based on a target application provided in this application embodiment. The diagram shows an unknown player who, after being identified by the identity recognition system of this embodiment, will be classified into two categories: adult game player and underage game player. The classification result will be used as an important basis for game management of player game time and consumption.

[0159] Specifically, the process of activating the near-field communication (NFC) module for document detection can begin by responding to the target application's authentication process for the target object and then detecting the hardware environment corresponding to the target application through the NFC module detection interface. For example, the NfcAdapter.getDefaultAdapter() system interface can be used to determine whether the device supports NFC functionality. If the hardware environment supports NFC functionality, the startup status of the NFC module is detected. For example, on an Android device, the NfcAdapter.isEnabled() system interface can be read to determine whether the interface is open. If it is not open, the target object needs to be guided to enable it. If the startup status of the NFC module indicates that the NFC module is enabled, the NFC module is set to reader mode to activate the NFC module for document detection, meaning the device can read NDEF format data from the NFC tag. Next, an NFC event detector is set up so that when the NFC tag is brought close to the device, the event detector can immediately receive an NFC event notification.

[0160] Optionally, if the near-field communication module's startup status indicates that the near-field communication module is not enabled, a startup reminder will be sent via system broadcast; if the near-field communication module is not activated, the system will enter the switch configuration page for the near-field communication module to enable the near-field communication module, thereby improving the effectiveness of identity authentication.

[0161] 302. Obtain the encrypted information of the certificate detected by the near-field communication module.

[0162] In this embodiment, the encrypted information of the document detected by the near-field communication module is the process of parsing the tag data in the detected object.

[0163] Specifically, in response to the near-field communication module detecting the approach of a detected object, a connection is established between the near-field communication module and the object tag corresponding to the detected object; then, the tag data contained in the object tag is read; and the tag data is packaged into a near-field communication event to distribute the near-field communication event to the event detector; then, the object type of the detected object is determined by the event detector; if the object type is a preset type (e.g., NDEF message), the target data segment in the tag data is parsed to obtain the document encryption information.

[0164] Optionally, the process of parsing the target data segment to obtain the encrypted document information can be as follows: first, determine the data record sequence corresponding to the tag data; then, parse the data record sequence to determine the identifier data segment (Header) and the target data segment (Payload); and then parse the payload information in the target data segment to obtain the encrypted document information. For example, in one possible scenario... Figure 5 This is a schematic diagram illustrating another object identity authentication method based on a target application provided in this application embodiment; each NDEF message contains one or more NDEF records. Each record can be divided into a header and a payload, where the payload is the specific effective payload. The header uses the following structure to identify the content and size of the record.

[0165] The following explanation will focus on scenarios where the target type is NDEF format. Figure 6 As shown, Figure 6 This application provides a flowchart of another object identity authentication method based on a target application. The flowchart shows that the current hardware device first detects whether it supports NFC function. For example, for an Android device, when the system SDK version is higher than 13, the NfcAdapter.getDefaultAdapter() system interface can be used to determine whether the device supports NFC function. If it supports NFC, the process proceeds to step b; otherwise, the detection process is terminated.

[0166] Then, guide the target device to enable NFC functionality. For example, on an Android device, you can check if the interface is enabled by reading the `NfcAdapter.isEnabled()` system interface. If it's not enabled, you need to guide the target device to enable it. First, check if the device supports the default enabling path. That is, try sending system broadcasts using `Settings.ACTION_WIRELESS_SETTINGS` and `Settings.ACTION_NFC_SETTINGS`. If the broadcast fails, display the manufacturer's cloud-based enabling solution. If successful, automatically enter the NFC switch settings page. After the target device successfully enables the function, proceed to the next setup step.

[0167] The setup steps involve configuring the NFC function mode and parameters. First, set the NFC function to reader mode, meaning the device can read NDEF format data from NFC tags. Second, configure the NFC event detector so that it receives an NFC event notification immediately when an NFC tag is brought close to the device.

[0168] Furthermore, when the target object brings the document close to the smart device, the NFC device actively establishes a connection with the tag. After the connection is established, it reads the NDEF message stored in the document tag, packages the tag data into an NFC event, and then distributes it to the event detector through the NFC event distribution mechanism. This determines whether the NDEF message carried by the NFC event is document-related data. If it is, the process proceeds to step f; otherwise, the process terminates. The NDEF message is then parsed according to its data format to extract the Payload data segment, which contains the document's encrypted information field.

[0169] In one possible scenario, the structure of the NDEF message is as follows: Figure 7 As shown, Figure 7 This is a schematic diagram of another object identification method based on a target application provided in this application embodiment; the diagram shows the Header data segment (A1) and Payload data segment (A2) contained in the NDEF message, thereby ensuring the accuracy of object identification.

[0170] 303. Send the encrypted document information to the Trusted Decoding System so that the Trusted Decoding System can generate a decryption receipt in response to the encrypted document information. The decryption receipt is used to trigger the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain the identity information. The identity information is returned by the document query service system to the Trusted Decoding System by sending a query request containing the decryption receipt.

[0171] In this embodiment, after the terminal document encryption information is collected, it still needs to go through a trusted decoding system and a document query service system. Each link works together to complete the document decoding and obtain the final identity data. The trusted decoding system is an identity information decoding system with credibility, such as a cloud decoding system of a management department. The document query service system is a backend service that is registered in the trusted decoding system and can perform identity verification business, such as the backend of a licensed document service institution. The specific types of multiple systems depend on the actual scenario. Through distributed information management, each system adopts trusted processing to avoid the risk of information leakage, and the credibility of identity information is improved through mutual verification.

[0172] Specifically, for the identity verification process across multiple platforms, the encrypted document information can first be packaged into a decoding request. Then, the decoding request is sent to the trusted decoding system for verification. If the verification passes, the trusted decoding system generates a decryption receipt based on the encrypted document information. Further, the decryption receipt from the trusted decoding system can be obtained and sent to the service backend of the target application. This service backend then forwards the receipt to the document query service system. The document query service system then performs a validity verification based on the decryption receipt. If the validity verification passes, the receipt is forwarded to the trusted decoding system for decoding to obtain the identity information. Finally, the system receives the identity information sent by the document query service system, thereby improving the reliability of the identity information.

[0173] 304. Receive identity information sent by the document inquiry service system.

[0174] In this embodiment, receiving the identity information sent by the document query service system is the document decoding process. That is, after the terminal document encryption information is collected, it is necessary to go through the management department's cloud decoding system and the document service licensed institution. Each link works together to complete the document decoding and obtain the final identity data.

[0175] In one possible scenario, the confidence decoding system is the management department's cloud decoding system, and the document inquiry service system is the backend of the licensed document service agency. This will be used as an example below; other system entities with the above functions can also be applied. Specifically, for example... Figure 8 As shown, Figure 8 This application provides a flowchart of another object identity authentication method based on a target application. The flowchart shows that after successfully reading the encrypted information block of a document, the NFC-enabled smart terminal device sends a decoding request to the management department's cloud decoding system, carrying the encrypted information block. Then, the management department's cloud decoding system verifies the NFC-enabled smart terminal's request and the encrypted data block it carries. Upon successful verification, it returns a document details receipt (reqid) to the NFC-enabled smart terminal. Further, after obtaining the information receipt (reqid), the NFC-enabled smart terminal carries this information receipt and forwards the network request to the document service licensed institution's backend through the application service backend. This allows the document service licensed institution's backend to verify the request's legitimacy and then forward the request again to the management department's cloud decoding system. Finally, after verifying the information receipt (reqid), the management department's cloud decoding system returns the corresponding decrypted document information, including the ID number, name, etc., which is then sequentially transmitted back to the NFC-enabled smart terminal through the document service licensed institution's backend and the application service backend, thus completing the document decoding process.

[0176] 305. Verify the identity information against the registration information of the target object in the service backend corresponding to the target application.

[0177] In this embodiment, the process of comparing identity information with the registration information of the target object in the service backend corresponding to the target application is the identity authentication process. The service backend corresponding to the target application can be a game service backend or a backend for other application types.

[0178] It is understandable that the identity authentication process in this embodiment is designed according to the principle of time-limited storage of sensitive data in the background and untrusted terminals. The transmission of verification data must be completed by the interaction of the background service. That is, the verification service background (the background of the target application) encrypts the verification data with the public key, and the game service background (the service background corresponding to the target application) decrypts the verification data with the matching private key, thereby realizing hierarchical management of the verification (authentication) process and strengthening the security of data.

[0179] Specifically, the process of comparing identity information with the registration information of the target object in the service backend of the target application can begin by opening a verification page in the target application in response to the acquisition of identity information; then, based on the identity information, key information for instructing the target object is determined; and the key information is encrypted and transmitted to the service backend of the target application through the verification page, so that the key information is compared with the registration information of the target object in the service backend of the target application; and then the identity authentication result fed back by the service backend of the target application is received.

[0180] 306. Output the identity verification result corresponding to the target object to the target application.

[0181] In this embodiment, the authentication process is performed in the service background, which ensures the security of information. Furthermore, the process execution after identity authentication by the target application improves the effectiveness of identity authentication.

[0182] In one possible scenario, the target application could be a mobile security app, and the corresponding backend service could be a game backend service. The verification process described above would be as follows: Figure 9 As shown, Figure 9This application provides a flowchart of another object identity authentication method based on a target application. The flowchart shows that first, a verification application is launched within the game application, and then a game verification H5 webpage (verification page) is opened within the verification application. Then, within the verification H5, the target object is guided to agree to the document-related privacy collection and usage agreement. This initiates the document reading process in the verification application. The verification application completes document reading and decoding, obtaining the verification result query key (key information). Further, the verification application passes the query key to the game verification H5 via the jsbridge interface, and the game verification H5 then transmits the query key to the game backend via an encrypted network. The game backend accesses the verification application's backend service with the query key to obtain identity data. The game backend service then verifies the identity data and sends the verification result to the game app, thus achieving a separate authentication process and reducing the risk of information leakage.

[0183] In addition, dynamic protection strategies can be formulated by detecting the current game operating environment, such as obtaining environmental parameters like the phone's debugging switch, whether it is connected to a computer, whether it is rooted, and whether it has a custom ROM. For example, NFC can be used to read ID cards for authentication in high-risk environments, while facial recognition technology can be used for authentication in normal environments.

[0184] In one possible scenario, the process of the identity authentication system reading the document in this embodiment is illustrated as follows: Figure 10 As shown, Figure 10 This is a schematic diagram of another object identity authentication method based on a target application provided in this application embodiment. The diagram shows that when it is necessary to verify the real identity of a game player, the game app launches a mobile security app. After the mobile security app authorizes the collection of the target object's privacy, it pops up an interface to guide the target object to complete the collection of document information. After the collected data is confidentialized by an authoritative institution, the confidential data is sent back to the game side, and the game side completes the final verification of the target object's identity.

[0185] The following explanation will be based on scenarios involving the identification of minors in games, such as... Figure 11 As shown, Figure 11 A flowchart of another object identity authentication method based on a target application provided in this application embodiment; after the game backend receives the player's request to log in to the game, the game backend sends a verification instruction to the game app, and the game app can open (awaken) the hand management app (target application); the hand management app first initializes the NFC module function, that is, checks the phone's NFC environment and switch configuration, and then guides the player to enable NFC. For those that do not support NFC, a return operation is performed when enabling NFC fails.

[0186] Furthermore, once the document reading is completed, the Hand Management App sends the encrypted document data to the management department's document identity system, which then sends a Reqid response, uploading the encrypted document block information to the management department's system to obtain a decryption receipt.

[0187] Then, the Hand Manager App, carrying the Reqid, triggers the management department's identity system to return identity information via the Hand Manager backend and the certificate-licensing institution backend. Specifically, it requests decrypted identity data from a third-party identity-licensing institution based on the decryption receipt. After obtaining the decrypted identity data, it immediately generates a query key (key information) and returns it to the game App, which in turn feeds back to the game backend. The game backend accesses the Hand Manager backend through the query key to obtain the player's identity data. After obtaining the identity data, it verifies the real-name information bound to the player's login account to complete the final identity verification.

[0188] As described in the above embodiments, by responding to the initiation of the identity authentication process for the target object in the target application, the near-field communication module of the terminal device is activated to perform document detection; then, the encrypted document information detected by the near-field communication module is obtained; and the encrypted document information is sent to the trusted decoding system, so that the trusted decoding system generates a decryption receipt in response to the encrypted document information. This decryption receipt is used to trigger the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain the identity information. This identity information is obtained by the document query service system sending a query request containing the decryption receipt back to the trusted decoding system; and the system receives the identity information sent by the document query service system; then, the identity information is compared with the registration information corresponding to the target object in the service backend corresponding to the target application to determine the identity authentication result. This achieves the object identity authentication process based on the target application. Because near-field communication is used for trusted document detection, and identity information is verified through multiple systems, the generation of forged identity information can be effectively avoided, improving the accuracy of identity authentication.

[0189] In one possible scenario, the target application in this embodiment is used to verify the identity of minors during the login process of a game application. The following description illustrates this scenario. Figure 12 As shown, Figure 12 A flowchart of another object identity authentication method based on a target application provided in this application embodiment; this embodiment includes, but is not limited to, the following steps:

[0190] 1201. Obtain the login information entered by the target object in the target application.

[0191] In this embodiment, since the target application can be a plugin for its managed application (such as a game or payment application, which will be described using a game as an example in the following embodiments), the login information entered by the target object in the target application is the login information of the application managed by the target application, such as the login information in a game.

[0192] Understandably, by managing the game's login interface through the target application, the authentication process is carried out before the login begins, thus preventing the authentication process from being bypassed through game vulnerabilities and improving the effectiveness of authentication.

[0193] 1202. Upload the login information to the verification backend of the target application to verify the login information.

[0194] In this embodiment, since the target application intervenes in the game's login process, after the login information is uploaded to the target application's verification backend, the verification backend communicates with the game's backend to verify the login information, thereby avoiding direct communication between the target object and the game's backend and improving information security.

[0195] 1203. If the login verification is successful, the identity authentication process for the target object will be initiated.

[0196] In this embodiment, successful login verification means that the login information (account and password) entered in the game is valid, and then the identity authentication process of the target object is carried out.

[0197] In one possible scenario, if the target object is configured with an identity identifier, the identity verification process can be performed directly based on the identity identifier, thereby improving the efficiency of identity verification. For example, if the identity identifier indicates that the target object is a minor, the result of identity verification will be failure. The specific configuration of the identity identifier will be explained in subsequent steps.

[0198] It is understandable that if the identity identifier has a specific time limit, the time limit should be determined before identity verification is performed based on the identity identifier. For example, if the time limit of the identity identifier is 24 hours, it should be determined whether the identity identifier has been marked for 24 hours before identity verification is performed based on the identity identifier. If not, then verification can be performed based on the identity identifier.

[0199] 1204. Perform a matching determination of the identification time period.

[0200] In this embodiment, since the identity verification process is performed on minors, and the operation time of minors has certain distribution characteristics, for example, minors may log in to the game after school, so the identity verification process can be performed on login behavior during specific time periods.

[0201] Specifically, the identification period can be set manually, such as from 6 pm to 12 am; or it can be based on historical data statistics, such as the distribution of time periods when minors log in to the game, and the time periods with the densest distribution can be set as the identification period.

[0202] 1205. End authentication.

[0203] In this embodiment, if it is not in the authentication period, it means that the probability of the target being a minor is small, and the authentication process can be skipped directly, and the game process can run normally, thereby improving the efficiency of authentication.

[0204] 1206. Detect the hardware environment corresponding to the target application through the near-field module detection interface.

[0205] In this embodiment, for identifying the authentication period before detecting the hardware environment corresponding to the target application through the near-field module detection interface, the time information when the target object enters login information can be determined first based on the running process corresponding to the target application, for example, the time information is 6:30 pm; then the authentication period set for the target object can be obtained, for example, the authentication period is from 6 pm to 8 pm; then the time information is compared with the authentication period; if the time indicated by the time information is within the authentication period, the hardware environment corresponding to the target application can be detected through the near-field module detection interface, thereby improving the effectiveness of identity authentication.

[0206] In addition, the identification time period can be determined by identifying the date information corresponding to the time information; then, a preset date comparison can be performed based on the date information to determine the available status corresponding to the date information, such as the preset date being a weekend or a public holiday; then, the identification time period set for the target object can be obtained according to the available status, such as the identification time period corresponding to weekends or public holidays being from 10:00 am to 8:00 pm, thereby realizing a targeted identity identification process, improving identification efficiency while ensuring identification effect.

[0207] 1207. Start the module based on the configuration of the near-field communication module.

[0208] In this embodiment, since different terminals have different configurations for the near-field communication module, a corresponding startup process is required. Specifically, it can detect whether the current hardware device supports NFC functionality, such as an Android device, and then guide the current user to enable NFC. For example, on an Android device, the system interface NfcAdapter.isEnabled() can be read to determine whether the interface is enabled; if it is not enabled, the user needs to be guided to enable it.

[0209] Additionally, it's necessary to check if the device supports the default activation path. After the user successfully enables the function, the NFC function mode and parameters are set. First, the NFC function is set to reader mode, meaning the device can read NDEF format data from NFC tags. Second, an NFC event detector is set so that when an NFC tag is near the device, the event detector immediately receives an NFC event notification. Further, when the user brings their ID card close to the smart device, the NFC device actively establishes a connection with the tag. After the connection is established, it reads the NDEF message stored in the ID card tag, packages the tag data into an NFC event, and then distributes it to the event detector through the NFC event distribution mechanism. Then, it determines whether the NDEF message carried by the NFC event is ID card data. If it is, the NDEF message is parsed according to its data format to extract the PAYLOAD data segment, which is the encrypted ID card information field; otherwise, the process terminates.

[0210] 1208. Obtain the encrypted information of the document detected by the near-field communication module.

[0211] In this embodiment, the process of obtaining document encryption information can first respond to the near-field communication module detecting the proximity of the detected object by establishing a connection between the near-field communication module and the object tag corresponding to the detected object; then, the tag data contained in the object tag is read; and the tag data is packaged into a near-field communication event to distribute the near-field communication event to the event detector; then, the object type of the detected object is determined by the event detector; if the object type is a preset type (e.g., NDEF message), the target data segment in the tag data is parsed to obtain the document encryption information.

[0212] 1209. Send the encrypted information of the document to the trusted decoding system so that the trusted decoding system can generate a decryption receipt in response to the encrypted information of the document.

[0213] In this embodiment, the decryption receipt is used to trigger the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain the identity information. The identity information is then sent back to the confidence decoding system via the document query service system, which sends a query request containing the decryption receipt.

[0214] Specifically, the trusted decoding system is a credible identity information decoding system, such as a cloud decoding system for management departments; while the document inquiry service system is a back-end service that can perform identity verification business and is registered in the trusted decoding system, such as the back-end of a licensed document service institution. The specific types of multiple systems depend on the actual scenario. Through distributed information management, each system adopts trusted processing, avoiding the risk of information leakage, and improving the credibility of identity information through mutual verification.

[0215] 1210. Receive identity information sent by the document inquiry service system.

[0216] In this embodiment, the confidence decoding system is the management department's cloud decoding system, and the document inquiry service system is the backend of the document service licensed institution. The following description uses this as an example, but other system entities with the above functions can also be applied.

[0217] Specifically, the process of decoding and acquiring identity information can begin by having the NFC-enabled smart terminal device successfully read the encrypted information block from the document and then sending a decoding request to the management department's cloud decoding system, carrying the encrypted information block with it. The management department's cloud decoding system then verifies the NFC-enabled smart terminal's request and the encrypted data block it carries. Upon successful verification, the system returns a receipt (reqid) for querying document details to the NFC-enabled smart terminal.

[0218] Furthermore, after obtaining the information receipt (reqid), the NFC-enabled smart terminal carries this information receipt and forwards the network request to the document service licensed institution's backend through the application service backend. This allows the document service licensed institution's backend to verify the request's legitimacy and then forward it again to the management department's cloud decoding system. Subsequently, after verifying the information receipt (reqid) in the management department's cloud decoding system, it returns the corresponding decrypted document information, including the ID number, name, etc., which is then sequentially transmitted back to the NFC-enabled smart terminal through the document service licensed institution's backend and the application service backend, thus completing the document decoding process.

[0219] 1211. Verify the identity information against the registration information of the target object in the service backend corresponding to the target application.

[0220] In this embodiment, the process of comparing identity information with the registration information of the target object in the service backend corresponding to the target application is the identity authentication process. The service backend corresponding to the target application can be a game service backend or a backend for other application types.

[0221] In addition, the process of comparing identity information with the registration information of the target object in the service backend of the target application can first respond to the acquisition of identity information by opening a verification page in the target application; then, based on the identity information, determine the key information used to indicate the target object; and transmit the key information to the service backend of the target application in encrypted form through the verification page, so that the key information can be compared with the registration information of the target object in the service backend of the target application; and then receive the identity authentication result fed back by the service backend of the target application.

[0222] 1212. Output the identity authentication result corresponding to the target object to the target application, and determine the identity identifier corresponding to the target object based on the identity authentication result.

[0223] In this embodiment, the identity authentication result indicates whether the target object is a minor, and the corresponding identity identifier is configured. Then, the identity identifier is bound to the target object so that the relationship can be invoked in the subsequent authentication process.

[0224] 1213. Broadcast the identification information.

[0225] In this embodiment, broadcasting the identity identifier means broadcasting the association relationship after the identity identifier is bound to the target object, so that the associated application receives the binding relationship between the bound identity identifier and the target object; after the associated object receives the association relationship, that is, the identity identifier corresponding to the target object, it can respond to the target object to trigger the associated application to perform identity authentication of the target object based on the identity identifier.

[0226] Furthermore, an expiration time can be configured for the identity identifier, such as an identity identifier being valid for 24 hours. This takes into account the periodicity of minors logging in, thereby improving the accuracy of identity verification based on the identity identifier.

[0227] In another possible scenario, since the target application can manage multiple related applications, it can identify minors for applications of the same type, such as managing game applications, while not needing to identify minors for learning applications.

[0228] Specifically, for the management process of type-based applications, the description information corresponding to the target application can be parsed to determine the application type corresponding to the target application management application (game); then, application traversal is performed based on the application type to determine the associated applications (other games installed on the terminal device); and then the identity identifier is broadcast so that the associated applications receive the binding relationship between the bound identity identifier and the target object, thereby improving the efficiency of identity authentication.

[0229] 1214. Identity authentication process based on identity identifiers.

[0230] In this embodiment, minors are managed by identifying them with identity tags. When a minor is logged out of the game, a pop-up message reminds them that they cannot play the game and directs them to a learning application. This enables a fast multi-application management process, improves the efficiency of identity verification during multi-application management, and enhances the management of minors' gaming activities.

[0231] As can be seen from this embodiment, the protection of minors in games is essential for the healthy and stable development of the game industry. However, black market operators are eyeing minors in games. This embodiment can protect minors. In the game field, the identification process of one game can quickly mark and assist the identification processes of other games, improving the identity identification efficiency of the target application at the terminal device level.

[0232] To better implement the above-described solutions of the embodiments of this application, related apparatus for implementing the above solutions is also provided below. Please refer to... Figure 13 , Figure 13 This application provides a schematic diagram of the structure of an object identity authentication device based on a target application. The object identity authentication device 1300 based on the target application includes:

[0233] The acquisition unit 1301 is used to respond to the start of the identity authentication process for the target object in the target application and to wake up the near-field communication module of the terminal device to perform document detection.

[0234] The acquisition unit 1301 is also used to acquire the document encryption information detected by the near-field communication module;

[0235] Sending unit 1302 is used to send the encrypted document information to the trust decoding system, so that the trust decoding system generates a decryption receipt in response to the encrypted document information. The decryption receipt is used to trigger the service backend corresponding to the target application to initiate an identity information query to the document query service system to obtain identity information. The identity information is obtained by sending a query request containing the decryption receipt to the trust decoding system through the document query service system.

[0236] The receiving unit 1303 is used to receive the identity information sent by the document inquiry service system;

[0237] The authentication unit 1304 is used to compare the identity information with the registration information corresponding to the target object in the service backend corresponding to the target application to determine the identity authentication result.

[0238] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface in response to the start of the identity authentication process for the target object in the target application.

[0239] The acquisition unit 1301 is specifically used to detect the startup status of the near-field communication module if the hardware environment supports near-field communication function.

[0240] The acquisition unit 1301 is specifically used to set the near-field communication module to card reader mode if the startup status of the near-field communication module indicates that the near-field communication module is turned on, so as to wake up the near-field communication module to perform document detection.

[0241] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to send an activation reminder via system broadcast if the activation status of the near-field communication module indicates that the near-field communication module is not activated.

[0242] The acquisition unit 1301 is specifically used to enter the switch configuration page for the near-field communication module if the near-field communication module is not activated, so as to enable the near-field communication module.

[0243] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to acquire the login information entered by the target object in the target application;

[0244] The acquisition unit 1301 is specifically used to upload the login information to the verification backend of the target application to perform login verification on the login information;

[0245] The acquisition unit 1301 is specifically used to initiate an identity authentication process for the target object if the login verification is successful.

[0246] The acquisition unit 1301 is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface.

[0247] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to determine the time information when the target object inputs the login information based on the running process corresponding to the target application;

[0248] The acquisition unit 1301 is specifically used to acquire the identification time period set for the target object;

[0249] The acquisition unit 1301 is specifically used to compare the time information with the identification time period;

[0250] The acquisition unit 1301 is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface if the time indicated by the time information is within the identification period.

[0251] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to determine the date information corresponding to the time information;

[0252] The acquisition unit 1301 is specifically used to perform a preset date comparison based on the date information in order to determine the idle state corresponding to the date information.

[0253] The acquisition unit 1301 is specifically used to acquire the identification time period set for the target object based on the idle state.

[0254] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to establish a connection between the near-field communication module and the object tag corresponding to the detected object in response to the near-field communication module detecting the proximity of the detected object;

[0255] The acquisition unit 1301 is specifically used to read the tag data contained in the object tag;

[0256] The acquisition unit 1301 is specifically used to package the tag data into near-field communication events, so as to distribute the near-field communication events to the event detector;

[0257] The acquisition unit 1301 is specifically used to determine the object type of the detected object through the event detector;

[0258] The acquisition unit 1301 is specifically used to parse the target data segment in the tag data to obtain the document encryption information if the object type is a preset type.

[0259] Optionally, in some possible implementations of this application, the acquisition unit 1301 is specifically used to determine the data record sequence corresponding to the tag data if the object type is a preset type;

[0260] The acquisition unit 1301 is specifically used to parse the data record sequence to determine the identifier data segment and the target data segment;

[0261] The acquisition unit 1301 is specifically used to parse the load information in the target data segment to obtain the document encryption information.

[0262] Optionally, in some possible implementations of this application, the sending unit 1302 is specifically used to package the document encryption information into a decoding request;

[0263] The sending unit 1302 is specifically used to send the decoding request to the confidence decoding system so that the confidence decoding system can verify the decoding request;

[0264] The sending unit 1302 is specifically used to generate the decryption receipt based on the document encryption information if the verification passes.

[0265] The receiving unit 1303 is specifically used to obtain the decryption receipt fed back by the confidence decoding system;

[0266] The receiving unit 1303 is specifically used to send the decryption receipt to the service backend corresponding to the target application, so that the service backend corresponding to the target application forwards the decryption receipt to the document query service system.

[0267] The receiving unit 1303 is specifically used by the document query service system to perform legality verification based on the decryption receipt;

[0268] The receiving unit 1303 is specifically used to forward the decryption receipt to the confidence decoding system to decode the information and obtain the identity information if the legality verification is successful.

[0269] The receiving unit 1303 is specifically used to receive the identity information sent by the document inquiry service system.

[0270] Optionally, in some possible implementations of this application, the authentication unit 1304 is specifically used to open a verification page in the target application in response to the acquisition of the identity information;

[0271] The identification unit 1304 is specifically used to determine key information for indicating the target object based on the identity information;

[0272] The authentication unit 1304 is specifically used to encrypt and transmit the key information through the verification page to the service backend corresponding to the target application, so that the key information and the registration information corresponding to the target object are authenticated in the service backend corresponding to the target application.

[0273] The authentication unit 1304 is specifically used to receive the identity authentication result of the target object fed back by the service backend corresponding to the target application.

[0274] Optionally, in some possible implementations of this application, the authentication unit 1304 is specifically used to determine the identity identifier corresponding to the target object based on the identity authentication result;

[0275] The identification unit 1304 is specifically used to bind the identity identifier to the target object;

[0276] The authentication unit 1304 is specifically used to broadcast the identity identifier so that the associated application receives the binding relationship between the identity identifier and the target object;

[0277] The authentication unit 1304 is specifically used to authenticate the identity of the target object based on the identity identifier in response to the target object triggering the associated application.

[0278] Optionally, in some possible implementations of this application, the identification unit 1304 is specifically used to parse the description information corresponding to the target application in order to determine the application type corresponding to the application managed by the target application;

[0279] The identification unit 1304 is specifically used to perform application traversal based on the application type to determine the associated application.

[0280] The authentication unit 1304 is specifically used to broadcast the identity identifier so that the associated application receives the binding relationship between the identity identifier and the target object.

[0281] By responding to the initiation of the identity authentication process for the target object in the target application, the near-field communication module of the terminal device is activated to perform document detection. Then, the encrypted document information detected by the near-field communication module is acquired and sent to the trusted decoding system. The trusted decoding system then generates a decryption receipt in response to the encrypted document information. This decryption receipt triggers the service backend of the target application to initiate an identity information query to the document query service system to obtain the identity information. This identity information is obtained by the document query service system sending a query request containing the decryption receipt back to the trusted decoding system. The system also receives the identity information sent by the document query service system and compares the identity information with the registration information of the target object in the service backend of the target application to determine the identity authentication result. This achieves object identity authentication based on the target application. Because near-field communication is used for trusted document detection and identity information is verified through multiple systems, the generation of forged identity information can be effectively avoided, improving the accuracy of identity authentication.

[0282] This application also provides a terminal device, such as... Figure 14 The diagram shown is a structural schematic of another terminal device provided in an embodiment of this application. For ease of explanation, only the parts related to the embodiment of this application are shown. For specific technical details not disclosed, please refer to the method section of the embodiment of this application. The terminal can be any terminal device including mobile phones, tablet computers, personal digital assistants (PDAs), point-of-sale (POS) terminals, in-vehicle computers, etc. Taking a mobile phone as an example:

[0283] Figure 14 This is a block diagram illustrating a portion of the structure of a mobile phone related to the terminal provided in the embodiments of this application. (Reference) Figure 14The mobile phone includes components such as a radio frequency (RF) circuit 1410, a memory 1420, an input unit 1430, a display unit 1440, a sensor 1450, an audio circuit 1460, a wireless fidelity (WiFi) module 1470, a processor 1480, and a power supply 1490. Those skilled in the art will understand that... Figure 14 The mobile phone structure shown does not constitute a limitation on the mobile phone and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0284] The following is combined with Figure 14 A detailed introduction to each component of a mobile phone:

[0285] RF circuit 1410 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and processes it with processor 1480; additionally, it transmits uplink data to the base station. Typically, RF circuit 1410 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier (LNA), a duplexer, etc. Furthermore, RF circuit 1410 can also communicate wirelessly with networks and other devices. The aforementioned wireless communication can use any communication standard or protocol, including but not limited to Global System for Mobile Communication (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, Short Message Service (SMS), etc.

[0286] The memory 1420 can be used to store software programs and modules. The processor 1480 executes various mobile phone functions and data processing by running the software programs and modules stored in the memory 1420. The memory 1420 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 1420 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0287] The input unit 1430 can be used to receive input numerical or character information, and to generate key signal inputs related to target object settings and function control of the mobile phone. Specifically, the input unit 1430 may include a touch panel 1431 and other input devices 1432. The touch panel 1431, also known as a touch screen, can collect touch operations on or near the target object (such as operations performed by the target object using a finger, stylus, or any suitable object or accessory on or near the touch panel 1431, and air touch operations within a certain range on the touch panel 1431), and drive the corresponding connection devices according to a pre-set program. Optionally, the touch panel 1431 may include two parts: a touch detection device and a touch controller. The touch detection device detects the touch position of the target object and detects the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, sends it to the processor 1480, and can receive and execute commands sent by the processor 1480. Furthermore, the touch panel 1431 can be implemented using various types of sensors, including resistive, capacitive, infrared, and surface acoustic wave sensors. In addition to the touch panel 1431, the input unit 1430 may also include other input devices 1432. Specifically, these other input devices 1432 may include, but are not limited to, one or more of the following: a physical keyboard, function keys (such as volume control buttons, power buttons, etc.), a trackball, a mouse, and a joystick.

[0288] The display unit 1440 can be used to display information input by a target object or information provided to the target object, as well as various menus of the mobile phone. The display unit 1440 may include a display panel 1441, optionally configured as a liquid crystal display (LCD), organic light-emitting diode (OLED), or similar form. Further, a touch panel 1431 may cover the display panel 1441. When the touch panel 1431 detects a touch operation on or near it, it transmits the information to the processor 1480 to determine the type of touch event. Subsequently, the processor 1480 provides corresponding visual output on the display panel 1441 according to the type of touch event. Although in Figure 14 In this embodiment, the touch panel 1431 and the display panel 1441 are two separate components to realize the input and output functions of the mobile phone. However, in some embodiments, the touch panel 1431 and the display panel 1441 can be integrated to realize the input and output functions of the mobile phone.

[0289] The mobile phone may also include at least one sensor 1450, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 1441 according to the ambient light level, and the proximity sensor can turn off the display panel 1441 and / or the backlight when the phone is moved to the ear. As a type of motion sensor, an accelerometer sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used for applications that recognize the phone's posture (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition-related functions (such as pedometer, taps), etc. Other sensors that may be configured in the mobile phone, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be described in detail here.

[0290] Audio circuit 1460, speaker 1461, and microphone 1462 provide an audio interface between the target and the mobile phone. Audio circuit 1460 converts received audio data into electrical signals and transmits them to speaker 1461, where speaker 1461 converts them into sound signals for output. On the other hand, microphone 1462 converts collected sound signals into electrical signals, which are received by audio circuit 1460, converted into audio data, and then processed by processor 1480 before being transmitted via RF circuit 1410 to, for example, another mobile phone, or the audio data can be output to memory 1420 for further processing.

[0291] WiFi is a short-range wireless transmission technology. A mobile phone, through its WiFi module 1470, can help the target user send and receive emails, browse web pages, and access streaming media, providing wireless broadband internet access. Although Figure 14 WiFi module 1470 is shown, but it is understood that it is not an essential component of a mobile phone and can be omitted as needed without changing the essence of the invention.

[0292] The processor 1480 is the control center of the mobile phone, connecting various parts of the phone through various interfaces and lines. It executes software programs and / or modules stored in the memory 1420, and calls data stored in the memory 1420 to perform various functions and process data, thereby monitoring the phone as a whole. Optionally, the processor 1480 may include one or more processing units; optionally, the processor 1480 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, target interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the aforementioned modem processor may also not be integrated into the processor 1480.

[0293] The mobile phone also includes a power supply 1490 (such as a battery) that supplies power to various components. Optionally, the power supply can be logically connected to the processor 1480 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system.

[0294] Although not shown, mobile phones may also include a camera, Bluetooth module, etc., which will not be described in detail here.

[0295] In this embodiment of the application, the processor 1480 included in the terminal also has the function of performing the various steps of the page processing method described above.

[0296] This application also provides a server; please refer to [link / reference]. Figure 15 , Figure 15This is a schematic diagram of a server structure provided in an embodiment of this application. The server 1500 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 1522 (e.g., one or more processors) and memory 1532, and one or more storage media 1530 (e.g., one or more mass storage devices) for storing application programs 1542 or data 1544. The memory 1532 and storage media 1530 can be temporary or persistent storage. The program stored in the storage media 1530 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the server. Furthermore, the CPU 1522 may be configured to communicate with the storage media 1530 and execute the series of instruction operations in the storage media 1530 on the server 1500.

[0297] Server 1500 may also include one or more power supplies 1526, one or more wired or wireless network interfaces 1550, one or more input / output interfaces 1558, and / or one or more operating systems 1541, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0298] The steps performed by the management device in the above embodiments can be based on this Figure 15 The server structure shown.

[0299] This application also provides a computer-readable storage medium storing object identity authentication instructions based on a target application. When these instructions are executed on a computer, they cause the computer to perform the aforementioned actions. Figures 3 to 12 The steps performed by the object identity authentication device based on the target application in the method described in the illustrated embodiment.

[0300] This application also provides a computer program product including object identity authentication instructions based on a target application, which, when run on a computer, causes the computer to perform the aforementioned... Figures 3 to 12 The steps performed by the object identity authentication device based on the target application in the method described in the illustrated embodiment.

[0301] This application also provides a target application-based object identity authentication system, which may include... Figure 13 The object identity authentication device based on the target application in the described embodiments, or Figure 14 The terminal device in the described embodiments, or Figure 15 The server described.

[0302] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0303] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0304] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0305] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0306] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, an object authentication device based on a target application, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0307] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for object identity authentication based on a target application, characterized in that, include: In response to the initiation of the identity authentication process for the target object in the target application, the near-field communication module of the terminal device is activated to perform document detection; The target is the individual identified by the game application as a suspected minor; Obtain the encrypted document information detected by the near-field communication module; The encrypted information of the document is packaged into a decoding request and sent to the trusted decoding system, so that the trusted decoding system can verify the decoding request. If the verification is successful, the trusted decoding system generates a decryption receipt based on the encrypted information of the document; the trusted decoding system is a credible identity information decoding system. Obtain the decryption receipt fed back by the confidence decoding system, and send the decryption receipt to the service backend corresponding to the target application, so that the service backend corresponding to the target application forwards the decryption receipt to the document query service system, and the document query service system performs legality verification based on the decryption receipt; If the legality verification passes, the decryption receipt is forwarded to the confidence decoding system for information decoding to obtain the identity information; Receive the identity information sent by the document inquiry service system; the document inquiry service system is the backend of a licensed document service institution registered in the confidence decoding system; The identity information is verified against the registration information corresponding to the target object in the service backend of the target application. The identity verification result corresponding to the target object is output to the target application, and the identity verification result is used to indicate whether the target object is a minor.

2. The method according to claim 1, characterized in that, The response to the initiation of the identity authentication process for the target object in the target application, which awakens the near-field communication module of the terminal device to perform document detection, includes: In response to the initiation of the identity authentication process for the target object in the target application, the hardware environment corresponding to the target application is detected through the near-field module detection interface; If the hardware environment supports near-field communication, then the startup status of the near-field communication module is detected; If the activation status of the near-field communication module indicates that the near-field communication module is enabled, then the near-field communication module is set to card reader mode to activate the near-field communication module for document detection.

3. The method according to claim 2, characterized in that, The method further includes: If the activation status of the near-field communication module indicates that the near-field communication module is not enabled, an activation reminder will be sent via system broadcast. If the near-field communication module is not activated, the system will enter the switch configuration page for the near-field communication module to enable it.

4. The method according to claim 2, characterized in that, The response to the initiation of the identity authentication process for the target object in the target application includes detecting the hardware environment corresponding to the target application through the near-field module detection interface, including: Obtain the login information entered by the target object in the target application; The login information is uploaded to the verification backend of the target application to verify the login information. If the login verification is successful, the identity authentication process for the target object will be initiated. The hardware environment corresponding to the target application is detected through the near-field module detection interface.

5. The method according to claim 4, characterized in that, The step of detecting the hardware environment corresponding to the target application through the near-field module detection interface includes: The time information when the target object inputs the login information is determined based on the running process corresponding to the target application; Obtain the identification time period set for the target object; The time information is compared with the identification time period; If the time indicated by the time information is within the identification period, the hardware environment corresponding to the target application is detected through the near-field module detection interface.

6. The method according to claim 5, characterized in that, The step of obtaining the identification time period set for the target object includes: Determine the date information corresponding to the time information; Based on the date information, a preset date comparison is performed to determine the idle status corresponding to the date information; The identification period set for the target object is obtained based on the idle state.

7. The method according to claim 1, characterized in that, The step of obtaining the document encryption information detected by the near-field communication module includes: In response to the near-field communication module detecting the proximity of the detected object, a connection is established between the near-field communication module and the object tag corresponding to the detected object; Read the tag data contained within the object tag; The tag data is packaged into near-field communication events to distribute the near-field communication events to the event detector; The object type of the detected object is determined by the event detector; If the object type is a preset type, the target data segment in the tag data is parsed to obtain the document encryption information.

8. The method according to claim 7, characterized in that, If the object type is a preset type, then the target data segment in the tag data is parsed to obtain the document encryption information, including: If the object type is a preset type, then determine the data record sequence corresponding to the tag data; The data record sequence is parsed to determine the identifier data segment and the target data segment; The payload information in the target data segment is parsed to obtain the document encryption information.

9. The method according to claim 1, characterized in that, The step of verifying the identity information against the registration information corresponding to the target object in the service backend of the target application includes: In response to the acquisition of the identity information, a verification page is opened in the target application; Based on the identity information, key information used to indicate the target object is determined; The key information is encrypted and transmitted to the service backend corresponding to the target application through the verification page, so that the key information and the registration information corresponding to the target object are identified in the service backend corresponding to the target application; The step of outputting the identity verification result corresponding to the target object to the target application includes: Receive the identity authentication result of the target object from the service backend corresponding to the target application.

10. The method according to any one of claims 1-9, characterized in that, The method further includes: Determine the identity identifier corresponding to the target object based on the identity authentication results; Bind the identity identifier to the target object; The identity identifier is broadcast so that the associated application receives the binding relationship between the identity identifier and the target object; In response to the target object triggering the associated application, the target object's identity is authenticated based on the identity identifier.

11. The method according to claim 10, characterized in that, The broadcasting of the identity identifier, so that the associated application receives the binding relationship between the identity identifier and the target object, includes: The description information corresponding to the target application is parsed to determine the application type corresponding to the application managed by the target application; The application traversal is performed based on the application type to determine the associated application; The identity identifier is broadcast so that the associated application receives the binding relationship between the identity identifier and the target object.

12. A target application-based object identity authentication device, characterized in that, include: The acquisition unit is used to respond to the initiation of the identity authentication process for the target object in the target application and to wake up the near-field communication module of the terminal device to perform document detection; The target is the individual identified by the game application as a suspected minor; The acquisition unit is also used to acquire the document encryption information detected by the near-field communication module; The sending unit is used to package the encrypted information of the document into a decoding request and send it to the trusted decoding system, so that the trusted decoding system can verify the decoding request. If the verification is successful, the trusted decoding system generates a decryption receipt based on the encrypted information of the document. The confidence decoding system is a credible identity information decoding system. The receiving unit is configured to obtain the decryption receipt fed back by the confidence decoding system, and send the decryption receipt to the service backend corresponding to the target application, so that the service backend corresponding to the target application forwards the decryption receipt to the document query service system, and the document query service system performs legality verification based on the decryption receipt. If the legality verification passes, the decryption receipt is forwarded to the confidence decoding system for information decoding to obtain the identity information; Receive the identity information sent by the document inquiry service system; the document inquiry service system is the backend of a licensed document service institution registered in the confidence decoding system; An authentication unit is used to authenticate the identity information against the registration information corresponding to the target object in the service backend of the target application. The acquisition unit is further configured to output the identity authentication result corresponding to the target object to the target application, and the identity authentication result is used to indicate whether the target object is a minor.

13. The apparatus according to claim 12, characterized in that, The acquisition unit is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface in response to the start of the identity authentication process for the target object in the target application. The acquisition unit is specifically used to detect the startup status of the near-field communication module if the hardware environment supports near-field communication. The acquisition unit is specifically used to set the near-field communication module to card reader mode if the startup status of the near-field communication module indicates that the near-field communication module is turned on, so as to wake up the near-field communication module to perform document detection.

14. The apparatus according to claim 13, characterized in that, The acquisition unit is specifically used to send an activation reminder via system broadcast if the activation status of the near-field communication module indicates that the near-field communication module is not activated. The acquisition unit is specifically used to enter the switch configuration page for the near-field communication module if the near-field communication module is not activated, so as to enable the near-field communication module.

15. The apparatus according to claim 13, characterized in that, The acquisition unit is specifically used to acquire the login information entered by the target object in the target application; The acquisition unit is specifically used to upload the login information to the verification backend of the target application to perform login verification on the login information; The acquisition unit is specifically used to initiate an identity authentication process for the target object if the login verification is successful. The acquisition unit is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface.

16. The apparatus according to claim 15, characterized in that, The acquisition unit is specifically used to determine the time information when the target object inputs the login information based on the running process corresponding to the target application. The acquisition unit is specifically used to acquire the identification time period set for the target object; The acquisition unit is specifically used to compare the time information with the identification time period; The acquisition unit is specifically used to detect the hardware environment corresponding to the target application through the near-field module detection interface if the time indicated by the time information is within the identification period.

17. The apparatus according to claim 16, characterized in that, The acquisition unit is specifically used to determine the date information corresponding to the time information; The acquisition unit is specifically used to perform a preset date comparison based on the date information in order to determine the idle state corresponding to the date information. The acquisition unit is specifically used to acquire the identification time period set for the target object based on the idle state.

18. A computer device, characterized in that, The computer device includes a processor and memory: The memory is used to store program code; the processor is used to execute the object identity authentication method based on any one of claims 1 to 11 according to the instructions in the program code.

19. A computer program product comprising a computer program / instructions stored in a computer-readable storage medium, characterized in that, When the computer program / instructions in the computer-readable storage medium are executed by a processor, they implement the steps of the object identity authentication method based on the target application as described in any one of claims 1 to 11.

20. A computer program product, characterized in that, The method includes computer instructions stored in a computer-readable storage medium; a processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the steps of the object identity authentication method based on a target application as described in any one of claims 1 to 11.