A dynamic induction-based identity authentication method and related device

CN118523944BActive Publication Date: 2025-12-09BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410714307.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-04
Publication Date
2025-12-09
Estimated Expiration
2044-06-04

AI Technical Summary

Technical Problem

The existing terminal devices cannot be used when customers do not carry their ID cards or bank cards, resulting in limited functionality and a poor customer experience.

Method used

Identity authentication is performed through the target application on the mobile terminal, the identifier of the terminal device is obtained and the authentication token is sent to the server. After the server parses the token, it displays the customer's identity information and prompts for verification information input. After the verification information is matched, the terminal device displays the identity authentication operation interface, thus realizing identity authentication without physical documents.

Benefits of technology

Identity verification can be completed without customers providing their ID card or bank card, which enhances the functionality of terminal devices and the customer experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118523944B_ABST
    Figure CN118523944B_ABST
Patent Text Reader

Abstract

The application discloses a dynamic induction-based identity authentication method and related device, which can be applied to the field of Internet of Things or the field of finance, and after a customer authenticates the identity of a target application program running on a mobile terminal and selects a terminal device type in the target application program, the mobile terminal is in an induction state. The mobile terminal in the induction state is moved to an induction area of the terminal device, and the identity of the terminal device is acquired. The mobile terminal establishes communication with the terminal device through a first server, so that the terminal device displays customer identity information and prompts the customer to input verification information. After the first server determines that the verification information matches customer reserved information, the first server sends a login instruction to the terminal device, so that the terminal device displays an operation interface. The whole identity authentication process does not require the customer to provide identity cards, bank cards or other certificates, realizes the functional improvement of the terminal device, and effectively improves the customer experience.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things, and more particularly, to an identity authentication method based on dynamic induction and related devices. BACKGROUND

[0002] With the development of science and technology, there are more and more terminal devices in bank outlets, such as self-service deposit and withdrawal machines, intelligent counters, and flow printing machines. At present, when a customer uses a terminal device to handle a business, the customer needs to present an ID card or a bank card for identity authentication. If the customer forgets to carry the ID card or the bank card, the customer cannot use the terminal device to handle the business, and the function of the terminal device still has a large room for improvement. SUMMARY

[0003] In view of the above problems, the present application provides an identity authentication method based on dynamic induction and related devices to improve the function of the terminal device. The specific scheme is as follows:

[0004] The first aspect of the present application provides an identity authentication method based on dynamic induction, applied to a terminal device, and the identity authentication method based on dynamic induction comprises the following steps.

[0005] In response to a mobile terminal in an induction state moving to an induction area of the terminal device, sending an identification of the terminal device to the mobile terminal, wherein the mobile terminal is in the induction state after a customer passes an identity authentication of a target application program running on the mobile terminal and selects a terminal device type in the target application program;

[0006] Receiving customer identity information sent by a first server, wherein the customer identity information is obtained by the first server after analyzing an authentication token after receiving the authentication token sent by the mobile terminal, and the authentication token further comprises the identification of the terminal device;

[0007] Displaying the customer identity information in a preset format and prompting the customer to input verification information corresponding to the customer identity information;

[0008] Sending the verification information input by the customer to the first server to enable the first server to match the verification information with customer reserved information;

[0009] In response to a login instruction sent by the first server after determining that the verification information matches the customer reserved information, displaying an operation interface after the customer passes the identity authentication of the terminal device.

[0010] In a possible implementation, after displaying the operation interface after the customer passes the identity authentication of the terminal device, the method further comprises the following steps.

[0011] In response to an operation instruction initiated by the client on the operation interface, a transaction corresponding to the operation instruction is executed.

[0012] Obtaining transaction environment information in a transaction process, the transaction environment information including at least one of transaction environment images and transaction environment audio information.

[0013] Sending the transaction environment information to the first server to enable the first server to perform anomaly detection on the transaction environment information.

[0014] In a possible implementation, the method further includes:

[0015] In response to a transaction termination instruction sent by the first server, terminating the current transaction.

[0016] The transaction termination instruction is generated by the first server according to an anomaly detection result.

[0017] The second aspect of the application provides a dynamic induction-based identity authentication device applied to a terminal device, the dynamic induction-based identity authentication device including:

[0018] A dynamic induction unit configured to send an identity of the terminal device to a mobile terminal in response to the mobile terminal moving to an induction area of the terminal device in an induction state, wherein the mobile terminal is in the induction state after a client performs identity authentication through a target application program running on the mobile terminal and selects a terminal device type in the target application program.

[0019] An identity information receiving unit configured to receive client identity information sent by a first server, the client identity information being obtained by the first server after receiving an authentication token sent by the mobile terminal and parsing the authentication token, the authentication token further including the identity of the terminal device.

[0020] An identity information displaying unit configured to display the client identity information in a preset format and prompt the client to input verification information corresponding to the client identity information.

[0021] A verification information sending unit configured to send the verification information input by the client to the first server to enable the first server to match the verification information with client reserved information.

[0022] An operation interface displaying unit configured to display an operation interface after the client performs identity authentication through the terminal device in response to a login instruction sent by the first server after determining that the verification information matches the client reserved information.

[0023] The third aspect of the application provides a terminal device, comprising at least one processor and a memory connected to the processor, wherein:

[0024] The memory is used for storing a computer program;

[0025] The processor is used for executing the computer program, so that the terminal device can implement the dynamic induction-based identity authentication method of the first aspect or any implementation manner of the first aspect.

[0026] The fourth aspect of the application provides an identity authentication system, comprising a mobile terminal, a terminal device and a first server;

[0027] The target application program is run on the mobile terminal, and the customer passes through the identity authentication of the target application program, and after the customer selects the terminal device type in the target application program, the mobile terminal is in an induction state;

[0028] The mobile terminal moves to the induction area of the terminal device, obtains the identity of the terminal device, and sends an authentication token carrying the customer identity information and the identity of the terminal device to the first server;

[0029] The first server parses the authentication token to obtain the customer identity information and the identity of the terminal device, and sends the customer identity information to the terminal device according to the identity of the terminal device;

[0030] After receiving the customer identity information, the terminal device displays the customer identity information in a preset format, prompts the customer to input the verification information corresponding to the customer identity information, and sends the verification information input by the customer to the first server;

[0031] The first server matches the verification information with the customer reserved information, and sends a login instruction to the terminal device after determining that the verification information matches the customer reserved information;

[0032] The terminal device displays the operation interface of the customer after the identity authentication through the terminal device in response to the login instruction.

[0033] In a possible implementation, the first server is further used for sending identity authentication pass receipt information to the mobile terminal after determining that the verification information matches the customer reserved information;

[0034] The mobile terminal is further used for judging whether the communication range between the terminal device exceeds a threshold value after receiving the receipt information; if the threshold value is exceeded, an abnormal transaction signal is generated, and the abnormal transaction signal is sent to the first server;

[0035] The first server is further configured to send a transaction termination instruction to the terminal device after receiving the abnormal transaction signal.

[0036] In a possible implementation, the mobile terminal encapsulates the customer identity information, the identifier of the terminal device, the time stamp and the invalidation time to generate the authentication token.

[0037] The first server parses the authentication token to obtain the customer identity information, the identifier of the terminal device, the time stamp and the invalidation time, judges whether the authentication token is invalid according to the time stamp and the invalidation time, sends the customer identity information to the terminal device according to the identifier of the terminal device if the authentication token is not invalid, and feeds back authentication token invalidation information to the mobile terminal if the authentication token is invalid.

[0038] In a possible implementation, the system further comprises a second server, and the second server is located at a network point where the terminal device is located.

[0039] The first server sends the customer identity information to the second server according to the identifier of the terminal device, and the second server is configured to forward the customer identity information to the terminal device.

[0040] The second server is further configured to forward the verification information to the first server after receiving the verification information sent by the terminal device.

[0041] The fifth aspect of the present application provides a computer program product comprising computer readable instructions, which, when executed on a terminal device, cause the terminal device to implement the identity authentication method based on dynamic induction of the first aspect or any implementation manner of the first aspect.

[0042] By the technical scheme, the application provides a dynamic induction-based identity authentication method and related device. After a customer authenticates an identity through a target application program running on a mobile terminal and selects a terminal device type in the target application program, the mobile terminal is in an induction state. The mobile terminal in the induction state is moved to an induction area of the terminal device to obtain an identity of the terminal device. The mobile terminal sends an authentication token including the identity of the terminal device and customer identity information to a first server, establishes communication with the terminal device through the first server, and causes the terminal device to display the customer identity information and prompt the customer to input verification information. After the customer inputs the verification information, the verification information is sent to the first server. The first server sends a login instruction to the terminal device after determining that the verification information matches customer reserved information, so that the terminal device displays an operation interface after the customer authenticates an identity through the terminal device in response to the login instruction. The identity authentication of the customer through the terminal device is completed based on dynamic induction between the mobile terminal and the terminal device. The entire identity authentication process does not require the customer to provide an identity card, a bank card or other certificates, the function of the terminal device is improved, and the customer experience is effectively improved. BRIEF DESCRIPTION OF DRAWINGS

[0043] The above and other features, advantages, and aspects of the present disclosure will become more apparent by describing in detail the following specific embodiments thereof with reference to the attached drawings. Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. It should be understood that the drawings are schematic and elements are not necessarily drawn to scale.

[0044] Figure 1 A system architecture schematic diagram is provided for the application;

[0045] Figure 2 A mobile terminal 100 or terminal device 200 structure schematic diagram is provided for the application;

[0046] Figure 3 A first server 300 structure schematic diagram is provided for the application;

[0047] Figure 4 A dynamic induction-based identity authentication method flow schematic diagram is provided for the application;

[0048] Figure 5 A dynamic induction-based identity authentication device structure schematic diagram is provided for the application. DETAILED DESCRIPTION

[0049] The embodiments of the application are described below with reference to the accompanying drawings. The terms used in the embodiment part of the application are only used to explain the specific embodiments of the application, and are not intended to limit the application.

[0050] The embodiments of the present application will be described below in conjunction with the drawings. It can be known by those skilled in the art that the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems as the technology develops and new scenarios appear.

[0051] The terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, and this is only a way of distinguishing the objects with the same attributes in the description of the embodiments of the present application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that the processes, methods, systems, products or devices containing a series of units do not have to be limited to those units, but can include other units not clearly listed or inherent to these processes, methods, products or devices.

[0052] The identity authentication method and related device based on dynamic induction provided by the present application can be applied in the field of Internet of Things or the field of finance. The above is only an example and does not limit the application field of the identity authentication method and related device based on dynamic induction provided by the present application.

[0053] It should be noted that the customer information (including but not limited to customer device information, customer personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the customer or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0054] Reference is made to Figure 1 , Figure 1 A system architecture diagram is shown. The system can include a mobile terminal 100, a terminal device 200 and a first server 300. The first server 300 can include one or more servers (one server is taken as an example in the description), and the first server 300 can provide the method provided by the embodiments of the present application for one or more terminal devices. Figure 1

[0055] The mobile terminal 100 can install a target application program, such as a mobile banking APP (application), and the above application program can provide an interface. The mobile terminal 100 can receive the relevant parameters input by the customer on the interface of the target application program, such as identity authentication information and terminal device type, and send the above parameters to the first server 300. The first server 300 can obtain a processing result based on the received parameters, and return the processing result to the mobile terminal 100. ​

[0056] The terminal device 200 can be installed with an application, such as an application of a self-service cash machine. The application can provide an interface, and the terminal device 200 can receive relevant parameters input by a customer on the interface, such as verification information, and send the parameters to the first server 300. The first server 300 can obtain a processing result based on the received parameters, and return the processing result to the terminal device 200.

[0057] Next, the product forms of the mobile terminal 100 and the terminal device 200 are described. Figure 1

[0058] The mobile terminal 100 in the embodiments of the present application can be a mobile phone, a tablet computer, a wearable device, an augmented reality (AR) / virtual reality (VR) device, and the like. The embodiments of the present application do not make any limitation in this regard.

[0059] The terminal device 200 in the embodiments of the present application can be a self-service cash machine, a smart counter, a flow printing machine, and the like. The embodiments of the present application do not make any limitation in this regard.

[0060] Figure 2 An optional hardware structure schematic diagram of the mobile terminal 100 or the terminal device 200 is shown.

[0061] Reference is made to Figure 2 As shown, the mobile terminal 100 or the terminal device 200 can include a radio frequency unit 110, a memory 120, an input unit 130, a display unit 140, a camera 150 (optional), an audio circuit 160 (optional), a speaker 161 (optional), a microphone 162 (optional), a headphone jack 163 (optional), a processor 170, an external interface 180, a power supply 190, and the like. Those skilled in the art can understand that Figure 2 The above-mentioned components are only examples of the mobile terminal 100 or the terminal device 200, and do not constitute a limitation on the mobile terminal 100 or the terminal device 200. The mobile terminal 100 or the terminal device 200 can include more or fewer components than those shown, or combine certain components, or include different components.

[0062] ​The input unit 130 can be used to receive inputted digital or character information, and to generate key signal input related to user settings and function control of the portable multifunctional device. Specifically, the input unit 130 can include a touch screen 131 (optional) and / or other input devices 132. The touch screen 131 can collect touch operations of a user thereon or thereabout (such as operations of a user using a finger, a knuckle, a stylus, or any suitable object on or near the touch screen), and drive corresponding connected devices according to pre-set programs. The touch screen can detect touch actions of a user on the touch screen, convert the touch actions into touch signals and send the touch signals to the processor 170, and can receive commands from the processor 170 and execute the commands; the touch signals at least include touch point coordinate information. The touch screen 131 can provide an input interface and an output interface between the mobile terminal 100 or the terminal device 200 and a user. In addition, the touch screen can be implemented in various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch screen 131, the input unit 130 can also include other input devices. Specifically, the other input devices 132 can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, on-off keys, etc.), trackballs, mice, joysticks, etc.

[0063] The input device 132 can receive inputted data, etc.

[0064] The display unit 140 can be used to display information input by a user or information provided to a user, various menus of the mobile terminal 100 or the terminal device 200, interactive interfaces, file displays, and / or playing of any kind of multimedia files. In the embodiments of the present application, the display unit 140 can be used to display interfaces of the mobile terminal 100 or the terminal device 200, processing results, etc.

[0065] The storage 120 can be used to store instructions and data. The storage 120 can mainly include a storage instruction area and a storage data area. The storage data area can store various data such as multimedia files, texts, etc.; the storage instruction area can store software units such as operating systems, applications, instructions required by at least one function, etc., or their subsets, expanded sets. It can also include a non-volatile random access memory; to provide the processor 170 with software and applications that include managing hardware, software, and data resources in a computing processing device, supporting control. It is also used for the storage of multimedia files, and the storage of running programs and applications.

[0066] The processor 170 is a control center of the mobile terminal 100 or the terminal device 200, connects each part of the mobile terminal 100 or the terminal device 200 by various interfaces and lines, performs various functions and processes data of the mobile terminal 100 or the terminal device 200 by running or executing instructions stored in the memory 120 and calling data stored in the memory 120, and thus controls the mobile terminal 100 or the terminal device 200 as a whole. Optionally, the processor 170 can include one or more processing units; preferably, the processor 170 can integrate an application processor and a modem processor, wherein the application processor mainly processes an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 170. In some embodiments, the processor, the memory, and the like can be implemented on a single chip, and in some embodiments, they can also be implemented on separate chips, respectively. The processor 170 can also be used to generate corresponding operation control signals to send to corresponding components of the computing processing device, read and process data in the software, especially read and process data and programs in the memory 120, so that each functional module therein performs corresponding functions, and thus controls the corresponding components to act according to the requirements of the instructions.

[0067] The memory 120 can be used to store software codes related to the dynamic induction-based identity authentication method, and the processor 170 can perform the steps of the dynamic induction-based identity authentication method, or can also dispatch other units (such as the above-mentioned input unit 130 and the display unit 140) to realize corresponding functions.

[0068] The RF unit 110 (optional) can be used for transmitting and receiving information or signals in the process of information or communication, for example, receiving the downlink information of the base station, and processing by the processor 170. In addition, the uplink data is sent to the base station. Generally, the RF circuit includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF unit 110 can also communicate with network devices and other devices through wireless communication. The wireless communication can use any communication standard or protocol, including but not limited to global system for mobile communication (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short messaging service (SMS), etc.

[0069] In the embodiments of the present application, the RF unit 110 can send data to the first server 300 and receive the processing result sent by the first server 300.

[0070] It should be understood that the RF unit 110 is optional, which can be replaced by other communication interfaces, for example, it can be a network interface.

[0071] The mobile terminal 100 or the terminal device 200 also includes a power supply 190 (such as a battery) for supplying power to each component. Preferably, the power supply can be logically connected to the processor 170 through a power management system, so as to realize the functions of managing charging, discharging and power consumption management through the power management system.

[0072] The mobile terminal 100 or the terminal device 200 also includes an external interface 180, which can be a standard MicroUSB interface, or a multi-pin connector, which can be used to connect the mobile terminal 100 or the terminal device 200 with other devices for communication, or can be used to connect a charger for charging the mobile terminal 100 or the terminal device 200.

[0073] Although not shown, the mobile terminal 100 or the terminal device 200 can further include a flash, a wireless fidelity (WiFi) module, a Bluetooth module, sensors of different functions, etc., which are not described here. Some or all of the methods described below can be applied in the mobile terminal 100 or the terminal device 200 as shown. Figure 2

[0074] Next, the product form of the first server 300 is described. Figure 1

[0075] Figure 3 A structural diagram of the first server 300 is provided, as shown in Figure 3 The first server 300 includes a bus 201, a processor 202, a communication interface 203, and a memory 204. The processor 202, the memory 204, and the communication interface 203 communicate through the bus 201.

[0076] The bus 201 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 In the description, only one thick line is used, but it does not mean that there is only one bus or only one type of bus.

[0077] The processor 202 can be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.

[0078] The memory 204 can include a volatile memory, such as a random access memory (RAM). The memory 204 can also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a mechanical hard drive (HDD), or a solid state drive (SSD).

[0079] ​​The memory 204 can be configured to store software code related to the dynamic induction-based identity authentication method, and the processor 202 can execute the steps of the dynamic induction-based identity authentication method of the chip, and can also dispatch other units to implement corresponding functions.

[0080] It should be understood that the first server 300 described above can be a centralized or distributed device, and the processors (for example, the processor 170 and the processor 202) in the mobile terminal 100, the terminal device 200 and the first server 300 can be hardware circuits (such as an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, etc.) or a combination of these hardware circuits. For example, the processor can be a hardware system with an execution instruction function, such as a CPU, a DSP, etc., or a hardware system without an execution instruction function, such as an ASIC, an FPGA, etc., or a combination of the hardware system without the execution instruction function and the hardware system with the execution instruction function.

[0081] In order to facilitate the understanding of the technical solutions provided in the present application, the following will be described through a specific application scenario.

[0082] With the mobile terminal being a smart phone, the terminal device being a self-service cash dispenser, and the first server being a bank core system server as an example, the smart phone runs a mobile banking APP, the customer passes the identity authentication of the mobile banking APP, and the customer selects the terminal device type as the self-service cash dispenser in the mobile banking APP, and then the smart phone is in a sensing state. The smart phone is close to the sensing area of the self-service cash dispenser, acquires the identifier of the self-service cash dispenser, and sends an authentication token carrying the customer identity information and the identifier of the self-service cash dispenser to the bank core system server. The bank core system server parses the authentication token to obtain the customer identity information and the identifier of the self-service cash dispenser, and sends the customer identity information to the self-service cash dispenser according to the identifier of the self-service cash dispenser, so as to establish a communication connection between the smart phone and the self-service cash dispenser. After receiving the customer identity information, the self-service cash dispenser displays the customer identity information after desensitization processing, such as replacing one character in the customer's name with an asterisk, and prompts the customer to input the verification information corresponding to the customer identity information, such as inputting the last four digits of the customer's reserved mobile phone number in the bank or inputting the last four digits of the customer's ID card number. The self-service cash dispenser sends the customer input verification information to the bank core system server, and the bank core system server matches the verification information with the customer's reserved information. If the two match, a login instruction is sent to the self-service cash dispenser. The self-service cash dispenser displays the operation interface of the customer after the identity authentication of the self-service cash dispenser in response to the login instruction, and the customer can operate on the operation interface to perform balance inquiry, deposit or withdrawal operation. The entire identity authentication process does not require the customer to provide identity cards, bank cards and other certificates, realizes the functional improvement of the self-service cash dispenser, and effectively improves the customer experience.

[0083] Reference Figure 4 , Figure 4 A flowchart of an identity authentication method based on dynamic induction provided by the embodiments of the present application is shown in FIG. 1. The identity authentication method based on dynamic induction provided by the embodiments of the present application can include steps 401 to 405, which are described in detail as follows. Figure 4

[0084] 401. In response to the mobile terminal in a sensing state moving to the sensing area of the terminal device, sending the identifier of the terminal device to the mobile terminal;

[0085] Wherein, after the customer passes the identity authentication of the target application program running on the mobile terminal, and the customer selects the terminal device type in the target application program, the mobile terminal is in a sensing state.

[0086] For example, in a bank scenario, the mobile terminal is a smart phone, the target application program is a mobile banking APP, and the customer identity authentication mode of the target application program can be face recognition, fingerprint recognition, voiceprint recognition, password login, etc.​

[0087] Different terminal device types have different security levels, different security levels correspond to different verification manners, and different terminal device types can support different short-distance communication manners. By selecting a terminal device type, the mobile terminal can subsequently perform dynamic induction communication with the terminal device according to the short-distance communication manner supported by the terminal device type. For example, if the short-distance communication manner supported by the terminal device type is NFC (Near Field Communication), the mobile terminal subsequently moves to the induction area of the terminal device, and performs dynamic induction communication with the terminal device by using NFC. If the short-distance communication manner supported by the terminal device is RFID (Radio Frequency Identification), the mobile terminal subsequently moves to the induction area of the terminal device, and performs dynamic induction communication with the terminal device by using RFID.

[0088] 402. receiving the customer identity information sent by the first server;

[0089] The customer identity information is obtained by the first server after receiving the authentication token sent by the mobile terminal and parsing the authentication token. The authentication token also includes the identifier of the terminal device.

[0090] It should be noted that after the mobile terminal obtains the identifier of the terminal device, the mobile terminal generates an authentication token carrying the customer identity information and the identifier of the terminal device, and sends the authentication token to the first server, so that the first server sends the customer identity information in the authentication token to the terminal device, and establishes a communication connection between the mobile terminal and the terminal device.

[0091] Taking a bank scenario as an example, the first server is a bank core system server, and the terminal device is a self-service deposit and withdrawal machine of a bank outlet. The bank core system server determines the target bank outlet server corresponding to the identifier of the self-service deposit and withdrawal machine according to the correspondence between the identifier of the self-service deposit and withdrawal machine and the bank outlet, and the correspondence between the bank outlet and the bank outlet server. The bank core system server sends the customer identity information and the identifier of the self-service deposit and withdrawal machine to the target bank outlet server, so that the target bank outlet server sends the customer identity information to the self-service deposit and withdrawal machine according to the identifier of the self-service deposit and withdrawal machine.

[0092] The customer identity information includes but is not limited to the customer's name.

[0093] 403. displaying the customer identity information in a preset format, and prompting the customer to input the verification information corresponding to the customer identity information;

[0094] In order to protect the privacy of the customer, the customer identity information is desensitized according to a preset format, and the desensitized customer identity information is displayed, for example, one character in the customer name is replaced by *.

[0095] The purpose of prompting the customer to input the verification information corresponding to the customer identity information is to improve the security of identity authentication, for example, prompting the customer to input the last four digits of the customer's bank-registered mobile phone number, prompting the customer to input the last four digits of the customer's ID card number, prompting the customer to input a face image, prompting the customer to input voiceprint information, prompting the customer to input a fingerprint, etc.

[0096] 404. The verification information input by the customer is sent to the first server to enable the first server to match the verification information with the customer's reserved information;

[0097] For example, the verification information is the last four digits of the customer's bank-registered mobile phone number, and the first server matches the verification information with the last four digits of the customer's bank-registered mobile phone number.

[0098] For example, the verification information is the last four digits of the customer's ID card number, and the first server matches the verification information with the last four digits of the customer's bank-registered ID card number.

[0099] For example, the verification information is a face image, and the first server matches the verification information with the customer's reserved face image.

[0100] 405. In response to the login instruction sent by the first server after determining that the verification information matches the customer's reserved information, an operation interface after the identity authentication of the customer through the terminal device is displayed.

[0101] If the first server determines that the verification information matches the customer's reserved information, it is determined that the verification is passed, and the terminal device displays an operation interface after the identity authentication of the customer through the terminal device in response to the login instruction sent by the first server. The operation interface is the same as the operation interface displayed after the customer passes the identity authentication by inserting a bank card and inputting a password.

[0102] If the first server determines that the verification information does not match the customer's reserved information, it sends a verification failure information to the mobile terminal and / or the terminal device.

[0103] The embodiment discloses an identity authentication method based on dynamic induction. After a customer authenticates the identity through a target application program running on a mobile terminal and selects a terminal device type in the target application program, the mobile terminal is in an induction state. The mobile terminal in the induction state moves to an induction area of the terminal device and acquires an identity of the terminal device. The mobile terminal sends an authentication token including the identity of the terminal device and customer identity information to a first server, establishes communication with the terminal device through the first server, and causes the terminal device to display the customer identity information and prompt the customer to input verification information. After the customer inputs the verification information, the verification information is sent to the first server. The first server sends a login instruction to the terminal device after determining that the verification information matches the customer's reserved information, so that the terminal device displays an operation interface of the customer after the identity authentication through the terminal device in response to the login instruction. The identity authentication of the customer through the terminal device is completed based on the dynamic induction between the mobile terminal and the terminal device. The entire identity authentication process does not require the customer to provide identity cards, bank cards and other certificates, the function of the terminal device is improved, and the customer experience is effectively improved.

[0104] To further optimize the above embodiment, after the terminal device displays the operation interface of the customer after the identity authentication through the terminal device, the following steps are further included:

[0105] A1: in response to an operation instruction initiated by the customer on the operation interface, executing a transaction corresponding to the operation instruction;

[0106] Taking the terminal device as an automatic teller machine as an example, in response to a balance inquiry instruction initiated by the customer on the operation interface, a balance inquiry transaction is executed; in response to a withdrawal instruction initiated by the customer on the operation interface, a withdrawal transaction is executed; and in response to a deposit instruction initiated by the customer on the operation interface, a deposit transaction is executed.

[0107] A2: acquiring transaction environment information in the transaction process, the transaction environment information including at least one of transaction environment images and transaction environment audio information;

[0108] Taking the terminal device as an automatic teller machine as an example, the transaction environment is an ATM (Automated Teller Machine) protective cabin.

[0109] During the entire transaction process from the beginning of the transaction to the end of the transaction, the transaction environment images and the transaction environment audio can be periodically sampled to acquire the transaction environment information.

[0110] A3: sending the transaction environment information to the first server to cause the first server to perform anomaly detection on the transaction environment information.

[0111] Exemplarily, the first server matches the transaction environment information with the exception library information to perform exception detection. The exception library information is pre-constructed and includes various exception information. Taking the transaction environment information as a transaction environment image as an example, the exception library information includes various exception image information. Taking the transaction environment information as transaction environment audio information as an example, the exception library information includes various exception audio information. If the matching degree between the transaction environment information and the exception library information is greater than a threshold, the exception detection result is a transaction exception.

[0112] Further, if the exception detection result is a transaction exception, the first server sends a transaction termination instruction to the terminal device, and the terminal device terminates the current transaction in response to the transaction termination instruction.

[0113] Further, the mobile terminal can also monitor the communication range between the mobile terminal and the terminal device during the transaction process. If the communication range exceeds a threshold, the mobile terminal generates exception transaction information and sends the exception transaction information to the first server. After receiving the exception transaction signal, the first server also sends a transaction termination instruction to the terminal device, and the terminal device terminates the current transaction in response to the transaction termination instruction.

[0114] By monitoring the transaction environment during the transaction process of the terminal device, the transaction security is further improved.

[0115] The above introduces a dynamic induction-based identity authentication method provided by the embodiments of the present application. The following will introduce a device for executing the dynamic induction-based identity authentication method.

[0116] Please refer to Figure 5 , Figure 5 FIG. 1 is a structural schematic diagram of a dynamic induction-based identity authentication device provided by the embodiments of the present application. As shown in the figure, the dynamic induction-based identity authentication device includes: Figure 5

[0117] The dynamic induction unit 501 is configured to send the identity of the terminal device to the mobile terminal in response to the mobile terminal in the induction state moving to the induction area of the terminal device. After the customer is authenticated by the target application program running on the mobile terminal and the customer selects the terminal device type in the target application program, the mobile terminal is in the induction state.

[0118] The identity information receiving unit 502 is configured to receive the customer identity information sent by the first server. The customer identity information is obtained by the first server after analyzing the authentication token received by the mobile terminal. The authentication token also includes the identity of the terminal device.

[0119] ​The identity information display unit 503 is configured to display the customer identity information in a preset format and prompt the customer to input verification information corresponding to the customer identity information.

[0120] The verification information sending unit 504 is configured to send the verification information input by the customer to the first server, so that the first server matches the verification information with customer reservation information.

[0121] The operation interface display unit 505 is configured to display an operation interface after the customer is authenticated by the terminal device in response to a login instruction sent by the first server after determining that the verification information matches the customer reservation information.

[0122] In a possible implementation, the method further includes:

[0123] The transaction execution unit is configured to execute a transaction corresponding to an operation instruction initiated by the customer on the operation interface.

[0124] The transaction environment information acquisition unit is configured to acquire transaction environment information in a transaction process, the transaction environment information including at least one of a transaction environment image and transaction environment audio information.

[0125] The transaction environment information sending unit is configured to send the transaction environment information to the first server, so that the first server performs anomaly detection on the transaction environment information.

[0126] In a possible implementation, the method further includes:

[0127] The transaction termination unit is configured to terminate a current transaction in response to a transaction termination instruction sent by the first server, wherein the transaction termination instruction is generated by the first server according to an anomaly detection result.

[0128] This embodiment discloses a dynamic sensing-based identity authentication device. After a customer authenticates their identity through a target application running on a mobile terminal and selects a terminal device type within the application, the mobile terminal enters a sensing state. The sensing mobile terminal moves to the sensing area of ​​the terminal device and acquires the terminal device's identifier. The mobile terminal sends an authentication token containing the terminal device's identifier and the customer's identity information to a first server, establishing communication with the terminal device through the first server. This allows the terminal device to display the customer's identity information and prompt the customer to input verification information. After the customer inputs the verification information, it is sent to the first server. The first server, after confirming that the verification information matches the customer's pre-registered information, sends a login command to the terminal device, causing the terminal device to display the user interface indicating successful authentication. This device achieves customer identity authentication on the terminal device based on dynamic sensing between the mobile terminal and the terminal device. The entire authentication process does not require the customer to provide identification documents such as ID cards or bank cards, thus improving the functionality of the terminal device and effectively enhancing the customer experience.

[0129] This application also provides an identity authentication system; please refer to [link / reference]. Figure 1 It includes a mobile terminal 100, a terminal device 200, and a first server 300;

[0130] The target application runs on the mobile terminal 100. After the customer authenticates their identity through the target application and selects the terminal device type in the target application, the mobile terminal 100 is in a sensing state.

[0131] The mobile terminal 100 moves to the sensing area of ​​the terminal device 200, obtains the identifier of the terminal device 200, and sends an authentication token carrying customer identity information and the identifier of the terminal device 200 to the first server 300.

[0132] The first server 300 parses the authentication token to obtain the customer identity information and the identifier of the terminal device 200, and sends the customer identity information to the terminal device 200 according to the identifier of the terminal device 200;

[0133] After receiving the customer identity information, the terminal device 200 displays the customer identity information in a preset format, prompts the customer to enter the verification information corresponding to the customer identity information, and sends the verification information entered by the customer to the first server 300.

[0134] The first server 300 matches the verification information with the customer's reserved information, and after determining that the verification information matches the customer's reserved information, sends a login command to the terminal device 200;

[0135] The terminal device 200 displays an operation interface after the customer is authenticated by the terminal device 200 in response to the login instruction.

[0136] In a possible implementation, the first server 300 is further configured to send, to the mobile terminal 100, a reply information of passing the authentication after determining that the check information matches the customer reservation information.

[0137] The mobile terminal 100 is further configured to determine whether a communication range between the mobile terminal 100 and the terminal device 200 exceeds a threshold value after receiving the reply information, generate an abnormal transaction signal if the communication range exceeds the threshold value, and send the abnormal transaction signal to the first server 300.

[0138] The first server 300 is further configured to send, to the terminal device 200, a transaction termination instruction after receiving the abnormal transaction signal.

[0139] The communication range between the mobile terminal 100 and the terminal device 200 is the distance between the mobile terminal 100 and the terminal device 200. When the distance between the mobile terminal 100 and the terminal device 200 exceeds the threshold value, it indicates that the distance between the mobile terminal 100 and the terminal device 200 is too far, which is beyond the normal distance of the customer operating the terminal device, and there may be a security risk. At this time, the abnormal transaction signal is generated to make the terminal device terminate the transaction, thereby improving the security of the transaction.

[0140] In a possible implementation, the authentication system further includes a second server, and the second server is located at a network point where the terminal device is located.

[0141] The first server sends the customer identity information to the second server according to the identifier of the terminal device, and the second server is configured to forward the customer identity information to the terminal device.

[0142] The second server is further configured to forward the check information to the first server after receiving the check information sent by the terminal device.

[0143] Taking a bank scenario as an example, a bank system covers a large number of terminal devices, in order to improve the communication efficiency between the first server and the terminal device, the second server can be used as a communication relay. For example, the first server is a bank core system server, the terminal device is a self-service deposit and withdrawal machine of a bank branch, and the second server is a bank branch server. The bank core system server determines the target bank branch server corresponding to the identifier of the self-service deposit and withdrawal machine according to the corresponding relationship between the identifier of the self-service deposit and withdrawal machine and the bank branch and the corresponding relationship between the bank branch and the bank branch server. The bank core system server sends the customer identity information and the identifier of the self-service deposit and withdrawal machine to the target bank branch server, so that the target bank branch server sends the customer identity information to the self-service deposit and withdrawal machine according to the identifier of the self-service deposit and withdrawal machine. Correspondingly, when the self-service deposit and withdrawal machine needs to send information to the bank core system, it returns along the original route, that is, the self-service deposit and withdrawal machine first sends data to the bank branch server, and then the bank branch server sends the data to the bank core system server.

[0144] The identity authentication system disclosed in the embodiment enables a customer to complete identity authentication in a target application program running on a mobile terminal, and enables a link to be established between the mobile terminal and a terminal device and automatic authentication to be completed when the terminal device is used, thereby simplifying the use of the terminal device and expanding the use approach of the terminal device. The entire identity authentication process does not require the customer to provide an identity card, a bank card or the like, thereby realizing functional improvement of the terminal device and effectively improving customer experience.

[0145] The terminal device provided in the embodiment of the present application comprises at least one processor and a memory connected to the processor, wherein:

[0146] The memory is configured to store a computer program.

[0147] The processor is configured to execute the computer program, so that the terminal device can implement any one of the identity authentication methods based on dynamic induction provided in the embodiments of the present application.

[0148] The embodiment of the present application further provides a computer program product comprising computer readable instructions, which, when executed on a terminal device, enable the terminal device to implement any one of the identity authentication methods based on dynamic induction provided in the embodiments of the present application.

[0149] The embodiment of the present application further provides a computer readable storage medium, which carries one or more computer programs, which, when executed by a terminal device, enable the terminal device to implement any one of the identity authentication methods based on dynamic induction provided in the embodiments of the present application.

[0150] In addition, it should be noted that the apparatus embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. In addition, the connection relationship between the modules in the apparatus embodiments provided in the present application indicates that there is a communication connection between them, which can be implemented as one or more communication buses or signal lines.

[0151] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and the necessary general hardware, and of course can also be realized by special hardware including special integrated circuits, special CPUs, special memories, special components, etc. Generally, functions completed by computer programs can be easily realized by corresponding hardware, and the specific hardware structure for realizing the same function can also be various, such as analog circuit, digital circuit or special circuit, etc. However, for the present application, software program implementation is a better embodiment. Based on this understanding, the technical solutions of the present application can be embodied in the form of software products, which are stored in readable storage media, such as computer floppy disks, U disks, mobile hard disks, ROM, RAM, magnetic or optical disks, etc., including a plurality of instructions for making a computer device (which can be a personal computer, a training device, or a network device, etc.) execute the methods described in various embodiments of the present application.

[0152] In the above embodiments, all or part can be realized by software, hardware, firmware or any combination thereof. When realized by software, it can be realized in the form of a computer program product in whole or in part.

[0153] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, training device or data center to another website, computer, training device or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be stored by the computer or a data storage device such as a training device, a data center, etc. integrated with one or more available media sets. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.

Claims

1. A dynamic induction based identity authentication method, characterized in that, The application is applied to a terminal device, and the dynamic induction-based identity authentication method comprises the following steps: In response to a mobile terminal in an induction state moving to an induction area of the terminal device, an identity of the terminal device is sent to the mobile terminal, wherein the mobile terminal is in the induction state after a customer is authenticated by a target application program running on the mobile terminal and the customer selects a terminal device type in the target application program; Customer identity information sent by a first server is received, wherein the customer identity information is obtained by the first server after analyzing an authentication token after receiving the authentication token sent by the mobile terminal, and the authentication token further comprises the identity of the terminal device; The customer identity information is displayed in a preset format, and the customer is prompted to input verification information corresponding to the customer identity information; The verification information input by the customer is sent to the first server, so that the first server matches the verification information with customer reservation information; In response to a login instruction sent by the first server after determining that the verification information matches the customer reservation information, an operation interface after the customer is authenticated by the terminal device is displayed.

2. The dynamic induction based identity authentication method of claim 1, wherein, After the operation interface after the customer is authenticated by the terminal device is displayed, the following steps are further included: In response to an operation instruction initiated by the customer on the operation interface, a transaction corresponding to the operation instruction is executed; Transaction environment information in a transaction process is obtained, wherein the transaction environment information comprises at least one of a transaction environment image and transaction environment audio information; The transaction environment information is sent to the first server, so that the first server performs anomaly detection on the transaction environment information.

3. The dynamic induction based identity authentication method of claim 2, wherein, The following steps are further included: In response to a transaction termination instruction sent by the first server, a current transaction is terminated; The transaction termination instruction is generated by the first server according to an anomaly detection result.

4. A dynamic induction based identity authentication device, characterized in that, The application is applied to a terminal device, and the dynamic induction-based identity authentication device comprises the following units: A dynamic induction unit is configured to send an identity of the terminal device to a mobile terminal in an induction state in response to the mobile terminal moving to an induction area of the terminal device, wherein the mobile terminal is in the induction state after a customer is authenticated by a target application program running on the mobile terminal and the customer selects a terminal device type in the target application program; An identity information receiving unit is configured to receive customer identity information sent by a first server, wherein the customer identity information is obtained by the first server after analyzing an authentication token after receiving the authentication token sent by the mobile terminal, and the authentication token further comprises the identity of the terminal device; An identity information displaying unit is configured to display the customer identity information in a preset format and prompt the customer to input verification information corresponding to the customer identity information; A verification information sending unit is configured to send the verification information input by the customer to the first server, so that the first server matches the verification information with customer reservation information; and A transaction environment information sending unit is configured to send transaction environment information in a transaction process to the first server, so that the first server performs anomaly detection on the transaction environment information. The operation interface display unit is configured to display an operation interface of the terminal device after the client is authenticated by the terminal device in response to a login instruction sent by the first server after determining that the check information matches the client reservation information.

5. A terminal device, characterized by, The system comprises at least one processor and a memory connected to the processor, wherein: The memory is configured to store a computer program; The processor is configured to execute the computer program to enable the terminal device to implement the dynamic induction-based identity authentication method according to any one of claims 1 to 3.

6. An identity authentication system characterized by comprising: The system comprises: a mobile terminal, a terminal device, and a first server; The mobile terminal runs a target application program, and the client is authenticated by the target application program, and the mobile terminal is in an induction state after the client selects a terminal device type in the target application program; The mobile terminal moves to an induction area of the terminal device, acquires an identity of the terminal device, and sends an authentication token carrying client identity information and the identity of the terminal device to the first server; The first server parses the authentication token to obtain the client identity information and the identity of the terminal device, and sends the client identity information to the terminal device according to the identity of the terminal device; After receiving the client identity information, the terminal device displays the client identity information in a preset format, prompts the client to input check information corresponding to the client identity information, and sends the check information input by the client to the first server; The first server matches the check information with client reservation information, and sends a login instruction to the terminal device after determining that the check information matches the client reservation information; The terminal device displays an operation interface of the terminal device after the client is authenticated by the terminal device in response to the login instruction.

7. The identity authentication system of claim 6, wherein, The first server is further configured to send a receipt information of identity authentication passing to the mobile terminal after determining that the check information matches the client reservation information; The mobile terminal is further configured to determine whether a communication range between the mobile terminal and the terminal device exceeds a threshold value after receiving the receipt information, generate an abnormal transaction signal if the communication range exceeds the threshold value, and send the abnormal transaction signal to the first server; The first server is further configured to send a transaction termination instruction to the terminal device after receiving the abnormal transaction signal.

8. The identity authentication system of claim 6, wherein, The mobile terminal encapsulates the client identity information, the identity of the terminal device, a timestamp, and an invalidation time to generate the authentication token; The first server parses the authentication token to obtain the client identity information, the identity of the terminal device, the timestamp, and the invalidation time, determines whether the authentication token is invalid according to the timestamp and the invalidation time, and sends the client identity information to the terminal device according to the identity of the terminal device if the authentication token is not invalid; If the authentication token is invalid, the first server feeds back authentication token invalidation information to the mobile terminal.

9. The identity authentication system of claim 6, wherein, The system further comprises a second server, and the second server is located at a network point where the terminal device is located. The first server sends the customer identity information to the second server according to the identity of the terminal device, and the second server is configured to forward the customer identity information to the terminal device. The second server is further configured to forward the check information to the first server after receiving the check information sent by the terminal device.

10. A computer program product, characterised in that, The computer readable instructions, when executed on a terminal device, cause the terminal device to implement the identity authentication method based on dynamic induction according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Application login method and device, terminal and storage medium

    CN111241499A

  • Business processing method and device for intelligent counter

    CN114861153A