Identity authentication method, device, terminal device and storage medium

By receiving the business type instruction of the authentication terminal, using the user identification card to obtain the target security data and perform comparison authentication, the security risks and adaptability problems of portrait authentication in the existing technology are solved, and efficient identity authentication is achieved in various business scenarios.

CN118797602BActive Publication Date: 2025-09-19CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311353116.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-18
Publication Date
2025-09-19
Estimated Expiration
2043-10-18

AI Technical Summary

Technical Problem

Existing portrait authentication methods pose security risks, are difficult to adapt to the identity authentication needs of various business scenarios, and data security is difficult to guarantee.

Method used

By receiving the business type instruction of the authentication terminal, the preset user identification card is used to obtain the target security data, and it is sent to the authentication application. It is compared and authenticated with the collected user data, and the super security of the user identification card is used to obtain security data of different business types to adapt to various scenarios.

Benefits of technology

It improves the security of data transmission and can perform identity authentication in accordance with different types of authentication application scenarios, thereby improving the accuracy and adaptability of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118797602B_ABST
    Figure CN118797602B_ABST
Patent Text Reader

Abstract

This application discloses an identity authentication method, apparatus, terminal device, and storage medium, relating to the field of identity authentication. The method comprises: receiving an authentication instruction sent by an authentication terminal, the authentication instruction including a service type; obtaining target security data corresponding to the service type in the authentication instruction through a preset user identification card, and sending the target security data to an authentication application; collecting user data to be authenticated through the authentication application, comparing the user data to be authenticated with the target security data, and obtaining an authentication result. The present invention not only ensures the security of data during the authentication process, but also allows identity authentication to be tailored to different application scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of identity authentication, and in particular to an identity authentication method, apparatus, terminal equipment and storage medium. Background Art

[0002] With the continuous development of information technology, society has entered the digital age, with an increasing number of transactions and services taking place online. In this digital society, a more efficient, convenient, and secure authentication method is needed. Currently, facial recognition is a widely used authentication method. It has significant applications in a variety of fields, including security and surveillance, social entertainment, advertising and marketing, and education research, bringing convenience and innovation to our lives.

[0003] However, the existing portrait authentication method usually stores the portrait data in the user's super SIM card. During authentication, the user's current portrait data is collected through the terminal and compared with the user's portrait data stored in the super SIM card. If the comparison is consistent, the authentication is passed. However, this method still has certain security risks and is difficult to adapt to the various business scenarios involved in the user authentication process. Summary of the Invention

[0004] The main purpose of the present invention is to provide an identity authentication method, apparatus, terminal device and storage medium, which can ensure the security of data during the authentication process and can perform identity authentication in accordance with different types of application scenarios.

[0005] To achieve the above object, the present invention provides an identity authentication method, which includes:

[0006] receiving an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a service type;

[0007] Acquire target security data corresponding to the service type in the authentication instruction through a preset user identification card, and send the target security data to the authentication application;

[0008] The authentication application collects user data to be authenticated, compares the user data to be authenticated with the target security data, and obtains an authentication result.

[0009] Optionally, before the step of receiving the authentication instruction sent by the authentication terminal, the step includes:

[0010] Based on a preset authentication application, user facial image data and a plurality of voice data recorded for different service types are obtained, and original security data is obtained based on the user facial image data and the plurality of voice data;

[0011] providing the original security data to the user identification card through the authentication application;

[0012] The step of obtaining target security data corresponding to the service type in the authentication instruction through a preset user identification card and sending the target security data to the authentication application includes:

[0013] Target security data corresponding to the service type in the authentication instruction is acquired from the original security data through the user identification card, and the target security data is sent to the authentication application.

[0014] Optionally, after the step of obtaining user facial image data and a plurality of voice data recorded for different service types based on a preset authentication application, the step further includes:

[0015] extracting, by the authentication application, keywords of the voice data from the plurality of voice data, the keywords corresponding to the service types;

[0016] The correspondence between the keywords and the service types and the original security data are provided to a user identification card, so that the user identification card can perform user identity authentication in combination with the authentication application.

[0017] Optionally, before the step of receiving the authentication instruction sent by the authentication terminal, the step includes:

[0018] Obtain user facial image data and multiple voice data recorded for different service types through the authentication application, extract keywords from the voice data, the keywords corresponding to the service types, and obtain original security data based on the user facial image data and multiple voice data;

[0019] Uploading the original security data to blockchain storage through the authentication application, so that the blockchain provides target security data to the user identification card;

[0020] Receiving the storage credential returned by the blockchain through the authentication application;

[0021] Sending the stored credentials and the correspondence between the service type and the keyword to the user identification card through the authentication application;

[0022] The corresponding relationship between the business type and the keyword is encrypted by the user identification card and sent to the blockchain for storage and obtaining the corresponding access credentials, so that the user identification card can perform user identity authentication in combination with the authentication application.

[0023] Optionally, the step of acquiring target security data corresponding to the service type in the authentication instruction through a preset user identification card and sending the target security data to the authentication application includes:

[0024] Obtaining a corresponding target storage credential according to the business type in the authentication instruction through the user identification card, and obtaining target security data corresponding to the business type in the authentication instruction from the original security data stored in the blockchain according to the target storage credential;

[0025] The corresponding target access credentials are obtained through the user identification card according to the business type in the authentication instruction. According to the target access credentials, the correspondence between the business type and the keyword is obtained from the blockchain to obtain the corresponding target keyword for the authentication application to perform user identity authentication.

[0026] Optionally, the step of collecting user data to be authenticated through the authentication application, comparing and authenticating the user data to be authenticated with the security data, and obtaining an authentication result includes:

[0027] sending a target keyword corresponding to the service type in the authentication instruction to the authentication application via the user identification card;

[0028] The authentication application displays a target keyword corresponding to the business type in the authentication instruction, collects user data to be authenticated based on the target keyword, compares and authenticates the user data to be authenticated with the security data, and obtains an authentication result.

[0029] Optionally, the step of obtaining original security data based on the user facial image data and the plurality of voice data includes:

[0030] By means of the authentication application, transforming and compressing the user face image data and the plurality of voice data, to obtain a data preprocessing result;

[0031] Encrypting the data preprocessing result using pixels of the face image at a preset position to obtain a data encryption result;

[0032] Performing pseudo-random sequence processing on the data encryption result to obtain a scrambling matrix result;

[0033] The scrambled matrix result is packaged to obtain original security data.

[0034] The present application also provides an identity authentication device, which includes:

[0035] An authentication instruction receiving module is used to receive an authentication instruction sent by an authentication terminal;

[0036] A data acquisition module, configured to acquire target security data corresponding to the service type in the authentication instruction through a preset user identification card;

[0037] A data sending module, configured to send the target security data to an authentication application;

[0038] A data collection module, used to collect user data to be authenticated through the authentication application;

[0039] The data authentication module is used to compare and authenticate the user data to be authenticated with the target security data to obtain an authentication result.

[0040] An embodiment of the present application also proposes a terminal device, which includes a memory, a processor, and an identity authentication program stored in the memory and executable on the processor. When the identity authentication program is executed by the processor, the steps of the identity authentication method described above are implemented.

[0041] An embodiment of the present application further provides a computer-readable storage medium, on which an identity authentication program is stored. When the identity authentication program is executed by a processor, the steps of the identity authentication method described above are implemented.

[0042] The identity authentication method, apparatus, terminal device, and storage medium proposed in the embodiments of the present application receive an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a service type; obtain target security data corresponding to the service type in the authentication instruction through a preset user identification card, and send the target security data to an authentication application; collect user data to be authenticated through the authentication application, compare and authenticate the user data to be authenticated with the target security data, and obtain an authentication result. Thus, when the preset user identification card receives the authentication instruction sent by the authentication terminal, it obtains the target security data corresponding to the service type in the authentication instruction and sends the security data to the authentication application for subsequent authentication preparation. When the authentication application receives the security data, it collects the user data to be authenticated and compares and authenticates the user data to be authenticated with the received security data, obtains the authentication result, and feeds it back to the authentication terminal. Since the target security data is obtained by the user identification card based on the service type in the authentication instruction, the user identification card will obtain different target security data according to different service types for the authentication application to authenticate the user. In this way, the user identification card's own strong security is utilized to not only better ensure data security during the data acquisition process, but also to perform identity authentication in accordance with different authentication application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 This is a schematic diagram of the functional modules of the terminal device to which the identity authentication device of this application belongs;

[0044] Figure 2 This is the overall architecture diagram of the identity authentication system embodiment of this application;

[0045] Figure 3 This is a flowchart of the first exemplary embodiment of the identity authentication method of this application;

[0046] Figure 4 This is a flowchart of a second exemplary embodiment of the identity authentication method of this application;

[0047] Figure 5 Schematic diagram of the interface for entering user information for this application's identity authentication method;

[0048] Figure 6 This is a flowchart of a third exemplary embodiment of the identity authentication method of this application;

[0049] Figure 7 This is a flowchart of a fourth exemplary embodiment of the identity authentication method of this application;

[0050] Figure 8 This is a flowchart of a fifth exemplary embodiment of the identity authentication method of this application;

[0051] Figure 9 This is a flowchart of a sixth exemplary embodiment of the identity authentication method of this application;

[0052] Figure 10 Schematic diagram of the interface for entering user information for this application's identity authentication method;

[0053] Figure 11 This is a flowchart of the seventh exemplary embodiment of the identity authentication method of this application;

[0054] Figure 12 This is a schematic diagram of the overall process of the identity authentication method for this application.

[0055] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0056] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0057] The main solution of the embodiment of the present application is: by receiving an authentication instruction sent by an authentication terminal, the authentication instruction includes a business type; obtaining target security data corresponding to the business type in the authentication instruction through a preset user identification card, and sending the target security data to the authentication application; collecting user data to be authenticated through the authentication application, comparing and authenticating the user data to be authenticated with the target security data, and obtaining an authentication result. Thus, when the preset user identification card receives the authentication instruction sent by the authentication terminal, it obtains the target security data corresponding to the business type in the authentication instruction, and sends the security data to the authentication application for subsequent authentication preparation. When the authentication application receives the security data, it collects the user data to be authenticated and compares and authenticates the user data to be authenticated with the received security data, obtains the authentication result, and feeds it back to the authentication terminal. Since the security data is obtained by the user identification card based on the business type in the authentication instruction, the user identification card will obtain different security data according to different business types for the authentication application to authenticate the authenticated user. This method can not only better ensure the security of data in the process of obtaining data by leveraging the super security of the user identification card itself, but also can be used to fit different types of authentication application scenarios for identity authentication.

[0058] The embodiments of the present application take into account that with the development of society, more and more business scenarios require identity authentication, and the security requirements for identity authentication in various business scenarios are becoming higher and higher. The existing technical solutions mainly perform identity identification on authenticated users in a single business scenario, which cannot be adapted to multiple business scenarios for identity authentication and cannot guarantee the security of data during the authentication process.

[0059] Based on this, an embodiment of the present application proposes a solution. When identity authentication is required, an authentication instruction is sent to a user identification card through an authentication terminal. After receiving the authentication instruction from the authentication terminal, the user identification card obtains target security data based on the business type in the authentication instruction and sends the target security data to the authentication application. The authentication application collects the user data to be authenticated and compares the user data to be authenticated with the received target security data for authentication, obtains the authentication result, and feeds it back to the authentication terminal. Since the security data is obtained by the user identification card based on the business type in the authentication instruction, the user identification card will obtain different security data based on different business types for the authentication application to compare with the authenticated user. In this way, the user identification card's own strong security is utilized to not only better ensure data security during the data acquisition process, but also to perform identity authentication in accordance with different authentication application scenarios.

[0060] Specifically, refer to Figure 1 , Figure 1This is a functional module diagram of the terminal device to which the identity authentication device of this application belongs. The identity authentication device can be a device independent of the terminal device that can process data, or it can be hosted on the terminal device in the form of hardware or software.

[0061] In this embodiment, the terminal device to which the identity authentication apparatus belongs includes at least an output module 110 , a processor 120 , a memory 130 and a communication module 140 .

[0062] The memory 130 stores an operating system and an identity authentication program. It receives authentication instructions sent by the authentication terminal, including a service type. It obtains target security data corresponding to the service type in the authentication instruction through a pre-installed user identification card and sends the target security data to the authentication application. The authentication application collects user data to be authenticated, compares the user data to be authenticated with the target security data, and obtains an authentication result. The authentication instruction, target security data, authentication result, etc. can be stored in the memory 130. The output module 110 can be a display screen, a speaker, etc. The communication module 140 can include a Wi-Fi module, a mobile communication module, and a Bluetooth module, etc., and communicates with external devices or servers through the communication module 140.

[0063] When the identity authentication program in the memory 130 is executed by the processor, the following steps are implemented:

[0064] Receive an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a business type; obtain target security data corresponding to the business type in the authentication instruction through a preset user identification card, and send the target security data to an authentication application; collect user data to be authenticated through the authentication application, compare and authenticate the user data to be authenticated with the target security data, and obtain an authentication result.

[0065] Furthermore, when the identity authentication program in the memory 130 is executed by the processor, the following steps are also implemented:

[0066] Based on a preset authentication application, user facial image data and a plurality of voice data recorded for different service types are obtained, and original security data is obtained based on the user facial image data and the plurality of voice data;

[0067] providing the original security data to the user identification card through the authentication application;

[0068] Target security data corresponding to the service type in the authentication instruction is acquired from the original security data through the user identification card, and the target security data is sent to the authentication application.

[0069] Furthermore, when the identity authentication program in the memory 130 is executed by the processor, the following steps are also implemented:

[0070] extracting, by the authentication application, keywords of the voice data from the plurality of voice data, the keywords corresponding to the service types;

[0071] The correspondence between the keywords and the service types and the original security data are provided to a user identification card, so that the user identification card can perform user identity authentication in combination with the authentication application.

[0072] Furthermore, when the identity authentication program in the memory 130 is executed by the processor, the following steps are also implemented:

[0073] Obtain user facial image data and multiple voice data recorded for different service types through the authentication application, extract keywords from the voice data, the keywords corresponding to the service types, and obtain original security data based on the user facial image data and multiple voice data;

[0074] Uploading the original security data to blockchain storage through the authentication application, so that the blockchain provides target security data to the user identification card;

[0075] Receiving the storage credential returned by the blockchain through the authentication application;

[0076] Sending the stored credentials and the correspondence between the service type and the keyword to the user identification card through the authentication application;

[0077] The corresponding relationship between the business type and the keyword is encrypted by the user identification card and sent to the blockchain for storage and obtaining the corresponding access credentials, so that the user identification card can perform user identity authentication in combination with the authentication application.

[0078] Furthermore, when the identity authentication program in the memory 130 is executed by the processor, the following steps are also implemented:

[0079] Obtaining a corresponding target storage credential according to the business type in the authentication instruction through the user identification card, and obtaining target security data corresponding to the business type in the authentication instruction from the original security data stored in the blockchain according to the target storage credential;

[0080] The corresponding target access credentials are obtained through the user identification card according to the business type in the authentication instruction. According to the target access credentials, the correspondence between the business type and the keyword is obtained from the blockchain to obtain the corresponding target keyword for the authentication application to perform user identity authentication.

[0081] Furthermore, when the identity authentication program in the memory 130 is executed by the processor, the following steps are also implemented:

[0082] sending a target keyword corresponding to the service type in the authentication instruction to the authentication application via the user identification card;

[0083] The authentication application displays a target keyword corresponding to the business type in the authentication instruction, collects user data to be authenticated based on the target keyword, compares and authenticates the user data to be authenticated with the security data, and obtains an authentication result.

[0084] Furthermore, when the identity authentication program in the memory 130 is executed by the processor, the following steps are also implemented:

[0085] By means of the authentication application, transforming and compressing the user face image data and the plurality of voice data, to obtain a data preprocessing result;

[0086] Encrypting the data preprocessing result using pixels of the face image at a preset position to obtain a data encryption result;

[0087] Performing pseudo-random sequence processing on the data encryption result to obtain a scrambling matrix result;

[0088] The scrambled matrix result is packaged to obtain original security data.

[0089] This embodiment, through the above-mentioned scheme, receives an authentication instruction sent by an authentication terminal, the authentication instruction including a service type; obtains target security data corresponding to the service type in the authentication instruction through a preset user identification card, and sends the target security data to the authentication application; the authentication application collects user data to be authenticated, compares and authenticates the user data to be authenticated with the target security data, and obtains an authentication result. Because the security data is obtained by the user identification card based on the service type in the authentication instruction, the user identification card will obtain different security data based on different service types for the authentication application to authenticate the user. In this way, the user identification card's inherently strong security is utilized to not only better ensure data security during the data acquisition process, but also to facilitate identity verification in accordance with different authentication application scenarios.

[0090] Reference Figure 2 , Figure 2 This is the overall architecture diagram of the identity authentication system for this application.

[0091] like Figure 2As shown, the identity authentication method architecture of this application includes a user mobile terminal, an authentication application, a user identification card, an authentication terminal and a blockchain. The user mobile terminal is pre-installed with an authentication application and a user identification card.

[0092] Among them, the user's mobile terminal serves as a blockchain node for accessing the blockchain; the user identification card can be a super SIM card; and the authentication terminal can be a terminal device with authentication requirements.

[0093] Based on the above terminal device and system architecture but not limited to the above architecture, an embodiment of the method of the present application is proposed.

[0094] Reference Figure 3 , Figure 3 This is a flowchart of the first exemplary embodiment of the identity authentication method of this application.

[0095] An embodiment of the present invention provides an identity authentication method, the method comprising:

[0096] Step S40: receiving an authentication instruction sent by the authentication terminal, wherein the authentication instruction includes a service type;

[0097] Among them, the authentication terminal refers to a terminal device with authentication requirements. The authentication requirement refers to the need to authenticate or authorize the user when using a certain system, device or service. Only authenticated or authorized users can obtain corresponding access rights or rights. Its purpose is to ensure that only authorized or authenticated users can use the device, thereby protecting the security and confidentiality of the device and related resources.

[0098] Among them, the terminal device refers to the device for authenticating identity. Specifically, the device will implement certain security mechanisms to ensure that only authenticated users can use the device or access restricted resources on the device. The terminal device can be an all-in-one terminal, card reader, cash register, etc. set up in scenarios such as banks, airports, and shopping malls.

[0099] Specifically, the authentication instruction sent by the authentication terminal includes a business type, wherein the business type may be a business type that requires authentication of the user identity, such as financial services, e-commerce, medical services, government agency services, and telecommunication services.

[0100] It can be seen from the above business types and scenarios that with the development and progress of society, the scenarios and business types that require user identity authentication are also constantly increasing. However, the existing identity authentication technology is relatively single and cannot fit the various business scenarios involved in the user authentication process. It cannot adapt to the current society's demand for identity authentication security and multi-scenario applications.

[0101] Therefore, this embodiment proposes to receive the authentication instruction sent by the authentication terminal through the user identification card, obtain the target security data corresponding to the business type in the authentication instruction, and send the security data to the authentication application for authentication preparation. When the authentication application receives the security data, it collects the user data to be authenticated and compares the user data to be authenticated with the received security data for authentication, obtains the authentication result and feeds it back to the authentication terminal. Since the security data is obtained by the user identification card according to the business type in the authentication instruction, the user identification card can obtain the corresponding security data according to different business types for the authentication application to authenticate the authenticated user. In this way, the user identification card itself has super strong security, which can not only better protect the security of data in the process of obtaining data, but also can be used to fit different types of authentication application scenarios for identity authentication.

[0102] Furthermore, by sending target security data corresponding to different business types to the authentication application, the authentication application can be helped to authenticate user information of different business types, thereby improving the accuracy of identity authentication.

[0103] Specifically, before the authentication instruction is issued, the user can establish a connection between the mobile terminal and the authentication terminal through near field communication. Through this connection, the authentication terminal can send an authentication instruction to the user identification card in the mobile terminal to promote the subsequent identity recognition process.

[0104] Mobile devices can be portable, making it easier for users to authenticate their identities in different scenarios. These devices can include smartphones, tablets, smartwatches, and other devices with information collection capabilities. The specific choice depends on the specific application scenario and requirements.

[0105] Step S50, obtaining target security data corresponding to the service type in the authentication instruction through a preset user identification card, and sending the target security data to the authentication application;

[0106] When the preset user identification card receives an authentication instruction from the authentication terminal, it searches for target security data corresponding to the service type in the card according to the service type in the authentication instruction.

[0107] To address identity authentication in different business scenarios, it's crucial to use the user identification card to identify the target security data corresponding to that business type. For example, in an authentication scenario where payment is the business type, the user identification card obtains the target security data corresponding to the payment business and sends it to the authentication application, prompting the authentication application to collect the user's payment data. This accurately matches the authentication scenario for payment as the business type, effectively preventing the authentication application from collecting data from users of other business types, and improving the accuracy and efficiency of collecting data from users.

[0108] It is understandable that when the business type in the authentication instruction changes, the target security data obtained by the user identification card will also change accordingly, and the authentication application will also collect different user data to be authenticated, with the aim of achieving accurate authentication of user information under different business types.

[0109] Among them, the user identification card can use the BIP channel transmission method to transmit the target security data to the authentication application.

[0110] Specifically, the BIP channel refers to conducting data transactions at the lower layer of the transmission channel and submitting the final results to the transmission channel only when necessary, thus avoiding the tedious process of each transaction entering the upper layer of the transmission channel. Since transactions can be carried out quickly and cheaply in the BIP channel without waiting for confirmation from the upper layer of the transmission channel, high transaction fees will not be incurred, and the security of data transmission can be guaranteed at a low cost.

[0111] Furthermore, in each authentication triggering process, the user identification card deletes the target security data after sending it to the authentication application, and does not retain any related data to ensure data security.

[0112] Step S60: collecting user data to be authenticated through the authentication application, comparing the user data to be authenticated with the target security data, and obtaining an authentication result;

[0113] After the authentication application receives the target security data sent from the user identification card, the authentication application collects data of the user to be authenticated, compares the collected data with the target security data for authentication, and feeds back the comparison authentication result to the authentication terminal to complete the user's identity identification.

[0114] Specifically, the user data to be authenticated collected by the authentication application includes facial image data and voice data.

[0115] The collected facial image data may include:

[0116] Facial image: A facial image refers to a static image of a user's face obtained through a camera or other image acquisition device. A facial image shows a person's facial features, including eyes, nose, mouth, eyebrows, chin, etc.

[0117] Facial key points: Facial key points are the locations of specific facial areas marked in a face image. These key points usually include feature points such as the eyes, nose, mouth, eyebrows, and facial contours.

[0118] Facial feature vector: A facial feature vector is a numerical expression extracted from a facial image by a face recognition algorithm. It is usually composed of a series of numbers and is used to represent the unique features of a face, such as facial contour, eye distance, nose shape, etc.

[0119] Lighting and color information: When collecting facial image data, data including lighting conditions and color information can also be collected. This data is used to describe the brightness, contrast, color saturation and other attributes of the facial image, which helps to improve the accuracy of the facial recognition algorithm.

[0120] Image quality assessment: Image quality assessment indicators are used to evaluate factors such as clarity, blur, and noise of facial images.

[0121] Simply put, the collected facial image data includes the facial image itself, as well as face-related location information, feature vectors, lighting color information, and image quality assessment data. These data play an important role in applications such as face recognition, facial expression analysis, and facial age and gender recognition.

[0122] The collected voice data may include:

[0123] Voice recording: Voice recording refers to the user's voice signals obtained through a microphone or other sound collection device. These voice signals can be the sounds produced by the user speaking or reading specific text.

[0124] Voiceprint features: Voiceprint features are numerical expressions extracted from voice data using speech recognition algorithms. They represent individual voice characteristics, including pitch, timbre, speaking speed, and rhythm. Voiceprint features are understood to be a unique encoding of an individual's voice, similar to the role of fingerprints in human identification.

[0125] Voice quality assessment: Voice quality assessment can be used to evaluate factors such as clarity, noise, and voice distortion of voice data.

[0126] Simply put, the collected facial image data includes voice recordings, voiceprint features, voice quality and other data, which play an important role in applications such as voiceprint recognition and voice identity verification.

[0127] Furthermore, after the authentication application collects the information of the user to be authenticated, it compares the information of the user to be authenticated with the target security data to obtain a comparison result.

[0128] Among them, the face data comparison method can use methods such as extracting comparison feature values, calculating Euclidean distance or cosine similarity, etc.

[0129] The comparison method of speech data can use audio preprocessing, cepstral coefficients, linear predictive coding and other methods.

[0130] The comparison results can be identical or different.

[0131] Furthermore, after the authentication terminal receives the authentication result from the authentication application, the authentication terminal can determine whether the identity of the user to be authenticated is legal based on the authentication result, and perform access control on the user. For example, when the comparison result is different, the authentication terminal determines that the identity of the user to be authenticated is illegal and rejects the user's access request. When the authentication result is the same, the authentication terminal can allow the user to enter a restricted area, use specific functions or obtain specific permissions.

[0132] In addition, the authentication terminal may also send a notification of the authentication result to the user to be authenticated.

[0133] When the authentication terminal determines that the identity of the user to be authenticated is legitimate, the terminal can notify the user of successful authentication through sound, screen display, or other means, and provide corresponding services. If the authentication terminal determines that the identity of the user to be authenticated is invalid, the terminal can notify the user of failed authentication and resend the authentication instruction to the user identification card to re-authenticate the identity of the user to be authenticated or take other security measures.

[0134] The identity authentication method proposed in the embodiment of the present application receives an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a business type; obtains target security data corresponding to the business type in the authentication instruction through a preset user identification card, and sends the target security data to an authentication application; collects user data to be authenticated through the authentication application, compares and authenticates the user data to be authenticated with the target security data, and obtains an authentication result. Since the security data is obtained by the user identification card based on the business type in the authentication instruction, the user identification card will obtain the corresponding security data according to different business types for the authentication application to authenticate the user. In this way, the user identification card itself has a strong security, which can not only better ensure the security of data in the process of acquiring data, but also can be used to fit different types of authentication application scenarios for identity authentication.

[0135] Reference Figure 4 , Figure 4 This is a flowchart of the second exemplary embodiment of the identity authentication method of this application.

[0136] Based on the first embodiment, a second embodiment of the present application is proposed. The difference between the second embodiment of the present application and the first embodiment is that:

[0137] In this embodiment, in step S40, an authentication instruction sent by the authentication terminal is received. The authentication instruction includes the following before the service type:

[0138] Step S10: Based on a preset authentication application, obtain user facial image data and a plurality of voice data recorded for different service types, and obtain original security data based on the user facial image data and the plurality of voice data;

[0139] Step S30, providing the original security data to the user identification card through the authentication application;

[0140] In addition, in this embodiment, the above step S50 includes:

[0141] Step S51 : acquiring target security data corresponding to the service type in the authentication instruction from the original security data through the user identification card, and sending the target security data to the authentication application.

[0142] Specifically, step S10, based on a preset authentication application, obtains user facial image data and a plurality of voice data recorded for different service types, and obtains original security data based on the user facial image data and the plurality of voice data;

[0143] Before the user performs identity authentication, the user needs to make preparations in the authentication application.

[0144] Specifically, the user needs to load an authentication application in the mobile terminal so that the user can store identity information for future identity authentication in the authentication application.

[0145] The mobile terminal used by the user can be a smart phone, tablet computer, smart watch or other device with Internet access and information collection function.

[0146] Furthermore, the authentication application provides the user with a window for entering user information, and the information that the user needs to enter includes the user's facial image and voice data.

[0147] After the authentication application collects the user's information, it generates original security data based on the collected information.

[0148] Figure 5 Schematic diagram of the interface for entering user information for this application's identity authentication method.

[0149] like Figure 5As shown, the user logs in to the authentication application, and the authentication application may provide option buttons, such as input information. The next level menu of input information may set two option buttons: face image and voice data.

[0150] When the user selects the face data button, a camera capture box appears. After the user confirms, the authentication application can collect the user's face data through the camera of the user's mobile terminal.

[0151] When the user selects the Voice Data button, an input box appears. For example, if the user enters "Payment," "Confidential," or "General" in the input box, the authentication app will generate three corresponding option buttons. Each time the user selects an option button, a recording capture box appears. The authentication app can then use the recording capture box to capture the three voice data entries for each of the three service types: Payment, Confidential, and General.

[0152] It is understandable that the authentication application will generate a related service type display based on the service type input by the user to prompt the user which service type of voice data currently needs to be stored.

[0153] Specifically, for step S30, the original security data is provided to the user identification card through the authentication application;

[0154] After the authentication application generates original security data based on the collected information, it needs to send the original security data to the user identification card for the user identification card to process the original security data.

[0155] Specifically, the user identification card processes the original security data in the following ways:

[0156] Encrypted storage: The received original security data is encrypted and stored in encrypted form in the user identification card to prevent unauthorized access and leakage.

[0157] Access control: Through the access control mechanism preset in the user identification card, the access rights to the original security data are restricted. Only authenticated and authorized users or legitimate applications can access this data.

[0158] Secure transmission: When the original security data needs to be transmitted to other devices or servers, an encrypted communication protocol can be used to ensure the security of the original security data during transmission.

[0159] Secure deletion: When the original security data is no longer needed, it can be completely deleted using a secure method to prevent malicious access.

[0160] Risk monitoring and response: Establish an effective risk monitoring mechanism to monitor abnormal fluctuations in raw security data in real time and take appropriate response measures, such as alarms and access blocking.

[0161] Specifically, in step S51, target security data corresponding to the service type in the authentication instruction is acquired from the original security data via the user identification card, and the target security data is sent to the authentication application.

[0162] The target security data is obtained from the original security data through the user identification card according to the service type in the authentication instruction.

[0163] The original security data includes user identity data corresponding to various service types. Since each service type corresponds to one piece of user identity data, when the user identification card receives an authentication instruction, it identifies the service type in the authentication instruction and searches the original security data for the user identity data corresponding to that service type.

[0164] Furthermore, the user identity data is sent to the authentication application via the user identification card for comparison.

[0165] The identity authentication method proposed in the embodiment of the present application obtains original security data through the user facial image data obtained by the authentication application and several voice data recorded for different business types, and sends the original security data to the user identification card. The user identification card searches for the target security data in the original security data through the received authentication instruction and sends the found target security data back to the authentication application. This process utilizes the user identification card's super security attributes and data processing capabilities to complete the processing and transmission of the original security data, providing higher security for the identity authentication process.

[0166] Reference Figure 6 , Figure 6 This is a flowchart of the third exemplary embodiment of the identity authentication method of this application.

[0167] Based on the second embodiment, the third embodiment of the present application is proposed. The difference between the third embodiment of the present application and the second embodiment is that:

[0168] In this embodiment, in step S10, based on a preset authentication application, user facial image data and a plurality of voice data recorded for different service types are obtained. After obtaining the original security data based on the user facial image data and the plurality of voice data, the following steps are further included:

[0169] Step S20: extracting keywords of the voice data from the plurality of voice data through the authentication application, where the keywords correspond to the service types.

[0170] In addition, in this embodiment, the above step S30 includes:

[0171] Step S31 : providing the correspondence between the keyword and the service type and the original security data to a user identification card, so that the user identification card can perform user identity authentication in combination with the authentication application.

[0172] Specifically, in step S20, keywords of the voice data are extracted from the plurality of voice data through the authentication application, where the keywords correspond to the service types.

[0173] After the user stores several voice data for future identity authentication in the authentication application, the authentication application extracts keywords from the voice data to extract the keywords of the voice data corresponding to different business types. Since the extracted keywords come from the voice data corresponding to different business types, the keywords and business types have a mutual correspondence. Simply put, when you know a certain keyword or a certain business type, you can know the business type corresponding to the keyword or the keyword corresponding to the business type.

[0174] Specifically, when the authentication application performs keyword extraction on the three pieces of voice data respectively, three pieces of text information are obtained, and then semantic recognition is performed on the three pieces of text information to extract three groups of keywords.

[0175] For example, when the voice message stored by the user for the payment service is converted into text as: I want to become a tycoon, the keyword extracted by the authentication application is: Monopoly, then the keyword Monopoly corresponds to the payment service.

[0176] When the voice information stored by the user for confidential business is converted into text as: Heaven knows, Earth knows, open the door with sesame seeds, and the keywords extracted by the authentication application are: Heaven, Earth, and Sesame seeds, then the keywords Heaven, Earth, and Sesame seeds correspond to confidential business.

[0177] When the voice message stored by the user for routine business is converted into text as: Jiji Ru Lüling, and the keywords extracted by the authentication application are: Ji, Lüling, then the keywords Ji, Lüling correspond to routine business.

[0178] The above three examples are just examples. Users can enter any voice according to their needs to suit the different business types input by users.

[0179] Specifically, in step S31 , the correspondence between the keyword and the service type and the original security data are provided to the user identification card, so that the user identification card can perform user identity authentication in combination with the authentication application.

[0180] Specifically, the authentication application determines the correspondence between the extracted keywords and the business type based on the extracted keywords and the business type from which they come, and provides the correspondence and the original security data to the user identification card so that the user identification card and the authentication application can cooperate with each other during the authentication process to complete the identity authentication of the user to be authenticated.

[0181] The identity authentication method proposed in the embodiment of the present application extracts keywords of the voice data from the multiple voice data through the authentication application, and the keywords correspond to the business types; the correspondence between the keywords and the business types and the original security data are provided to the user identification card, so that the user identification card can perform user identity authentication in combination with the authentication application. Since different keywords come from voice data in different business types, when the authentication application sends the correspondence between the keywords and the business types to the user identification card for subsequent identity authentication of the authenticated user, it can meet the authentication requirements under different business types and has a wider range of applicable scenarios.

[0182] Reference Figure 7 , Figure 7 This is a flowchart of the fourth exemplary embodiment of the identity authentication method of this application.

[0183] Based on the first embodiment, a fourth embodiment of the present application is proposed. The fourth embodiment of the present application differs from the first embodiment in that:

[0184] In this embodiment, in step S40, an authentication instruction sent by the authentication terminal is received. The authentication instruction includes the following before the service type:

[0185] Step S101: Obtain user facial image data and multiple voice data recorded for different service types through the authentication application, extract keywords from the voice data, where the keywords correspond to the service types, and obtain original security data based on the user facial image data and multiple voice data;

[0186] Before the user performs identity authentication, the user needs to store the identity information for future identity authentication in the authentication application of the mobile terminal in advance. After the authentication application collects the information stored by the user, the authentication application will generate original security data.

[0187] Among them, after the authentication application collects the user's information, the authentication application will extract keywords based on the voice data in the user information. Since the keywords are extracted from the voice data in the corresponding business type, the authentication application will obtain the correspondence between the keywords and the business type.

[0188] Step S102, uploading the original security data to a blockchain storage through the authentication application, so that the blockchain can provide the target security data to the user identification card;

[0189] Blockchain is a distributed ledger technology used to record data and transactions, ensuring their security and transparency. Simply put, a blockchain is a chain structure consisting of a series of data blocks, each containing some transaction information and linked to the previous block through cryptographic methods.

[0190] Because the biggest feature of blockchain is decentralization and immutability, it does not rely on central institutions or third-party trust. Instead, it maintains and confirms the accuracy and integrity of data through multiple nodes in the network. Once the data is uploaded to the blockchain for storage, it is almost impossible to modify or delete, so it has high security.

[0191] Taking advantage of the ultra-high security of blockchain, the authentication application uploads the generated original security data to the blockchain for storage, which can effectively protect the original security data from being leaked or destroyed.

[0192] Among them, ways to upload original security data to the blockchain for storage can be to use blockchain storage platforms, create your own smart contracts, and utilize existing applications and protocols.

[0193] Uploading the original security data to the blockchain for storage facilitates retrieval of the user identification card during future authentication.

[0194] Step S103: receiving the storage credential returned by the blockchain through the authentication application;

[0195] When uploading original security data to the blockchain for storage, the authentication application needs to call the corresponding application programming interface or smart contract function and provide parameters related to the uploaded data.

[0196] Among them, these parameters may include the data itself, storage location, access rights, etc. At the same time, after calling the program programming interface or smart contract function, the blockchain will return a storage certificate to indicate that the data has been successfully uploaded to the blockchain.

[0197] The storage credential can be used for subsequent verification and query of uploaded data. Simply put, the storage credential is a unique identifier that can be used to track the location and status of data in the blockchain.

[0198] By storing credentials, authentication applications can verify whether the data has been successfully uploaded to the blockchain and is readily available. In addition, stored credentials can also be used for data traceability and auditing to ensure data integrity and immutability.

[0199] Step S104, sending the stored credentials and the correspondence between the service type and the keyword to the user identification card through the authentication application;

[0200] After receiving the storage credentials returned from the blockchain, the authentication application sends the corresponding relationship between the storage credentials, business types and keywords to the user identification card.

[0201] Step S105: The correspondence between the service type and the keyword is encrypted by the user identification card and sent to the blockchain for storage and obtaining a corresponding access credential for the user identification card to perform user identity authentication in combination with the authentication application;

[0202] After the user identification card receives the correspondence between the business type and the keyword and the storage certificate sent by the authentication application, the correspondence between the business type and the keyword is encrypted and uploaded to the blockchain for storage.

[0203] Encryption is the process of converting original data into a form that is difficult to understand or decipher by using a specific algorithm. The purpose is to protect the security of the data. The encryption method can be:

[0204] Symmetric encryption algorithm: Symmetric encryption uses the same key to encrypt and decrypt data.

[0205] Asymmetric encryption: Asymmetric encryption uses a pair of keys, including a public key and a private key. The public key is used to encrypt data, and the private key is used to decrypt data.

[0206] Hybrid encryption: Use an asymmetric encryption algorithm to securely exchange symmetric encryption keys, and then use the symmetric encryption algorithm to encrypt and decrypt the actual data.

[0207] After the user identification card encrypts the corresponding relationship and uploads it to the blockchain for storage, it obtains the access credentials returned by the blockchain.

[0208] Among them, the access credential is a kind of evidence that the user identification card uploads data to the blockchain, which is used to prove that the user identification card is the data upload end, making it easier for the user identification card to obtain relevant data in the future.

[0209] The identity authentication method proposed in the embodiment of the present application uploads the original security data to the blockchain storage through the authentication application, so that the blockchain provides the target security data to the user identification card; receives the storage certificate returned by the blockchain through the authentication application; sends the storage certificate and the correspondence between the business type and the keyword to the user identification card through the authentication application; encrypts the correspondence between the business type and the keyword through the user identification card and sends it to the blockchain for storage and obtains the corresponding access certificate, so that the user identification card can perform user identity authentication in combination with the authentication application, and the authentication application sends the obtained storage certificate to the user identification card for storage, so that the user identification card can use the storage certificate to retrieve the data uploaded to the blockchain by the authentication application through the blockchain, thereby realizing data sharing. Using the blockchain for data storage and using the certificate to retrieve the blockchain data can ensure the security of data storage, improve the transparency and credibility of the data, and reduce the possibility of human error and tampering.

[0210] Reference Figure 8 , Figure 8 This is a flowchart of the fifth exemplary embodiment of the identity authentication method of this application.

[0211] Based on the fourth embodiment, a fifth embodiment of the present application is proposed. The difference between the fifth embodiment of the present application and the fourth embodiment is that:

[0212] In this embodiment, in step S50, target security data corresponding to the service type in the authentication instruction is obtained through a preset user identification card, and the target security data is sent to the authentication application for refinement, wherein the refinement step includes:

[0213] Step S501: obtaining a corresponding target storage credential based on the service type in the authentication instruction through the user identification card, and obtaining target security data corresponding to the service type in the authentication instruction from the original security data stored in the blockchain based on the target storage credential;

[0214] Since the storage credentials returned by the blockchain to the authentication application are generated based on the business type in the original security data, when the user identification card obtains the storage credentials, it can find the corresponding target storage credentials based on the business type in the authentication instruction. The user identification card uses the target storage credentials to access the blockchain and obtain the target security data corresponding to the target storage credentials.

[0215] Step S502: Obtaining a corresponding target access credential based on the service type in the authentication instruction through the user identification card, obtaining a correspondence between the service type and the keyword from the blockchain based on the target access credential, and obtaining a corresponding target keyword for the authentication application to perform user identity authentication;

[0216] The user identification card uses the previously obtained access credentials returned by the blockchain to access the blockchain according to the business type in the authentication instruction to obtain the correspondence between the business type and the keyword corresponding to the business type in the authentication instruction.

[0217] The corresponding relationship between the service type and the keyword can be used to find the target keyword for subsequent sending to the authentication application for prompting the authentication user.

[0218] The identity authentication method proposed in the embodiment of the present application obtains the corresponding target storage credential according to the business type in the authentication instruction through the user identification card, and obtains the target security data corresponding to the business type in the authentication instruction from the original security data stored in the blockchain according to the target storage credential; obtains the corresponding target access credential according to the business type in the authentication instruction through the user identification card, and obtains the correspondence between the business type and the keyword from the blockchain according to the target access credential to obtain the corresponding target keyword for the authentication application to perform user identity authentication, and searches for the corresponding storage credential and access credential through the business type in the authentication instruction to access the blockchain to obtain the corresponding data, thereby achieving more secure, transparent and controllable data access, and helping to build trust and protect the security and privacy of data.

[0219] Reference Figure 9 , Figure 9 This is a flowchart of the sixth exemplary embodiment of the identity authentication method of this application.

[0220] Based on the third or fifth embodiment, a sixth embodiment of the present application is proposed. The difference between the sixth embodiment of the present application and the third or fifth embodiment is that:

[0221] In this embodiment, in step S60, the authentication application collects user data to be authenticated, compares the user data to be authenticated with the target security data, and obtains an authentication result for refinement, wherein the refinement step includes:

[0222] Step S61, sending the target keyword corresponding to the service type in the authentication instruction to the authentication application via the user identification card;

[0223] The target keyword can be sent to the authentication application through the BIP channel.

[0224] The process of data transmission through the BIP channel can include the following steps:

[0225] Participants negotiate: details and rules for establishing a BIP channel between the user identification card and the authentication application.

[0226] Channel creation: After determining the details, the user identification card and the authentication application perform a series of operations to create a BIP channel.

[0227] Data transmission: Once the channel is established, the user identification card and the authentication application can start to transmit data through the channel. The data can be encrypted and divided into small blocks for transmission to ensure security and efficiency.

[0228] Interaction and Update: The user identification card and the authentication application can interact with each other by sending messages on the established channel. The user identification card and the authentication application can agree to update the channel status, confirm transactions, or perform other operations.

[0229] Specifically, sending keywords to the authentication application can help the authentication application collect to-be-authenticated user data of the corresponding business type, thereby improving the accuracy of the collection.

[0230] like Figure 10 Schematic diagram of the interface for entering user information for this application's identity authentication method;

[0231] like Figure 10 The following example illustrates an authentication application using keywords to prompt the user. When the authentication application receives the keyword "Monopoly" from the user identification card, it displays it to the user. The user then knows that the next spoken sentence to say is "I am Monopoly." The authentication application captures the user's current facial image and the current spoken sentence "I am Monopoly."

[0232] Step S62: Displaying target keywords corresponding to the business type in the authentication instruction through the authentication application, collecting user data to be authenticated based on the target keywords, and comparing and authenticating the user data to be authenticated with the security data to obtain an authentication result;

[0233] When the authentication application receives the keyword from the user identification card, it displays it.

[0234] The display methods may include:

[0235] Text: Use text to display keywords, which can be displayed to users on the screen in different fonts, colors, sizes and formats.

[0236] Pictures: Keywords can be displayed intuitively through pictures. Static pictures or dynamic images (such as GIF) can be used to present graphical keywords, giving users a better experience.

[0237] Prompt tone: By broadcasting keywords through prompt tone, users can be reminded of the keywords displayed in the current interface, making it easier to serve more user groups.

[0238] Furthermore, after the user knows which service type's user information needs to be collected, the user uses the authentication application to input the current facial image data and the voice data corresponding to the service type.

[0239] After the authentication application collects the information entered by the user to be authenticated, it uses the entered information to compare and authenticate with the security data to obtain the authentication result.

[0240] The identity authentication method proposed in the embodiment of the present application sends the target keyword corresponding to the business type in the authentication instruction to the authentication application through the user identification card; the target keyword corresponding to the business type in the authentication instruction is displayed through the authentication application, and the user data to be authenticated is collected based on the target keyword, and the user data to be authenticated is compared and authenticated with the security data to obtain an authentication result. Among them, the method of displaying keywords in the authentication application can prompt the user to enter voice data of which business type, help the user recall the voice data related to this business type that has been entered before for future identity authentication, and improve the accuracy of identity authentication.

[0241] Reference Figure 11 , Figure 11 This is a flowchart of the seventh exemplary embodiment of the identity authentication method of this application.

[0242] Based on the fourth embodiment, a seventh embodiment of the present application is proposed. The difference between the seventh embodiment of the present application and the fourth embodiment is that:

[0243] In this embodiment, in step S101, the authentication application obtains user facial image data and multiple voice data recorded for different service types, extracts keywords from the voice data, and extracts keywords corresponding to service types. The original security data is obtained based on the user facial image data and multiple voice data, and then refined. The refinement step includes:

[0244] Step S1011: compressing the user face image data and the plurality of voice data using the authentication application to obtain a compression result;

[0245] The data compression processing method may be:

[0246] Wavelet Transform: Wavelet transform is used to decompose speech data and facial image data into wavelet coefficients of different scales and frequencies. By retaining important wavelet coefficients, the purpose of data compression can be achieved.

[0247] Huffman Coding: Huffman coding is a lossless compression algorithm that compresses data by representing symbols that appear more frequently with shorter codes and symbols that appear less frequently with longer codes.

[0248] After compression processing, facial images and voice data can obtain compression processing results, wherein the compression processing results can be composed of several observation vectors.

[0249] Step S1012, encrypting the data preprocessing result using pixels of the face image at a preset position to obtain a data encryption result;

[0250] The compression processing results M1 and M2 are encrypted to obtain the data encryption results Ms1 and Ms2. The specific calculation formula is as follows:

[0251]

[0252]

[0253] Among them, n is a constant used to calculate the sum, x represents the two-dimensional horizontal coordinate of the face image pixel, y represents the two-dimensional vertical coordinate of the face image pixel, and I1(x, y) refers to the pixel signal value of the compression processing result M1 with the two-dimensional horizontal coordinate x and the two-dimensional vertical coordinate y.

[0254] By analogy, I2(x, y) refers to the pixel signal value of the compression processing result M2 with the two-dimensional horizontal coordinate being x and the two-dimensional vertical coordinate being y.

[0255] The pre-processing results are encrypted using the pixels of the face image at preset positions. The purpose of encryption is to convert the data into an unreadable form. Only the legitimate decryptor can restore the data and access the original information.

[0256] The pixels of the face image at the preset position refer to using the pixel values ​​of the face image as a key or a part of the key to perform encryption operations on data.

[0257] Specifically, the pixels of the face image at a preset position can be used as a key to encrypt the result of data preprocessing. For example, the lowest bit of the pixel value can be used to store the binary representation of the key. In this way, the encrypted data can only be successfully restored if the correct key is provided during decryption.

[0258] Since the pixels of the face image at the preset position are determined in advance, the key can be conveniently stored or transmitted together with the data and decrypted when needed.

[0259] Step S1013, performing pseudo-random sequence processing on the data encryption result to obtain a scrambling matrix result;

[0260] For the encrypted data, a scrambling matrix is ​​obtained according to the pseudo-random sequence to obtain a scrambling matrix result.

[0261] Specifically, the random sequence processing method can be: first obtain four pseudo-random sequences, which can be generated from a chaotic system, such as G1, G2, G3 and G4, and use the pseudo-random sequences G1 and G2 to scramble the encryption results Ms1, and use the pseudo-random sequences G3 and G4 to scramble the encryption results Ms2 to obtain a scrambled matrix result.

[0262] Among them, chaotic systems are a type of nonlinear dynamical systems, which are characterized by extremely complex behaviors, highly sensitive evolution that depends on initial conditions and parameters, and seemingly random outputs.

[0263] Random sequences can be generated by chaotic systems, and the method of generating random sequences can be based on chaotic mapping or chaos generator.

[0264] Chaotic mapping is an iterative mapping whose evolution rules are characterized by nonlinear and chaotic properties. It can map an input value to another output value and generate a sequence by repeatedly iterating this mapping.

[0265] Step S1014: Packing the scrambled matrix result to obtain original security data;

[0266] Pack the scrambled matrix results to obtain the original secure data.

[0267] In order to facilitate data management, transmission, sharing and storage, data files or information need to be integrated into a whole. The packaging methods may include:

[0268] Compression packaging: compress files or data to reduce file size and facilitate transmission and storage.

[0269] Archive packaging: Package multiple files or directories into an archive file for easy management, backup, and sharing.

[0270] Container packaging: Package the application and its dependent library files and configuration files into a container to achieve consistent deployment and operation of the application in different environments.

[0271] Volume packaging: Divide a large file into multiple smaller volumes, each containing a portion of the data, and can be transferred or stored separately.

[0272] The identity authentication method proposed in the embodiment of the present application, through the authentication application, transforms and compresses the user's facial image data and the multiple voice data to obtain a data preprocessing result; uses the pixels of the facial image at a preset position to encrypt the data preprocessing result to obtain a data encryption result; performs pseudo-random sequence processing on the data encryption result to obtain a scrambled matrix result; packages the scrambled matrix result to obtain original security data, authenticates the user through the authentication application, and then compresses, encrypts and scrambles the facial image and voice data, and finally packages them into original security data, providing higher confidentiality and security for subsequent data storage.

[0273] Based on the seventh embodiment, an eighth embodiment of the present application is proposed. The eighth embodiment of the present application differs from the seventh embodiment in that:

[0274] In this embodiment, in step S1011, the authentication application compresses the user's facial image data and the plurality of voice data, and refines the compression processing results, wherein the refinement step includes:

[0275] Step S10111: performing discrete cosine transform on the user facial image data and the plurality of voice data through the authentication application to obtain observation vectors of the user facial image data and voice data after discrete cosine transform processing;

[0276] Among them, DCT (Discrete Cosine Transform) processing is performed on the face image and voice data.

[0277] Among them, DCT is a commonly used mathematical transformation method, mainly used in the fields of signal processing and data compression. Discrete cosine transform can convert a signal or image from the time domain (or spatial domain) to the frequency domain by representing the signal or image as a linear combination of a series of cosine functions.

[0278] Discrete cosine transform is widely used in audio, image and video compression. By converting signals or images into the frequency domain, the frequency domain features of the signals or images can be extracted while removing redundant information.

[0279] Among them, after discrete cosine transform processing, several observation vectors M can be formed.

[0280] Specifically, the number of observation vectors M can be selected according to the encryption level. When more observation vectors M are obtained, the encryption complexity is higher and the data is more secure. For example, if the number of observation vectors M obtained is two, the observation vectors of the user's facial image data and voice data obtained are:

[0281] M1=αP1+βA1, M2=αP2+βA2.

[0282] Among them, α and β are an observation matrix of size m rows and n columns, M is an observation vector of length m, P1 and P2 are one-dimensional image signals of length l1 and l2 respectively, A1 and A2 are input speech signals of length l3 and l4 respectively. Compression processing of facial images and speech data can effectively reduce the data volume.

[0283] Reference Figure 12 , Figure 12 This is a technical flow chart of the identity authentication method for this application.

[0284] like Figure 12 As shown, the components of the identity authentication method of this application are: authentication application, user identification card, authentication terminal and blockchain.

[0285] The technical process of the identity authentication method for this application may include the following steps:

[0286] 1. The authentication application obtains the user's facial image and multiple sets of voice data entered for different business types, and extracts the keywords corresponding to each set of voice data.

[0287] 2. The authentication application compresses and encrypts the facial image and voice data respectively, uploads the encrypted data to the blockchain for storage, and obtains the storage certificate generated by the blockchain based on each data business type. The authentication application sends the storage certificate and the correspondence between the business type and the keyword to the user identification card.

[0288] 3. The user identification card retains the storage credentials and encrypts the correspondence between the business type and the keyword and uploads it to the blockchain. The user identification card obtains the access credentials returned by the blockchain regarding the correspondence between the business type and the keyword.

[0289] 4. The authentication terminal sends an instruction to the user identification card of the user to be authenticated. The user identification card searches for the corresponding storage credentials and access credentials based on the business type in the instruction. It accesses the blockchain through the found storage credentials and access credentials and obtains the correspondence between the business type and the keyword, as well as the encrypted data packet corresponding to the storage credentials.

[0290] 5. The user identification card invokes the authentication application and sends the keywords obtained from the correspondence analysis between the service type and the keywords and the encrypted data packet to the authentication application.

[0291] 6. The authentication application displays the received keywords to the user, collects the current facial image and current voice data of the user to be authenticated, decrypts and decompresses the encrypted data packet sent by the user identification card, and compares it with the collected current facial image and current voice data of the user to be authenticated. If the comparison results are consistent, the authentication pass result is sent to the authentication terminal.

[0292] The subscriber identification card may be a super SIM card.

[0293] Super SIM card is a new type of SIM card technology that uses virtual SIM technology and has super data processing capabilities. It can effectively protect data during the identity authentication process. In addition, the super SIM card integrates the networks of multiple operators, allowing users to switch seamlessly between different operators to obtain better network coverage and service quality. It can be widely applied to various business scenarios.

[0294] In addition, an embodiment of the present application further provides an identity authentication device, comprising:

[0295] An authentication instruction receiving module is used to receive an authentication instruction sent by an authentication terminal;

[0296] A data acquisition module, configured to acquire target security data corresponding to the service type in the authentication instruction through a preset user identification card;

[0297] A data sending module, configured to send the target security data to an authentication application;

[0298] A data collection module, used to collect user data to be authenticated through the authentication application;

[0299] The data authentication module is used to compare and authenticate the user data to be authenticated with the target security data to obtain an authentication result.

[0300] For the principle and implementation process of identity authentication implemented in this embodiment, please refer to the above embodiments and will not be repeated here.

[0301] In addition, an embodiment of the present application also proposes a terminal device, which includes a memory, a processor, and an identity authentication program stored in the memory and runnable on the processor. When the identity authentication program is executed by the processor, the steps of the identity authentication method described above are implemented.

[0302] Since this identity authentication program adopts all the technical solutions of all the aforementioned embodiments when executed by the processor, it has at least all the beneficial effects brought by all the technical solutions of all the aforementioned embodiments, which will not be described one by one here.

[0303] In addition, an embodiment of the present application further provides a computer-readable storage medium, on which an identity authentication program is stored. When the identity authentication program is executed by a processor, the steps of the identity authentication method described above are implemented.

[0304] Since this identity authentication program adopts all the technical solutions of all the aforementioned embodiments when executed by the processor, it has at least all the beneficial effects brought by all the technical solutions of all the aforementioned embodiments, which will not be described one by one here.

[0305] Compared with the existing technology, the identity authentication method, apparatus, terminal device and storage medium proposed in the embodiments of the present application receive an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a business type; obtains target security data corresponding to the business type in the authentication instruction through a preset user identification card, and sends the target security data to an authentication application; collects user data to be authenticated through the authentication application, compares and authenticates the user data to be authenticated with the target security data, and obtains an authentication result. Therefore, when the preset user identification card receives the authentication instruction sent by the authentication terminal, it obtains the target security data corresponding to the business type in the authentication instruction, and sends the security data to the authentication application for subsequent authentication preparation. When the authentication application receives the security data, it collects the user data to be authenticated and compares the user data to be authenticated with the received security data for authentication, obtains the authentication result and feeds it back to the authentication terminal. Since the security data is obtained by the user identification card based on the business type in the authentication instruction, the user identification card will obtain different security data according to different business types for the authentication application to authenticate the authenticated user. In this way, not only can the user identification card itself have super strong security, and better ensure the security of data in the process of obtaining data, but it can also be used to fit different types of authentication application scenarios for identity authentication.

[0306] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0307] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0308] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as mentioned above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, controlled terminal, or network device, etc.) to execute the method of each embodiment of the present application.

[0309] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. An identity authentication method, characterized in that: The method is applied to a mobile terminal, and the identity authentication method includes: Obtaining original security data based on user face image data and several voice data; receiving an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a service type; Acquire target security data corresponding to the service type of the authentication instruction in the original security data through a preset user identification card, and send the target security data to the authentication application; Collecting user data to be authenticated through the authentication application, comparing the user data to be authenticated with the target security data for authentication, and obtaining an authentication result; The step of obtaining original security data based on the user's facial image data and the plurality of voice data includes: compressing the user's facial image data and the plurality of voice data using the authentication application to obtain a compression result; The compression processing result is encrypted using the lowest bit of the pixel value of the face image at a preset position to obtain a data encryption result, and the original security data is determined based on the data encryption result.

2. The identity authentication method according to claim 1, wherein: The step of receiving the authentication instruction sent by the authentication terminal includes: Based on a preset authentication application, user facial image data and a plurality of voice data recorded for different service types are obtained, and original security data is obtained based on the user facial image data and the plurality of voice data; providing the original security data to the user identification card through the authentication application; The step of obtaining target security data corresponding to the service type in the authentication instruction through a preset user identification card and sending the target security data to the authentication application includes: Target security data corresponding to the service type in the authentication instruction is acquired from the original security data through the user identification card, and the target security data is sent to the authentication application.

3. The identity authentication method according to claim 2, wherein: After the step of obtaining the user's facial image data and a plurality of voice data recorded for different service types based on the preset authentication application, the following steps are further included: extracting, by the authentication application, keywords of the voice data from the plurality of voice data, the keywords corresponding to the service types; The correspondence between the keywords and the service types and the original security data are provided to a user identification card, so that the user identification card can perform user identity authentication in combination with the authentication application.

4. The identity authentication method according to claim 1, wherein: The step of receiving the authentication instruction sent by the authentication terminal includes: Obtain user facial image data and multiple voice data recorded for different service types through the authentication application, extract keywords from the voice data, the keywords corresponding to the service types, and obtain original security data based on the user facial image data and multiple voice data; Uploading the original security data to blockchain storage through the authentication application, so that the blockchain provides target security data to the user identification card; Receiving the storage credential returned by the blockchain through the authentication application; Sending the stored credentials and the correspondence between the service type and the keyword to the user identification card through the authentication application; The corresponding relationship between the business type and the keyword is encrypted by the user identification card and sent to the blockchain for storage and obtaining the corresponding access credentials, so that the user identification card can perform user identity authentication in combination with the authentication application.

5. The identity authentication method according to claim 4, wherein: The step of obtaining target security data corresponding to the service type in the authentication instruction through a preset user identification card and sending the target security data to the authentication application includes: Obtaining a corresponding target storage credential according to the business type in the authentication instruction through the user identification card, and obtaining target security data corresponding to the business type in the authentication instruction from the original security data stored in the blockchain according to the target storage credential; The corresponding target access credentials are obtained through the user identification card according to the business type in the authentication instruction. According to the target access credentials, the correspondence between the business type and the keyword is obtained from the blockchain to obtain the corresponding target keyword for the authentication application to perform user identity authentication.

6. The identity authentication method according to claim 3 or 5, characterized in that: The step of collecting the user data to be authenticated by the authentication application, comparing and authenticating the user data to be authenticated with the security data, and obtaining the authentication result includes: sending a target keyword corresponding to the service type in the authentication instruction to the authentication application via the user identification card; The authentication application displays a target keyword corresponding to the business type in the authentication instruction, collects user data to be authenticated based on the target keyword, compares and authenticates the user data to be authenticated with the security data, and obtains an authentication result.

7. The identity authentication method according to claim 1, wherein: The step of determining the original security data according to the data encryption result includes: Performing pseudo-random sequence processing on the data encryption result to obtain a scrambling matrix result; The scrambled matrix result is packaged to obtain original security data.

8. The identity authentication method according to claim 1, wherein: The step of compressing the user face image data and the plurality of voice data by the authentication application to obtain a compression result includes: Through the authentication application, discrete cosine transform is performed on the user face image data and the plurality of voice data to obtain observation vectors of the user face image data and voice data after discrete cosine transform processing.

9. An identity authentication device, characterized in that: include: An authentication instruction receiving module is used to obtain original security data based on the user's facial image data and several voice data; receiving an authentication instruction sent by an authentication terminal, wherein the authentication instruction includes a service type; A data acquisition module, configured to acquire target security data corresponding to the service type of the authentication instruction in the original security data through a preset user identification card; A data sending module, configured to send the target security data to an authentication application; A data collection module, used to collect user data to be authenticated through the authentication application; A data authentication module is used to compare and authenticate the user data to be authenticated with the target security data to obtain an authentication result; The authentication instruction receiving module is further configured to: compressing the user's facial image data and the plurality of voice data using the authentication application to obtain a compression result; The compression processing result is encrypted using the lowest bit of the pixel value of the face image at a preset position to obtain a data encryption result, and the original security data is determined based on the data encryption result.

10. A terminal device, characterized in that: The terminal device includes a memory, a processor, and an identity authentication program stored in the memory and executable on the processor. When the identity authentication program is executed by the processor, the steps of the identity authentication method according to any one of claims 1 to 8 are implemented.

11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores an identity authentication program, which, when executed by a processor, implements the steps of the identity authentication method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Authentication method, and authentication data processing method and device based on blockchain

    CN107257340A

  • Service access method, SIM card, server and service platform

    CN115361683A