Vault authentication method, device, equipment, storage medium and program product

By obtaining the applicant's application reason text converted from video and audio, and combining it with the approver's client-side liveness verification, the security risks and usability issues of static password authentication methods are resolved, enabling remote approval and multi-factor authentication, and improving the security and convenience of vault authentication.

CN118802162BActive Publication Date: 2025-11-21HANDAN BRANCH OF CHINA MOBILE GRP HEBEI COMPANYLIMITED +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410584298.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-11
Publication Date
2025-11-21
Estimated Expiration
2044-05-11

AI Technical Summary

Technical Problem

The existing static password authentication method has significant security risks and usability issues. It cannot complete the authorization operation when the approver is not present, which may lead to the leakage or misuse of important and sensitive data.

Method used

By obtaining the applicant's application reason text converted from video and audio, and combining it with the approver's client-side liveness authentication, remote approval can be achieved, avoiding the leakage of static passwords, and employing multiple identity verification methods such as facial liveness information and fingerprints.

Benefits of technology

This enhances the security and convenience of vault authentication, ensuring remote approval even when the approver is not present, reducing the risk of sensitive data leakage, and improving the accuracy of identity verification and audit records.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802162B_ABST
    Figure CN118802162B_ABST
Patent Text Reader

Abstract

The application provides a vault authentication method, device, equipment, a storage medium and a program product. The method comprises the following steps: obtaining a target data application request sent by an applicant client; sending a data collection request to the applicant client based on the target data application request; obtaining an applicant video and an application reason text, wherein the application reason text is obtained by converting an applicant audio; sending application information to an examiner client; obtaining examiner authentication data and an examiner approval result sent by the examiner client, wherein the application information comprises the applicant video, the application reason text, an applicant account corresponding to the applicant client, and a sending time of the target data application request; and determining an approval result of the target data application request based on the examiner authentication data and the examiner approval result. The application can improve the security of vault authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vault authentication technology, and more particularly to vault authentication methods, apparatus, equipment, storage media, and program products. Background Technology

[0002] To prevent the leakage of sensitive data, a series of data security protection measures have emerged. One typical method for preventing the leakage of important sensitive data is the "treasury approval" measure. The treasury approval measure adopts a one-person operation and one-person approval approach to increase process control in the data use process, preventing data from being directly manipulated by only one person, which could lead to the leakage and misuse of important sensitive data.

[0003] However, existing vault authentication methods mostly rely on static passwords. With static passwords, when accessing or manipulating important sensitive data is required, the authorizing person enters their password in a pop-up authorization window to complete the authorization process. This method presents serious security risks. The risk lies in the fact that if the static password is leaked, or if the operator records the authorizing person's static password, authorization can still be completed even if the authorizing person is unaware of the specific operation, leading to the leakage or misuse of important sensitive data. Furthermore, vault authorization based on static passwords also suffers from usability issues. Normal static password authorization requires both the authorizing person and the applicant to be present at the authorization site. If the authorizing person is not present, the approval process cannot be completed, causing business processes to stall. Alternatively, in emergency situations, the absent authorizing person may have to disclose the password to the applicant, resulting in the lack of rigorous review of important sensitive data operations. Therefore, static password authentication has poor non-repudiation capabilities. Summary of the Invention

[0004] This invention provides a vault authentication method, apparatus, equipment, storage medium, and program product to address the significant security risks inherent in existing static password-based authentication methods, thereby enhancing the security of vault authentication.

[0005] This invention provides a vault authentication method, comprising:

[0006] Obtain the target data request sent by the applicant's client, and based on the target data request, send a data collection request to the applicant's client to obtain the applicant's video and the text of the application reason, wherein the text of the application reason is obtained based on the applicant's audio.

[0007] The application information is sent to the approver's client, and the approver's authentication data and approval result sent by the approver's client are obtained. The application information includes the applicant's video, the application reason text, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent.

[0008] The approval result of the target data application request is determined based on the approver's authentication data and the approver's approval result.

[0009] According to the vault authentication method provided by the present invention, the step of sending a data collection request to the applicant's client based on the target data application request to obtain the applicant's video and the text of the application reason includes:

[0010] In response to the target data request, a first data collection request is sent to the applicant's client, and the applicant's liveness information collected by the applicant's client in response to the first data collection request is obtained;

[0011] Authentication is performed based on the applicant's liveness information to determine whether the user corresponding to the applicant's client has the target data permissions;

[0012] If available, a second data collection request is sent to the applicant's client, and the applicant's video and the text of the application reason are collected by the applicant's client in response to the second data collection request.

[0013] According to the vault authentication method provided by the present invention, the approver authentication data includes first approver liveness information and second approver liveness information; the step of obtaining the approver authentication data sent by the approver client and the approver approval result includes:

[0014] Obtain the first liveness information of the approver collected by the approver client, and verify the identity of the user of the approver client based on the first liveness information of the approver to obtain the first approver identity verification result;

[0015] When the first approver's identity verification result is successful, a third data collection request is sent to the approver's client to obtain the approver's approval result and the approver's second liveness information collected by the approver's client in response to the third data collection request.

[0016] According to the vault authentication method provided by the present invention, determining the approval result of the target data application request based on the approver's authentication data and the approver's approval result includes:

[0017] Authentication and authorization are performed based on the second liveness information of the approver. When the authentication and authorization are successful, the approval result of the approver is determined to be the approval result of the target data application request.

[0018] The present invention also provides a vault authentication method, comprising:

[0019] Obtain a data collection request, and collect the applicant's video and audio based on the data collection request;

[0020] The applicant's audio was converted into text to obtain the application reason text;

[0021] The applicant's video and the text of the application reason will be sent to the authentication system server for authentication and approval.

[0022] The present invention also provides a vault authentication method, comprising:

[0023] Obtain application information, which includes the applicant's video, the text of the application reason, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent. The text of the application reason is obtained based on the applicant's audio.

[0024] Information is collected based on the application information to obtain approver authentication data and approver approval results;

[0025] The approver's authentication data and the approver's approval result are sent to the authentication system server for authentication and approval.

[0026] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the vault authentication method as described above.

[0027] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the vault authentication method as described above.

[0028] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the vault authentication method as described above.

[0029] The vault authentication method, apparatus, equipment, storage medium, and program products provided by this invention, after receiving a target data application request sent by the applicant's client, call the applicant's client to collect the applicant's video, convert the applicant's audio into application reason text, and forward the applicant's video and application reason text sent by the applicant's client, along with the applicant's account and the time the target data application request was sent, to the approver's client. In this way, the approver can operate through the approver's client, which will return the approver's authentication data and the approver's approval result. Then, based on the approver's authentication data and the approver's approval result, the approval result of the target data application request is determined. This enables remote approval through the client even when the approver is not on-site, without disclosing static passwords to the applicant, thus improving the security of vault authentication. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0031] Figure 1 This is one of the flowcharts illustrating the vault authentication method provided by the present invention;

[0032] Figure 2 This is a system schematic diagram of the vault authentication method provided by the present invention;

[0033] Figure 3 This is the second flowchart illustrating the vault authentication method provided by the present invention;

[0034] Figure 4 This is the third flowchart of the vault authentication method provided by the present invention;

[0035] Figure 5 This is the fourth flowchart of the vault authentication method provided by the present invention;

[0036] Figure 6 This is a schematic diagram of the structure of the vault authentication device provided by the present invention;

[0037] Figure 7 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0039] like Figure 1 As shown, the present invention provides a vault authentication method, applied in an authentication system server, comprising the following steps:

[0040] S110. Obtain the target data application request sent by the applicant's client, and send a data collection request to the applicant's client based on the target data application request to obtain the applicant's video and the application reason text, which is obtained by converting the applicant's audio.

[0041] S120. Send the application information to the approver's client, obtain the approver's authentication data and the approver's approval result sent by the approver's client. The application information includes the applicant's video, the text of the application reason, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent.

[0042] S130. Determine the approval result of the target data application request based on the approver's authentication data and the approver's approval result.

[0043] The method provided by this invention involves the authentication system server, upon receiving a target data application request from an applicant's client, calling the applicant's client to collect the applicant's video and converting the applicant's audio into a textual statement of the application reason. The applicant's video and the textual statement of the application reason, along with the applicant's account and the time the target data application request was sent, are then forwarded to the approver's client. This allows the approver to operate through their client, resulting in the client returning approver authentication data and the approver's approval result. Based on the approver's authentication data and approval result, the approval result of the target data application request is determined. This method enables remote approval even when the approver is not physically present, without disclosing static passwords to the applicant, thus improving the security of vault authentication.

[0044] Based on the target data application request, a data collection request is sent to the applicant's client to obtain the applicant's video and the text of the application reason, including:

[0045] In response to the target data request, a first data collection request is sent to the applicant's client, and the applicant's liveness information collected by the applicant's client in response to the first data collection request is obtained;

[0046] Authentication is performed based on the applicant's liveness information to determine whether the user corresponding to the applicant's client has the right to access the target data.

[0047] If available, a second data collection request is sent to the applicant's client to obtain the applicant's video and the text of the application reason collected by the applicant's client in response to the second data collection request.

[0048] like Figure 2 As shown, the method provided by this invention is applied to an important and sensitive data application system, involving three parties: an authentication system server, an applicant client, and an approver client. The system includes a financial control module, which is responsible for triggering vault authentication, determining the applicant's account vault permissions, determining the approver's approval permissions, and determining the vault approval result. The financial control module is deployed in the authentication system server. The financial control module is the core module, responsible for calling other modules to perform related operations.

[0049] like Figure 3As shown, during the vault authentication and approval process, the applicant first logs into the application system that stores the target data (i.e., important and sensitive data), entering their account and password. The application system then calls the identity authentication module to compare the user's entered account and authentication information, determining whether the authentication information is correct and completing the basic account authentication and login process. Afterward, the application system assigns a user permission token to the applicant based on their role. Subsequently, if the applicant begins to manipulate the important and sensitive data, i.e., issues a target data request, the vault approval process is triggered, and the vault control module begins the vault authentication and authorization approval process.

[0050] The applicant's liveness information can be their facial liveness data. In the treasury authentication and authorization approval process, the first step is to respond to the target data request and issue a first data collection request, such as... Figure 2 As shown, the facial liveness verification module deployed on the applicant's client triggers the applicant's facial liveness authentication operation, collecting and submitting the applicant's facial liveness information on the client. Further, the facial liveness verification module can perform preliminary analysis on the acquired facial liveness information, such as analyzing whether it is a real face or an image, and submit the analyzed facial liveness information to the authentication system server. The identity verification module deployed on the authentication system server performs identity verification to confirm whether the applicant currently attempting to operate on the target data is consistent with the logged-in account, preventing others from impersonating the account to operate on sensitive data. If the applicant does not have the necessary permissions to operate on important sensitive data, the target data application request is rejected. The introduction of liveness verification technology improves the non-repudiation of the treasury approval process, helps clarify the attribution of data security responsibilities, increases the accuracy of accountability for security incidents, and improves data security.

[0051] Once the applicant's liveness information is verified and it is determined that the user currently operating the applicant's client has the necessary permissions for the target data, a second data collection request is sent to the applicant's client. The applicant's client responds to the second data collection request and collects the applicant's video and the text of the application reason.

[0052] The applicant's client application includes an audio / video recording module to record video of the applicant. The application reason text is obtained by converting the applicant's audio recorded during audio recording. Specifically, the applicant's client application can include a natural language processing (NLP) module to extract the text from the applicant's audio, resulting in the application reason text. This invention introduces natural language recognition technology to convert the applicant's application reason into speech and text, facilitating the applicant's input of the application reason without manual input, thus improving work efficiency. Furthermore, in practice, due to the need for manual input of application reasons, applicants often simply enter a vague reason to reduce workload. This manually entered reason may not be detailed enough to reflect the applicant's true intentions. The method provided by this invention uses NLP technology to convert the applicant's application reason into speech and text, making the operation more convenient. It eliminates the need for manual input; the applicant only needs to state their application reason, allowing for a more detailed explanation and avoiding a series of audit risks caused by simply entering the reason. In addition, the audio and video recording also helps to preserve the applicant's application information, providing sufficient audit evidence for subsequent audit work.

[0053] After obtaining the applicant's video and the text of the application reason, the application information, including the applicant's video, the text of the application reason, the applicant's account corresponding to the applicant's client, and the time the target data application request was sent, is sent to the approver's client, thereby providing an approval reminder to the approver. In the method provided by this invention, in addition to the text of the application reason, the applicant's video, the applicant's account corresponding to the applicant's client, and the time the target data application request was sent are also sent to the approver's client. In this way, the approver can view the applicant's video through the approver's client to verify the authenticity of the application, and further determine whether the applicant's account has been stolen by comparing the applicant's account with the applicant's video. Simultaneously, the time the target data application request was sent can be used to determine whether the application is immediate, preventing duplicate applications and improving the security of vault authentication.

[0054] After receiving the application information, the approver's client needs to return the approver's approval result as well as the approver's authentication data. In other words, the authentication system server obtains the approver's authentication data in addition to the approver's approval result, so that the approver can be authenticated based on the approver's authentication data, thus preventing the risk of data leakage caused by the theft of the approver's account.

[0055] In the method provided by this invention, in order to further improve the security of vault authentication, the approver is also subjected to liveness authentication, that is, the approver authentication data includes liveness information.

[0056] Furthermore, the method provided by this invention employs two types of liveness information for approver authentication. That is, the approver authentication data includes both first and second liveness information of the approver, thereby increasing approval security. Specifically, obtaining the applicant authentication data and the applicant approval result sent by the approver's client includes:

[0057] Obtain the first liveness information of the approver collected by the approver's client, and verify the identity of the user of the approver's client based on the first liveness information to obtain the first approver's identity verification result;

[0058] When the first approver's identity verification result is successful, a third data collection request is sent to the approver's client to obtain the applicant's approval result and the approver's second liveness information collected by the approver's client in response to the third data collection request.

[0059] Specifically, the first and second liveness information of the approver can be different types of liveness information, such as facial information and fingerprint information. Of course, the first and second liveness information of the approver can also be other types of liveness information, such as voiceprint information. The following explanation uses facial information as the first liveness information and fingerprint information as the second liveness information of the approver.

[0060] Before approval, the applicant first uses their client to collect the approver's initial liveness information (facial information). This can be obtained and preliminarily checked through the facial liveness verification module on the applicant's client, such as checking whether the face is an image. The approver's initial liveness information is then sent to the authentication system server. The authentication and authorization module on the authentication system server authenticates the approver's identity. The authentication result is then passed to the vault approval module on the authentication system server. When the vault approval module confirms that the authentication result is successful, it sends a third data collection request to the approver's client. The approver's client responds to the third data collection request, collecting the approver's approval result and the approver's second liveness information. In other words, after the approver's authentication and authorization are completed, the approver's approval opinion is entered, and the approver's second liveness information (fingerprint information) is entered through the approver's client.

[0061] After obtaining the second liveness information of the approver, the authentication system server performs re-authentication and authorization based on the second liveness information of the approver. That is, it determines the approval result of the target data application request based on the approver's authentication data and the approver's approval result, including:

[0062] Authentication and authorization are performed based on the approver's second liveness information. When the authentication and authorization are successful, the approver's approval result is determined as the approval result of the target data application request.

[0063] The method provided by this invention performs two rounds of approval by verifying the approver's identity using first and second liveness information, thereby ensuring the correctness of the approver's identity, strengthening the identity verification of the approver, and protecting the security of sensitive data.

[0064] Furthermore, after determining the approval result of the target data request, the process also includes:

[0065] The application information, approver authentication data, and approver approval results shall be archived and recorded.

[0066] In other words, the authentication system server records the process data after each vault authentication approval, which can be easily queried during later audits.

[0067] The method provided by this invention introduces dual liveness verification for both the approver and the applicant during the vault authentication process. This strong verification of the applicant's and approver's identities reduces the risk of leakage or misuse of important and sensitive data in cases of applicant account theft or approver privilege misuse, thus improving data security. Simultaneously, it combines facial liveness verification, fingerprint collection, and video capture technologies to perform multiple identity verifications on participants. Without affecting user experience, it effectively increases the identity verification records throughout the entire process, laying a solid foundation for subsequent auditing. Furthermore, through interaction with the applicant's and approver's clients, it enhances the convenience of vault authentication while significantly improving the security of the vault approval process. Even when neither party is present, the vault authentication process can still be conveniently completed through the client.

[0068] The following describes another vault authentication method provided by this invention. This method is applied to the applicant's client, such as... Figure 4 As shown, the method includes:

[0069] S410. Obtain a data collection request and collect the applicant's video and audio based on the data collection request;

[0070] S420. Convert the applicant's audio into text to obtain the application statement.

[0071] S430. Send the applicant's video and the text of the application reason to the authentication system server for authentication and approval.

[0072] The detailed process of the vault authentication method executed on the applicant's client can be found in the description of the vault authentication method executed on the authentication system server described above, and will not be repeated here.

[0073] The following describes another vault authentication method provided by this invention. This method is applied to the approver's client, such as... Figure 5As shown, the method includes:

[0074] S510. Obtain application information, which includes the applicant's video, the text of the application reason, the applicant's client corresponding to the applicant's account, and the time when the target data application request was sent. The text of the application reason is obtained based on the applicant's audio.

[0075] S520. Collect information based on application information to obtain approver authentication data and approver approval results;

[0076] S530. Send the approver's authentication data and approval results to the authentication system server for authentication and approval.

[0077] The detailed process of the vault authentication method executed on the approver's client can be found in the description of the vault authentication method executed on the authentication system server described above, and will not be repeated here.

[0078] The vault authentication device provided by this invention is described below. The vault authentication device described below corresponds to the vault authentication method described above. For example... Figure 6 As shown, the vault authentication device provided by the present invention includes:

[0079] The application data acquisition module 610 is used to acquire the target data application request sent by the applicant's client, and send a data collection request to the applicant's client based on the target data application request to acquire the applicant's video and the application reason text. The application reason text is obtained based on the applicant's audio.

[0080] The approval data acquisition module 620 is used to send application information to the approver's client, acquire the approver's authentication data and approval results sent by the approver's client, and the application information includes the applicant's video, the text of the application reason, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent.

[0081] The vault control module 630 is used to determine the approval result of the target data application request based on the approver's authentication data and the approver's approval result.

[0082] Figure 7 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 7As shown, the electronic device may include: a processor 710, a communications interface 720, a memory 730, and a communication bus 740. The processor 710, communications interface 720, and memory 730 communicate with each other via the communication bus 740. The processor 710 can call logical instructions in the memory 730 to execute a vault authentication method. The vault authentication method includes: obtaining a target data application request sent by the applicant's client; sending a data collection request to the applicant's client based on the target data application request; obtaining the applicant's video and application reason text, where the application reason text is derived from the applicant's audio; sending the application information to the approver's client; obtaining the approver's authentication data and approval result sent by the approver's client; the application information includes the applicant's video, application reason text, the applicant's account corresponding to the applicant's client, and the time the target data application request was sent; and determining the approval result of the target data application request based on the approver's authentication data and approval result. Alternatively, it may include: obtaining a data collection request; collecting the applicant's video and audio based on the data collection request; converting the applicant's audio into text to obtain the application reason text; and sending the applicant's video and application reason text to the authentication system server for authentication and approval. Alternatively, it may include: obtaining application information, including the applicant's video, application reason text, the applicant's client-related account, and the time the target data application request was sent; the application reason text is obtained based on the applicant's audio conversion; collecting information based on the application information to obtain the approver's authentication data and approval result; and sending the approver's authentication data and approval result to the authentication system server for authentication and approval.

[0083] Furthermore, the logical instructions in the aforementioned memory 730 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0084] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the vault authentication method provided above. The vault authentication method includes: obtaining a target data application request sent by an applicant's client; sending a data collection request to the applicant's client based on the target data application request; obtaining the applicant's video and application reason text, wherein the application reason text is obtained based on the applicant's audio; sending the application information to the approver's client; obtaining the approver's authentication data and the approver's approval result sent by the approver's client; the application information includes the applicant's video, application reason text, the applicant's account corresponding to the applicant's client, and the time the target data application request was sent; and determining the approval result of the target data application request based on the approver's authentication data and the approver's approval result. Alternatively, it may include: obtaining a data collection request; collecting the applicant's video and audio based on the data collection request; converting the applicant's audio into text to obtain the application reason text; and sending the applicant's video and application reason text to the authentication system server for authentication and approval. Alternatively, it may include: obtaining application information, which includes the applicant's video, the text of the application reason, the applicant's client-related account, and the time when the target data application request was sent; the text of the application reason is obtained based on the applicant's audio; collecting information based on the application information to obtain the approver's authentication data and the approver's approval result; and sending the approver's authentication data and the approver's approval result to the authentication system server for authentication and approval.

[0085] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the vault authentication method described above. The vault authentication method includes: obtaining a target data application request sent by an applicant's client; sending a data collection request to the applicant's client based on the target data application request; obtaining the applicant's video and application reason text, wherein the application reason text is derived from the applicant's audio; sending the application information to the approver's client; obtaining the approver's authentication data and approval result sent by the approver's client; the application information includes the applicant's video, application reason text, the applicant's account corresponding to the applicant's client, and the time the target data application request was sent; and determining the approval result of the target data application request based on the approver's authentication data and approval result. Alternatively, it may include: obtaining a data collection request; collecting the applicant's video and audio based on the data collection request; converting the applicant's audio into text to obtain the application reason text; and sending the applicant's video and application reason text to the authentication system server for authentication and approval. Alternatively, it may include: obtaining application information, which includes the applicant's video, the text of the application reason, the applicant's client-related account, and the time when the target data application request was sent; the text of the application reason is obtained based on the applicant's audio; collecting information based on the application information to obtain the approver's authentication data and the approver's approval result; and sending the approver's authentication data and the approver's approval result to the authentication system server for authentication and approval.

[0086] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0087] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for authenticating a vault, characterized in that, include: Obtain the target data request sent by the applicant's client, and based on the target data request, send a data collection request to the applicant's client to obtain the applicant's video and the text of the application reason, wherein the text of the application reason is obtained based on the applicant's audio. The application information is sent to the approver's client, and the approver's authentication data and approval result sent by the approver's client are obtained. The application information includes the applicant's video, the application reason text, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent. The approval result of the target data application request is determined based on the approver's authentication data and the approver's approval result.

2. The vault authentication method according to claim 1, characterized in that, The process of sending a data collection request to the applicant's client based on the target data application request to obtain the applicant's video and application reason text includes: In response to the target data request, a first data collection request is sent to the applicant's client, and the applicant's liveness information collected by the applicant's client in response to the first data collection request is obtained; Authentication is performed based on the applicant's liveness information to determine whether the user corresponding to the applicant's client has the target data permissions; If available, a second data collection request is sent to the applicant's client, and the applicant's video and the text of the application reason are collected by the applicant's client in response to the second data collection request.

3. The vault authentication method according to claim 1, characterized in that, The approver authentication data includes the approver's first liveness information and the approver's second liveness information; obtaining the approver authentication data and the approver's approval result sent by the approver's client includes: Obtain the first liveness information of the approver collected by the approver client, and verify the identity of the user of the approver client based on the first liveness information of the approver to obtain the first approver identity verification result; When the first approver's identity verification result is successful, a third data collection request is sent to the approver's client to obtain the approver's approval result and the approver's second liveness information collected by the approver's client in response to the third data collection request.

4. The vault authentication method according to claim 3, characterized in that, The process of determining the approval result of the target data application request based on the approver's authentication data and the approver's approval result includes: Authentication and authorization are performed based on the second liveness information of the approver. When the authentication and authorization are successful, the approval result of the approver is determined to be the approval result of the target data application request.

5. A method for authenticating a vault, characterized in that, include: Obtain a data collection request, and collect the applicant's video and audio based on the data collection request; The applicant's audio was converted into text to obtain the application reason text; The applicant's video and the text of the application reason will be sent to the authentication system server for authentication and approval.

6. A method for authenticating a vault, characterized in that, include: Obtain application information, which includes the applicant's video, the text of the application reason, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent. The text of the application reason is obtained based on the applicant's audio. Information is collected based on the application information to obtain approver authentication data and approver approval results; The approver's authentication data and the approver's approval result are sent to the authentication system server for authentication and approval.

7. A vault authentication device, characterized in that, include: The application data acquisition module is used to acquire the target data application request sent by the applicant's client, and based on the target data application request, send a data collection request to the applicant's client to acquire the applicant's video and the application reason text, wherein the application reason text is obtained based on the applicant's audio. The approval data acquisition module is used to send application information to the approver's client, acquire the approver's authentication data and approval result sent by the approver's client, and the application information includes the applicant's video, the application reason text, the applicant's account corresponding to the applicant's client, and the time when the target data application request was sent. The vault control module is used to determine the approval result of the target data application request based on the approver's authentication data and the approver's approval result.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the vault authentication method as described in any one of claims 1-4, or the vault authentication method as described in claim 5, or the vault authentication method as described in claim 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the vault authentication method as described in any one of claims 1-4, or the vault authentication method as described in claim 5, or the vault authentication method as described in claim 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the vault authentication method as described in any one of claims 1-4, or the vault authentication method as described in claim 5, or the vault authentication method as described in claim 6.

Citation Information

Patent Citations

  • Intelligent unmanned crown block voice control system

    CN114373457A

  • Access control method, device and equipment and storage medium

    CN117746544A