Method, device, storage medium and electronic device for identity authentication

By introducing a cross-device-assisted authentication solution to NFC in real-person identity authentication, the problem of devices that do not support NFC functions is difficult to complete authentication, and the security and integrity of authentication are achieved.

CN119211938BActive Publication Date: 2025-05-16ANT ZHIXIN HANGZHOU INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411707432.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-05-16
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

The existing technology relies on face-scanning technology in real-person identity authentication. It cannot ensure the reliability of identity authentication when facing generative AI attacks, and devices that do not support NFC functions are difficult to complete NFC real-person ID verification.

Method used

A cross-device-assisted verification of NFC is proposed. After users complete human characteristics verification, they need to conduct an NFC document verification. If the user's mobile phone does not support NFC function, he or she can perform auxiliary verification through another device that supports NFC function to ensure the integrity and security of NFC verification.

Benefits of technology

It effectively prevents injection attacks based on generative AI, ensures the accuracy and security of identity verification, and allows devices that do not support NFC functions to complete NFC real-person ID verification and successfully complete the identity verification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119211938B_ABST
    Figure CN119211938B_ABST
Patent Text Reader

Abstract

The embodiments of this specification disclose a method, apparatus, storage medium and electronic device for identity authentication, which obtain user identity information input by a target user, send the user identity information to a first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC; receive the verification token information returned by the first network device, so that a second user device performs NFC verification on a target certificate of the target user based on the verification token information provided by the first user device; send a verification result query request corresponding to the verification token information to the first network device, so that the first network device obtains verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user passes the identity authentication based on the verification result information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to computer technology, and in particular to a method, device, storage medium and electronic device for identity authentication. Background Art

[0002] With the rapid development of generative AI technology, the number of attacks against face-based identity verification is increasing, and the number of successful cases is gradually increasing. In the process of electronic KYC (electronic Know Your Customer, eKYC is a method of verifying the identity of a customer electronically), many scenarios require real-person identity authentication.

[0003] Real-person identity authentication verifies a person's true identity through various technical means to ensure that the person being authenticated is indeed a specific, real person, not just a virtual entity or imposter with that identity information. Real-person identity authentication emphasizes the verification of "real people" and is usually used in scenarios with high security requirements, such as financial services, e-government, and social media real-name authentication. If you only rely on face recognition technology for real-person identity authentication, the reliability of identity authentication may not be guaranteed in the face of attacks. Therefore, other identity authentication methods need to be introduced to enhance security.

[0004] NFC (Near Field Communication) technology can be used to read information from documents, such as ID cards, and compare and verify this data with authoritative databases. However, not all mobile phones currently support NFC. Summary of the invention

[0005] The purpose of the embodiments of this specification is to provide a method, device, storage medium and electronic device for identity authentication.

[0006] The embodiment of this specification provides a method for identity authentication, which is applied to a first user device and proposes a cross-device auxiliary verification NFC solution. After completing the human feature verification, the user needs to perform an NFC certificate verification. When the user's mobile phone does not support the NFC function, another device that supports the NFC function can be used to assist in the verification, thereby achieving the integrity and security of the NFC verification. This method effectively prevents injection attacks based on generative AI, and enables devices that do not support the NFC function to complete NFC real-person certificate verification, thereby successfully completing the identity authentication process. This method effectively prevents the risk of impersonation caused by generative AI injection attacks and ensures the accuracy and security of identity authentication. During the auxiliary verification process, the identity information of the person being verified, such as the ID card name, is stored in the backend server and represented by a token. The token is only passed to the auxiliary verification party. The auxiliary verification party cannot directly obtain the specific identity information of the person being verified, thereby effectively protecting the privacy of the person being verified. Even if the token is leaked during the verification or transmission process, it will not cause the leakage of user information, ensuring information security. The method includes:

[0007] Obtaining user identity information input by a target user, and sending the user identity information to a first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC, and the target user has completed human feature verification on the first user device;

[0008] receiving the verification token information returned by the first network device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device;

[0009] The verification result query request corresponding to the verification token information is sent to the first network device, so that the first network device obtains the verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user passes the identity authentication according to the verification result information.

[0010] Furthermore, obtaining the user identity information input by the target user includes:

[0011] Determining whether the first user equipment supports NFC;

[0012] If not, obtain the user identity information input by the target user.

[0013] Furthermore, the method further comprises:

[0014] In response to a sending trigger operation performed by the target user on the verification token information, the verification token information is sent to the second user equipment.

[0015] Furthermore, the method further comprises:

[0016] Generate and present graphic code information corresponding to the verification token information, so that the second user equipment obtains the verification token information by scanning the graphic code information.

[0017] This embodiment of the specification provides a method for identity authentication, which is applied to a first network device, and the method includes:

[0018] Receiving user identity information of a target user sent by a first user device, and generating verification token information corresponding to the target user, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC;

[0019] Returning the verification token information to the first user device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device;

[0020] Obtain verification result information corresponding to the target certificate determined based on the verification token information, and determine whether the target user passes the identity authentication according to the verification result information.

[0021] This embodiment of the specification provides a method for identity authentication, which is applied to a second user equipment, and the method includes:

[0022] Based on the verification token information corresponding to the target user provided by the first user device, the target certificate of the target user is read by NFC to obtain the NFC information corresponding to the target certificate, wherein the target user has completed the human feature verification on the first user device, and the first user device does not support NFC;

[0023] The NFC information and the verification token information are sent to the second network device, so that the second network device obtains the user identity information of the target user according to the verification token information, performs verification based on the NFC information and the user identity information, and if the verification is successful, updates the status information corresponding to the verification token information, and, in response to receiving a verification result query request for the verification token information sent by the first network device, determines the verification result information corresponding to the target certificate according to the verification status, and returns the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0024] Furthermore, the method further comprises:

[0025] Receive the verification token information sent by the first user equipment.

[0026] Furthermore, the method further comprises:

[0027] The verification token information is obtained in response to a scanning operation performed on graphic code information corresponding to the verification token information, wherein the graphic code information is generated on the first user device.

[0028] This embodiment of the specification provides a method for identity authentication, which is applied to a second network device, and the method includes:

[0029] Receiving NFC information corresponding to a target certificate of a target user and verification token information corresponding to the target certificate sent by a second user device, wherein the target user has completed human feature verification on a first user device, the first user device does not support NFC, and the second user device performs NFC reading on the target certificate based on the verification token information provided by the first user device to obtain the NFC information;

[0030] Obtain the user identity information of the target user according to the verification token information, perform verification based on the NFC information and the user identity information, and if the verification is successful, update the status information corresponding to the verification token information;

[0031] Receive a verification result query request regarding the verification token information sent by the first network device, determine the verification result information corresponding to the target certificate according to the verification status, and return the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0032] Furthermore, the verification based on the NFC information and the user identity information includes:

[0033] Information comparison verification and signature verification are performed based on the NFC information and the user identity information.

[0034] The embodiment of this specification also provides a first device for identity authentication, including:

[0035] a certificate information input module, configured to obtain user identity information input by a target user, and send the user identity information to a first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC, and the target user has completed human feature verification on the first user device;

[0036] A first receiving module, configured to receive the verification token information returned by the first network device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device;

[0037] A verification result query module is used to send a verification result query request corresponding to the verification token information to the first network device, so that the first network device obtains the verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user has passed the identity authentication based on the verification result information.

[0038] The embodiment of this specification also provides a second device for identity authentication, including:

[0039] A verification token generation module, configured to receive user identity information of a target user sent by a first user device, and generate verification token information corresponding to the target user, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC;

[0040] A first sending module, configured to return the verification token information to the first user equipment, so that the second user equipment performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user equipment;

[0041] The verification result obtaining module is used to obtain verification result information corresponding to the target certificate determined based on the verification token information, and determine whether the target user has passed the identity authentication according to the verification result information.

[0042] The embodiment of this specification also provides a third device for identity authentication, including:

[0043] An NFC verification module is used to perform NFC reading on a target certificate of a target user based on verification token information corresponding to a target user provided by a first user device, and obtain NFC information corresponding to the target certificate, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC;

[0044] A second sending module is used to send the NFC information and the verification token information to a second network device, so that the second network device obtains the user identity information of the target user according to the verification token information, performs verification based on the NFC information and the user identity information, and if the verification is successful, updates the status information corresponding to the verification token information, and, in response to receiving a verification result query request for the verification token information sent by the first network device, determines the verification result information corresponding to the target certificate according to the verification status, and returns the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0045] The embodiment of this specification also provides a fourth device for identity authentication, including:

[0046] A second receiving module is configured to receive NFC information corresponding to a target certificate of a target user and verification token information corresponding to the target certificate, sent by a second user device, wherein the target user has completed human feature verification on a first user device, the first user device does not support NFC, and the second user device performs NFC reading on the target certificate based on the verification token information provided by the first user device to obtain the NFC information;

[0047] A verification module, used to obtain the user identity information of the target user according to the verification token information, perform verification based on the NFC information and the user identity information, and if the verification is successful, update the status information corresponding to the verification token information;

[0048] A verification result determination module is used to receive a verification result query request regarding the verification token information sent by the first network device, determine the verification result information corresponding to the target certificate according to the verification status, and return the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0049] The embodiments of the present specification also provide a storage medium, wherein the storage medium stores a computer program, and the computer program is suitable for being loaded by a processor and executing the steps of the above method.

[0050] An embodiment of the present specification also provides an electronic device, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the above method.

[0051] In the embodiment of this specification, a cross-device assisted verification NFC solution is proposed. After completing the human feature verification, the user needs to perform an NFC certificate verification. When the user's mobile phone does not support the NFC function, another device that supports the NFC function can be used to assist in the verification, thereby achieving the integrity and security of the NFC verification. This method effectively prevents injection attacks based on generative AI, and enables devices that do not support the NFC function to complete NFC real-person certificate verification, thereby smoothly completing the identity authentication process. This method effectively prevents the risk of impersonation caused by generative AI injection attacks and ensures the accuracy and security of identity authentication. During the auxiliary verification process, the identity information of the person being verified, such as the ID card name, is stored in the backend server and represented by a token. The token is only passed to the auxiliary verification party. The auxiliary verification party cannot directly obtain the specific identity information of the person being verified, thereby effectively protecting the privacy of the person being verified. Even if the token is leaked during the verification or transmission process, it will not cause the leakage of user information, ensuring information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] Figure 1 A flowchart of a method for identity authentication provided in an embodiment of this specification;

[0053] Figure 2 A flowchart of a method for identity authentication provided in an embodiment of this specification;

[0054] Figure 3 A flowchart of a method for identity authentication provided in an embodiment of this specification;

[0055] Figure 4 A flowchart of a method for identity authentication provided in an embodiment of this specification;

[0056] Figure 5 A flowchart of an example of a method for identity authentication provided in an embodiment of this specification;

[0057] Figure 6 A schematic diagram of the structure of a first device for identity authentication provided in an embodiment of this specification;

[0058] Figure 7 A schematic diagram of the structure of a second device for identity authentication provided in an embodiment of this specification;

[0059] Figure 8 A schematic diagram of the structure of a third device for identity authentication provided in an embodiment of this specification;

[0060] Fig. 9 A schematic diagram of the structure of a fourth device for identity authentication provided in an embodiment of this specification;

[0061] Fig.10 A schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION

[0062] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.

[0063] The devices referred to in this application include but are not limited to user devices, network devices, or devices formed by integrating user devices and network devices through a network. The user devices include but are not limited to any mobile electronic products that can interact with users (for example, interact with users through a touchpad), such as smart phones, tablet computers, etc. The mobile electronic products can use any operating system, such as Android operating system, iOS operating system, etc. Among them, the network device includes an electronic device that can automatically perform numerical calculations and information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (Application Specific Integrated Circuit, ASIC), programmable logic devices (Programmable Logic Device, PLD), field programmable gate arrays (Field Programmable Gate Array, FPGA), digital signal processors (Digital Signal Processor, DSP), embedded devices, etc. The network devices include but are not limited to computers, network hosts, single network servers, multiple network server sets or multiple servers. The cloud is composed of a large number of computers or network servers based on cloud computing (Cloud Computing), wherein cloud computing is a type of distributed computing, a virtual supercomputer composed of a group of loosely coupled computer sets. The network includes but is not limited to the Internet, a wide area network, a metropolitan area network, a local area network, a VPN network, a wireless self-organizing network (Ad Hoc network), etc. Preferably, the device can also be a program running on the user device, the network device, or a device formed by the user device and the network device, the network device, the touch terminal, or the network device and the touch terminal integrated through a network. The words first, second, etc. referred to in this application are used to indicate the names and do not indicate any specific order. Of course, those skilled in the art should understand that the above-mentioned devices are only examples, and other existing or future devices that may appear should also be included in the scope of protection of this application if they are applicable to this application, and are included here by reference.

[0064] See also Figure 1 , is a flowchart of a method for identity authentication applied to a first user device provided in an embodiment of this specification. In an embodiment of this specification, the method for identity authentication is applied to a first device for identity authentication or an electronic device equipped with the first device. Figure 1 The process shown is described in detail, and the method for identity authentication may specifically include the following steps:

[0065] S102, obtaining user identity information input by a target user, and sending the user identity information to a first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC, and the target user has completed human feature verification on the first user device.

[0066] In some embodiments, the target user has completed human feature verification on the first user device. Human feature verification refers to identity authentication based on feature information of at least one part of the human body, including but not limited to face verification, fingerprint verification, etc. It should be noted that the above verification methods are only examples and not limitations. Those skilled in the art should be able to understand that any method of human feature verification can be included in the protection scope of this specification.

[0067] In some embodiments, the first user device does not support NFC. In response to the target user initiating a verification request for a real certificate on the first user device (the verification request is used to verify whether the user corresponding to the real certificate subsequently provided by the target user is the target user himself), a collection page for user identity information of the target user is rendered on the first user device, and the target user enters the user identity information on the first user device. The first user device sends the user identity information entered by the target user to the corresponding first network device, wherein the target certificate is a real certificate owned by the target user, and the target certificate includes but is not limited to an identity card, a passport, a vehicle registration certificate, a driver's license, etc. It should be noted that the above-mentioned certificate types are only examples and not limitations. Those skilled in the art should understand that any type of target certificate can be included in the protection scope of this specification. The user identity information includes but is not limited to the user's name, the certificate number of at least one real certificate owned by the user, etc. This specification does not limit the specific content of the user identity information.

[0068] In some embodiments, in response to the target user initiating a verification request regarding a real certificate on the first user device, the first user device will send a corresponding online account opening request to the corresponding first network device. The first network device will open an account for the target user based on the received online account opening request, and return a collection request for the target user's user identity information to the first user device. The first user device will render a corresponding collection page based on the received collection request for the target user to enter user identity information.

[0069] In some embodiments, if the first network device and the second network device are the same network device, the first network device saves the user identity information after receiving the user identity information, and randomly generates a verification token information (for example, a string), which is unique for different users and different types of certificates. For example, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information. In some embodiments, an association relationship between the verification token information and the target user is established in the first network device, and the user identity information of the target user can be obtained in the first network device through the verification token information.

[0070] In some embodiments, if the first network device and the second network device are two different network devices, the first network device will send a corresponding verification token information acquisition request to the second network device after receiving the user identity information, wherein the verification token information acquisition request includes the user identity information. After receiving the verification token information acquisition request, the second network device saves the user identity information, randomly generates a verification token information (token, such as a string), and establishes an association relationship between the verification token information and the target user in the second network device, and the user identity information of the target user can be obtained in the second network device through the verification token information. In some embodiments, the second network device returns the generated verification token information to the first network device.

[0071] In some embodiments, the second network device (i.e., the NFC verification network device) is a network device corresponding to another NFC-supported user device other than the first user device, i.e., the second user device (i.e., the NFC verification user device), and the user corresponding to the second user device (i.e., the NFC auxiliary verification user) may also be the target user, or the user corresponding to the second user device may be another user other than the target user. In some embodiments, the first network device and the second network device may be the same network device, or they may be two different network devices.

[0072] S104: Receive the verification token information returned by the first network device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device.

[0073] In some embodiments, the first network device will return the verification token information corresponding to the target user to the first user device. After receiving the verification token information, the first user device can directly present the verification token information to the target user, or can first generate graphic code information corresponding to the verification token information, and then present the graphic code information to the target user, wherein the graphic code information includes but is not limited to QR codes, bar codes, etc., and this specification does not limit this.

[0074] In some embodiments, the target user can send the verification token information or the graphic code information to the second user device through the first user device, for example, the target user sends the verification token information or the graphic code information to the second user device through a social application on the first user device. In some embodiments, the user corresponding to the second user device (i.e., the NFC-assisted verification user) can also manually input the verification token information into the second user device.

[0075] In some embodiments, the second user device may obtain the verification token information based on a scanning operation performed by a user corresponding to the second user device through a camera on the second user device on the graphic code information presented on the first user device. In some embodiments, the second user device may obtain the verification token information based on a scanning operation performed by a user corresponding to the second user device through a camera on the second user device on the graphic code information sent by the first user device to the second user device. In some embodiments, the second network device (i.e., the NFC verification network device) is a network device corresponding to another NFC-supporting user device other than the first user device, i.e., the second user device (i.e., the NFC verification user device), and the user corresponding to the second user device (i.e., the NFC auxiliary verification user) may also be the target user, or the user corresponding to the second user device (i.e., the NFC auxiliary verification user) may be another user other than the target user. In some embodiments, the first network device and the second network device may be the same network device, or they may be two different network devices.

[0076] In some embodiments, after the second user device obtains the verification token information provided by the first user device, the user corresponding to the second user device, namely the NFC auxiliary verification user, can perform auxiliary verification on at least one real certificate owned by the target user (i.e., the target certificate) based on the verification token information. For example, the second user device sends a corresponding auxiliary verification request to the NFC auxiliary verification user, and the NFC auxiliary verification user handles the auxiliary verification corresponding to the verification token information. In some embodiments, the second user device will pull up the NFC page, read the at least one real certificate owned by the target user (i.e., the target certificate) provided by the NFC auxiliary verification user through the NFC module in the second user device, and obtain the corresponding NFC information (i.e., the information read by the NFC module for the real target certificate), and then the second user device will send the NFC information and the verification token information to the corresponding second network device.

[0077] In some embodiments, based on the received verification token information, the second network device obtains the user identity information of the target user associated with the verification token information (i.e., the user identity information entered by the target user on the first user device), and then performs information comparison based on the user identity information and the NFC information, and determines the verification result corresponding to the target certificate based on the comparison result, and the verification result is used to indicate whether the NFC verification of the target certificate (i.e., verifying whether the target certificate is the target user's authentic certificate) is successful. In some embodiments, an association relationship between the verification token information and the verification result is also established on the second network device. In some embodiments, the second network device returns the verification result to the second user device, and presents the verification result to the NFC-assisted verification user on the second user device. In some embodiments, if the NFC-assisted verification user and the target user are the same user, the target user can directly view the verification result. If the NFC-assisted verification user and the target user are two different users, the NFC-assisted verification user can show the verification result presented on the second user device to the target user. Alternatively, the NFC-assisted verification user can perform a sending operation on the verification result, so that the second user device sends the verification result to the first user device, and presents the verification result to the target user on the first user device. For example, the NFC-assisted verification user sends the verification result to the first user device through a social application.

[0078] S106, sending a verification result query request corresponding to the verification token information to the first network device, so that the first network device obtains the verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user passes the identity authentication according to the verification result information.

[0079] In some embodiments, in response to the target user continuing the identity authentication process, the first user will send a verification result query request corresponding to the verification token information to the first network device, and the verification result query request is used to query the verification result corresponding to the target certificate of the target user associated with the verification token information, that is, to query whether the NFC verification of the target certificate of the target user associated with the verification token information is successful, wherein the verification result query request includes the verification token information.

[0080] In some embodiments, if the first network device and the second network device are the same network device, then after receiving the verification result query request, the first network device will query the corresponding verification result of the target certificate of the target user associated with the verification token information based on the verification token information. The verification result is used to indicate whether the NFC verification of the target certificate (i.e., verifying whether the target certificate is the authentic certificate of the target user himself) is successful.

[0081] In some embodiments, if the first network device and the second network device are two different network devices, after receiving the verification result query request, the first network device will send the verification result query request to the second network device, and the second network device will query the corresponding verification result of the target certificate associated with the verification token information based on the verification token information, and return the verification result to the first network device.

[0082] In some embodiments, the first network device determines whether the target user has passed the identity authentication based on the verification result corresponding to the obtained target certificate. If the verification result of the NFC verification of the target certificate is that the verification has been passed, it is determined that the target user has passed the identity authentication. If the verification result of the NFC verification of the target certificate is that the verification has not been passed, it is determined that the target user has not passed the identity authentication. In some embodiments, the first network device returns the indication information indicating whether the target user has passed the identity authentication to the first user device to be presented to the target user on the first user device. Through the above steps, the NFC verification of the real certificate is completed on a device that does not support NFC through the cooperation of another NFC-supporting device, thereby ensuring the security and integrity of the identity authentication.

[0083] In the embodiment of this specification, a cross-device assisted verification NFC solution is proposed. After completing the human feature verification, the user needs to perform an NFC certificate verification. When the user's mobile phone does not support the NFC function, another device that supports the NFC function can be used to assist in the verification, thereby achieving the integrity and security of the NFC verification. This method effectively prevents injection attacks based on generative AI, and enables devices that do not support the NFC function to complete NFC real-person certificate verification, thereby successfully completing the KYC process. This method effectively prevents the risk of impersonation caused by generative AI injection attacks and ensures the accuracy and security of identity authentication. During the auxiliary verification process, the identity information of the person being verified, such as the ID card name, is stored in the backend server and represented by a token. The token is only passed to the auxiliary verification party. The auxiliary verification party cannot directly obtain the specific identity information of the person being verified, thereby effectively protecting the privacy of the person being verified. Even if the token is leaked during the verification or transmission process, it will not cause the leakage of user information, ensuring information security.

[0084] In some embodiments, the step of obtaining the user identity information input by the target user includes: determining whether the first user device supports NFC; if not, obtaining the user identity information input by the target user. In some embodiments, the capability information of the first user device is collected to determine whether the first user device supports the NFC function. If the first user device does not support the NFC function, the user identity information input by the target user is obtained. If the first user device supports the NFC function, the NFC page can be directly pulled up on the first user device, and the NFC module in the first user device is used to read at least one real certificate (i.e., the target certificate) owned by the target user provided by the user corresponding to the second user device, i.e., the NFC auxiliary verification user, to obtain the corresponding NFC information (i.e., the information read by the NFC module for the real target certificate), and then the user identity information input by the target user is compared with the NFC information, and the verification result corresponding to the target certificate is determined according to the comparison result, and the verification result is used to indicate whether the NFC verification of the target certificate (i.e., verifying whether the target certificate is the real certificate of the target user) is passed, wherein the NFC auxiliary verification user and the target user may be the same user, or may be two different users.

[0085] In some embodiments, the method further includes: in response to a sending trigger operation performed by the target user on the verification token information, sending the verification token information to the second user device. In some embodiments, in response to a sending trigger operation performed by the target user on the verification token information, the first user device will send the verification token information to the second user device. For example, the target user can send the verification token information to the NFC-assisted verification user in a social application, so that the first user device sends the verification token information to the NFC-assisted verification user corresponding to the NFC-assisted verification user, that is, the second user device.

[0086] In some embodiments, the method further includes: generating and presenting the graphic code information corresponding to the verification token information, so that the second user device obtains the verification token information by scanning the graphic code information. In some embodiments, the graphic code information corresponding to the verification token information can be generated first, and then the graphic code information can be presented to the target user on the first user device, wherein the graphic code information includes but is not limited to a QR code, a barcode, etc., and this specification does not limit this. In some embodiments, the target user can send the graphic code information to the second user device through the first user device, for example, the target user sends the graphic code information to the NFC auxiliary verification user in the social application, so that the first user device sends the graphic code information to the NFC verification user device corresponding to the NFC auxiliary verification user, that is, the second user device. In some embodiments, the second user device can obtain the verification token information based on the scanning operation performed by the NFC auxiliary verification user on the graphic code information presented on the first user device through the camera on the second user device. In some embodiments, the second user device can also obtain the verification token information based on the scanning operation performed by the NFC auxiliary verification user on the graphic code information sent by the first user device to the second user device through the camera on the second user device.

[0087] Figure 2 The flowchart of a method for identity authentication applied to a first network device is provided in an embodiment of the present specification. In the embodiment of the present specification, the method for identity authentication is applied to a second device for identity authentication or an electronic device equipped with a second device. Figure 2 The process shown is described in detail, and the method for identity authentication may specifically include the following steps:

[0088] S202, receiving user identity information of a target user sent by a first user device, and generating verification token information corresponding to the target user, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC.

[0089] In some embodiments, the target user has completed human feature verification on a first user device that does not support NFC, and the first user device sends the user identity information input by the target user to the first network device, where the user identity information includes but is not limited to the user's name, the document number of at least one real document owned by the user, etc. This specification does not limit the specific content of the user identity information.

[0090] In some embodiments, the first network device receives the user identity information of the target user sent by the first user device, and generates verification token information corresponding to the target user. The specific generation method has been described in the previous text and will not be repeated here.

[0091] S204: Return the verification token information to the first user equipment, so that the second user equipment performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user equipment.

[0092] In some embodiments, the first network device returns the verification token information to the first user device. After receiving the verification token information, the first user device can provide the verification token information to a second user device that supports NFC (i.e., an NFC verification user device). The second user device performs NFC verification on at least one real certificate owned by the target user (i.e., the target certificate) based on the verification token information. The specific verification method has been described in detail in the previous text and will not be repeated here.

[0093] S206, obtaining verification result information corresponding to the target certificate determined based on the verification token information, and determining whether the target user has passed the identity authentication according to the verification result information.

[0094] In some embodiments, in response to the target user continuing the identity authentication process, the first user will send a verification result query request corresponding to the verification token information to the first network device, and the verification result query request is used to query the verification result corresponding to the target certificate of the target user associated with the verification token information, that is, whether the NFC verification performed on the target certificate is successful based on the verification token information query, wherein the verification result query request includes the verification token information.

[0095] In some embodiments, after receiving the verification result query request, the first network device will obtain the verification result corresponding to the target certificate obtained based on the verification token information, and determine whether the target user has passed the identity authentication based on the verification result. If the verification result of the NFC verification of the target certificate is that the verification has passed, it is determined that the target user has passed the identity authentication. If the verification result of the NFC verification of the target certificate is that the verification has not passed, it is determined that the target user has not passed the identity authentication. The first network device may locally query the corresponding verification result of the target certificate of the target user associated with the verification token information based on the verification token information, or the first network device may send the verification result query request to the first network device. The second network device locally queries the corresponding verification result of the target certificate of the target user associated with the verification token information based on the verification token information, and returns the verification result to the first network device. At this time, the first network device and the second network device are two different network devices. The second network device (i.e., the NFC verification network device) is another NFC-supported user device other than the first user device, i.e., the network device corresponding to the second user device (i.e., the NFC verification user device). The user corresponding to the second user device (i.e., the NFC auxiliary verification user) can also be the target user, or the user corresponding to the second user device (i.e., the NFC auxiliary verification user) is another user other than the target user. In some embodiments, the first network device returns the indication information indicating whether the target user has passed the identity authentication to the first user device to present it to the target user on the first user device. Through the above steps, the NFC verification of the real certificate is completed on the device that does not support NFC through the cooperation of another NFC-supported device, ensuring the security and integrity of the identity authentication.

[0096] Figure 3 A flowchart of a method for identity authentication applied to a second user device provided in an embodiment of this specification is provided. In an embodiment of this specification, the method for identity authentication is applied to a third device for identity authentication or an electronic device equipped with a third device. Figure 3 The process shown is described in detail, and the method for identity authentication may specifically include the following steps:

[0097] S302, based on the verification token information corresponding to the target user provided by the first user device, the target certificate of the target user is read by NFC to obtain NFC information corresponding to the target certificate, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC.

[0098] In some embodiments, the target user has completed human feature verification on a first user device that does not support NFC. After receiving the verification token information returned by the first network device, the first user device can provide the verification token information to a second user device that supports NFC (i.e., the NFC verification user device). The second user device performs NFC reading on at least one real certificate owned by the target user (i.e., the target certificate) based on the verification token information to obtain the NFC information corresponding to the target certificate. The specific method for providing the verification token information has been described in detail in the previous text and will not be repeated here.

[0099] In some embodiments, after obtaining the verification token information provided by the first user device, the second user device will actively pull up the corresponding NFC page and request the user corresponding to the second user device, namely the NFC auxiliary verification user, to perform an auxiliary verification operation on at least one real certificate owned by the target user (ie, the target certificate); or, in response to the auxiliary verification request initiated by the NFC auxiliary verification user for the target certificate, pull up the corresponding NFC page to perform an auxiliary verification operation on the target certificate.

[0100] In some embodiments, the NFC module in the second user device is used to read at least one real certificate (i.e., target certificate) owned by the target user provided by the user corresponding to the second user device, i.e., the NFC assisted verification user, to obtain NFC information corresponding to the target certificate (i.e., the information read by the NFC module for the real target certificate), wherein the NFC assisted verification user and the target user may be the same user, or may be two different users.

[0101] In some embodiments, the certificate type of the target certificate that the target user needs to perform auxiliary verification on is specified for the target user by the first user device or the first network device, or the certificate type of the target certificate is selected by the target user on the first user device. In some embodiments, the second user device can send a corresponding auxiliary verification certificate type acquisition request to the first network device, and the auxiliary verification certificate type acquisition request includes the verification token information. The first network device will return the certificate type of the target certificate to the second user device based on the received verification token information. In some embodiments, the first user device will send the certificate type of the target certificate to the second user device while sending the verification token information to the second user device. In some embodiments, the first user device will generate corresponding graphic code information based on the verification token information and the certificate type of the target certificate, and the second user device can obtain the certificate type of the target certificate based on the graphic code information provided by the first user device.

[0102] In some embodiments, a plurality of different types of real certificates may be presented to the target user on the first user device, and the target user needs to select one of the multiple certificates as the target certificate for verification. In some embodiments, the first user device or the first network device may also specify a default type of real certificate for the target user as the target certificate for verification. In some embodiments, the first user device or the first network device may also determine a type of real certificate that matches the target user from a plurality of different types of real certificates based on the personal user information or user portrait of the target user as the target certificate for verification. In some embodiments, the first user device or the first network device may also determine a type of real certificate that matches the completion status from a plurality of different types of real certificates based on the completion status of the target user's human feature verification as the target certificate for verification, wherein the completion status includes but is not limited to the verification time, the number of verification retries, etc. of the target user during the human feature verification process, and this specification does not limit this.

[0103] S304, sending the NFC information and the verification token information to the second network device, so that the second network device obtains the user identity information of the target user according to the verification token information, performs verification based on the NFC information and the user identity information, and if the verification is successful, updates the status information corresponding to the verification token information, and, in response to receiving a verification result query request for the verification token information sent by the first network device, determines the verification result information corresponding to the target certificate according to the verification status, and returns the verification result information to the first network device, so that the first network device determines whether the target user passes the identity authentication according to the verification result information.

[0104] In some embodiments, the second user device sends the NFC information and the verification token information to the second network device, wherein the second network device (i.e., the NFC verification network device) is another NFC-supported user device other than the first user device, i.e., the network device corresponding to the second user device (i.e., the NFC verification user device), and the user corresponding to the second user device (i.e., the NFC auxiliary verification user) may also be the target user, or the user corresponding to the second user device (i.e., the NFC auxiliary verification user) is another user other than the target user. In some embodiments, the first network device and the second network device may be the same network device, or they may be two different network devices.

[0105] In some embodiments, the second network device obtains the user identity information of the target user associated with the verification token information (i.e., the user identity information entered by the target user on the first user device) based on the received verification token information, and then performs information comparison based on the user identity information and the NFC information, and determines the verification result corresponding to the target certificate based on the comparison result. The verification result is used to indicate whether the NFC verification of the target certificate (i.e., verifying whether the target certificate is the authentic certificate of the target user) is successful.

[0106] In some embodiments, if the verification is successful, the second network device locally updates the status information corresponding to the verification token information, that is, updates the status information corresponding to the verification token information to verified. Subsequently, after receiving the verification result query request for the verification token information sent by the first network device (the verification result query request includes the verification token information), the second network device verifies the status information corresponding to the verification token information, confirms the verification result corresponding to the target certificate, and returns the verification result to the first network device, so that the first network device determines whether the target user has passed the identity authentication based on the verification result. If the verification result of the NFC verification of the target certificate is verified, it is determined that the target user has passed the identity authentication. If the verification result of the NFC verification of the target certificate is not verified, it is determined that the target user has not passed the identity authentication (that is, the real certificate verification has not passed).

[0107] In some embodiments, the method further includes: receiving the verification token information sent by the first user device. In some embodiments, in response to the sending trigger operation performed by the target user on the verification token information, the first user device will send the verification token information to the second user device. For example, the target user can send the verification token information to the NFC-assisted verification user in the social application, so that the first user device sends the verification token information to the NFC-assisted verification user corresponding to the NFC-assisted verification user, that is, the second user device. In some embodiments, the verification token information can also be manually input by the NFC-assisted verification user on the second user device.

[0108] In some embodiments, the method further includes: obtaining the verification token information in response to a scanning operation performed on the graphic code information corresponding to the verification token information, wherein the graphic code information is generated on the first user device. In some embodiments, the first user device generates the graphic code information corresponding to the verification token information and presents the graphic code information to the target user, wherein the graphic code information includes but is not limited to a QR code, a barcode, etc., and this specification does not limit this. In some embodiments, the target user can send the graphic code information to the second user device through the first user device, and the second user device can obtain the verification token information based on the scanning operation performed by the NFC-assisted verification user through the camera on the second user device on the graphic code information received by the second user device. For example, the target user sends the graphic code information to the NFC-assisted verification user in the social application, so that the first user device sends the graphic code information to the NFC-assisted verification user corresponding to the NFC-assisted verification user, that is, the second user device. In some embodiments, the second user device can obtain the verification token information based on the scanning operation performed by the NFC-assisted verification user through the camera on the second user device on the graphic code information presented on the first user device.

[0109] Figure 4 A flowchart of a method for identity authentication applied to a second network device provided in an embodiment of this specification. In an embodiment of this specification, the method for identity authentication is applied to a fourth device for identity authentication or an electronic device equipped with a fourth device. Figure 4 The process shown is described in detail, and the method for identity authentication may specifically include the following steps:

[0110] S402, receiving NFC information corresponding to the target certificate of the target user and verification token information corresponding to the target certificate sent by the second user device, wherein the target user has completed human feature verification on the first user device, the first user device does not support NFC, and the second user device performs NFC reading on the target certificate based on the verification token information provided by the first user device to obtain the NFC information.

[0111] In some embodiments, the target user has completed human feature verification on a first user device that does not support NFC. The NFC module on the second user device reads at least one real certificate (i.e., the target certificate) owned by the target user provided by the NFC-assisted verification user to obtain corresponding NFC information (i.e., the information read by the NFC module for the real target certificate). The second user device then sends the NFC information and the verification token information to the second network device.

[0112] S404, obtaining the user identity information of the target user according to the verification token information, performing verification based on the NFC information and the user identity information, and if the verification is successful, updating the status information corresponding to the verification token information.

[0113] In some embodiments, the second network device obtains the user identity information of the target user associated with the verification token information (i.e., the user identity information entered by the target user on the first user device) based on the received verification token information, and then performs information comparison based on the user identity information and the NFC information, and determines the verification result corresponding to the target certificate based on the comparison result. The verification result is used to indicate whether the NFC verification of the target certificate (i.e., verifying whether the target certificate is the authentic certificate of the target user) is successful.

[0114] In some embodiments, if the verification is successful, the second network device locally updates the status information corresponding to the verification token information, that is, updates the status information corresponding to the verification token information to verified.

[0115] S406, receiving a verification result query request regarding the verification token information sent by the first network device, determining the verification result information corresponding to the target certificate according to the verification status, and returning the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0116] In some embodiments, after receiving a verification result query request regarding the verification token information sent by the first network device (the verification result query request includes the verification token information), the second network device verifies the status information corresponding to the verification token information, confirms the verification result corresponding to the target certificate, and returns the verification result to the first network device, so that the first network device determines whether the target user has passed the identity authentication based on the verification result. If the verification result of the NFC verification of the target certificate is passed, it is determined that the target user has passed the identity authentication. If the verification result of the NFC verification of the target certificate is failed, it is determined that the target user has not passed the identity authentication.

[0117] In some embodiments, the verification based on the NFC information and the user identity information includes: performing information comparison verification and signature verification based on the NFC information and the user identity information. In some embodiments, the NFC information includes the certificate information and signature information of the real target certificate read by the first user device through the NFC module, wherein the certificate information includes but is not limited to any information on the target certificate, such as user name, certificate number, etc., and this specification does not limit the specific content of the certificate information.

[0118] In some embodiments, the second network device compares and verifies the user identity information input by the target user on the first user device with the certificate information of the real target certificate read by the second user device through the NFC module, and performs signature verification on the signature information of the real target certificate read by the second user device through the NFC module (the certificate information of the target certificate (such as user name, certificate number, photo, etc.) is stored in the chip of the real target certificate and is accompanied by a digital signature. When the target certificate is read through NFC, the public key is required to verify the validity of the signature. If the signature matches, it means that the data is complete and credible; if the signature verification fails, it means that the data may have been tampered with or forged, that is, the signature information of the target certificate needs to be signature verified). Only when both the information comparison verification and the signature verification pass, will the verification result corresponding to the target certificate be determined as the NFC verification of the target certificate has passed. If the information comparison verification fails or the signature verification fails, the verification result corresponding to the target certificate will be determined as the NFC verification of the target certificate has not passed. In some embodiments, the information comparison verification operation and the signature verification operation are both performed by the second network device. In some embodiments, the information comparison and verification operation is performed by the second network device, and the signature verification operation is performed by the NFC signature verification network device (different from the NFC verification network device, i.e., the second network device). The second network device will send the signature information of the real target certificate read by the second user device through the NFC module to the NFC signature verification network device, which will perform signature verification on the signature information and return the corresponding signature verification result to the second network device. Here, since the signature information of the target certificate can only be obtained through the real target certificate, even if the attacker obtains control of the user device, he cannot attack by injecting forged information. Through this mechanism, the risk of injection attack on the user is effectively avoided.

[0119] Figure 5 A flowchart of an example method for identity authentication provided in an embodiment of this specification.

[0120] like Figure 5As shown, the eKyc user (i.e., the user who authenticates his identity electronically) has completed face verification on an application app that does not support NFC. The eKyc user initiates verification of the real person's ID (i.e., the real ID), and the application app collects the device's capability information. If the device does not support NFC, the application app initiates online account opening to the corresponding application server. The application server collects the user's name and ID number (such as ID card number), and the application app renders the collection page. The eKyc user enters the name and ID number, and the application app sends the name and ID number to the application server. The application server requests the corresponding NFC verification server to initialize, obtain the verification token, and save the name and ID number. The NFC verification server is initialized successfully and returns the token to the application server. The application server returns the token to the application app, and the application app renders the QR code corresponding to the token. The eKyc user sends the QR code to the NFC verification app that supports NFC, or the NFC verification app directly scans the QR code on the application app, and the NFC verification app initiates an auxiliary verification request to the NFC auxiliary verification user. Request, NFC assisted verification user handles auxiliary verification, NFC verification app pulls up the NFC page, reads the user ID of the eKyc user, and obtains the corresponding NFC information. The NFC verification app sends the token corresponding to the QR code and the NFC information to the NFC verification server. The NFC verification server obtains the name and ID number based on the token, compares the information based on the obtained name, ID number and NFC information, and sends the signature information in the NFC information to the NFC signature verification server for signature verification. If the verification passes, the token status is updated and the NFC verification app is notified that the verification passes. The NFC verification app notifies the NFC assisted verification user that the verification passes. The eKyc user uses the token to continue the eKyc process (i.e., identity verification process). The application app queries the application server whether the token is verified. The application server queries the NFC verification sever whether the token is verified. The NFC verification sever notifies the application server that the verification passes. The application server notifies the application app that the real person ID (i.e., the real ID) is verified. The application app notifies the eKyc user that the real person ID is verified.

[0121] Figure 6The structural diagram of a first device for identity authentication provided in an embodiment of this specification, the first device for identity authentication (hereinafter referred to as "first device 1") can be implemented as all or part of an electronic device through software, hardware or a combination of both. According to some embodiments, the first device 1 includes a certificate information input module 11, a first receiving module 12 and a verification result query module 13.

[0122] The certificate information input module 11 is used to obtain the user identity information input by the target user, and send the user identity information to the first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC, and the target user has completed human feature verification on the first user device;

[0123] A first receiving module 12 is used to receive the verification token information returned by the first network device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device;

[0124] The verification result query module 13 is used to send a verification result query request corresponding to the verification token information to the first network device, so that the first network device obtains the verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user has passed the identity authentication based on the verification result information.

[0125] In some embodiments, obtaining the user identity information input by the target user includes:

[0126] Determining whether the first user equipment supports NFC;

[0127] If not, obtain the user identity information input by the target user.

[0128] In some embodiments, the first device 1 is further used for:

[0129] In response to a sending trigger operation performed by the target user on the verification token information, the verification token information is sent to the second user equipment.

[0130] In some embodiments, the first device 1 is further used for:

[0131] Generate and present graphic code information corresponding to the verification token information, so that the second user equipment obtains the verification token information by scanning the graphic code information.

[0132] Figure 7A schematic diagram of the structure of a second device for identity authentication provided in an embodiment of this specification, the second device for identity authentication (hereinafter referred to as "second device 2") can be implemented as all or part of an electronic device through software, hardware or a combination of both. According to some embodiments, the second device 2 includes a verification token generation module 21, a first sending module 22 and a verification result acquisition module 23.

[0133] A verification token generation module 21 is used to receive user identity information of a target user sent by a first user device, and generate verification token information corresponding to the target user, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC;

[0134] A first sending module 22, configured to return the verification token information to the first user equipment, so that the second user equipment performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user equipment;

[0135] The verification result obtaining module 23 is used to obtain verification result information corresponding to the target certificate determined based on the verification token information, and determine whether the target user has passed the identity authentication according to the verification result information.

[0136] Figure 8 A schematic diagram of the structure of a third device for identity authentication provided in an embodiment of this specification, the third device for identity authentication (hereinafter referred to as "third device 3") can be implemented as all or part of an electronic device through software, hardware or a combination of both. According to some embodiments, the third device 3 includes an NFC authentication module 31 and a second sending module 32.

[0137] The NFC verification module 31 is used to perform NFC reading on a target certificate of a target user based on verification token information corresponding to a target user provided by a first user device, and obtain NFC information corresponding to the target certificate, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC;

[0138] The second sending module 32 is used to send the NFC information and the verification token information to the second network device, so that the second network device obtains the user identity information of the target user according to the verification token information, performs verification based on the NFC information and the user identity information, and if the verification is successful, updates the status information corresponding to the verification token information, and, in response to receiving a verification result query request for the verification token information sent by the first network device, determines the verification result information corresponding to the target certificate according to the verification status, and returns the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0139] In some embodiments, the third device 3 is further used for:

[0140] Receive the verification token information sent by the first user equipment.

[0141] In some embodiments, the third device 3 is further used for:

[0142] The verification token information is obtained in response to a scanning operation performed on graphic code information corresponding to the verification token information, wherein the graphic code information is generated on the first user device.

[0143] Fig. 9 A schematic diagram of the structure of a fourth device for identity authentication provided in an embodiment of this specification, the fourth device for identity authentication (hereinafter referred to as "fourth device 4") can be implemented as all or part of an electronic device through software, hardware or a combination of both. According to some embodiments, the fourth device 4 includes a second receiving module 41, a verification module 42 and a verification result determination module 43.

[0144] The second receiving module 41 is configured to receive NFC information corresponding to a target certificate of a target user and verification token information corresponding to the target certificate, sent by a second user device, wherein the target user has completed human feature verification on a first user device, the first user device does not support NFC, and the second user device performs NFC reading on the target certificate based on the verification token information provided by the first user device to obtain the NFC information;

[0145] A verification module 42, configured to obtain the user identity information of the target user according to the verification token information, perform verification based on the NFC information and the user identity information, and if the verification is successful, update the status information corresponding to the verification token information;

[0146] The verification result determination module 43 is used to receive a verification result query request regarding the verification token information sent by the first network device, determine the verification result information corresponding to the target certificate according to the verification status, and return the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information.

[0147] In some embodiments, the verification based on the NFC information and the user identity information includes:

[0148] Information comparison verification and signature verification are performed based on the NFC information and the user identity information.

[0149] The above device embodiments correspond to the method embodiments. For specific descriptions, please refer to the description of the method embodiments, which will not be repeated here. The device embodiments are obtained based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments. For specific descriptions, please refer to the corresponding method embodiments.

[0150] The embodiment of the present specification also provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor to execute the method of the embodiment of the present specification.

[0151] The embodiments of the present specification also provide a computer program product, which stores at least one instruction, and the at least one instruction is loaded by the processor to execute the method of the embodiments of the present specification.

[0152] The embodiments of this specification also provide Fig.10 The structural diagram of the electronic device shown in FIG. Fig.10 At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the method of the embodiment of this specification.

[0153] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0154] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0155] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0156] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0157] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0158] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0159] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0160] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0161] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.

Claims

1. A method for identity authentication, applied to a first user device, comprising: Obtain user identity information input by a target user, and send the user identity information to a first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC, the target user has completed human feature verification on the first user device, and the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information; receiving the verification token information returned by the first network device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device, wherein the target certificate is provided to the second user device by an NFC-assisted verification user corresponding to the second user device, and the NFC-assisted verification user includes other users except the target user; A verification result query request corresponding to the verification token information is sent to the first network device, so that the first network device obtains the verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user has passed the identity authentication based on the verification result information, wherein the verification result query request includes the verification token information.

2. According to the method of claim 1, the step of obtaining the user identity information input by the target user comprises: Determining whether the first user equipment supports NFC; If not, obtain the user identity information input by the target user.

3. The method according to claim 1, further comprising: In response to a sending trigger operation performed by the target user on the verification token information, the verification token information is sent to the second user equipment.

4. The method according to claim 1, further comprising: Generate and present graphic code information corresponding to the verification token information, so that the second user equipment obtains the verification token information by scanning the graphic code information.

5. A method for identity authentication, applied to a first network device, comprising: Receive user identity information of a target user sent by a first user device, and generate verification token information corresponding to the target user, wherein the target user has completed human feature verification on the first user device, the first user device does not support NFC, and the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information; Returning the verification token information to the first user device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device, wherein the target certificate is provided to the second user device by an NFC auxiliary verification user corresponding to the second user device, and the NFC auxiliary verification user includes other users except the target user; Obtain verification result information corresponding to the target certificate determined based on the verification token information, and determine whether the target user has passed the identity authentication according to the verification result information, wherein the verification result query request includes the verification token information.

6. A method for identity authentication, applied to a second user device, comprising: Based on the verification token information corresponding to the target user provided by the first user device, the target certificate of the target user is read by NFC to obtain the NFC information corresponding to the target certificate, wherein the target user has completed the human feature verification on the first user device, the first user device does not support NFC, the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information, and the target certificate is provided to the second user device by the NFC auxiliary verification user corresponding to the second user device, and the NFC auxiliary verification user includes other users except the target user; The NFC information and the verification token information are sent to a second network device, so that the second network device obtains the user identity information of the target user according to the verification token information, performs verification based on the NFC information and the user identity information, and if the verification is successful, updates the status information corresponding to the verification token information, and, in response to receiving a verification result query request regarding the verification token information sent by the first network device, determines the verification result information corresponding to the target certificate according to the status information, and returns the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information, wherein the verification result query request includes the verification token information.

7. The method according to claim 6, further comprising: Receive the verification token information sent by the first user equipment.

8. The method according to claim 6, further comprising: The verification token information is obtained in response to a scanning operation performed on graphic code information corresponding to the verification token information, wherein the graphic code information is generated on the first user device.

9. A method for identity authentication, applied to a second network device, comprising: Receive NFC information corresponding to a target certificate of a target user and verification token information corresponding to the target certificate, sent by a second user device, wherein the target user has completed human feature verification on the first user device, the first user device does not support NFC, and the second user device performs NFC reading on the target certificate based on the verification token information provided by the first user device to obtain the NFC information, the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information, and the target certificate is provided to the second user device by an NFC-assisted verification user corresponding to the second user device, and the NFC-assisted verification user includes other users except the target user; Obtain the user identity information of the target user according to the verification token information, perform verification based on the NFC information and the user identity information, and if the verification is successful, update the status information corresponding to the verification token information; Receive a verification result query request regarding the verification token information sent by the first network device, determine the verification result information corresponding to the target certificate based on the status information, and return the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication based on the verification result information, wherein the verification result query request includes the verification token information.

10. The method according to claim 9, wherein the verification based on the NFC information and the user identity information comprises: Information comparison verification and signature verification are performed based on the NFC information and the user identity information.

11. A first device for identity authentication, comprising: a certificate information input module, used to obtain user identity information input by a target user, and send the user identity information to a first network device, so that the first network device generates verification token information corresponding to the target user, wherein the first user device does not support NFC, the target user has completed human feature verification on the first user device, and the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information; A first receiving module is configured to receive the verification token information returned by the first network device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device, wherein the target certificate is provided to the second user device by an NFC auxiliary verification user corresponding to the second user device, and the NFC auxiliary verification user includes other users except the target user; A verification result query module is used to send a verification result query request corresponding to the verification token information to the first network device, so that the first network device obtains the verification result information corresponding to the target certificate determined based on the verification token information, and determines whether the target user has passed the identity authentication based on the verification result information, wherein the verification result query request includes the verification token information.

12. A second device for identity verification, comprising: a verification token generation module, configured to receive user identity information of a target user sent by a first user device, and generate verification token information corresponding to the target user, wherein the target user has completed human feature verification on the first user device, and the first user device does not support NFC, wherein the target certificate is provided to the second user device by an NFC-assisted verification user corresponding to the second user device, and the NFC-assisted verification user includes other users except the target user; A first sending module, configured to return the verification token information to the first user device, so that the second user device performs NFC verification on the target certificate of the target user based on the verification token information provided by the first user device, wherein the target certificate is provided to the second user device by an NFC auxiliary verification user corresponding to the second user device, and the NFC auxiliary verification user includes other users except the target user; A verification result obtaining module is used to obtain verification result information corresponding to a target certificate based on the verification token information, and determine whether the target user has passed identity authentication according to the verification result information, wherein the verification result query request includes the verification token information.

13. A third device for identity authentication, comprising: An NFC verification module is configured to perform NFC reading on a target certificate of a target user based on verification token information corresponding to a target user provided by a first user device, and obtain NFC information corresponding to the target certificate, wherein the target user has completed human feature verification on the first user device, the first user device does not support NFC, the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information, and the target certificate is provided to the second user device by an NFC auxiliary verification user corresponding to the second user device, and the NFC auxiliary verification user includes other users except the target user; A second sending module is used to send the NFC information and the verification token information to a second network device, so that the second network device obtains the user identity information of the target user according to the verification token information, performs verification based on the NFC information and the user identity information, and if the verification is successful, updates the status information corresponding to the verification token information, and, in response to receiving a verification result query request regarding the verification token information sent by the first network device, determines the verification result information corresponding to the target certificate according to the status information, and returns the verification result information to the first network device, so that the first network device determines whether the target user has passed the identity authentication according to the verification result information, wherein the verification result query request includes the verification token information.

14. A fourth device for identity authentication, comprising: A second receiving module is configured to receive NFC information corresponding to a target certificate of a target user and verification token information corresponding to the target certificate, which is sent by a second user device, wherein the target user has completed human feature verification on the first user device, the first user device does not support NFC, and the second user device performs NFC reading on the target certificate based on the verification token information provided by the first user device to obtain the NFC information, the verification token information is randomly generated, different users correspond to different verification token information, and different types of certificates of the same user also correspond to different verification token information, and the target certificate is provided to the second user device by an NFC-assisted verification user corresponding to the second user device, and the NFC-assisted verification user includes other users except the target user; A verification module, used to obtain the user identity information of the target user according to the verification token information, perform verification based on the NFC information and the user identity information, and if the verification is successful, update the status information corresponding to the verification token information; A verification result determination module is used to receive a verification result query request regarding the verification token information sent by the first network device, determine the verification result information corresponding to the target certificate based on the status information, and return the verification result information to the first network device so that the first network device determines whether the target user has passed the identity authentication based on the verification result information, wherein the verification result query request includes the verification token information.

15. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

16. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the method as claimed in any one of claims 1 to 10.

17. A computer program product having at least one instruction stored thereon, characterized in that: When the at least one instruction is executed by the processor, the steps of the method described in any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Data acquisition method and device, terminal and wearable device

    CN108462674A