Identity verification method, apparatus, device, storage medium, and program product

By combining user intent, information, and access platform, a suitable combination of verification methods is determined, different verification methods are integrated, and the identity verification process is optimized. This solves the problem of low identity verification accuracy and achieves more efficient resource utilization and secure access.

CN119363377BActive Publication Date: 2025-12-12MASHANG CONSUMER FINANCE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411329983.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-20
Publication Date
2025-12-12
Estimated Expiration
2044-09-20

AI Technical Summary

Technical Problem

The accuracy of existing authentication methods cannot be guaranteed, resulting in excessive resource consumption and a decline in user experience.

Method used

By combining user intent, information, and access platform, a suitable combination of verification methods can be determined, integrating the advantages of different verification methods and optimizing the decision-making process using identity verification records.

Benefits of technology

It improves the accuracy of identity verification, reduces unnecessary resource consumption, and enhances user experience and access security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363377B_ABST
    Figure CN119363377B_ABST
Patent Text Reader

Abstract

The present application discloses an identity verification method, device, equipment, storage medium and program product, which is used for making full use of the performance of different identity verification methods, improving the accuracy and efficiency of identity verification, and reducing resource consumption. The identity verification method comprises the following steps: determining the intention of a user, user information and a first identity verification record based on an access request submitted by the user through a first access platform; determining a first verification method combination suitable for the user from a plurality of verification method combinations based on the first access platform, the user information and the intention; determining whether to perform identity verification on the user based on the first verification method combination and the first identity verification record; and if it is determined to perform identity verification on the user, performing identity verification on the user based on the first verification method combination.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and particularly relates to an identity verification method and device, equipment, a storage medium and a program product. BACKGROUND

[0002] Identity verification is an important means to realize secure communication. By verifying the identity of a user, unauthorized access can be effectively prevented, and user data and system security can be protected. With the rapid development of Internet technology, various identity verification methods emerge in an endless stream. The choice of which identity verification method to use for identity verification often depends on the specific needs of the applicant or the terminal user, resulting in an inability to guarantee the accuracy of identity verification. SUMMARY

[0003] The purpose of the embodiments of the present application is to provide an identity verification method, device, equipment, storage medium and program product, which can make full use of the performance of different identity verification methods, improve the accuracy and efficiency of identity verification, and reduce resource consumption.

[0004] In order to achieve the above-mentioned purpose, the embodiments of the present application adopt the following technical solutions:

[0005] In a first aspect, the embodiments of the present application provide an identity verification method, comprising:

[0006] determining the intention of a user, user information and a first identity verification record based on an access request submitted by the user through a first access platform;

[0007] determining a first verification method combination suitable for the user from a plurality of verification method combinations based on the first access platform, the user information and the intention;

[0008] determining whether to perform identity verification on the user based on the first verification method combination and the first identity verification record;

[0009] if it is determined to perform identity verification on the user, performing identity verification on the user based on the first verification method combination.

[0010] In a second aspect, the embodiments of the present application provide an identity verification device, comprising:

[0011] a determination module configured to determine the intention of a user, user information and a first identity verification record based on an access request submitted by the user through a first access platform;

[0012] The determination module is further configured to determine a first verification method combination suitable for the user from a plurality of verification method combinations based on the first access platform, the user information and the intention;

[0013] a decision module configured to determine whether to authenticate the user based on the first authentication mode combination and the first identity authentication record;

[0014] a verification module configured to authenticate the user based on the first authentication mode combination if it is determined to authenticate the user.

[0015] In a third aspect, an embodiment of the present application provides an electronic device, comprising:

[0016] a processor;

[0017] a memory configured to store instructions executable by the processor;

[0018] The processor is configured to execute the instructions to implement the identity authentication method according to the first aspect.

[0019] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the identity authentication method according to the first aspect.

[0020] In a fifth aspect, an embodiment of the present application provides a computer program product, the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to perform some or all of the steps of the identity authentication method according to the first aspect.

[0021] The above at least one technical solution adopted by the embodiments of the present application can achieve the following beneficial effects:

[0022] Since different users have different risks in the process of accessing the business system without intention, and different access platforms have unique business characteristics, the first verification mode combination determined based on the first access platform, user information and intention can better adapt to the risk existing in the access request, and the first verification mode combination contains at least two verification modes, compared with selecting a single verification mode, the functions of different verification modes can be fully played, which is helpful to more accurately verify the identity of the user, improve the verification accuracy, and thus improve the access security; secondly, the first identity verification record describes the identity verification situation of the user before, such as whether the user has been verified, whether the identity verification is successful, and the verification mode used for verifying the user, etc. Based on the first identity verification record and the first verification mode combination, it can be determined whether the user has risks and whether the verification mode in the first verification mode combination is effective, and then it can be determined whether it is necessary to verify the identity of the user this time. In the case of determining to verify the identity of the user, the identity of the user is verified based on the first verification mode combination. In this way, the integration and data interconnection between the originally discrete verification modes can be realized, the problems such as the decline of user experience and excessive resource consumption caused by unnecessary identity verification can be avoided, the resource utilization rate can be improved, and the access request of the user can be responded in time. BRIEF DESCRIPTION OF DRAWINGS

[0023] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application, and do not limit the application. In the drawings:

[0024] Figure 1 A schematic diagram of an implementation environment suitable for the identity verification method provided by an embodiment of the application;

[0025] Figure 2 A flowchart of an identity verification method provided by an embodiment of the application;

[0026] Figure 3 A flowchart of an identity verification method provided by another embodiment of the application;

[0027] Figure 4 A structural schematic diagram of an identity verification device provided by an embodiment of the application;

[0028] Figure 5 A structural schematic diagram of an electronic device provided by an embodiment of the application. DETAILED DESCRIPTION

[0029] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described below in connection with specific embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0030] The terms "first", "second", and the like in the specification and claims are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means that the front and rear associated objects are in an "or" relationship.

[0031] It should be understood that the identity verification method provided by the embodiments of the present application can be executed by an electronic device. Here, the so-called electronic device can include terminal devices such as smartphones, tablet computers, notebook computers, desktop computers, smart voice interaction devices, smart home appliances, smart watches, vehicle-mounted terminals, aircraft, etc.; or the electronic device can also include servers such as independent physical servers, and can also be a server cluster or distributed system composed of multiple physical servers, and can also be a cloud server providing cloud computing services.

[0032] The technical solutions provided by the embodiments of the present application will be described in detail below in connection with the drawings.

[0033] In order to facilitate the understanding of the technical solutions provided by the embodiments of the present application, first, the technical solutions provided by the embodiments of the present application will be described in connection with Figure 1 The implementation environment to which the technical solutions provided by the embodiments of the present application are applicable will be described. It should be understood that the technical solutions provided by the embodiments of the present application are applicable to Figure 1 The implementation environment shown is only an exemplary description, and should not be understood as a limitation on the implementation environment to which the technical solutions are applicable.

[0034] As Figure 1 shown, an implementation environment to which the technical solutions provided by the embodiments of the present application are applicable includes a plurality of access platforms and business systems.

[0035] The access platform provides services of the access service system. The multiple access platforms may include, for example, but are not limited to, an instant messaging assistant (IMA), a customer service hotline system, an intelligent customer service system, and the like. A user can access the service system through any access platform and submit an access purpose and specific requirements. Once receiving an access request of the user, the access platform forwards the access request to the service system for processing. The access request carries a user identifier and a text describing requirements.

[0036] The service system includes a decision engine and a data processing module. After receiving the access request, the decision engine immediately starts a data retrieval process, obtains user information and a first identity verification record of the user based on the user identifier carried in the access request, and provides reliable data support for subsequent identity verification decision.

[0037] The decision engine also performs intent recognition based on the text describing requirements carried in the access request to obtain an intent of the user, and makes a decision based on the user information, the intent, an access platform receiving the access request, and the first identity verification record to determine whether to perform identity verification on the user and a first verification method combination suitable for the user. The first verification method combination includes at least two of the following verification methods: face verification, lip reading verification, three-element (face, name, and ID card) verification, auxiliary question verification, 5G video verification, dial pad verification, and the like. If it is determined to perform identity verification on the user, the first verification method is recommended to a customer service, and the verification method selected by the customer service is pushed to the access platform receiving the access request to complete identity verification on the user through the access platform, ensuring seamless connection of the process. Finally, the access platform displays / synchronizes the identity verification result.

[0038] The data processing module also generates an identity verification record of this verification based on related information (such as the first verification method combination, the verification method selected by the customer service, verification process data, and the like) used in the identity verification process of the user and a verification result, and stores the identity verification record in a database as support data for future decision and a reference basis for risk assessment, thereby realizing effective recycling and management optimization of data, and facilitating deep improvement of a user portrait and accurate implementation of risk assessment. In actual application, the verification process data can be obtained by the data processing module through listening or burying. For example, taking lip reading verification as an example, the lip reading verification process is divided into four steps of sending a verification code, verifying the verification code, user lip reading verification, and processing the verification result, a listener is added in each of the steps to collect user process data, and / or burying point data is added in each of the steps to report various system data, and after grouping, cleaning, and analyzing the collected user process data and the reported various system data, the verification process data is obtained after being packaged.

[0039] Please refer toFigure 2 The following is a flowchart illustrating an authentication method provided in one embodiment of this application. The method includes the following steps:

[0040] S202, based on the access request submitted by the user through the first access platform, determine the user's intent, user information, and first authentication record.

[0041] The first access platform is Figure 1 This is one of several access platforms shown. An access request is used to request access to a service provided by an application server, such as a loan service. The access request carries at least one of the following information: the user's identifier (such as the user's username, contact information, etc.) and text entered by the user indicating their request.

[0042] Intent indicates a user's motivation for accessing a service. As one example, the user's intent is determined based on the service requested in the access request. For instance, if the requested service is early loan repayment, the user's intent is determined to be early loan repayment. As another example, Natural Language Processing (NLP) techniques are used to identify the user's intent from the text carried in the access request. For example, if the access request contains the text "My loan is paid off, please issue me a repayment certificate," NLP techniques can identify the user's intent as "Issue a repayment certificate."

[0043] User information describes a user's detailed characteristics, including but not limited to: basic information, profile tags, access behavior, and device information. Basic information includes entry-level statistical characteristics such as age, gender, and geographic location. Profile tags describe a user's profile; for example, a user who prefers to consume on credit and then pay off the loan would be tagged as "pay later"; another example is a user who likes to report problems through complaints, who would be tagged as "high-risk complaint." Access behavior includes services the user has previously visited and the frequency of access to various services provided by the business system. Device information includes the type of device the user uses, operating system, and browser preferences. As an example, user information is retrieved from the database based on the user identifier carried in the access request.

[0044] The first identity authentication record refers to a record of identity authentication of the user before the user submits the access request. The first identity authentication record may for example include at least one of the following information: whether the user has been authenticated before submitting the current access request, whether the identity authentication is successful, a recommended authentication mode combination applicable to the user, an authentication mode used for identity authentication of the user, etc. As an example, according to the user identifier carried in the access request, the first identity authentication record of the user is found in the database.

[0045] S204, determining, based on the first access platform, the user information and the intent, a first authentication mode combination applicable to the user from a plurality of authentication mode combinations.

[0046] Each authentication mode combination includes at least two authentication modes arranged in order. As an example, each authentication mode combination can include a preferred authentication mode, a secondary authentication mode and an alternative authentication mode. The preferred authentication mode refers to the first authentication mode. The secondary authentication mode refers to the second authentication mode, which can be selected in the case that the preferred authentication mode cannot be used or is denied by human subjectivity. The alternative authentication mode refers to the third authentication mode, which can be selected in the case that the preferred and secondary authentication modes cannot be used or are considered to be denied by human subjectivity.

[0047] Since different users have different risks in the process of accessing the business system without intent, and different access platforms have unique business characteristics, the first authentication mode combination determined based on the first access platform, the user information and the intent can better adapt to the risk existing in the current access request, and the first authentication mode combination includes at least two authentication modes, which can fully play the role of different authentication modes compared to selecting a single authentication mode in isolation, helping to more accurately identity authenticate the user, improving the authentication accuracy, and thus improving the access security.

[0048] In the embodiments of the present application, the above S204 can be implemented in various ways, which are not limited in the present application.

[0049] In one implementation, the above S204 includes the following steps:

[0050] S241, determining a first business scenario matching the intent from a plurality of business scenarios.

[0051] As an example, the business scenario corresponding to the intent obtained in S202 can be determined as the first business scenario from a plurality of business scenarios based on a preset correspondence between the business scenarios and the intents. For example, the business scenario corresponding to the intent "issue a clearance certificate" is "clearance certificate", the business scenario corresponding to the intent "consult membership fee" is "membership fee", the business scenario corresponding to the intent "apply for early repayment" is "early clearance", and so on.

[0052] As another example, for each business scenario, a text used to describe the business scenario is matched with the intent to obtain a matching degree between the business scenario and the intent; from a plurality of business scenarios, a third business scenario with a matching degree greater than or equal to a first threshold value is determined, and a fourth business scenario associated with the third business scenario is determined; and the third business scenario and the fourth business scenario are determined as the first business scenario matching the intent.

[0053] The association relationship between the business scenarios can be preset according to actual needs. For example, Table 1 below shows an example of an association relationship between business scenarios.

[0054] Table 1

[0055]

[0056] The name and code of the business scenario are globally unique. The text used to describe the business scenario can include the name of the business scenario. Matching the text used to describe the business scenario with the intent can be implemented using various matching techniques commonly used in the art, such as calculating the distance between the text and the intent, the semantic similarity, and the like, which are not limited by the embodiments of the present application. The first threshold value can be set according to actual needs, which is not limited by the embodiments of the present application.

[0057] For example, assuming that the intent is "I want to repay", by matching the intent with the text used to describe each business scenario, two third business scenarios, "early clearance" and "partial early clearance", are obtained. Based on Table 1, the fourth business scenarios associated with the third business scenario "early clearance" include "periodical repayment", and these business scenarios are determined as the first business scenario matching the intent. The name, code and matching degree between the intent of each first business scenario are shown in Table 2.

[0058] Table 2

[0059]

[0060] Considering that in real businesses, there is often relevance between business scenarios, by taking the third business scenario with high matching degree and the fourth business scenario associated with the third business scenario as the first business scenario matched with the intent, and determining the first verification manner combination on this basis, it can be ensured that the first verification manner combination covers all relevant business scenarios, which is beneficial to improve the accuracy of identity verification.

[0061] As another example, for each business scenario, the text used to describe the business scenario is matched with the intent to obtain a first matching degree between the business scenario and the intent; based on the first matching degree between the business scenario and the intent and an interference factor of the business scenario, a second matching degree between the business scenario and the intent is obtained; from the plurality of business scenarios, a business scenario with a second matching degree greater than or equal to a first threshold value with the intent is determined as a first business scenario matched with the intent.

[0062] Wherein, the interference factor of each business scenario can be simply understood as adding or subtracting points on the basis of the first matching degree. The interference factor of each business scenario can be set according to actual needs, which is not limited by the embodiments of the present application. For example, in order to guide the user to repay the loan as much as possible, the interference factor of the business scenario "repayment of loan" can be set to a relatively large positive number, so that the second matching degree of the business scenario for the intent is higher, and it can be considered first when determining the first verification manner combination.

[0063] S242, from the plurality of verification manners, determine at least one second verification manner combination applicable to the first business scenario and the first access platform based on the business scenario and the access platform to which each verification manner combination is applicable.

[0064] The business scenario applicable to each authentication mode combination is also referred to as a second business scenario, so as to be distinguished from the first business scenario in the foregoing. The access platform applicable to each authentication mode combination is also referred to as a second access platform, so as to be distinguished from the scenario of submitting an access request. The second business scenario and the second access platform applicable to different authentication mode combinations are different, and the second business scenario and the second access platform applicable to each authentication mode combination can be preconfigured according to actual needs. Optionally, each authentication mode combination can also have other attributes, for example, at least one of the following attributes, including but not limited to: a name, a code, a risk level, a first score, applicable user conditions, and the like. Among them, the name and the code are used to globally uniquely identify the authentication mode combination, the risk level indicates the risk level that can be coped with by the authentication mode combination, the first score indicates the recommended strength of the authentication mode level, and the applicable user conditions refer to the conditions required to be met by the user to which the authentication mode combination is applicable. These attributes can be set according to actual needs, and embodiments of the present application do not limit this. In actual application, in order to realize fine-grained access security control, the risk level can be divided into six levels: high, high-medium, high, medium, low-medium, and lowest. The first score can be a value between 0 and 10.

[0065] For example, Table 3 below shows an example of an authentication mode combination and its attributes.

[0066] Table 3

[0067]

[0068] As an example, for each authentication mode combination, the business scenario applicable to the authentication mode combination is compared with the first business scenario, and the access platform applicable to the authentication mode combination is compared with the first access platform. If both comparisons are successful, the authentication mode combination is determined as a second authentication mode combination.

[0069] S243, determining, based on the user information and the user conditions applicable to each second authentication mode combination, a first authentication mode combination applicable to the user from at least one second authentication mode combination.

[0070] The user conditions applicable to different authentication mode combinations are also different. For example, the user condition 1 applicable to the authentication mode combination 1 includes: the user is the principal, the user is a real-name user, and the portrait label of the user is “priority of enjoying first and paying later”; or the user is the principal, the current date is the repayment day of the user, and the portrait label of the user is “priority of enjoying first and paying later”. Among them, the principal means that the access request is issued by the user himself, and the non-principal means that the access request is issued by someone on behalf of the user.

[0071] As an example, for each second authentication mode combination, the user information is compared with the user condition applicable to the second authentication mode, and if the user information satisfies the user condition, the second authentication mode combination is determined as the first authentication mode combination applicable to the user.

[0072] As another example, for each second authentication mode combination, a second score of the second authentication mode is determined based on the risk level of the second authentication mode combination and the first score; the at least one second authentication mode combination is traversed in descending order of the second score; if the user information satisfies the user condition applicable to the traversed second authentication mode combination, the traversed second authentication mode combination is determined as the first authentication mode combination applicable to the user, and the traversal is stopped.

[0073] Illustratively, the risk level of the second authentication mode combination can be mapped to a numerical value in a preset value range, and the numerical value is added to the first score to obtain the second score of the second authentication mode combination. The preset value range is the same as the value range to which the first score belongs.

[0074] Suppose there are five second authentication mode combinations, i.e., authentication mode combination 1 to authentication mode combination 5, and the second scores of these second authentication modes are in descending order as follows: authentication mode combination 1 -> authentication mode combination 2 -> authentication mode combination 3 -> authentication mode combination 4 -> authentication mode combination 5. If the user information satisfies the user condition applicable to authentication mode 2 when authentication mode 2 is traversed, authentication mode 2 is determined as the first authentication mode combination applicable to the user.

[0075] Since the higher the second score of the second authentication mode combination, the greater the probability that the second authentication mode combination is applicable to the user, determining the first authentication mode combination by the above method not only ensures that the determined first authentication mode is applicable to the user, but also can avoid comparing the user information with the user conditions applicable to all second authentication mode combinations as much as possible, thereby reducing the amount of calculation, improving the determination efficiency of the first authentication mode combination, and reducing the consumption of computing resources.

[0076] Since one intent can involve multiple business scenarios, each business scenario has unique business characteristics, and thus the authentication mode applicable to each business scenario is different. In the above embodiment, the first business scenario matching the intent is determined first, and then the first authentication mode combination applicable to the user is selected based on the first business scenario, the first access platform, and the user information, which can ensure that the first authentication mode combination covers all related business scenarios, and is conducive to improving the accuracy of identity verification.

[0077] In another implementation, each authentication manner combination is configured with applicable intention, access platform and user condition. In this case, S204 includes the following steps: for each authentication manner combination, comparing the service scenario applicable to the authentication manner combination with the first service scenario, comparing the intention applicable to the authentication manner combination with the intention determined through S202, and comparing the user condition applicable to the authentication manner combination with the user information of the user, and if all the comparisons are successful, determining the authentication manner combination as the first authentication manner combination applicable to the user.

[0078] The embodiments of the present application show part of the implementation of S204. Of course, it should be understood that S204 can also be implemented in other manners, which are not limited in the embodiments of the present application.

[0079] S206, determining whether to perform identity verification on the user based on the first authentication manner combination and the first identity verification record.

[0080] As mentioned above, the first identity verification record describes whether the user has been subjected to identity verification before, the result of the identity verification and the authentication manner used, based on which and the first authentication manner combination, it can be determined whether the user is at risk and whether the authentication manners in the first authentication manner combination are effective, and further, it can be determined whether it is necessary to perform identity verification on the user this time. In this way, the integration and data interconnection and intercommunication among originally discrete authentication manners can be achieved, and the problems such as the decline of user experience and excessive resource consumption caused by unnecessary identity verification can be avoided, the resource utilization rate is improved, and it is helpful to respond to the access request of the user in time.

[0081] In an implementation, S206 includes the following steps:

[0082] S261, determining whether there is a second identity verification record in the first identity verification record.

[0083] In actual application, the number of the first identity verification record can be one or more. For each first identity verification record, if the first identity verification record indicates that the user has been subjected to identity verification before and the result of the identity verification is successful, the first identity verification record is determined as the second identity verification record.

[0084] S262, if there is a second identity verification record in the first identity verification record, querying whether there is a third authentication manner combination in the second identity verification record, and determining whether to perform identity verification on the user based on the query result and the first authentication manner combination.

[0085] The third verification mode combination is recommended to the user before the first verification mode combination is determined. For example, if the verification mode combination shown in Table 3 is recommended to the user, and at least one of the verification modes is used to authenticate the user, the verification mode combination is determined as the third verification mode combination. If the verification mode combination shown in Table 3 is recommended to the user, but the verification mode used to authenticate the user is the auxiliary question verification, it is determined that the third verification mode combination does not exist in the second identity authentication record.

[0086] If the third verification mode combination exists in the second identity authentication record, it indicates that the verification mode combination recommended to the user is used to authenticate the user and is successful, and then based on the risk level of the third verification mode combination and the risk level of the first verification mode combination, it is determined whether to authenticate the user.

[0087] For example, considering that the verification mode combination with a high risk level is more strict and has higher reliability than the verification mode combination with a low risk level, in the case that the verification mode combination with a high risk level has successfully authenticated the user, the verification mode combination with a low risk level is usually also successful in authenticating the user, and there is no need to authenticate the user again, thereby avoiding the problems of user experience degradation and excessive resource consumption caused by unnecessary identity authentication. Based on this, if the third verification mode combination exists in the second identity authentication record, and the risk level of the third verification mode combination is greater than or equal to the risk level of the first verification mode combination, it indicates that the user has been successfully authenticated by the verification mode with a high risk level, and in this case, it is unnecessary to authenticate the user by the first verification mode combination with a low risk level, and it is determined not to authenticate the user.

[0088] In addition, it is also considered that if the verification mode combination with a low risk level successfully authenticates the user, there can be two cases: the first case is that the verification mode combination is too loose, resulting in that the risk user is determined as a normal user; the second case is that the user is indeed a normal user. In this case, it is necessary to authenticate the user again by the verification mode combination with a high risk level to determine whether the user is a risk user. Based on this, if the third verification mode combination exists in the second identity authentication record, and the risk level of the third verification mode combination is less than the risk level of the first verification mode combination, it indicates that the user has only been successfully authenticated by the verification mode with a low risk, and it is not yet possible to accurately determine whether the user is a risk user, and it is determined to authenticate the user.

[0089] If the third authentication mode combination does not exist in the second authentication record, it indicates that the authentication mode combination once recommended for the user is not used for authenticating the user, but other authentication modes are used to authenticate the user and the authentication is successful, and then the first authentication mode used to authenticate the user is obtained from the second authentication record, and whether to authenticate the user is determined based on the first authentication mode and the first authentication mode combination.

[0090] Exemplarily, the first authentication mode includes a plurality of second authentication modes arranged in sequence. Considering that the second authentication mode in the first position is more strict and reliable than other second authentication modes, if the user is authenticated successfully by using the second authentication mode in the first position, it is not necessary to authenticate the user by using the second authentication mode again, and the result of authenticating the user by using other second authentication modes is usually successful, thereby avoiding problems such as degradation of user experience, excessive consumption of resources and the like caused by unnecessary authentication. Based on this, after obtaining the first authentication mode used to authenticate the user from the second authentication record, if the first authentication mode is the same as the second authentication mode in the first position in the first authentication mode combination, it is determined that the user is not authenticated.

[0091] In actual application, the number of the first authentication mode can be one or more, and therefore, the first authentication mode being the same as the second authentication mode in the first position includes the following cases: case 1, the first authentication mode is only the same as the second authentication mode in the first position; case 2, the first authentication mode includes the second authentication mode in the first position and at least one second authentication mode, for example, the first authentication mode includes a preferred second authentication mode and a second authentication mode, or the first authentication mode includes a preferred second authentication mode and a second authentication mode, and the like.

[0092] In addition, it is also considered that the authentication mode combination once not successfully recommended and the second authentication mode in the first position once not used to authenticate the user successfully, there can be two cases: the first case is that the first authentication mode once used is too loose to cause a risk user to be misjudged as a normal user; the second case is that the user is indeed a normal user. Therefore, in this case, it is necessary to authenticate the user again by means of the first authentication mode combination to determine whether the user is a normal user. Based on this, after obtaining the first authentication mode used to authenticate the user from the second authentication record, if the first authentication mode is different from the second authentication mode in the first position in the first authentication mode combination, it is determined to authenticate the user; or if the first authentication mode is different from each second authentication mode in the first authentication mode combination, it is determined to authenticate the user.

[0093] S263, if the second authentication record does not exist in the first authentication record, authenticating the user.

[0094] If the second authentication record does not exist in the first authentication record, there are two cases: the first case is that the user has never been authenticated; the second case is that the user has failed to be authenticated. In either case, the user needs to be authenticated this time to improve access security.

[0095] It is worth noting that in actual applications, there can also be a case where the first authentication mode combination is not determined. In this case, it can be determined that the user is not authenticated.

[0096] The embodiments of the present application show part of the implementation of S206 described above. Of course, it should be understood that S206 described above can also be implemented by other ways, and the embodiments of the present application do not limit this. Illustratively, in some other implementation, as long as the authentication mode combination used by the user is different from the first authentication mode combination, the user is determined to be authenticated, regardless of whether there is a second authentication record of authentication success in the first authentication record.

[0097] S208, if it is determined to authenticate the user, authenticating the user based on the authentication mode in the first authentication mode combination.

[0098] In an embodiment, the user can be authenticated by the authentication modes in the first authentication mode combination in turn. If the authentication result of more than half of the authentication modes is authentication success, the final authentication result is determined to be authentication failure; otherwise, the final authentication result is determined to be authentication success.

[0099] In another embodiment, the second authentication modes in the first authentication mode combination are traversed according to the order of the second authentication modes in the first authentication mode combination; the user is authenticated by the traversed second authentication mode. If the authentication result is authentication success, the traversal is stopped; if the authentication result is authentication failure, the next second authentication mode is continued to be traversed. If the authentication result of the last second authentication mode is authentication failure, the final authentication result is determined to be authentication failure.

[0100] In yet another embodiment, the first authentication mode combination is recommended to the customer service; from the multiple second authentication modes included in the first authentication mode combination, a third authentication mode selected by the customer service is determined; the link of the third authentication mode is displayed to the user through the first access platform; in response to the triggering operation on the link, the user is authenticated based on the third authentication mode.

[0101] Exemplarily, the user accesses the business system through the online customer service system. After the business system determines the first identity verification manner combination and determines to perform identity verification on the user through S202-S206, the first verification manner combination is displayed to the work platform of the customer service for selection by the customer service. After selection by the customer service, a corresponding link is generated based on the third verification manner selected by the user and is displayed to the online customer service system. In response to triggering operation of the user on the link, identity verification is performed on the user using the third verification manner. If the verification succeeds, the user is allowed to access the business system; if the verification fails, the access request of the user is rejected.

[0102] Through the above implementation manner, the self-determination of identity verification and the collaboration between the first access platform, the business system and the work platform of the customer service are improved, which is beneficial to improving the efficiency of the entire business process and the fluency and convenience of the user experience.

[0103] The identity verification method provided by one or more embodiments of the present application can better adapt to the risk existing in the access request because different users have different risks in the process of accessing the business system without intention and different access platforms have unique business characteristics, and the first verification manner combination determined based on the first access platform, the user information and the intention contains at least two verification manners, which can fully play the role of different verification manners compared with selecting a single verification manner in isolation, is helpful to more accurately perform identity verification on the user, improves the verification accuracy, and thus improves the access security. Secondly, the first identity verification record describes the situation of performing identity verification on the user before this time, such as whether the user has been subjected to identity verification, whether the identity verification is successful and the verification manner used to perform identity verification on the user, etc. Based on the first identity verification record and the first verification manner combination, it can be determined whether the user has risks and whether the verification manners in the first verification manner combination are effective, and then it can be determined whether it is necessary to perform identity verification on the user. In the case of determining to perform identity verification on the user, identity verification is performed on the user based on the first verification manner combination. In this way, the integration and data interconnection between originally discrete verification manners can be realized, the problems of decline of user experience and excessive consumption of resources caused by unnecessary identity verification can be avoided, the resource utilization rate is improved, and it is helpful to timely respond to the access request of the user.

[0104] In order to facilitate the understanding of the identity verification method provided by the embodiments of the present application, a specific application scenario is described below.

[0105] The user accesses a service system through an IMA system, the IMA system allocates a free customer service to the user, and a window session is established between the customer service and the user for the customer service to provide services for the user, at this time the customer service will ask the user about the intention. After the user expresses the intention, the IMA system determines a first service scene matched with the intention, and pushes the first service scene to the work platform of the customer service, and the customer service confirms the first work scene and whether it is the user himself. After the customer service confirms, the IMA system determines a first verification mode combination suitable for the user from a plurality of verification mode combinations in combination with the characteristics of the IMA system, the intention of the user and the user information of the user, and determines whether to perform identity verification on the user based on the first verification mode combination and the first identity verification record; if it is determined to perform identity verification on the user, the first identity verification mode is pushed to the work platform of the customer service for the user to select. After the customer service selects, a corresponding link is generated according to the third verification mode selected by the customer service, and the link is displayed in the session window with the user. In response to a triggering operation on the link, the IMA system performs identity verification on the user using the third verification mode, and displays the identity verification result.

[0106] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different than the order in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain implementations, multitasking and parallel processing can be utilized or can be advantageous.

[0107] Based on the same inventive concept, the embodiments of the present application also provide an identity verification device. Please refer to Figure 4 , which is a structural schematic diagram of an identity verification device provided by an embodiment of the present application. As shown in Figure 4 , in a software implementation, the identity verification device 400 includes a determination module 410, a decision module 420 and a verification module 430.

[0108] The determination module 410 is configured to determine the intention of the user, the user information and the first identity verification record based on the access request submitted by the user through the first access platform.

[0109] The determination module 410 is further configured to determine a first verification mode combination suitable for the user from a plurality of verification mode combinations based on the first access platform, the user information and the intention.

[0110] The decision module 420 is configured to determine whether to perform identity verification on the user based on the first verification mode combination and the first identity verification record.

[0111] The verification module 430 is configured to, if it is determined to authenticate the user, authenticate the user based on the first authentication manner combination.

[0112] In another embodiment, the determination module is configured to:

[0113] determine, from a plurality of business scenarios, a first business scenario that matches the intent;

[0114] determine, from the plurality of authentication manner combinations, at least one second authentication manner combination that is applicable to the first business scenario and the first access platform based on a business scenario and an access platform to which each authentication manner combination is applicable;

[0115] determine, from the at least one second authentication manner combination, the first authentication manner combination that is applicable to the user based on the user information and a user condition to which each second authentication manner combination is applicable.

[0116] In another embodiment, when the determination module determines, from a plurality of business scenarios, a first business scenario that matches the intent, the determination module is configured to:

[0117] match, for each business scenario, text used to describe the business scenario with the intent to obtain a matching degree between the business scenario and the intent; determine, from the plurality of business scenarios, a third business scenario whose matching degree with the intent is greater than or equal to a first threshold value, and determine a fourth business scenario associated with the third business scenario;

[0118] determine the third business scenario and the fourth business scenario as the first business scenario that matches the intent.

[0119] In another embodiment, when the determination module determines, from the at least one second authentication manner combination, the first authentication manner combination that is applicable to the user based on the user information and a user condition to which each second authentication manner combination is applicable, the determination module is configured to:

[0120] determine, for each second authentication manner combination, a second score of the second authentication manner based on a risk level of the second authentication manner combination and a first score;

[0121] traverse the at least one second authentication manner combination in descending order of the second scores;

[0122] if the user information satisfies a user condition to which the traversed second authentication manner combination is applicable, determine the traversed second authentication manner combination as the first authentication manner combination that is applicable to the user, and stop the traversal.

[0123] In another embodiment, the decision module is configured to:

[0124] determining whether a second identity authentication record, which is verified successfully, exists in the first identity authentication record;

[0125] if the second identity authentication record exists in the first identity authentication record, querying whether a third verification mode combination exists in the second identity authentication record, and determining whether to perform identity authentication on the user based on a query result and the first verification mode combination, wherein the third verification mode combination is a verification mode combination recommended to be used on the user and used to perform identity authentication on the user before the first verification mode combination is determined;

[0126] if the second identity authentication record does not exist in the first identity authentication record, determining to perform identity authentication on the user.

[0127] In another embodiment, when the decision module determines whether to perform identity authentication on the user based on the query result and the first verification mode combination, the decision module performs the following steps:

[0128] if the third verification mode combination exists in the second identity authentication record and a risk level of the third verification mode combination is less than a risk level of the first verification mode combination, determining to perform identity authentication on the user.

[0129] In another embodiment, when the decision module determines whether to perform identity authentication on the user based on the query result and the first verification mode combination, the decision module performs the following steps:

[0130] if the third verification mode combination does not exist in the second identity authentication record, obtaining a first verification mode used to perform identity authentication on the user from the second identity authentication record;

[0131] if the first verification mode is different from a second verification mode located at a first position in the first verification mode combination, determining to perform identity authentication on the user, the first verification mode combination including a plurality of second verification modes arranged in sequence;

[0132] if the first verification mode is different from each second verification mode in the first verification mode combination, determining to perform identity authentication on the user.

[0133] In another embodiment, the verification module is configured to:

[0134] recommend the first verification mode combination to a customer service, the first verification mode combination including a plurality of second verification modes arranged in sequence;

[0135] From the plurality of second verification manners, a third verification manner selected by the customer service is determined;

[0136] A link of the third verification manner is displayed to the user through the first access platform;

[0137] In response to a triggering operation on the link, the user is authenticated based on the third verification manner.

[0138] Obviously, the tag processing apparatus provided by the embodiments of the present application can be used as Figure 2 the execution subject of the identity verification method shown in the figure, for example Figure 2 In the identity verification method shown in the figure, S202 and S204 can be executed by Figure 4 the determination module 410 in the identity verification apparatus 400, S206 can be executed by Figure 4 the decision module 420 in the identity verification apparatus 400, and S208 can be executed by Figure 4 the verification module 430 in the identity verification apparatus 400.

[0139] According to another embodiment of the present application, Figure 4 the modules in the identity verification apparatus can be combined into one or several other modules respectively or all, or some of the modules can be further split into a plurality of modules with smaller functions to constitute, which can realize the same operation without affecting the implementation of the technical effects of the embodiments of the present application. The above modules are divided based on logical functions, and in actual application, the functions of one module can also be realized by a plurality of modules, or the functions of a plurality of modules can be realized by one module. In the embodiments of the present application, the identity verification apparatus can also include other modules, which can also be realized by other modules in actual application, and can be realized by a plurality of modules in cooperation.

[0140] According to another embodiment of the present application, the module apparatus as shown in the figure can be constructed, and the module method of the embodiments of the present application can be implemented by running the computer program (including program code) capable of executing the steps involved in the corresponding method as shown in the figure on a general computing device such as a computer including processing elements and storage elements such as a central processing unit (CPU), a random access memory (RAM), and a read-only memory (ROM). Figure 2 Figure 4 The computer program can be recorded on a computer readable storage medium, for example, and transferred to an electronic device through the computer readable storage medium, and run therein.

[0141] ​Figure 5 is a structural schematic diagram of an electronic device according to an embodiment of the present application. Please refer to Figure 5 At the hardware level, the electronic device comprises a processor, and optionally further comprises an internal bus, a network interface, and a memory. The memory can include a memory, such as a high-speed random-access memory (RAM), and can further include a non-volatile memory, such as at least one disk memory. Of course, the electronic device can further include other hardware required by the business.

[0142] The processor, the network interface, and the memory can be connected to each other through the internal bus, which can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, and a control bus, etc. For ease of representation, Figure 5 only one bidirectional arrow is used in the figure, but it does not mean that there is only one bus or only one type of bus.

[0143] The memory is used to store a program. Specifically, the program can include program code, and the program code includes computer operation instructions. The memory can include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0144] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs, and forms an identity verification apparatus at the logical level. The processor executes the program stored in the memory, and is specifically used to perform the following operations:

[0145] Based on an access request submitted by a user through a first access platform, determine the intention of the user, user information, and a first identity verification record;

[0146] Based on the first access platform, the user information, and the intention, determine a first verification mode combination suitable for the user from a plurality of verification mode combinations;

[0147] Based on the first verification mode combination and the first identity verification record, determine whether to perform identity verification on the user;

[0148] If it is determined to perform identity verification on the user, perform identity verification on the user based on the first verification mode combination.

[0149] The method performed by the identity verification apparatus disclosed in the embodiments of the present application shown in Figure 2 The method performed by the identity verification apparatus disclosed in the embodiments of the present application shown in

[0150] The electronic device can further perform the method shown in Figure 2 and realize the functions of the identity verification apparatus in the embodiments shown in Figure 2 , Figure 3 , Figure 4 The embodiments of the present application will not be described here again.

[0151] Of course, in addition to the software implementation, the electronic device of the present application does not exclude other implementation manners, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or a logic device.

[0152] The embodiments of the present application further propose a computer readable storage medium, which stores one or more programs, the one or more programs including instructions capable of causing the portable electronic device including a plurality of application programs to perform the method shown in Figure 2 and specifically used to perform the following operations:

[0153] determine the intention of the user, the user information and the first identity authentication record based on the access request submitted by the user through the first access platform;

[0154] determine a first authentication mode combination suitable for the user from a plurality of authentication mode combinations based on the first access platform, the user information and the intention;

[0155] determine whether to authenticate the user based on the first authentication mode combination and the first identity authentication record;

[0156] if it is determined to authenticate the user, authenticate the user based on the first authentication mode combination.

[0157] The embodiments of the present application further provide a computer program product, which comprises a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a computer to perform part or all of the steps of the identity authentication method provided by the embodiments of the present application.

[0158] In summary, the above only describes the preferred embodiments of the present application and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0159] The system, device, module or unit illustrated in the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain function. A typical implementation device is a computer. Specifically, the computer may, for example, be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device or a combination of any of these devices.

[0160] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0161] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed, or inherent to such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.

[0162] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiments.

Claims

1. An authentication method, characterized in that, include: Based on the access request submitted by the user through the first access platform, the user's intent, user information, and first authentication record are determined; The first authentication record includes: whether the user was authenticated before submitting the access request, whether the authentication was successful, the recommended combination of authentication methods applicable to the user, and the authentication method used to authenticate the user; Based on the first access platform, the user information, and the intent, a first verification method combination suitable for the user is determined from multiple verification method combinations; Based on the first verification method combination and the first identity verification record, determine whether to authenticate the user; If it is determined that the user needs to be authenticated, then the user is authenticated based on the first authentication method combination.

2. The method according to claim 1, characterized in that, The step of determining a first verification method combination suitable for the user from multiple verification method combinations based on the first access platform, the user information, and the intent includes: Identify a first business scenario that matches the stated intent from multiple business scenarios; Based on the business scenario and access platform applicable to each combination of verification methods, at least one second combination of verification methods applicable to the first business scenario and the first access platform is determined from the multiple combinations of verification methods. Based on the user information and the user conditions applicable to each second verification method combination, a first verification method combination applicable to the user is determined from the at least one second verification method combination.

3. The method according to claim 2, characterized in that, The step of determining the first business scenario that matches the intent from multiple business scenarios includes: For each business scenario, the text used to describe the business scenario is matched with the intent to obtain the matching degree between the business scenario and the intent; From the plurality of business scenarios, a third business scenario with a matching degree greater than or equal to a first threshold is determined, and a fourth business scenario associated with the third business scenario is determined; The third and fourth business scenarios are identified as the first business scenario that matches the intent.

4. The method according to claim 2, characterized in that, The step of determining a first verification method combination applicable to the user from the at least one second verification method combination based on the user information and the user conditions applicable to each second verification method combination includes: For each combination of second verification methods, a second score for the second verification method is determined based on the risk level and the first score of the combination of second verification methods. The at least one combination of second verification methods is traversed in descending order of the second score; If the user information meets the user conditions applicable to the second verification method combination traversed, then the second verification method combination traversed is determined as the first verification method combination applicable to the user, and the traversal stops.

5. The method according to claim 1, characterized in that, The step of determining whether to authenticate the user based on the first authentication method combination and the first authentication record includes: Determine whether a successfully authenticated second authentication record exists in the first authentication record; If the second authentication record exists in the first authentication record, then query whether a third authentication method combination exists in the second authentication record, and determine whether to authenticate the user based on the query result and the first authentication method combination; wherein, the third authentication method combination is an authentication method combination recommended for the user and used to authenticate the user before determining the first authentication method combination; If the second authentication record is not present in the first authentication record, then it is determined that the user needs to be authenticated.

6. The method according to claim 5, characterized in that, The step of determining whether to authenticate the user based on the combination of the query result and the first verification method includes: If the third verification method combination exists in the second authentication record, and the risk level of the third verification method combination is lower than the risk level of the first verification method combination, then it is determined that the user will be authenticated.

7. The method according to claim 5, characterized in that, The step of determining whether to authenticate the user based on the combination of the query result and the first verification method includes: If the third verification method combination is not present in the second authentication record, then the first verification method used to authenticate the user is obtained from the second authentication record; if the first verification method is different from the second verification method that is first in the first verification method combination, then it is determined that the user is to be authenticated, wherein the first verification method combination includes multiple second verification methods arranged in order. If the first verification method is different from each of the second verification methods in the combination of the first verification methods, then it is determined that the user needs to be authenticated.

8. The method according to claim 1, characterized in that, The step of authenticating the user based on the verification method in the first verification method combination includes: Recommend the first verification method combination to customer service, wherein the first verification method combination includes multiple second verification methods arranged in sequence; From the plurality of second verification methods, determine the third verification method selected by the customer service representative; The link to the third verification method is displayed to the user through the first access platform; In response to the triggering operation of the link, the user is authenticated based on the third authentication method.

9. An identity verification device, characterized in that, include: The determination module is used to determine the user's intent, user information, and first authentication record based on the access request submitted by the user through the first access platform; The first authentication record includes: whether the user was authenticated before submitting the access request, whether the authentication was successful, the recommended combination of authentication methods applicable to the user, and the authentication method used to authenticate the user; The determining module is further configured to determine a first verification method combination applicable to the user from multiple verification method combinations based on the first access platform, the user information, and the intent; The decision module is used to determine whether to authenticate the user based on the first verification method combination and the first authentication record; The verification module is used to verify the user's identity based on the first verification method combination if it is determined that the user needs to be verified.

10. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the authentication method as described in any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the authentication method as described in any one of claims 1 to 8.

12. A computer program product, characterized in that, The computer program product includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps in the authentication method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Safety verification method and device, electronic equipment and storage medium

    CN112417429A

  • Identity verification method and device, computer equipment and computer readable storage medium

    CN115118501A