An authentication system and method based on biometric recognition
By designing a biometric authentication system based on biometric recognition, combining face recognition and two-factor authentication technology, the security and stability of identity authentication in the existing technology are solved, the integration of identity authentication and business processes is achieved, and the security and efficiency of authentication are improved.
Patent Information
- Application Number
- CN202411111289.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-14
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2044-08-14
AI Technical Summary
The existing technology has problems such as password leakage and forgetting passwords in identity authentication, which are prone to hackers. At the same time, biometric identification technology faces data privacy and security issues, the difficulty of integration and complementarity of different technologies, and the identification stability issues under different environments and conditions.
An identity authentication system based on biometric identification has been designed, including the registration and registration authentication SDK function module, the backend management module, the interface service module, the registration and approval system transformation module, the real-name authentication information query module, the binding identity authentication information module, the generation of identity authentication result information module and the application case query transformation module. Through facial recognition, two-factor authentication and other technologies, the integration of identity authentication and business processes is achieved.
It has realized "one-one-one authentication for every matter", prevented identity impersonation and forged authentication data, opened up barriers to real-name authentication and business processing, reduced processing time, simplified material preparation, realized full-on online business processing, and reduced round-trip costs for applicants.
Smart Images

Figure CN119513845B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of biometric recognition and artificial intelligence, and particularly to an identity authentication system and method based on biometric recognition. Background Art
[0002] Biometric Recognition is a technology for confirming an individual's identity by detecting and analyzing their unique physiological or behavioral characteristics. This technology utilizes an individual's characteristics, such as fingerprints, faces, irises, voiceprints, etc., for identity authentication.
[0003] In today's digital age, with the popularization of the Internet and mobile devices, people increasingly rely on digital identities for various activities, such as online shopping, social media, e-banking, etc. However, the accompanying digital fraud and identity theft have also become a severe challenge. Therefore, the research and development of identity authentication technology have become even more important. Usernames and passwords are the most common identity authentication methods, and users need to enter their usernames and passwords to access their accounts. However, this method has problems such as password leakage and forgotten passwords, and is vulnerable to hacker attacks. In addition to usernames and passwords, two-factor authentication also requires users to provide a second form of identity verification. Biometric recognition technology also faces some challenges, such as data privacy and security issues, the integration and complementarity of different biometric recognition technologies, and the recognition stability under different environments and conditions. Biometric recognition results cannot be accurately bound to services, and there is a risk of being misused. Summary of the Invention
[0004] The purpose of the present invention is to provide an identity authentication system and method based on biometric recognition to solve the problems raised in the above background art.
[0005] To solve the above technical problems, the present invention provides the following technical solution: An identity authentication system based on biometric recognition, the system includes a registration and identity authentication SDK function module, a registration and identity authentication background management module, a registration and identity authentication interface service module, a registration and approval system transformation module, a real-name authentication information query module, a bound identity authentication information module, a generated identity authentication result information module, and an application case query transformation module;
[0006] The registration and authentication SDK function module is used for the registration of new users and the login of registered users; the registration and authentication background management module is used to manage user registration information and registration records; the registration and authentication interface service module is used to provide an interface with an external system for user authentication; the registration and approval system transformation module includes domestic capital registration, foreign capital registration, agricultural professional registration, and individual registration; the real-name authentication information query module is used to query the real-name authentication information of users; the bound identity authentication information module is used to bind the identity authentication information of users to the accounts in the system; the generated identity authentication result information module is used to generate an authentication result based on the identity information provided by the user; the application case query transformation module is used to transform the query of application cases for domestic capital registration, foreign capital registration, agricultural professional registration, and individual registration, and add a function to view the identity authentication result information in the application case details information to view the identity authentication result information bound to the application case.
[0007] The output end of the registration and authentication SDK function module is connected to the input end of the registration and authentication background management module; the output end of the registration and authentication background management module is connected to the input end of the registration and authentication interface service module; the output end of the registration and authentication interface service module is connected to the input end of the registration and approval system transformation module; the output end of the registration and approval system transformation module is connected to the input end of the real-name authentication information query module; the output end of the real-name authentication information query module is connected to the input end of the bound identity authentication information module; the output end of the bound identity authentication information module is connected to the input end of the generated identity authentication result information module; the output end of the generated identity authentication result information module is connected to the input end of the application case query transformation module.
[0008] The registration and authentication SDK function module includes an in-APP authentication mechanism, a registration and authentication SDK structure, and a unified identity authentication service platform.
[0009] The in-APP authentication mechanism includes an APP registration unit, a two-factor face recognition authentication unit, and an APP login unit.
[0010] The specific steps of the registration and authentication SDK structure are as follows:
[0011] S2-1. After completing the registration authentication through the APP registration unit, search for registration and authentication in the APP for the first identity authentication.
[0012] S2-2. Click on the registration and authentication service to enter face recognition.
[0013] S2-3. If the verification is successful, enter the task creation page, and fill in the enterprise name, unified social credit code number, business type, and role on the task creation page;
[0014] S2-4. After filling is completed, conduct identity authentication. If the enterprise information is filled in incorrectly, return to fill it in again;
[0015] S2-5. For ID card users, enter two-factor authentication, that is, choose one of mobile phone number authentication and bank card authentication plus face recognition authentication; for non-ID card users, only conduct face recognition authentication;
[0016] S2-6. If the verification is successful, complete the identity verification service;
[0017] The unified identity authentication service platform is used to provide services for S2-2 and S2-5. When entering face recognition, it compares and identifies the collected face features with the ID card. In addition, it also includes the verification of exit and entry documents and real persons;
[0018] The registration identity verification SDK is integrated with the APP to provide a secure, reliable, standard and normative identity verification service through the APP, supporting the real-name authentication requirements in registration and filing business scenarios such as enterprise establishment registration, change registration, cancellation registration, etc. that involve new changes in personnel information. When a natural person uses the APP for the first time, an account registration is required. The registration requires two-factor real-name identity authentication. After passing the authentication, log in to the APP and search for and use the "registration identity verification" service. When using the "registration identity verification" service, two identity authentications are required. The first identity authentication can combine the real-name registration account of the APP + face recognition to form two-factor authentication; after the business is created, when the business is confirmed to respond to the requirement of "one person, one authentication for one matter", a second identity authentication is required. For this authentication: for ID card users, use two-factor authentication, that is, real-name mobile phone number authentication / bank card authentication + face recognition to improve the authentication security and avoid the risk of prosthesis attacks; for non-ID card users, call face recognition for authentication. After the authentication is successful, complete an authentication record and file it for convenient call by the registration and approval system.
[0019] The registration identity verification background management module is used for user management, authentication record management, and log management;
[0020] The user management is used to access the user system of the registration business system and realize the management functions of user accounts, including adding users, modifying users, deleting users, querying users, and setting permissions;
[0021] The authentication record management is used to provide the management functions of user authentication records, including adding records, modifying record tags, and querying records;
[0022] The log management is used to provide log management functions for background services, including recording all actions of administrators and operators; recording internal operating errors and anomalies of the entire system; making real-time statistics and analysis of authentication records; and providing query, analysis and backup.
[0023] The module for generating identity authentication result information is used to generate an identity authentication result information document according to the identity authentication result bound to the case; including online and offline cases; for offline cases, the documents can be viewed and printed in the receipt, material creation and decision stages; for online cases, the documents are generated in the electronic file of the review form;
[0024] The specific electronic signature of a natural person on the PC in the online registration identity verification scheme is:
[0025] After a natural person has checked the files to be signed and clicked on batch signature, a face recognition service is added for identity authentication. The QR code on the page is scanned by a mobile phone, and face recognition is completed on the mobile phone. After the authentication is passed, an event certificate is issued for electronic signature and the authentication result information of this identity authentication is recorded.
[0026] After setting up the electronic signature after the intention authentication on the PC side, the user needs to complete a face recognition authentication in combination with the user information of the login authentication after initiating the signature to prevent the situation where the signature is not made by the user himself, and provide an effective basis for the subsequent electronic signature accountability. The specific steps are as follows:
[0027] S6-1. Initiate batch signing interface transformation, return success / failure information, and update to return authentication QR code page;
[0028] S6-2: During the QR code scanning authentication process, if the page is closed due to improper operation, and the signature system does not receive the authentication result within three minutes, it is considered that the authentication has failed, the process ends, and the failure result is called back;
[0029] S6-3, user authentication fails, the signing process ends, and the failure result is called back;
[0030] S6-4: If the user receives a QR code on the PC but does not scan it for authentication, the authentication will be deemed to have failed after three minutes, the process ends, and the failure result will be called back;
[0031] S6-5. After the signing is successful, the information is uploaded through the callback interface, and the authentication serial number and signing serial number are added. The business system binds them, and the signing system is synchronously stored in the database;
[0032] S6-6, Add new scope of willingness authentication: Determine whether the user needs to add face recognition willingness authentication based on the type of certificate;
[0033] If the document type is ID card, Mainland Travel Permit for Hong Kong and Macao Residents (Home Return Permit), or passport, face recognition for willingness authentication can be performed. For other document types, the previous process shall be followed.
[0034] In the online registration identity verification solution, the specific mobile natural person electronic signature is as follows:
[0035] S7-1. The first stage is the natural person user login authentication stage. When the user logs in to the system for identity authentication, after completing the real-name authentication of the mobile phone number (name, ID number, mobile phone number) / bank card real-name authentication (name, ID number, bank reserved mobile phone number, bank card number), face recognition authentication is performed.
[0036] S7-2. After the natural person user selects the document to be signed and clicks the sign button, the business system initiates a batch signing service.
[0037] S7-3. The signature system calls the enterprise cloud identity authentication platform to obtain the face recognition authentication service page and returns it to the business system.
[0038] S7-4. The business system displays the face recognition authentication page, and the natural person conducts face verification.
[0039] S7-5. After the verification is passed, the signature system performs the natural person electronic signature in the background. After the signing is completed, the signature result is notified to the business system, and then the business system notifies the user.
[0040] In step S7-2, the specific steps for selecting the batch signing business are as follows:
[0041] S8-1. Before batch selection, face recognition is performed. If the verification is passed, a new page shows the name and account number for the user to confirm; after the user identity is confirmed correctly, the batch signing business is selected.
[0042] S8-2. Obtain the user's processed business and processing time through the user's historical processing records to generate a user business data matrix.
[0043] S8-3. Real-time obtain the browsing business frequency of the user within one month before handling the business, collect the real-time user feedback on handling the same business, and generate a user business handling information list through the data of the ratio of other users handling the business within one month when the user handles the business.
[0044] S8-4. Using the user business data matrix as the base data, perform business handling curve fitting through the curve fitting model combined with the user business handling information list; analyze the user's business handling and the user's browsing business frequency in the same period in previous years, and perform prediction sorting for the user's business handling.
[0045] S8-5. The user sorts according to the business handling, previews the business content and the evaluation feedback of the user for handling this business, and selects to batch-sign the business;
[0046] S8-6. Backup the real-time data analysis matrix of the user's business handling and the user's business handling information list, and input the data into the historical data analysis large model to make a reference adjustment to the historical handling records of the current user;
[0047] The user business data matrix is as follows:
[0048]
[0049] Among them, t is the full cycle of the user's business handling; α is the cycle label after dividing the full cycle of the user's business handling by year, α ≤ 12; β is the time point within each stage cycle, specifically a certain day of handling the business, β ≤ 31; is the time label at the β time point within the α cycle after slicing the full cycle of the user's business handling; is corresponding to the set of business handled corresponding to the time label;
[0050] The user business handling information list is as follows:
[0051]
[0052] Among them, j1, j2, and ji respectively represent the number of users handling historical business 1, business 2, and business i; T1, T2, and Ti respectively represent the number of users canceling business 1, business 2, and business i; RT1, RT2, and RTi respectively represent the feedback information of business 1, business 2, and business i.
[0053] In steps S8-3 and S8-4, the prediction and sorting of the user's business handling are specifically as follows:
[0054] Prediction formula:
[0055]
[0056] Among them, Q(i) represents the probability of the user handling business i; E(i) represents the ratio of users handling business i in the most recent month; δ i (tf-idf) represents the frequency of the user browsing business i in the most recent month; E t (i) represents the number of historical records of the user handling business i in month t of different years; represents the frequency of the user browsing business i when handling business i in month t of different years; E t′ (i) represents the number of historical records of the user handling business i in month t' of different years, where t' includes all months except month t; Indicates the frequency of the user viewing service i when handling service i in month t' of different years; α and β are the influence weights of month t and t' respectively;
[0057] The frequency of viewing service i is calculated as:
[0058] S1. Extract the keywords in service i;
[0059] S2. Calculate the frequency tf(i) of each keyword in service i in the user's historical browsing records;
[0060] tf(i) = q / d
[0061] where q is the number of times the keyword appears; d is the total number of words in the document
[0062] S3. Calculate the inverse document frequency idf(i) of each keyword in service i in the user's historical browsing records;
[0063] idf(i) = log[z / (p + 1)]
[0064] where z is the total number of documents; p is the number of documents containing the keyword;
[0065] S4. Calculate the keyword frequency of service i;
[0066] δ i (tf-idf) = tf(i) * idf(i) * 100%
[0067] where δ i (tf-idf) indicates the frequency of the user viewing service i in the most recent month.
[0068] An authentication method based on biometric recognition, the method comprising the following steps:
[0069] S1. Perform registration authentication, including creating authentication services, querying historical authentication, and authenticating record tags;
[0070] S2. Manage the background of registration authentication, including user management, authentication record management, and log management;
[0071] S3. Provide registration authentication interface services, including querying authentication records and writing back the usage status of authentication records;
[0072] S4. Transform the registration approval system, and the registration approval services involved in the offline process transformation include domestic-funded registration, foreign-funded registration, agricultural professional registration, and individual registration;
[0073] S5. At the receiving stage, provide an identity authentication information query function. Through the name and ID number, call the background service of the registration identity verification SDK to query the valid identity authentication records of the personnel who need identity authentication for this business, for the operator to view;
[0074] S6. Bind the identity authentication information;
[0075] S7. Generate an identity authentication result information document according to the identity authentication result bound for the case handling; including online case handling and offline case handling; for the offline case handling, it is viewed and printed at the receiving, creating materials, and decision-making stages; for the online case handling, the document is generated in the electronic file of the review form;
[0076] S8. Reform the query of application cases for domestic enterprise registration, foreign enterprise registration, agricultural professional cooperative registration, and individual registration. In the application case details information, add a function to view the identity authentication result information and view the identity authentication result information bound to this application case;
[0077] The binding result includes binding success and binding failure.
[0078] In step S6, the binding of the identity authentication information means that when the operator views the identity authentication records, for each person who needs identity authentication, check a piece of identity authentication record for business binding; the operator can adjust the business binding at any time during the receiving stage; when submitting the received documents, the system calls the background service of the registration identity verification SDK for formal business binding and informs the operator of the binding result; for those with successful binding, the authentication result information of the bound identity authentication also needs to be recorded.
[0079] This transformation includes the identity verification SDK (Android & iOS & HarmonyOS), electronic signature system, security authentication gateway, signature verification system, timestamp system, and trusted password service.
[0080] The identity verification SDK provides a secure, trustworthy, standard, and normative identity verification service externally.
[0081] The security authentication gateway is a security gateway product based on the national secret SSL protocol. Through the national secret SSL protocol and suites, it provides a secure encryption tunnel for users to ensure the integrity and confidentiality of data in the SSL link.
[0082] The signature verification system provides trusted digital signature (verification) and encryption / decryption services for various electronic data of users, ensuring the integrity, confidentiality, non-repudiation, and post-event traceability of users' key data.
[0083] The timestamp system issues authoritative electronic certificates to users to prove the integrity and non-repudiation of the electronic data file content since the trusted timestamp was applied. In this project, it is used in conjunction with the electronic signature system to provide time information stamping during the signing process, improve the credibility, transparency and traceability of the document, and facilitate business process management and problem troubleshooting.
[0084] Trusted cryptographic services provide key storage and management, support signature verification and timestamp to complete related signature and timestamp services.
[0085] Compared with the prior art, the beneficial effects achieved by the present invention are:
[0086] 1. The present invention establishes the whole process management of real-name authentication for business handling, realizes "one authentication for one person per matter", and prevents the impersonation of other people's information and the forgery of authentication data;
[0087] 2. The present invention breaks through the barriers between real-name identity authentication and business handling, quickly retrieves relevant evidence, and solves the problem of difficulty in investigation and evidence;
[0088] 3. The present invention integrates the real-name authentication technology into the business process, shortens the processing time, and simplifies the relevant materials;
[0089] 4. The present invention enables full online processing of business, reducing the applicant's round-trip costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.
[0091] In the attached picture:
[0092] Figure 1 This is an overall process architecture diagram of offline handling of an identity authentication system based on biometric recognition of the present invention;
[0093] Figure 2 This is a diagram of the registration and identity authentication SDK process architecture of an identity authentication system based on biometric recognition of the present invention;
[0094] Figure 3 This is a flowchart of the electronic signature after the new intention authentication on the PC side of the present invention;
[0095] Figure 4 This is a flowchart of the electronic signature of a natural person on a mobile terminal of the present invention;
[0096] Figure 5 It is the flow chart of the electronic signature of the legal person on the mobile terminal of the present invention. DETAILED DESCRIPTION
[0097] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0098] Please refer to Figures 1 - 5 , the present invention provides a technical solution: an identity authentication system based on biometric recognition, which includes a registration and authentication SDK function module, a registration and authentication background management module, a registration and authentication interface service module, a registration and approval system transformation module, a real-name authentication information query module, a bound identity authentication information module, a generated identity authentication result information module, and an application case query transformation module;
[0099] The registration and authentication SDK function module is used for the registration of new users and the login of registered users; the registration and authentication background management module is used for managing user registration information and registration records; the registration and authentication interface service module is used to provide an interface with an external system for user identity authentication; the registration and approval system transformation module includes domestic capital registration, foreign capital registration, agricultural professional registration, and individual registration; the real-name authentication information query module is used to query the real-name authentication information of users; the bound identity authentication information module is used to bind the identity authentication information of users to the accounts in the system; the generated identity authentication result information module is used to generate an authentication result based on the identity information provided by the user; the application case query transformation module is used to transform the query of application cases for domestic capital registration, foreign capital registration, agricultural professional registration, and individual registration, and add a function to view identity authentication result information in the application case details information to view the identity authentication result information bound to the application case.
[0100] In the embodiments of the present invention,
[0101] A natural person hopes to establish a company and needs to conduct a new authentication service:
[0102] Fill in the enterprise name: Fill in "ABC Technology Co., Ltd." (necessary);
[0103] Fill in the unified social credit code: xxxx567890ABCDE (not necessary);
[0104] Select the business type: Enterprise establishment;
[0105] Select the role type: Legal person;
[0106] A natural person queries his own past authentication records:
[0107] Query content: including information such as enterprise name, business type, role type, authentication result, etc.;
[0108] Enterprise name: ABC Technology Co., Ltd.;
[0109] Business type: enterprise establishment;
[0110] Role type: legal person;
[0111] Authentication result: successful;
[0112] The system performs label management on authentication records:
[0113] Authentication record:
[0114] Enterprise name: ABC Technology Co., Ltd.;
[0115] Business type: enterprise establishment;
[0116] Role type: legal person;
[0117] Authentication result: successful;
[0118] Label classification:
[0119] Authentication record is valid (business not processed);
[0120] Authentication record has been used (business has been processed);
[0121] Authentication record has expired (business not processed);
[0122] Validity period: The record will expire if not used after 3 natural days.
[0123] Adding a new user in the management background:
[0124] Adding a user:
[0125] User name: zhangmou;
[0126] Password: ********;
[0127] Permissions: administrator;
[0128] Modifying a user:
[0129] User name: zhangmou;
[0130] New password: ********;
[0131] Deleting a user: "User name: limou";
[0132] Query user: Find the user information of the user named "wangmou". Set permissions: Username: zhangmou, Permission: Super administrator. Add an authentication record in the management background:
[0133] Add record: ;
[0134] Enterprise name: XYZ Technology Co., Ltd.;
[0135] Business type: Enterprise change;
[0136] Role type: Shareholder;
[0137] Modify record label:
[0138] Modify label: Change from "Authentication record valid" to "Authentication record used"; Query record:
[0139] Query condition: All authentication records where the enterprise name contains "Technology".
[0140] Record the operation logs of the background administrator:
[0141] Record administrator operation:
[0142] Operator: admin;
[0143] Operation content: Add user zhangmou;
[0144] Record system error:
[0145] Error type: Database connection failed;
[0146] Time: 2024-08-01 10:00:00;
[0147] Statistical analysis:
[0148] Authentication record statistics: A total of 100 authentication records were added in July 2024.
[0149] Query, analyze and backup:
[0150] Query the operation logs for July.
[0151] Backup the system logs for the first half of 2024.
[0152] Call the authentication record query interface to obtain the authentication information of natural persons:
[0153] Query request:
[0154] Name of natural person: Zhang;
[0155] ID number: xxxx5678901234xxxx;
[0156] Return result:
[0157] Personnel information: Name: Zhang, ID number: xxxx5678901234xxxx; Authentication business serial number: 20240801001;
[0158] Authentication result: Success;
[0159] Authentication time: 2024-08-01 09:00:00;
[0160] Authentication record label: Authentication record is valid;
[0161] Portrait picture information of the authentication process: URL;
[0162] Use status of the authentication record written back by the called interface:
[0163] Usage record:
[0164] Business serial number: 20240801001;
[0165] Usage status: Used;
[0166] Write-back result:
[0167] Updated record label: Authentication record has been used;
[0168] The transformed system processes domestic investment registration business:
[0169] Transformation content:
[0170] Add the function of querying identity authentication information;
[0171] Add the function of binding and generating identity authentication result information;
[0172] Query identity authentication information in the receiving link:
[0173] Query request:
[0174] Name: Li;
[0175] ID number: xxxx5432109876xxxx;
[0176] Query result:
[0177] Valid identity authentication record: 20240801002;
[0178] Operator binds the identity authentication record:
[0179] Select binding:
[0180] Check the identity authentication record: 20240801002;
[0181] The selection steps for the batch signing business are as follows:
[0182] Before batch selection, face recognition is performed. After passing the verification, the new page shows the name and account number, and the user confirms them. After the user identity is confirmed correctly, the batch signing business is selected.
[0183] Obtain the user's handled business and handling time through the user's historical handling records, and generate a user business data matrix.
[0184] Obtain the real-time browsing business frequency of the user within one month before handling the business, collect the real-time user feedback on handling the same business, and generate a user business handling information list through the data of the handling ratio of other users within one month when the user handles the business.
[0185] Using the user business data matrix as the base data, perform business curve fitting through the curve fitting model combined with the user business handling information list; analyze the user's handled business and the user's browsing business frequency in the same period of previous years for the same user, and perform prediction sorting of the user's business handling.
[0186] The user previews the business content and the evaluation feedback of the user handling the business according to the business handling sorting, and selects the batch signing business.
[0187] Back up the real-time data analysis matrix of the user handling the business and the user business handling information list, and input the data into the historical data analysis large model to make a reference adjustment to the historical handling records of the current user.
[0188] The user business data matrix is:
[0189]
[0190] Among them, t is the full cycle of the user handling the business; α is the cycle label after dividing the full cycle of the user handling the business by year, α ≤ 12; β is the time point within each stage cycle, specifically a certain day of handling the business, β ≤ 31; is the time label at the β time point within the α cycle after slicing the full cycle of the user handling the business; is corresponding to the set of handled businesses of the time label;
[0191] The user business handling information list is:
[0192]
[0193] Among them, j1, j2, and ji respectively represent the number of users who have handled service 1, service 2, and service i in history; T1, T2, and Ti respectively represent the number of users who have cancelled service 1, service 2, and service i; RT1, RT2, and RTi respectively represent the feedback information of service 1, service 2, and service i.
[0194] User service handling prediction and sorting, specifically:
[0195] Prediction formula:
[0196]
[0197] Among them, Q(i) represents the probability that a user handles service i; E(i) represents the ratio of users who have handled service i in the most recent month; δ i (tf-idf) represents the frequency of a user browsing service i in the most recent month; E t (i) represents the number of historical records of a user handling service i in month t of different years; represents the frequency of a user browsing service i when handling service i in month t of different years; E t′ (i) represents the number of historical records of a user handling service i in month t' of different years, where t' includes all months except month t; represents the frequency of a user browsing service i when handling service i in month t' of different years; α and β are the influence weights of month t and month t' respectively;
[0198] The frequency of browsing service i is calculated as:
[0199] s1. Extract the keywords in service i;
[0200] s2. Calculate the frequency tf(i) of each keyword in service i in the user's historical browsing records;
[0201] tf(i) = q / d
[0202] Among them, q is the number of times the keyword appears; d is the total number of words in the document
[0203] s3. Calculate the inverse document frequency idf(i) of each keyword in service i in the user's historical browsing records;
[0204] idf(i) = log[z / (p + 1)]
[0205] Among them, z is the total number of documents; p is the number of documents containing the keyword;
[0206] s4. Calculate the keyword frequency of service i;
[0207] δ i δ(tf-idf) = tf(i) * idf(i) * 100%
[0208] wherein, δ i (tf-idf) represents the frequency of the user browsing service i in the most recent month.
[0209] Submission binding:
[0210] Formal binding: Binding is successful, record the result information.
[0211] Generate the document of the identity authentication result information:
[0212] Offline case handling:
[0213] View and print the document in the links of receiving, creating materials, making decisions, etc.
[0214] Online case handling:
[0215] Generate the document in the electronic file of the "Review Form".
[0216] Transform the query function of the application case:
[0217] Add function:
[0218] Add the function of "View Identity Authentication Result Information" in the detailed information of the application case.
[0219] View result:
[0220] View the identity authentication result information bound to the application case: The authentication result is successful.
[0221] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or also includes elements inherent to such process, method, article or device.
[0222] Finally, it should be noted that: The above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. An identity authentication system based on biometric recognition, characterized in that: The system includes a registration and identity authentication SDK function module, a registration and identity authentication background management module, a registration and identity authentication interface service module, a registration and approval system transformation module, a real-name authentication information query module, a binding identity authentication information module, an identity authentication result information generation module and an application case query transformation module; The registration and identity authentication SDK function module is used for the registration of new users and the login of registered users; the registration and identity authentication background management module is used to manage user registration information and registration records. Among them, the business system provides batch signing services, and the steps for selecting the business to be signed in batches are as follows: S8-1. Before batch selection, face recognition is performed. After verification, the user provides the name and account number on a new page for confirmation. After the user's identity is confirmed, the batch signing service is selected. S8-2. Obtain the user's business and processing time through the user's historical processing records, and generate a user business data matrix; S8-3, real-time acquisition of the browsing frequency of the user in the month before the user handles the service, collection of real-time user feedback on the same service, and generation of a user service handling information list based on the service handling ratio data of other users in the month when the user handles the service; S8-4, using the user business data matrix as the base data, and combining the user business handling information list with the curve fitting model to perform business handling curve fitting; analyzing the business handling of the same user in the same time period in previous years and the browsing business frequency of the user in the same time period, and performing user business handling prediction and ranking; S8-5. Users sort the services, preview the service content and the user's evaluation feedback on the services, and select to sign the services in batches; S8-6, back up the real-time data analysis matrix of the user's business handling and the user's business handling information list, and input the data into the historical data analysis model to make reference adjustments to the historical handling records of the current user; In steps S8-3 and S8-4, the user handles the predicted order of services, specifically: Prediction formula: ; Among them, Q(i) represents the probability of a user handling service i; E(i) represents the ratio of users who handled service i in the last month; Indicates the frequency of users browsing service i in the last month; E t (i) represents the number of historical records of the user handling business i in month t in different years; represents the frequency of users browsing service i when handling service i in month t of different years; Indicates the user's The number of historical records of business i handled in a month, Include all months except month t; Indicates that users in different years Frequency of browsing business i when handling business i in a month; and They are t month and Monthly impact weight; The frequency of browsing service i is calculated as: s1. Extract keywords from business i; s2. Calculate the frequency tf(i) of each keyword in business i in the user's historical browsing records; ; Among them, q is the number of times the keyword appears; d is the total number of words in the document; s3. Calculate the inverse document frequency idf(i) of each keyword in business i in the user's historical browsing records; ; Where z is the total number of documents; p is the number of documents containing the keyword; s4. Calculate the keyword frequency of business i; ; in, Indicates the frequency of users browsing service i in the last month; The registration and identity authentication interface service module is used to provide an interface with an external system to perform user identity authentication; the registration and approval system transformation module includes domestic capital registration, foreign capital registration, agricultural college registration and individual registration; the real-name authentication information query module is used to query the user's real-name authentication information; the binding identity authentication information module is used to bind the user's identity authentication information with an account in the system; the generating identity authentication result information module is used to generate an authentication result according to the identity information provided by the user; the application case query transformation module is used to transform the application case query of domestic capital registration, foreign capital registration, agricultural college registration and individual registration, and add a function of viewing the identity authentication result information in the application case details information to view the identity authentication result information bound to the application case; The output end of the registration and identity authentication SDK function module is connected to the input end of the registration and identity authentication background management module; the output end of the registration and identity authentication background management module is connected to the input end of the registration and identity authentication interface service module; the output end of the registration and identity authentication interface service module is connected to the input end of the registration and approval system transformation module; the output end of the registration and approval system transformation module is connected to the input end of the real-name authentication information query module; the output end of the real-name authentication information query module is connected to the input end of the binding identity authentication information module; the output end of the binding identity authentication information module is connected to the input end of the generation identity authentication result information module; the output end of the generation identity authentication result information module is connected to the input end of the application query transformation module.
2. The identity authentication system based on biometric recognition according to claim 1, characterized in that: The registration and identity authentication SDK functional module includes an in-APP authentication mechanism, a registration and identity authentication SDK structure and a unified identity authentication service platform; The in-APP authentication mechanism includes an APP registration unit, a two-factor face recognition authentication unit, and an APP login unit; The specific steps of registering the identity authentication SDK structure are: S2-1. After completing the registration authentication through the APP registration unit, search for registration authentication in the APP and perform the first authentication; S2-2. Click to register for identity verification service and enter face recognition; S2-3. If the verification is successful, enter the task creation page and fill in the company name, unified social credit code number, business type and role on the task creation page; S2-4. Once completed, identity authentication will be performed. If the company information is incorrect, the user will be asked to fill it in again. S2-5, ID card users, enter two-factor authentication, that is, mobile phone number authentication and bank card authentication plus face recognition authentication; non-ID card users, only face recognition authentication; S2-6. If the verification is successful, the identity verification service is completed; The unified identity authentication service platform is used to provide services for S2-2 and S2-5, and compares and identifies the collected facial features with the ID card when entering the face recognition.
3. The identity authentication system based on biometric recognition according to claim 1, characterized in that: The registration and identity authentication background management module is used for user management, authentication record management and log management; The user management is used to access the user system of the registration business system and implement the management functions of user accounts, including adding users, modifying users, deleting users, querying users and setting permissions; the authentication record management is used to provide the management functions of user authentication records, including adding records, modifying record tags and querying records; the log management is used to provide the log management function of the background service, including recording the operation steps of administrators and operators; Record internal operating errors and anomalies of the entire system; Make real-time statistics and analysis of certification records; provide query, analysis and backup.
4. The identity authentication system based on biometric recognition according to claim 1, characterized in that: The module for generating identity authentication result information is used to generate an identity authentication result information document according to the identity authentication result bound to the document; Including online and offline processing; For offline processing, documents can be viewed and printed during the receipt, material creation and decision stages; For online processing, the documents are generated in the electronic file of the review form.
5. The identity authentication system based on biometric recognition according to claim 4, characterized in that: The specific electronic signature of a natural person on the PC in the online registration identity verification scheme is: After a natural person has checked the files to be signed and clicked on batch signature, a face recognition service is added for identity authentication. The QR code on the page is scanned by a mobile phone, and face recognition is completed on the mobile phone. After the authentication is passed, an event certificate is issued for electronic signature and the authentication result information of this identity authentication is recorded.
6. The identity authentication system based on biometric recognition according to claim 4, characterized in that: The specific steps for setting up the electronic signature after the intention authentication on the PC are as follows: S6-1. Initiate batch signing interface transformation, return success / failure information, and update to return authentication QR code page; S6-2: During the QR code scanning authentication process, if the page is closed due to improper operation, and the signature system does not receive the authentication result within three minutes, it is considered that the authentication has failed, the process ends, and the failure result is called back; S6-3, user authentication fails, the signing process ends, and the failure result is called back; S6-4: If the user receives a QR code on the PC but does not scan it for authentication, the authentication will be deemed to have failed after three minutes, the process ends, and the failure result will be called back; S6-5. After the signing is successful, the information is uploaded through the callback interface, and the authentication serial number and signing serial number are added. The business system binds them, and the signing system is synchronously stored in the database; S6-6. Add a new scope of willingness authentication, and determine whether the user needs to add facial recognition willingness authentication based on the type of certificate.
7. The identity authentication system based on biometric recognition according to claim 4, characterized in that: The specific electronic signature of a natural person on the mobile terminal in the online registration identity verification scheme is: S7-1. The first stage is the natural person user login authentication stage. The user logs in to the system for identity authentication. After completing the mobile phone number real-name authentication / bank card real-name authentication, face recognition authentication is performed; S7-2. The natural person user selects the business to be signed in batches and clicks to sign. The business system initiates the batch signing service. S7-3, the signature system calls the enterprise cloud identity authentication platform, obtains the face recognition authentication service page, and returns it to the business system; S7-4. The business system displays the face recognition authentication page, and the natural person performs face verification; S7-5. After verification, the signature system background will conduct an electronic signature by a natural person. After the signature is completed, the signature result will be notified to the business system, and the business system will inform the user.
8. The identity authentication system based on biometric recognition according to claim 7, characterized in that: Specifically: The user service data matrix is: ; Among them, t is the entire cycle of the user's business handling; Provide cycle labels for users after dividing the entire business cycle by year. ; It is a time point in each phase cycle, specifically a day when the business is handled. ; After slicing the entire cycle of a user's business, the label is During the cycle A time stamp at the time point; For the corresponding A collection of business operations with time tags; The user service handling information list is: ; in, , and Respectively represent the number of users who have handled business 1, business 2, and business i in the past; , and Respectively represent the number of users who canceled service 1, service 2, and service i; , and Respectively represent the feedback information of business 1, business 2 and business i.
9. An identity authentication method based on biometric identification, applied to an identity authentication system based on biometric identification as claimed in any one of claims 1 to 8, characterized in that: The method comprises the following steps: S1. Perform registration and identity verification, including new authentication services, historical authentication queries, and authentication record tags; S2. Registration and identity authentication background management, including user management, authentication record management, and log management; S3. Provide registration and authentication interface services, including authentication record query and authentication record usage status writeback; S4. Registration and approval system transformation: the registration and approval businesses involved in the offline process transformation include domestic capital registration, foreign capital registration, agricultural special registration and individual registration; S5. In the receiving stage, provide identity authentication information query function, call the registration and identity authentication SDK background service through name and ID number to query the valid identity authentication record of the person who needs identity authentication for this business, so that the person in charge can view it; S6. When checking the identity authentication records, the handler shall select an identity authentication record for each person who needs identity authentication to perform business binding; the handler can adjust the business binding at any time during the receipt stage; when the receipt is submitted, the system calls the registration and identity authentication SDK background service to perform formal business binding and informs the handler of the binding result; S7. Generate an identity authentication result information document based on the identity authentication result bound to the application; including online application and offline application; the offline application is viewed and printed during the receipt, material creation and decision stages; the online application, the document is generated in the electronic file of the review form; S8. Improve the query of domestic capital registration, foreign capital registration, agricultural special registration and individual registration applications. Add the function of viewing identity authentication result information in the application details to view the identity authentication result information bound to the application. The binding result includes binding success and binding failure.
Citation Information
Patent Citations
Government affairs remote authentication system and method
CN108600154A
Intelligent news recommendation method and system based on explicit and implicit interest features
CN116340641A