Identity verification method and device, storage medium and electronic device

By integrating terminal device information, biometric information, environmental information, and document information through multi-dimensional cross-verification, the problem of low accuracy caused by the single nature of traditional identity verification methods has been solved, resulting in a significant improvement in identity verification and enhanced security.

CN119848819BActive Publication Date: 2026-02-03JIANXIN CONSUMER FINANCE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411954726.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2026-02-03
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

Traditional user authentication methods are simplistic, resulting in low accuracy and susceptibility to sophisticated counterfeiting techniques, making it difficult to effectively distinguish between genuine users and imposters.

Method used

By comprehensively determining terminal device information, biometric information, environmental information, and document information, and employing a multi-dimensional cross-verification method, including biometric information detection, environmental information detection, and document information detection, a system response message is generated to determine whether access is permitted.

Benefits of technology

It improves the accuracy and security of identity verification, effectively resists malicious behavior, ensures efficient access to business systems, and prevents identity spoofing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119848819B_ABST
    Figure CN119848819B_ABST
Patent Text Reader

Abstract

The application discloses an identity verification method and device, a storage medium and an electronic device. The method comprises the following steps: determining terminal device information, biological information, environmental information and certificate information based on a service access request sent by a target object; determining whether the terminal device meets a device access condition based on the terminal device information; in the case where the terminal device meets the device access condition, sending a detection instruction to the target object to instruct the target object to be detected, and generating a system response message, wherein the system response message is used for indicating whether the target object is allowed to access, and the detection instruction comprises at least two of the following: detection based on the biological information, detection based on the environmental information and detection based on the certificate information. The application solves the technical problem that the accuracy is low due to the single user identity verification mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, and more specifically, to an authentication method and apparatus, a storage medium, and an electronic device. Background Technology

[0002] Traditional user authentication methods are often limited to a single dimension, such as relying solely on facial recognition or document scanning for identity verification. This significantly reduces their accuracy and security, making them vulnerable to impersonation using sophisticated techniques. In other words, the limitations of a single verification method prevent effective differentiation between genuine users and imposters. Therefore, related technologies suffer from the technical problem of low accuracy due to the reliance on a single user authentication method.

[0003] There is currently no effective solution to the above problems. Summary of the Invention

[0004] This application provides an authentication method and apparatus, storage medium and electronic device to at least solve the technical problem of low accuracy caused by the single user authentication method.

[0005] According to one aspect of the embodiments of this application, an authentication method is provided, comprising: determining terminal device information, biometric information, environmental information, and document information based on a service access request sent by a target object, wherein the terminal device information is used to indicate information corresponding to the terminal device used by the target object, the biometric information is used to indicate the object characteristics of the target object, the environmental information is used to indicate the collection environment of the biometric information, and the document information is used to indicate the identity characteristics of the target object; determining whether the terminal device meets the device access conditions based on the terminal device information; if the terminal device meets the device access conditions, sending a detection instruction to the target object to instruct the target object to perform detection, and generating a system response message, wherein the system response message is used to indicate whether the target object is allowed to access, and the detection instruction includes at least two of the following: detection based on the biometric information, detection based on the environmental information, and detection based on the document information.

[0006] According to another aspect of the embodiments of this application, an identity verification device is also provided, comprising: a determining module, configured to determine terminal device information, biometric information, environmental information, and document information based on a service access request sent by a target object, wherein the terminal device information is used to indicate information corresponding to the terminal device used by the target object, the biometric information is used to indicate the object characteristics of the target object, the environmental information is used to indicate the collection environment of the biometric information, and the document information is used to indicate the identity characteristics of the target object; and a generating module, configured to determine whether the terminal device meets the device access conditions based on the terminal device information, and if the terminal device meets the device access conditions, send a detection instruction to the target object to instruct the target object to perform detection, and generate a system response message, wherein the system response message is used to indicate whether the target object is allowed to access, and the detection instruction includes at least two of the following: detection based on the biometric information, detection based on the environmental information, and detection based on the document information.

[0007] Optionally, the device is configured to determine whether the terminal device meets the device access conditions based on the terminal device information in the following manner: if the terminal device meets the device access conditions, send a detection instruction to the target object to instruct the target object to be detected, and generate a system response message; if the terminal device meets the device access conditions, send a detection instruction to the target object to determine the type of the target object; if the object type of the target object is the target type, perform an image detection operation on the authentication image using a sample image library to determine the image detection result, wherein the authentication image is used to extract the biological information and the environmental information, and the image detection result includes the similarity between each sample image in the sample image library and the authentication image, and the visual label of the target object, wherein the visual label is used to indicate the object features of the target object in the authentication image; perform a document detection operation on the document information to obtain a document detection result, wherein the document detection result is used to indicate whether the document information corresponds to the target object; and generate a system response message based on the image detection result and the document detection result.

[0008] Optionally, the device is configured to generate a system response message based on the image detection result and the document detection result in the following manner: determining image detection feature values ​​according to the target business type corresponding to the business data and the image detection result, and determining document detection feature values ​​according to the target business type and the document detection result; querying the target image weight value and target document weight value corresponding to the target business type in the business weight mapping list; performing a weighted summation of the image detection feature value and the document detection feature value using the image weight value and the document weight value to obtain a target detection parameter; generating a first system response message when the value of the target detection parameter is greater than or equal to a preset scoring threshold, wherein the first system response message indicates that the target object is allowed to access, and the system response message includes the first system response message; generating a second system response message when the value of the target detection parameter is less than the scoring threshold, wherein the second system response message indicates that the target object is prohibited from access, and the system response message includes the second system response message.

[0009] Optionally, the apparatus is configured to determine an image detection result by performing an image detection operation on the authentication image using a sample image library when the object type of the target object is a target type, in the following manner: performing a similarity comparison operation on the authentication image using the sample image library to obtain a first detection result, wherein the first detection result is used to indicate the similarity between each sample image in the sample image library and the authentication image; when the first detection result indicates that the sample image library includes a target sample image whose similarity to the authentication image meets the image authentication conditions, determining the identity of the target object; and generating the image detection result based on the identity of the target object.

[0010] Optionally, the device is configured to perform an image detection operation on the authentication image using a sample image library to determine the image detection result when the object type of the target object is the target type: performing a source verification operation on the authentication image to determine the source of the authentication image; when the source of the authentication image indicates that the authentication image was acquired by an image acquisition component associated with the terminal device from the target object, performing a feature extraction operation on the authentication image to determine the biological information and the environmental information; determining the visual label based on the biological information and the environmental information; and generating the image detection result based on the visual label.

[0011] Optionally, the device is configured to determine the visual label based on the biological information and the environmental information in the following manner: querying a sample biological information database based on the biological information to determine whether target sample biological information corresponding to the biological information exists in the sample biological information database, and querying a sample environmental information database based on the environmental information to determine whether target sample environmental information corresponding to the environmental information exists in the sample environmental information database; if the target sample biological information and / or the target sample environmental information exists, generating a first visual label, wherein the first visual label indicates that the target object is prohibited from accessing, and the visual label includes the first visual label; if the target sample biological information and / or the target sample environmental information does not exist, generating a second visual label, wherein the second visual label indicates that the target object is allowed to access, and the visual label includes the second visual label.

[0012] Optionally, the device is configured to perform a document detection operation on the document information in the following manner to obtain a document detection result: querying a sample document library based on the image detection result to determine whether there is target sample document information in the sample document library corresponding to the identity of the target object; if the target sample document information exists and the document information meets a preset document status, generating a first document detection result, wherein the first document detection result indicates that the target object is allowed to access, and the document detection result includes the first document detection result; if the target sample document information does not exist and / or the document information does not meet the preset document status, generating a second document detection result, wherein the second document detection result indicates that the target object is prohibited from access, and the document detection result includes the second document detection result.

[0013] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer-readable storage medium, and the computer program is configured to execute the above-described authentication method at runtime.

[0014] According to another aspect of the embodiments of this application, a computer program product or computer program is provided, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the authentication method described above.

[0015] According to another aspect of the embodiments of this application, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to execute the above-described authentication method through the computer program.

[0016] In this embodiment, a method is adopted that comprehensively determines terminal device information, biometric information, environmental information, and document information based on the business access request sent by the target object. Through multi-dimensional cross-verification of information, the accuracy and security of identity verification are improved, and malicious behavior is effectively resisted. This achieves a significant improvement in identity verification technology, ensuring efficient access to the business system. By comprehensively considering the security status of the target object's device, the uniqueness of personal biometric characteristics, the actual conditions of the collection environment, and the legality of document information, the technical problems of low accuracy and susceptibility to impersonation in traditional single verification methods are effectively solved. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0018] Figure 1 This is a schematic diagram of an application environment for an optional authentication method according to an embodiment of this application;

[0019] Figure 2 This is a flowchart illustrating an optional authentication method according to an embodiment of this application;

[0020] Figure 3 This is a schematic diagram of an optional authentication method according to an embodiment of this application;

[0021] Figure 4 This is a schematic diagram of an optional authentication device according to an embodiment of this application;

[0022] Figure 5 This is a schematic diagram of the structure of an optional authentication product according to an embodiment of this application;

[0023] Figure 6 This is a schematic diagram of the structure of an optional electronic device according to an embodiment of this application. Detailed Implementation

[0024] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0025] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0026] The present application will be described below with reference to embodiments:

[0027] According to one aspect of the embodiments of this application, an authentication method is provided. Optionally, in this embodiment, the above-described authentication method can be applied to, for example... Figure 1 The hardware environment shown consists of server 101 and terminal device 103. For example... Figure 1As shown, server 101 is connected to terminal device 103 via a network and can be used to provide services to terminal device or applications installed on terminal device. Application 107 can be video application, instant messaging application, browser application, educational application, game application, etc. Database 105 can be set up on the server or independently of the server to provide data storage services for server 101, such as a game data storage server. The network mentioned above can include, but is not limited to, wired networks and wireless networks. The wired network includes local area networks, metropolitan area networks, and wide area networks. The wireless network includes Bluetooth, WIFI, and other networks that enable wireless communication. Terminal device 103 can be a terminal configured with an application, and can include, but is not limited to, at least one of the following: mobile phones (such as Android phones, iOS phones, etc.), laptops, tablets, handheld computers, MID (Mobile Internet Devices), PADs, desktop computers, smart TVs, smart voice interaction devices, smart home appliances, vehicle terminals, aircraft, virtual reality (VR) terminals, augmented reality (AR) terminals, mixed reality (MR) terminals, and other computer devices. The server mentioned above can be a single server, a server cluster composed of multiple servers, or a cloud server.

[0028] Combination Figure 1 As shown, the above authentication method can be executed by an electronic device, which can be a terminal device or a server. The above authentication method can be implemented by the terminal device or the server respectively, or by the terminal device and the server together.

[0029] The above is merely an example, and this embodiment does not impose any specific limitations.

[0030] Alternatively, as an alternative implementation method, such as Figure 2 As shown, the above authentication methods include:

[0031] S202, based on the service access request sent by the target object, determine the terminal device information, biometric information, environmental information and certificate information, wherein the terminal device information is used to indicate the information corresponding to the terminal device used by the target object, the biometric information is used to indicate the object characteristics of the target object, the environmental information is used to indicate the collection environment of the biometric information, and the certificate information is used to indicate the identity characteristics of the target object;

[0032] Optionally, in this embodiment, terminal device information refers to device-related data used by the target object when accessing services, including but not limited to device model, operating system version, IP address, MAC address, etc., used to assess the security and legality of the device; biometric information refers to the individual biometric data of the target object, including but not limited to facial images, iris scans, fingerprint templates, voiceprint features, etc.; environmental information refers to the surrounding environmental conditions when biometric information is collected, including but not limited to lighting conditions, noise levels, geographical location information, etc.; document information refers to the identity verification materials provided by the target object, including but not limited to images or data of ID cards, passports, driver's licenses, used to verify the legal identity information of the target object.

[0033] It should be noted that, in specific implementations, terminal device information can be acquired in various ways, such as automatic reporting via built-in detection software or extraction from device management services after authorization by the target object; biometric information collection may be achieved through a front-facing camera, microphone, or dedicated biometric hardware; environmental information collection can be performed through device sensors or third-party service interfaces; and verification of document information may involve data verification with third-party systems. This application does not limit these aspects, and all specific implementation methods are within the scope of protection of this invention.

[0034] For example, first, the system receives a business access request from the target object; then, automatically or with the cooperation of the target object, it collects and analyzes terminal device information, biometric information, environmental information, and document information respectively; then, based on the above multi-dimensional information, the system comprehensively judges the identity of the target object to ensure the security and compliance of business access.

[0035] S204, based on the terminal device information, determine whether the terminal device meets the device access conditions. If the terminal device meets the device access conditions, send a detection instruction to the target object to instruct the target object to be detected, and generate a system response message. The system response message is used to indicate whether the target object is allowed to access. The detection instruction includes at least two of the following: detection based on biometric information, detection based on environmental information, and detection based on document information.

[0036] Optionally, in this embodiment, the aforementioned device access conditions refer to the system's preset terminal device security standards, including but not limited to whether the device is infected by a virus, whether it is located in a high-incidence fraud area, whether the device hardware is normal, and whether it is connected to a trusted network; the aforementioned system response message refers to the decision notification generated by the system based on the terminal device information and subsequent detection results regarding whether to allow the target object to access the device, including but not limited to granting access rights, denying access rights, and requiring further manual review; the aforementioned detection instruction refers to the system's instruction to the target object to collect biometric information, environmental information, or document information, including but not limited to requiring facial recognition, collecting ambient sound, and uploading ID card photos.

[0037] It should be noted that, in practical implementation, the device access conditions can be flexibly adjusted to adapt to the security requirements of different business scenarios. For example, stricter security check standards may be set in high-risk businesses. At the same time, the form and content of system response messages should also be customized according to the actual application scenario to ensure the accuracy and timeliness of information transmission. This application does not impose any limitations on this.

[0038] For example, firstly, the system analyzes the terminal device information of the target object based on the received business access request to determine whether the device meets the preset access conditions; after confirming the device security, the system sends a detection instruction to the target object, requiring the provision of at least two types of information (such as biometric information and identification information); after the target object completes the provision of information according to the instruction, the system comprehensively analyzes all information, generates a system response message, and decides whether to allow access.

[0039] In an exemplary embodiment, taking a consumer finance loan application scenario as an example, when the system receives a user's loan application request, it first checks the terminal device information to confirm that the user's device has not enabled proxy services, has not been rooted, and is located in a secure network environment. After the device meets the access conditions, the system sends a detection instruction to the user, requiring the user to perform facial recognition and upload a photo of their ID card. The user performs facial capture in front of the camera and submits images of the front and back of their ID card. The system uses facial recognition based on biometric information and ID card verification based on document information, combined with a security assessment of environmental information, to comprehensively determine the user's identity. If all detection results show that the information is genuine and without abnormalities, the system generates a system response message allowing access, and the user can continue with the loan application operation. Conversely, if any abnormality is detected, the system generates an access denial response message, prompting the user to verify the accuracy of the device and information, or to initiate a manual review process to ensure the security and compliance of business operations.

[0040] In one exemplary embodiment, Figure 3This is a schematic diagram of an optional authentication method according to an embodiment of this application. The flowchart of the embodiment of this application can be illustrated as follows: Figure 3 As shown.

[0041] This application's embodiments employ a method that comprehensively determines terminal device information, biometric information, environmental information, and document information based on business access requests sent by the target object. Through multi-dimensional cross-verification of information, it achieves the goal of improving the accuracy and security of identity verification and effectively resisting malicious behavior. This results in a significant improvement in identity verification technology, ensuring efficient access to business systems. By comprehensively considering the security status of the target object's device, the uniqueness of personal biometric characteristics, the actual conditions of the collection environment, and the legality of document information, it effectively solves the technical problems of low accuracy and susceptibility to impersonation in traditional single verification methods.

[0042] As an optional solution, the above-mentioned method, based on the terminal device information, determines whether the terminal device meets the device access conditions. If the terminal device meets the device access conditions, a detection command is sent to the target object to instruct the target object to be detected, and a system response message is generated. This includes: if the terminal device meets the device access conditions, sending a detection command to the target object to determine the type of the target object; if the object type of the target object is the target type, performing an image detection operation on the authentication image using a sample image library to determine the image detection result, wherein the authentication image is used to extract the biological information and the environmental information, and the image detection result includes the similarity between each sample image in the sample image library and the authentication image, as well as the visual label of the target object, wherein the visual label is used to indicate the object features of the target object in the authentication image; performing a document detection operation on the document information to obtain a document detection result, wherein the document detection result is used to indicate whether the document information corresponds to the target object; and generating a system response message based on the image detection result and the document detection result.

[0043] Optionally, in the embodiments of this application, the above-mentioned target object type refers to the classification of the target object by the system after preliminary verification, including but not limited to new users, existing users, high-risk users, etc.; the above-mentioned sample image library refers to the image set that stores the biological information and environmental information of legitimate users, which is used to compare the authentication images provided by the target object, including but not limited to images of users who have successfully verified their identity in the past, environmental reference images issued by the official authorities, etc.

[0044] It should be noted that, in the specific implementation process, the determination of the target object type can be achieved through various methods such as device information, historical behavior data, or preset rules. The construction of the sample image library should include a wide range of representative image samples to cover biometric and environmental features in different scenarios. Document detection operations may involve multiple steps such as image clarity verification, document authenticity identification, and consistency comparison between information and the target object. This application does not impose any limitations on these steps.

[0045] In an exemplary embodiment, taking the online account opening application scenario as an example, when the system receives an account opening request sent by a new user via their mobile phone, it first confirms, based on the terminal device information, that the device is not rooted, not using a VPN, and that the network environment is secure. The system then sends a detection instruction to the new user, instructing them to take a face photo and upload a photo of their ID card. The new user completes face authentication in front of the camera and submits images of the front and back of their ID card. The system compares the images against a sample image library to determine the authenticity of the face and environmental information and generates an image detection result containing a similarity score and visual labels. Simultaneously, the system performs a document detection operation on the ID card photo to verify the accuracy and consistency of the information, obtaining a document detection result. Finally, the system comprehensively evaluates the image detection result and the document detection result and generates a system response message. If all detection results are confirmed to be correct, the system response message will instruct the new user to complete the online account opening process.

[0046] Through the embodiments of this application, a multi-dimensional cross-verification method is adopted to improve the accuracy and security of identity verification, thereby effectively preventing fraud by black and gray market organizations.

[0047] As an optional solution, the above-mentioned generation of system response messages based on the image detection results and the document detection results includes: determining image detection feature values ​​according to the target business type corresponding to the business data and the image detection results, and determining document detection feature values ​​according to the target business type and the document detection results; querying the target image weight value and target document weight value corresponding to the target business type in the business weight mapping list, and using the image weight value and document weight value to perform a weighted sum of the image detection feature values ​​and the document detection feature values ​​to obtain target detection parameters; generating a first system response message when the value of the target detection parameters is greater than or equal to a preset scoring threshold, wherein the first system response message indicates that the target object is allowed to access, and the system response message includes the first system response message; generating a second system response message when the value of the target detection parameters is less than the scoring threshold, wherein the second system response message indicates that the target object is prohibited from access, and the system response message includes the second system response message.

[0048] Optionally, in this embodiment, the target business type corresponding to the aforementioned business data refers to the business type identified by the system based on the user's request, including but not limited to loan applications, account registration, and high-risk transaction confirmation; the aforementioned image detection results and document detection results refer to the conclusions drawn by the system after analyzing the authentication images and document information uploaded by the target object, including but not limited to the similarity of biometric information comparison, the security assessment of environmental information, the verification results of document authenticity, and information consistency; the aforementioned business weight mapping list refers to the list of importance that the system sets for image detection and document detection results according to different business types, including but not limited to the setting of weighting coefficients for different business scenarios.

[0049] It should be noted that, in the specific implementation process, the determination of the target business type may be based on the metadata of business data, user behavior patterns, or preset business classification rules. The specific methods for obtaining image detection results and document detection results depend on the implementation of image processing and document recognition technologies, which may include methods such as deep learning, pattern recognition, or expert systems. The construction of the aforementioned business weight mapping list should take into account the business risk level and the possibility of fraud. For example, higher image and document weight values ​​may be assigned to high-risk businesses to strengthen the strictness of identity verification. This application does not impose any limitations on this.

[0050] In an exemplary embodiment, taking a loan application scenario as an example, after receiving a loan application initiated by a user, the system first analyzes the business data to determine that the target business type is loan approval. Subsequently, the system calculates image detection feature values ​​based on image detection results. These feature values ​​reflect the similarity between the user's face and stored samples, as well as the environmental security score. Simultaneously, the system calculates document detection feature values ​​based on document detection results. These feature values ​​are based on the authenticity of the ID card information and the consistency of the user's identity. The system finds the target image weight value and target document weight value corresponding to the loan approval business in the business weight mapping list, and performs a weighted summation of the image detection feature values ​​and document detection feature values ​​to obtain the target detection parameters in the loan application scenario. If the target detection parameters reach or exceed a preset scoring threshold, the system generates a first system response message, indicating that the user is allowed to proceed with the loan approval process. Conversely, if the target detection parameters do not reach the scoring threshold, the system generates a second system response message, indicating that the user's access is denied to prevent potential fraud risks.

[0051] Through the embodiments of this application, an identity verification strategy that is dynamically adjusted according to business type is adopted, which realizes refined management and risk control of user identity, and achieves the goal of flexibly adjusting verification standards according to different business scenarios and improving the accuracy of identity confirmation.

[0052] As an optional approach, when the object type of the target object is a target type, the above-mentioned method of performing image detection operation on the authentication image using a sample image library to determine the image detection result includes: performing a similarity comparison operation on the authentication image using the sample image library to obtain a first detection result, wherein the first detection result is used to indicate the similarity between each sample image in the sample image library and the authentication image; when the first detection result indicates that the sample image library includes a target sample image whose similarity to the authentication image meets the image authentication conditions, determining the identity of the target object; and generating the image detection result based on the identity of the target object.

[0053] Optionally, in the embodiments of this application, the above-mentioned image authentication conditions refer to the similarity threshold or scoring standard that is considered as valid identity authentication in the similarity comparison operation, including but not limited to reaching a certain percentage of similarity, comparison results that meet specific scoring rules, etc.; the above-mentioned target sample image refers to a sample image that meets the image authentication conditions with the similarity to the authentication image, which is used to further confirm the identity of the target object.

[0054] It should be noted that, in specific implementation, the determination of the above-mentioned target type can be based on the user's historical behavior, device information or system preset rules, and the setting of image authentication conditions can take into account the natural range of changes in biometrics, such as the influence of factors such as light, angle and expression on similarity scoring. This application does not limit this.

[0055] In an exemplary embodiment, taking a new user registration scenario as an example, after receiving a new user's registration request, the system determines that the user belongs to the target type based on the terminal device information, i.e., strict identity verification is required. The system retrieves historical user image data from the sample image library and compares it with the authentication image uploaded by the new user to obtain a first detection result. If there is a target sample image in the first detection result that meets the image authentication conditions with the similarity to the authentication image, the system will determine the identity of the new user and generate an image detection result based on this identity information. Otherwise, if the similarity comparison does not meet the preset image authentication conditions, the system will generate a further verification instruction, which may require the user to provide other forms of identity verification.

[0056] Through the embodiments of this application, a high-precision identification of the target object is achieved by using a comprehensive sample image library for similarity comparison and target type matching. This achieves the goal of effectively preventing identity fraud and improving business security while ensuring user experience.

[0057] As an optional approach, when the object type of the target object is the target type, the above-mentioned image detection operation on the authentication image using a sample image library to determine the image detection result includes: performing a source verification operation on the authentication image to determine the source of the authentication image; when the source of the authentication image indicates that the authentication image was acquired by an image acquisition component associated with the terminal device, performing a feature extraction operation on the authentication image to determine the biological information and the environmental information; determining the visual label based on the biological information and the environmental information; and generating the image detection result based on the visual label.

[0058] Optionally, in the embodiments of this application, the above-mentioned source verification operation refers to the verification of the authenticity and acquisition method of the certified image, including but not limited to checking image metadata, identifying whether the image has been edited or synthesized, and confirming whether the image was directly captured by the camera of the terminal device; the above-mentioned feature extraction operation refers to the process of extracting biological and environmental information from the certified image, including but not limited to facial feature point localization, iris texture analysis, background ambient light detection, and noise level assessment.

[0059] Optionally, in the embodiments of this application, the above-mentioned biological information refers to the biological characteristic data of the target object, the above-mentioned environmental information refers to the surrounding environmental conditions at the time of image acquisition, and the visual tag is a descriptive mark attached to the authentication image based on the comprehensive analysis of biological information and environmental information.

[0060] It should be noted that the above source verification operation can employ various technical means, such as image watermark recognition, metadata parsing, and image quality assessment, and this application does not limit these methods.

[0061] In an exemplary embodiment, taking the online banking account opening application scenario as an example, when the system identifies that the user belongs to the target type, that is, a new user attempting to open an account for the first time, the system first verifies the source of the selfie authentication image uploaded by the user, checking whether the image was directly taken by the user's device camera; if the authentication image passes the source verification, the system will perform feature extraction operations to extract facial features and environmental features from the image, such as lighting conditions, background noise, etc.; then, the system generates visual labels based on the extracted biometric and environmental information, such as "taken under natural light", "no traces of synthesis", "highly matched with the official face database", etc.; finally, the system generates image detection results based on these visual labels. If the results show that the image is real and the biometric and environmental features meet expectations, the user's authentication will be considered successful, and the system will generate a system response message allowing access.

[0062] Through the embodiments of this application, by verifying the source of the authenticated image and extracting biological environmental features to generate visual tags, a comprehensive assessment of the identity and environmental status of the target object is achieved. This achieves the technical effect of enhancing user experience while ensuring identity verification security and effectively preventing identity forgery attacks and environmental fraud.

[0063] It should also be noted that image source verification and feature extraction operations, as well as visual label generation, can be continuously optimized with advancements in image processing technology. For example, employing more advanced deep learning models can improve the accuracy of image feature extraction, further enhancing the reliability of identity verification. Simultaneously, the system should regularly update its sample image library to adapt to constantly changing environmental factors and technological challenges. This application does not impose any limitations on this.

[0064] As an optional approach, determining the visual label based on the aforementioned biological information and environmental information includes: querying a sample biological information database based on the aforementioned biological information to determine whether target sample biological information corresponding to the aforementioned biological information exists in the sample biological information database; and querying a sample environmental information database based on the aforementioned environmental information to determine whether target sample environmental information corresponding to the aforementioned environmental information exists in the sample environmental information database; if the target sample biological information and / or the target sample environmental information exists, generating a first visual label, wherein the first visual label indicates that access by the target object is prohibited, and the visual label includes the first visual label; if the target sample biological information and / or the target sample environmental information does not exist, generating a second visual label, wherein the second visual label indicates that access by the target object is permitted, and the visual label includes the second visual label.

[0065] Optionally, in the embodiments of this application, the aforementioned sample biometric database refers to a database that stores verified real user biometric data, including but not limited to face templates, iris images, fingerprint patterns, etc.

[0066] Optionally, in the embodiments of this application, the above-mentioned sample environment information database refers to a database containing typical background information of users in a safe environment, including but not limited to common network signal characteristics, ambient light patterns, voiceprint samples, etc.

[0067] Optionally, in the embodiments of this application, the first visual label and the second visual label refer to labels generated based on the comparison results of biological information and environmental information, which are used to indicate whether the target object is allowed to perform access operations.

[0068] In an exemplary embodiment, taking the identity verification scenario of online financial services as an example, the system first extracts biometric and environmental information from the authentication image of the target object. Then, the system queries the sample biometric and sample environmental information databases respectively to determine whether a matching target sample biometric and target sample environmental information corresponding to the extracted biometric and environmental information can be found. If a matching target sample biometric or target sample environmental information exists, it indicates that the target object may be involved in fraudulent activities or is in an insecure environment, and the system generates a first visual label to indicate that the target object is prohibited from accessing the database. Conversely, if the query results show that neither the target sample biometric nor the target sample environmental information exists, the system generates a second visual label to indicate that the target object's identity and environmental status are normal, allowing it to perform subsequent business operations.

[0069] Through the embodiments of this application, visual tags are generated by comparing biometric and environmental information with a sample library, thereby achieving dual verification of the target object's identity and environmental status. This achieves the technical effect of accurately identifying legitimate users and potential risky behaviors, enhancing the security and credibility of online financial services, and effectively preventing attacks and fraudulent activities by black market operators.

[0070] As an optional approach, the above-mentioned document detection operation on the document information to obtain document detection results includes: querying a sample document library based on the image detection results to determine whether there is target sample document information in the sample document library corresponding to the identity of the target object; if the target sample document information exists and the document information meets the preset document status, generating a first document detection result, wherein the first document detection result indicates that the target object is allowed to access, and the document detection result includes the first document detection result; if the target sample document information does not exist, and / or the document information does not meet the preset document status, generating a second document detection result, wherein the second document detection result indicates that the target object is prohibited from access, and the document detection result includes the second document detection result.

[0071] Optionally, in this embodiment of the application, the aforementioned sample document library refers to a set of verified document information maintained by the system, including but not limited to the front and back images of ID cards, passports, driver's licenses, etc., and their corresponding user identity information.

[0072] Optionally, in this embodiment of the application, the aforementioned preset document status refers to a series of inspection conditions set to ensure the validity of the document, including but not limited to the document validity period, document clarity, and consistency between document information and user data.

[0073] Optionally, in the embodiments of this application, the first document detection result and the second document detection result refer to the determination result generated by the system to allow or prohibit the target object from accessing the document based on the comparison of the document information with the sample document database and the satisfaction of the preset document status.

[0074] In an exemplary embodiment, taking the user authentication scenario of online financial services as an example, after receiving the identification information of the target object, the system first queries the sample identification document database based on the biometric and environmental information in the image detection results to confirm whether there is a record matching the target object's identity information. At the same time, the system checks whether the identification document information meets the preset identification document status, such as whether the document is valid, whether the image is clear, and whether the identification number, name, and other information are consistent with the user's registration information. If a matching record exists in the sample identification document database and the identification document information meets the preset identification document status, the system generates a first identification document detection result that allows access. Conversely, if no matching record is found in the sample identification document database, or the identification document information does not meet the preset identification document status, the system generates a second identification document detection result that prohibits access.

[0075] Through the embodiments of this application, a comprehensive verification of document information is achieved by using a combination of comprehensive document information comparison and preset document status checks, thereby effectively preventing document forgery and identity theft.

[0076] As an optional solution, when the terminal device meets the device access conditions, a detection instruction is sent to the target object to instruct the target object to perform an object detection operation and determine the object type of the target object. This includes: the detection instruction includes at least one of a head detection instruction, an eye detection instruction, a mouth detection instruction, and a face detection instruction; the object detection operation includes at least one of a head rotation operation, a blinking operation, a mouth opening operation, and a stationary operation, wherein the head detection instruction corresponds to the head rotation operation, the eye detection instruction corresponds to the blinking operation, the mouth detection instruction corresponds to the mouth opening operation, and the face detection instruction corresponds to the stationary operation.

[0077] In an exemplary embodiment, taking the scenario of opening an online bank account as an example, the system sends a detection command to the target object after initially determining that the terminal device meets the device access conditions, namely, the device is secure, has not been tampered with, and the network connection is normal.

[0078] Suppose the system needs to verify whether a target object is a living person. The detection instructions might include eye detection instructions, requiring the target object to blink. In this step, the system captures a real-time video stream or photo of the target object through a camera and observes whether it can blink according to the instructions, thereby determining whether the target object is a real human being and not a photo or video.

[0079] If the target object successfully passes this detection, the system will generate a corresponding object detection result, indicating that its object type is a live object; conversely, if the target object fails to blink or its actions are abnormal, the system will generate another type of object detection result, indicating that its object type may be a non-live object, thereby taking further verification measures or denying service.

[0080] Through the embodiments of this application, by sending specific detection instructions to the target object and requiring it to perform corresponding operations, dynamic detection of the target object's identity status is achieved. This achieves the technical effect of quickly confirming that the user is a living, real person with operational capabilities during user interaction, effectively improving the security of online services and user experience.

[0081] It should be noted that the above-mentioned detection instructions and detection operations of the target object can be diversified, such as combining head rotation, mouth opening action or continuous static observation, to enhance the accuracy of liveness detection and prevent fraud attempts. This application does not limit this.

[0082] As an optional approach, the method further includes: generating an access denial message when the object type of the target object is not the target type, wherein the access denial message indicates that the target object cannot operate the business data; and sending the access denial message to the target object.

[0083] In an exemplary embodiment, taking an online loan application scenario as an example, after the system performs a series of object detection operations on the target object, such as liveness detection, document information comparison, and environmental security assessment, if the system determines that the object type of the target object does not conform to the preset target type, that is, the system believes that the user may not be a legitimate applicant who needs to undergo high-security verification, or may have potential risky behavior, the system will generate an access denial message.

[0084] Furthermore, the access denial message details why the target object cannot operate on business data, such as a mismatch between the identification information and a record in the sample identification database, or environmental information indicating that the user may be in an insecure environment.

[0085] Next, the system can send an access denial message to the target through a secure communication channel, such as via email, SMS, or in-app message, to inform the user that their access request has been denied and to provide relevant appeal channels or guidance on how to resolve issues encountered during authentication.

[0086] Through the embodiments of this application, by generating and sending access denial messages, timely feedback and risk control are achieved when the target object's identity type does not match. This effectively prevents non-target type users from operating sensitive business data, protects system security and user privacy, and improves service transparency and user satisfaction.

[0087] In one exemplary embodiment, this application addresses the identity verification problem during customer authentication. By comprehensively considering factors such as client device security information, biometric information like facial features, identification document information, and surrounding environmental information, the customer's identity is identified, including but not limited to... Figure 3 As shown:

[0088] S1, channel side;

[0089] S2, Device Security: By detecting information about the devices used on the channel side, we determine whether there are any risks, such as whether a VPN is being used, whether root privileges are being used, whether frameworks are being enabled, and whether the MAC address is on a malicious list.

[0090] S3, Liveness Detection: Determines whether someone is a real person by requiring them to perform actions such as head turning, blinking, opening their mouth, or changing screen colors, without making any judgments about the person's identity.

[0091] S4, Face Recognition: Based on the face photo in the keyframe, compare it with the local photo library to score the similarity, or query a third-party system through relevant interfaces to determine the identity of the face.

[0092] S5, Face Photo Authentication: Determines whether a photo is photoshopped or forged.

[0093] S6, Visual Tag Judgment: The system analyzes background information in photos and a database of malicious faces to filter entries, and also labels entries based on the actual clothing and accessories worn by the person in the photo.

[0094] S7, ID card photo authentication: After completing facial recognition, ID card recognition is required to determine if there are any signs of Photoshop manipulation, and to compare it with the previous facial information and query relevant databases, etc.

[0095] The embodiments of this application employ a comprehensive approach that combines biometric information, document information, and environmental information to verify the authenticity of a customer's identity, thereby achieving a more accurate customer identity verification scheme and effectively identifying malicious forgery.

[0096] It is understood that in the specific embodiments of this application, data such as user information are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0097] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0098] According to another aspect of the embodiments of this application, an authentication apparatus for implementing the above-described authentication method is also provided. For example... Figure 4 As shown, the device includes:

[0099] The determination module 402 is used to determine terminal device information, biometric information, environmental information and certificate information based on the business access request sent by the target object. The terminal device information is used to indicate the information corresponding to the terminal device used by the target object, the biometric information is used to indicate the object characteristics of the target object, the environmental information is used to indicate the collection environment of the biometric information, and the certificate information is used to indicate the identity characteristics of the target object.

[0100] The generation module 404 is used to determine whether the terminal device meets the device access conditions based on the terminal device information. If the terminal device meets the device access conditions, it sends a detection instruction to the target object to instruct the target object to be detected and generates a system response message. The system response message is used to indicate whether the target object is allowed to access. The detection instruction includes at least two of the following: detection based on biometric information, detection based on environmental information, and detection based on document information.

[0101] As an optional solution, the above-mentioned device is used to determine whether the terminal device meets the device access conditions based on the terminal device information in the following manner: if the terminal device meets the device access conditions, a detection command is sent to the target object to instruct the target object to be detected, and a system response message is generated; if the terminal device meets the device access conditions, a detection command is sent to the target object to determine the type of the target object; if the object type of the target object is the target type, an image detection operation is performed on the authentication image using a sample image library to determine the image detection result, wherein the authentication image is used to extract biological and environmental information, and the image detection result includes the similarity between each sample image in the sample image library and the authentication image, as well as the visual label of the target object, wherein the visual label is used to indicate the object features of the target object in the authentication image; an ID card detection operation is performed on the ID card information to obtain the ID card detection result, wherein the ID card detection result is used to indicate whether the ID card information corresponds to the target object; and a system response message is generated based on the image detection result and the ID card detection result.

[0102] As an optional solution, the above-mentioned device is used to generate a system response message based on image detection results and document detection results in the following manner: determining image detection feature values ​​according to the target business type corresponding to the business data and the image detection results, and determining document detection feature values ​​according to the target business type and the document detection results; querying the target image weight value and target document weight value corresponding to the target business type in the business weight mapping list; using the image weight value and document weight value to perform a weighted summation of the image detection feature value and the document detection feature value to obtain the target detection parameter; generating a first system response message when the value of the target detection parameter is greater than or equal to a preset scoring threshold, wherein the first system response message indicates that the target object is allowed to access, and the system response message includes the first system response message; generating a second system response message when the value of the target detection parameter is less than the scoring threshold, wherein the second system response message indicates that the target object is prohibited from access, and the system response message includes the second system response message.

[0103] As an optional solution, the above-mentioned apparatus is used to determine the image detection result by performing an image detection operation on the authentication image using a sample image library when the object type of the target object is the target type: performing a similarity comparison operation on the authentication image using the sample image library to obtain a first detection result, wherein the first detection result is used to indicate the similarity between each sample image in the sample image library and the authentication image; when the first detection result indicates that the sample image library includes target sample images whose similarity to the authentication image meets the image authentication conditions, determining the identity of the target object; and generating an image detection result based on the identity of the target object.

[0104] As an optional solution, the above-mentioned device is used to perform image detection operations on the authentication image using a sample image library to determine the image detection result when the object type of the target object is the target type: performing a source verification operation on the authentication image to determine the source of the authentication image; when the source of the authentication image indicates that the authentication image was acquired by an image acquisition component associated with the terminal device from the target object, performing a feature extraction operation on the authentication image to determine biological information and environmental information; determining visual labels based on the biological information and environmental information; and generating image detection results based on the visual labels.

[0105] As an optional solution, the above-mentioned device is used to determine visual labels based on biological information and environmental information in the following manner: querying a sample biological information database based on the biological information to determine whether target sample biological information corresponding to the biological information exists in the sample biological information database, and querying a sample environmental information database based on the environmental information to determine whether target sample environmental information corresponding to the environmental information exists in the sample environmental information database; if target sample biological information and / or target sample environmental information exist, generating a first visual label, wherein the first visual label indicates that access by the target object is prohibited, and the visual label includes the first visual label; if target sample biological information and / or target sample environmental information do not exist, generating a second visual label, wherein the second visual label indicates that access by the target object is permitted, and the visual label includes the second visual label.

[0106] As an optional solution, the above-mentioned device is used to perform document detection operations on document information in the following manner to obtain document detection results: querying a sample document library based on the image detection results to determine whether there is target sample document information in the sample document library corresponding to the identity of the target object; if the target sample document information exists and the document information meets the preset document status, generating a first document detection result, wherein the first document detection result indicates that the target object is allowed to access, and the document detection result includes the first document detection result; if the target sample document information does not exist, and / or the document information does not meet the preset document status, generating a second document detection result, wherein the second document detection result indicates that the target object is prohibited from access, and the document detection result includes the second document detection result.

[0107] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0108] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0109] According to one aspect of this application, a computer program product is provided, the computer program product comprising a computer program.

[0110] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0111] Figure 5 A schematic block diagram of a computer system architecture for implementing an electronic device according to embodiments of the present application is shown.

[0112] It should be noted that, Figure 5 The computer system 500 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0113] like Figure 5 As shown, the computer system 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 502 or programs loaded from storage section 508 into random access memory (RAM). The RAM 503 also stores various programs and data required for system operation. The CPU 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output interface 505 (I / O interface) is also connected to the bus 504.

[0114] The following components are connected to the input / output interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a local area network card, modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the input / output interface 505 as needed. A removable medium 511, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 510 as needed so that computer programs read from it can be installed into the storage section 508 as needed.

[0115] Specifically, according to embodiments of this application, the processes described in the various method flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable medium 511. When the computer program is executed by central processing unit 501, it performs various functions defined in the system of this application.

[0116] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable media 511. When the computer program is executed by central processing unit 501, it performs various functions provided in the embodiments of this application.

[0117] According to another aspect of the embodiments of this application, an electronic device for implementing the above-described authentication method is also provided, the electronic device being... Figure 1 The terminal device or server shown. This embodiment uses this electronic device as an example for illustration. Figure 6 As shown, the electronic device includes a memory 602 and a processor 604. The memory 602 stores a computer program, and the processor 604 is configured to execute the steps in any of the above method embodiments via the computer program.

[0118] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.

[0119] Optionally, in this embodiment, the processor may be configured to execute the methods in the embodiments of this application via a computer program.

[0120] Alternatively, as those skilled in the art will understand, Figure 6 The structure shown is for illustrative purposes only. Figure 6 This does not limit the structure of the aforementioned electronic devices. For example, the electronic device may also include components that are more... Figure 6 The more or fewer components shown (such as network interfaces, etc.), or having the same Figure 6 The different configurations shown.

[0121] The memory 602 can be used to store software programs and modules, such as the program instructions / modules corresponding to the authentication method and device in this embodiment. The processor 604 executes various functional applications and data processing by running the software programs and modules stored in the memory 602, thereby implementing the aforementioned authentication method. The memory 602 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 602 may further include memory remotely located relative to the processor 604, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. Specifically, the memory 602 may be used, but is not limited to, to store terminal device information, biometric information, environmental information, and document information, etc. As an example, such as... Figure 6 As shown, the memory 602 may include, but is not limited to, the determining module 402 and the generating module 404 from the authentication device. Furthermore, it may include, but is not limited to, other module units from the authentication device, which will not be elaborated upon in this example.

[0122] Optionally, the transmission device 606 described above is used to receive or send data via a network. Specific examples of the network described above may include wired networks and wireless networks. In one example, the transmission device 606 includes a Network Interface Controller (NIC), which can be connected to other network devices and routers via a network cable to communicate with the Internet or a local area network. In another example, the transmission device 606 is a radio frequency (RF) module, used for wireless communication with the Internet.

[0123] In addition, the aforementioned electronic device also includes: a display 608 for displaying terminal device information, biometric information, environmental information and document information; and a connection bus 610 for connecting various module components in the aforementioned electronic device.

[0124] In other embodiments, the aforementioned terminal device or server can be a node in a distributed system, wherein the distributed system can be a blockchain system, which is a distributed system formed by connecting multiple nodes through network communication. The nodes can form a peer-to-peer network, and any form of computing device, such as a server, terminal, or other electronic device, can become a node in the blockchain system by joining this peer-to-peer network.

[0125] According to one aspect of this application, a computer-readable storage medium is provided, wherein a processor of an electronic device reads computer instructions from the computer-readable storage medium, and executes the computer instructions, causing the electronic device to perform the authentication methods provided in the various alternative implementations of the above-described authentication aspects.

[0126] Optionally, in this embodiment, the computer-readable storage medium described above may be configured to store methods for performing the embodiments of this application.

[0127] Optionally, in this embodiment, those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0128] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0129] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause one or more electronic devices to execute all or part of the steps of the methods described in the various embodiments of this application.

[0130] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0131] In the several embodiments provided in this application, it should be understood that the disclosed application can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0132] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0133] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0134] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. An authentication method, characterized in that, include: Based on the service access request sent by the target object, terminal device information, biometric information, environmental information, and identification information are determined. The terminal device information is used to indicate the information corresponding to the terminal device used by the target object, the biometric information is used to indicate the object characteristics of the target object, the environmental information is used to indicate the collection environment of the biometric information, and the identification information is used to indicate the identity characteristics of the target object. Based on the terminal device information, it is determined whether the terminal device meets the device access conditions. If the terminal device meets the device access conditions, a detection instruction is sent to the target object to instruct the target object to be detected, and a system response message is generated. The system response message is used to indicate whether the target object is allowed to access. The detection instruction includes at least two of the following: detection based on the biometric information, detection based on the environmental information, and detection based on the document information. The method further includes: when the terminal device meets the device access conditions, sending the detection instruction to the target object to determine the type of the target object; when the object type of the target object is the target type, performing an image detection operation on the authentication image using a sample image library to determine the image detection result, including: performing a source verification operation on the authentication image to determine the source of the authentication image; when the source of the authentication image indicates that the authentication image was acquired by an image acquisition component associated with the terminal device from the target object, performing a feature extraction operation on the authentication image to determine the biological information and the environmental information; according to the... The biological information and the environmental information determine visual labels; based on the visual labels, the image detection result is generated, wherein the authentication image is used to extract the biological information and the environmental information, and the image detection result includes the similarity between each sample image in the sample image library and the authentication image, as well as the visual label of the target object, the visual label being used to indicate the object features of the target object in the authentication image; an identification document detection operation is performed on the identification document information to obtain an identification document detection result, wherein the identification document detection result is used to indicate whether the identification document information corresponds to the target object; based on the image detection result and the identification document detection result, the system response message is generated.

2. The method according to claim 1, characterized in that, The generation of a system response message based on the image detection result and the document detection result includes: The image detection feature value is determined based on the target business type corresponding to the business data and the image detection result, and the document detection feature value is determined based on the target business type and the document detection result; In the business weight mapping list, query the target image weight value and target document weight value corresponding to the target business type, and use the image weight value and document weight value to perform a weighted sum of the image detection feature value and the document detection feature value to obtain the target detection parameters; When the value of the target detection parameter is greater than or equal to a preset scoring threshold, a first system response message is generated, wherein the first system response message indicates that the target object is allowed to access the system response message, and the system response message includes the first system response message. If the value of the target detection parameter is less than the scoring threshold, a second system response message is generated, wherein the second system response message indicates that the target object is prohibited from accessing the system response message, and the system response message includes the second system response message.

3. The method according to claim 1, characterized in that, When the object type of the target object is the target type, the step of performing image detection operation on the authentication image using a sample image library to determine the image detection result includes: A similarity comparison operation is performed on the authentication image using a sample image library to obtain a first detection result, wherein the first detection result is used to indicate the similarity between each sample image in the sample image library and the authentication image; If the first detection result indicates that the sample image library includes a target sample image whose similarity to the authenticated image meets the image authentication conditions, the identity of the target object is determined. The image detection result is generated based on the identity of the target object.

4. The method according to claim 1, characterized in that, The step of determining visual labels based on the biological information and the environmental information includes: Based on the biological information, query the sample biological information database to determine whether there is target sample biological information in the sample biological information database that corresponds to the biological information; and based on the environmental information, query the sample environmental information database to determine whether there is target sample environmental information in the sample environmental information database that corresponds to the environmental information. When the target sample biological information and / or the target sample environmental information exist, a first visual label is generated, wherein the first visual label indicates that the target object is prohibited from accessing the sample, and the visual label includes the first visual label. In the absence of the target sample biological information and / or the target sample environmental information, a second visual label is generated, wherein the second visual label indicates that the target object is allowed to access the sample, and the visual label includes the second visual label.

5. The method according to claim 1, characterized in that, The step of performing a document detection operation on the document information to obtain a document detection result includes: Based on the image detection results, query the sample document database to determine whether there is target sample document information in the sample document database that corresponds to the identity of the target object; If the target sample document information exists and the document information meets the preset document status, a first document detection result is generated, wherein the first document detection result indicates that the target object is allowed to access the document, and the document detection result includes the first document detection result. If the target sample document information does not exist, and / or the document information does not meet the preset document status, a second document detection result is generated, wherein the second document detection result indicates that the target object is prohibited from accessing the document, and the document detection result includes the second document detection result.

6. An identity verification device, characterized in that, include: The determination module is used to determine terminal device information, biometric information, environmental information, and identification information based on the business access request sent by the target object. The terminal device information is used to indicate the information corresponding to the terminal device used by the target object, the biometric information is used to indicate the object characteristics of the target object, the environmental information is used to indicate the collection environment of the biometric information, and the identification information is used to indicate the identity characteristics of the target object. A generation module is used to determine whether the terminal device meets the device access conditions based on the terminal device information. If the terminal device meets the device access conditions, a detection instruction is sent to the target object to instruct the target object to be detected, and a system response message is generated. The system response message is used to indicate whether the target object is allowed to access. The detection instruction includes at least two of the following: detection based on the biometric information, detection based on the environmental information, and detection based on the document information. The device is further configured to: when the terminal device meets the device access conditions, send the detection instruction to the target object to determine the type of the target object; when the object type of the target object is the target type, perform an image detection operation on the authentication image using a sample image library to determine the image detection result, including: performing a source verification operation on the authentication image to determine the source of the authentication image; when the source of the authentication image indicates that the authentication image was acquired by an image acquisition component associated with the terminal device from the target object, perform a feature extraction operation on the authentication image to determine the biological information and the environmental information; according to the... The biological information and the environmental information determine visual labels; based on the visual labels, the image detection result is generated, wherein the authentication image is used to extract the biological information and the environmental information, and the image detection result includes the similarity between each sample image in the sample image library and the authentication image, as well as the visual label of the target object, the visual label being used to indicate the object features of the target object in the authentication image; an identification document detection operation is performed on the identification document information to obtain an identification document detection result, wherein the identification document detection result is used to indicate whether the identification document information corresponds to the target object; based on the image detection result and the identification document detection result, the system response message is generated.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein the computer program can be executed by an electronic device to perform the method described in any one of claims 1 to 5.

8. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 5.

9. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method described in any one of claims 1 to 5 through the computer program.

Citation Information

Patent Citations

  • Identity authentication method and device

    CN107872433A

  • A human-certificate integrated verification terminal, system and method based on multi-mode face recognition

    CN109902780A

  • Control method and device for access connection of power system and electronic equipment

    CN119046915A