A user identity authentication method and device, a storage medium and an electronic device

By guiding users to directly access a trusted student registration website and monitoring their actions, data is collected for identity authentication, solving the instability and high cost problems caused by interface dependencies in traditional methods, and realizing a flexible, secure and user-friendly student identity authentication process.

CN119903500BActive Publication Date: 2026-03-24ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, service providers rely on student status verification service interfaces when verifying student identities, which leads to an unstable and costly verification process and a poor user experience.

Method used

By guiding users to directly access a trusted student registration website, monitoring user operations and collecting access data, generating identity verification data for authentication, and bypassing interface dependencies, the system's flexibility and robustness are improved.

Benefits of technology

It reduces the operating costs of the certification process, improves the accuracy and security of certification, and provides clear operating instructions to ensure a smooth verification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119903500B_ABST
    Figure CN119903500B_ABST
Patent Text Reader

Abstract

The specification discloses a user identity authentication method and device, a storage medium and an electronic device, wherein the method comprises: a user terminal initiates a student identity authentication request for a target application, outputs a guided access operation instruction for a trusted student status website to the user terminal, monitors a guided access operation of the user terminal on the trusted student status website based on the guided access operation instruction, collects student status website access data of the user terminal, determines identity recognition verification data of the user terminal based on the student status website access data, performs student identity authentication on the user terminal based on the identity recognition verification data, and obtains a student identity authentication result of the user terminal.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present specification relates to the technical field of computer, and particularly relates to a user identity authentication method and device, a storage medium and an electronic equipment. BACKGROUND

[0002] With the popular application of computers and the Internet and the rapid development of communication technology, the society gradually enters the information age. At present, when a service provider provides services for users, it often needs to verify the specified type of identity of the user. For example, when the service provider needs to authenticate the student identity of the user, it often needs to obtain the student identity information of the user from the student verification service interface request provided by the trusted student agency (such as the China Academic Degrees & Certificates Verification Center) and the third-party data source, so as to realize the authentication of the student identity of the user based on the obtained student identity information of the user. SUMMARY

[0003] The present specification provides a user identity authentication method and device, a storage medium and an electronic equipment, and the technical solutions are as follows:

[0004] In a first aspect, the present specification provides a user identity authentication method, and the method comprises:

[0005] In response to a student identity authentication request of a user terminal for a target application, outputting a guided access operation instruction for a trusted student website to the user terminal;

[0006] Monitoring the guided access operation of the user terminal to the trusted student website based on the guided access operation instruction;

[0007] Collecting student website access data for the user terminal, determining identity recognition verification data for the user terminal based on the student website access data, and performing student identity authentication on the user terminal based on the identity recognition verification data to obtain a student identity authentication result for the user terminal.

[0008] In a second aspect, the present specification provides a user identity authentication device, and the device comprises:

[0009] A request authentication module configured to output a guided access operation instruction for a trusted student website to a user terminal in response to a student identity authentication request of the user terminal for a target application;

[0010] An operation monitoring module configured to monitor the guided access operation of the user terminal to the trusted student website based on the guided access operation instruction;

[0011] The student authentication module is configured to collect student website access data of the user terminal, determine identity verification data of the user terminal based on the student website access data, perform student identity authentication on the user terminal based on the identity verification data, and obtain a student identity authentication result of the user terminal.

[0012] In a third aspect, the present specification provides a computer storage medium storing at least one instruction adapted to be loaded by a processor and to execute the method steps of one or more embodiments of the present specification.

[0013] In a fourth aspect, the present specification provides a computer program product storing at least one instruction adapted to be loaded by a processor and to execute the method steps of one or more embodiments of the present specification.

[0014] In a fifth aspect, the present specification provides an electronic device, which can include a processor and a memory, wherein the memory stores a computer program adapted to be loaded by the processor and to execute the method steps of one or more embodiments of the present specification.

[0015] The technical solutions provided by some embodiments of the present specification have at least the following beneficial effects:

[0016] In one or more embodiments of the present specification, the user terminal initiates a student identity authentication request for a target application, and the electronic device outputs an indication of a guided access operation for a trusted student website to the user terminal. The user terminal is monitored to perform a guided access operation for accessing the trusted student website based on the indication of the guided access operation. Student website access data of the user terminal is collected to determine identity verification data of the user terminal. The student identity authentication of the user terminal is performed to obtain a student identity authentication result of the user terminal. By dividing the student identity authentication process into user guidance, operation monitoring, data collection and verification based on the user accessing the trusted student website, the high cost and instability of the traditional target application relying on the student verification service interface are solved. By guiding the user to access the trusted student website, the interface dependence is bypassed, and the flexibility and robustness of the system are effectively improved. In addition, by collecting the student website access data of the user accessing the student website and generating the identity verification data, the accuracy and security of the authentication are ensured. Furthermore, the scheme takes into account the user experience, provides clear operation guidance, ensures smooth verification process, reduces the operation cost of the authentication process, and is suitable for student identity authentication requirements in various scenarios. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the specification or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the specification, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0018] Figure 1 is a schematic diagram of a user identity authentication system provided by the specification;

[0019] Figure 2 is a schematic diagram of a user identity authentication method provided by the specification;

[0020] Figure 3 is a schematic diagram of a collection authorization security verification scene provided by the specification;

[0021] Figure 4 is a schematic diagram of a data collection process provided by the specification;

[0022] Figure 5 is a schematic diagram of a website video frame processing process provided by the specification;

[0023] Figure 6 is a schematic diagram of a video recording academic information collection scene provided by the specification;

[0024] Figure 7 is a schematic diagram of a student identity authentication process provided by the specification;

[0025] Figure 8 is a schematic diagram of an academic information verification scene provided by the specification;

[0026] Figure 9 is a schematic diagram of a user identity authentication device provided by the specification;

[0027] Figure 10 is a schematic diagram of an electronic device provided by the specification. DETAILED DESCRIPTION

[0028] The technical solutions in the specification will be described clearly and completely in the specification combined with the drawings in the specification. Obviously, the described embodiments are only some embodiments of the specification, not all embodiments. Based on the embodiments in the specification, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the specification.

[0029] In the description of the specification, it should be understood that the terms "first", "second" and the like are used only for descriptive purposes, and cannot be understood as indicating or implying relative importance. In the description of the specification, it should be noted that, unless otherwise explicitly specified and limited, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally also include steps or units not listed, or can optionally also include other steps or units inherent to these processes, methods, products or devices. The specific meaning of the above terms in the specification can be understood by the person skilled in the art on a case-by-case basis. In addition, in the description of the specification, "a plurality of" means two or more, unless otherwise specified. The association relationship of the associated objects is described, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after it.

[0030] In the related art, when a service provider provides a user with a convenient service under a student identity, the user's student identity usually needs to be verified. The student identity verification is very dependent on the student status verification service interface provided by a third-party data source such as the China Academic Degrees and Certification Network. For example, when the service provider needs to authenticate the user's student identity, the user's student identity information is usually requested from the official agency student status verification service interface, so as to rely on the obtained user's student identity information to authenticate the student identity of the user, in order to provide corresponding services for the user. Since this identity verification method is heavily dependent on the data services provided by the student status verification service interface of other agencies, but the student status verification service interface in many cases is unstable and the interface fee of the student status verification service interface is expensive, etc. Limitations lead to high cost of the entire verification process.

[0031] The specification will be described in detail below in conjunction with specific embodiments.

[0032] Please refer to Figure 1 , a scenario diagram of a user identity authentication system provided by the specification. As Figure 1 shown, the user identity authentication system can at least include a client cluster and a service platform 100.

[0033] The client cluster can include at least one client, such as Figure 1 shown, specifically including a client 1 corresponding to a user 1, a client 2 corresponding to a user 2,..., and a client n corresponding to a user n, n is an integer greater than 0.

[0034] The clients in the client cluster can be electronic devices with communication functions, including but not limited to wearable devices, handheld devices, personal computers, tablet computers, vehicle-mounted devices, smart phones, computing devices, or other processing devices connected to wireless modems, etc. Electronic devices can be called different names in different networks, such as user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, electronic device, wireless communication device, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), electronic device in 5G network or future evolution network, etc.

[0035] The service platform 100 can be a separate server device, such as a rack-mounted, blade, tower, or cabinet server device, or a hardware device with strong computing power such as a workstation, a mainframe computer, etc. It can also be a server cluster composed of multiple servers. Each server in the service cluster can be composed in a symmetrical manner, where each server is functionally and positionally equivalent in the transaction link, and each server can independently provide services externally. The independent service can be understood as not requiring the assistance of another server.

[0036] In one or more embodiments of the present specification, the service platform 100 can establish a communication connection with at least one client in the client cluster, and complete the interaction of data in the user identity authentication process based on the communication connection.

[0037] For example, a client can initiate a student identity authentication request for a target application to the service platform 100, and output a guided access operation instruction for a trusted student website to the user terminal.

[0038] The service platform 100 monitors the guided access operation of the user terminal to the trusted student website based on the guided access operation instruction, collects student website access data for the user terminal, determines identity verification data for the user terminal based on the student website access data, performs student identity authentication on the user terminal based on the identity verification data, and obtains a student identity authentication result for the user terminal.

[0039] It should be noted that the service platform 100 and at least one client in the client cluster establish a communication connection through a network for interactive communication, where the network can be a wireless network or a wired network. The wireless network includes but is not limited to a cellular network, a wireless local area network, an infrared network or a Bluetooth network. The wired network includes but is not limited to an Ethernet, a universal serial bus (USB) or a controller area network. In one or more embodiments of the specification, technologies and / or formats such as Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML) and the like are used to represent data (such as the target compressed package) exchanged through the network. In addition, all or some links can be encrypted using conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec) and the like. In other embodiments, custom and / or dedicated data communication technologies can be used instead of or in addition to the above data communication technologies.

[0040] The user identity authentication system embodiments provided by the specification belong to the same concept as the user identity authentication method in one or more embodiments. The execution subject corresponding to the user identity authentication method involved in one or more embodiments of the specification can be an electronic device, which can be the service platform 100 described above. The execution subject corresponding to the user identity authentication method involved in one or more embodiments of the specification can also be an electronic device corresponding to a client, which is determined based on the actual application environment. The user identity authentication system embodiment embodies the implementation process, which can be seen from the method embodiments described below, and will not be described here.

[0041] Based on Figure 1 The scenario diagram shown below is used to introduce in detail the user identity authentication method provided by one or more embodiments of the specification.

[0042] Please refer to Figure 2 A flowchart of a user identity authentication method is provided for one or more embodiments of the specification. The method can be implemented by relying on a computer program and can run on a user identity authentication device based on the von Neumann architecture. The computer program can be integrated in an application or run as an independent tool application. The user identity authentication device can be an electronic device.

[0043] Specifically, the user identity authentication method comprises:

[0044] S102: In response to a student identity authentication request of a user terminal for a target application, outputting a guided access operation instruction for a trusted student status website to the user terminal;

[0045] User identity authentication background: When a user needs certain specific services, such as applying for educational benefits or student-only services, the target application usually needs to verify whether the user has a student identity. The traditional method relies on interface calling student status database verification, which is limited by the stability of the student status verification service interface provided by the trusted student status website (such as the China Academic Degrees & Certificates Verification Center) and the interface verification cost. By guiding the user to directly access the student status website (such as the China Academic Degrees & Certificates Verification Center), not only can the student status verification service interface be bypassed, but also the security and transparency of the authentication process can be improved, and the entire process of user identity authentication in the target application is no longer a black box verification for the user.

[0046] Target application: The platform application or service application initiated by the user to request identity authentication, such as an online education application, a library management system application, a shopping application, a payment application, etc. It should be noted that the target application and the trusted student status website are independent of each other.

[0047] Guided access operation instruction: A pre-defined guide to the preset user access operation of the trusted student status website, used to guide the user to access the trusted student status website. For example: clicking on a specific link to access the China Academic Degrees & Certificates Verification Center and following the specified steps to query student status information.

[0048] For example, the user triggers a student identity authentication request in the target application. For example, clicking the "student authentication" button in the educational benefits service of the target application.

[0049] The electronic device identifies the user's student identity authentication request and determines that it needs to access a trusted student status website such as the China Academic Degrees & Certificates Verification Center to complete the student identity verification, in order to avoid the instability of the student status verification service interface provided by the trusted student status website for the target application and the interface verification cost

[0050] The electronic device generates a series of guided access operation instructions for accessing the China Academic Degrees & Certificates Verification Center, such as: access link or QR code, login operation steps (such as entering username and password), verification information query guide.

[0051] The electronic device transmits these guided access operation instructions to the user terminal. It can be presented in the form of page display, pop-up prompt or notification, and the user terminal needs to access the trusted student status website according to the preset guided access operation and make the preset guided access operation;

[0052] For example, Xiaoming applies for a student discount course of an online learning platform application (i.e. target application).

[0053] User trigger: Xiaoming clicks the "Student Authentication" button, initiating an authentication request.

[0054] System response: The system determines that Xiaoming's authentication requires access to the China Academic Degrees and Certificates Authentication Network (CDACAN) and generates guidance for accessing the CDACAN:

[0055] "Please click the following link within the target application to access the CDACAN: www.chsi.com.cn."

[0056] "After logging in, select the 'Online Verification of Student Status' service."

[0057] These guidance instructions are displayed through a pop-up window on Xiaoming's mobile phone.

[0058] In a feasible implementation, the status of the student verification service of the target application's trusted student website service interface can be detected first. If the status of the student verification service is an abnormal service status, the step of outputting guidance information for accessing the trusted student website to the user terminal is executed.

[0059] The above implementation proposes an intelligent processing mechanism that determines the subsequent operation flow by detecting the status of the trusted student website service interface of the target application. Specifically, if the interface service status is abnormal, an alternative method of guiding the user to directly access the student website is adopted. The following is a detailed explanation of this method:

[0060] The main consideration is that traditional student identity verification relies on the interface service provided by the trusted student website. However, in actual operation, the following limitations may be encountered: Interface service status abnormal: for example, interface response delay, service downtime, or data return error. Interface call cost: frequent interface calls can lead to high costs, especially in large-scale verification scenarios. User experience degradation: interface abnormalities may prevent users from completing the verification process, affecting the user experience.

[0061] By detecting the interface service status at the beginning of the process, it can be determined whether to switch to a backup plan (guide the user to directly access the student website), improving the robustness of the process.

[0062] Specifically, the status of the student verification service of the target application's trusted student website service interface is detected. The target application's trusted student website service interface refers to the API that the target application calls to verify the user's student identity by accessing the CDACAN or other trusted student database. The status of the student verification service indicates the working status of the interface, which can be at least divided into normal (available) and abnormal (unavailable).

[0063] If the status of the student verification service is an abnormal service status, the step of outputting guidance information for accessing the trusted student website is executed.

[0064] Optionally, if the student status verification service state is a normal service state, the student identity authentication of the user terminal is performed by calling the interface service of the trusted student status website.

[0065] It can be understood that the interface service state detection mechanism is introduced in the above manner, and the user guidance mode is switched when the interface is abnormal, which effectively improves the flexibility and stability of the authentication process. By guiding the user to directly access the student status website, the interface restriction can be bypassed, ensuring smooth authentication process, while reducing the dependence risk and cost of the system.

[0066] S104: Monitor the guided access operation of the user terminal to the trusted student status website based on the guided access operation instruction.

[0067] In order to ensure that the user can complete the student status verification step by step, the electronic device needs to monitor whether the user has correctly performed the guided operation. This not only helps to detect abnormal behavior (such as incomplete verification), but also provides data basis for subsequent authentication.

[0068] Guided access operation: the user completes the access process of the trusted student status website according to the guided access operation instruction, for example, after the user clicks to enter the verification, the user is guided to open the student information page, and prompted to click the "start collection" button to enter the information collection process.

[0069] For example, after the user clicks to enter the verification, the system guides the user to open the student information page, and prompts the user to click the "start collection" button to enter the information collection process. In the collection process, the user's screen is recorded, and the video stream is transmitted to the server in real time for effective video frame extraction,

[0070] Further, the system monitors the guided access operation of the user by the following monitoring mechanism:

[0071] 1) Network log analysis: record whether the user has accessed the specified link.

[0072] 2) Embedded code: embed code in the guidance page to track operation, such as capturing button click event.

[0073] 3) User-authorized data collection: collect user page access records on the trusted student status website.

[0074] Further, the system analyzes the user's website access track to check whether it conforms to the preset guide corresponding to the guided access operation instruction, for example:

[0075] Whether the link to the China Academic Degrees & Certificates Verification Center is clicked.

[0076] Whether the login is completed.

[0077] Whether the student status verification page is entered.

[0078] If the user does not follow the steps, the system can issue a reminder or interrupt the authentication process.

[0079] For example: Xiaoming accesses the China Academic Degrees & Certificates Verification Center according to the instructions. Operation monitoring:

[0080] The system records that Xiaoming clicked the "China Academic Degrees & Certificates Verification Center login link".

[0081] Page tracking record: Xiaoming accessed the www.chsi.com.cn homepage and successfully logged in.

[0082] Timestamp and status code show that Xiaoming stayed on the "student status verification" page for 10 seconds.

[0083] System judgment result: the system confirms that Xiaoming correctly performs the guided access operation to the trusted student status website.

[0084] S106: Collect student status website access data for the user terminal, determine identity recognition verification data for the user terminal based on the student status website access data, perform student identity authentication for the user terminal based on the identity recognition verification data, and obtain a student identity authentication result for the user terminal.

[0085] Consider that the traditional student identity authentication process directly depends on the return data of the third-party interface, while the present scheme collects user access to trusted student status websites such as data (such as page access records, submitted student status numbers), analyzes their authenticity, and generates identity verification data. This not only bypasses the high-cost interface call, but also improves the controllability and stability of the process.

[0086] Student status website access data: behavior data generated by the user when verifying in the trusted student status website, such as page access path, input field, etc.

[0087] Identity recognition verification data: key information extracted from student status website access data, such as name, student status number, etc.

[0088] Student identity authentication result: the final student authentication result, including the determination of whether the user is a student, and the detailed status (such as authentication passed, authentication failed).

[0089] In one feasible implementation, user access data on trusted student registration websites is collected through user authorization interfaces or backend logs. This access data includes, but is not limited to, one or more of the following: user login time, accessed page paths, submitted form fields, website user student registration information, user accessed website page characteristic information, and user biometric information.

[0090] Then, data analysis is performed on the access data of the student registration website: at least the student registration information of the website users, such as name, ID number, and student ID number, is obtained by extracting the data. The extracted data is then compared with the student authentication verification rules or database stored in the system to confirm consistency.

[0091] Then, an authentication judgment is performed: if the data is consistent and meets the rules, a "student authentication successful" result is generated; if the data is missing, inconsistent, or abnormal, a "student authentication failed" result is generated.

[0092] In one feasible implementation, the device environment information of the user terminal can be obtained first, and a security risk detection can be performed based on the device environment information to obtain a security risk detection result. Based on the security risk detection result, the step of collecting the student registration website access data for the user terminal can be executed.

[0093] For example, such as Figure 3 As shown, Figure 3 This is a schematic diagram of a data collection and authorization security verification scenario. Figure 3 The document illustrates the security and authorization management steps in a student identity verification process, primarily including: data collection and authorization & environment security checks: ensuring user devices and permissions meet security requirements to guarantee the reliability and security of subsequent operations; and guiding users to the student verification website: after the device and authorization checks are passed, guiding users to open the student verification page to begin the student identity verification task.

[0094] For example, authorization is granted, specifically guiding users to grant video recording and information collection permissions. During the verification process, users may need to record videos or upload materials; to obtain these resources, the system needs user authorization. Information collection permissions are used to record user behavior logs or collect student registration verification results to ensure the integrity of the authentication process. An optional implementation method is for the system to display a pop-up window prompting authorization information when the user initiates a verification request. The prompt includes an explanation of the purpose of the video recording and information collection permissions. After the user agrees, the system checks whether the permission status is normal.

[0095] The environmental safety detection is an example, that is, obtaining device environment information of the user terminal, and performing device security risk detection based on the device environment information to obtain a security risk detection result. The device security risk detection is to ensure that the device environment used by the user is safe and reliable, for example, detecting whether the device has potential threats (such as being rooted or jailbroken), detecting whether the device uses a system agent software, confirming whether the network environment is stable, whether a recommended network environment (such as a cellular network environment) is used, and ensuring the integrity of data transmission. If the security risk detection result indicates that the device or the environment has risks, the student identity authentication process can be interrupted or the user can be guided to switch to a safe device. If the security risk detection result indicates that the environment detection is safe, the system will guide the user to the next stage of the student status authentication process, that is, opening a trusted student verification website for operation. Through the guided operation, the user's confusion is reduced, and the authentication success rate is improved.

[0096] In the above manner, through the permission collection and the device environment detection, the device and the network used by the user are ensured to be safe, unauthorized interference or data leakage in the authentication process is avoided, after confirming that the user device and the authorization state are normal, the system will continue to verify, the stability and the accuracy of the student identity authentication process are improved. Clear guided operation is provided to avoid authentication failure caused by improper operation of the user, and security is enhanced through necessary prompts.

[0097] In one or more embodiments of the present specification, the user terminal initiates a student identity authentication request for a target application, at this time, the electronic device outputs a guided access operation instruction for a trusted student website to the user terminal, monitors guided access operation of the user terminal to the trusted student website based on the guided access operation instruction, collects student website access data of the user terminal, determines identity recognition verification data of the user terminal, and performs student identity authentication of the user terminal to obtain a student identity authentication result of the user terminal. By dividing the student identity authentication process into user guidance, operation monitoring, data collection and verification based on user access to a trusted student website, the high cost and instability problem of the traditional target application relying on a student verification service interface is solved. By guiding the user to access the trusted student website, the interface dependence is bypassed, the flexibility and robustness of the system are effectively improved; and by collecting student website access data of the user accessing the student website and generating identity recognition verification data, the accuracy and security of the authentication are ensured. In addition, the scheme takes into account the user experience, provides clear operation guidance, ensures smooth verification process, reduces the operation cost of the authentication process, and is suitable for student identity authentication needs in various scenarios.

[0098] See Figure 4 , Figure 4is a flowchart of a data collection process proposed by one or more embodiments of the present specification. Specifically, the collection is performed for the user's access data to the student website, and the identity verification data for the user is determined based on the access data to the student website. For reference, see the following embodiments

[0099] S202: Record the user's access website video for the guided access operation, and extract the access website video frame from the user's access website video.

[0100] User access website video: A dynamic video recording the user's operation during the completion of the student website access process, reflecting the actual operation behavior, including mouse clicks, page browsing, information input, etc.

[0101] Access website video frame: A static image frame extracted from the recorded video. The video can be decomposed into a continuous sequence of pictures for subsequent analysis and processing.

[0102] Illustratively, the electronic device system starts the video recording function to record the user's access website video for the guided access operation when the user accesses the trusted student website, and records the user's operation in real time. Access website video frames are extracted from the user's access website video, and irrelevant content video frames are removed, leaving key information access website video frames.

[0103] S204: Perform recognition processing on the access website video frame to obtain identity verification data for the user terminal.

[0104] Recognition processing: Extract and analyze the information in the access website video frame by using technologies such as computer vision (e.g., OCR text recognition, two-dimensional code decoding, image content analysis, etc.), graphic code decoding technology, and graphic analysis technology, to generate structured data.

[0105] Identity verification data: Key information related to the user's identity extracted from the access website video frame, such as name, student number, school name, etc., for subsequent identity verification and matching. In some embodiments, the identity verification data can include website user student information, user access website page feature information, and access user biometric information.

[0106] In a feasible implementation, the recognition processing of the access website video frame to obtain the identity verification data for the user terminal can be fitted according to one or more of the following methods:

[0107] 1. Perform website student information recognition processing on the access website video frame to obtain website user student information for the user terminal.

[0108] Website user academic information: key user academic information related to user identity generated after accessing website video frame recognition.

[0109] For example, access website video frames containing academic information, such as "academic verification report" pages, are extracted, OCR (optical character recognition) is used to identify the text information in the page, and the identified academic information is structured to obtain website user academic information.

[0110] 2. Website page feature recognition processing is performed on the access website video frame to obtain user access website page feature information.

[0111] Website page feature recognition: unique page features of the academic website in the video frame are identified by computer vision technology, such as page layout, color style, button position, etc.

[0112] Website page feature information: feature data reflecting whether the website accessed by the user is a real and reliable academic website.

[0113] In some embodiments, website page feature recognition can be combined with subsequent verification to avoid user modification of academic webpage data. The server will compare the extracted webpage information, including frame structure, website address, title, sponsor, copyright, and other website page feature information, with the reliable academic official website information retained by the system to determine whether they are consistent. In this way, some abnormal pages can be preliminarily identified.

[0114] Illustratively, website page feature information is extracted from access website video frames, such as page structure (HTML DOM structure) and visual features of page elements (such as logo and specific button position). Subsequently, these website page feature information can be compared with the pre-stored page feature templates of reliable academic websites to verify whether the website accessed by the user is an officially certified page and detect whether there are abnormal page features (such as fake pages or phishing websites).

[0115] Optionally, the webpage verification method can also be performed by simultaneously carrying the MD5 signature of the current HTML template and the public key matching the private key used for signature in the HTML academic page when the server side issues the HTML template. When the HTML academic page runs on the terminal side, the value obtained by performing MD5 on the HTML academic webpage is compared with the MD5 value generated by the server after decryption by the public key to ensure that the HTML academic webpage has not been modified.

[0116] 3. User biometric feature recognition processing is performed on the access website video frame to obtain access user biometric feature information.

[0117] User biometric identification: By analyzing the user's face, voice or other biometric features in the access website video frame, verify whether the operation is a real user.

[0118] Access user biometric information: Biometric data reflecting the identity of the user, such as facial feature points, voice features, etc.

[0119] As shown schematically, the user's biometric features are extracted from the access video frame, such as the user's facial features, the user's voice information (if any). The extracted access user biometric information is matched with the pre-stored user biometric data (such as facial feature template), the operation user identity is verified, and the biometric abnormality is detected, such as video fraud or disguised operation.

[0120] In this specification, the above-mentioned method can solve the problems of untrusted data, page forgery and false operation in traditional authentication method, and is particularly suitable for scenes with high requirements for authentication accuracy and security. In high security requirement scenarios, it can be combined with student information recognition, page feature recognition and biometric identification to ensure data source and operation authenticity.

[0121] Please refer to Figure 5 , Figure 5 is a flowchart of a website video frame processing method proposed by one or more embodiments of the present specification. After the access website video frame is extracted from the user access website video, the following method can be used for reference:

[0122] S3002: Perform picture anti-forgery detection on the access website video frame to obtain a video anti-forgery detection result;

[0123] In the student identity authentication process, the user may submit a fake video frame, such as by taking a screenshot, taking a screen shot or modifying image content to impersonate a real operation. Directly using the student information extracted from the fake frame may lead to authentication failure or data fraud risk. Through picture anti-forgery detection, filter the fake frame data, ensure that the subsequent identity information extraction is based on real and reliable user operation records, thereby improving the security of authentication and the credibility of data.

[0124] Picture anti-forgery detection: Using computer vision and image processing technology to analyze the authenticity of the access website video frame, and determine whether the frame is a fake image. For example, detect whether there is a screenshot, a synthetic image, a screen shot, etc.

[0125] Video anti-forgery detection result: The judgment result of anti-forgery detection, indicating whether the video frame is generated in the process of real user accessing the student website, which may include "real", "fake", "suspected fake" and other classifications.

[0126] As shown in Figure 6 ,Figure 6 is a schematic diagram of a video recording learning information collection scene; schematically, the user screen image of the accessed website video frame is analyzed, the image feature values such as the optical characteristics, resolution, texture and format of the image are extracted, the forgery feature detection is performed based on the image feature detection, including but not limited to the screenshot feature detection: the image features such as the resolution and image edge definition in the frame are analyzed to determine whether it is a screenshot; the photographing feature detection: the screen reflection and moire features in the photographed image are identified; the synthesis detection: whether the content is tampered or spliced is detected by analyzing the compression characteristics and texture consistency of the image. Each frame is assigned a forgery result label such as “real”, “forgery” and “suspected forgery”, and the result is stored for subsequent screening.

[0127] S3004: screening the accessed website video frame of the non-forgery type based on the video forgery detection result;

[0128] Video forgery detection result: the forgery detection result generated in the previous step, indicating the authenticity state of each frame.

[0129] Screening non-forgery type: according to the forgery detection result, the video frames judged as forgery are filtered out, and the real frames are retained for subsequent processing.

[0130] Schematically, the forgery detection result is read, the forgery result label (such as “real”, “forgery”) of each frame is obtained, the frame list is traversed, and only the frames with the label “real” are retained. All frames with the label “forgery” or “suspected forgery” are removed, and the screened frame list is returned for subsequent identity information extraction.

[0131] In this specification, the forged frames are removed by forgery detection, and only the real frames are processed subsequently, ensuring that the extracted identity information is reliable. It prevents users from forging identity through screenshot or photographing, reduces the risk of authentication fraud, enhances the security of authentication, reduces the processing burden of invalid frames through screening, and improves the efficiency of the authentication process. The system can efficiently filter out forged frames, ensure the authenticity and security of identity authentication, and provide reliable protection for student status verification.

[0132] S3006: performing abnormal access operation recognition on the accessed website video frame to obtain an abnormal access operation recognition result;

[0133] Abnormal access operation recognition: using behavior analysis and video frame content detection technology, whether the user has abnormal behavior in the process of accessing the student status website is identified, for example, the operation does not conform to the guided process, the website is not logged in or attempts to perform illegal operation. As shown in the dynamic detection of user abnormal operation for abnormal access recognition. Figure 6

[0134] ​Abnormal access operation identification result: the system's identification result of the user's behavior, usually divided into "normal behavior" and "abnormal behavior", abnormal behavior may include skipping login, fake page access, not completing operations according to instructions, etc.

[0135] Considering that the student status verification process requires the user to strictly follow the instructions, but some users may have abnormal operation behaviors, such as skipping key steps (e.g. not completing the loading of the student status verification page), simulating or faking the student status verification scene (e.g. accessing through a script simulation), interrupting or making errors in the operation process.

[0136] Based on this, through the abnormal identification of user access behavior, the authenticity and integrity of the authentication process are ensured. If abnormal behavior is found, the user's operation is interrupted or redirected in time, thereby ensuring the security and accuracy of the authentication process.

[0137] Illustratively, whether the user operation steps in the access website video frame meet the expectations. For example, whether the correct student status verification page is accessed, whether the login operation is completed. Through abnormal detection of the access website video frame, preset abnormal behaviors are detected, such as not logging in the student status website behavior, skipping important verification steps behavior, non-student status website page access behavior, page features and trusted page template mismatch behavior (such as fake page), and then based on the preset abnormal behavior detection result, it is marked as "normal" or "abnormal";

[0138] Optionally, page feature recognition technology (such as SIFT feature point matching) can be used to verify whether the user access page is a student status verification page. If the page features do not match the expected template, it is determined to be abnormal.

[0139] Optionally, a behavior model (such as a user path analysis model) is used to detect whether the user has completed the steps according to the normal operation process. If the user path is significantly different from the expected path, it is marked as abnormal.

[0140] S3008: If the abnormal access operation identification result is an abnormal behavior type, interrupt the user's access to the website video recording and / or output a re-student identity authentication prompt information and perform the step of outputting access to trusted student status website guidance information to the user end.

[0141] Interrupting the user's access to the website video recording: after detecting abnormal behavior, the system immediately stops recording the user's video operation, avoiding continuing to process invalid or fake data.

[0142] Re-student identity authentication prompt information: the system sends a prompt information to the user, informing him of the abnormal operation and guiding him to start the student status verification process again.

[0143] Outputting access to the trusted student website guidance information: re-providing the user with operation guidance for accessing the student website to ensure that the user can correctly complete the authentication process.

[0144] It can be understood that if there is abnormal behavior in the user operation process, continuing to record or process related data may cause authentication failure or unnecessary waste of resources. By interrupting the abnormal operation in time and guiding the user to complete the correct authentication process, not only can system resources be saved, but also the user experience can be optimized and the success rate of authentication can be improved.

[0145] Illustratively, if the abnormal access operation recognition result is an abnormal behavior type, the system immediately triggers a response, interrupts the current video recording, and stops subsequent data analysis and processing. Alternatively, the system can send a re-student identity authentication prompt information to the user, an abnormal prompt information, explain the abnormal reason, for example: "You have not completed the login operation, please start the authentication again." "Detecting abnormal access page, please confirm and re-operate." Then output clear re-student identity authentication prompt information, and execute the step of outputting access to the trusted student website guidance information to the user end.

[0146] In this specification, the abnormal behavior in the user operation is discovered and corrected in time, the influence of fake or invalid data on the authentication result is avoided, the robustness of the authentication process is improved, the recording and processing of abnormal operation are interrupted, the system computing resources are saved, the abnormal behavior detection and re-authentication guidance are performed to prevent malicious operation and data falsification, the abnormal prompt and re-guidance ensure that the user understands the error reason and completes the verification according to the correct process, and the authentication success rate is improved. The system can effectively detect abnormal behavior, quickly respond and guide the user to complete the correct student verification process, and ensure the reliability and security of authentication.

[0147] See Figure 7 , Figure 7 is a flowchart of a student identity authentication process according to one or more embodiments of the present specification, which performs student identity authentication on the user end based on the identity recognition verification data to obtain a student identity authentication result for the user end. The following one or more ways can be used for fitting, specifically:

[0148] S4002: determining website user student information from the identity recognition verification data based on the student information verification process, performing student information verification processing on the user end based on the website user student information, and obtaining a student information verification result;

[0149] Student information verification process: extracting student information (such as name, student number, school name, etc.) from the user's identity recognition verification data, and comparing with the system pre-stored data or rules to verify the authenticity of the student information.

[0150] Student information verification result: indicates the final result of student information verification, usually "verification passed" or "verification failed". In some embodiments, the student information verification result includes the first student information verification result, the second student information verification result, the third student information verification result, and the fourth student information verification result;

[0151] In a feasible implementation, the student information verification processing of the user terminal based on the website user's student information is performed to obtain a student information verification result, which can be fitted by referring to one or more of the following ways:

[0152] S2: Determine the historical verification record corresponding to the same student user based on the website user's student information, perform verification frequency detection based on the historical verification record to obtain a user verification frequency detection result, perform student information consistency detection based on the historical verification record to obtain an information consistency detection result, and obtain a first student information verification result based on the user verification frequency detection result and the information consistency detection result;

[0153] In student information verification, only current verification data may not be able to comprehensively determine the authenticity of the user's identity. By introducing historical verification records, the system can further verify the user's student information from the dimensions of verification frequency and information consistency, thereby enhancing the depth and accuracy of authentication.

[0154] Verification frequency detection: discovers abnormal verification behavior, such as high-frequency verification, which may indicate identity abuse or data forgery.

[0155] Information consistency detection: ensures that the user's student information remains consistent in multiple verifications, excluding the possibility of data tampering or identity impersonation.

[0156] Multi-dimensional result comprehensive judgment: combines the frequency and consistency results to generate a more comprehensive first student information verification result.

[0157] Historical verification record: the user's past student verification data in the system, including verification time, verification times, verification success or failure status, and corresponding student information.

[0158] Verification frequency detection: detects the frequency of the user's verification records, such as multiple verification requests submitted in a short period of time, which may indicate abnormal behavior.

[0159] Student information consistency detection: compares the student information submitted by the user in the historical verification record to determine whether it is consistent. If the information is found to be inconsistent, it may indicate identity impersonation or tampering.

[0160] First student information verification result: the final judgment based on the user verification frequency and student information consistency detection result, indicating whether the user's student information is reliable.

[0161] To illustrate, the first step is to determine the historical verification records corresponding to the same student based on the website user's student status information. This includes: querying the historical verification records in the system through the user's key fields (such as student ID number or national ID number) and extracting all verification data for that user, including verification time, submitted information, and verification results.

[0162] Then, verification frequency detection is performed based on historical verification records, including analyzing the frequency of user verification records. For example: short-term high frequency: the same user submits verification multiple times within one day. Long-term abnormality: a user's total number of verifications far exceeds the average of other users.

[0163] Secondly, determine whether the frequency is abnormal to obtain a comprehensive frequency detection result: normal: frequency is lower than the preset threshold; abnormal: frequency exceeds the threshold.

[0164] Secondly, consistency detection results are obtained by performing consistency checks on student registration information based on historical verification records. This includes extracting student registration information fields (such as name, student ID, and school) from the user's historical verification records and comparing whether the information submitted each time in the historical data is completely consistent. Consistent consistency detection results: there is no difference in the information in all records. Inconsistent consistency detection results: some fields in the historical records have changed.

[0165] Finally, by combining the frequency detection results and the consistency detection results, a first student status information verification result is generated through logical rules. If the frequency is normal and the information is consistent, a first student status information verification result that passes the verification is generated. If the frequency is abnormal or the information is inconsistent, a first student status information verification result that fails the verification is generated.

[0166] This is an illustrative example of detecting whether a current user has any illegal historical verification records to identify risky users. The main rule of this S2 step is to identify whether the same identity has been used multiple times with different student registration codes and school information for verification. During system design, a historical verification data management unit is correspondingly designed to store the verification records and data for a specific user identity. During each verification frequency check, the system queries the historical verification data by verifying the user's identity information and compares it. If it identifies that a user identity has undergone multiple identity verifications (i.e., verification frequency detection processing) and the provided academic information is inconsistent (i.e., student registration information consistency detection processing), an inconsistency-type information consistency detection result is generated. Furthermore, the system will subsequently determine the user as a risky user based on the inconsistency-type information consistency detection result and interrupt the student identity verification process.

[0167] S4: Based on the student registration information of the website user, the official verification service is used to verify the student registration identity information to obtain the second student registration information verification result;

[0168] Illustratively, key student information such as name, student ID number, and school name is extracted from the identity verification data, and the extracted key student information is matched with pre-stored data (such as a student database) in the system to check for inconsistencies, missing fields, or data falsification. If the comparison result is consistent, a second student information verification result of “student identity information verification passed” is returned, and if there is inconsistency, a second student information verification result of “student identity information verification failed” is returned.

[0169] S6: Student graduation status detection based on the website user student information to obtain a third student information verification result;

[0170] Student graduation status detection can be understood as identifying whether the current user is enrolled. The enrollment information, enrollment year, and school system are extracted from the website user student information, and whether the current user has graduated is calculated based on the extracted information to obtain a third student information verification result. For users who have graduated, this identity verification can be directly rejected.

[0171] S8: Based on the student identification code in the website user student information, obtain student identification code identification information, and perform student information consistency check on the website user student information and the student identification code identification information to obtain a fourth student information verification result.

[0172] Illustratively, based on the student identification code in the website user student information, the student identification code can be identified to obtain student identification code identification information. The website user student information and the student identification code identification information are checked for consistency to obtain a fourth student information verification result. That is, a second verification is performed. The server can obtain student information from the website by accessing or crawling based on the student ID number collected from the student information network. In some cases, the student information corresponding to the student ID number may be in a desensitized form, and the data can be compared for consistency through fuzzy matching. The data compared includes user name, ID number, school, student ID, enrollment date, education form, school system, and student status. For cases where at least one comparison fails, the student identity verification is directly rejected.

[0173] Then, at least one of the first student information verification result, the second student information verification result, the third student information verification result, and the fourth student information verification result can be combined to obtain a student information verification result.

[0174] S4004: Based on the student information network page verification process, determine the user access website page feature information from the identity verification data, perform student information network page verification processing based on the user access website page feature information, and obtain a student information network page verification result;

[0175] Student webpage verification process: By analyzing the user's access to the website page feature information, it is confirmed whether the user has accessed the real student verification page, and the compliance of the page operation is verified.

[0176] Student webpage verification result: The result of verifying the authenticity of the page and the operation behavior, usually "verification passed" or "verification failed".

[0177] Illustratively, the page features (such as page structure, button layout, logo location, etc.) are extracted from the user's video frames to determine whether the page is a trusted student website. The page features are matched with the pre-stored student webpage templates to check whether the page layout and content are consistent. If the page features completely meet the expectations, the student webpage verification result of "student webpage verification passed" is returned. If the features are abnormal (such as fake pages or incorrect access), the student webpage verification result of "student webpage verification failed" is returned.

[0178] By verifying the authenticity and compliance of the user's access to the page, the authenticity of the operation is further ensured, which is suitable for scenarios to prevent fake pages or abnormal behaviors.

[0179] In a feasible implementation, in the student identity authentication process, verifying whether the user has accessed a real and trusted student website is a key link. Fake pages or illegal redirections may cause the authentication result to be tampered with or invalid. Therefore, the features of the user's access page need to be compared with the features of the trusted website page to ensure the authenticity and security of the access process. By verifying the page features, it is verified whether the user has accessed the official student website to prevent phishing pages or fake pages from affecting the authentication result. Specifically, the student webpage verification process based on the user's access to the website page feature information is performed to obtain the student webpage verification result, which can refer to the following methods:

[0180] A2: Obtain trusted website page feature information saved for accessing the trusted student website;

[0181] Trusted website page feature information: pre-stored feature data of trusted student website pages, for example:

[0182] Page layout (such as HTML DOM structure), page image elements (such as logo picture features), page text content (such as title, prompt text), and page element interaction behavior (such as button click feedback);

[0183] Illustratively, the system pre-collects page feature information (such as HTML structure, image features (such as logo or other static content), and page dynamic characteristics (such as AJAX request, button behavior)) from trusted student websites during the authentication process configuration stage, and then stores the extracted trusted website page feature information in a structured form in a database or folder.

[0184] A4: Perform page feature verification processing on the user access website page feature information and the trusted website page feature information to obtain a student status webpage verification result;

[0185] User access website page feature information: Page features extracted from video frames or network data operated by the user, such as page content, layout, or dynamic behavior.

[0186] Page feature verification processing: Comparing the features of the user access page with the trusted page features to detect whether the pages match and confirm the authenticity of the user access page.

[0187] Student status webpage verification result: The result of the page feature comparison, usually "verification passed" or "verification failed".

[0188] Illustratively, extract user access website page feature information: Extract page features from user access records or video frames, and the extracted features include static information (such as title, logo) and dynamic behavior (such as button operation).

[0189] Then compare the user access website page feature information and the trusted website page feature information: 1. Static feature comparison: Verify whether the page title, logo feature, element layout, etc. are consistent with the trusted page. 2. Dynamic feature comparison: Verify whether the page response behavior meets the expected (such as button click to load verification page).

[0190] Generate student status webpage verification result: If the user page features are completely consistent with the trusted page, generate a student status webpage verification result of verification passed. If there are differences in features (such as fake pages, content tampering), generate a student status webpage verification result of verification failed.

[0191] Illustratively, through feature verification, it is ensured that the page accessed by the user is a real and trusted student status website, and abnormal operations (such as fake page button behavior) are detected through dynamic behavior verification. It can effectively verify the authenticity and legality of the user access page, and provides comprehensive and reliable technical support for student status webpage verification.

[0192] S4006: Determine access user biometric information from the identity verification data based on the real user verification process, perform real user verification processing based on the user biometric information, and obtain a user identity verification result;

[0193] In identity authentication, it may be difficult to completely confirm the authenticity of the user's identity by only using student information and page feature verification. For example, student information may be used by others, and page feature verification cannot rule out the possibility of fake operations. Therefore, introducing user biometric information (such as facial features or behavioral features) for real user verification is an important supplement to the identity verification process. Through biometric verification, it is confirmed that the operation process is indeed completed by the target user; exclude illegal behaviors such as proxy operations or video forgeries; and through a multi-dimensional verification mechanism, reduce the fraud risk in identity authentication.

[0194] Real user verification process: Based on the user's biometric information (such as face, voice, behavior characteristics), verify whether the operation user is the target user.

[0195] Access user biometric information: User biometric data collected during the operation process, such as: facial feature points (such as the geometric relationship of eyes, nose, and mouth), voice characteristics (such as frequency, speech rhythm), and behavior characteristics (such as mouse clicks, touch screen swipe patterns).

[0196] User identity verification result: The result of verifying user biometric information, usually "verification passed" or "verification failed".

[0197] Illustratively, extract user biometric information from identity recognition verification data, denoise and standardize the collected biometric data, and convert it into a structured user biometric vector.

[0198] Then compare the user biometric vector with the target user's biometric template. The system can call the biometric template saved during the target user's registration, and calculate the similarity through a feature matching algorithm. The verification rule can be to set a similarity threshold, and if the similarity is higher than the threshold, the verification is passed; otherwise, the verification fails.

[0199] Then generate the user identity verification result: if the comparison result meets the preset rule, return "verification passed". If the comparison fails, return "verification failed" and prompt the user to re-operate.

[0200] Through the above method, real user verification is realized, ensuring that the operation process is completed by the target user, preventing fake or fake operations, enhancing data credibility, and improving authentication security. Automatic collection and comparison of biometric features can optimize user experience, support multi-modal biometric verification such as face, voice, and behavior, adapt to different devices and scenarios, and the system can effectively verify the real identity of the user, providing higher security and accuracy for student authentication processes.

[0201] In one feasible implementation, the process of performing real user verification based on the user's biometric information to obtain the user identity verification result can be performed in the following manner:

[0202] B2: Obtain the student's facial image and the user's facial image from the user's biometric information;

[0203] B4: Perform facial matching between the student's facial image and the user's facial image to obtain the user's identity verification result;

[0204] For example, facial matching can be used to verify whether a person is the same person. The student registration page collects information such as the user's facial photo, name, and ID number. By extracting the facial photo and combining it with relevant facial comparison services, it can be verified whether the current identity information and the photo belong to the same person. If they are not the same person, the student identity verification can be rejected directly.

[0205] S4008: Based on at least one of the student status information verification result, the student status webpage verification result, and the user identity verification result, obtain the student identity authentication result for the user terminal.

[0206] Single-dimensional verification methods (such as student registration information verification) may have limitations, such as the risk of data forgery, page tampering, or user identity fraud. By combining multiple verification results (such as student registration information verification, student registration webpage verification, and user identity verification), the system can verify user identity from multiple dimensions, improving the security and accuracy of student identity authentication. Combining multiple verification results provides a more comprehensive authentication judgment, reducing the possibility of false judgments from single verifications and thus enhancing authentication accuracy. Even in cases where some verification results are missing (such as when biometric verification is not performed), the system can still generate an authentication conclusion based on the available results. Multi-dimensional authentication reduces the risk of fraud and ensures the reliability of the authentication process.

[0207] In one feasible implementation, if at least one of the following verification results—student registration information verification result, student registration webpage verification result, and user identity verification result—is successful, then a successful student identity authentication result is generated; conversely, if at least one of these results is unsuccessful, then an unsuccessful student identity authentication result is generated.

[0208] like Figure 8 As shown, Figure 8 This is a schematic diagram illustrating a scenario for verifying academic credentials. Specifically:

[0209] 1. Process combination of multiple OCR results, multiple extraction of OCR data from user video frames to ensure data integrity and accuracy, integration of OCR data extracted from different frames to obtain student website access data;

[0210] 2. Extract identity verification data from OCR results-student website access data;

[0211] 3. Multi-dimensional student identity verification to obtain student identity authentication results:

[0212] 1) First, identify the basic elements of the page framework and compare them with the China Academic Degrees and Titles Information Network page to verify whether the page accessed by the user is a trusted China Academic Degrees and Titles Information Network page. That is, S4004 is executed: determining user access website page feature information from the identity verification data based on the China Academic Degrees and Titles Information Network page verification process, performing China Academic Degrees and Titles Information Network page verification processing based on the user access website page feature information, and obtaining China Academic Degrees and Titles Information Network page verification results;

[0213] 2) Verify the student name and student number extracted by OCR to verify whether the user's student information extracted by OCR is consistent with the system pre-stored data. That is, S4002 is executed: determining website user student information from the identity verification data based on the student information verification process, performing student information verification processing on the user end based on the website user student information, and obtaining student information verification results;

[0214] 3) Identify whether the extracted student code is used in different identities; That is, S2 is executed: determining the historical verification records corresponding to the same student user based on the website user student information, performing verification frequency detection based on the historical verification records to obtain user verification frequency detection results, performing student information consistency detection based on the historical verification records to obtain information consistency detection results, and obtaining first student information verification results based on the user verification frequency detection results and the information consistency detection results;

[0215] 4) Check the legality of the student status and identity, that is, determine whether the current identity is enrolled;

[0216] 5) Determine whether to graduate according to the enrollment year and school system;

[0217] That is, S6 is executed: performing student graduation status detection based on the website user student information to obtain third student information verification results;

[0218] 6) Extract the student user photo for face verification; That is, S4006 is executed: determining access user biometric information from the identity verification data based on the real user verification process, performing real user verification processing based on the user biometric information, and obtaining user identity verification results;

[0219] 7) Extract school information and education network crawler data for comparison;

[0220] In the present specification, the student identity is comprehensively verified in combination with student information, webpage features and user biological features, the weight or result judgment logic is adjusted according to the scene and data situation, the authentication security is improved, the multi-dimensional verification reduces the single-point verification failure or fraud risk, the robustness of the authentication system is enhanced, the reliable authentication conclusion can still be output in the case of partial result missing, the user experience is optimized, the automatic comprehensive verification reduces the repeated operation, and the authentication efficiency is improved. The system can generate a student identity authentication result based on multi-dimensional verification results, and provide strong support for identity authentication scenes with high security requirements;

[0221] The specific implementation of the present specification will be described below. Figure 9 The user identity authentication device provided by the present specification will be described in detail. It should be noted that Figure 9 The user identity authentication device shown in the present specification is used to execute the method of the present specification Figures 1-8 The method of the embodiment shown in the present specification is only shown in relation to the present specification, and the specific technical details not disclosed are described with reference to the present specification Figures 1-8 The embodiment shown in the present specification.

[0222] Please refer to Figure 9 , which shows the structure diagram of the user identity authentication device of the present specification. The user identity authentication device 1 can be realized by software, hardware or a combination of the two to become all or part of the user electronic device. According to some embodiments, the user identity authentication device 1 includes a request authentication module 11, an operation monitoring module 12 and a student authentication module 13, which are specifically used for:

[0223] The request authentication module 11 is configured to respond to a student identity authentication request of a user terminal for a target application, and output a guided access operation instruction for a trusted student website to the user terminal.

[0224] The operation monitoring module 12 is configured to monitor the guided access operation of the user terminal on the trusted student website based on the guided access operation instruction.

[0225] The student authentication module 13 is configured to collect student website access data for the user terminal, determine identity recognition verification data for the user terminal based on the student website access data, perform student identity authentication on the user terminal based on the identity recognition verification data, and obtain a student identity authentication result for the user terminal.

[0226] The collection of student website access data for the user terminal and the determination of identity recognition verification data for the user terminal based on the student website access data include:

[0227] recording a user access website video for the guided access operation, extracting an access website video frame from the user access website video;

[0228] performing identification processing on the access website video frame to obtain identity identification verification data for the user terminal.

[0229] In an available implementation, the performing identification processing on the access website video frame to obtain identity identification verification data for the user terminal comprises:

[0230] performing website enrollment information identification processing on the access website video frame to obtain website user enrollment information for the user terminal; and / or,

[0231] performing website page feature identification processing on the access website video frame to obtain user access website page feature information; and / or,

[0232] performing user biological feature identification processing on the access website video frame to obtain access user biological feature information.

[0233] In an available implementation, after the extracting an access website video frame from the user access website video, the method further comprises:

[0234] performing picture anti-counterfeiting detection on the access website video frame to obtain a video anti-counterfeiting detection result, and screening the access website video frame of a non-counterfeit type based on the video anti-counterfeiting detection result; and / or,

[0235] performing abnormal access operation identification on the access website video frame to obtain an abnormal access operation identification result, and if the abnormal access operation identification result is an abnormal behavior type, interrupting user access website video recording and / or outputting a re-student identity authentication prompt information and performing the step of outputting access credible enrollment website guidance information to the user terminal.

[0236] In an available implementation, the performing student identity authentication on the user terminal based on the identity identification verification data to obtain a student identity authentication result for the user terminal comprises:

[0237] determining website user enrollment information from the identity identification verification data based on an enrollment information verification process, performing enrollment information verification processing on the user terminal based on the website user enrollment information to obtain an enrollment information verification result; and / or,

[0238] determining user access website page feature information from the identity identification verification data based on an enrollment webpage verification process, performing enrollment webpage verification processing based on the user access website page feature information to obtain an enrollment webpage verification result; and / or,

[0239] determine access user biometric information from the identity verification data based on a real user verification process, perform real user verification processing based on the user biometric information, and obtain a user identity verification result;

[0240] Based on at least one of the student information verification result, the student webpage verification result and the user identity verification result, a student identity authentication result for the user terminal is obtained.

[0241] In a feasible implementation, the student webpage verification processing based on the user access website page feature information to obtain a student webpage verification result includes: obtaining trusted website page feature information saved for the trusted student website, performing page feature verification processing on the user access website page feature information and the trusted website page feature information to obtain a student webpage verification result.

[0242] The real user verification processing based on the user biometric information to obtain a user identity verification result includes: obtaining a student face image and a user face image in the user biometric information, and performing face matching on the student face image and the user face image to obtain a user identity verification result.

[0243] The student information verification processing based on the website user student information on the user terminal to obtain a student information verification result includes: determining the historical verification record corresponding to the same student user based on the website user student information, performing verification frequency detection based on the historical verification record to obtain a user verification frequency detection result, performing student information consistency detection based on the historical verification record to obtain an information consistency detection result, obtaining a first student information verification result based on the user verification frequency detection result and the information consistency detection result; and / or, obtaining a second student information verification result based on the website user student information using an official verification service to verify the student identity information; and / or, obtaining a third student information verification result based on the website user student information to detect the student graduation state; obtaining student code identification information based on the student identification code in the website user student information, and performing student information consistency check on the website user student information and the student code identification information to obtain a fourth student information verification result.

[0244] In a feasible implementation, the device is further used for:

[0245] Obtain the device environment information of the user terminal, perform device security risk detection based on the device environment information to obtain a security risk detection result, and perform the step of collecting student website access data for the user terminal based on the security risk detection result; and / or,

[0246] The user identity authentication device provided in the embodiments of the present application can detect the status of the student status verification service of the trusted student status website service interface corresponding to the target application, and if the status of the student status verification service is an abnormal service status, the step of outputting the guidance information for accessing the trusted student status website to the user end is executed. It should be noted that the user identity authentication device provided in the embodiments of the present application is only used for illustrating the division of the functional modules, and in actual application, the above-mentioned functions can be completed by different functional modules according to the needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the user identity authentication device and the user identity authentication method provided in the embodiments of the present application belong to the same concept, and the implementation process is embodied in the method embodiments, which will not be described here.

[0247] The serial number of the present specification is only for description, and does not represent the advantages and disadvantages of the embodiments.

[0248] The present specification also provides a computer storage medium, which can store a plurality of instructions, the instructions being suitable for being loaded and executed by a processor to execute the user identity authentication method of the embodiments of the present application as shown in the above Figures 1-8 The specific execution process can refer to the specific description of the embodiments of the present application as shown in the above Figures 1-8 The specific execution process can refer to the specific description of the embodiments of the present application as shown in the above

[0249] The present specification also provides a computer program product, which stores at least one instruction, the at least one instruction being loaded and executed by the processor to execute the user identity authentication method of the embodiments of the present application as shown in the above Figures 1-8 The specific execution process can refer to the specific description of the embodiments of the present application as shown in the above Figures 1-8 The specific execution process can refer to the specific description of the embodiments of the present application as shown in the above

[0250] Please refer to Figure 10 , a structural block diagram of an electronic device provided by the embodiments of the present application. The electronic device in the present specification can include one or more of the following components: a processor 1010, a memory 1020, an input device 1030, an output device 1040 and a bus 1050. The processor 1010, the memory 1020, the input device 1030 and the output device 1040 can be connected through the bus 1050.

[0251] The processor 1010 can include one or more processing cores. The processor 1010 connects various parts within the entire electronic device by various interfaces and lines, executes various functions of the electronic device and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 1020, and calling data stored in the memory 1020. Alternatively, the processor 1010 can be implemented in at least one of a hardware form of a digital signal processing (DSP), a field-programmable gate array (FPGA), a programmable logic array (PLA). The processor 1010 can integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes an operating system, a user interface, and an application program, etc.; the GPU is responsible for rendering and drawing display content; and the modem is used for processing wireless communication. It can be understood that the above-mentioned modem can also not be integrated into the processor 1010, but be implemented by a separate communication chip.

[0252] The memory 1020 can include a random access memory (RAM) and can also include a read-only memory (ROM). Alternatively, the memory 1020 includes a non-transitory computer-readable storage medium. The memory 1020 can be used to store instructions, programs, codes, code sets or instruction sets.

[0253] Among them, the input device 1030 is used to receive input instructions or data, and the input device 1030 includes but is not limited to a keyboard, a mouse, a camera, a microphone or a touch device. The output device 1040 is used to output instructions or data, and the output device 1040 includes but is not limited to a display device and a speaker, etc. In the embodiment of the present specification, the input device 1030 can be a temperature sensor used to obtain the operating temperature of the electronic device. The output device 1040 can be a speaker used to output an audio signal.

[0254] In addition, those skilled in the art can understand that the structure of the electronic device shown in the above-mentioned drawings does not constitute a limitation on the electronic device, and the electronic device can include more or fewer components than the drawings, or combine certain components, or different component arrangements. For example, the electronic device also includes radio frequency circuitry, an input unit, a sensor, audio circuitry, a wireless fidelity (WIFI) module, a power supply, a Bluetooth module, and the like, which are not described here.

[0255] In the embodiments of the present specification, the execution subject of each step can be the electronic device introduced above. Alternatively, the execution subject of each step is an operating system of the electronic device. The operating system can be an Android system, an IOS system, or other operating systems, and the embodiments of the present specification do not limit this.

[0256] In the electronic device, Figure 10 In the electronic device, the processor 1010 can be configured to invoke a program stored in the memory 1020 and perform to implement the user identity authentication method as described in the various method embodiments of the present specification.

[0257] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory, or a random access memory, etc.

[0258] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the embodiments of the present specification are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions. For example, the school website access data, identity verification data, etc. involved in the present specification are obtained under sufficient authorization.

[0259] The above only describes the preferred embodiments of the present specification, and of course cannot limit the scope of the rights of the present specification, so equivalent changes made according to the claims of the present specification still fall within the scope covered by the present specification.

Claims

1. A user authentication method, the method comprising: In response to a user's request for student identity authentication for a target application, the system outputs a guidance instruction to the user for accessing a trusted student registration website. Monitor the user's access to the trusted student registration website based on the guided access operation instruction; Collect student registration website access data for the user terminal, determine identity verification data for the user terminal based on the student registration website access data, perform student identity authentication on the user terminal based on the identity verification data, and obtain student identity authentication result for the user terminal.

2. The method according to claim 1, wherein collecting student registration website access data for the user terminal and determining identity verification data for the user terminal based on the student registration website access data includes: Record a video of a user accessing a website in response to the guided access operation, and extract video frames of the website accessing video from the video of the user accessing the website. The video frames accessed from the website are processed to obtain identity verification data for the user.

3. The method according to claim 2, wherein the step of identifying and processing the video frames accessed from the website to obtain identity verification data for the user terminal includes: The website student registration information is identified and processed by the video frames accessed on the website to obtain the website user student registration information for the user terminal; And / or, Perform website page feature recognition processing on the video frames accessed to the website to obtain user access website page feature information; and / or, The biometric information of the accessing user is obtained by performing biometric identification processing on the video frames of the accessed website.

4. The method according to claim 2, further comprising, after extracting the website access video frames from the user's website access video: Perform image anti-counterfeiting detection on the video frames accessing the website to obtain video anti-counterfeiting detection results; and filter out non-counterfeit video frames accessing the website based on the video anti-counterfeiting detection results; and / or, The abnormal access operation is identified by analyzing the video frames of the accessed website. If the abnormal access operation identification result is an abnormal behavior type, the recording of the user's access to the website video is interrupted and / or a prompt message for re-authenticating the student identity is output, and the step of outputting guidance information for accessing the trusted student status website to the user terminal is executed.

5. The method according to claim 1, wherein performing student identity authentication on the user terminal based on the identity verification data to obtain a student identity authentication result for the user terminal includes: Based on the student registration information verification process, the website user's student registration information is determined from the identity verification data; based on the website user's student registration information, the user terminal is subjected to student registration information verification processing to obtain the student registration information verification result; and / or, Based on the student status webpage verification process, the user access website page feature information is determined from the identity recognition verification data, and the student status webpage verification process is performed based on the user access website page feature information to obtain the student status webpage verification result. And / or, Based on the real user verification process, the biometric information of the accessing user is determined from the identity recognition verification data, and real user verification is performed based on the user's biometric information to obtain the user identity verification result. Based on at least one of the student registration information verification results, the student registration webpage verification results, and the user identity verification results, a student identity authentication result is obtained for the user terminal.

6. The method according to claim 5, The process of verifying student status webpages based on the user's website access page feature information, to obtain the student status webpage verification result, includes: Obtain the trusted website page feature information stored for accessing the trusted student registration website, and perform page feature verification processing on the user access website page feature information and the trusted website page feature information to obtain the student registration webpage verification result; The process of verifying the real user based on the user's biometric information to obtain the user identity verification result includes: acquiring the student's facial image and the user's facial image from the user's biometric information, and performing facial matching on the student's facial image and the user's facial image to obtain the user identity verification result. The step of verifying the student status information of the user based on the website user's student status information to obtain a student status information verification result includes: determining historical verification records corresponding to the same student status user based on the website user's student status information; performing verification frequency detection based on the historical verification records to obtain a user verification frequency detection result; performing student status information consistency detection based on the historical verification records to obtain an information consistency detection result; obtaining a first student status information verification result based on the user verification frequency detection result and the information consistency detection result; and / or, using an official verification service to verify the student status identity information based on the website user's student status information to obtain a second student status information verification result; and / or, performing student graduation status detection based on the website user's student status information to obtain a third student status information verification result; obtaining student status code identification information based on the student status identification code in the website user's student status information; and performing a student status information consistency check on the website user's student status information and the student status code identification information to obtain a fourth student status information verification result.

7. The method according to claim 1, further comprising: Obtain the device environment information of the user terminal, perform device security risk detection based on the device environment information to obtain security risk detection results, and perform the step of collecting student website access data for the user terminal based on the security risk detection results; And / or, The status of the student status verification service of the trusted student status website service interface corresponding to the target application is detected. If the student status verification service status is an abnormal service status, the step of outputting the guidance information for accessing the trusted student status website to the user terminal is executed.

8. A user authentication device, the device comprising: The authentication request module is used to respond to the user's student identity authentication request for the target application and output the guidance access operation instructions for the trusted student registration website to the user. An operation monitoring module is used to monitor the user's access to the trusted student registration website based on the guided access operation instruction; The student authentication module is used to collect access data of the student registration website for the user terminal, determine the identity verification data for the user terminal based on the access data of the student registration website, perform student identity authentication on the user terminal based on the identity verification data, and obtain the student identity authentication result for the user terminal.

9. A computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the steps of the method as claimed in any one of claims 1 to 7.

10. A computer program product storing at least one instruction, said at least one instruction being loaded by a processor and executing the steps of the method as claimed in any one of claims 1 to 7.

11. An electronic device, comprising: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the steps of the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • An identity-enhanced authentication and authentication method and device

    CN109787988A

  • Method and device for determining resource access permission, equipment and medium

    CN110457932A