Identity authentication method and system, electronic equipment and computer program product
By introducing a two-factor authentication method of 'voice verification code + password' in the railway customer service system, using IP phones to generate and broadcast voice verification codes, combined with password verification, the problem of insufficient security of identity authentication in the existing technology is solved, and efficient and economical security reinforcement effect is achieved.
Patent Information
- Application Number
- CN202411933776.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-06
AI Technical Summary
The identity authentication method based on the 'image verification code + password' in the railway customer service system has security problems. The image verification code is easily bypassed or cracked, which increases the risk of 'bumping library' attacks. In addition, two-factor authentication methods such as 'sMS verification code + password' and 'face recognition + password' are not applicable to the railway customer service system due to cost and equipment configuration restrictions.
A two-factor authentication method based on 'voice verification code + password' is proposed. Voice verification code is generated and broadcasted through IP phones, and verification is carried out in combination with passwords. The redundant storage mechanism of Redis and MySQL databases is used to ensure data security.
It achieves a security reinforcement effect that significantly reduces costs, does not require additional configuration of software and hardware devices, does not need to pay SMS service costs, and can effectively prevent 'bumping library' attacks and improve the security of identity authentication.
Smart Images

Figure CN119945731A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of system security authentication, and in particular to an identity authentication method, system, electronic device and computer program product. Background Art
[0002] Identity authentication is the first line of defense for network security. Common identity authentication technologies include password authentication, smart card authentication, and biometric authentication. At present, the railway customer service system uses an identity authentication method based on "picture verification code + password" for customer service personnel, which has major security issues. The picture verification code can be easily bypassed or cracked, which greatly increases the possibility of the identity authentication system being attacked by "database collision". However, two-factor authentication methods such as "SMS verification code + password", "face recognition + password" and "fingerprint recognition + password" are not suitable for identity authentication in specific application scenarios such as railway customer service systems due to various factors such as cost. Summary of the invention
[0003] In view of this, the embodiments of the present application provide an identity authentication method, system, electronic device and computer program product to solve the above problems.
[0004] In a first aspect, an embodiment of the present application proposes a customer service system identity authentication method, the method comprising: displaying a first interface; the first interface comprising at least a first control for inputting a voice verification code and a second control for inputting identity information; in response to a voice verification code acquisition request issued by a user through an IP phone, generating a first voice verification code, and broadcasting the first voice verification code through the IP phone; comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result; when the first verification result indicates that the verification is passed, verifying the identity information input by the user to obtain a second verification result.
[0005] Compared with biometric authentication and the verification method of "SMS verification code + password", the two-factor method of voice verification code + password proposed in the embodiment of the present application does not require additional configuration of software and hardware equipment, nor does it require payment of SMS service costs. It can significantly reduce costs and achieve the same security reinforcement effect.
[0006] In one possible implementation, generating a first voice verification code includes: generating accompanying data, the accompanying data including a first extension number of the IP phone and a platform number to which the first extension number belongs; generating a verification code record based on the accompanying data; the verification code record includes the accompanying data and the first voice verification code.
[0007] In one possible implementation, generating accompanying data includes: obtaining a first extension number of an IP phone; identifying the first extension number as an extension number recorded in a legal extension number database; obtaining a first password entered by a user through the IP phone; and generating accompanying data when the first password is correct.
[0008] In one possible implementation, the first interface also includes a third control for entering an extension number; after generating a verification code record, the method also includes: storing the verification code record to Redis data; comparing the second voice verification code entered by the user with the first voice verification code, and before obtaining a first verification result, the method also includes: receiving a login request submitted by the user, the login request including the second voice verification code entered by the user and the second extension number; determining whether the second extension number exists in the Redis data when there is no abnormality in the Redis database; comparing the second voice verification code entered by the user with the first voice verification code to obtain a first verification result, including: when the second extension number exists in the Redis data, comparing the second voice verification code entered by the user with the first voice verification code, and if they are consistent, obtaining a first verification result indicating that the verification is passed.
[0009] In one possible implementation, the verification code record includes accompanying data and a first voice verification code and the generation time of the first voice verification code; after generating the verification code record, the method also includes: storing the verification code record in a MySQL database; comparing the second voice verification code input by the user with the first voice verification code, before obtaining the first verification result, the method also includes: in the case where the Redis database is abnormal or the second extension number does not exist in the Redis data, determining whether the second extension number exists in the MySQL database; if it exists, determining whether the difference between the submission time and the generation time of the login request is less than or equal to a predetermined threshold; comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result, including: in the case where the difference is less than or equal to the predetermined threshold, comparing the second voice verification code input by the user with the first voice verification code, and if they are consistent, obtaining a first verification result of verification passing.
[0010] In one possible implementation, before generating the first voice verification code, the method also includes: obtaining the user's work number and the platform number to which the work number belongs; obtaining the first extension number of the IP phone based on the query result of whether the platform number belongs to the first set; the first set is used to record the platform number that uses the voice verification code or to record the platform number that does not use the voice verification code; determining whether to use the voice verification code based on the query result of whether the first graded number belongs to the second set; the second set is used to record the extension number that uses the voice verification code or to record the extension number that does not use the voice verification code; generating the first voice verification code includes: generating the first voice verification code when it is determined that the voice verification code is used.
[0011] In one possible implementation, after obtaining the second verification result, the method further includes: generating an authorization token when the second verification result indicates that the verification is successful; displaying an interface for accessing the customer service system; and carrying the authorization token in an access request to the customer service system triggered by the interface.
[0012] In the second aspect, an embodiment of the present application also provides a customer service system identity authentication system, the system comprising: a first subsystem, used to display a first interface; the first interface comprises at least a first control for inputting a voice verification code and a second control for inputting identity information; a second subsystem, used to generate a first voice verification code in response to a voice verification code acquisition request issued by a user through an IP phone, and to broadcast the first voice verification code through the IP phone; the first subsystem is also used to compare the second voice verification code input by the user with the first voice verification code to obtain a first verification result; and, when the first verification result indicates that the verification is passed, verify the identity information input by the user to obtain a second verification result.
[0013] In a third aspect, an embodiment of the present application further provides an electronic device, the electronic device comprising: a processor, the processor being used to execute a computer program or instruction in a memory to implement a method as described in any one of the above-mentioned first aspects.
[0014] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored program, wherein when the program is executed by a processor, the method as described in any one of the above-mentioned first aspects is implemented.
[0015] In a fifth aspect, an embodiment of the present application further provides a computer program product, which includes a program. When the program is executed by an electronic device, the electronic device implements the method as described in any one of the above-mentioned first aspects.
[0016] In the sixth aspect, an embodiment of the present application also provides a chip system, comprising: a communication interface for inputting and / or outputting data; a processor for executing a computer executable program so that a device equipped with the chip system executes a method as described in any one of the above-mentioned first aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0018] Figure 1A schematic diagram of the structure of an electronic device provided in an embodiment of the present application; Figure 2 A flowchart of a customer service system identity authentication method provided in an embodiment of the present application; Figure 3 A schematic diagram of the first interface of the customer service system identity authentication method provided in an embodiment of the present application; Figure 4 A schematic diagram of the system architecture of the customer service system identity authentication method provided in an embodiment of the present application; Figure 5 A flowchart of the IVR voice verification code request process in the customer service system identity authentication method provided in an embodiment of the present application; Figure 6 A flowchart of the process of generating and storing a voice verification code in the customer service system identity authentication method provided in an embodiment of the present application; Figure 7 A schematic diagram of the broadcasting process of the voice verification code in the customer service system identity authentication method provided in the embodiment of the present application; Figure 8 A schematic diagram of the verification process of the voice verification code in the customer service system identity authentication method provided in the embodiment of the present application; Fig. 9 A schematic diagram of the control flow of using a voice verification code in the customer service system identity authentication method provided in an embodiment of the present application; Fig.10 A curve diagram of detailed data statistics of the amount of voice verification codes sent in the customer service system identity authentication method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to better understand the technical solution of the present application, the embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0020] It should be clear that the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.
[0021] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0022] It should be understood that the term "and / or" used in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0023] Before introducing the embodiments of the present application, the related technologies and their technical problems are first explained.
[0024] At present, the railway customer service system has security issues based on the "picture verification code + password" identity authentication method. On the one hand, with the advancement of image recognition technology, the picture verification code can be easily bypassed or cracked, which greatly increases the possibility of the identity authentication system being attacked by "database collision". On the other hand, the picture verification code can also be recognized by other people other than the railway customer service system, and due to the fixedness and long-term use of the password, it is easy for others to impersonate due to password leakage.
[0025] In response to the above problems, a solution is usually to use two-factor authentication methods such as "SMS verification code + password", "face recognition + password" and "fingerprint recognition + password" for security reinforcement. It is worth noting that the above methods require the participation of private devices (such as mobile phones) or physical devices that are specifically used to collect information (such as cameras, fingerprint collectors).
[0026] In order to prevent customer service agents from leaking passengers' personal privacy information through recording, taking photos, etc., the railway customer service center has implemented a "no mobile phone on site" management model, which means that customer service agents cannot use SMS verification codes through their mobile phones. Therefore, the "SMS verification code + password" authentication method is not suitable for railway customer service scenarios.
[0027] In addition, at the railway customer service center, the customer service seats are not equipped with cameras and fingerprint collectors. Purchasing cameras or fingerprint collectors and the corresponding identification systems will greatly increase the operating costs of the customer service center. Therefore, the two-factor authentication method based on "face recognition + password" and "fingerprint recognition + password" is not the best solution.
[0028] Although the two-factor authentication method of "voiceprint recognition + password" has been applied to banking, e-commerce and other fields. However, due to the fact that its timbre, frequency and other characteristics are easily affected by the physical health status (such as nasal sounds caused by colds) and emotional state of customer service agents, identity authentication is prone to misjudgment, which in turn causes the customer service agent to be unable to log in to the customer service system normally to work. Therefore, this method is not suitable for identity authentication in the railway customer service system.
[0029] As for the two-factor authentication method of "email verification code + password", since email is very vulnerable to phishing attacks, it will increase the security risk of the railway customer service system in the identity authentication process to a certain extent. Therefore, this method has certain limitations.
[0030] In order to solve the above problems, through in-depth research on the existing network and software and hardware environment of the railway customer service center, a two-factor authentication method based on "voice verification code + password" was proposed based on the railway customer service voice platform.
[0031] The method proposed in the embodiment of the present application can be applied to a railway customer service system or other application scenarios that require verification of the identity of members, for example, it can be applied to customer service systems of other categories such as banks and enterprises.
[0032] The method proposed in the embodiment of the present application can be applied to an electronic device. The electronic device can be, for example, a server. For example, Figure 1 FIG. 1 shows a schematic diagram of the server structure. Figure 1 As shown, the server 100 may include: one or more processors 110 , a communication interface 120 , a memory 130 , and a communication bus 140 connecting different components (including the memory 130 , the communication interface 120 and the processor 110 ).
[0033] The communication bus 140 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, or a local bus using any of a variety of bus structures. For example, the communication bus 140 may include, but is not limited to, an industry standard architecture (ISA) bus, a micro channel architecture (MCA) bus, an enhanced ISA bus, a video electronics standards association (VESA) local bus, and a peripheral component interconnection (PCI) bus.
[0034] Electronic devices typically include a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device, including volatile and non-volatile media, removable and non-removable media.
[0035] The memory 130 may include a computer system readable medium in the form of a volatile memory, such as a random access memory (RAM) and / or a cache memory. The memory 130 may include at least one program product having a set (e.g., at least one) of program modules, which are configured to execute the video summary generation method provided in the embodiment of the present application.
[0036] A program / utility having a set (at least one) of program modules may be stored in the memory 130, such program modules including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination thereof may include an implementation of a network environment. The program modules generally perform the functions and / or methods in the embodiments of the present application.
[0037] The processor 110 executes various functional applications and data processing by running the programs stored in the memory 130, such as implementing the video summary generation method provided in the embodiment of the present application.
[0038] It should be understood that Figure 3 The processor 110 in the server 100 shown may be a system on chip SOC, and the processor 110 may include a central processing unit (CPU), and may further include other types of processors, such as a graphics processing unit (GPU) and the like.
[0039] like Figure 2 As shown, the identity authentication method proposed in the embodiment of the present application may include the following process: S101: Displaying a first interface.
[0040] For example, the first interface displayed is as follows Figure 3 As shown. The first interface includes at least a first control I01 for inputting a voice verification code and a second control for inputting identity information. For example, the second control can be used to input one or more of a user ID, a role, an extension number, and a user password.
[0041] S102: In response to a voice verification code acquisition request sent by a user through an IP phone, a first voice verification code is generated, and the first voice verification code is broadcasted through the IP phone.
[0042] The user may issue a voice verification code acquisition request through an IP phone by dialing a number or issuing a voice command. For example, a fixed number on the phone is set as a shortcut key for obtaining a voice verification code, or the user may issue a voice command of "please broadcast the voice verification code".
[0043] The backend system, such as the IVR interactive voice response system and / or the voice verification code service system, generates a corresponding voice verification code in response to a request from a user via an IP phone, plays the code via the IP phone, and sends the correct voice verification code to the identity authentication system.
[0044] S103: Compare the second voice verification code input by the user with the first voice verification code to obtain a first verification result.
[0045] After the user hears the voice verification code broadcast by the IP phone, the user can enter the voice verification code (second voice verification code) in the input box of the first control I01 in the first interface.
[0046] The identity authentication system compares the voice verification code to be verified entered by the user with the correct voice verification code. If they are consistent, the verification is successful.
[0047] S104: When the first verification result indicates that the verification is successful, verify the identity information input by the user to obtain a second verification result.
[0048] If the voice verification code is passed, continue to verify other identity information, such as continuing to verify one or more of the user's work number, role, extension number, and user password.
[0049] The customer service system identity authentication method proposed in the embodiment of the present application is a two-factor authentication method. Figure 4 As shown, this authentication method can be based on Figure 4 Exemplarily, based on the system architecture, the method proposed in the embodiment of the present application may include the following process: S401: A user (e.g., a customer service agent) logs in to a unified customer service authentication system (e.g., a railway customer service unified authentication system) and enters Figure 3 The information in the first interface is shown.
[0050] S402: The user uses an IP phone to request a voice verification code through an IVR.
[0051] S403: The interactive voice response system (IVR) sends the extension number, platform number and other accompanying information of the user's phone to the voice verification code service system.
[0052] S404: The voice verification code service system randomly generates a digital verification code according to the accompanying information, and sends the digital verification code back to the IVR.
[0053] S405: The IVR retrieves the corresponding voice file from the local library in the order of the digital verification code from left to right, and broadcasts it to the customer service agent through the IP phone.
[0054] S406: After the user obtains the content of the voice verification code, the user inputs the voice verification code into a corresponding control in the first interface displayed by the unified identity authentication system.
[0055] S407: The unified identity authentication system transmits the extension number, verification code, and request time to the voice verification code service system.
[0056] S408: The voice verification code service system verifies the input voice verification code and returns the verification result.
[0057] S409: After receiving the verification code verification result, the unified identity authentication system authenticates the customer service agent's identity information and returns a Ticket to the customer service agent's browser client after the authentication is passed. The Ticket can be understood as an authorization token.
[0058] S401: The customer service agent client carries the ticket to access the railway customer service system.
[0059] S402: The railway customer service system calls the unified authentication system to verify the ticket.
[0060] S403: The unified authentication system transmits the information of the ticket verification to the railway customer service system. At this point, the railway customer service system has realized a complete two-factor authentication function.
[0061] A specific embodiment is listed below.
[0062] The identity authentication method provided in this embodiment can be applied to electronic devices, such as Figure 1 A server or other electronic device as shown.
[0063] Exemplarily, the method may include the following process: S501: In response to a user sending a request for obtaining a voice verification code, the IVR system generates and stores a voice verification code.
[0064] Depend on Figure 4 It can be seen that the IVR interactive voice response system is one of the core processes for building a two-factor authentication method based on "voice verification code + password". This embodiment will elaborate on the method for implementing the IVR interactive voice response system, which is mainly divided into the following two stages: the active request stage of the voice verification code and the broadcast stage.
[0065] IVR voice verification code request stage: Unlike mobile terminals such as cell phones, the IP phones of customer service agents are fixed to the customer service agent workstations. Since there are many on-site personnel at the railway customer service center, if a passive method of obtaining voice verification codes based on mobile terminal devices such as cell phones is adopted, and the IP phone is used to passively obtain the voice verification codes required by the unified authentication system, it is easy for others to impersonate customer service agents to occupy workstations and use verification codes. Therefore, the passive method of obtaining voice verification codes poses a security risk in railway customer service scenarios. In response to the above problems, this embodiment proposes a strategy for actively dialing to request voice verification codes: We can first build a phone number filtering mechanism to prevent external communication devices from actively dialing and occupying the railway customer service voice platform resources. Figure 5 As shown in the dotted box on the left: the incoming call number is compared with the extension number library to filter out the extension numbers that are not exclusive to customer service seats; if the incoming call number does not exist in the extension number library, it will be directly hung up.
[0066] Next, by building a customer service agent identity authentication mechanism, we simulated the power-on unlocking function before reading the SMS verification code to prevent others from impersonating customer service agents and using IP phones to request voice verification codes. Figure 5 As shown in the dotted box on the right: Based on the incoming call number, the password entered by the customer service agent is compared with the password database to determine whether the current extension number is used by the current customer service agent. At the same time, in order to avoid the customer service agent from accidentally entering the wrong password, three re-verification opportunities are set; if more than three times, the system will alarm and directly hang up.
[0067] After passing the above two authentication mechanisms, the extension number, platform number and other accompanying data contained in this IVR call will be transmitted to the voice verification code service system to obtain the voice verification code for identity verification in the unified authentication system.
[0068] For more information about the generation and storage process of voice verification codes, please refer to Figure 6 As shown: After the IVR system receives the request for obtaining the voice verification code from the user through the IP phone, in response to the request, the IVR system sends the data carrying the extension number, platform number and other information to the voice verification code service system.
[0069] The voice verification code service system receives the accompanying data transmitted from the IVR system, randomly generates an N-digit verification code, and records the generation time of the verification code.
[0070] The voice verification code service system combines the verification code, generation time, extension number, platform number and other information into a verification code record, and stores it in Redis and MySQL databases respectively to ensure the security and reliability of the data.
[0071] In order to prevent the verification code from being valid for a long time, a lifespan is set for the voice verification code in Redis, that is, once the voice verification code record exceeds the lifespan, it will be cleared by Redis. In MySQL, this is achieved by limiting the difference between the request access time and the verification code generation time.
[0072] Optionally, in this embodiment, in the MySQL database storage process, in order to prevent the meaningless accumulation and expansion of the verification code generation record, resulting in too long query time for the voice verification code during the verification process, resulting in a slow response of the voice verification code service system, this embodiment also designs an in-situ update strategy: after the verification code record of an extension number is generated, check whether there is an existing record based on the current extension number. If the record does not exist, add a new verification code record to the data table; if the record already exists, update the verification code, generation time and other information, so as to achieve the purpose of limiting the unlimited growth of verification code data records. The extension number can be used as an index field for querying the voice verification code.
[0073] S502: broadcasting a voice verification code via a fixed IP phone.
[0074] The broadcast process of IVR voice verification code is as follows Figure 7 As shown, the IVR splits the obtained N-digit verification code N times in order from left to right, and only splits out one digit (denoted as X) each time, and retrieves the corresponding "noteX" voice file from the 0-9 digital voice file library for digital broadcasting.
[0075] Taking the digital verification code 8856 as an example, the voice broadcast process of each verification code number is as follows: Figure 5 As shown in the dashed box on the right: First, the verification code 8856 is split into 8 and 856, of which 856 is used for the next round of splitting; then, the corresponding "note8" voice file (audio content is the number 8) is searched from the 0-9 voice file library with the split number 8 as the index. Finally, note8 is loaded into the IVR answering system and the number is broadcast to the customer service seat. After the broadcast is completed, the next round of split broadcasting will begin, and so on until the remaining numbers are empty, and the broadcasting process ends.
[0076] It should be noted that if the digital broadcast is performed according to the above process, the playback speed of the entire verification code will be too fast, making it impossible for the customer service agent to accurately identify the specific digital content of the audio. Therefore, this embodiment also improves the playback speed of the IVR: by setting a 1-second time interval between each digital voice file, the playback speed of the IVR is adjusted to the speaking level of a normal person, so that the verification code can be accurately recognized by the customer service agent.
[0077] S503: Verify the voice verification code.
[0078] The voice verification code service system is another core process of the entire "voice verification code + password" two-factor authentication method. The verification of the voice verification code will be explained below.
[0079] After hearing the voice verification code broadcast by the IP phone, the user enters the voice verification code into Figure 3 In the input box of the first control I01 shown in the figure, after the user clicks to log in, the voice verification code input by the user is submitted to the unified identity authentication system.
[0080] like Figure 8 As shown, the verification process of the voice verification code is divided into two verification methods: one is the verification code verification based on Redis, and the other is the verification code verification based on the MySQL database.
[0081] Among them, Redis, as a data storage system at the memory level, can provide faster verification code search speed compared to MySQL database. Therefore, in order to improve the response performance of the voice verification code service system, Redis is selected as the main MySQL as the auxiliary method for verification of verification codes. That is, if the working status of Redis is abnormal, MySQL will be selected for verification.
[0082] The verification code verification process based on Redis is as follows Figure 8 As shown in the dashed box on the left: First, the obtained Figure 3 The extension number entered in the first interface shown is compared with the extension number stored in Redis to determine whether the currently obtained extension number already exists.
[0083] If the extension number already exists, it will be added from Figure 3 The voice verification code obtained in the verification code is compared with the verification code stored in Redis to determine whether the verification code currently obtained is consistent with the verification code stored in Redis. If the two verification codes are the same, the verification is passed; if the two verification codes are different, the verification fails. Finally, the verification code verification result is returned to the railway customer service unified authentication system.
[0084] It should be noted that there are two situations that will cause the currently obtained extension number to not be retrieved in Redis, making the verification code verification method based on Redis impossible to execute. One situation is that the time interval from the customer service agent receiving the voice verification code to submitting the voice verification code for verification is too long, exceeding the lifetime set by Redis, and is cleared by Redis. Therefore, the corresponding record of the obtained extension number cannot be retrieved in Redis.
[0085] Another situation is Figure 8 During the verification code generation and storage process shown, due to a Redis failure, the generated verification code and extension number and other information could not be stored in Redis, and then Redis was repaired and restarted.
[0086] In view of the above two problems existing in the Redis-based verification, in order to ensure the stable operation of the unified authentication system, in this embodiment, a verification method based on MySQL is adopted to solve them.
[0087] The verification code verification process based on MySQL is as follows Figure 8 As shown in the dotted box on the right: First, retrieve the extension number record in the MySQL database. If the extension number exists, then calculate the difference between the obtained request time and the verification code generation time in the record where the current extension number is located. If the difference is greater than the preset time limit, the verification will be returned as unsuccessful, and a prompt will be given that "the verification code has expired, please obtain the verification code again." If the difference is less than the time limit, then the verification code will be verified. Finally, the verification code verification result is returned to the railway customer service unified authentication system. The preset time limit can be 1-5 minutes, for example Figure 8 The duration is 3 minutes.
[0088] In this embodiment, after the voice verification code is verified, other identity information, such as work number, extension number, user password, etc., is verified. Alternatively, in other embodiments, the voice verification code and other identity information may be verified together.
[0089] It should be noted that whether the above voice verification code function is enabled is controllable. Fig. 9 As shown, taking the railway customer service system application scenario as an example, the IVR interactive response system can be built on multiple railway customer service voice platforms that are interconnected based on an internal LAN.
[0090] Because the local area network sometimes has network jitter due to line adjustment, equipment failure and other factors. Considering that network jitter will affect the entire customer service system, it will be impossible to obtain the voice verification code through the IVR, and then the customer service system will not be able to operate normally. Therefore, for the use of voice verification codes, this embodiment proposes a global control module in the unified authentication system. Specifically, for example, Fig. 9 The dashed box on the left shows: First, by obtaining Figure 3 The user ID shown is used to retrieve the platform number. For example, the platform can be the platform number to which each customer service center belongs.
[0091] Then, it is determined whether the current platform belongs to the first set Set1 of platform numbers that do not use voice verification codes. If the platform number does not belong to Set1, the extension number is checked; if the platform number belongs to Set1, the voice verification code function of the entire customer service center is disabled. That is, by adding and deleting platform numbers in Set1, the use of voice verification codes can be controlled at the master control level.
[0092] In addition, since the two-factor authentication method proposed in the embodiment of the present application is more complicated, its function needs to be fully verified before it is more comprehensively promoted and used.
[0093] Therefore, this embodiment also proposes a method for controlling the use of a voice verification code, such as Figure 8 As shown in the dashed box on the right: First, obtain the extension number entered by the customer service agent. Then, determine whether the obtained extension number belongs to the extension number set Set2 that does not use verification codes. If the extension number does not belong to Set2, the railway customer service unified authentication system is granted the right to use voice verification codes; if the extension number belongs to Set2, the system is prohibited from using voice verification codes. That is, by adding and deleting extension numbers in Set2, the extension number is used as the smallest unit of management and control to achieve control over the use of voice verification codes.
[0094] In other words, before the voice verification code is promoted and used, this control method is used to realize the parallel operation of the single-factor authentication of the original unified authentication system and the method proposed in this embodiment within each railway customer service center: keep the original "picture verification code + password" identity authentication method unchanged, and first switch a small number of customer service seats to the "voice verification code + password" two-factor authentication; after a period of parallel verification, gradually release the number of customer service seats using voice verification codes, so as to achieve a smooth transition to the upgrade of the unified authentication system.
[0095] The above is only an exemplary description. Other and more implementation modes can be obtained based on the above exemplary description, which are not listed one by one in this specification.
[0096] Since the cost information of two-factor authentication technology based on biometrics (face, fingerprint, etc.) is difficult to obtain, this embodiment only takes the two-factor authentication method based on "SMS verification + password" as a reference object, and compares it with the proposed method at the technical effect level to further demonstrate the advantages of the method proposed in this embodiment in the application scenario of "no mobile phone on site".
[0097] At present, the two-factor authentication method based on "voice verification code + password" has completed trial operation verification in multiple customer service centers and has been fully promoted. This embodiment randomly selected the voice verification code sending volume for two consecutive weeks (a total of 14 days) during the non-holiday railway ticket sales peak period. The details are as follows: Fig.10 shown.
[0098] Depend on Fig.10 It can be seen that the number of voice verification codes sent each week has a certain periodic stability: the highest number of sending is on Friday and Sunday, the lowest number is on Tuesday and Wednesday, the number of sending is not much different between Monday and Thursday, and the number of sending on Saturday is basically between Wednesday and Thursday. The number of voice verification codes sent shows that the railway department has dynamically adjusted the number of customer service seats working every day, and it also indirectly reflects the current situation of railway passenger travel: more people travel on Friday and Sunday, and fewer at other times.
[0099] In addition, by Fig.10 It can be seen that the average number of voice verification codes sent per day is about 7,100. If the same number of verification codes are sent via SMS, without considering the hardware procurement costs for deploying SMS servers and the labor costs of operation and maintenance personnel, and only considering the cost of sending verification codes, the railway customer service center will need to bear additional high SMS service costs every year. And the SMS service costs are accumulated one by one and will be incurred every year.
[0100] The voice verification code method proposed in this embodiment is to share the existing railway customer service voice platform resources, which does not require additional configuration of software and hardware equipment, nor does it require payment of SMS service costs. Obviously, compared with the two-factor authentication method of "SMS verification code + password", the proposed method can not only achieve the same security reinforcement effect, but also has better application benefits and can significantly reduce costs.
[0101] In summary, the technical solution proposed in the embodiment of the present application realizes the generation, storage and verification of verification codes by constructing a voice verification code service system. In order to ensure the security and reliability of data, a Redis and MySQL redundant storage method is proposed; in order to improve the response speed of the system, two optimization strategies are proposed: MySQL in-place update and Redis priority access strategy.
[0102] In addition, an IVR interactive response system was built to enable customer service agents to actively request and obtain voice verification codes. In order to avoid external communication equipment from preempting platform resources, a phone number filtering mechanism was proposed; at the same time, in order to ensure the legitimacy of the identity of the customer service agent requesting the voice verification code, a customer service agent identity authentication mechanism was proposed. In addition, in order to ensure that the customer service agent can accurately listen to the content of the voice verification code, the IVR playback speed was optimized.
[0103] Furthermore, a voice verification code usage management system was built to control the authority of customer service agents to use voice verification codes, ensuring the normal operation of the customer service center when network jitter causes customer service agents to be unable to receive voice verification codes through IVR.
[0104] An embodiment of the present application further provides an electronic device, the electronic device comprising: a processor, the processor being used to execute a computer program or instruction in a memory to implement a method as described in any of the above embodiments.
[0105] The electronic device involved in the present application may be one or more of the following devices: a smart phone, a portable computer (Tablet Personal Computer, Tablet PC), a laptop computer (laptop), a desktop computer (Desktop computer), a wearable device, an extended reality (extended reality, XR) device such as augmented reality (AR), virtual reality (VR), mixed reality (MR), an ultra-mobile personal computer (UMPC), a netbook or a personal digital assistant (PDA), etc. The embodiments of the present application do not impose any special restrictions on the specific type of the electronic device.
[0106] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in this application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk SolidState Disk), etc.
[0107] In the embodiments of the present application, "at least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0108] The above are only preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A customer service system identity authentication method, characterized in that: The method comprises: Display a first interface; the first interface includes at least a first control for inputting a voice verification code and a second control for inputting identity information; In response to a voice verification code acquisition request sent by a user through an IP phone, a first voice verification code is generated, and the first voice verification code is broadcasted through the IP phone; Comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result; When the first verification result indicates that the verification is passed, the identity information input by the user is verified to obtain a second verification result.
2. The method according to claim 1, characterized in that Generate the first voice verification code, including: Generate associated data, the associated data including the first extension number of the IP phone and the platform number to which the first extension number belongs; A verification code record is generated according to the accompanying data; the verification code record includes the accompanying data and the first voice verification code.
3. The method according to claim 2, characterized in that Generate road data, including: Obtaining the first extension number of the IP phone; Identify the first extension number as an extension number recorded in a legal extension number database; Obtain the first password entered by the user through the IP phone; When the first password is correct, the accompanying data is generated.
4. The method according to claim 2 or 3, characterized in that: The first interface also includes a third control for inputting an extension number; After generating the verification code record, the method further includes: Storing the verification code record in Redis data; Before comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result, the method further includes: Receiving a login request submitted by a user, wherein the login request includes a second voice verification code and a second extension number input by the user; When it is determined that there is no abnormality in the Redis database, determining whether the second extension number exists in the Redis database; Comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result, including: When the second extension number exists in the Redis data, the second voice verification code input by the user is compared with the first voice verification code, and if they are consistent, a first verification result indicating that the verification is passed is obtained.
5. The method according to claim 4, characterized in that The verification code record includes the accompanying data, the first voice verification code, and the generation time of the first voice verification code; After generating the verification code record, the method further includes: Storing the verification code record in the MySQL database; Before comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result, the method further includes: When the Redis database is abnormal or the second extension number does not exist in the Redis data, determine whether the second extension number exists in the MySQL database; If it exists, determining whether the difference between the submission time of the login request and the generation time is less than or equal to a predetermined threshold; Comparing the second voice verification code input by the user with the first voice verification code to obtain a first verification result, including: When the difference is less than or equal to a predetermined threshold, the second voice verification code input by the user is compared with the first voice verification code, and if they are consistent, a first verification result of verification passing is obtained.
6. The method according to claim 1, characterized in that Before generating the first voice verification code, the method further includes: Obtain the work number of the user and the platform number to which the work number belongs; According to the query result of whether the platform number belongs to the first set, obtaining the first extension number of the IP phone; the first set is used to record the platform number using the voice verification code or the platform number not using the voice verification code; Determine whether to use a voice verification code according to a query result of whether the first hierarchical number belongs to a second set; the second set is used to record extension numbers that use voice verification codes or to record extension numbers that do not use voice verification codes; Generate the first voice verification code, including: When it is determined to use the voice verification code, a first voice verification code is generated.
7. The method according to claim 1, characterized in that After obtaining the second verification result, the method further includes: If the second verification result indicates that the verification is passed, generating an authorization token; An interface for accessing a customer service system is displayed; and an access request to the customer service system triggered based on the interface carries the authorization token.
8. The customer service system identity authentication system is characterized by: The system comprises: A first subsystem is used to display a first interface; the first interface at least includes a first control for inputting a voice verification code and a second control for inputting identity information; The second subsystem is used to generate a first voice verification code in response to a voice verification code acquisition request issued by a user through an IP phone, and broadcast the first voice verification code through the IP phone; The first subsystem is further used to compare the second voice verification code input by the user with the first voice verification code to obtain a first verification result; and, when the first verification result indicates that the verification is passed, verify the identity information input by the user to obtain a second verification result.
9. An electronic device, characterized in that: The electronic device comprises: A processor, wherein the processor is configured to execute a computer program or instruction in a memory to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium comprises a stored program, wherein the program implements the method according to any one of claims 1 to 7 when executed by a processor.
11. A computer program product, characterized in that The computer program product comprises a program, and when the program is executed by an electronic device, the electronic device implements the method according to any one of claims 1 to 7.