Identity authentication method and device

By using routing policies adjusted by routing rules base and prediction model in the identity authentication system, the appropriate authentication server is dynamically selected, which solves the problems of latency and authentication abnormalities caused by excessive load, and improves the stability of the business system.

CN119946148APending Publication Date: 2025-05-06KE COM (BEIJING) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411854723.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

When performing identity authentication, how to select a suitable authentication server to avoid delays and authentication exceptions caused by excessive load, thereby improving the stability of the business system.

Method used

By receiving an authentication request sent by the terminal device, it is determined whether the request hits the routing rules in the routing rule library preconfigured by the user. If hit, the authentication server is assigned based on the rule; if missed, the routing policy is adjusted based on the traffic information of the current moment output by the prediction model to assign the authentication server.

Benefits of technology

It realizes that when the user specifies or does not specify an authentication server, the appropriate authentication server is dynamically selected, thereby improving the stability of the business system and the processing efficiency of authentication requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946148A_ABST
    Figure CN119946148A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an identity authentication method and device. The method comprises the following steps: receiving an authentication request sent by terminal equipment; determining whether the authentication request hits a routing rule in a routing rule base, wherein the routing rule base comprises at least one routing rule pre-configured by a user; if the authentication request hits the routing rule in the routing rule base, distributing the authentication request to a corresponding authentication server based on the routing rule hit by the authentication request; if the authentication request does not hit the routing rule in the rule base, allocating an authentication server to the authentication request based on a routing policy; the routing strategy is obtained by adjusting an original routing strategy based on the flow information of the current moment output by the prediction model. The method is used for selecting a proper authentication server so as to improve the stability of a service system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to an identity authentication method and device. Background Art

[0002] Real-name authentication is a common and important identity authentication method in modern society. Its core purpose is to ensure the authenticity of the user's identity and prevent illegal activities such as online fraud and false registration. With the accelerated development of digitalization, real-name authentication has become a key link in maintaining network security and social order.

[0003] There are many authentication servers. When performing identity authentication, one can be selected from these multiple authentication servers for identity authentication. However, the loads of different authentication servers are different. If identity authentication is performed through an authentication server with a higher load, there is a high probability that there will be excessive delays or even authentication anomalies, which will affect the stability of the business system. Therefore, how to select a suitable authentication server to improve the stability of the business system is an urgent problem to be solved. Summary of the invention

[0004] In view of this, an embodiment of the present application provides an identity authentication method and device for selecting a suitable authentication server to improve the stability of a business system.

[0005] In order to achieve the above purpose, the embodiments of the present application provide the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides an identity authentication method, including:

[0007] Receiving an authentication request sent by a terminal device;

[0008] Determining whether the authentication request hits a routing rule in a routing rule library, wherein the routing rule library includes at least one routing rule preconfigured by a user;

[0009] If the authentication request hits a routing rule in the routing rule library, the authentication request is assigned to a corresponding authentication server based on the routing rule hit by the authentication request;

[0010] If the authentication request does not hit the routing rule in the rule base, an authentication server is assigned to the authentication request based on a routing policy; the routing policy is obtained by adjusting the original routing policy based on the current traffic information output by the prediction model.

[0011] As an optional implementation of the embodiment of the present application, the determining whether the authentication request hits a routing rule preconfigured by the user includes at least one of the following:

[0012] Determining whether the user type corresponding to the authentication request matches a routing rule based on user type in the routing rule library;

[0013] Determining whether the authentication method corresponding to the authentication request matches the routing rule based on the authentication method in the routing rule library;

[0014] Determine whether the service type corresponding to the authentication request matches a routing rule based on the service type in the routing rule library.

[0015] As an optional implementation of the embodiment of the present application, allocating an authentication server to the authentication request based on a routing policy includes:

[0016] Performing a hash calculation on the identification code of the authentication request to obtain a hash value corresponding to the authentication request;

[0017] Performing a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value;

[0018] Determine the authentication server corresponding to the module value according to the module value and the target mapping relationship, wherein the target mapping relationship includes the mapping relationship between each module value of the preset value and the corresponding task service;

[0019] The authentication request is distributed to an authentication server corresponding to the module value.

[0020] As an optional implementation of the embodiment of the present application, performing a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value includes:

[0021] Perform a modulus operation on the hash value based on N*M to obtain a modulus value corresponding to the hash value;

[0022] Wherein, N is the total number of authentication servers, and M is a positive integer.

[0023] As an optional implementation of the embodiment of the present application, the traffic information at the current moment output by the prediction model includes: the total traffic at the current moment and the traffic of each authentication server at the current moment;

[0024] Adjust the original routing strategy based on the current traffic information output by the prediction model, including:

[0025] The initial mapping relationship is adjusted based on the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment to obtain the target mapping relationship.

[0026] As an optional implementation of the embodiment of the present application, the method further includes:

[0027] Monitor the status of each authentication server;

[0028] When it is monitored that the state of the first authentication server is abnormal, the routing rule and / or the routing policy is adjusted to prohibit the authentication request from being assigned to the first authentication server.

[0029] As an optional implementation of the embodiment of the present application, the method further includes:

[0030] When it is detected that the state of the first authentication server is abnormal, determining an authentication request to be retried; the authentication request to be retried is an authentication request that has been assigned to the first authentication server and has not completed authentication;

[0031] An authentication server is allocated to the authentication request to be retried based on the adjusted routing rule and / or the routing policy.

[0032] In a second aspect, an embodiment of the present application provides an identity authentication device, including:

[0033] A communication unit, used for receiving an authentication request sent by a terminal device;

[0034] A matching unit, configured to determine whether the authentication request matches a routing rule in a routing rule library, wherein the routing rule library includes at least one routing rule preconfigured by a user;

[0035] a processing unit, configured to, when the authentication request hits a routing rule in the routing rule library, distribute the authentication request to a corresponding authentication server based on the routing rule hit by the authentication request;

[0036] The processing unit is used to allocate an authentication server to the authentication request based on a routing policy when the authentication request does not hit the routing rule in the rule base; the routing policy is obtained by adjusting the original routing policy based on the traffic information at the current moment output by the prediction model.

[0037] As an optional implementation of the embodiment of the present application, the matching unit is specifically configured to perform at least one of the following:

[0038] Determining whether the user type corresponding to the authentication request matches a routing rule based on user type in the routing rule library;

[0039] Determining whether the authentication method corresponding to the authentication request matches the routing rule based on the authentication method in the routing rule library;

[0040] Determine whether the service type corresponding to the authentication request matches a routing rule based on the service type in the routing rule library.

[0041] As an optional implementation of the embodiment of the present application, the processing unit is specifically used to perform a hash calculation on the identification code of the authentication request to obtain a hash value corresponding to the authentication request; perform a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value; determine the authentication server corresponding to the modulus value based on the modulus value and the target mapping relationship, the target mapping relationship including a mapping relationship between each modulus value of the preset value and the corresponding task service; and assign the authentication request to the authentication server corresponding to the modulus value.

[0042] As an optional implementation of the embodiment of the present application, the processing unit is specifically configured to perform a modulus operation on the hash value based on N*M to obtain a modulus value corresponding to the hash value;

[0043] Wherein, N is the total number of authentication servers, and M is a positive integer.

[0044] As an optional implementation of the embodiment of the present application, the traffic information at the current moment output by the prediction model includes: the total traffic at the current moment and the traffic of each authentication server at the current moment;

[0045] The processing unit is further used to adjust the initial mapping relationship based on the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment to obtain the target mapping relationship.

[0046] As an optional implementation of the embodiment of the present application, the processing unit is also used to monitor the status of each authentication server; when the status of the first authentication server is detected to be abnormal, the routing rules and / or the routing policy are adjusted to prohibit the authentication request from being allocated to the first authentication server.

[0047] As an optional implementation of the embodiment of the present application, the processing unit is also used to determine an authentication request to be retried when an abnormal state of the first authentication server is monitored; the authentication request to be retried is an authentication request that has been assigned to the first authentication server and has not completed authentication; and an authentication server is assigned to the authentication request to be retried based on the adjusted routing rules and / or the routing policy.

[0048] In a third aspect, an embodiment of the present application provides an identity authentication device, including: a memory and a processor, wherein the memory is used to store a computer program and the processor is used to enable the identity authentication device to implement the identity authentication method described in any of the above embodiments when executing the computer program.

[0049] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which, when the computer program is executed by a computing device, enables the computing device to implement any of the above-mentioned identity authentication methods.

[0050] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a computer, enables the computer to implement any of the above-mentioned identity authentication methods.

[0051] The identity authentication method provided in the embodiment of the present application, when receiving an authentication request sent by a terminal device, first determines whether the authentication request hits the routing rules in the routing rule library, and in the case where the authentication request hits the routing rules in the routing rule library, the authentication request is assigned to the corresponding authentication server based on the routing rules hit by the authentication request, and in the case where the authentication request does not hit the routing rules in the rule library, the authentication server is assigned to the authentication request based on the routing policy. Since the routing rule library includes at least one user-preconfigured routing rule, and the routing policy is obtained by adjusting the original routing policy based on the current traffic information output by the prediction model, the embodiment of the present application can assign the authentication request to the authentication server specified by the user when the user specifies the authentication server through the routing rule, and assign the authentication server to the authentication request based on the current traffic information when the user does not specify the authentication server, so the embodiment of the present application can select a suitable authentication server to improve the stability of the business system. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings required in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0054] Figure 1 A schematic diagram of the structure of the business system provided in the embodiment of the present application;

[0055] Figure 2 One of the flow charts of the identity authentication method provided in the embodiment of the present application;

[0056] Figure 3 The second step flow chart of the identity authentication method provided in the embodiment of the present application;

[0057] Figure 4 A schematic diagram of the structure of an identity authentication device provided in an embodiment of the present application;

[0058] Figure 5A schematic diagram of the hardware structure of the identity authentication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0059] In order to more clearly understand the above-mentioned purposes, features and advantages of the present application, the scheme of the present application will be further described below. It should be noted that the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.

[0060] In the following description, many specific details are set forth to facilitate a full understanding of the present application, but the present application may also be implemented in other ways different from those described herein. Obviously, the embodiments in the specification are only part of the embodiments of the present application, rather than all of the embodiments.

[0061] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way. In addition, in the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" refers to two or more.

[0062] The following first describes the business system provided by the embodiment of the present application. Figure 1 As shown, the business system provided by the embodiment of the present application includes:

[0063] Terminal device 11 , service server 12 , and multiple authentication servers 13 . Figure 1 In the figure, a business system including three authentication servers 13 is taken as an example.

[0064] The terminal device 11 can perform business interactions with the user, and send an authentication request to the business server 12 when the user needs to be authenticated. The authentication information carried in the authentication request may be different based on different authentication methods. For example: when the authentication method is to match the name and ID number, the authentication request may carry the name and identity information entered by the user. Another example: when the authentication method is a mobile phone number, the authentication request may carry the mobile phone number entered by the user and a verification code. The terminal device 11 can be a mobile phone, a tablet computer, a personal computer (PC), a workstation, etc., which is not limited in the embodiments of the present application. Figure 1 In the figure, the terminal device 11 is taken as an example of a mobile phone.

[0065] The business server 12 is used to carry and run business applications and related services, such as providing business logic processing, storing and managing business data, and implementing user authentication and authorization. The business server 12 can save the user's pre-configured routing rules and the routing strategy obtained based on the predicted current traffic information. When the business server receives the authentication request sent by the terminal device 11, it first determines whether the business request hits the user's pre-configured routing rules. If so, the business request is assigned to the corresponding authentication server 13 based on the routing rules. If not, the authentication server is assigned to the authentication request based on the routing strategy. The business server 12 is also used to forward the authentication request to the assigned authentication server so that the authentication server performs identity authentication, and sends the authentication result to the business server 12. The business server 12 can also perform subsequent business processing based on the authentication result. For example: sending the authentication result to the terminal device 11, when the authentication result is passed, authorizing the user to perform related business operations, when the authentication result is not passed, prohibiting the user from performing related business operations, etc.

[0066] The authentication server 13 stores relevant information for authentication. For example, the authentication server may include the user's ID number, passport number, mobile phone number, etc. When the authentication server 13 receives the authentication request sent by the business server 12, it can perform identity authentication based on the identity information carried in the authentication request and return the authentication result to the business server 12.

[0067] The embodiment of the present application provides an identity authentication method, and the execution subject of the identity authentication method can be a business server in the above business system. Figure 2 As shown, the identity authentication method includes the following steps:

[0068] S21. Receive an authentication request sent by a terminal device.

[0069] In some embodiments, the authentication request sent by the terminal device is an identity authentication request. For example: a real-name authentication request. When the authentication request sent by the terminal device is a real-name authentication request based on identity card information, the authentication request may carry the user's name and identity card number. When the authentication request sent by the terminal device is a real-name authentication request based on bank card information, the authentication request may carry the bank card number, the name of the bank where the account is opened, the type of bank card, the name of the cardholder, the reserved mobile phone number, the verification code, etc. When the authentication request sent by the terminal device is a real-name authentication based on a mobile phone number, the authentication request may carry information such as the mobile phone number, the verification code, and the user's name.

[0070] S22: Determine whether the authentication request matches a routing rule in a routing rule library.

[0071] The routing rule base includes at least one routing rule preconfigured by a user.

[0072] In some embodiments, routing rules may include routing rules based on user type. Routing rules based on user type refer to routing rules that determine the authentication server according to the different categories to which users belong. When routing rules include routing rules based on user type, determining whether the authentication request hits the routing rules in the routing rule library includes: determining whether the user type corresponding to the authentication request matches the routing rules based on user type in the routing rule library. For example: the routing rules in the routing rule library include: authenticating a user of type A through authentication server 1, then determining whether the user type corresponding to the authentication request is type A, if so, determining that the routing rule is hit, if not, determining that the routing rule is not hit.

[0073] In some embodiments, the routing rules may include: routing rules based on the authentication method. Routing rules based on user type refer to routing rules that determine the authentication server according to the authentication method. When the routing rules include routing rules based on the authentication method, determining whether the authentication request hits the routing rules in the routing rule library includes: determining whether the authentication method corresponding to the authentication request matches the routing rules based on the authentication method in the routing rule library. For example: the routing rules in the routing rule library include: if the authentication method is based on the identity card, then authentication is performed through the authentication server 2, then it is determined whether the authentication method corresponding to the authentication request is based on the identity card, if so, it is determined that the routing rule is hit, if not, it is determined that the routing rule is not hit.

[0074] In some embodiments, routing rules may include: routing rules based on business type. Routing rules based on user type refer to routing rules that determine the authentication server based on business type. When routing rules include routing rules based on business type, determining whether the authentication request hits the routing rules in the routing rule library includes: determining whether the business type corresponding to the authentication request matches the routing rules based on business type in the routing rule library. For example: the routing rules in the routing rule library include: if the business type is a contracted business, authentication is performed through the authentication server 3, then it is determined whether the business type corresponding to the authentication request is a contracted business, if so, it is determined that the routing rule is hit, if not, it is determined that the routing rule is not hit.

[0075] In the above step S22, if the authentication request hits the routing rule in the routing rule library, the following step S23 is executed:

[0076] S23: Allocate the authentication request to a corresponding authentication server based on the routing rule hit by the authentication request.

[0077] In the embodiment of the present application, allocating the authentication request to the corresponding authentication server means sending the authentication request to the corresponding authentication server so that the corresponding authentication server obtains the authentication result corresponding to the authentication request.

[0078] In some cases, the authentication request may not hit any routing rule in the routing rule base. For example, any routing rule in the rule base includes:

[0079] Routing rule 1: Authentication server 1 authenticates the authentication request of type A user;

[0080] Routing rule 2: Authenticate the authentication request based on the ID card through authentication server 2;

[0081] Routing rule 3: Authentication request 3 of the contracted service is authenticated by authentication server 3;

[0082] When the user type corresponding to the authentication request is B, the corresponding authentication method is authentication based on mobile phone number, and the business type is payment, no routing rule in the routing rule library is hit.

[0083] In the above step S22, if the authentication request matches the routing rule in the routing rule library, the following step S24 is executed:

[0084] S24. Allocate an authentication server for the authentication request based on a routing policy.

[0085] The routing strategy is obtained by adjusting the original routing strategy based on the current traffic information output by the prediction model.

[0086] That is, before allocating the authentication server for the authentication request based on the routing policy, the method further includes the following steps a to c:

[0087] Step a: Collect historical data.

[0088] Historical data can cover network traffic conditions in different time periods and business scenarios. Using machine learning algorithms, predictive models can identify potential patterns and trends in the data, such as peak traffic hours and traffic characteristics in specific business scenarios.

[0089] Step b: Build a prediction model based on historical data.

[0090] Building a prediction model based on historical data includes: extracting features for prediction from historical data, selecting features based on their relevance and importance, and removing redundant or irrelevant features to improve model performance.

[0091] Based on historical data, the artificial intelligence module will build a prediction model to predict traffic trends in the future. These prediction results not only include changes in the total amount of traffic, but also cover the distribution characteristics of traffic, such as the proportion of traffic in different business scenarios, traffic fluctuations in different time periods, etc.

[0092] In some embodiments, after the prediction model is constructed based on historical data, the constructed prediction model can be trained and optimized.

[0093] Step c: Obtain the current traffic information based on the prediction model.

[0094] In some embodiments, the traffic information at the current moment includes: the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment.

[0095] Step d: adjusting the original routing strategy based on the current traffic information to obtain the routing strategy.

[0096] After obtaining the traffic information, the routing strategy of data calls can be dynamically adjusted according to the traffic information, so as to preferentially distribute authentication requests to authentication servers with lower loads and faster responses, so as to avoid delays and congestion caused by overload of a single channel.

[0097] The identity authentication method provided in the embodiment of the present application, when receiving an authentication request sent by a terminal device, first determines whether the authentication request hits the routing rules in the routing rule library, and in the case where the authentication request hits the routing rules in the routing rule library, the authentication request is assigned to the corresponding authentication server based on the routing rules hit by the authentication request, and in the case where the authentication request does not hit the routing rules in the rule library, the authentication server is assigned to the authentication request based on the routing policy. Since the routing rule library includes at least one user-preconfigured routing rule, and the routing policy is obtained by adjusting the original routing policy based on the current traffic information output by the prediction model, the embodiment of the present application can assign the authentication request to the authentication server specified by the user when the user specifies the authentication server through the routing rule, and assign the authentication server to the authentication request based on the current traffic information when the user does not specify the authentication server, so the embodiment of the present application can select a suitable authentication server to improve the stability of the business system.

[0098] As an extension and refinement of the above embodiment, the present application embodiment also provides another identity authentication method, referring to Figure 3 As shown, the identity authentication method includes the following steps:

[0099] S301: Receive an authentication request sent by a terminal device.

[0100] S302: Determine whether the authentication request matches a routing rule in a routing rule library.

[0101] The routing rule base includes at least one routing rule preconfigured by a user.

[0102] In the above step S302, if the authentication request matches the routing rule in the routing rule library, the following step S303 is executed:

[0103] S303: Allocate the authentication request to a corresponding authentication server based on the routing rule hit by the authentication request.

[0104] In the above step S302, if the authentication request does not match the routing rule in the routing rule library, the following step S304 is executed:

[0105] S304: Perform a hash calculation on the identification code of the authentication request to obtain a hash value corresponding to the authentication request.

[0106] In some embodiments, the identification code of the authentication request may be a serial number of the authentication request. For example, the identification code of the authentication request may be: 202412020001.

[0107] In some embodiments, performing hash calculation on the identification code of the authentication request includes: performing hash calculation on the identification code of the authentication request based on MD5 (Message-Digest Algorithm 5).

[0108] S305: Perform a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value.

[0109] Modulo operation is also called remainder operation. It is a mathematical operation usually represented by "%". For two integers a and b (b≠0), a%b represents the remainder after a is divided by b. For example: because the quotient of 7 divided by 3 is 2 and the remainder is 1, then 7%3=1.

[0110] In some embodiments, performing a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value includes: performing a modulus operation on the hash value based on N*M to obtain a modulus value corresponding to the hash value, wherein N is the total number of authentication servers and M is a positive integer.

[0111] For example, if M=2 and N=10, a modulus operation is performed on the hash value based on a preset value to obtain a modulus value corresponding to the hash value, including: performing a modulus operation on the hash value based on 10.

[0112] S306: Determine the authentication server corresponding to the module value according to the mapping relationship between the module value and the target.

[0113] The target mapping relationship includes a mapping relationship between each module value of the preset value and the corresponding task service.

[0114] Exemplarily, when the total number of authentication servers is 10 and the preset value is 20, the value range of the modulus value corresponding to the hash value is [0, 19], and the target mapping relationship can be shown in the following Table 1:

[0115] Table 1

[0116]

[0117] S307: Distribute the authentication request to an authentication server corresponding to the module value.

[0118] In some embodiments, the traffic information at the current moment output by the prediction model includes: the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment; the original routing strategy is adjusted based on the traffic information at the current moment output by the prediction model, including: adjusting the initial mapping relationship based on the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment to obtain the target mapping relationship.

[0119] Exemplarily, when the initial mapping relationship is as shown in Table 1 above, if it is necessary to allocate fewer authentication requests to the authentication server 4 and more authentication requests to the authentication server 2, the adjusted target mapping relationship may be as shown in Table 2 below:

[0120] Table 2

[0121]

[0122] As shown in Table 2 above, the authentication server corresponding to the module value 6 in the initial mapping relationship is authentication server 4, and the authentication server corresponding to the module value 6 in the target mapping relationship is authentication server 2, so that fewer authentication requests are allocated to authentication server 4 and more authentication requests are allocated to authentication server 2.

[0123] In some embodiments, the identity authentication method provided in the embodiments of the present application also includes: monitoring the status of each authentication server, and when the status of the first authentication server is detected to be abnormal, adjusting the routing rules and / or the routing policy to prohibit the authentication request from being allocated to the first authentication server.

[0124] In the embodiment of the present application, the abnormal status of the authentication server includes: the authentication server response timeout, the response delay of the authentication server is greater than the preset time length, the load rate of the authentication server is greater than the preset load rate, etc.

[0125] When the state of the first authentication server is detected to be abnormal, the routing rule and / or the routing policy is adjusted to prohibit the authentication request from being assigned to the first authentication server, thereby avoiding further assigning the authentication request to the first authentication server and reducing the probability of authentication abnormality.

[0126] In some embodiments, when the state of the first authentication server is detected to be abnormal, an authentication request to be retried is determined, and an authentication server is assigned to the authentication request to be retried based on the adjusted routing rule and / or routing policy. The authentication request to be retried is an authentication request that has been assigned to the first authentication server and has not completed authentication.

[0127] The implementation method of allocating the authentication server for the authentication request to be retried based on the adjusted routing rule and / or the routing policy can refer to Figure 2 or Figure 3 The embodiment shown is different only in that the routing rule and / or the routing strategy are adjusted, and to avoid repetition, they will not be described again here.

[0128] Allocating an authentication server to the authentication request to be retried based on the adjusted routing rule and / or routing policy can ensure the continuity and availability of the authentication service.

[0129] In some embodiments, the information of the abnormal server and the retry results may also be recorded for subsequent analysis and improvement.

[0130] Based on the same inventive concept, as an implementation of the above method, an embodiment of the present application also provides an identity authentication device, which corresponds to the above method embodiment. For ease of reading, this embodiment will no longer repeat the details of the above method embodiment one by one, but it should be clear that the identity authentication device in this embodiment can correspond to all the contents in the above method embodiment.

[0131] The present application embodiment provides an identity authentication device, Figure 4 is a schematic diagram of the structure of the identity authentication device, such as Figure 4 As shown, the identity authentication device 400 includes:

[0132] The communication unit 41 is used to receive the authentication request sent by the terminal device;

[0133] A matching unit 42, configured to determine whether the authentication request matches a routing rule in a routing rule library, wherein the routing rule library includes at least one routing rule preconfigured by a user;

[0134] A processing unit 43 is configured to allocate the authentication request to a corresponding authentication server based on the routing rule hit by the authentication request when the authentication request hits a routing rule in the routing rule library;

[0135] The processing unit 43 is used to allocate an authentication server to the authentication request based on a routing policy when the authentication request does not hit the routing rule in the rule base; the routing policy is obtained by adjusting the original routing policy based on the current traffic information output by the prediction model.

[0136] As an optional implementation of the embodiment of the present application, the matching unit 42 is specifically configured to perform at least one of the following:

[0137] Determining whether the user type corresponding to the authentication request matches a routing rule based on user type in the routing rule library;

[0138] Determining whether the authentication method corresponding to the authentication request matches the routing rule based on the authentication method in the routing rule library;

[0139] Determine whether the service type corresponding to the authentication request matches a routing rule based on the service type in the routing rule library.

[0140] As an optional implementation of the embodiment of the present application, the processing unit 43 is specifically used to perform a hash calculation on the identification code of the authentication request to obtain a hash value corresponding to the authentication request; perform a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value; determine the authentication server corresponding to the modulus value according to the modulus value and the target mapping relationship, the target mapping relationship including the mapping relationship between each modulus value of the preset value and the corresponding task service; and assign the authentication request to the authentication server corresponding to the modulus value.

[0141] As an optional implementation of the embodiment of the present application, the processing unit 43 is specifically configured to perform a modulus operation on the hash value based on N*M to obtain a modulus value corresponding to the hash value;

[0142] Wherein, N is the total number of authentication servers, and M is a positive integer.

[0143] As an optional implementation of the embodiment of the present application, the traffic information at the current moment output by the prediction model includes: the total traffic at the current moment and the traffic of each authentication server at the current moment;

[0144] The processing unit 43 is further configured to adjust the initial mapping relationship based on the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment, so as to obtain the target mapping relationship.

[0145] As an optional implementation of the embodiment of the present application, the processing unit 43 is also used to monitor the status of each authentication server; when the status of the first authentication server is detected to be abnormal, the routing rules and / or the routing policy are adjusted to prohibit the authentication request from being allocated to the first authentication server.

[0146] As an optional implementation of the embodiment of the present application, the processing unit 43 is also used to determine an authentication request to be retried when it is monitored that the state of the first authentication server is abnormal; the authentication request to be retried is an authentication request that has been assigned to the first authentication server and has not completed authentication; and an authentication server is assigned to the authentication request to be retried based on the adjusted routing rules and / or the routing policy.

[0147] The identity authentication device provided in the embodiment of the present application can execute the identity authentication method provided in any of the above embodiments. Its implementation principle and technical effect are similar and will not be repeated here.

[0148] Based on the same inventive concept, an embodiment of the present application also provides an identity authentication device. Figure 5 A schematic diagram of the structure of the identity authentication device provided in the embodiment of the present application, such as Figure 5 As shown, the identity authentication device provided in this embodiment includes: a memory 501 and a processor 502, wherein the memory 501 is used to store a computer program, and the processor 502 is used to execute any identity authentication method provided in the above embodiments when executing the computer program.

[0149] Based on the same inventive concept, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the computing device implements any identity authentication method provided in the above embodiments.

[0150] Based on the same inventive concept, an embodiment of the present application further provides a computer program product. When the computer program product is run on a computer, the computing device implements any identity authentication method provided in the above embodiments.

[0151] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media that include computer-usable program code.

[0152] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0153] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0154] Computer readable media include permanent and non-permanent, removable and non-removable storage media. Storage media can be implemented by any method or technology to store information, and the information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0155] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein, and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. An identity authentication method, characterized in that: include: Receiving an authentication request sent by a terminal device; Determining whether the authentication request hits a routing rule in a routing rule library, wherein the routing rule library includes at least one routing rule preconfigured by a user; If the authentication request hits a routing rule in the routing rule library, the authentication request is assigned to a corresponding authentication server based on the routing rule hit by the authentication request; If the authentication request does not hit the routing rule in the rule base, assigning an authentication server to the authentication request based on the routing policy; The routing strategy is obtained by adjusting the original routing strategy based on the current traffic information output by the prediction model.

2. The method according to claim 1, characterized in that The determining whether the authentication request hits a routing rule preconfigured by a user includes at least one of the following: Determining whether the user type corresponding to the authentication request matches a routing rule based on user type in the routing rule library; Determining whether the authentication method corresponding to the authentication request matches the routing rule based on the authentication method in the routing rule library; Determine whether the service type corresponding to the authentication request matches a routing rule based on the service type in the routing rule library.

3. The method according to claim 1, characterized in that The allocating an authentication server to the authentication request based on a routing policy includes: Performing a hash calculation on the identification code of the authentication request to obtain a hash value corresponding to the authentication request; Performing a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value; Determine the authentication server corresponding to the module value according to the module value and the target mapping relationship, wherein the target mapping relationship includes the mapping relationship between each module value of the preset value and the corresponding task service; The authentication request is distributed to an authentication server corresponding to the module value.

4. The method according to claim 3, characterized in that: The performing a modulus operation on the hash value based on a preset value to obtain a modulus value corresponding to the hash value includes: Perform a modulus operation on the hash value based on N*M to obtain a modulus value corresponding to the hash value; Wherein, N is the total number of authentication servers, and M is a positive integer.

5. The method according to claim 3, characterized in that: The current traffic information output by the prediction model includes: the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment; Adjust the original routing strategy based on the current traffic information output by the prediction model, including: The initial mapping relationship is adjusted based on the total traffic volume at the current moment and the traffic volume of each authentication server at the current moment to obtain the target mapping relationship.

6. The method according to claim 1, characterized in that The method further comprises: Monitor the status of each authentication server; When it is monitored that the state of the first authentication server is abnormal, the routing rule and / or the routing policy is adjusted to prohibit the authentication request from being assigned to the first authentication server.

7. The method according to claim 6, characterized in that The method further comprises: When it is detected that the state of the first authentication server is abnormal, determining an authentication request to be retried; the authentication request to be retried is an authentication request that has been assigned to the first authentication server and has not completed authentication; An authentication server is allocated to the authentication request to be retried based on the adjusted routing rule and / or the routing policy.

8. An identity authentication device, characterized in that: include: A memory and a processor, wherein the memory is used to store a computer program and the processor is used to enable the identity authentication device to implement the identity authentication method described in any one of claims 1 to 7 when executing the computer program.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a computing device, the computing device implements the identity authentication method described in any one of claims 1 to 7.

10. A computer program product, characterized in that When the computer program product runs on a computer, the computer is enabled to implement the identity authentication method according to any one of claims 1 to 7.