Identity authentication method and system for WeChat applet

By collecting and analyzing the identity cache information and authentication process of WeChat applet users, combining the user's access behavior characteristics and the effectiveness of identity cache, multi-dimensional trusted authentication of WeChat applet user identities is achieved, solving the security risks and lack of flexibility of identity authentication in the existing technology, and improving the security and credibility of authentication.

CN119995983AActive Publication Date: 2025-05-13SHAOYANG POLYTECHNIC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510140070.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-13
Estimated Expiration
2045-02-08

AI Technical Summary

Technical Problem

The existing WeChat mini-program identity authentication methods rely on a single identity authentication information, pose security risks, it is difficult to effectively identify complex attack behaviors, and lack flexibility and intelligence.

Method used

By collecting the user's identity cache information on the front end of the mini program and the authentication process information of the backend server, extracting the user's identity authentication process association and access behavior characteristics in the backend server, as well as the offline periodicity and online continuity of the front end of the mini program, comprehensively determine the user's first and second authentication characteristics, and performing multi-dimensional trusted authentication.

Benefits of technology

It improves the security and credibility of identity authentication, can effectively identify complex attack behaviors, reduce misjudgments and misjudgments, improve user experience and enhance protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995983A_ABST
    Figure CN119995983A_ABST
Patent Text Reader

Abstract

The invention provides an identity authentication method and system for a WeChat applet. The method comprises the following steps: determining a first authentication feature of a user in a back-end server through a flow association relationship of identity authentication of the user in the back-end server and an access behavior feature of the user in the WeChat applet; extracting off-line periodicity and on-line continuity of the user identity cache at the front end of the applet, and performing validity authentication on the user identity cache according to the off-line periodicity and a cache use interval in the identity cache information to obtain effective characteristics of the user identity cache in an off-line state; determining a second authentication feature of the user in the applet front end through the effective feature and the online continuity; and performing credibility authentication on the user identity by using the first authentication feature and the second authentication feature to obtain the authentication credibility of the user identity in the WeChat applet, and judging the user identity based on the authentication credibility. Based on the scheme, the multi-dimensional credible authentication of the WeChat applet user identity can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of access control technology, and more specifically, to an identity authentication method and system for a WeChat applet. Background Art

[0002] Since its release in 2017, WeChat Mini Programs have attracted a large number of developers with their simple architecture and convenient usage. Developers can build lightweight applications with localized experience, which users can access directly through WeChat without downloading. The emergence of WeChat Mini Programs makes cross-platform development possible. Developers can deploy the same code to WeChat, Alipay, ByteDance and other platforms at the same time, greatly improving development efficiency. As a lightweight application form, WeChat Mini Programs has gradually developed from the initial basic functions to a diversified application ecosystem.

[0003] In the prior art, many authentication methods rely on single identity authentication information, such as user name, password, SMS verification code, etc. These traditional methods have certain security risks and are easily affected by forgery or tampering. User name and password are the most common authentication methods, but their security is relatively low and they are vulnerable to threats such as brute force cracking and dictionary attacks. Although SMS verification codes can add a layer of security protection, they rely on the user's mobile phone number, and the verification code is valid for a certain period of time. It is easy to be attacked by a middleman or bypassed by mobile phone card hijacking. It only relies on a single piece of information for verification, lacks flexibility and intelligence, and cannot effectively identify complex attack behaviors. Therefore, how to achieve multi-dimensional trusted authentication of WeChat mini program user identities is a difficult problem faced by the industry. Summary of the invention

[0004] The present application provides a WeChat applet identity authentication method and system, which can realize multi-dimensional trusted authentication of WeChat applet user identities.

[0005] In a first aspect, the present application provides an identity authentication method for a WeChat applet, comprising: When a user accesses a WeChat mini program, the user's identity cache information in the mini program front end and the authentication process information of the back-end server are collected; Extracting a process association relationship of the user's identity authentication in the backend server from the authentication process information, and determining a first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet; Extract the offline periodicity and online continuity of the user identity cache in the mini-program front end, authenticate the validity of the user identity cache according to the offline periodicity and the cache usage interval in the identity cache information, obtain the valid features of the user identity cache in the offline state, and determine the second authentication features of the user in the mini-program front end through the valid features and the online continuity; The user identity is authenticated for credibility using the first authentication feature and the second authentication feature to obtain the authentication credibility of the user identity in the WeChat applet, and the user identity is judged based on the authentication credibility.

[0006] In some embodiments, extracting the process association relationship of the user's identity authentication in the backend server from the authentication process information specifically includes: Get multiple logical sub-processes of identity authentication in the backend server; Extracting process association values ​​between adjacent logical sub-processes from the authentication process information; The process association relationship of the user's identity authentication in the backend server is determined based on all process association values.

[0007] In some embodiments, determining the first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet specifically includes: Extract the user's access behavior characteristics in WeChat Mini Programs from the user's historical access records; For each logical sub-process of identity authentication in the back-end server, extract the dependency features of the logical sub-process from the process association relationship; Determine the behavior matching degree between the user behavior and the logical sub-process through the dependency feature and the access behavior feature, and then obtain the behavior matching degree between the user behavior and each logical sub-process; The first authentication feature of the user in the backend server is determined based on all behavior matching degrees.

[0008] In some embodiments, extracting the offline periodicity and online continuity of the user identity cached in the mini-program front end specifically includes: Get the user's identity cache record in the mini program front end; Extract all offline time periods and all online time periods in the mini program front end from the identity cache record; Determine the offline periodicity of the user identity cache in the mini program front end through all offline time periods; The online continuity of the user identity cache in the mini program front end is determined through all online time periods.

[0009] In some embodiments, the validity of the user identity cache is authenticated according to the offline periodicity and the cache usage interval in the identity cache information, and the valid features of the user identity cache in the offline state specifically include: Get multiple usage intervals of the user identity cache in offline state; Determining the validity of the user identity cache at each usage interval by the offline periodicity; Determine the validity matching value between the user cache and each usage interval according to the validity of each usage interval and the cache usage interval in the identity cache information; The validity characteristics of the user identity cache in the offline state are determined based on all validity matching values.

[0010] In some embodiments, determining the second authentication feature of the user in the mini-program front end through the valid feature and the online continuity specifically includes: Extracting a continuous feature that the user identity cache is in an online state from the online continuity; The effective feature and the continuous feature are authenticated and fused to obtain a second authentication feature of the user in the mini program front end.

[0011] In some embodiments, using the first authentication feature and the second authentication feature to authenticate the credibility of the user identity, and obtaining the authentication credibility of the user identity in the WeChat applet specifically includes: Perform feature matching on the first authentication feature and the second authentication feature to obtain a feature matching degree of the user identity in the mini program front end and the back end server; The user identity is authenticated for credibility through the feature matching degree, and the authentication credibility of the user identity in the WeChat applet is obtained.

[0012] In the second aspect, the present application provides an identity authentication system for a WeChat applet, including: The collection module is used to collect the user's identity cache information in the WeChat mini program front end and the authentication process information of the back-end server when the user accesses the WeChat mini program; A processing module, used to extract the process association relationship of the user's identity authentication in the backend server from the authentication process information, and determine the first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet; The processing module is also used to extract the offline periodicity and online continuity of the user identity cache in the mini-program front end, authenticate the validity of the user identity cache according to the offline periodicity and the cache usage interval in the identity cache information, obtain the valid features of the user identity cache in the offline state, and determine the second authentication features of the user in the mini-program front end through the valid features and the online continuity; An execution module is used to use the first authentication feature and the second authentication feature to perform credibility authentication on the user identity, obtain the authentication credibility of the user identity in the WeChat applet, and judge the user identity based on the authentication credibility.

[0013] In a third aspect, the present application provides a computer device, comprising a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the above-mentioned WeChat applet identity authentication method.

[0014] In a fourth aspect, the present application provides a computer-readable storage medium, which stores instructions or codes. When the instructions or codes are run on a computer, the computer implements the above-mentioned WeChat applet identity authentication method when executing.

[0015] The technical solution provided by the embodiments disclosed in this application has the following beneficial effects: In a WeChat applet identity authentication method and system provided by the present application, when a user accesses a WeChat applet, the identity cache information of the user in the applet front end and the authentication process information of the back-end server are collected; the process association relationship of the user's identity authentication in the back-end server is extracted from the authentication process information, and the first authentication feature of the user in the back-end server is determined through the process association relationship and the user's access behavior characteristics in the WeChat applet; the offline periodicity and online continuity of the user identity cache in the applet front end are extracted, and the validity of the user identity cache is authenticated according to the offline periodicity and the cache usage interval in the identity cache information, and the valid features of the user identity cache in the offline state are obtained, and the second authentication features of the user in the applet front end are determined through the valid features and the online continuity; The user identity is authenticated for credibility using the first authentication feature and the second authentication feature to obtain the authentication credibility of the user identity in the WeChat applet, and the user identity is judged based on the authentication credibility.

[0016] It can be seen that in this application, the first authentication feature and the second authentication feature are used to authenticate the credibility of the user identity, obtain the authentication credibility of the user identity in the WeChat applet, and judge the user identity based on the authentication credibility; first, determine the first authentication feature to obtain the feature used to verify the degree of authentication between the user behavior and the user identity in the back-end server, thereby ensuring the comprehensiveness and rigor of the authentication information of the WeChat applet, not only relying on simple authentication information, but also verifying from multiple angles such as user behavior and authentication intervals, thereby effectively improving the security and credibility of the authentication process, and helping the WeChat applet to accurately distinguish between legitimate users and illegal users when dealing with complex authentication scenarios, reduce misjudgments and missed judgments, and improve user experience while strengthening the protection capabilities of the WeChat applet; then, determine the second authentication feature to obtain the user's The validity feature of the identity cache in the mini-program front-end allows WeChat mini-programs to ensure accurate authentication of user identities in various network environments. Even when the network is unavailable or the user does not log in again, the credibility of the identity can be ensured through the valid features of the cache. In addition, the consideration of online continuity enhances the dynamic nature of user identity authentication, ensuring that the authentication is not only static, but also can be verified in real time as user behavior changes. By comprehensively considering the authentication features in offline and online states, the second authentication feature further enhances the comprehensiveness and accuracy of the authentication, which helps to achieve multi-dimensional trusted authentication of WeChat mini-program user identities. This multi-dimensional authentication method can effectively respond to different attack methods and authentication challenges, and improve overall security and user experience. In summary, based on the above scheme, multi-dimensional trusted authentication of WeChat mini-program user identities can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0018] Figure 1 is an exemplary flow chart of the identity authentication method of the WeChat applet shown in some embodiments of the present application; Figure 2 It is an architectural diagram of the inter-service communication and caching mode in the WeChat applet shown in some embodiments of the present application; Figure 3 It is a schematic diagram of a process for determining authentication credibility according to some embodiments of the present application; Figure 4 It is a structural diagram of the identity authentication system of the WeChat applet shown in some embodiments of the present application; Figure 5 It is a structural diagram of a computer device for implementing the identity authentication method of WeChat mini-program according to some embodiments of the present application. DETAILED DESCRIPTION

[0019] In order to better understand the technical solution of the present application, the technical solution of the present application will be described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0020] refer to Figure 1 , which is an exemplary flow chart of a WeChat applet identity authentication method according to some embodiments of the present application. The WeChat applet identity authentication method mainly includes the following steps: In step 101, when a user accesses a WeChat applet, the user's identity cache information in the applet front end and the authentication process information of the backend server are collected.

[0021] It should be noted that in this application, the authentication process information refers to the rules, conditions and process information used by the backend server in the identity authentication process; the identity cache information refers to the relevant data about the user identity stored in the front end of the mini program.

[0022] In specific implementation, when a user accesses a WeChat mini program, all identity caches of the user in the mini program front end are obtained from the session of the mini program front end, so that the collection of all identity caches can be used as identity cache information, and multiple logical sub-processes of identity authentication in the back-end server and the logical associations between adjacent logical sub-processes are obtained from the console of the back-end server, so that the collection of all logical associations can be used as the authentication process information of the back-end server, where the logical association represents the inherent connection and interaction between different logical sub-processes in the identity authentication process, and the logical sub-process represents a part of the sub-process in the identity authentication process, which is usually a step that is refined based on specific authentication rules or logic. Each logical sub-process performs specific tasks, such as feature extraction and feature matching, and ultimately collaborates to complete the entire identity authentication process.

[0023] In some embodiments, reference Figure 2The figure is an architectural diagram of the inter-service communication and cache mode in the WeChat applet shown in some embodiments of the present application. The figure shows the architectural design of the inter-service communication and cache mode. The theme of the content in the figure is inter-service communication + cache mode. The connecting lines between service A and database A, and between service B and database B represent the data flow, and the arrows between service A and service B represent the calling relationship between services. Service A and database A interact with data through the local cache, and service A is also connected to the distributed cache; service A and service B communicate through RPC (remote procedure call), and service B is directly connected to database B for data storage and retrieval. The figure also lists four implementation methods: the first is local cache / distributed cache plus RPC, which combines the fast access of local cache and the scalability of distributed cache, and realizes communication between services through RPC; the second is (push) RPC synchronization, that is, service A actively pushes data to service B for synchronization; the third is scheduled worker (pull) plus write cache, service B pulls data from service A through scheduled tasks and writes it to the local cache; the fourth is asynchronous MQ (message queue), service A sends data to the message queue, and service B obtains data asynchronously from the message queue.

[0024] In step 102, the process association relationship of the user's identity authentication in the backend server is extracted from the authentication process information, and the first authentication feature of the user in the backend server is determined through the process association relationship and the user's access behavior characteristics in the WeChat applet.

[0025] In some embodiments, extracting the process association relationship of the user's identity authentication in the backend server from the authentication process information can be implemented by the following steps: Get multiple logical sub-processes of identity authentication in the backend server; Extracting process association values ​​between adjacent logical sub-processes from the authentication process information; The process association relationship of the user's identity authentication in the backend server is determined based on all process association values.

[0026] It should be noted that, in the present application, the process association relationship represents the mutual association and dependence relationship between different logical sub-processes in the identity authentication process; in specific implementation, first, obtaining multiple logical sub-processes for identity authentication in the back-end server can be implemented in the following manner, namely: multiple logical sub-processes for identity authentication in the back-end server can be obtained from the authentication process information; then, extracting the process association value between adjacent logical sub-processes from the authentication process information can be implemented in the following manner, namely: taking the quantified value of the logical association between adjacent logical sub-processes in the authentication process information as the process association value between adjacent logical sub-processes, and the process association value is a numerical value used to quantify the degree of logical dependence between adjacent logical sub-processes; finally, determining the process association relationship of the user's identity authentication in the back-end server based on all process association values ​​can be implemented in the following manner, namely: taking the set of all process association values ​​as the process association relationship of the user's identity authentication in the back-end server.

[0027] In some embodiments, determining the first authentication feature of the user in the backend server through the process association relationship and the user's access behavior features in the WeChat applet can be implemented by the following steps: Extract the user's access behavior characteristics in WeChat Mini Programs from the user's historical access records; For each logical sub-process of identity authentication in the back-end server, extract the dependency features of the logical sub-process from the process association relationship; Determine the behavior matching degree between the user behavior and the logical sub-process through the dependency feature and the access behavior feature, and then obtain the behavior matching degree between the user behavior and each logical sub-process; The first authentication feature of the user in the backend server is determined based on all behavior matching degrees.

[0028] It should be noted that in this application, the first authentication feature represents the feature used in the backend server to verify the degree of authentication between user behavior and user identity; the access behavior feature represents the behavior pattern characteristics of the user when accessing the WeChat mini program, including access frequency, access time and click flow; the dependency feature represents the dependency relationship between logical sub-processes in the user identity authentication process; the behavior matching degree represents the degree of consistency between the user's behavior characteristics in the process of accessing the mini program and the preset behavior characteristics.

[0029] In the specific implementation, first, the following method can be used to extract the user's access behavior features in the WeChat applet from the user's historical access records, namely: collect the user's historical access records within a specified time period from the WeChat applet on the back-end server, and use the feature extraction algorithm to extract the behavioral sub-features of each user's visit to the WeChat applet from the historical access records. A set of behavioral sub-features with a repetition rate exceeding a preset feature threshold (the default is 60%) can be screened from all behavioral sub-features as the user's access behavior features in the WeChat applet; secondly, for each logical sub-process of identity authentication in the back-end server, the following method can be used to extract the dependent features of the logical sub-process from the process association relationship, namely: for the back-end server For each logical sub-process of identity authentication, the mean of the two process association values ​​with the logical sub-process in the process association relationship can be used as the dependency feature of the logical sub-process; then, the behavior matching degree between the user behavior and the logical sub-process is determined by the dependency feature and the access behavior feature, and then the behavior matching degree between the user behavior and each logical sub-process can be obtained. This can be achieved in the following way, namely: the cosine similarity between the dependency feature and the access behavior feature can be used as the behavior matching degree between the user behavior and the logical sub-process, and the behavior matching degree between the user behavior and each logical sub-process can be obtained in the above way; finally, the standard deviation of all behavior matching degrees can be used as the first authentication feature of the user in the back-end server.

[0030] In step 103, the offline periodicity and online continuity of the user identity cache in the mini-program front end are extracted, and the validity of the user identity cache is authenticated according to the offline periodicity and the cache usage interval in the identity cache information to obtain the valid features of the user identity cache in the offline state, and the second authentication features of the user in the mini-program front end are determined through the valid features and the online continuity.

[0031] In some embodiments, extracting the offline periodicity and online continuity of the user identity cached in the mini-program front end can be achieved by the following steps: Get the user's identity cache record in the mini program front end; Extract all offline time periods and all online time periods in the mini program front end from the identity cache record; Determine the offline periodicity of the user identity cache in the mini program front end through all offline time periods; The online continuity of the user identity cache in the mini program front end is determined through all online time periods.

[0032] In the specific implementation, first, obtaining the identity cache record of the user in the mini-program front end can be achieved in the following manner, namely: obtaining the record content of each time the user performs identity caching from the console of the WeChat mini-program front end, so that the collection of all record contents can be used as the identity cache record of the user in the mini-program front end; secondly, extracting all offline time periods and all online time periods in the mini-program front end from the identity cache record can be achieved in the following manner, namely: for each identity cache, the cache generation time in the cache content of this identity cache is used as the effective time point of the identity cache, and the time point when the WeChat mini-program is closed after the identity cache is used as the expiration time point of the identity cache, so that the time period from the effective time point to the expiration time point can be used as the online time period of this identity cache, and the last same The time period from the expiration time point of a user identity cache to the effective time point of this identity cache is used as the offline time period of this identity cache. The offline time period and online time period in each identity cache can be obtained through the above method, thereby obtaining all offline time periods and all online time periods in the mini-program front end; then, the offline periodicity of the user identity cache in the mini-program front end can be determined through all offline time periods, which can be implemented in the following way, namely: the set of all offline time periods can be used as the offline periodicity of the user identity cache in the mini-program front end; finally, the online continuity of the user identity cache in the mini-program front end can be determined through all online time periods, which can be implemented in the following way, namely: the set of all online time periods can be used as the online continuity of the user identity cache in the mini-program front end.

[0033] It should be noted that in this application, online continuity is a feature that reflects the degree of identity continuity of the user in the online state; offline periodicity is a periodic feature that is used to determine the validity of cached information during the offline period; identity cache records represent the process records of saving cached information about the user's identity on the front end of the mini program. The cached information includes the user's login status, authentication data, and access history, which are used to speed up the authentication process and reduce the need for repeated authentication; the offline time period represents the validity period of the identity authentication information when the user has no network connection, reflecting the degree of dependence of the user on the identity information in the offline state; the online time period represents the validity period of the identity authentication information when the user is connected to the network, reflecting the frequency and stability of the user's access to the identity information in the online state.

[0034] In some embodiments, the user identity cache is authenticated for validity according to the offline periodicity and the cache usage interval in the identity cache information, and the valid characteristics of the user identity cache in the offline state can be obtained by the following steps: Get multiple usage intervals of the user identity cache in offline state; Determining the validity of the user identity cache at each usage interval by the offline periodicity; Determine the validity matching value between the user cache and each usage interval according to the validity of each usage interval and the cache usage interval in the identity cache information; The validity characteristics of the user identity cache in the offline state are determined based on all validity matching values.

[0035] In the specific implementation, first, obtaining multiple usage intervals of the user identity cache in the offline state can be achieved in the following manner, namely: obtaining multiple usage intervals of the user identity cache in the offline state from the console of the WeChat applet, the usage interval area in the console is generated by clustering analysis of the usage intervals of all user identity caches in the WeChat applet, and in actual use, it can be fine-tuned through manual adjustment in combination with historical experience to improve the accuracy of the division of the usage intervals; secondly, determining the validity of the user identity cache in each usage interval through the offline periodicity can be achieved in the following manner, namely: for each usage interval, all offline time periods with a duration within the usage interval range screened in the offline periodicity can be used as the interval time period, and the average of the corresponding durations of all interval time periods can be used as the validity of the usage interval. The validity of the user identity cache in each usage interval can be obtained through the above method; then, the validity matching value between the user cache and each usage interval is determined according to the validity of each usage interval and the cache usage interval in the identity cache information, which can be implemented in the following manner, namely: for each usage interval, the difference between the lower limit of the usage interval and the cache usage interval is calculated respectively, so as to use the ratio of the calculated difference to the validity of the usage interval as the validity matching value between the user cache and the usage interval, and the validity matching value between the user cache and each usage interval can be obtained through the above method; finally, the validity feature of the user identity cache in the offline state is determined according to all the validity matching values, which can be implemented in the following manner, namely: the standard deviation of all the validity matching values ​​is used as the validity feature of the user identity cache in the offline state.

[0036] It should be noted that in this application, valid features refer to features that can reflect the authenticity and stability of user identity during the identity authentication process; the usage interval reflects the time interval of continuity of user identity information access; the validity indicates the validity of the user identity authentication result within the specified time period; the validity match value indicates the degree of match between the validity of the identity authentication information and the expected standards in the user identity authentication process.

[0037] In some embodiments, determining the second authentication feature of the user in the mini-program front end by the valid feature and the online continuity can be implemented by the following steps: Extracting a continuous feature that the user identity cache is in an online state from the online continuity; The effective feature and the continuous feature are authenticated and fused to obtain a second authentication feature of the user in the mini program front end.

[0038] It should be noted that, in the present application, the second authentication feature represents the feature of the validity of the user in the identity cache of the mini-program front-end; in the specific implementation, first, the continuous feature of the user identity cache being in an online state is extracted from the online continuity, which can be implemented in the following way, namely: the standard deviation of the corresponding duration of all online time periods in the online continuity can be used as the continuous feature of the user identity cache being in an online state, wherein the continuous feature is a feature used to reflect the degree of continuity of the user's online state; then, the valid feature and the continuous feature are authenticated and fused to obtain the second authentication feature of the user in the mini-program front-end, which can be implemented in the following way, namely: the ratio of the valid feature to the continuous feature is used as the result of the authentication fusion, so that the result of the authentication fusion can be used as the second authentication feature of the user in the mini-program front-end.

[0039] In step 104, the user identity is authenticated for credibility using the first authentication feature and the second authentication feature to obtain the authentication credibility of the user identity in the WeChat applet, and the user identity is judged based on the authentication credibility.

[0040] In some embodiments, the first authentication feature and the second authentication feature are used to authenticate the credibility of the user identity, and the authentication credibility of the user identity in the WeChat applet is obtained. Figure 3 The figure is a schematic diagram of a process for determining authentication credibility in some embodiments of the present application. In this embodiment, determining authentication credibility can be achieved by using the following steps: In step 1041, feature matching is performed on the first authentication feature and the second authentication feature to obtain a feature matching degree of the user identity in the mini program front end and the back end server; In step 1042, the user identity is authenticated for credibility through the feature matching degree to obtain the authentication credibility of the user identity in the WeChat applet.

[0041] In the specific implementation, first, feature matching is performed on the first authentication feature and the second authentication feature to obtain the feature matching degree of the user identity in the front end of the mini program and the back end server. This can be achieved in the following manner, namely: converting the first authentication feature and the second authentication feature into feature vectors to ensure that the two have a unified dimension and data format, and quantifying the feature matching degree between the two feature vectors by using a similarity measurement method (for example, Euclidean distance), that is, the Euclidean distance between the first authentication feature and the second authentication feature can be used as the feature matching degree of the user identity in the front end of the mini program and the back end server; then, initializing a neural network-based authentication feedback model, and using the feature matching degree as the authentication value in the authentication feedback model, so as to use the authentication feedback model to perform credibility authentication on the user identity, so that the feedback value of the credibility score output by the authentication feedback model after credibility authentication can be used as the authentication credibility of the user identity in the WeChat mini program.

[0042] It should be noted that in this application, authentication credibility refers to the degree of credibility of the user's identity during the authentication process; feature matching refers to the consistency between the front-end and back-end authentication features; the authentication feedback model is an intelligent model based on a neural network, which aims to evaluate the credibility of the user's identity by analyzing and learning the user's identity authentication features. In this authentication feedback model, the feature matching is used as input data as the authentication value, that is, the authentication feedback model receives the matching degree between the front-end and back-end authentication features as input, and gradually extracts effective authentication patterns and association rules through the operation of multi-layer neural networks. After training, the model can generate a credibility score based on the input authentication value (feature matching) as the final output feedback value, which represents the authentication credibility of the user's identity in the WeChat applet; the technical principle of the authentication feedback model is based on the self-learning ability of the neural network, which can identify complex authentication relationships from a large amount of historical authentication data and dynamically adjust parameters to achieve accurate and reliable identity authentication results.

[0043] In some embodiments, judging the user identity based on the authentication credibility can be achieved in the following manner, namely: the credibility threshold of the user identity can be obtained from the WeChat applet console. When the authentication credibility meets or exceeds the threshold, the WeChat applet outputs a "trusted" authentication result, allowing the user to continue to access the applet and its related resources, or perform subsequent operations (for example, entering an account, conducting transactions). When the authentication credibility is lower than the threshold, the WeChat applet outputs an "untrusted" authentication result, refusing the user access to the applet, requiring the user to perform further identity authentication (for example, SMS verification code, identity reset), or take other security measures.

[0044] In addition, in another aspect of the present application, in some embodiments, the present application provides an identity authentication system for a WeChat applet, referring to Figure 4, which is a schematic diagram of the structure of the identity authentication system of the WeChat applet according to some embodiments of the present application. The identity authentication system of the WeChat applet includes: a collection module 201, a processing module 202 and an execution module 203, which are described as follows: Collection module 201, in this application, collection module 201 is mainly used to collect the user's identity cache information in the mini-program front end and the authentication process information of the back-end server when the user accesses the WeChat mini-program; Processing module 202, in this application, processing module 202 is used to extract the process association relationship of the user's identity authentication in the backend server from the authentication process information, and determine the first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet; It should be noted that the processing module 202 is also used to extract the offline periodicity and online continuity of the user identity cache in the mini-program front end, authenticate the validity of the user identity cache according to the offline periodicity and the cache usage interval in the identity cache information, obtain the valid features of the user identity cache in the offline state, and determine the second authentication features of the user in the mini-program front end through the valid features and the online continuity; Execution module 203. In this application, execution module 203 is mainly used to use the first authentication feature and the second authentication feature to authenticate the credibility of the user identity, obtain the authentication credibility of the user identity in the WeChat applet, and judge the user identity based on the authentication credibility.

[0045] The above describes in detail the example of the identity authentication method and system of the WeChat applet provided in the embodiment of the present application. It can be understood that the corresponding device includes a hardware structure and / or software module corresponding to the execution of each function in order to realize the above functions. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present application.

[0046] In some embodiments, the present application also provides a computer device, comprising a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the above-mentioned WeChat applet identity authentication method.

[0047] In some embodiments, reference Figure 5, the dotted line in the figure indicates that the unit or module is optional. The figure is a schematic diagram of the structure of a computer device for implementing the identity authentication method of the WeChat applet according to the embodiment of the present application. The identity authentication method of the WeChat applet described in the above embodiment can be Figure 5 The computer device shown in the figure is implemented, and the computer device includes at least one processor 301, a memory 302 and at least one communication unit 305. The computer device can be a terminal device, a server or a chip.

[0048] The processor 301 may be a general-purpose processor or a special-purpose processor. For example, the processor 301 may be a central processing unit (CPU), which may be used to control the computer device, execute software programs, and process data of the software programs. The computer device may also include a communication unit 305 to implement signal input (reception) and output (transmission).

[0049] For example, the computer device may be a chip, the communication unit 305 may be an input and / or output circuit of the chip, or the communication unit 305 may be a communication interface of the chip, and the chip may be a component of a terminal device, a network device, or other devices.

[0050] For another example, the computer device may be a terminal device or a server, and the communication unit 305 may be a transceiver of the terminal device or the server, or the communication unit 305 may be a transceiver circuit of the terminal device or the server.

[0051] The computer device may include one or more memories 302, on which a program 304 is stored. The program 304 can be executed by the processor 301 to generate instructions 303, so that the processor 301 performs the method described in the above method embodiment according to the instructions 303. Optionally, data (such as a target audit model) can also be stored in the memory 302. Optionally, the processor 301 can also read the data stored in the memory 302, and the data can be stored at the same storage address as the program 304, or the data can be stored at a different storage address from the program 304.

[0052] The processor 301 and the memory 302 may be provided separately or integrated together, for example, integrated on a system on chip (SOC) of the terminal device.

[0053] It should be understood that each step of the above method embodiment can be completed by a hardware-based logic circuit or software-based instructions in the processor 301. The processor 301 can be a CPU, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, such as discrete gates, transistor logic devices, or discrete hardware components.

[0054] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0055] For example, in some embodiments, the present application also provides a computer-readable storage medium, which stores instructions or codes. When the instructions or codes are run on a computer, the computer implements the above-mentioned WeChat applet identity authentication method when executing.

[0056] Although the preferred embodiments of the present application have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0057] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A WeChat applet identity authentication method, characterized in that: The steps include: When a user accesses a WeChat mini program, the user's identity cache information in the mini program front end and the authentication process information of the back-end server are collected; Extracting a process association relationship of the user's identity authentication in the backend server from the authentication process information, and determining a first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet; Extract the offline periodicity and online continuity of the user identity cache in the mini-program front end, authenticate the validity of the user identity cache according to the offline periodicity and the cache usage interval in the identity cache information, obtain the valid features of the user identity cache in the offline state, and determine the second authentication features of the user in the mini-program front end through the valid features and the online continuity; The user identity is authenticated for credibility using the first authentication feature and the second authentication feature to obtain the authentication credibility of the user identity in the WeChat applet, and the user identity is judged based on the authentication credibility.

2. The method according to claim 1, characterized in that Extracting the process association relationship of the user's identity authentication in the backend server from the authentication process information specifically includes: Get multiple logical sub-processes of identity authentication in the backend server; Extracting process association values ​​between adjacent logical sub-processes from the authentication process information; The process association relationship of the user's identity authentication in the backend server is determined based on all process association values.

3. The method according to claim 1, characterized in that Determining the first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet specifically includes: Extract the user's access behavior characteristics in WeChat Mini Programs from the user's historical access records; For each logical sub-process of identity authentication in the back-end server, extract the dependency features of the logical sub-process from the process association relationship; Determine the behavior matching degree between the user behavior and the logical sub-process through the dependency feature and the access behavior feature, and then obtain the behavior matching degree between the user behavior and each logical sub-process; The first authentication feature of the user in the backend server is determined based on all behavior matching degrees.

4. The method according to claim 1, characterized in that Extracting the offline periodicity and online continuity of the user identity cache in the mini program front end specifically includes: Get the user's identity cache record in the mini program front end; Extract all offline time periods and all online time periods in the mini program front end from the identity cache record; Determine the offline periodicity of the user identity cache in the mini program front end through all offline time periods; The online continuity of the user identity cache in the mini program front end is determined through all online time periods.

5. The method according to claim 1, characterized in that The validity of the user identity cache is authenticated according to the offline periodicity and the cache usage interval in the identity cache information, and the valid features of the user identity cache in the offline state specifically include: Get multiple usage intervals of the user identity cache in offline state; Determining the validity of the user identity cache at each usage interval by the offline periodicity; Determine the validity matching value between the user cache and each usage interval according to the validity of each usage interval and the cache usage interval in the identity cache information; The validity characteristics of the user identity cache in the offline state are determined based on all validity matching values.

6. The method according to claim 1, characterized in that Determining the second authentication feature of the user in the mini-program front end through the valid feature and the online continuity specifically includes: Extracting a continuous feature that the user identity cache is in an online state from the online continuity; The effective feature and the continuous feature are authenticated and fused to obtain a second authentication feature of the user in the mini program front end.

7. The method according to claim 1, characterized in that Using the first authentication feature and the second authentication feature to authenticate the credibility of the user identity, and obtaining the authentication credibility of the user identity in the WeChat applet specifically includes: Perform feature matching on the first authentication feature and the second authentication feature to obtain a feature matching degree of the user identity in the mini program front end and the back end server; The user identity is authenticated for credibility through the feature matching degree, and the authentication credibility of the user identity in the WeChat applet is obtained.

8. An identity authentication system for a WeChat applet, characterized in that: include: The collection module is used to collect the user's identity cache information in the WeChat mini program front end and the authentication process information of the back-end server when the user accesses the WeChat mini program; A processing module, used to extract the process association relationship of the user's identity authentication in the backend server from the authentication process information, and determine the first authentication feature of the user in the backend server through the process association relationship and the user's access behavior feature in the WeChat applet; The processing module is also used to extract the offline periodicity and online continuity of the user identity cache in the mini-program front end, authenticate the validity of the user identity cache according to the offline periodicity and the cache usage interval in the identity cache information, obtain the valid features of the user identity cache in the offline state, and determine the second authentication features of the user in the mini-program front end through the valid features and the online continuity; An execution module is used to use the first authentication feature and the second authentication feature to perform credibility authentication on the user identity, obtain the authentication credibility of the user identity in the WeChat applet, and judge the user identity based on the authentication credibility.

9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the computer device executes the identity authentication method of the WeChat applet described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions or codes, and when the instructions or codes are executed on a computer, the computer implements the identity authentication method of the WeChat applet as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Shared resource identity authentication method and system and security authentication device

    CN108400989A

  • Authentication method and communication terminal

    CN108925144A

  • Breakpoint data transmission method, device and equipment, and computer storage medium

    CN110336791A

  • Online video communication method for webpage end and WeChat applet end and storage medium

    CN111356024A

  • Information recommendation method and device based on artificial intelligence and electronic equipment

    CN111368210A