Body verification method and device, computer readable storage medium, electronic equipment and computer program product
By obtaining the user's nucleus information, determining the set of nucleus methods that can be performed, and nucleus methods for users based on the various nucleus methods in the set, the problem of insufficient nuclear security in the existing technology is solved, and effective resistance to cyber black industry attacks is achieved.
Patent Information
- Application Number
- CN202510019378.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-05-23
AI Technical Summary
When facing cyber black industry attacks, existing nuclear technology is insufficient in security and it is difficult to provide multi-layer protection.
By obtaining the user's nucleus information, determining the set of nucleus methods that can be performed, and nucleus users based on various nucleus methods in the set, including face recognition, document recognition, voiceprint comparison and motion detection.
It significantly improves nuclear security, provides multi-layer protection capabilities, and effectively resists cyber black industry attacks.
Smart Images

Figure CN120030514A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of authentication technology, and in particular to an authentication method, device, computer-readable storage medium, electronic device, and computer program product. Background Art
[0002] Authentication refers to the process of verifying the real identity of a user. As people pay more attention to network security, user authentication technology has been widely used in the fields of Internet, finance, e-commerce, social media, etc., which has led to increasing security requirements for authentication systems from users and related industries. Summary of the invention
[0003] The embodiments of this specification provide an authentication method, device, computer-readable storage medium, electronic device and computer program product, which can improve authentication security by determining a set of authentication methods that a user can perform and using multiple authentication methods in the authentication method set to authenticate the user.
[0004] An authentication method provided in an embodiment of the present specification includes:
[0005] Obtaining authentication information corresponding to the user;
[0006] Determine a set of authentication methods corresponding to the user according to the authentication applicable information;
[0007] The user is authenticated based on each authentication method in the authentication method set.
[0008] Furthermore, in some embodiments, the authentication applicable information includes recorded authentication information that can verify the identity of the user, and the authentication information includes one or more of facial features, ID images, and voiceprint features corresponding to the user;
[0009] The determining, according to the authentication applicable information, a set of authentication methods corresponding to the user includes:
[0010] Determine the authentication methods that the user can perform based on the authentication information to obtain the authentication method set, which includes but is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
[0011] Furthermore, in some implementations, the identity verification applicable information also includes nationality information corresponding to the user;
[0012] The determining, according to the authentication applicable information, a set of authentication methods corresponding to the user includes:
[0013] Determine the authentication methods that the user can perform based on the authentication information and the nationality information to obtain the authentication method set, which includes but is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
[0014] Furthermore, in some embodiments, the authentication applicable information includes the user's historical authentication record;
[0015] After determining the authentication method set corresponding to the user according to the authentication applicable information, the method further includes:
[0016] Calculate the authentication failure probability of each authentication method in the authentication method set according to the historical authentication record;
[0017] Authentication methods whose authentication failure probability is greater than a preset probability threshold are eliminated from the authentication method set to obtain a new authentication method set.
[0018] Further, in some implementations, authenticating the user based on each authentication method in the authentication method set includes:
[0019] Collecting user authentication data corresponding to each authentication method in the authentication method set;
[0020] The authentication data of each user is sent to the corresponding authentication model for authentication.
[0021] Furthermore, in some implementations, before authenticating the user based on each authentication method in the authentication method set, the method further includes:
[0022] Sorting each authentication method in the authentication method set to obtain an authentication method sequence;
[0023] The authenticating the user based on each authentication method in the authentication method set includes:
[0024] The user is authenticated in sequence based on the order of the authentication methods in the authentication method sequence.
[0025] Furthermore, in some implementations, the step of sorting the authentication methods in the authentication method set to obtain an authentication method sequence includes:
[0026] Calculate the authentication failure probability corresponding to each authentication method in the authentication method set according to the historical authentication records;
[0027] The authentication methods in the authentication method set are sorted in order from low to high probability of authentication failure to obtain an authentication method sequence.
[0028] Furthermore, in some implementations, authenticating the user in sequence based on the order of the authentication methods in the authentication method sequence includes:
[0029] Determine a target authentication method that is ranked first in the authentication method sequence;
[0030] Collecting user authentication data corresponding to the target authentication methods;
[0031] Sending the authentication data of each user to the authentication model corresponding to the target authentication method for authentication;
[0032] If it is determined that the authentication is successful, the authentication method that is ranked one position after the target authentication method in the authentication method sequence is used as the new target authentication method, and the step of collecting user authentication data corresponding to each of the target authentication methods is performed;
[0033] If it is determined that the authentication has not passed, the authentication process will be exited and an authentication failure prompt message will be output.
[0034] Furthermore, in some implementations, the user authentication data includes but is not limited to one or more of video data, audio data, and gyroscope data.
[0035] Furthermore, in some implementations, the collecting of user authentication data corresponding to the target authentication modes includes:
[0036] The authentication instruction information corresponding to the target authentication method is displayed on the authentication interaction page, and the authentication instruction information is used to instruct the user to execute the action instruction corresponding to the target authentication method so that the terminal device can collect the user authentication data corresponding to the target authentication method.
[0037] The embodiment of this specification also provides a verification device, including:
[0038] A user information acquisition module, used to acquire authentication applicable information corresponding to the user;
[0039] An authentication method determination module, used to determine an authentication method set corresponding to the user according to the authentication applicable information;
[0040] An authentication module is used to authenticate the user based on each authentication method in the authentication method set.
[0041] The embodiments of this specification also provide a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are implemented.
[0042] An embodiment of the present specification also provides an electronic device, comprising: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the above method.
[0043] The embodiments of the present specification also provide a computer program product, on which at least one instruction is stored, and when the at least one instruction is executed by a processor, the steps of the above method are implemented.
[0044] In the embodiments of the present specification, in response to a user initiating an authentication process, applicable authentication information corresponding to the user is obtained, a set of authentication methods corresponding to the user is determined based on the applicable authentication information, and then the user is authenticated based on each authentication method in the set of authentication methods. By using multiple authentication methods to authenticate the user, multi-layer protection capabilities are provided against black market attacks, which can significantly improve the security of authentication. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 A schematic diagram of the structure of a verification system provided in an embodiment of this specification;
[0046] Figure 2 A flowchart of a verification method provided in an embodiment of this specification;
[0047] Figure 3 A flowchart of a verification method provided in an embodiment of this specification;
[0048] Figure 4 A flowchart of a verification method provided in an embodiment of this specification;
[0049] Figure 5 A flowchart of a verification method provided in an embodiment of this specification;
[0050] Figure 6 A schematic diagram of the structure of a verification device provided in an embodiment of this specification;
[0051] Figure 7 A schematic diagram of the structure of a verification device provided in an embodiment of this specification;
[0052] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.
[0054] Before describing in detail the authentication method provided in the embodiments of this specification, the relevant technical background is first described.
[0055] Identity verification refers to the process of verifying the real identity of the user. Usually when registering on certain apps or websites, in order to ensure the authenticity and security of user information, it is necessary to authenticate the user to prove the user's real identity and the legitimacy of the authorized operation.
[0056] The online black industry chain, referred to as the online black industry, refers to the use of Internet technology to carry out network attacks, steal information, extortion and fraud, steal money, promote pornography, gambling, drugs and other network illegal activities.
[0057] With the development of artificial intelligence technology, while promoting social progress, it has also become a tool for some criminals to commit illegal acts. With the support of artificial intelligence technology, the efficiency and ability of cybercriminals to attack identity systems have been greatly improved. Improving identity security is an inevitable way to resist cybercriminals' attacks with increasing attack capabilities.
[0058] Based on this, the embodiments of this specification provide an authentication method, which obtains applicable authentication information corresponding to the user, then determines the authentication method set corresponding to the user based on the applicable authentication information, and finally authenticates the user based on each authentication method in the authentication method set. By using multiple authentication methods to authenticate the user, multi-layer protection capabilities are provided against black market attacks, which can significantly improve the authentication security.
[0059] The authentication method provided in one or more embodiments of this specification can be applied to Figure 1 In the authentication system shown, the authentication system may include a terminal device 01 and a server 02. The terminal device 101 and the server 102 are in communication connection with each other.
[0060] Among them, the terminal device 01 can be a mobile phone, a tablet computer, a handheld computer, a PC, a cellular phone, a personal digital assistant (PDA), a wearable device (such as a smart watch, a smart bracelet), a smart home device (such as a TV), a car machine (such as a car computer, a car TV), a smart screen, a game console, a smart TV box, and an augmented reality (AR) / virtual reality (VR) device, etc. This specification embodiment does not impose any special restrictions on the specific device form of the terminal device 01. The terminal device 01 and the server 02 can be connected through a cable network, a wired network, an optical fiber network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a public switched telephone network (PSTN), a Bluetooth TM network, a ZigBee TM network, a near field communication (NFC) network or a similar network. User 03 can initiate the authentication process through terminal device 01, and terminal device 01 and server 02 can exchange data with each other to complete the authentication of user 03.
[0061] The authentication method provided in one or more embodiments of this specification may be executed in the above-mentioned terminal device 01, or may be executed in the server 02. When the authentication method provided in one or more embodiments of this specification is executed in the terminal device 01, the terminal device 01 may store data or instructions for executing the authentication method provided in the embodiment of this specification, and may execute or be used to execute the data or instructions. In some possible implementations, the terminal device 01 may include a hardware device with a data information processing function and the necessary programs required to drive the hardware device to work. When the authentication method provided in one or more embodiments of this specification is executed on the server 02, the server 02 may store data or instructions for executing the authentication method provided in the embodiment of this specification, and may execute or be used to execute the data or instructions. In some possible implementations, the server 02 may include a hardware device with a data information processing function and the necessary programs required to drive the hardware device to work.
[0062] It should be noted that the authentication method provided in the embodiments of this specification can be executed entirely on the terminal device 01, or entirely on the server 02, or partially on the terminal device 01 and partially on the server 02. In the embodiments of this specification, there is no specific limitation on this. Among them, when it is determined that the authentication method is executed entirely on the terminal device 01, the terminal device 01 can independently complete the authentication process. As another example, when the method for determining the verification method is executed entirely on the server 02, the server 02 interacts with the user through the terminal device 01 to complete the collection of user authentication data corresponding to different authentication methods, and performs authentication verification based on the user authentication data locally on the server.
[0063] See also Figure 2 , is a flowchart of a verification method provided in an embodiment of this specification. The execution subject of the process can be an application for executing the verification process, or a device equipped with an application for executing the verification process. Figure 2 The process shown is described in detail, and the authentication method may specifically include the following steps:
[0064] S102, in response to a request for identity verification initiated by a user, obtaining identity verification applicable information corresponding to the user;
[0065] In the embodiments of the present specification, the user may trigger the authentication process in certain specific application scenarios. After the user triggers the authentication process, the authentication applicable information corresponding to the user is searched and obtained in the database according to the user account information.
[0066] The authentication applicable information may include authentication information pre-stored by the user in a database and used to verify the user's identity, and may also include information such as the user's historical authentication records, etc. Based on the authentication applicable information, an authentication method that can be performed can be selected for the user.
[0067] S104, determining a set of authentication methods corresponding to the user according to the authentication applicable information;
[0068] In the embodiment of the present specification, after obtaining the authentication applicable information, the authentication mode set corresponding to the user is determined according to the authentication applicable information. The authentication mode set includes all authentication modes that the user can perform.
[0069] It is to be understood that in one or more embodiments of the present specification, the authentication method that can be performed refers to an authentication method that can effectively verify the identity of the user.
[0070] S106, authenticating the user based on each authentication method in the authentication method set.
[0071] In the embodiments of the present specification, after the authentication method set corresponding to the user is determined, the user may be authenticated according to each authentication method in the authentication method set.
[0072] Among them, the authentication method may include but is not limited to face recognition authentication, document recognition authentication, voiceprint comparison authentication, action verification authentication, question authentication, etc. It is not difficult to understand that different authentication methods can verify the user's identity from different information dimensions. In the embodiments of this specification, the user is authenticated according to multiple authentication methods in the authentication method set, and the user's identity can be authenticated from multiple dimensions, thereby improving the authentication security and effectively resisting Internet black industry attacks.
[0073] In one embodiment of the present specification, the authentication applicable information includes the recorded authentication information that can verify the identity of the user, and the authentication information includes one or more of the facial features, ID images, and voiceprint features corresponding to the user. Then in step S104, the authentication method set corresponding to the user is determined according to the authentication applicable information, which can be: determining the authentication method that the user can perform according to the authentication information, and obtaining the authentication method set, the authentication method is not limited to any one of face recognition verification, ID recognition verification, voiceprint comparison verification, and motion detection verification.
[0074] It is not difficult to understand that authentication is mainly achieved by collecting real-time user authentication data and comparing the real-time collected user authentication data with the authentication information pre-stored in the database to verify whether the user's identity is authentic and reliable. Therefore, it is necessary to determine whether the user can perform the corresponding authentication method based on the authentication information stored in the database. For example, if the user's voiceprint information is not stored in the database, the user cannot be authenticated by voiceprint comparison verification. The database can be located in the user terminal device 01 or in the server 02.
[0075] In one embodiment of the present specification, the authentication applicable information includes the nationality information corresponding to the user and the recorded authentication information that can verify the identity of the user. Then in step S104, the authentication method set corresponding to the user is determined according to the authentication applicable information, which can be: determining the authentication method that the user can perform according to the authentication information and the nationality information, and obtaining the authentication method set, the authentication method is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
[0076] It should be noted that the layout and text of ID cards of people of different nationalities are different, and a specially trained ID card recognition model is required to recognize the ID card of the corresponding nationality. Therefore, when the authentication system does not have an ID card recognition model that can recognize the ID card of the corresponding nationality, even if the recorded authentication information that can verify the identity of the user includes the ID card information, the user cannot be authenticated by using the ID card recognition and verification method. At this time, the ID card recognition and verification method cannot be used as an authentication method that the user can perform.
[0077] In one embodiment of the present specification, the authentication application information includes the user's historical authentication record. Then, in step S104, after determining the authentication method set corresponding to the user according to the authentication application information, it also includes: calculating the authentication failure probability of each authentication method in the authentication method set according to the historical authentication record; eliminating the authentication methods in the authentication method set whose authentication failure probability is greater than a preset probability threshold, and obtaining a new authentication method set.
[0078] It should be noted that in actual application scenarios, users may have low pass rates for authentication methods such as face recognition verification and action recognition verification due to poor makeup and poor action execution ability. In the embodiment, after obtaining the authentication method set corresponding to the user, the authentication failure probability corresponding to each authentication method is calculated based on the user's historical authentication record, and the authentication methods with authentication failure probabilities greater than the preset probability threshold are removed from the authentication method set to avoid authentication failure in a certain authentication method due to the above reasons, which affects the user's experience of using the authentication function.
[0079] See also Figure 3 , is a flowchart of a verification method provided in an embodiment of this specification. The execution subject of the process can be an application for executing the verification process, or a device equipped with an application for executing the verification process. Figure 3 The process shown is described in detail, and the authentication method may specifically include the following steps:
[0080] S202, obtaining authentication information corresponding to the user;
[0081] Specifically, for step S202, please refer to the detailed description of step S102 in another embodiment of this specification, which will not be repeated here.
[0082] S204, determining a set of authentication methods corresponding to the user according to the authentication applicable information;
[0083] Specifically, for step S204, please refer to the detailed description of step S104 in another embodiment of this specification, which will not be repeated here.
[0084] S206, collecting user authentication data corresponding to each authentication method in the authentication method set;
[0085] In the embodiments of the present specification, when authenticating a user based on each authentication method in the authentication method set, firstly, user authentication data corresponding to each authentication method in the authentication method set is collected.
[0086] For example, when authenticating a user based on facial recognition verification, the user authentication data that needs to be collected is the user's facial image data; when authenticating a user based on voiceprint comparison verification, the user authentication data that needs to be collected is the user's voice data.
[0087] S208, sending the authentication data of each user to the corresponding authentication model for authentication.
[0088] In the embodiments of the present specification, after obtaining the user authentication data, the user authentication data corresponding to different authentication methods are sent to the corresponding authentication model to obtain the detection result output by the model, and whether the user identity authentication is passed is determined based on the detection result.
[0089] It should be noted that in one or more embodiments of this specification, the corresponding user authentication data can be obtained in different ways according to different authentication methods. For example, when the authentication method is voiceprint verification, the user's voice data can be collected by calling the user's microphone; when the authentication method is face recognition verification, the user's face image data can be collected by calling the user's camera.
[0090] In a feasible implementation, user verification data is collected by collecting real-time video images of the user. That is, after the user triggers the verification process, the camera is called to collect the real-time video image of the user. The user's corresponding face image, ID image, face movement and other user verification data can be obtained through the real-time video image to meet the collection of user verification data corresponding to different verification methods.
[0091] Furthermore, in one or more embodiments of the present specification, authentication models corresponding to different authentication methods are pre-trained, and the authentication models are used to identify and verify the collected user authentication data to obtain authentication results. For example, the authentication model corresponding to the authentication method of face recognition verification is a face recognition model, the authentication model corresponding to the authentication method of motion recognition verification is a motion recognition model, and the authentication model corresponding to the authentication method of document recognition verification is a document recognition model. Among them, the authentication model corresponding to each authentication method can be located at the server end or at the user end.
[0092] See also Figure 4, is a flowchart of a verification method provided in an embodiment of this specification. The execution subject of the process can be an application for executing the verification process, or a device equipped with an application for executing the verification process. Figure 4 The process shown is described in detail, and the authentication method may specifically include the following steps:
[0093] S302, obtaining authentication information corresponding to the user;
[0094] Specifically, for step S302, please refer to the detailed description of step S102 in another embodiment of this specification, which will not be repeated here.
[0095] S304, determining a set of authentication methods corresponding to the user according to the authentication applicable information;
[0096] Specifically, for step S304, please refer to the detailed description of step S102 in another embodiment of this specification, which will not be repeated here.
[0097] S306, sorting the authentication methods in the authentication method set to obtain an authentication method sequence;
[0098] In the embodiment of this specification, after obtaining the authentication method set corresponding to the user, the authentication methods in the authentication method set are sorted to obtain the authentication method set sequence. The order of the authentication methods in the authentication method set sequence is the order of authenticating the user.
[0099] Optionally, each authentication method in the authentication method set may be sorted in a random manner to obtain an authentication method sequence.
[0100] S308, authenticate the user in sequence based on the order of the authentication methods in the authentication method sequence.
[0101] In the embodiment of the present specification, after obtaining the sequence of authentication methods, the user is authenticated in sequence according to the sequence of authentication methods in the sequence of authentication methods. For example, if the sequence of authentication methods in the sequence of authentication methods is face recognition verification, document recognition verification and voiceprint comparison verification, then when the user is authenticated, the user's face image data is first collected, and face recognition verification is performed based on the face image data, and then after determining that the face recognition verification is passed, the user's document image is collected, and document recognition verification is performed based on the document image, and after determining that the document recognition verification is verified, the user's voice data is collected again, and voiceprint comparison verification is performed based on the voice data, and after determining that the voiceprint verification is passed, it is determined that the user authentication is passed. It should be noted that in the embodiment of the present specification, the user is authenticated in sequence based on each authentication method in the sequence of authentication methods, and only after the previous authentication method is passed, the next authentication method will be enabled to authenticate the user. If any of the authentication methods fails to be verified, it is determined that the user authentication fails and the user identity cannot be determined. By using multiple authentication methods to authenticate users and providing multi-layer protection against black market attacks, authentication security can be significantly improved.
[0102] In one embodiment of the present specification, in step S306, each authentication method in the authentication method set is sorted to obtain an authentication method sequence, which can be as follows: the authentication failure probability corresponding to each authentication method in the authentication method set is calculated according to the historical authentication records; and each authentication method in the authentication method set is sorted in order from low to high in terms of the authentication failure probability to obtain an authentication method sequence.
[0103] In the embodiments of the present specification, each authentication method can be sorted according to the authentication failure probability corresponding to the authentication method calculated according to the historical authentication record. Specifically, each authentication method in the authentication method set can be sorted in order from low to high in terms of the authentication failure probability to obtain an authentication method sequence.
[0104] In actual application scenarios, during the process of sequentially authenticating the user based on each authentication method in the authentication method sequence, since the failure of any authentication method will result in the exit of the authentication process, if the user wants to try authentication again, he needs to restart the authentication process, even if the authentication method that has been passed before still needs to be authenticated again. If the user fails during the authentication of an authentication method with a higher probability of failure after passing through several authentication methods with a lower probability of failure, and then restarts the authentication process, the authentication method that the user passed previously will become meaningless due to the failure of the authentication method with a higher probability of failure, which wastes the user's time. In the embodiments of the present specification, by arranging the authentication methods with a higher probability of failure at the front of the authentication method sequence, and using the authentication methods with a relatively higher probability of failure to authenticate the user in advance, it is possible to avoid the situation where the user fails in the authentication method with a higher probability of failure after passing through several authentication methods with a lower probability of failure, thereby avoiding meaningless waste of time for the user and improving the user experience.
[0105] The historical authentication record may be an authentication record within a preset time period before, or may be all authentication records before. The authentication failure probability is the ratio of the number of authentication failures to the total number of authentications in the historical authentication record.
[0106] In one or more embodiments of this specification, see Figure 5 , is a flow chart of a verification method provided in an embodiment of this specification. Figure 5 As shown, S308, authenticating the user in sequence based on the order of the authentication methods in the authentication method sequence may include the following steps:
[0107] S3081, determining a target authentication method that is ranked first in the authentication method sequence;
[0108] S3082, collecting user authentication data corresponding to the target authentication methods;
[0109] S3083, sending the authentication data of each user to the authentication model corresponding to the target authentication method for authentication;
[0110] S3084, if it is determined that the authentication is successful, the authentication method that is ranked one position after the target authentication method in the authentication method sequence is used as a new target authentication method, and the step of collecting user authentication data corresponding to each target authentication method is performed;
[0111] S3085: If it is determined that the authentication has not passed, the authentication process is exited and an authentication failure prompt message is output.
[0112] In a feasible implementation, user authentication data corresponding to the target authentication method is collected. Specifically, authentication indication information corresponding to the target authentication method is displayed on the authentication interaction page, and the authentication indication information is used to instruct the user to execute action instructions corresponding to the target authentication method so that the terminal device can collect the user authentication data corresponding to the target authentication method.
[0113] Among them, the authentication interaction page is a page displayed on the user side for interacting with the user during the acquisition of user authentication data. The authentication instruction information corresponding to the target authentication method is displayed on the authentication interaction page to instruct the user to execute the action instructions corresponding to the target authentication method, so that the user terminal can collect the user authentication data corresponding to the target authentication method.
[0114] Among them, user authentication data may include but is not limited to one or more of video data, audio data, and gyroscope data. Depending on the authentication method, the type of authentication data that needs to be collected is also different. For example, when the authentication method is motion recognition verification, it is necessary to collect video data containing the user's face image and the gyroscope data of the user terminal. When the authentication method is voiceprint comparison verification, it is necessary to collect audio data containing the user's voice.
[0115] In actual application scenarios, after the authentication process is started, the camera can be called to obtain the user's real-time video screen, and the microphone can be enabled to collect real-time audio data and the posture data of the user terminal can be collected through the gyroscope. The real-time video screen is displayed on the display interface of the user terminal. After the target authentication method is determined, the authentication instruction information corresponding to the target authentication method is displayed on the real-time video screen to instruct the user to execute the action instructions corresponding to the target authentication method, so that the user terminal can collect the user authentication data corresponding to the target authentication method. For example, when the authentication method is action recognition verification, the authentication instruction information can be opening the mouth, turning the head to the left, turning the head to the right, blinking, etc.; when the authentication method is document recognition verification, the authentication instruction information can be: placing the corresponding document in the corresponding position so that the camera can capture a clear document image.
[0116] See also Figure 6 , is a schematic diagram of the structure of a verification device provided in an embodiment of this specification. Figure 6 As shown, the authentication device 1 can be implemented as all or part of the electronic device through software, hardware or a combination of both. According to some embodiments, the authentication device 1 may include a user information acquisition module 11, an authentication method determination module 12, and an authentication module 13, wherein:
[0117] A user information acquisition module 11 is used to acquire authentication applicable information corresponding to the user;
[0118] An authentication method determination module 12 is used to determine an authentication method set corresponding to the user according to the authentication applicable information;
[0119] The authentication module 13 is used to authenticate the user based on each authentication method in the authentication method set.
[0120] Optionally, the authentication applicable information includes recorded authentication information that can verify the identity of the user, and the authentication information includes one or more of facial features, ID images, and voiceprint features corresponding to the user;
[0121] The authentication method determination module 12 is specifically used for:
[0122] Determine the authentication methods that the user can perform based on the authentication information to obtain the authentication method set, which includes but is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
[0123] Optionally, the identity verification applicable information also includes nationality information corresponding to the user;
[0124] The authentication method determination module 12 is specifically used for:
[0125] Determine the authentication methods that the user can perform based on the authentication information and the nationality information to obtain the authentication method set, which includes but is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
[0126] Optionally, the authentication applicable information includes the user's historical authentication record;
[0127] After executing the step of determining the authentication mode set corresponding to the user according to the authentication applicable information, the authentication mode determination module 12 is further configured to:
[0128] Calculate the authentication failure probability of each authentication method in the authentication method set according to the historical authentication record;
[0129] Authentication methods whose authentication failure probability is greater than a preset probability threshold are eliminated from the authentication method set to obtain a new authentication method set.
[0130] Optionally, the authentication module 13 is specifically used for:
[0131] Collecting user authentication data corresponding to each authentication method in the authentication method set;
[0132] The authentication data of each user is sent to the corresponding authentication model for authentication.
[0133] Optional, see Figure 7 The device further comprises a sequence generating module 14, which is specifically used for:
[0134] Sorting each authentication method in the authentication method set to obtain an authentication method sequence;
[0135] Optionally, the authentication module 13 is specifically used for:
[0136] The user is authenticated in sequence based on the order of the authentication methods in the authentication method sequence.
[0137] Optionally, the sequence generation module 14 is specifically used to:
[0138] Calculate the authentication failure probability corresponding to each authentication method in the authentication method set according to the historical authentication records;
[0139] The authentication methods in the authentication method set are sorted in order from low to high probability of authentication failure to obtain an authentication method sequence.
[0140] Optionally, when the authentication module 13 performs authentication on the user in sequence based on the authentication modes in the authentication mode sequence, it is specifically configured to:
[0141] Determine a target authentication method that is ranked first in the authentication method sequence;
[0142] Collecting user authentication data corresponding to the target authentication methods;
[0143] Sending the authentication data of each user to the authentication model corresponding to the target authentication method for authentication;
[0144] If it is determined that the authentication is successful, the authentication method that is ranked one position after the target authentication method in the authentication method sequence is used as the new target authentication method, and the step of collecting user authentication data corresponding to each of the target authentication methods is performed;
[0145] If it is determined that the authentication has not passed, the authentication process will be exited and an authentication failure prompt message will be output.
[0146] Optionally, the user authentication data includes but is not limited to one or more of video data, audio data, and gyroscope data.
[0147] Optionally, when the authentication module 13 collects the user authentication data corresponding to the target authentication modes, it is specifically used to:
[0148] The authentication instruction information corresponding to the target authentication method is displayed on the authentication interaction page, and the authentication instruction information is used to instruct the user to execute the action instruction corresponding to the target authentication method so that the terminal device can collect the user authentication data corresponding to the target authentication method.
[0149] The above device embodiments correspond to the method embodiments. For specific descriptions, please refer to the description of the method embodiments, which will not be repeated here. The device embodiments are obtained based on the corresponding method embodiments and have the same technical effects as the corresponding method embodiments. For specific descriptions, please refer to the corresponding method embodiments.
[0150] The embodiments of this specification also provide a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the authentication method described above is implemented. The specific execution process can be found in the specific description of the relevant embodiments of the authentication method, which will not be repeated here.
[0151] This specification also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor as the above-mentioned authentication method. The specific execution process can be found in the specific description of the relevant embodiments of the authentication method, which will not be repeated here.
[0152] The embodiments of this specification also provide Figure 8 The structural diagram of the electronic device shown in FIG. Figure 8 At the hardware level, the electronic device may include a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above-mentioned authentication method. The specific execution process can be referred to the specific description of the relevant embodiments of the authentication method, which will not be repeated here.
[0153] Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is to say, the executor of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0154] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for computer-readable storage media, computer program products and Figure 8 As for the electronic device shown, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0155] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.
[0156] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.
[0157] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0158] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0159] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0160] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0161] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0162] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0163] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0164] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0165] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0166] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0167] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0168] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0169] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0170] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.
Claims
1. A verification method, comprising: Obtaining authentication information corresponding to the user; Determine a set of authentication methods corresponding to the user according to the authentication applicable information; The user is authenticated based on each authentication method in the authentication method set.
2. According to the method of claim 1, the authentication applicable information includes recorded authentication information that can verify the identity of the user, and the authentication information includes one or more of facial features, ID images, and voiceprint features corresponding to the user; The determining, according to the authentication applicable information, a set of authentication methods corresponding to the user includes: Determine the authentication methods that the user can perform based on the authentication information to obtain the authentication method set, which includes but is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
3. According to the method of claim 2, the authentication applicable information further includes the nationality information of the user; The determining, according to the authentication applicable information, a set of authentication methods corresponding to the user includes: Determine the authentication methods that the user can perform based on the authentication information and the nationality information to obtain the authentication method set, which includes but is not limited to any one of face recognition verification, document recognition verification, voiceprint comparison verification, and motion detection verification.
4. The method according to claim 1, wherein the authentication applicable information includes the user's historical authentication record; After determining the authentication method set corresponding to the user according to the authentication applicable information, the method further includes: Calculate the authentication failure probability of each authentication method in the authentication method set according to the historical authentication record; Authentication methods whose authentication failure probability is greater than a preset probability threshold are eliminated from the authentication method set to obtain a new authentication method set.
5. The method according to claim 1, wherein authenticating the user based on each authentication method in the authentication method set comprises: Collecting user authentication data corresponding to each authentication method in the authentication method set; The authentication data of each user is sent to the corresponding authentication model for authentication.
6. The method according to claim 1, before authenticating the user based on each authentication method in the authentication method set, further comprising: Sorting each authentication method in the authentication method set to obtain an authentication method sequence; The authenticating the user based on each authentication method in the authentication method set includes: The user is authenticated in sequence based on the order of the authentication methods in the authentication method sequence.
7. The method according to claim 6, wherein the step of sorting the authentication methods in the authentication method set to obtain the authentication method sequence comprises: Calculate the authentication failure probability corresponding to each authentication method in the authentication method set according to the historical authentication records; The authentication methods in the authentication method set are sorted in order from low to high probability of authentication failure to obtain an authentication method sequence.
8. The method according to claim 6, wherein the step of sequentially authenticating the user based on the order of the authentication modes in the authentication mode sequence comprises: Determine a target authentication method that is ranked first in the authentication method sequence; Collecting user authentication data corresponding to the target authentication methods; Sending the authentication data of each user to the authentication model corresponding to the target authentication method for authentication; If it is determined that the authentication is successful, the authentication method that is ranked one position after the target authentication method in the authentication method sequence is used as a new target authentication method, and the step of collecting user authentication data corresponding to each of the target authentication methods is performed; If it is determined that the authentication has not passed, the authentication process will be exited and an authentication failure prompt message will be output.
9. According to the method described in any one of claims 5 or 8, the user authentication data includes but is not limited to one or more of video data, audio data, and gyroscope data.
10. According to the method of claim 8, the collecting of user authentication data corresponding to the target authentication modes respectively comprises: The authentication instruction information corresponding to the target authentication method is displayed on the authentication interaction page, and the authentication instruction information is used to instruct the user to execute the action instruction corresponding to the target authentication method so that the terminal device can collect the user authentication data corresponding to the target authentication method.
11. A verification device, comprising: A user information acquisition module, used to acquire authentication applicable information corresponding to the user; An authentication method determination module is used to determine an authentication method set corresponding to the user according to the authentication applicable information; An authentication module is used to authenticate the user based on each authentication method in the authentication method set.
12. A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method according to any one of claims 1 to 10.
13. An electronic device comprising: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the steps of the method as claimed in any one of claims 1 to 10.
14. A computer program product having at least one instruction stored thereon, wherein when the at least one instruction is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.