Identity verification method and device, storage medium and electronic equipment

By using ultrasonic information and real-time ultrasonic audio verification methods during the authentication process, the security problem of artificial intelligence generating fake videos for authentication is solved, achieving higher authentication security and user experience.

CN120050086APending Publication Date: 2025-05-27ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510192628.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

With the development of artificial intelligence content generation technology, attackers can authenticate by generating fake videos, infringing on the interests of users and threatening the security of user identity verification.

Method used

By using ultrasonic information during the authentication process, the server sends ultrasonic information to the terminal, causing the terminal to play standard ultrasonic audio and collects real-time ultrasonic audio. The server verifies the collected real-time ultrasonic audio to determine the user's identity verification results.

Benefits of technology

By using ultrasonic audio in identity authentication, the security of user authentication is improved, preventing attackers from impersonating identity by injecting fake videos without causing interference to users, and maintaining a good user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050086A_ABST
    Figure CN120050086A_ABST
Patent Text Reader

Abstract

The invention discloses an identity verification method and device, a storage medium and electronic equipment, and the method comprises the steps: enabling a server to transmit ultrasonic information to a terminal during identity verification, enabling the terminal to play a standard ultrasonic audio through the ultrasonic information, collecting the real-time ultrasonic audio of a user during identity verification, and transmitting the real-time ultrasonic audio to the terminal; the verification information including the real-time ultrasonic audio is sent to a server, and the server verifies the verification information including the real-time ultrasonic audio. The ultrasonic audio is added during identity verification, the real-time ultrasonic audio is verified, and the ultrasonic audio exceeds the hearing range of human ears, so that an attacker is difficult to perceive that verification information further comprises the ultrasonic audio, the ultrasonic audio cannot be added into an injected false video, and the safety of a user during identity verification is improved. And the ultrasonic audio frequency exceeds the hearing range of human ears, so that any interference is not caused to the user, and the user still has good experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computers, and in particular, to an identity authentication method, apparatus, storage medium, and electronic device. Background Art

[0002] With the development of Internet technology, users can conduct shopping, registration services, etc. through the network. When a user performs a service, identity authentication can be performed first to ensure the secure execution of the service, such as identity authentication through face recognition. However, with the development of Artificial Intelligence Generated Content (AIGC) technology, attackers can use AIGC to generate false videos of users, which include the user's face, nodding, shaking the head, and other specified action contents. Then, through injection attacks, the false videos are injected into the server side or the terminal side for identity authentication to infringe on the interests of users.

[0003] Therefore, how to improve the security of user identity authentication is an urgent problem to be solved.

[0004] Based on this, this specification provides an identity authentication method. Summary of the Invention

[0005] This specification provides an identity authentication method, apparatus, storage medium, and electronic device to at least partially solve the above problems existing in the prior art.

[0006] This specification adopts the following technical solutions:

[0007] This specification provides an identity authentication method, which is applied to a server and includes:

[0008] Receiving an identity authentication data acquisition request sent by a terminal in response to a user's identity authentication operation;

[0009] Based on the identity authentication data acquisition request, determining an identity authentication interface and determining ultrasonic information;

[0010] Returning the identity authentication interface and the ultrasonic information to the terminal, so that the terminal displays the identity authentication interface to the user and plays a standard ultrasonic audio based on the ultrasonic information;

[0011] Receiving verification information including real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation, where the real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio;

[0012] Verify the verification information including the real-time ultrasonic audio to obtain the user's identity verification result, and return the identity verification result to the terminal so that the terminal can display the identity verification result to the user.

[0013] Optionally, the ultrasonic information includes a standard ultrasonic audio or ultrasonic signal parameters;

[0014] Determining the ultrasonic information specifically includes:

[0015] Obtain ultrasonic signal parameters;

[0016] When the ultrasonic information includes a standard ultrasonic audio, based on the ultrasonic signal parameters, determine the standard ultrasonic audio and determine the standard ultrasonic audio as the ultrasonic information;

[0017] When the ultrasonic information includes ultrasonic signal parameters, determine the ultrasonic signal parameters as the ultrasonic information so that the terminal can determine the standard ultrasonic audio based on the ultrasonic signal parameters and play it.

[0018] Optionally, the ultrasonic signal parameters include a verification code;

[0019] Based on the ultrasonic signal parameters, determining the standard ultrasonic audio specifically includes:

[0020] Based on a preset coding method, determine the correspondence between the verification code characters and the ultrasonic frequencies; or

[0021] Determine a coding identifier, and based on the coding identifier, determine the correspondence between the verification code characters and the ultrasonic frequencies;

[0022] According to the correspondence, encode the verification code to obtain the standard ultrasonic audio.

[0023] Optionally, verifying the verification information including the real-time ultrasonic audio to obtain the user's identity verification result specifically includes:

[0024] Decode the real-time ultrasonic audio to obtain decoding parameters;

[0025] Determine whether the decoding parameters match the verification code;

[0026] If so, determine the user's identity verification result as parameter verification successful.

[0027] Optionally, the verification information further includes at least one of the user's face image and the user's verification video;

[0028] Verify the verification information including the real-time ultrasonic audio to obtain the user's identity verification result, specifically including:

[0029] When the verification information includes the user's face image, determine whether there is a face in the pre-stored face information database that matches the user's face image;

[0030] If there is, determine the user's identity verification result as successful face verification.

[0031] Optionally, when the verification information includes the user's verification video, verify the verification information including the real-time ultrasonic audio to obtain the user's identity verification result, specifically including:

[0032] Judge whether the user has performed an action according to the verification video;

[0033] If so, when the action feature of the user in the verification video matches the action feature of the specified action, determine the user's identity verification result as successful liveness verification;

[0034] If not, determine the user's identity verification result as unsuccessful liveness verification.

[0035] Optionally, the method further includes:

[0036] When at least one of the real-time ultrasonic audio, the user's face image, and the user's verification video fails to be verified, determine the user's identity verification result as verification failed.

[0037] This specification provides an identity verification method, which is applied to a terminal and includes:

[0038] In response to the user's identity verification operation, send an identity verification data acquisition request to the server;

[0039] Receive the identity verification interface and ultrasonic information returned by the server based on the identity verification data acquisition request;

[0040] Display the identity verification page to the user so that the user can perform an identity verification operation based on the identity verification interface; based on the ultrasonic information, play a standard ultrasonic audio and collect real-time ultrasonic audio;

[0041] In response to the user's verification completion operation, send the verification information including the real-time ultrasonic audio to the server, so that the server verifies the verification information including the real-time ultrasonic audio to obtain the user's identity verification result and return it;

[0042] Receive the authentication result of the user sent by the server and display it.

[0043] Optionally, the ultrasonic information includes a standard ultrasonic audio or ultrasonic signal parameters;

[0044] Based on the ultrasonic information, playing the standard ultrasonic audio specifically includes:

[0045] When the ultrasonic information includes a standard ultrasonic audio, play the standard ultrasonic audio;

[0046] When the ultrasonic information includes ultrasonic signal parameters, based on the ultrasonic signal parameters, determine the standard ultrasonic audio and play it.

[0047] Optionally, the ultrasonic signal parameters include a verification code;

[0048] Based on the ultrasonic signal parameters, determining the standard ultrasonic audio specifically includes:

[0049] Based on a preset coding method or based on the coding identifier in the ultrasonic signal parameters, determine the correspondence between the verification code characters and the ultrasonic frequencies;

[0050] According to the correspondence, encode the verification code to obtain the standard ultrasonic audio.

[0051] This specification provides an authentication device, which is applied to a server. The device includes:

[0052] An authentication data acquisition request receiving module, configured to receive an authentication data acquisition request sent by a terminal in response to a user's authentication operation;

[0053] An authentication data determination module, configured to determine an authentication interface and determine ultrasonic information based on the authentication data acquisition request;

[0054] An authentication data return module, configured to return the authentication interface and the ultrasonic information to the terminal, so that the terminal displays the authentication interface to the user and plays a standard ultrasonic audio based on the ultrasonic information;

[0055] A verification information receiving module, configured to receive verification information including a real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation, where the real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio;

[0056] A verification module is used to verify the verification information including the real-time ultrasonic audio, obtain the identity verification result of the user, and return the identity verification result to the terminal, so that the terminal can display the identity verification result to the user.

[0057] Optionally, the ultrasonic information includes a standard ultrasonic audio or ultrasonic signal parameters;

[0058] The identity verification data determination module is specifically configured to obtain ultrasonic signal parameters; when the ultrasonic information includes a standard ultrasonic audio, based on the ultrasonic signal parameters, determine the standard ultrasonic audio, and determine the standard ultrasonic audio as the ultrasonic information; when the ultrasonic information includes ultrasonic signal parameters, determine the ultrasonic signal parameters as the ultrasonic information, so that the terminal can determine the standard ultrasonic audio based on the ultrasonic signal parameters and play it.

[0059] Optionally, the ultrasonic signal parameters include a verification code;

[0060] The identity verification data determination module is specifically configured to determine the correspondence between the verification code characters and the ultrasonic frequency based on a preset coding method; or determine a coding identifier, and based on the coding identifier, determine the correspondence between the verification code characters and the ultrasonic frequency; according to the correspondence, encode the verification code to obtain a standard ultrasonic audio.

[0061] Optionally, the verification module is specifically configured to decode the real-time ultrasonic audio to obtain decoding parameters; determine whether the decoding parameters match the verification code; if so, determine the identity verification result of the user as parameter verification successful.

[0062] Optionally, the verification information further includes at least one of the user's face image and the user's verification video;

[0063] The verification module is specifically configured to, when the verification information includes the user's face image, determine whether there is a face in the pre-stored face information database that matches the user's face image according to the pre-stored face information database; if so, determine the identity verification result of the user as face verification successful.

[0064] Optionally, when the verification information includes the user's verification video, the verification module is specifically configured to determine whether the user has performed an action according to the verification video; if so, when the action feature of the user in the verification video matches the action feature of the specified action, determine the identity verification result of the user as liveness verification successful; if not, determine the identity verification result of the user as liveness verification unsuccessful.

[0065] Optionally, the verification module is specifically configured to determine that the user's identity verification result fails when at least one of the real-time ultrasonic audio, the user's face image, and the user's verification video fails to be verified.

[0066] This specification provides an identity verification device, which is applied to a terminal. The device includes:

[0067] An identity verification data acquisition request sending module, configured to send an identity verification data acquisition request to a server in response to a user's identity verification operation;

[0068] An identity verification data receiving module, configured to receive an identity verification interface and ultrasonic information returned by the server based on the identity verification data acquisition request;

[0069] A verification information acquisition module, configured to display the identity verification page to the user, so that the user performs an identity verification operation based on the identity verification interface; based on the ultrasonic information, play a standard ultrasonic audio, and collect real-time ultrasonic audio;

[0070] A verification information sending module, configured to send verification information including real-time ultrasonic audio to the server in response to the user's verification completion operation, so that the server verifies the verification information including the real-time ultrasonic audio to obtain the user's identity verification result and return it;

[0071] A verification result receiving module, configured to receive and display the user's identity verification result sent by the server.

[0072] Optionally, the ultrasonic information includes a standard ultrasonic audio or ultrasonic signal parameters; the verification information acquisition module is specifically configured to play the standard ultrasonic audio when the ultrasonic information includes the standard ultrasonic audio; when the ultrasonic information includes ultrasonic signal parameters, determine a standard ultrasonic audio based on the ultrasonic signal parameters and play it.

[0073] Optionally, the ultrasonic signal parameters include a verification code;

[0074] The verification information acquisition module is specifically configured to determine the correspondence between verification code characters and ultrasonic frequencies based on a preset encoding method or based on an encoding identifier in the ultrasonic signal parameters; encode the verification code according to the correspondence to obtain a standard ultrasonic audio.

[0075] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above identity verification method is implemented.

[0076] This specification provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the above authentication method is implemented.

[0077] The above at least one technical solution adopted in this specification can achieve the following beneficial effects:

[0078] In the authentication method provided in this specification, the server first receives an authentication data acquisition request sent by the terminal in response to the user's authentication operation. Based on this authentication data acquisition request, an authentication interface is determined, and ultrasonic information is determined. Then, the authentication interface and the ultrasonic information are returned to the terminal, so that the terminal displays the authentication interface to the user and plays a standard ultrasonic audio based on the ultrasonic information. Then, the server receives the authentication information including the real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation. The real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio. Finally, the authentication information including the real-time ultrasonic audio is verified to obtain the user's authentication result, and the authentication result is returned to the terminal, so that the terminal displays the authentication result to the user.

[0079] It can be seen from the above method that during authentication, the server can send ultrasonic information to the terminal, so that the terminal plays a standard ultrasonic audio through the ultrasonic information, and collects the real-time ultrasonic audio of the user during authentication, and sends the authentication information including the real-time ultrasonic audio to the server. The server verifies the authentication information including the real-time ultrasonic audio. By adding ultrasonic audio during authentication and verifying the real-time ultrasonic audio, since the ultrasonic audio is beyond the audible range of the human ear, it is difficult for attackers to detect that the authentication information also includes ultrasonic audio and cannot add ultrasonic audio to the injected false video, improving the security of the user during authentication. And since the ultrasonic audio is beyond the audible range of the human ear, it will not cause any interference to the user, and the user still has a good experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] The drawings described herein are used to provide a further understanding of this specification, and constitute a part of this specification. The illustrative embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation of this specification. In the attached

[0081] In the figure:

[0082] Figure 1 is a schematic flow chart of an authentication method provided by this specification;

[0083] Figure 2A schematic diagram of the interaction between a terminal and a server provided in this specification;

[0084] Figure 3 A schematic diagram of the interaction between a server and a terminal provided in this specification;

[0085] Figure 4 A schematic diagram of the verification process provided in this specification;

[0086] Figure 5 A schematic diagram of the verification image verification process provided in this specification;

[0087] Figure 6 A schematic diagram of the process for determining the standard ultrasonic audio provided in this specification;

[0088] Figure 7 A schematic diagram of the determined standard ultrasonic audio provided in this specification;

[0089] Figure 8 Another schematic diagram of the determined standard ultrasonic audio provided in this specification;

[0090] Figure 9 A schematic diagram of an identity verification device provided in this specification;

[0091] Figure 10 Corresponding to Figure 1 the schematic diagram of the electronic device. Detailed implementation manners

[0092] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the scope of protection of this application.

[0093] The technical solutions provided in each embodiment of this specification will be described in detail below in conjunction with the drawings.

[0094] When users perform various services, in order to determine the identity of the users and reduce the risk of users suffering losses, identity verification is usually carried out before the users perform the services. Among them, the services may include payment services, etc., and this specification does not limit this. During the identity verification process, the identity of the user can be verified by taking pictures of the user's face, etc. However, with the development of AIGC technology, attackers can use AIGC technology to forge the user's face, forge videos of the user performing specified actions, etc. Then, the forged verification information is injected into the terminal side or the server side for verification through injection attacks, which infringes on the interests of users. Therefore, this specification provides an identity verification method. The execution entities of this specification include the server and the terminal, and this specification does not limit the types of the terminal and the server. For example, the terminal can be a smart phone, a tablet computer, etc.

[0095] Figure 1 It is a schematic flow diagram of an identity verification method provided by this specification, specifically including the following steps:

[0096] S100: Receive the identity verification data acquisition request sent by the terminal in response to the user's identity verification operation.

[0097] In one or more embodiments of this specification, the user can perform identity verification through the terminal.

[0098] Figure 2 It is a schematic diagram of the interaction between the terminal and the server provided by this specification. For example Figure 2 As shown, assuming the terminal is a smart phone, the user can click the identity verification button displayed on the smart phone to perform identity verification. Of course, the user can also perform identity verification through other identity verification operations, and this specification does not limit this.

[0099] Figure 3 It is a schematic diagram of the interaction between the server and the terminal provided by this specification. For example Figure 3 As shown.

[0100] The terminal sends an identity verification data acquisition request to the server in response to the user's identity verification operation, and the server receives the identity verification data acquisition request sent by the terminal in response to the user's identity verification operation, so as to determine the identity verification data for subsequent verification based on the identity verification data acquisition request.

[0101] S102: Based on the identity verification data acquisition request, determine the identity verification interface and determine the ultrasonic information.

[0102] After receiving an authentication data acquisition request, the server can determine the authentication interface for authentication and determine ultrasonic information. Among them, the authentication interface can include instructions for guiding the user to perform specified actions, such as instructions for guiding the user to nod, shake the head, etc., and can also include verification texts that the user needs to dictate, such as random numbers, random texts, etc. It can also include prompt texts for prompting the user to input the account password, etc. This specification does not limit the specific data content included in the authentication interface, but the specific data content included in the authentication interface needs to match the subsequent verification information. For example, if the authentication interface includes instructions for guiding the user to perform specified actions, the verification information returned by the terminal received by the server should include verification images. If the authentication interface includes prompt texts for prompting the user to input the account password, the verification information returned by the terminal received by the server should include the user's account password.

[0103] It should be noted that the ultrasonic information can include standard ultrasonic audio or ultrasonic signal parameters. When the server determines the ultrasonic information, for different ultrasonic information, the server has different methods for determining the ultrasonic information. Specifically, it can be divided into two cases: the server determines the standard ultrasonic audio and the terminal determines the standard ultrasonic audio. When the server determines the standard ultrasonic audio, the ultrasonic information can include the standard ultrasonic audio. When the terminal determines the standard ultrasonic audio, the ultrasonic information includes ultrasonic signal parameters.

[0104] When determining the standard ultrasonic audio, the server can first obtain ultrasonic parameters. After that, if it is the server that determines the standard ultrasonic audio, the server can determine the standard ultrasonic audio based on the ultrasonic signal parameters and determine the standard ultrasonic audio as the ultrasonic information. If it is the terminal that determines the standard ultrasonic audio, the server can determine the ultrasonic signal parameters as the ultrasonic information so that the terminal can determine the standard ultrasonic audio based on the ultrasonic signal parameters and play it.

[0105] In addition, the server can also directly obtain historical ultrasonic audio, use the historical ultrasonic audio as the standard ultrasonic audio, and then determine the standard ultrasonic audio as the ultrasonic information.

[0106] S104: Return the authentication interface and the ultrasonic information to the terminal so that the terminal can display the authentication interface to the user and play the standard ultrasonic audio based on the ultrasonic information.

[0107] Specifically, the server returns the authentication interface and the ultrasonic information to the terminal. The terminal receives the authentication interface and the ultrasonic information returned by the server, and displays the authentication page to the user, so that the user can perform an authentication operation based on the authentication interface. For example, the authentication interface displays text instructing the user to nod. The user performs a nodding action according to the text displayed on the authentication interface.

[0108] In addition, the terminal can also play the standard ultrasonic audio based on the ultrasonic information and collect real-time ultrasonic audio for subsequent server verification of the user's identity.

[0109] Furthermore, if the server determines the standard ultrasonic audio, the ultrasonic information includes the standard ultrasonic audio, and there is no need for the terminal to determine it again. The terminal can directly play the standard ultrasonic audio. If the terminal determines the standard ultrasonic audio, the ultrasonic information includes ultrasonic signal parameters. The terminal can determine the standard ultrasonic audio based on the ultrasonic signal parameters and play it. This specification does not limit the way the terminal plays the standard ultrasonic audio. For example, it can be played through a speaker or through a receiver.

[0110] S106: Receive the verification information including the real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation. The real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio.

[0111] When the terminal plays the standard ultrasonic audio, it also collects real-time ultrasonic audio. At the same time, it can also obtain other verification information, including at least one of the user's face image and the user's verification video. All types of verification information obtained by the terminal need to be sent to the server so that the server can verify the verification information to determine the user's authentication result. Then, in response to the user's verification completion operation, the terminal sends the verification information including the real-time ultrasonic audio to the server. The server receives the verification information including the real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation for verification.

[0112] It should be noted that the terminal can also obtain the user's input account password, etc. through the authentication interface. This specification does not limit this. Multiple verification information can improve the security of user authentication.

[0113] S108: Verify the verification information including the real-time ultrasonic audio to obtain the user's authentication result, and return the authentication result to the terminal so that the terminal can display the authentication result to the user.

[0114] The verification information may include at least one of the collected real-time ultrasonic audio, the face image of the user, and the verification video of the user, and may also include other verification information, which is not limited in this specification. In one or more embodiments of this specification, the verification information including the foregoing three types is taken as an example for illustration. The server needs to verify the foregoing verification information one by one. This specification does not limit the verification order of the foregoing verification information. And when at least one of the real-time ultrasonic audio, the face image of the user, and the verification video of the user fails to be verified, the identity verification result of the user is determined to be verification failed, and the identity verification result of the user is returned to the terminal. The terminal receives the identity verification result of the user sent by the server and displays it. For example, first verify the face image of the user. When the identity verification result of the user is face verification failed, there is no need to verify the real-time ultrasonic audio and the verification video of the user, and the identity verification result of the user is directly determined to be verification failed. Then, return the verification failed to the terminal so that the terminal can display the verification result of the verification failed to the user.

[0115] Figure 4 It is a schematic diagram of the verification process provided in this specification, as Figure 4 shown.

[0116] Taking the example of first verifying the real-time ultrasonic audio, then verifying the face image of the user, and finally verifying the verification video of the user. When verifying the real-time ultrasonic audio, if the standard ultrasonic audio is determined by the terminal, the server can decode the real-time ultrasonic audio according to the decoding method corresponding to the encoding method to obtain decoding parameters. Among them, the encoding method can be fixed or random, which will be described in detail later and will not be elaborated here. Then, determine whether the decoding parameters match the ultrasonic signal parameters. If so, the identity verification result of the user is determined to be parameter verification successful. If not, return verification failed to the terminal. If the standard ultrasonic audio is determined by the server, then, in addition to the foregoing verification method, the server can also determine whether the real-time ultrasonic audio matches the standard ultrasonic audio. Specifically, it can determine whether the audio features of the real-time ultrasonic audio match the audio features of the standard ultrasonic audio, and other methods can also be used to determine whether the real-time ultrasonic audio matches the standard ultrasonic audio, which is not limited in this specification.

[0117] When the parameter verification is successful, the server can determine whether there is a face that matches the user's face image according to the pre-stored face information database. If there is a match, the server determines that the user's identity verification is successful. If not, the server returns a verification failure to the terminal. Of course, the terminal can also send the user's account identifier to the server. The server determines the face image corresponding to the account identifier in the pre-stored face information database and determines whether the face image corresponding to the account identifier matches the face image in the verification information to obtain the face verification result. Among them, face image matching can compare the image features of the face images. If the image features are the same or the similarity is greater than the preset similarity threshold, the face images match. This specification does not limit the specific method for determining whether face images match.

[0118] When the face verification is successful, the server can verify the user's verification video and determine whether the user's verification video is successful. If the verification result of the verification video is also successful, the server determines that the user's identity verification is successful and returns the successful identity verification to the terminal. The terminal receives and displays it to the user so that the user can perform subsequent services. If not, the server returns a verification failure to the terminal.

[0119] Based on Figure 1 In the identity verification method shown above, when performing identity verification, the server can send ultrasonic information to the terminal so that the terminal plays a standard ultrasonic audio through the ultrasonic information and collects the real-time ultrasonic audio of the user during identity verification, and sends the verification information including the real-time ultrasonic audio to the server. The server verifies the verification information including the real-time ultrasonic audio. By adding ultrasonic audio during identity verification and verifying the real-time ultrasonic audio, since the ultrasonic audio is beyond the audible range of the human ear, it is difficult for attackers to detect that the verification information also includes ultrasonic audio and impossible to add ultrasonic audio to the injected fake video, thereby improving the security of the user during identity verification. And since the ultrasonic audio is beyond the audible range of the human ear, it will not cause any interference to the user, and the user still has a good experience.

[0120] Regarding step S108, Figure 5 This is a schematic diagram of the verification process of the verification video provided in this specification, as Figure 5 shown.

[0121] When verifying the user's verification image, the server can first determine whether the user has performed an action. If so, it can then determine whether the action performed by the user is the specified action. Specifically, the server first determines, based on the verification image, whether the user has performed an action. If not, the server determines that the live verification of the user's identity is unsuccessful. If so, it can determine whether the action characteristics of the user match the action characteristics of the specified action to determine whether the action performed by the user is the specified action. When the action characteristics of the user in the verification image match the action characteristics of the specified action, the server determines that the live verification of the user's identity is successful. Other methods can also be used to determine whether the action performed by the user is the specified action. This specification does not limit how to determine whether the user has performed an action, how to determine whether the action characteristics of the user match the action characteristics of the specified action, and how to determine whether the user has performed an action.

[0122] Embodiment 1: When the server determines the standard ultrasonic audio

[0123] Regarding step S102, Figure 6 is a schematic flowchart of the process for determining the standard ultrasonic audio provided in this specification, as Figure 6 shown.

[0124] Based on different coding methods, the specific content included in the ultrasonic parameters also varies. The ultrasonic parameters can include only the verification code, or can also include the verification code and the coding identifier. Specifically, when the server determines the standard ultrasonic audio, if it is a fixed coding method, the ultrasonic parameters obtained by the server include only the verification code. The verification code can include several random numbers or can be a fixed value. This specification does not limit this. If it is a random number, the number of digits of the random number is positively correlated with security, that is, the more digits the random number has, the higher the security during user verification. The server can determine the correspondence between the verification code characters and the ultrasonic frequency based on a preset coding method, and encode the verification code according to this correspondence to obtain the standard ultrasonic audio. Among them, the preset coding method is the fixed coding method. The fixed coding method means that during coding, the correspondence between the verification code characters and the ultrasonic frequency is fixed, and the ultrasonic frequency is greater than or equal to 20,000 Hz, which is greater than the audible range of the human ear.

[0125] Figure 7 is a schematic diagram of the determined standard ultrasonic audio provided in this specification, as Figure 7 shown.

[0126] For example, in a preset encoding method, the ultrasonic frequency corresponding to the binary number 0 is 20000 Hz, and the ultrasonic frequency corresponding to the binary number 1 is 20100 Hz. The binary numbers 0 and 1 are the verification code characters, and a verification code can be determined according to several verification code characters. Suppose the verification code is a three-digit random number, and the random number is the decimal number 223. Then, the decimal number 2 can be converted to the binary number 0010, and the decimal number 3 can be converted to the binary number 0011. Then, according to the preset encoding method, the random number 223 is encoded to obtain an ultrasonic frequency signal sequence of 20000 Hz(0), 20000 Hz(0), 20100 Hz(1), 20000 Hz(0), 20000 Hz(0), 20000 Hz(0), 20100 Hz(1), 20000 Hz(0), 20000 Hz(0), 20000 Hz(0), 20100 Hz(1), 20100 Hz(1). Based on this ultrasonic frequency signal sequence, the standard ultrasonic audio can be obtained.

[0127] Since the verification code is several random numbers, when the standard ultrasonic audio is determined by the server according to the verification code, even if the correspondence between the verification code characters and the ultrasonic frequency is fixed, different standard ultrasonic audios will be generated for each verification. The attacker cannot determine the random numbers and it is even more difficult to generate the correct ultrasonic audio based on the random numbers, solving the problem that the attacker can replace the user for identity verification through injection attacks and improving the security of user identity verification.

[0128] When the server determines the standard ultrasonic audio, if it is a random encoding method, the ultrasonic parameters obtained by the server include the verification code and the encoding identifier. In a pre-established encoding identifier library, based on this encoding identifier, the correspondence between the verification code characters and the ultrasonic frequency is determined. Among them, the pre-established encoding identifier library includes several correspondences between the verification code characters and the ultrasonic frequency. For example, when the encoding identifier is a, the ultrasonic frequency corresponding to the binary number 0 is 30000 Hz, and the ultrasonic frequency corresponding to the binary number 1 is 30100 Hz. When the encoding identifier is b, the ultrasonic frequency corresponding to the binary number 0 is 20500 Hz, and the ultrasonic frequency corresponding to the binary number 1 is 20200 Hz, etc. After the server determines the correspondence, it can encode the verification code according to this correspondence to obtain the standard ultrasonic audio.

[0129] It can be understood that the correspondence between the verification code characters and the ultrasonic frequency can also change randomly. Then, in the case where the correspondence between the verification code characters and the ultrasonic frequency changes randomly and the verification code also changes randomly, the difficulty for the attacker to generate the correct ultrasonic audio is further increased, thereby improving the security of user identity verification.

[0130] For step S108, correspondingly, when the server performs verification, the server may decode the real-time ultrasonic audio according to the decoding method corresponding to the encoding method to obtain decoding parameters, and determine whether the decoding parameters match the verification code. If so, the identity verification result of the user is determined to be successful in parameter verification.

[0131] Specifically, when the standard ultrasonic audio is obtained based on a preset encoding method, the real-time ultrasonic audio is decoded according to the decoding method corresponding to the preset encoding method to obtain decoding parameters. When the standard ultrasonic audio is encoded based on the corresponding relationship determined by the encoding identifier, the decoding method is determined according to the encoding identifier, and the real-time ultrasonic audio is decoded according to the decoding method to obtain decoding parameters.

[0132] It should be noted that the identity verification data acquisition request received by the server in S100 may also include an account identifier. Therefore, when performing step S102, the server may determine the encoding identifier based on the account identifier sent by the terminal and record the mapping relationship between the account identifier and the encoding identifier, so that when performing step S108, the encoding identifier used during encoding can be determined according to the account identifier and the mapping relationship. Of course, when the terminal sends the verification information to the server, the encoding identifier may also be sent to the server, and the server may directly determine the decoding method according to the encoding identifier returned by the terminal to verify the real-time ultrasonic audio.

[0133] Embodiment 2 When the terminal determines the standard ultrasonic audio

[0134] Similarly, the terminal can also determine the standard ultrasonic audio, and there are also two encoding methods.

[0135] For step S104, if it is a fixed encoding method, the ultrasonic signal parameters sent by the server may only include the verification code. The terminal determines the corresponding relationship between the verification code characters and the ultrasonic frequency based on the preset encoding method, and encodes the verification code according to this corresponding relationship to obtain the standard ultrasonic audio.

[0136] Figure 8 Another schematic diagram of the determined standard ultrasonic audio provided in this specification is as Figure 8 shown.

[0137] For example, in the preset encoding method, the ultrasonic frequency corresponding to the binary number 0 is 20200 Hz, and the ultrasonic frequency corresponding to the binary number 1 is 20000 Hz. The binary numbers 0 and 1 are the verification code characters, and a verification code can be determined based on several verification code characters. Suppose the verification code is a three-digit random number, and the random number is the decimal number 322. Then, the decimal number 2 can be converted into the binary number 0010, and the decimal number 3 can be converted into the binary number 0011. Then, according to the preset encoding method, the random number 322 is encoded to obtain an ultrasonic frequency signal sequence of 20200 Hz(0), 20200 Hz(0), 20000 Hz(1), 20000 Hz(1), 20200 Hz(0), 20200 Hz(0), 20000 Hz(1), 20200 Hz(0), 20200 Hz(0), 20200 Hz(0), 20000 Hz(1), 20200 Hz(0). The standard ultrasonic audio can be obtained according to this ultrasonic frequency signal sequence.

[0138] If it is a random encoding method, the ultrasonic signal parameters sent by the server may include the verification code and the encoding identifier. The terminal determines the correspondence between the verification code characters and the ultrasonic frequency based on the encoding identifier in the ultrasonic signal parameters, and encodes the verification code according to this correspondence to obtain the standard ultrasonic audio.

[0139] Audio transmission usually requires more bandwidth. Therefore, the terminal determines the standard ultrasonic audio, which can save bandwidth and improve the verification efficiency.

[0140] The terminal needs to send the correspondence between the verification code characters and the ultrasonic frequency in the random encoding method to the server so that the server can verify the real-time ultrasonic audio. Specifically for step S100, the terminal can also send the account identifier to the server so that the server can determine the encoding identifier based on the account identifier sent by the terminal and record the mapping relationship between the account identifier and the encoding identifier. When decoding, the server can determine the encoding identifier used during encoding according to the account identifier and the mapping relationship, and then determine the decoding method corresponding to the encoding identifier. Of course, when the terminal sends the verification information to the server, it can also send the encoding identifier to the server. The server can directly determine the decoding method according to the encoding identifier returned by the terminal to verify the real-time ultrasonic audio.

[0141] Even if the terminal performs encoding, the specific encoding method is not disclosed. Therefore, attackers cannot generate the correct ultrasonic audio, which improves the accuracy of user authentication.

[0142] In the authentication method provided in this specification, video and audio authentication are performed simultaneously. Specifically, through the acquisition devices of the terminal, such as cameras and microphones, the video stream and ultrasonic audio of the user are synchronously acquired, and the server can verify the image features and audio features of the user simultaneously. Even if an attacker successfully forges an image, it is very difficult to forge ultrasonic audio synchronously. In addition, ultrasonic waves are inaudible and difficult to record. Ultrasonic signals are above the audible range of the human ear, and ordinary recording devices cannot accurately capture and reproduce these high-frequency signals. Therefore, it is difficult for attackers to obtain and forge ultrasonic verification codes by conventional means. Moreover, in this specification, by combining the correspondence between the changing ultrasonic frequency and the verification code characters with random numbers, the security and anti-counterfeiting ability of user authentication are greatly improved. An attacker not only needs to forge the live actions of the user synchronously but also needs to accurately generate and play ultrasonic signals of specific frequencies. This multi-level protection mechanism significantly increases the complexity and cost of the attack, making user authentication more secure and reliable. It effectively resists attacks based on video synthesis and signal forgery, ensuring the security of user authentication.

[0143] The above is the authentication method provided by one or more embodiments of this specification. Based on the same idea, this specification also provides a corresponding authentication device, such as Figure 9 As shown, the device is applied to the server, and the device includes:

[0144] An authentication data acquisition request receiving module 900, configured to receive an authentication data acquisition request sent by the terminal in response to a user's authentication operation;

[0145] An authentication data determination module 902, configured to determine an authentication interface and determine ultrasonic information based on the authentication data acquisition request;

[0146] An authentication data return module 904, configured to return the authentication interface and the ultrasonic information to the terminal, so that the terminal displays the authentication interface to the user and plays a standard ultrasonic audio based on the ultrasonic information;

[0147] A verification information receiving module 906, configured to receive verification information including real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation, where the real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio;

[0148] A verification module 908, configured to verify the verification information including the real-time ultrasonic audio to obtain the user's authentication result, and return the authentication result to the terminal, so that the terminal displays the authentication result to the user.

[0149] Optionally, the ultrasonic information includes a standard ultrasonic audio or ultrasonic signal parameters;

[0150] The authentication data determination module 902 is specifically configured to obtain ultrasonic signal parameters; when the ultrasonic information includes a standard ultrasonic audio, based on the ultrasonic signal parameters, determine the standard ultrasonic audio, and determine the standard ultrasonic audio as the ultrasonic information; when the ultrasonic information includes ultrasonic signal parameters, determine the ultrasonic signal parameters as the ultrasonic information, so that the terminal determines the standard ultrasonic audio based on the ultrasonic signal parameters and plays it.

[0151] Optionally, the ultrasonic signal parameters include a verification code;

[0152] The authentication data determination module 902 is specifically configured to determine the correspondence between the verification code characters and the ultrasonic frequencies based on a preset coding method; or determine a coding identifier, and based on the coding identifier, determine the correspondence between the verification code characters and the ultrasonic frequencies; according to the correspondence, encode the verification code to obtain a standard ultrasonic audio.

[0153] Optionally, the verification module 908 is specifically configured to decode the real-time ultrasonic audio to obtain decoded parameters; determine whether the decoded parameters match the verification code; if so, determine the user's authentication result as parameter verification successful.

[0154] Optionally, the verification information further includes at least one of the user's face image and the user's verification video;

[0155] The verification module 908 is specifically configured to, when the verification information includes the user's face image, determine whether there is a face in the pre-stored face information database that matches the user's face image; if so, determine the user's authentication result as face verification successful.

[0156] Optionally, when the verification information includes the user's verification video, the verification module 908 is specifically configured to determine whether the user has performed an action based on the verification video; if so, when the action characteristics of the user in the verification video match the action characteristics of a specified action, determine the user's authentication result as liveness verification successful; if not, determine the user's authentication result as liveness verification unsuccessful.

[0157] Optionally, the verification module 908 is specifically configured to, when at least one of the real-time ultrasonic audio, the user's face image, and the user's verification video fails to be verified, determine the user's authentication result as verification failed.

[0158] This specification provides an authentication device, which is applied to a terminal. The device includes:

[0159] An authentication data acquisition request sending module, configured to send an authentication data acquisition request to a server in response to a user's authentication operation;

[0160] An authentication data receiving module, configured to receive an authentication interface and ultrasonic information returned by the server based on the authentication data acquisition request;

[0161] A verification information acquisition module, configured to display the authentication page to the user, so that the user performs an authentication operation based on the authentication interface; based on the ultrasonic information, play a standard ultrasonic audio, and collect real-time ultrasonic audio;

[0162] A verification information sending module, configured to send verification information including real-time ultrasonic audio to the server in response to the user's verification completion operation, so that the server verifies the verification information including the real-time ultrasonic audio to obtain the user's authentication result and return it;

[0163] A verification result receiving module, configured to receive and display the user's authentication result sent by the server.

[0164] Optionally, the ultrasonic information includes a standard ultrasonic audio or ultrasonic signal parameters; the verification information acquisition module is specifically configured to play the standard ultrasonic audio when the ultrasonic information includes the standard ultrasonic audio; when the ultrasonic information includes ultrasonic signal parameters, determine a standard ultrasonic audio based on the ultrasonic signal parameters and play it.

[0165] Optionally, the ultrasonic signal parameters include a verification code;

[0166] The verification information acquisition module is specifically configured to determine the correspondence between verification code characters and ultrasonic frequencies based on a preset encoding method or based on an encoding identifier in the ultrasonic signal parameters; encode the verification code according to the correspondence to obtain a standard ultrasonic audio.

[0167] This specification also provides a computer-readable storage medium, which stores a computer program, and the computer program can be used to execute the above Figure 1 provided authentication method.

[0168] This specification also provides Figure 10 a schematic structural diagram of the electronic device shown. As Figure 10As shown in the figure, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory. Of course, it may also include other hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above Figure 1 authentication method. Of course, in addition to the software implementation method, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and can also be hardware or logic devices.

[0169] In the 1990s, it was obvious to distinguish whether an improvement to a technology was an improvement in hardware (e.g., improvement to circuit structures such as diodes, transistors, switches, etc.) or an improvement in software (improvement to method flows). However, with the development of technology, many improvements to method flows today can be regarded as direct improvements to hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structures by programming the improved method flows into the hardware circuits. Therefore, it cannot be said that an improvement to a method flow cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. The designer can program by himself / herself to "integrate" a digital system on a piece of PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow with the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.

[0170] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that, in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.

[0171] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0172] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0173] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0174] The present invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block of the flowchart illustrations and / or block diagrams, and combinations of flows and / or blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart Figure 1 for one or more flows and / or blocks Figure 1 of the flowchart and / or block diagrams.

[0175] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the functions specified in the flowchart Figure 1 for one or more flows and / or blocks Figure 1 of the flowchart and / or block diagrams.

[0176] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart Figure 1 for one or more flows and / or blocks Figure 1 of the flowchart and / or block diagrams.

[0177] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0178] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. The memory is an example of computer-readable media.

[0179] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0180] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0181] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0182] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0183] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.

[0184] The above description is only for the embodiments of this specification and is not intended to limit this specification. For those skilled in the art, various modifications and changes can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this application.

Claims

1. An identity authentication method, the method being applied to a server, the method comprising: Receiving a request for obtaining identity authentication data sent by a terminal in response to an identity authentication operation of a user; Based on the identity authentication data acquisition request, determine the identity authentication interface and determine the ultrasonic information; Returning the identity authentication interface and the ultrasonic information to the terminal, so that the terminal displays the identity authentication interface to the user and plays standard ultrasonic audio based on the ultrasonic information; Receiving verification information including real-time ultrasonic audio sent by the terminal in response to the verification completion operation of the user, where the real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio; Verify the verification information including the real-time ultrasonic audio to obtain the identity verification result of the user, and return the identity verification result to the terminal so that the terminal displays the identity verification result to the user.

2. The method according to claim 1, wherein the ultrasonic information comprises standard ultrasonic audio or ultrasonic signal parameters; Determine the ultrasonic information, including: Obtain ultrasonic signal parameters; When the ultrasonic information includes standard ultrasonic audio, based on the ultrasonic signal parameters, the standard ultrasonic audio is determined, and the standard ultrasonic audio is determined as the ultrasonic information; When the ultrasonic information includes ultrasonic signal parameters, the ultrasonic signal parameters are determined as ultrasonic information, so that the terminal determines and plays standard ultrasonic audio based on the ultrasonic signal parameters.

3. The method according to claim 2, wherein the ultrasonic signal parameter comprises a verification code; Based on the ultrasonic signal parameters, determining a standard ultrasonic audio frequency specifically includes: Based on a preset encoding method, determining the correspondence between the verification code characters and the ultrasonic frequency; or Determine a coding identifier, and based on the coding identifier, determine a correspondence between verification code characters and ultrasonic frequency; According to the corresponding relationship, the verification code is encoded to obtain a standard ultrasonic audio.

4. The method according to claim 3, verifying the verification information including the real-time ultrasonic audio to obtain the identity verification result of the user, specifically comprising: Decoding the real-time ultrasonic audio to obtain decoding parameters; Determining whether the decoding parameter matches the verification code; If so, the identity verification result of the user is determined as successful parameter verification.

5. The method according to claim 1, wherein the verification information further comprises at least one of a facial image of the user and a verification image of the user; Verifying the verification information including the real-time ultrasonic audio to obtain the identity verification result of the user specifically includes: When the verification information includes a facial image of the user, judging whether there is a face matching the facial image of the user according to a pre-stored facial information database; If so, the identity verification result of the user is determined as successful face verification.

6. The method according to claim 5, when the verification information includes the verification image of the user, verifying the verification information including the real-time ultrasonic audio to obtain the identity verification result of the user, specifically includes: determining, based on the verification image, whether the user has performed an action; If so, when the action feature of the user in the verification image matches the action feature of the specified action, the identity verification result of the user is determined as a successful liveness verification; If not, the identity authentication result of the user is determined as unsuccessful liveness authentication.

7. The method of claim 5, further comprising: When at least one of the verification information of the real-time ultrasonic audio, the user's facial image and the user's verification image is not successfully verified, the identity verification result of the user is determined as verification failure.

8. An identity authentication method, the method being applied to a terminal, the method comprising: In response to the user's identity authentication operation, sending an identity authentication data acquisition request to the server; Receiving the identity authentication interface and ultrasonic information returned by the server based on the identity authentication data acquisition request; The identity authentication page is displayed to the user, so that the user performs identity authentication operations based on the identity authentication interface; based on the ultrasonic information, standard ultrasonic audio is played, and real-time ultrasonic audio is collected; In response to the user's verification completion operation, sending verification information including real-time ultrasonic audio to the server, so that the server verifies the verification information including the real-time ultrasonic audio, obtains the user's identity verification result, and returns it; Receive the identity verification result of the user sent by the server and display it.

9. The method according to claim 8, wherein the ultrasonic information comprises standard ultrasonic audio or ultrasonic signal parameters; Based on the ultrasonic information, playing standard ultrasonic audio specifically includes: When the ultrasonic information includes standard ultrasonic audio, playing the standard ultrasonic audio; When the ultrasonic information includes ultrasonic signal parameters, standard ultrasonic audio is determined based on the ultrasonic signal parameters and played.

10. The method of claim 9, wherein the ultrasonic signal parameter comprises a verification code; Based on the ultrasonic signal parameters, determining a standard ultrasonic audio frequency specifically includes: Determining a correspondence between verification code characters and ultrasonic frequency based on a preset encoding method or based on an encoding identifier in the ultrasonic signal parameter; According to the corresponding relationship, the verification code is encoded to obtain a standard ultrasonic audio.

11. An identity authentication device, the device being applied to a server, the device comprising: An identity verification data acquisition request receiving module, used to receive an identity verification data acquisition request sent by a terminal in response to an identity verification operation of a user; An identity authentication data determination module, used to determine an identity authentication interface and ultrasonic information based on the identity authentication data acquisition request; An identity authentication data returning module, used for returning the identity authentication interface and the ultrasonic information to the terminal, so that the terminal displays the identity authentication interface to the user and plays standard ultrasonic audio based on the ultrasonic information; A verification information receiving module, used to receive verification information including real-time ultrasonic audio sent by the terminal in response to the user's verification completion operation, where the real-time ultrasonic audio is collected by the terminal when playing the standard ultrasonic audio; The verification module is used to verify the verification information including the real-time ultrasonic audio, obtain the identity verification result of the user, and return the identity verification result to the terminal so that the terminal displays the identity verification result to the user.

12. The device of claim 11, wherein the ultrasonic information comprises standard ultrasonic audio or ultrasonic signal parameters; The identity authentication data determination module is specifically used to obtain ultrasonic signal parameters; when the ultrasonic information includes standard ultrasonic audio, the standard ultrasonic audio is determined based on the ultrasonic signal parameters, and the standard ultrasonic audio is determined as ultrasonic information; when the ultrasonic information includes ultrasonic signal parameters, the ultrasonic signal parameters are determined as ultrasonic information, so that the terminal determines the standard ultrasonic audio based on the ultrasonic signal parameters and plays it.

13. The device of claim 12, wherein the ultrasonic signal parameter comprises a verification code; The identity authentication data determination module is specifically used to determine the correspondence between the verification code characters and the ultrasonic frequency based on a preset encoding method; or to determine a coding identifier, and based on the coding identifier, determine the correspondence between the verification code characters and the ultrasonic frequency; according to the correspondence, encode the verification code to obtain a standard ultrasonic audio.

14. The device as described in claim 13, wherein the verification module is specifically used to decode the real-time ultrasonic audio to obtain decoding parameters; determine whether the decoding parameters match the verification code; if so, determine the user's identity authentication result as successful parameter verification.

15. The device according to claim 11, wherein the verification information further comprises at least one of a face image of the user and a verification image of the user; The verification module is specifically used to determine whether there is a face matching the user's face image based on a pre-stored face information database when the verification information includes the user's face image; if so, determine the user's identity authentication result as a successful face verification.

16. The device as claimed in claim 15, when the verification information includes a verification image of the user, the verification module is specifically used to determine whether the user has performed an action based on the verification image; if so, when the action characteristics of the user in the verification image match the action characteristics of the specified action, the identity verification result of the user is determined as a successful liveness verification; if not, the identity verification result of the user is determined as an unsuccessful liveness verification.

17. The device as described in claim 15, wherein the verification module is specifically used to determine the user's identity verification result as verification failure when at least one verification information among the real-time ultrasonic audio, the user's facial image and the user's verification image is unsuccessful.

18. An identity authentication device, the device being applied to a terminal, the device comprising: An identity authentication data acquisition request sending module, used to send an identity authentication data acquisition request to a server in response to an identity authentication operation of a user; An identity authentication data receiving module, used for receiving the identity authentication interface and ultrasonic information returned by the server based on the identity authentication data acquisition request; A verification information acquisition module is used to display the identity authentication page to the user so that the user can perform identity authentication operations based on the identity authentication interface; based on the ultrasonic information, play standard ultrasonic audio and collect real-time ultrasonic audio; A verification information sending module, configured to send the verification information including the real-time ultrasonic audio to the server in response to the verification completion operation of the user, so that the server verifies the verification information including the real-time ultrasonic audio, obtains the identity verification result of the user, and returns it; The verification result receiving module is used to receive the identity verification result of the user sent by the server and display it.

19. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 10.

20. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 10 when executing the program.

Citation Information

Cited By

  • Identity authentication method and device based on voiceprint

    CN120639317A