Identity authentication system and method and electronic equipment
By verifying identity in the login application system and transmitting information to the target identity platform, the problem of identity authentication systems in different provinces is solved, cross-regional identity authentication is realized, efficiency is improved, and full network service is realized.
Patent Information
- Application Number
- CN202311620850.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-05-30
AI Technical Summary
The identity authentication systems between different provinces are not connected, resulting in the target customer needing to enter customer information multiple times to complete identity authentication.
After identity verification is carried out based on the customer information entered by the target customer in the login application system, the target customer information is passed to the target identity platform of the target area to achieve cross-regional identity authentication. After the target identity platform receives the information, it switches to the target application system so that the target customer does not need to repeatedly enter customer information.
The target customer's cross-regional identity authentication is achieved, avoiding repeated entry of customer information, improving the efficiency of identity authentication, and achieving one-time authentication of target customers in the tax network and full network service.
Smart Images

Figure CN120074827A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to an identity authentication system, method and electronic device. Background Art
[0002] According to the national requirements of "Internet + Government Services" and network security, it is currently necessary to establish a unified 4A management mechanism for identity management (Account), identity authentication (Authentication), access control (Authorization), and risk audit (Audit) for various entities such as legal persons, natural persons, tax personnel, and physical resources in the tax cyberspace.
[0003] Among them, when performing identity authentication, the identity authentication systems between different provinces (or regions) are not interconnected, so that each province needs to use its own identity authentication system to authenticate target customers, resulting in the need for target customers to enter customer information multiple times.
[0004] Exemplarily, after a target customer enters corresponding customer information in the A identity authentication system of Province A for identity authentication, when the target customer needs to access an application or service using the B identity authentication system of Province B, the target customer needs to re-enter the corresponding customer information in the B identity authentication system for identity authentication. Summary of the Invention
[0005] This application provides an identity authentication system, method and electronic device to solve the problem that the identity authentication systems between different provinces (or regions) are not interconnected, resulting in the need for target customers to repeatedly enter customer information. The specific implementation solutions are as follows:
[0006] In a first aspect, this application provides an identity authentication system, and the method includes: a login application system corresponding to the login area, a target application system corresponding to the target area, and a target identity platform;
[0007] The login application system is configured to, after determining that the target customer passes identity verification based on the customer information input by the target customer, in response to the target customer accessing the target application system, transmit the information corresponding to the target customer to the target identity platform;
[0008] The target identity platform is configured to receive the information and switch to the target application system based on the information.
[0009] Through the above application embodiments, after the login application system corresponding to the login area (such as Province A) determines that the target customer passes the identity verification based on the customer information input by the target customer, when it is determined that the target customer needs to access the target application system corresponding to the target area (such as Province B), it sends the information corresponding to the target customer to the target identity platform corresponding to the target area; then, after receiving the information, the target identity platform switches to the target application system based on the information, so that the target customer can achieve cross-region (such as from the login area to the target area) identity authentication without having to enter the customer information multiple times.
[0010] In a possible implementation manner, the login application system is further configured to, in response to an access request from the target customer, call the corresponding login identity platform, so that the login identity platform performs the identity verification on the target customer based on the customer information input by the target customer; and,
[0011] receive the verification success information sent by the login identity platform, and determine that the target customer passes the identity verification based on the verification success information; wherein, the verification success information indicates that the target customer passes the identity verification.
[0012] In a possible implementation manner, the identity verification includes internal identity verification; the identity authentication system further includes: the login identity platform;
[0013] The login identity platform is configured to, in response to the call of the login application system, receive the customer information input by the target customer; perform the internal identity verification on the target customer based on the customer information; when it is determined that the target customer passes the internal identity verification, send the verification success information to the login application system, so that the login application system determines that the target customer passes the identity verification based on the verification success information.
[0014] In a possible implementation manner, the login identity platform is further configured to determine the access permission corresponding to the target customer when it is determined that the target customer passes the internal identity verification.
[0015] In a possible implementation manner, the identity verification further includes external identity verification;
[0016] The login identity platform is further configured to, after performing the internal identity verification on the target customer based on the customer information, when it is determined that the target customer does not pass the internal identity verification, call an external verification source to perform the external identity verification on the target customer; if the target customer passes the external identity verification, send the verification success information to the login application system, so that the login application system determines that the target customer passes the identity verification based on the verification success information.
[0017] In a possible implementation, the customer information includes the business entity, authentication factor, authentication method, and identity information corresponding to the target customer; the authentication factor includes single-factor authentication or multi-factor authentication; the authentication method includes one or more of an account password method with a first-level authentication level, a verification code method with a second-level authentication level, a digital certificate method with a third-level authentication level, a real-person authentication method with a fourth-level authentication level, and a real-person and evidence-based authentication method with a fifth-level authentication level.
[0018] In a possible implementation, the target identity platform is further configured to determine whether the identity of the target customer is correct based on the information, and switch to the target application system when it is determined that the identity of the target customer is correct.
[0019] In a second aspect, the present application further provides an identity authentication method, which is applied to an identity authentication system and includes:
[0020] After the identity authentication system determines that the target customer passes the identity verification based on the customer information input by the target customer through logging in to the application system, in response to the target customer accessing the target application system, the identity authentication system transmits the information corresponding to the target customer to the target identity platform through the logging-in application system; wherein, the logging-in application system corresponds to the logging-in area, and the target application system and the target identity platform correspond to the target area.
[0021] The identity authentication system receives the information through the target identity platform, and switches to the target application system through the target identity platform based on the information.
[0022] In a third aspect, the present application provides an electronic device, including:
[0023] A memory for storing a computer program;
[0024] A processor for implementing the steps of the above identity authentication method when executing the computer program stored on the memory.
[0025] In a fourth aspect, the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the above identity authentication method are implemented.
[0026] For the technical effects that can be achieved by each of the above second to fourth aspects and each aspect, please refer to the technical effects that can be achieved by the above first aspect or various possible solutions in the first aspect, and will not be repeated here. Description of the Drawings
[0027] Figure 1a Schematic diagram 1 of the structure of an identity authentication system provided by an embodiment of the present application;
[0028] Figure 1b Schematic diagram 2 of the structure of an identity authentication system provided by an embodiment of the present application;
[0029] Figure 2a Schematic diagram 1 of the login page provided by an embodiment of the present application;
[0030] Figure 2b Schematic diagram 2 of the login page provided by an embodiment of the present application;
[0031] Figure 2c Schematic diagram of the login page provided by an embodiment of the present application Figure 3 ;
[0032] Figure 2d Schematic diagram of the login page provided by an embodiment of the present application Figure 4 ;
[0033] Figure 2e Schematic diagram of the login page provided by an embodiment of the present application Figure 5 ;
[0034] Figure 3 Schematic diagram of the application system switching page provided by an embodiment of the present application;
[0035] Figure 4 Schematic diagram of the process of an identity authentication method provided by an embodiment of the present application;
[0036] Figure 5 Schematic diagram of an electronic device provided by the present application. Detailed implementation manners
[0037] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of the present application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B may represent: A is directly connected to B and A is connected to B through C. In addition, in the description of the present application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0038] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0039] Currently, when conducting identity authentication between different provinces, the target customer needs to enter customer information in the identity authentication system corresponding to each province, which causes the target customer to enter the customer information repeatedly and reduces the efficiency of identity authentication.
[0040] Therefore, this application proposes an identity authentication system. After the login application system corresponding to the login area (such as Province A) determines that the target customer passes the identity verification based on the customer information input by the target customer, it transmits the information corresponding to the target customer (i.e., trust transfer) to the target identity platform corresponding to the target area (such as Province B), so that the target identity platform can switch to the target application system corresponding to the target area based on the received information, enabling the target customer to achieve identity authentication in the target area without re-entering the customer information again, that is, realizing cross-regional identity authentication of the target customer, thus avoiding the target customer from repeatedly entering the customer information, improving the efficiency of identity authentication, and enabling the target customer to complete authentication once in the tax network and handle all services across the network.
[0041] As Figure 1a shown, it is a schematic structural diagram of the identity authentication system provided by an embodiment of this application. The identity authentication system includes a login application system 11 corresponding to the login area (such as Province A), a target application system 12 corresponding to the target area (such as Province B), and a target identity platform 121.
[0042] The login application system 11 is configured to transmit the information corresponding to the target customer to the target identity platform 121 in response to the target customer accessing the target application system 12 after determining that the target customer passes the identity verification based on the customer information input by the target customer.
[0043] The target identity platform 121 is configured to receive the information and switch to the target application system 12 based on this information.
[0044] In an embodiment of this application, the login application system 11 and the target application system 12 are the same application systems located in different regions in the identity authentication system.
[0045] In a possible implementation, before the login application system 11 determines that the target customer passes the identity verification based on the customer information input by the target customer, the identity authentication system integrates the identity authentication services or identity authentication pages of multiple access channels (such as the web (Web) side, the application (Application, APP) side, WeChat official account, WeChat mini-program, Alipay life number, etc.), and provides various integrated identity authentication services such as multi-channel page integration and interface service integration, so as to facilitate the docking and integration of the login application system 11 in the tax cyberspace with the corresponding login identity platform of the login application system 11, and the target application system 12 with the corresponding target identity platform 121 of the target application system 12, so as to facilitate the corresponding login identity platform or the corresponding target identity platform 121 to take over the identity verification of the target customer, and then realize the unified management of identity authentication.
[0046] Therefore, in the embodiment of the present application, as Figure 1b shown, the identity authentication system further includes a login identity platform 111. The login identity platform 111 corresponds to the login application system 11 and both correspond to the login area.
[0047] After the login application system 11 is docked and integrated with the corresponding login identity platform 111, and before the login application system 11 determines that the target customer passes the identity verification based on the customer information input by the target customer, the login application system 11 also needs to configure authentication factors and authentication methods, so as to facilitate the corresponding login identity platform 111 to provide the target customer with optional authentication factors and optional authentication methods.
[0048] The above authentication factors include single-factor authentication and multi-factor authentication. The above authentication methods include the account password method with a first-level authentication level, the verification code method with a second-level authentication level, the digital certificate method with a third-level authentication level, the real-person authentication method with a fourth-level authentication level, and the real-person and real-evidence authentication method with a fifth-level authentication level.
[0049] It should be noted that when the above real-person authentication method and the above real-person and real-evidence authentication method are used for the first time, an external verification source needs to be called for authentication. For natural person subjects in the tax cyberspace, the external verification source can be the Ministry of Public Security, the Immigration Bureau, etc. For legal person subjects in the tax cyberspace, the external verification source can be the Central Compilation and Translation Bureau and the Market Supervision and Management, etc. Thus, in this way, the authoritative identity verification channels for natural persons such as the Ministry of Public Security and the Immigration Bureau are opened, and the enterprise identity verification channels such as the Market Supervision and Management and the Central Compilation and Translation Bureau are opened, and then the accurate identity verification of the subjects in the tax cyberspace can be realized.
[0050] In the embodiments of the present application, the above authentication methods are not limited to the above account password method, the above verification code method, the above digital certificate method, the above real-person authentication method, and the above real-person evidence verification method, but also include various authentication methods in the prior art.
[0051] Further, after the login application system 11 configures the authentication factors and authentication methods, in response to the access request of the target customer, it verifies the identity of the target customer based on the customer information input by the target customer, and determines that the target customer passes the identity verification.
[0052] In a possible implementation manner, when the login application system 11 verifies the identity of the target customer based on the customer information input by the target customer and determines that the target customer passes the identity verification, it can, in response to the access request of the target customer, call the corresponding login identity platform 111, so that the login identity platform 111 verifies the identity of the target customer based on the customer information input by the target customer. Thus, after receiving the verification success information sent by the login identity platform 111, it determines that the target customer passes the identity verification based on this verification success information. Among them, the verification success information indicates that the target customer passes the identity verification.
[0053] In the embodiments of the present application, when the login application system 11 calls the corresponding login identity platform 111, it can be implemented by jumping to the login page to call the login identity platform 111. This login page is the login page corresponding to the login identity platform 111. Thus, the login identity platform 111 can receive the customer information input by the target customer based on this login page, and then verify the identity of the target customer based on this customer information.
[0054] Through the above method, the login application system 11 calls the corresponding login identity platform 111 to enable the login identity platform 111 to implement the identity verification of the target customer, so as to realize the unified management of identity authentication through the login identity platform 111.
[0055] In a possible implementation manner, the above identity verification includes internal identity verification. Therefore, when the login identity platform 111 verifies the identity of the target customer based on the customer information input by the target customer, it is used to receive the customer information input by the target customer in response to the call of the login application system 11. Then, based on this customer information, it conducts an internal identity verification on the target customer. When it is determined that the target customer passes the internal identity verification, it sends the verification success information to the login application system 11, so that the login application system 11 determines that the target customer passes the identity verification based on the verification success information.
[0056] In the above - mentioned manner, the login identity platform 111 conducts an internal identity verification on the target customer based on the customer information input by the target customer. When it is determined that the target customer passes the internal identity verification, a verification success message is sent to the login application system 11, enabling the login application system 11 to determine that the target customer has passed the identity verification, so that the application system 11 can allow the target customer to access the corresponding specific application or service only after determining that the target customer has passed the identity verification, thereby improving the security of accessing the specific application or service.
[0057] In the embodiment of the present application, the customer information input by the above - mentioned target customer may include the business entity corresponding to the target customer, authentication factors, authentication methods, and identity information.
[0058] Therefore, the login page may be as Figure 2a shown, including a business entity dropdown (i.e., business entity options), an authentication factor dropdown (i.e., authentication factor options), an authentication method dropdown (i.e., authentication method options), and an identity information entry field.
[0059] In the embodiment of the present application, the above - mentioned business entities include enterprises, devices, applications, and individuals. The device and the application are physical resources.
[0060] In the tax cyberspace, the above - mentioned business entities can be divided into two categories, namely the taxpayer - side entities and the tax - official - side entities. Among them, the taxpayer - side entities include legal persons (such as enterprises, organizations), natural persons (such as individuals), and logistics resources (such as devices, applications); the tax - official - side entities include tax officials (such as individuals) and physical resources (such as devices, applications).
[0061] In a possible implementation manner, when the login identity platform 111 receives the business entity included in the customer information input by the target customer, it may also first receive the selected entity type (i.e., taxpayer - side entity or tax - official - side entity) of the target customer. Then, based on the entity type, corresponding business entity options (such as enterprise, device, application, individual) are provided for the target customer, so as to facilitate the target customer to more quickly select the corresponding business entity according to their own entity type, providing a better experience for the target customer; at the same time, it is convenient for the identity authentication system to determine whether the target customer is handling tax - payment business or tax - related business, so as to provide corresponding services for the target customer.
[0062] Specifically, if the selected entity type of the target customer is a taxpayer - side entity, options of enterprise, individual, device, and application are provided for the target customer in the business entity.
[0063] If the selected entity type of the target customer is a tax - official - side entity, options of tax official, device, and application are provided for the target customer in the business entity.
[0064] Exemplarily, as Figure 2b shown, the login page includes a subject type and a business entity. The subject type selected by the target customer is the taxpayer-side subject, and only options of enterprise, individual, device, and application are provided for the target customer in the business entity dropdown.
[0065] As Figure 2c shown, the login page includes a subject type and a business entity. The subject type selected by the target customer is the tax officer-side subject, and only options of tax officer, device, and application are provided for the target customer in the business entity dropdown.
[0066] In the above manner, based on the business entity in the customer information input by the target customer, it is convenient for the identity authentication system to determine whether the target customer is an individual, a device, an application, or an enterprise, so as to facilitate the identity authentication system to provide corresponding services for the target customer and realize the classified management of various entities.
[0067] In the embodiment of the present application, the authentication factors included in the customer information input by the above target customer include single-factor authentication or multi-factor authentication among the authentication factors configured in the login application system 11. The authentication methods included in the customer information input by the target customer include one or more of the account password method, verification code method, digital certificate method, real-person authentication method, and real-person evidence method among the authentication methods configured in the login application system 11.
[0068] Moreover, for different business entities, the optional authentication methods provided by the login identity platform 111 for the target customer can be the same or different. In the embodiment of the present application, the corresponding relationship between the business entity and the authentication method can be adjusted according to the specific application scenario to meet the needs of different business entities.
[0069] In the above manner, the target customer can select specific authentication factors and authentication methods according to their own needs (such as login needs and identity authentication needs), thereby realizing the flexible configuration of authentication factors and the flexible configuration of authentication methods, and further realizing hierarchical and classified authorization management. At the same time, different authentication methods are provided for different business entities in the tax network to meet the needs of different business entities.
[0070] In a possible implementation manner, when the login identity platform 111 receives the customer information input by the target customer, after receiving the business entity included in the customer information, it can first receive the authentication factor selected by the target customer, and then receive the authentication method selected by the target customer.
[0071] Specifically, after the login identity platform 111 receives the authentication factor selected by the target customer, if the authentication factor selected by the target customer is single-factor authentication, when the login identity platform 111 provides optional authentication methods for the target customer, it prompts the target customer that only one authentication method can be selected.
[0072] If the authentication factor selected by the target customer is multi-factor authentication, when the login identity platform 111 provides optional authentication methods for the target customer, it prompts the target customer to select multiple authentication methods. The multiple authentication methods are at least two authentication methods.
[0073] In the embodiment of the present application, when prompting the target customer that only one authentication method can be selected or prompting the target customer to select multiple authentication methods, it can be prompted in the form of single selection or multiple selection, or can be prompted in the form of a prompt box. In the embodiment of the present application, the prompt form for prompting the target customer to select one authentication method or multiple authentication methods can be adjusted according to the specific application scenario.
[0074] Exemplarily, the target customer is prompted to select one authentication method or multiple authentication methods in the form of single selection or multiple selection. As Figure 2d shown, when the business entity selected by the target customer is an enterprise and the authentication factor selected is single-factor authentication, the selection symbol before each authentication method in the authentication method drop-down list is a circle, and "Single Selection" is displayed at the title position of the authentication method drop-down list, indicating that the target customer can only select one authentication method.
[0075] As Figure 2e shown, when the business entity selected by the target customer is an enterprise and the authentication factor selected is multi-factor authentication, the selection symbol before each authentication method in the authentication method drop-down list is a square, and "Multiple Selection" is displayed at the title position of the authentication method drop-down list, indicating that the target customer needs to select multiple authentication methods.
[0076] In the embodiment of the present application, the identity information included in the customer information input by the above-mentioned target customer may include the identity identification number (Identity document, ID), name, fingerprint information, facial information, etc. of the target customer.
[0077] Further, after the login identity platform 111 receives the customer information input by the target customer and conducts an internal identity verification on the target customer based on the customer information input by the target customer, first, it determines whether the authentication factor is single-factor authentication.
[0078] If the authentication factor is single-factor authentication, based on the authentication method selected by the target customer, as well as the business entity and identity information of the target customer, an internal identity verification is performed on the target customer.
[0079] If the authentication factor is not single-factor authentication, it means the authentication factor is multi-factor authentication. At this time, based on the multi-factor authentication rules, for each authentication method selected by the customer and the business entity and identity information of the target customer, internal identity verification of the target customer is performed in sequence.
[0080] The above multi-factor authentication rules are that the lower the authentication level of the authentication method, the earlier this authentication method is used for authentication. Among them, the authentication levels are sorted from low to high as: level 1 (account password method), level 2 (verification code method), level 3 (digital certificate method), level 4 (real-person authentication method), level 5 (real-person and evidence-based authentication method).
[0081] Exemplarily, the authentication factor selected by the target customer is multi-factor authentication, and the authentication methods selected by the target customer are the account password method and the digital certificate method. Then, the login identity platform 111 first uses the account password method to perform internal identity verification on the target customer. When the target customer passes the verification corresponding to the account password method, the login identity platform 111 continues to use the digital certificate method to perform internal identity verification on the target customer. When the target customer passes the verification corresponding to the digital certificate method, it is determined that the target customer has passed the identity verification.
[0082] In a possible implementation manner, when the login identity platform 111 determines that the target customer has passed the internal identity verification, the login identity platform 111 can also determine the access rights corresponding to the target customer, so that the target customer can access specific applications or services that meet the access rights when logging in to the application system 11, avoiding the target customer accessing applications or services that cannot be accessed, thereby improving the security of accessing applications or services.
[0083] In the embodiments of the present application, authentication methods with different authentication levels correspond to different access rights. Therefore, when the above login identity platform 111 determines the access rights corresponding to the target customer, it can be determined based on the authentication level corresponding to the authentication method selected by the target customer.
[0084] In another possible implementation manner, the identity verification also includes external identity verification.
[0085] At this time, the login identity platform 111 is also used to, after performing internal identity verification on the target customer based on the customer information input by the target customer, when it is determined that the target customer fails the internal identity verification, call an external verification source to perform external identity verification on the target customer. If the target customer passes the external identity verification, the login identity platform 111 sends a verification success message to the login application system 11, so that the login application system 11 determines that the target customer has passed the identity verification based on this verification success message.
[0086] In the above manner, when the target customer fails the internal identity verification, the external identity verification source is used to conduct an external identity verification on the target customer. When the target customer passes the external identity verification, it is determined that the target customer has passed the identity verification. Thus, through double-layer identity verification, the accuracy of the identity verification of the target customer is further improved.
[0087] In summary, in the embodiment of the present application, the identity verification includes internal identity verification and external identity verification. When the target customer passes the internal identity verification or the external identity verification, it can be determined that the target customer has passed the identity verification.
[0088] However, it should be noted that in the embodiment of the present application, only when the authentication method included in the customer information input by the target customer includes the real-person authentication method or the real-person and real-evidence method, is it necessary to call the external verification source to conduct an external identity verification. Therefore, only when the authentication method included in the customer information input by the target customer includes the real-person authentication method or the real-person and real-evidence method, does the identity verification include the external identity verification.
[0089] After conducting an external identity verification on the target customer, the external source identity information corresponding to the target customer in the called external verification source can be saved, so that when the same target customer accesses and logs in to the application system 11 next time, and the authentication method includes the real-person authentication method or the real-person and real-evidence method, the identity information input by the target customer can be directly compared with the stored external source identity information to achieve the internal identity verification of the target customer.
[0090] Therefore, in the embodiment of the present application, when the login identity platform 111 conducts an internal identity verification on the target customer, if the authentication method included in the customer information input by the target customer includes the real-person authentication method or the real-person and real-evidence method, it is necessary to determine whether the external source identity information of the target customer is stored in the login application system 11.
[0091] When the external source identity information of the target customer is stored in the login application system 11, a direct comparison is made based on the stored external source identity information and the identity information input by the target customer to achieve the internal identity verification of the target customer.
[0092] When the external source identity information of the target customer is not stored in the login application system 11, it means that the login identity platform 111 is conducting the identity verification on the target customer for the first time. At this time, a direct external identity verification is conducted on the target customer. In other words, when the external source identity information of the target customer is not stored in the login application system 11, it is determined that the internal identity verification of the target customer fails. At this time, it is necessary to call the external verification source to conduct an external identity verification on the target customer.
[0093] In the embodiments of the present application, whether the login identity platform 111 performs external identity verification on the target customer or internal identity verification, the external identity verification or internal identity verification can be implemented based on the multi-channel identity authentication service or identity authentication page integrated in the identity authentication system.
[0094] Similarly, in the embodiments of the present application, when the target customer passes the external identity verification, the login identity platform 111 can also determine the access rights corresponding to the target customer, so as to facilitate the target customer to access the specific applications or services that meet the access rights when logging in to the application system 11.
[0095] In another possible implementation manner, when the login identity platform 111 determines that the target customer fails the external identity verification, the login identity platform 111 sends a verification failure message to the login application system 11, so that the login application system 11 determines that the target customer fails the identity verification based on the verification failure message, thereby prohibiting the access of the target customer.
[0096] In the embodiments of the present application, after the login application system 11 determines that the target customer passes the identity verification, each application system located in different regions in the identity authentication system will share the information of the target customer and the relevant information during the identity verification.
[0097] Further, when the login application system 11 responds to the target customer's access to the target application system 12, the login application system 11 can provide the target customer with an option to switch the application system, so as to facilitate the target customer to choose whether to switch the application system, and thus determine that the target customer accesses the target application system 12 based on the target customer's selection (i.e., in response to the target customer's access to the target application system 12). The option to switch the application system can be displayed in the form of an application system switch page.
[0098] Exemplarily, the application system switch page is as Figure 3 shown. The current login application system 11 is the application system in Region A, and the target customer can select the application system to which they need to switch according to the drop-down list of the target application system 12.
[0099] Further, after the login application system 11 determines that the target customer accesses the target application system 12, it transmits the information corresponding to the target customer to the target identity platform 121, so that the target identity platform 121 switches to the corresponding target application system 12 based on this information.
[0100] In the embodiments of the present application, when the login application system 11 transmits the information corresponding to the target customer to the target identity platform 121, it can transmit this information to the target identity platform 121 based on the login identity platform 111.
[0101] The information corresponding to the target customer transmitted to the target identity platform 121 may include: the identity information of the target customer (such as the ID, name, etc. of the target customer), the access rights of the target customer, etc.
[0102] After receiving the information corresponding to the target customer, the target identity platform 121 switches to the target application system 12 based on this information.
[0103] In a possible implementation manner, when the target identity platform 121 switches to the target application system 12 based on the received information, it may first determine whether the identity of the target customer is correct based on the received information, and when it determines that the identity of the target customer is correct, it switches to the target application system 12. This avoids the situation where during the process from the successful verification of the target customer's identity in the login application system 11 to the target identity platform 121 switching to the target application system 12, it is impossible to know whether the information of the target customer has been intercepted or tampered with by a malicious third party, and further improves the security of the application system switching and the security of accessing specific applications or services.
[0104] In the embodiment of the present application, when the target identity platform 121 determines whether the identity of the target customer is correct based on the information, it determines whether the received information conforms to the information of the target customer shared by the target application system 12 from the login application system 11 and the relevant information during the identity verification of the target customer. If so, it determines that the identity of the target customer is correct and switches to the target application system 12.
[0105] In the embodiment of the present application, after the target identity platform 121 determines that the identity of the target customer is correct, before switching to the target application system 12, it may also first establish a session and then switch to the target application system 12 according to this session.
[0106] In the embodiment of the present application, the method of establishing a session is the method of establishing a session in the prior art and will not be elaborated here.
[0107] In another possible implementation manner, when the target identity platform 121 determines whether the received information conforms to the information of the target customer shared by the target application system 12 from the login application system 11 and the relevant information during the identity verification of the target customer, if not, when it determines that the identity of the target customer is incorrect, it refuses to switch to the target application system 12 and sends a rejection switching message to the login application system 11 to enable the login application 11 to determine that the switching to the target application system 12 fails. This rejection switching message indicates that the target identity platform 121 refuses to switch to the target application system 12.
[0108] In addition, the above-mentioned switching rejection information can also indicate the reason why the target identity platform 121 refuses to switch to the target application system 12, so that the logged-in application system 11 can clearly understand the reason for the application system switching failure, so as to execute the corresponding solution for the reason for the application system switching failure, thereby completing the application system switching.
[0109] In summary, the identity authentication system proposed in the embodiment of the present application realizes unified management of various entities, multi-channel access, multiple authentication methods and multi-factor configurability in the tax network space, opens up multiple authoritative verification sources, and realizes a unified 4A management mechanism for accurate identity verification. The target customer can use the identity authentication system to perform identity authentication in the login area (such as Province A), and then through trust transmission (that is, the target customer's corresponding information is transmitted to the target identity platform 121 corresponding to the target application system 12 through the login application system 11), to achieve identity authentication in the target area (such as Province B), so that the target user can be authenticated once in the tax network and can be handled through the entire network.
[0110] Based on the same inventive concept, an embodiment of the present application also provides an identity authentication method, which is applied to the identity authentication system provided by any of the above embodiments. Figure 4 As shown, the method includes:
[0111] S401, after the identity authentication system determines that the target customer has passed the identity verification based on the customer information input by the target customer through the login application system, in response to the target customer accessing the target application system, the identity authentication system transmits the corresponding information of the target customer to the target identity platform through the login application system.
[0112] Among them, the login application system corresponds to the login area, and the target application system and the target identity platform correspond to the target area.
[0113] S402, the identity authentication system receives information through the target identity platform, and switches to the target application system based on the information through the target identity platform.
[0114] Through the above method, after the identity authentication system determines that the target customer has passed the identity verification through the login application system corresponding to the login area, when the target customer needs to access the target application system corresponding to the target area, the target customer's corresponding information is transmitted to the target identity platform corresponding to the target application system through the login application system (that is, trust transmission), and then the target identity platform switches to the target application system based on the received information, so that the target customer does not need to re-enter the customer information in the target area, and the identity authentication of the target area can be realized, that is, the identity authentication of the target customer across regions is realized, thereby avoiding the target customer from repeatedly entering the customer information, and realizing the target customer's one-time authentication in the tax network and handling it across the entire network.
[0115] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The above-mentioned electronic device can implement the functions of the foregoing identity authentication method. Refer to Figure 5 , the above-mentioned electronic device includes:
[0116] At least one processor 501 and a memory 502 connected to the at least one processor 501. In the embodiments of the present application, the specific connection medium between the processor 501 and the memory 502 is not limited. Figure 5 Taking the connection between the processor 501 and the memory 502 through the bus 500 as an example. The bus 500 is represented by a thick line in Figure 5 . The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus 500 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, Figure 5 only one thick line is used to represent it in, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 501 can also be called a controller, and the name is not limited.
[0117] In the embodiments of the present application, the memory 502 stores instructions executable by the at least one processor 501. The at least one processor 501 can execute the identity authentication method described above by executing the instructions stored in the memory 502.
[0118] Among them, the processor 501 is the control center of the system. It can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 502 and calling the data stored in the memory 502, various functions of the system and process data, so as to monitor the system as a whole.
[0119] In a possible design, the processor 501 may include one or more processing units. The processor 501 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 501. In some embodiments, the processor 501 and the memory 502 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.
[0120] The processor 501 may be a general-purpose processor, such as a Central Processing Unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the identity authentication method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0121] The memory 502, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 502 may include at least one type of storage medium, for example, it may include flash memory, hard disk, multimedia card, card-type memory, Random Access Memory (RAM), Static Random Access Memory (SRAM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), magnetic memory, magnetic disk, optical disc, and so on. The memory 502 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 502 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0122] By designing and programming the processor 501, the code corresponding to the identity authentication method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 4 the steps of the identity authentication method of the illustrated embodiment when running. How to design and program the processor 501 is a well-known technology to those skilled in the art and will not be elaborated here.
[0123] Based on the same inventive concept, the embodiments of the present application also provide a storage medium that stores computer instructions, and when the computer instructions run on a computer, the computer is caused to execute the identity authentication method described above.
[0124] In some possible embodiments, aspects of the identity authentication method provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in the identity authentication method according to various exemplary embodiments of the present application described above in this specification.
[0125] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0126] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.
[0127] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that realizes the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.
[0128] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in one or more flows in the flowchart and / or one or more blocks in the block diagram.
[0129] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. An identity authentication system, characterized in that, it includes: a login application system corresponding to the login area, a target application system corresponding to the target area, and a target identity platform; the login application system is used for, after determining that the target customer passes the identity verification based on the customer information input by the target customer, in response to the target customer accessing the target application system, transmitting the information corresponding to the target customer to the target identity platform; the target identity platform is used for receiving the information and switching to the target application system based on the information.
2. The system according to claim 1, characterized in that, the login application system is further used for, in response to the access request of the target customer, calling the corresponding login identity platform, so that the login identity platform performs the identity verification on the target customer based on the customer information input by the target customer; and, receiving the verification success information sent by the login identity platform and determining that the target customer passes the identity verification based on the verification success information; wherein, the verification success information indicates that the target customer passes the identity verification.
3. The system according to claim 2, characterized in that, the identity verification includes internal identity verification; the identity authentication system further includes: the login identity platform; the login identity platform is used for, in response to the call of the login application system, receiving the customer information input by the target customer; performing the internal identity verification on the target customer based on the customer information; when determining that the target customer passes the internal identity verification, sending the verification success information to the login application system, so that the login application system determines that the target customer passes the identity verification based on the verification success information.
4. The system according to claim 3, characterized in that, the login identity platform is further used for, when determining that the target customer passes the internal identity verification, determining the access permission corresponding to the target customer.
5. The system according to claim 3, characterized in that, the identity verification further includes external identity verification; the login identity platform is further used for, after performing the internal identity verification on the target customer based on the customer information, when determining that the target customer does not pass the internal identity verification, calling an external verification source to perform the external identity verification on the target customer; if the target customer passes the external identity verification, sending the verification success information to the login application system, so that the login application system determines that the target customer passes the identity verification based on the verification success information.
6. The system according to claim 1, characterized in that, The customer information includes the business entity, authentication factors, authentication methods, and identity information corresponding to the target customer; the authentication factors include single-factor authentication or multi-factor authentication; the authentication methods include one or more of the account password method with a first-level authentication level, the verification code method with a second-level authentication level, the digital certificate method with a third-level authentication level, the real-person authentication method with a fourth-level authentication level, and the real-person and actual-evidence authentication method with a fifth-level authentication level.
7. The system according to claim 1, characterized in that the target identity platform is further configured to determine whether the identity of the target customer is correct based on the information, and switch to the target application system when it is determined that the identity of the target customer is correct.
8. An identity authentication method for an identity authentication system according to any one of claims 1-7, characterized in that it includes: After the identity authentication system determines that the target customer passes the identity verification based on the customer information input by the target customer through logging in to the application system, in response to the target customer accessing the target application system, the identity authentication system transmits the information corresponding to the target customer to the target identity platform through the logging-in application system; wherein, the logging-in application system corresponds to the logging-in area, and the target application system and the target identity platform correspond to the target area; The identity authentication system receives the information through the target identity platform, and switches to the target application system based on the information through the target identity platform.
9. An electronic device, characterized in that it includes: a memory for storing a computer program; a processor for implementing the method steps described in claim 8 when executing the computer program stored on the memory.
10. A computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program, and the computer program realizes the method steps described in claim 8 when executed by a processor.