Multi-element integrated identity authentication system and method

Through the multi-integrated identity authentication system, the adaptive identity authentication and risk verification modules are used to solve the problem of oversimplicity or complexity of identity authentication in the prior art, and the effect of improving security and user experience is achieved.

CN120165978APending Publication Date: 2025-06-17NANJING HUADUN ELECTRIC POWER INFORMATION SAFETY EVALUATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510555685.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing identity authentication technology is both too simple and has poor protection effect, and is too complex and has cumbersome authentication, affecting the user experience.

Method used

Design a diversified integrated identity authentication system, including identity authentication module, whitelist module, blacklist module, risk verification module and early warning module. Through adaptive identity authentication, the appropriate authentication method is selected according to the risk level of the target user, and stored on the whitelist or blacklist respectively when the authentication is passed or failed to pass, and risk verification and early warning are carried out.

Benefits of technology

It effectively improves the security of target users when accessing information systems, avoids cumbersome authentication processes, and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165978A_ABST
    Figure CN120165978A_ABST
Patent Text Reader

Abstract

The invention discloses a multivariate integrated identity authentication system and method. The system comprises an identity authentication module, a white list module, a black list module, a risk verification module and an early warning module. Wherein the identity authentication module is used for performing self-adaptive identity authentication according to risk level information of a target user; the white list module is used for storing the target user in a preset white list when the identity authentication of the target user is passed; the blacklist module is used for storing the target user in a preset blacklist when the identity authentication of the target user is not passed; the risk verification module is used for carrying out risk verification on the target user according to the behavior habit of the target user, a preset white list and a preset black list, and determining a risk level corresponding to the target user; and the early warning module is used for giving an early warning to the target user when the identity of the target user is not authenticated and / or the risk level is greater than a preset risk level. By adopting the system scheme, the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of secure communication, and in particular, to a multi-element integrated identity authentication system and method. Background Art

[0002] As a commonly used technical means for information security protection, identity authentication technology has been widely applied to various information systems to ensure that the identities of accessing users are consistent and prevent illegal access. With the development of new technologies, various attack means have become diversified, posing new challenges to identity authentication technology.

[0003] Some of the existing identity authentication technologies are too simple, such as only performing username and password authentication, resulting in poor protection effects; some are too complex, such as using biometric authentication, password authentication, verification code authentication, etc. in combination, leading to cumbersome authentication and affecting the user experience of customers. Summary of the Invention

[0004] The present invention provides a multi-element integrated identity authentication system and method to solve the problem of overly simple or overly complex identity authentication, and improve the user experience of customers through adaptive identity authentication.

[0005] According to one aspect of the present invention, there is provided a multi-element integrated identity authentication system, which includes an identity authentication module, a whitelist module, a blacklist module, a risk assessment module, and a warning module; wherein:

[0006] The identity authentication module is configured to perform adaptive identity authentication based on the risk level information of the target user; wherein, the identity authentication methods for adaptive identity authentication include real-name authentication, biometric authentication, temporary key authentication, and SMS verification;

[0007] The whitelist module is configured to store the target user in a preset whitelist when the identity authentication of the target user is passed;

[0008] The blacklist module is configured to store the target user in a preset blacklist when the identity authentication of the target user fails;

[0009] The risk assessment module is configured to assess the risk of the target user based on the behavior habits of the target user, the preset whitelist, and the preset blacklist, and determine the risk level corresponding to the target user; the behavior habits refer to the legal operation behaviors of the target user after accessing the information system;

[0010] The warning module is configured to issue a warning to the target user when the identity authentication of the target user fails and / or the risk level is greater than the preset risk level.

[0011] According to another aspect of the present invention, a multi - integrated identity authentication method is provided. The multi - integrated identity authentication method is implemented by a multi - integrated identity authentication system, and the method includes:

[0012] Performing adaptive identity authentication based on the risk level information of the target user; wherein, the identity authentication methods for adaptive identity authentication include real - name authentication, biometric authentication, temporary key authentication, and SMS verification;

[0013] When the identity authentication of the target user is passed, storing the target user into a preset white list;

[0014] When the identity of the target user is not authenticated, storing the target user into a preset black list;

[0015] Performing risk assessment on the target user based on the behavior habits of the target user, the preset white list, and the preset black list, and determining the risk level corresponding to the target user; the behavior habit refers to the legal operation behavior of the target user after accessing the information system;

[0016] When the identity of the target user is not authenticated and / or the risk level is greater than the preset risk level, issuing a warning to the target user.

[0017] In the technical solution of the embodiment of the present invention, the identity authentication module performs adaptive identity authentication based on the risk level information of the target user; the white list module stores the target user into the preset white list when the identity authentication of the target user is passed; the black list module stores the target user into the preset black list when the identity of the target user is not authenticated; the risk assessment module performs risk assessment on the target user based on the behavior habits of the target user, the preset white list, and the preset black list, and determines the risk level corresponding to the target user; the warning module issues a warning to the target user when the identity of the target user is not authenticated and / or the risk level is greater than the preset risk level. By adopting this solution, the problem that the identity authentication is either too simple or too complex is solved, and the beneficial effects of effectively improving the security when the target user accesses the information system and avoiding cumbersome authentication in adaptive identity authentication to improve the user experience are achieved.

[0018] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0020] Figure 1 FIG. Figure 1 is a schematic structural diagram of a multi - integrated identity authentication system provided according to Embodiment 1 of the present invention;

[0021] Figure 2 FIG. is a schematic structural diagram of an identity authentication module provided according to Embodiment 2 of the present invention;

[0022] Figure 3 FIG.

[0023] is a schematic structural diagram of a multi - integrated identity authentication system provided according to Embodiment 3 of the present invention;

[0023] Figure 4 FIG. is a schematic flowchart of a multi - integrated identity authentication method provided according to Embodiment 4 of the present invention. Detailed Embodiments

[0024] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0025] Among them, the acquisition, storage, use, and processing of data in the technical solutions of this application all comply with the relevant regulations of laws and regulations. It should be noted that the terms "first", "second", "target", "original", etc. in the description and claims of the present invention and the above - mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including", "etc.", and "having" and any variations thereof are intended to cover non - exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0026] Embodiment 1

[0027] Figure 1FIG. 0 is a schematic structural diagram of a multi - integrated identity authentication system provided in the first embodiment of the present invention. This embodiment is applicable to the situation where when a target user accesses an information system, the target user is authenticated in a multi - integrated manner. The multi - integrated identity authentication system 100 includes an identity authentication module 110, a whitelist module 120, a blacklist module 130, a risk assessment module 140, and an early warning module 150; where:

[0028] The identity authentication module 110 is used to perform adaptive identity authentication based on the risk level information of the target user; among them, the identity authentication methods for adaptive identity authentication include real - name authentication, biometric authentication, temporary key authentication, and SMS verification;

[0029] The whitelist module 120 is used to store the target user in a preset whitelist when the identity authentication of the target user is passed;

[0030] The blacklist module 130 is used to store the target user in a preset blacklist when the identity authentication of the target user fails;

[0031] The risk assessment module 140 is used to assess the risk of the target user based on the behavior habits of the target user, the preset whitelist, and the preset blacklist, and determine the risk level corresponding to the target user; the behavior habits are determined by the operation behavior of the target user after accessing the information system;

[0032] The early warning module 150 is used to issue an early warning to the target user when the identity authentication of the target user fails and / or the risk level is greater than the preset risk level.

[0033] Among them, the identity authentication module may refer to a module for authenticating the identity of the target user, and a multi - integrated method is adopted for identity authentication in the identity authentication module. The multi - integration may refer to a process of performing integrated identity verification on the target user in multiple ways when the target user accesses the information system. The information systems accessed by the target user include, but are not limited to, the enrollment information management system of higher education institutions, the student status management and graduate employment information management system, the bank personal account management system, the cafeteria dining information management system, the sales management system, the telecommunication service management system, and the digital management system, etc. The various information in the information system belongs to the confidential information in the industry and has relatively high privacy; therefore, when the target user accesses the information system, the identity of the target user needs to be authenticated. For example, when the target user accesses the bank personal account management system, it is necessary to determine whether the accessing user is the actual holder or actual manager of the bank personal account.

[0034] Adaptive identity authentication may refer to performing corresponding authentication based on the risk level information of the target user. The identity authentication methods of the adaptive identity authentication include, but are not limited to, real-name authentication, biometric authentication, temporary key authentication, and SMS verification. The risk level information may refer to whether there is a risk for the target user and the information after classifying the existing risks. For example, if there is no risk for the target user, the risk level information is determined to be zero; if there is a risk but the risk is small, the risk level information is determined to be a first-level risk; the greater the risk of the target user, the higher the corresponding risk level information. When the risk level information corresponding to the target user is higher, more identity authentication methods are adopted; when the risk level information corresponding to the target user is lower, fewer identity authentication methods are adopted. For example, if the risk level information corresponding to the target user is a first-level risk, at this time the risk level is relatively low, and any one of the identity authentication methods can be selected for identity authentication; if the risk level information corresponding to the target user is a third-level risk, at this time the risk level is relatively high, and at least three of the identity authentication methods need to be selected for identity authentication to ensure the correct identity of the target user and improve the security of accessing the information system.

[0035] Among them, the whitelist module may refer to storing the target user in a preset whitelist when the target user passes the identity authentication; among them, the preset whitelist is integrated in the whitelist module. The preset whitelist stores the target users who have passed the identity authentication and records the number of times the target users who have passed the identity authentication have passed. When a certain number of times is reached, the target user can be accessed without authentication when accessing the information system.

[0036] Among them, the blacklist module may refer to storing the target user in a preset blacklist when the target user fails to pass the identity authentication; among them, the preset blacklist is integrated in the blacklist module. The preset whitelist stores the target users who have failed to pass the identity authentication and records the number of times the target users who have failed to pass the identity authentication have failed. When a certain number of times is reached, the target user will no longer be able to access the information system.

[0037] The risk verification module may refer to a module for verifying the risk of the target user. The risk verification may refer to determining whether the target user is in the preset white list or the preset black list and determining the historical operation behavior of the target user when accessing the information system. If the target user exists in the preset whitelist and there are no violations in the historical operation behavior, it is determined that the risk level of the target user is relatively low. If the target user exists in the preset blacklist and / or there are violations in the historical operation behavior, it is determined that the risk level of the target user is relatively high.

[0038] The warning module may refer to a module that warns the target user when a risk occurs to the target user. For example, when the identity authentication of the target user accessing the information system fails, the target user is warned to indicate an illegal intrusion behavior. Or, when the risk level of the target user exceeds the preset risk level, it can be determined that the target user is an illegal intrusion user, and then the target user is warned.

[0039] Optionally, the warning methods of the warning module include but are not limited to email warning, SMS warning, and in-site communication warning. Warning the target user through multiple warning methods facilitates the timely discovery of illegal intrusion users.

[0040] The embodiment of the present invention provides a multi-element integrated identity authentication system, which includes an identity authentication module, a whitelist module, a blacklist module, a risk assessment module, and a warning module. Among them: the identity authentication module is used to perform adaptive identity authentication based on the risk level information of the target user. Among them, the identity authentication methods for adaptive identity authentication include real-name authentication, biometric authentication, temporary key authentication, and SMS verification. The whitelist module is used to store the target user in the preset whitelist when the identity authentication of the target user is passed. The blacklist module is used to store the target user in the preset blacklist when the identity authentication of the target user fails. The risk assessment module is used to assess the risk of the target user based on the behavior habits of the target user, the preset whitelist, and the preset blacklist, and determine the risk level corresponding to the target user. The behavior habits are determined by the historical operation behaviors of the target user after accessing the information system. The warning module is used to issue a warning to the target user when the identity authentication of the target user fails and / or the risk level is greater than the preset risk level. By using the system of the embodiment of the present invention, adaptive identity authentication is performed on the target user based on the risk level information of the target user, and risk assessment and warning are performed based on the authentication result, so as to effectively improve the security when the target user accesses the information system, and the adaptive identity authentication avoids cumbersome authentication to improve the user experience.

[0041] Embodiment 2

[0042] Figure 2 FIG. is a schematic structural diagram of an identity authentication module provided in Embodiment 2 of the present invention. The embodiment of the present invention further optimizes the foregoing embodiment on the basis of the above embodiment, and the embodiment of the present invention can be combined with each optional solution in one or more of the above embodiments. As Figure 2 shown, the identity authentication module 110 includes a real-name authentication unit 111, a biometric authentication unit 112, a temporary key authentication unit 113, and an SMS verification unit 114. Among them:

[0043] The real-name authentication unit 111 is used to authenticate the target user based on the real-name identity information of the target user; the real-name identity information includes identity information obtained from at least one of an ID card, a passport, a driver's license, and a residence permit.

[0044] The biometric recognition unit 112 is used to recognize and authenticate the biometric information of the target user; the biometric information includes at least one of fingerprint information, voice information, retina information, and face image information.

[0045] The temporary key authentication unit 113 is used to authenticate the identity of the target user using a temporary key; the temporary key refers to a temporary key sent by the information system accessed by the user to the target user via email.

[0046] The SMS verification unit 114 is used to authenticate the identity of the target user using a verification code; the verification code refers to an SMS verification code sent by the information system accessed by the user to the target user.

[0047] Among them, the real-name authentication unit is used to conduct real-name authentication on the target user, which requires the target user to provide real identity information to prevent the target user from anonymously disrupting network order activities. For example, the real identity information of the target user can be obtained from any one of an ID card, a passport, a driver's license, and a residence permit.

[0048] The biometric recognition unit may refer to recognizing and authenticating the biometric information of the target user, and the biometric information includes but is not limited to fingerprint information, voice information, retina information, and face image information. Biometric recognition of the target user is performed based on the real biometric sampling information provided by the target user.

[0049] The temporary key authentication unit may refer to verifying the target user using a temporary key sent by the accessed information system. When the target user accesses the information system, through corresponding operations, the information system will send a temporary key to the target user via email, and the target user inputs the temporary key for identity verification.

[0050] The SMS verification unit may refer to verifying the target user using an SMS verification code sent by the accessed information system. When the target user accesses the information system, through corresponding operations, the information system will send an SMS verification code to the target user via SMS, and the target user inputs the SMS verification code for identity verification.

[0051] Optionally, in the embodiments of the present invention, the target user is adaptively authenticated through an identity authentication unit, a biometric recognition unit, a temporary key authentication unit, and a short message verification unit. When the risk level of the target user is relatively low, any one or two of the identity authentication unit, the biometric recognition unit, the temporary key authentication unit, and the short message verification unit can be used to authenticate the target user. When the risk level of the target user is relatively high, at least two of the identity authentication unit, the biometric recognition unit, the temporary key authentication unit, and the short message verification unit need to be used to authenticate the target user. The security of the information system is improved through multiple authentication methods, and the authentication frequency is reduced and the access efficiency is improved through the adaptive identity authentication method.

[0052] As an optional but non-limiting implementation manner, the identity authentication module is specifically configured to:

[0053] Determine the risk level of the target user according to the risk assessment module; wherein, the risk level includes a first-level risk, a second-level risk, and a third-level risk. The risk level of the first-level risk is lower than that of the second-level risk, and the risk level of the second-level risk is lower than that of the third-level risk. The higher the risk level, the greater the risk of the target user.

[0054] If the risk level of the target user is a first-level risk, select at least one identity authentication method from the identity authentication methods for authentication;

[0055] If the risk level of the target user is a second-level risk, select at least two identity authentication methods from the identity authentication methods for authentication;

[0056] If the risk level of the target user is a third-level risk, select at least three identity authentication methods from the identity authentication methods for authentication.

[0057] Optionally, according to the risk level information of the target user, an authentication method can be adaptively selected from the at least one authentication method to authenticate the target user. If the risk level information of the target user is relatively high, multiple authentication methods need to be used to authenticate the target user; if the risk level information of the target user is relatively low, any one or two authentication methods need to be used to authenticate the target user. For example, if the risk level of the target user is a first-level risk, at least one authentication method is selected from the authentication methods for authentication; the efficiency of the target user accessing the information system is improved by reducing the authentication method. If the risk level of the target user is a second-level risk, at least two authentication methods are selected from the authentication methods for authentication; repeated authentication is performed through multiple authentication methods to ensure the correct identity of the target user. If the risk level of the target user is a third-level risk, at least three authentication methods are selected from the authentication methods for authentication; to avoid illegal intrusion. If the risk level of the target user exceeds the third-level risk, all authentication information needs to be used to authenticate the target user to determine the correct identity of the target user. In the embodiment of the present invention, by adaptively selecting the authentication method, the authentication efficiency can be effectively improved, and the security of the target user accessing the information system can be improved.

[0058] Optionally, when it is determined to use the real-name authentication method to authenticate the target user, the real-name identity information of the target user can be adaptively obtained from the at least one document according to the risk level information of the target user to authenticate the target user. The adaptiveness here can mean that if the risk level information of the target user is relatively high, the real identity information of the target user needs to be obtained from multiple documents to authenticate the target user to improve the reliability of the authentication. If the risk level information of the target user is relatively low, the real identity information of the target user needs to be obtained from any one or two documents to authenticate the target user to improve the authentication efficiency.

[0059] Optionally, when it is determined to use the biometric authentication method to authenticate the target user, the biometric information of the target user can be adaptively obtained from the at least one biometric information according to the risk level information of the target user to authenticate the target user. The adaptiveness here can mean that if the risk level information of the target user is relatively high, multiple biometric information needs to be used to authenticate the target user to improve the reliability of the authentication; if the risk level information of the target user is relatively low, only any one or two biometric information needs to be used to authenticate the target user to improve the authentication efficiency.

[0060] An embodiment of the present invention provides a multi - integrated identity authentication system, which adaptively selects a corresponding number of identity authentication methods from real - name authentication, biometric authentication, temporary key authentication, and SMS verification for identity authentication according to the risk level information of the target user; at the same time, according to the risk level information of the target user, a corresponding number of information can be adaptively selected from real - name identity information and / or biometric information for identity authentication. By adaptively selecting identity authentication methods, real - name identity information, and biometric information to authenticate the target user, the identity authentication efficiency can be effectively improved, and the security of the target user accessing the information system can be enhanced.

[0061] Embodiment III

[0062] Figure 3 FIG. is a schematic structural diagram of a multi - integrated identity authentication system provided by Embodiment III of the present invention. Based on the above - mentioned embodiments, Embodiment III of the present invention further optimizes the foregoing embodiments, and Embodiment III of the present invention can be combined with each optional solution in one or more of the above - mentioned embodiments. As Figure 3 shown, the system includes:

[0063] Optionally, the whitelist module is specifically configured to:

[0064] Determine the consecutive passing times of the target user in the preset whitelist during identity authentication;

[0065] If the consecutive passing times reach the preset passing times threshold, then mark the target user as a non - authentication target user.

[0066] Among them, after the target user passes the identity authentication, store the target user in the preset whitelist; count the consecutive passing times of the target user for identity authentication; if the consecutive passing times exceed the preset passing times threshold, it can be determined that the target user is a high - quality user, and the target user can be marked as a non - authentication target user, so as to directly access the information system when the target user accesses the information system next time. Marking the target user as a non - authentication target user can effectively improve the access efficiency of the target user and reduce the time cost of identity authentication.

[0067] Optionally, the whitelist module is further specifically configured to: perform random identity authentication on non - authentication target users. To avoid the impersonation of non - authentication target users, random identity authentication needs to be performed on non - authentication target users. The random identity authentication may refer to randomly selecting one time for identity authentication when the non - authentication target user accesses the information system multiple times.

[0068] Optionally, the blacklist module is specifically configured to:

[0069] Verify the target user in the preset blacklist to determine whether the target user exists in the preset whitelist;

[0070] If the target user exists in the preset whitelist, re - authenticate the target user;

[0071] If the target user does not exist in the preset whitelist, determine the number of consecutive failed authentication attempts of the target user, and when the number of consecutive failed authentication attempts reaches the preset threshold of failed attempts, mark the target user as a target user prohibited from accessing the information system.

[0072] Among them, after the target user fails the identity authentication, store the target user in the preset blacklist. In practical applications, there may be identity authentication failures caused by the target user's human error. Therefore, it is necessary to re - verify the target users in the preset blacklist.

[0073] By verifying the target users in the preset whitelist, determine whether the target users in the preset blacklist also exist in the preset whitelist; if they exist in the preset whitelist at the same time, re - authenticate the target users to eliminate the problem of human error. If they do not exist in the preset whitelist at the same time, count the number of consecutive failed authentication attempts of the target user, and when the number of consecutive failed authentication attempts reaches the preset threshold of failed attempts, mark the target user as a target user prohibited from accessing the information system. When the target user is marked as a target user prohibited from accessing the information system, the target user will no longer be able to access the information system.

[0074] In an alternative solution of the embodiment of the present invention, verify the target users in the preset blacklist to determine whether the target users exist in the preset whitelist; if the target users do not exist in the preset whitelist and the current number of failed authentication attempts is 1, re - authenticate the target users and determine whether the identity authentication is passed. When the target users do not exist in the preset whitelist and the current number of failed authentication attempts is 1, re - authenticate the target users, which also avoids the problem of misoperation.

[0075] Optionally, the risk assessment module is further specifically configured to:

[0076] Conduct identity verification on the target user according to the preset verification indicators and determine the identity verification result;

[0077] Determine the risk level of the target user according to the identity verification result and store the target user in the preset whitelist or the preset blacklist;

[0078] Among them, the preset verification indicators include whether there is a litigation record and whether there is a credit record; if any one of the preset verification indicators exists in the identity verification result, the target user will be stored in the preset blacklist; if none of the preset verification indicators exists in the identity verification result, the target user will be stored in the preset whitelist.

[0079] Among them, when conducting risk assessment on the target user, risk assessment can also be carried out based on whether the target user has a litigation record and whether there is a credit record. If the target user has a litigation record and / or has a credit record, it indicates that the credit of the target user has problems and the risk level of the target user is relatively high, then the target user needs to be stored in the preset blacklist. If the target user does not have a litigation record and does not have a credit record, it indicates that the risk level of the target user is relatively low, then the target user will be stored in the preset whitelist.

[0080] Optionally, the preset verification indicators also include but are not limited to recommendation letters and honor certificates. For example, if the target user has a recommendation letter and / or honor certificate related to accessing the information system, it indicates that the risk level of the target user is relatively low, then the target user can be stored in the preset whitelist.

[0081] In the embodiments of the present invention, the risk level of the target user is determined through multiple verification indicators to improve the security of the target user's identity, thereby ensuring the security of the information system.

[0082] Optionally, the system further includes a data transmission module, where:

[0083] The data transmission module is used to transmit various authentication information in the identity authentication module to the database module; one end of the data transmission module is connected to the identity authentication module, and the other end is connected to the database module.

[0084] Among them, the data transmission module, as a data transmission medium, transmits the identity authentication information and identity authentication results of the real-name authentication unit, biometric recognition unit, temporary key authentication unit, and SMS verification unit to the database module.

[0085] Optionally, the system further includes a database module, where:

[0086] The database module is used to obtain and store the authentication information transmitted by the data transmission module; one end of the database module is connected to the data transmission module, and the other end is simultaneously connected to the whitelist module, blacklist module, risk assessment module, and warning module.

[0087] Among them, the database module is used to store the identity authentication information transmitted by the data transmission module, and provide a basis for risk assessment, early warning, storage in a preset whitelist, and preset blacklist for the target user.

[0088] An embodiment of the present invention provides a multi-integrated identity authentication system. By verifying the number of successful authentication times of target users in a preset whitelist, the target users are marked as users exempt from authentication, so as to improve the efficiency of target users accessing the information system. By verifying the number of failed authentication times of target users in a preset blacklist, the failure of identity authentication caused by misoperation is avoided; at the same time, the target users with consecutive failed authentications are marked as target users prohibited from accessing the information system, so as to avoid the intrusion of illegal users. By verifying the risk level of target users through multiple verification indicators, the security of the target user's identity is improved, thereby ensuring the security of the information system.

[0089] Embodiment 4

[0090] Figure 4 FIG. is a schematic flowchart of a multi-integrated identity authentication method provided in Embodiment 4 of the present invention. This embodiment is applicable to the situation where a multi-integrated method is used to authenticate the identity of a target user when the target user accesses the information system. The multi-integrated identity authentication method is implemented by a multi-integrated identity authentication system, and the method includes:

[0091] S410. Perform adaptive identity authentication based on the risk level information of the target user.

[0092] Among them, the identity authentication methods for adaptive identity authentication include real-name authentication, biometric authentication, temporary key authentication, and SMS verification.

[0093] Based on the above embodiment, optionally, the performing adaptive identity authentication based on the risk level information of the target user includes:

[0094] Perform authentication using the real-name authentication unit; the real-name identity information includes identity information obtained from at least one of an ID card, a passport, a driver's license, and a residence permit;

[0095] Perform recognition and authentication on the biometric information of the target user; the biometric information includes at least one of fingerprint information, voice information, retina information, and face image information;

[0096] Perform authentication on the identity of the target user using a temporary key; the temporary key refers to a temporary key sent by the information system accessed by the user to the target user via email;

[0097] Perform authentication on the identity of the target user using a verification code; the verification code refers to an SMS verification code sent by the information system accessed by the user to the target user.

[0098] Based on the above embodiments, optionally, the adaptive identity authentication according to the risk level information of the target user further includes:

[0099] Determine the risk level of the target user according to the risk assessment module; wherein, the risk level includes primary risk, secondary risk, and tertiary risk, the risk level of primary risk is less than that of secondary risk, the risk level of secondary risk is less than that of tertiary risk, and the higher the risk level, the greater the risk of the target user.

[0100] If the risk level of the target user is primary risk, select at least one identity authentication method from the identity authentication methods for authentication;

[0101] If the risk level of the target user is secondary risk, select at least two identity authentication methods from the identity authentication methods for authentication;

[0102] If the risk level of the target user is tertiary risk, select at least three identity authentication methods from the identity authentication methods for authentication.

[0103] S420. When the identity authentication of the target user is passed, store the target user in the preset white list.

[0104] Based on the above embodiments, optionally, after storing the target user in the preset white list when the identity authentication of the target user is passed, the method includes:

[0105] Determine the consecutive passing times of the target user in the preset white list during identity authentication;

[0106] If the consecutive passing times reach the preset passing times threshold, mark the target user as a user exempt from authentication.

[0107] S430. When the identity authentication of the target user fails, store the target user in the preset black list.

[0108] Based on the above embodiments, optionally, after storing the target user in the preset black list when the identity authentication of the target user fails, the method includes:

[0109] Verify the target user in the preset black list to determine whether the target user exists in the preset white list;

[0110] If the target user exists in the preset white list, re-authenticate the target user;

[0111] If the target user does not exist in the preset whitelist, determine the number of consecutive times the target user fails the authentication. When the number of consecutive times of failed authentication reaches the preset threshold of failed times, mark the target user as a target user prohibited from accessing the information system.

[0112] S440. Perform risk assessment on the target user based on the target user's behavior habits, preset whitelist, and preset blacklist, and determine the corresponding risk level of the target user.

[0113] The behavior habits are determined by the historical operation behaviors of the target user after accessing the information system.

[0114] Based on the above embodiments, optionally, after performing risk assessment on the target user based on the target user's behavior habits, preset whitelist, and preset blacklist, and determining the corresponding risk level of the target user, the method further includes:

[0115] Perform identity verification on the target user according to the preset verification indicators, and determine the identity verification result;

[0116] Determine the risk level of the target user according to the identity verification result, and store the target user in the preset whitelist or preset blacklist;

[0117] Among them, the preset verification indicators include whether there is a litigation record and whether there is a credit default record; if any one of the preset verification indicators exists in the identity verification result, store the target user in the preset blacklist; if none of the preset verification indicators exists in the identity verification result, store the target user in the preset whitelist.

[0118] S450. When the identity of the target user is not authenticated and / or the risk level is greater than the preset risk level, issue a warning to the target user.

[0119] Based on the above embodiments, optionally, the warning methods include email warning, SMS warning, and in-site communication warning

[0120] Based on the above embodiments, optionally, the method further includes:

[0121] Use the data transmission module to transmit various authentication information in the identity authentication module to the database module; wherein, one end of the data transmission module is connected to the identity authentication module, and the other end is connected to the database module.

[0122] Based on the above embodiments, optionally, the method further includes:

[0123] The database module is used to obtain and store the authentication information transmitted by the data transmission module. One end of the database module is connected to the data transmission module, and the other end is simultaneously connected to the whitelist module, the blacklist module, the risk assessment module, and the early warning module.

[0124] The multi - element integrated identity authentication method provided in the embodiments of the present invention can be applied to the multi - element integrated identity authentication system provided in any of the above - mentioned embodiments of the present invention, and has the corresponding functions and beneficial effects of the multi - element integrated identity authentication system. For the technical details not described in detail in the above embodiments, reference can be specifically made to the multi - element integrated identity authentication system provided in any embodiment of the present application.

[0125] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. No limitation is imposed herein.

[0126] The above - mentioned specific implementation manners do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A multi-integrated identity authentication system, characterized in that: The multi-integrated identity authentication system includes an identity authentication module, a whitelist module, a blacklist module, a risk assessment module and an early warning module; wherein: The identity authentication module is used to perform adaptive identity authentication based on the risk level information of the target user; wherein the identity authentication methods of the adaptive identity authentication include real-name authentication, biometric authentication, temporary key authentication and SMS verification; The whitelist module is used to store the target user in a preset whitelist when the target user's identity authentication passes; The blacklist module is used to store the target user in a preset blacklist when the identity of the target user is not authenticated; The risk assessment module is used to assess the risk of the target user based on the target user's behavior habits, a preset whitelist, and a preset blacklist, and determine the risk level corresponding to the target user; the behavior habits are determined by the target user's historical operation behaviors after accessing the information system; The warning module is used to issue a warning to the target user when the identity of the target user is not authenticated and / or the risk level is greater than a preset risk level.

2. The system according to claim 1, characterized in that The identity authentication module includes a real-name authentication unit, a biometrics unit, a temporary key authentication unit, and a text message verification unit; wherein: The real-name authentication unit is used to authenticate the target user based on the real-name identity information of the target user; the real-name identity information includes identity information obtained from at least one of an identity card, a passport, a driver's license and a residence permit; The biometric identification unit is used to identify and authenticate the biometric information of the target user; the biometric information includes at least one of fingerprint information, voice information, retinal information and face image information; The temporary key authentication unit is used to authenticate the identity of the target user using a temporary key; the temporary key refers to the temporary key sent to the target user by the information system accessed by the user via an email; The SMS verification unit is used to authenticate the identity of the target user using a verification code; the verification code refers to the SMS verification code sent to the target user by the information system accessed by the user.

3. The system according to claim 1, characterized in that The identity authentication module is specifically used for: Determine the risk level of the target user according to the risk assessment module; wherein the risk level includes level one risk, level two risk and level three risk, the risk level of level one risk is lower than the risk level of level two risk, the risk level of level two risk is lower than the risk level of level three risk, and the higher the risk level, the greater the risk of the target user; If the risk level of the target user is level one, selecting at least one identity authentication method from the identity authentication methods for authentication; If the risk level of the target user is level 2 risk, at least two identity authentication methods are selected from the identity authentication methods for authentication; If the risk level of the target user is level three, at least three identity authentication methods are selected from the identity authentication methods for authentication.

4. The system according to claim 1, characterized in that The whitelist module is specifically used for: Determine the number of consecutive passes of identity authentication by target users in the preset whitelist; If the number of consecutive passes reaches the preset pass threshold, the target user is marked as an authentication-free target user.

5. The system according to claim 1, characterized in that The blacklist module is specifically used for: Check the target user in the preset blacklist to determine whether the target user exists in the preset whitelist; If the target user exists in the preset whitelist, re-authenticate the target user; If the target user does not exist in the preset whitelist, the number of times the target user has failed authentication continuously is determined, and when the number of times the target user has failed authentication continuously reaches a preset failure threshold, the target user is marked as a target user prohibited from accessing the information system.

6. The system according to claim 1, characterized in that The risk assessment module is also specifically used for: Conduct identity verification on target users based on preset verification indicators and determine identity verification results; Determine the risk level of the target user based on the identity verification result, and store the target user in a preset whitelist or a preset blacklist; Among them, the preset verification indicators include whether there is a litigation record and whether there is a record of breach of trust; if any of the preset verification indicators exists in the identity verification result, the target user is stored in a preset blacklist; if any of the preset verification indicators does not exist in the identity verification result, the target user is stored in a preset whitelist.

7. The system according to claim 1, characterized in that The warning modes of the warning module include email warning, SMS warning and in-station communication warning.

8. The system according to claim 1, characterized in that The system also includes a data transmission module, wherein: The data transmission module is used to transmit various authentication information in the identity authentication module to the database module; wherein one end of the data transmission module is connected to the identity authentication module, and the other end is connected to the database module.

9. The system according to claim 1, characterized in that The system also includes a database module, wherein: The database module is used to obtain and store the authentication information transmitted by the data transmission module; wherein one end of the database module is connected to the data transmission module, and the other end is simultaneously connected to the whitelist module, the blacklist module, the risk assessment module and the early warning module.

10. A multi-integrated identity authentication method, characterized in that: The multi-integrated identity authentication method is implemented by using a multi-integrated identity authentication system, and the method comprises: Adaptive identity authentication is performed based on the risk level information of the target user; the identity authentication methods of adaptive identity authentication include real-name authentication, biometric authentication, temporary key authentication, and SMS verification; When the target user passes the identity authentication, the target user is stored in the preset whitelist; When the identity of the target user is not authenticated, the target user is stored in a preset blacklist; The target user is assessed for risk based on the target user's behavior habits, a preset whitelist, and a preset blacklist, and the risk level corresponding to the target user is determined; the behavior habits are determined based on the target user's historical operation behaviors after accessing the information system; When the identity of the target user is not authenticated and / or the risk level is greater than a preset risk level, an early warning is issued to the target user.