Identity verification method and device based on biological feature recognition, equipment and medium

By introducing secondary authentication factors into biometric recognition technology and mixing or superimposing them with biometric authentication factors, the problem of biometric recognition being easily counterfeited is solved, and the recognition security and accuracy are improved.

CN120180401APending Publication Date: 2025-06-20TD TECH LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311767399.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

Biometric recognition technology is easily counterfeit, especially due to the development of AI technology, biometric recognition methods such as facial recognition are no longer safe.

Method used

By introducing secondary authentication factors into the biometric acquisition information and mixing them with the biometric authentication factors, consistent authentication information is generated for comparison, or the secondary authentication factors are respectively checked to improve the verification accuracy of biometrics.

Benefits of technology

It effectively improves the security and verification accuracy of biometric recognition to prevent counterfeit attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180401A_ABST
    Figure CN120180401A_ABST
Patent Text Reader

Abstract

The invention provides an identity verification method and device based on biological feature recognition, equipment and a medium, and the method comprises the steps: obtaining biological feature collection information of a user in response to an identity verification request initiated by the user; when the biological characteristic acquisition information carries a biological characteristic authentication factor and a secondary authentication factor at the same time, comparing the biological characteristic acquisition information with preset first authentication information superposed with a verification biological characteristic authentication factor and a verification secondary authentication factor; or when the biological feature acquisition information only carries the biological feature authentication factor, comparing the biological feature acquisition information with preset second authentication information carrying a verification biological feature authentication factor, and calling a verification result of a secondary authentication factor of the user. According to the method and the device, the secondary authentication factor is introduced on the basis of the biological feature authentication factor to identify the authenticity of the biological feature of the user, so that the verification accuracy of the biological feature is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of biometric recognition technology, and particularly to an identity verification method, device, equipment and medium based on biometric recognition. Background Art

[0002] As an important means of identifying user identity information, biometric recognition has been widely used in various electrical equipment. Among them, common biometric recognition methods include face recognition, fingerprint recognition, palmprint recognition, and so on.

[0003] With the continuous development of technologies such as Artificial Intelligence (AI), biometrics are becoming increasingly easy to forge. Taking face recognition as an example, using AI technology, it is possible to perform 3D modeling of a human face through a photo, and then conduct forgery attacks through a 3D head model. In addition, AI technology can also imitate human voice characteristics, action expressions, etc., making biometric recognition technologies represented by face recognition no longer secure.

[0004] Therefore, there is an urgent need to propose an identity verification solution that can improve the security of biometric recognition to solve the problem that current biometric recognition is easily forged. Summary of the Invention

[0005] In view of the above problems, that is, the problem that biometric recognition is easily forged, this application provides an identity verification method, device, equipment and medium based on biometric recognition.

[0006] In a first aspect, this application provides an identity verification method based on biometric recognition, including:

[0007] In response to an identity verification request initiated by a user, obtain biometric collection information of the user;

[0008] When both a biometric authentication factor and a secondary authentication factor are carried in the biometric collection information, compare the biometric collection information with first authentication information pre-set with a verified biometric authentication factor and a verified secondary authentication factor; when the biometric collection information is consistent with the first authentication information, determine that the identity verification of the user is passed;

[0009] Or, when only the biometric authentication factor is carried in the biometric collection information, compare the biometric collection information with second authentication information pre-set with a verified biometric authentication factor, and retrieve the verification result of the secondary authentication factor of the user; in response to the biometric collection information being consistent with the second authentication information and the verification result of the second authentication factor being verified, determine that the identity verification of the user is passed.

[0010] In one embodiment, the biometric authentication factor includes one or a combination of the following information: fingerprint information, palmprint information, or face information; and / or, the secondary authentication factor includes one or a combination of the following information: encrypted text information, encrypted picture information, or encrypted color information.

[0011] In one embodiment, the first authentication information is an authentication object containing corresponding mixed authentication information obtained by performing mixed processing on the verified biometric authentication factor and the verified secondary authentication factor based on a preset algorithm.

[0012] The comparing of the biometric acquisition information with the first authentication information pre-stored with the verified biometric authentication factor and the verified secondary authentication factor includes:

[0013] Based on the preset algorithm, perform mixed processing on the biometric authentication factor and the secondary authentication factor in the biometric acquisition information to obtain mixed information to be authenticated, and compare the mixed information to be authenticated with the mixed authentication information.

[0014] In one embodiment, the retrieving of the verification result of the secondary authentication factor of the user includes:

[0015] Obtain the index information corresponding to the secondary authentication factor, and retrieve the verification result of the secondary authentication factor of the user from the authentication database based on the index information; wherein, the index information is a query index established after real-time verification of the secondary authentication factor of the user and uploading the verification result to the authentication database, and having a mapping relationship with the verification result.

[0016] In one embodiment, the real-time verification of the secondary authentication factor of the user includes:

[0017] Obtain the secondary authentication factor of the user, and compare the secondary authentication factor with the pre-stored verified secondary authentication factor. If the comparison is consistent, determine that the verification result of the secondary authentication factor is verification passed.

[0018] In one embodiment, the pre-storing of the first authentication information with the verified biometric authentication factor and the verified secondary authentication factor includes:

[0019] For each authorized user, respectively collect the biometric authentication information of the authorized user to obtain the verified biometric factor.

[0020] Overlay the verified secondary authentication factor on the verified biometric factor to obtain the first authentication information with the verified biometric authentication factor and the verified secondary authentication factor overlaid; wherein, the overlay method includes information mixing overlay and / or layer overlay.

[0021] In one implementation, after obtaining the biometric collection information of the user, the following steps are further included:

[0022] Determine whether the auxiliary function for verifying the secondary authentication factor is triggered and enabled;

[0023] If it is triggered and enabled, perform the step of comparing the biometric collection information with the first authentication information pre-stored with the verification biometric authentication factor and the verification secondary authentication factor superimposed thereon; or, perform the step of comparing the biometric collection information with the second authentication information pre-stored with the verification biometric authentication factor and retrieve the verification result of the user's secondary authentication factor.

[0024] In a second aspect, an embodiment of the present application provides an identity verification device based on biometric recognition, including:

[0025] An acquisition module, configured to obtain the biometric collection information of the user in response to an identity verification request initiated by the user;

[0026] A first verification module, configured to, when the biometric collection information carries both a biometric authentication factor and a secondary authentication factor, compare the biometric collection information with the first authentication information pre-stored with the verification biometric authentication factor and the verification secondary authentication factor superimposed thereon; when the biometric collection information is consistent with the first authentication information, determine that the identity verification of the user is passed;

[0027] Or, a second verification module, configured to, when the biometric collection information only carries a biometric authentication factor, compare the biometric collection information with the second authentication information pre-stored with the verification biometric authentication factor and retrieve the verification result of the user's secondary authentication factor; in response to the biometric collection information being consistent with the second authentication information and the verification result of the second authentication factor being verified as passed, determine that the identity verification of the user is passed.

[0028] In a third aspect, an embodiment of the present application provides an electronic device, including: a memory and a processor;

[0029] The memory stores computer execution instructions;

[0030] The processor executes the computer execution instructions stored in the memory, so that the electronic device executes the biometric verification method based on biometric recognition described above.

[0031] Fourthly, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the above-mentioned biometric authentication method based on biometric recognition.

[0032] The identity authentication method, device, equipment and medium based on biometric recognition provided by the present application, by responding to an identity authentication request initiated by a user, obtaining the biometric collection information of the user, when both a biometric authentication factor and a secondary authentication factor are carried in the biometric collection information, comparing the biometric collection information with a first authentication information pre-set with a verified biometric authentication factor and a verified secondary authentication factor, and in response to the biometric collection information being consistent with the first authentication information, determining that the user's identity authentication is passed; or, when only the biometric authentication factor is carried in the biometric collection information, comparing the biometric collection information with a second authentication information pre-set with a verified biometric authentication factor, and retrieving the verification result of the user's secondary authentication factor, and in response to the biometric collection information being consistent with the second authentication information and the verification result of the second authentication factor being verified, determining that the user's identity authentication is passed. In this process, by introducing a secondary authentication factor on the basis of the biometric authentication factor, by performing a primary verification on the first authentication information superimposed with the biometric authentication factor and the secondary authentication factor, or by respectively verifying the second authentication information of the biometric authentication factor and the secondary authentication factor, to identify the authenticity of the biometric, so as to achieve the purpose of improving the verification accuracy of the biometric. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 It is a schematic diagram of a possible application scenario provided by an embodiment of the present application;

[0034] Figure 2 It is a schematic flowchart of an identity authentication method based on biometric recognition provided by an embodiment of the present application;

[0035] Figure 3 is Figure 2 a schematic flowchart of step S202a in

[0036] Figure 4 It is a schematic flowchart of another identity authentication method based on biometric recognition provided by an embodiment of the present application;

[0037] Figure 5 It is a schematic flowchart of setting a secondary authentication factor on the terminal device side in Exemplary Embodiment 1 of the present application;

[0038] Figure 6 It is a schematic flowchart of face entry on the terminal device side in Exemplary Embodiment 1 of the present application;

[0039] Figure 7 It is a schematic flowchart for the authentication end of Exemplary Embodiment 1 of the present application to perform face information verification;

[0040] Figure 8 It is a schematic flowchart for the terminal device side of Exemplary Embodiment 2 of the present application to set a secondary authentication factor;

[0041] Figure 9 It is a schematic flowchart for the terminal device side of Exemplary Embodiment 2 of the present application to perform face entry;

[0042] Figure 10a It is a schematic flowchart for the terminal device side of Exemplary Embodiment 2 of the present application to perform face information verification;

[0043] Figure 10b It is a schematic flowchart for the authentication end of Exemplary Embodiment 2 of the present application to perform face information verification;

[0044] Figure 11 It is a schematic structural diagram of an identity authentication device based on biometric recognition provided by an embodiment of the present application;

[0045] Figure 12 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0046] In current biometric recognition technologies, external visible biometric features are acquired for comparison and recognition. As long as the features are externally visible, there is always a way for attackers to obtain them, and attacks can be carried out by imitating biometric features.

[0047] In related technologies, in response to problems such as biometric recognition being easily counterfeited by 3D models due to the development of AI technology, mainly by increasing the difficulty for attackers to counterfeit biometric features, such as introducing dynamic expressions, to defend against counterfeiting attacks. However, with the development of technology, attackers can continuously crack the feature information such as dynamic expressions carried by the introduced biometric features through 3D modeling and other means, resulting in that even if the difficulty of biometric features is increased, the security of biometric recognition still cannot be guaranteed.

[0048] In view of the above technical problems, the embodiments of the present application provide an authentication method, device, equipment and medium based on biometric recognition. By responding to an authentication request initiated by a user, biometric acquisition information of the user is obtained. When both a biometric authentication factor and a secondary authentication factor are carried in the biometric acquisition information, the biometric acquisition information is compared with a first authentication information pre-set with a verified biometric authentication factor and a verified secondary authentication factor superimposed thereon. In response to the biometric acquisition information being consistent with the first authentication information, it is determined that the user's authentication is passed. Alternatively, when only the biometric authentication factor is carried in the biometric acquisition information, the biometric acquisition information is compared with a second authentication information pre-set with a verified biometric authentication factor, and the verification result of the user's secondary authentication factor is retrieved. In response to the biometric acquisition information being consistent with the second authentication information and the verification result of the second authentication factor being verified, it is determined that the user's authentication is passed. In this process, by introducing a secondary authentication factor on the basis of the biometric authentication factor, by performing a primary verification on the first authentication information superimposed with the biometric authentication factor and the secondary authentication factor, or by separately verifying the second authentication information of the biometric authentication factor and the secondary authentication factor respectively, the authenticity of the biometric factor is identified, effectively improving the verification accuracy of the biometric factor.

[0049] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be described in more detail below with reference to the accompanying drawings in the embodiments of the present application. In the drawings, the same or similar reference numerals denote the same or similar components or components with the same or similar functions throughout. The described embodiments are some, but not all, of the embodiments of the present application. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present application and should not be construed as a limitation of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0050] Figure 1 A possible scenario diagram provided for the embodiments of the present application is shown in Figure 1As shown in the figure, it includes a terminal device 110 and a first server 120, and the terminal device 110 and the first server 120 are electrically connected. In one embodiment, the terminal device 110 is used to receive an authentication request initiated by a user, generate biometric acquisition information of the user, which can be directed to and generated for the user, and transmit it to the first server 120; the first server 120 is an authentication server. In response to the authentication request initiated by the user, the first server 120 obtains the biometric acquisition information, and determines whether both a biometric authentication factor and a secondary authentication factor are carried in the biometric acquisition information. When both the biometric authentication factor and the secondary authentication factor are carried, the biometric acquisition information is compared with the first authentication information pre-set with a verified biometric authentication factor and a verified secondary authentication factor. If the comparison is consistent, the user's identity authentication is confirmed to be passed.

[0051] In another embodiment, it further includes a second server 130, which is used to store second authentication factor information. It can be the server side of the terminal manufacturer. The second server 130 is electrically connected to the terminal device 110. The terminal device is also used to collect the secondary authentication factor of the user when receiving the authentication request initiated by the user, verify the secondary authentication factor, and then transmit the verification result of the secondary authentication factor to the authentication database in the second server 130. The first server 120 retrieves the verification result of the second authentication factor from the second server 130, and verifies whether the biometric acquisition information is consistent with the second authentication information. When both are consistent, the user's identity authentication is confirmed to be passed. Optionally, during the user identity authentication process. The first server 120 undertakes the main computing work, and the terminal device 110 and the second server 130 undertake the secondary computing work; or, the first server 120 undertakes the secondary computing work, and the terminal device 110 or the second server 130 undertakes the main computing work; or, the first server 120, the terminal device 110, or the second server 130 can each independently undertake the computing work.

[0052] Among them, the terminal device 110 may include, but is not limited to, a computer, a smart phone, a tablet computer, an e-book reader, a Moving Picture experts group audio layer III (MP3) player, a Moving Picture experts group audio layer IV (MP4) player, a portable computer, an in-vehicle computer, a wearable device, a desktop computer, a set-top box, a smart TV, and so on.

[0053] The first server 120 or the second server 130 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.

[0054] Optionally, the number of the above-mentioned terminal devices 110, first servers 120 or second servers 130 can be more or less, and the embodiments of the present application do not limit this.

[0055] The above briefly describes the scenario schematic diagram of the present application. Next, taking the first server 120 (hereinafter referred to as the authentication end) applied in Figure 1 as an example, the identity authentication method based on biometric recognition provided by the embodiments of the present application will be described in detail.

[0056] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of an identity authentication method based on biometric recognition provided by the embodiments of the present application. The method includes steps S201 - S203.

[0057] Step S201, in response to an identity authentication request initiated by a user, obtain biometric acquisition information of the user.

[0058] Taking face recognition as an example, the user initiates an identity authentication request to a terminal device (such as a mobile phone). The identity authentication request can be a request to trigger the unlocking of the mobile phone's lock screen. When the user faces the mobile phone screen with their face, the identity authentication request is automatically triggered. The terminal device acquires the user's biometric acquisition information and transmits the corresponding identity authentication request and biometric acquisition information to the first server. Among them, the biometric acquisition information can be a biometric acquisition picture.

[0059] In an implementation, when the user triggers the identity authentication request, the terminal device acquires the user's face information and prompts the user to verify the secondary authentication factor. Taking the secondary authentication factor as a password as an example, the user inputs the password on the mobile phone interface. The terminal device acquires the password information input by the user and sends it to the first server as biometric acquisition information. It can be understood that the acquisition order of the secondary authentication factor and the face (biometric factor) is not sequential. The secondary authentication factor can be acquired first, or the face can be acquired first. The present embodiment does not make a specific limitation on this.

[0060] In this embodiment, the secondary authentication factor is an encryption factor other than the biometric authentication factor, which may be the user account login status, the password set by the user, an external UKey, the connection of a specific Bluetooth device, etc. This embodiment does not specifically limit the specific content of the secondary authentication factor.

[0061] In one implementation manner, the biometric authentication factor includes one or a combination of the following information: fingerprint information, palmprint information, or face information; and / or, the secondary authentication factor at least includes one or a combination of the following information: encrypted text information, encrypted picture information, or encrypted color information.

[0062] It can be understood that the above information is only a possible example of the biometric authentication factor in the embodiments of the present application, rather than a limitation. For example, in addition to the above fingerprint information, palmprint information, and face information, the biometric authentication factor may also include voice recognition or palm vein recognition, etc.; in addition to the above encrypted text information (such as the user account login status, the set password, etc.), encrypted picture information (such as uploading a specific picture), and encrypted color information (such as selecting a specific color), the secondary authentication factor may also include encrypted connection information (such as an external UKey, the connection of a specific Bluetooth device, etc.). This embodiment only makes partial enumeration of this and does not specifically limit it.

[0063] Optionally, the secondary authentication factor may be processed additional information. For example, if the secondary authentication factor is a password, an existing algorithm such as a watermark algorithm can be used to generate a watermark corresponding to the password based on the password, and the watermark can be superimposed on the biometric authentication factor during superimposition; for another example, through a color mode (RGB color mode, RGB) algorithm, the numbers corresponding to the password can be mapped into corresponding color templates, and based on the above processing operations of the secondary authentication factor, the color template corresponding to the password can be superimposed on the biometric authentication factor. It can be understood that the RGB algorithm can use numbers to map corresponding colors. The above operations on the secondary authentication factor facilitate the superimposition between the secondary authentication factor and the biometric authentication factor.

[0064] Step S202: When the biometric authentication factor and the secondary authentication factor are both carried in the biometric acquisition information, compare the biometric acquisition information with the first authentication information pre-stored with the verified biometric authentication factor and the verified secondary authentication factor superimposed; when the biometric acquisition information is consistent with the first authentication information, determine that the user's identity verification is passed.

[0065] In an implementation of this embodiment, the authentication end simultaneously compares the biometric authentication factor and the secondary authentication factor with the first authentication information superimposed with the verification biometric authentication factor and the verification secondary authentication factor. When the comparison by the authentication end is consistent, it is considered that the user's identity verification is passed. It can be understood that in this implementation, the authentication end only needs to compare the obtained biometric acquisition information with the pre-set (pre-saved in the authentication end) first authentication information to complete the user's identity verification. Compared with another implementation mentioned later, the authentication end can achieve authentication without interacting with other servers, that is, seamless authentication.

[0066] Here, it should be noted that the superimposition in this embodiment of the verification biometric authentication factor and the verification secondary authentication factor can be either the mixed processing of information or the ordinary combination of information. Among them, the mixed processing means the mixed authentication information obtained after the mixed processing of the verification biometric authentication factor and the verification secondary authentication factor, which will be introduced in detail later in this text and will not be elaborated here; the ordinary combination can be that the first authentication information includes two independent verification information, that is, the verification biometric authentication factor and the verification secondary factor.

[0067] Or, in step S203, when only the biometric authentication factor is carried in the biometric acquisition information, the biometric acquisition information is compared with the pre-set second authentication information carrying the verification biometric authentication factor, and the verification result of the user's secondary authentication factor is retrieved; in response to the biometric acquisition information being consistent with the second authentication information and the verification result of the second authentication factor being verified passed, it is determined that the user's identity verification is passed.

[0068] Optionally, in this embodiment, retrieving the verification result of the user's secondary authentication factor can be retrieved from the authentication database, which can be in the terminal device or other servers, or the terminal device or other servers upload to a specific memory based on the cloud. Among them, the terminal device can be the terminal device for collecting biometric acquisition information, and the other server can be the manufacturer's server of the terminal device (for example, in the scenario where the terminal device verifies the secondary authentication factor and uploads the verification result to the manufacturer's server). This embodiment does not make specific limitations on this.

[0069] In another implementation of this embodiment, the authentication end only verifies the biometric authentication factor, and retrieves the verification result of the secondary authentication factor (for example, retrieved from the authentication database) by interacting with other servers or terminals, and determines that the user's identity verification is passed when both are verified passed. In this process, the authentication end needs to interact with other servers or terminals to sense each other to complete the final authentication.

[0070] Further, the authentication end can obtain the trigger enabling information of the secondary authentication factor. When triggered and enabled, if the secondary authentication factor is not carried in the biometric collection information, the secondary authentication factor is retrieved and verified to improve the verification flexibility of the biometric factor.

[0071] In one implementation, the first authentication information in this embodiment is an authentication object containing corresponding mixed authentication information obtained by mixing the verification biometric authentication factor and the verification secondary authentication factor based on a preset algorithm. This authentication object can be an authentication picture or other objects, and this embodiment does not make specific limitations thereon; as Figure 3 shown, in step S202, the biometric collection information is compared with the first authentication information pre-set with the verification biometric authentication factor and the verification secondary authentication factor superimposed thereon, and is further divided into the following step S202a.

[0072] Step S202a: Based on the preset algorithm, mix the biometric authentication factor and the secondary authentication factor in the biometric collection information to obtain mixed information to be authenticated, and compare the mixed information to be authenticated with the mixed authentication information.

[0073] In this embodiment, in order to further improve the security of biometric authentication, the biometric authentication factor and the secondary authentication factor are mixed, and the mixing process can be doping or attaching the secondary authentication information to the biometric authentication factor.

[0074] It should be noted that those skilled in the art can adaptively set the preset algorithm in combination with actual applications and existing technologies. This embodiment does not make specific limitations on the preset algorithm. For example, the preset algorithm can adopt a picture overlay algorithm, such as doping or attaching the secondary authentication information to the biometric authentication factor, or other mixing algorithms (such as a position algorithm) can be used to dope or attach the secondary authentication factor to a specific position of the biometric factor, and so on.

[0075] It can be understood that in this embodiment, the same algorithm can be used to mix the factors in the authentication process and the generation process of the authentication information.

[0076] In one implementation, the verification result of retrieving the secondary authentication factor of the user in step S203 above may include the following steps:

[0077] Obtain the index information corresponding to the secondary authentication factor, and retrieve the verification result of the user's secondary authentication factor from the authentication database based on the index information; wherein, the index information is a query index established after the real-time verification of the user's secondary authentication factor and uploading the verification result to the authentication database, and has a mapping relationship with the verification result.

[0078] In this embodiment, for another implementation, the secondary authentication factor needs to be identified on the terminal device side. In order to enable the authentication side to perceive the verification result of the secondary authentication factor on the terminal side, the terminal device side needs to provide the authentication side with the function of recording and querying the verification result of the device's second factor. This function is implemented by index information in this embodiment. In some embodiments, in addition to index information, other retrieval forms can also be used (such as using timestamps or basic information of other secondary authentication factors for retrieval), but the retrieval efficiency is lower compared to the index form.

[0079] In this embodiment, in the authentication database, by establishing a mapping relationship between the verification result of the secondary authentication factor and the query index, when the authentication side retrieves the verification result from the authentication database, the authentication database can be used to store the authentication factors of all users. In actual applications, the number of concurrent triggers for identity verification of the same type (such as face verification of different terminal devices) at the same time may be hundreds or thousands or even more, and the authentication database needs to store a lot of

[0080] In one implementation manner, for the above-mentioned another implementation, the secondary authentication factor can also be authenticated on the authentication side. Specifically, the real-time verification of the user's secondary authentication factor may include the following steps: obtain the user's secondary authentication factor, and compare the secondary authentication factor with the preset verification secondary authentication factor. If the comparison is consistent, it is determined that the verification result of the secondary authentication factor is verified.

[0081] In the above example of this embodiment, it mainly describes the verification of the secondary authentication factor by the terminal device or other servers. In this embodiment, a feasible implementation manner for verifying the secondary authentication factor on the authentication side is provided. Different from the implementation in which the authentication side simultaneously authenticates the biometric authentication factor and the secondary authentication factor in the biometric acquisition information corresponding to step S202, in this embodiment, the biometric acquisition information (only including the biometric authentication factor) and the secondary authentication factor are authenticated separately. In this implementation manner, the biometric authentication factors have an order of authentication. Taking the secondary authentication factor being authenticated first as an example, it needs to be saved in the authentication database first, and then the authentication of the biometric authentication factor is executed. After both authentications are completed, the identity verification of the user is identified according to the verification result.

[0082] In one embodiment, the authentication end can pre-configure the first authentication information to verify the biometric acquisition information. Specifically, the steps for pre-configuring the first authentication information with the biometric authentication factor and the secondary authentication factor superimposed thereon may include the following: for each authorized user, collect the biometric authentication information of the authorized user to obtain the biometric factor for verification; superimpose the secondary authentication factor for verification on the biometric factor for verification to obtain the first authentication information with the biometric authentication factor and the secondary authentication factor for verification superimposed thereon; wherein the superimposing method includes information mixing superimposing and / or layer superimposing.

[0083] Taking the face unlocking of a terminal device as an example, the authorized users in this embodiment are all users who can perform face unlocking. The biometric authentication information may be the face authentication picture of the user. In some embodiments, it may also be a fingerprint authentication picture, a palmprint authentication picture, etc. Or, for voice authentication, the biometric authentication information is a sound wave. This embodiment does not make specific limitations in this regard.

[0084] In this embodiment, the mixing superimposing may adopt the same implementation as the above mixing process. The layer superimposing may be superimposing the secondary authentication factor in the form of a picture on the upper layer or the lower layer of the face authentication picture. Taking the secondary authentication factor as an encrypted color factor (color encryption information), for example, green, by superimposing a green picture on the face authentication picture, the first authentication information is a green face authentication picture. Other forms of secondary authentication factors can also be superimposed through the above superimposing forms, and no more details will be elaborated here.

[0085] It should be noted that in addition to the above superimposing methods, it may also include a general combination superimposing method, that is, the superimposing method in which the biometric factor for verification and the secondary authentication factor for verification are two independent pieces of information. This embodiment does not make specific limitations on the superimposing method. For different superimposing methods, the authentication end performs flexible information verification.

[0086] Please refer to Figure 4 , Figure 4 which is a schematic flowchart of another identity verification method based on biometric recognition provided by an embodiment of the present application. On the basis of the above embodiment, in this embodiment, by judging whether the secondary authentication factor is enabled, the user identity authentication process in different modes can be realized, improving user convenience. Specifically, in addition to the above steps S201 - S203, after obtaining the biometric acquisition information of the user in the above step S201, the following steps may also be included:

[0087] Step S401: Determine whether the auxiliary function for verifying the secondary authentication factor is triggered and enabled. If so, perform the step of comparing the biometric acquisition information with the pre-set first authentication information overlaid with the verification biometric authentication factor and the verification secondary authentication factor; or, perform the step of comparing the biometric acquisition information with the pre-set second authentication information carrying the verification biometric authentication factor and retrieving the verification result of the user's secondary authentication factor.

[0088] In this embodiment, the auxiliary function for verifying the secondary authentication factor can be the key function of the terminal. The user operates the key to determine whether to activate the auxiliary function for verifying the secondary authentication factor and transmits the information on whether it is triggered and enabled to the authentication end.

[0089] Optionally, the user sets whether the auxiliary function for the secondary authentication factor is triggered and enabled on the terminal device and transmits the information on whether it is triggered and enabled to the authentication end. The authentication end saves the information on whether it is triggered and enabled, the corresponding timestamp when the information is received, and the terminal device identifier (and / or the application identifier corresponding to the terminal device that needs to perform identity verification). After responding to the user's identity verification request, it determines whether the auxiliary function for verifying the secondary authentication factor is triggered and enabled according to the pre-saved information on whether it is triggered and enabled (the latest timestamp). When it is triggered and enabled, it verifies the secondary authentication factor. Otherwise, it can perform the verification using the existing biometric authentication process (i.e., only identify whether the user's biometric authentication factor is correct).

[0090] As a further improvement, for different applications of the terminal device, there are respective identity verification processes. The user can set uniformly or separately whether to enable or disable the auxiliary function of the secondary authentication factor for each identity verification.

[0091] In this embodiment, the user can trigger and enable the secondary authentication factor according to specific requirements. The authentication end determines whether the secondary authentication factor is triggered and enabled and selects the corresponding authentication mode to authenticate the user's biometric acquisition information according to the judgment result, improving the convenience of the user.

[0092] For the convenience of understanding the embodiments of the present application, two exemplary embodiments are provided for the above two different realizations, and explanations are given respectively in combination with Figures 5 - 10b as shown:

[0093] Exemplary Embodiment 1: The terminal device is modified (i.e., the acquisition end superimposes the biometric authentication factor and the secondary authentication factor), and the authentication end is not aware. Taking face recognition as an example, the specific process includes the following steps of setting the secondary authentication factor, face entry stage, and face authentication stage.

[0094] 1) Set the secondary authentication factor

[0095] Authorized users can set secondary authentication factors on the terminal device. The secondary authentication factors can be determined by the terminal manufacturer and / or the authentication side, and the form of the secondary authentication factors is not restricted in this embodiment. In addition, the terminal manufacturer can use methods such as cloud synchronization to enable the secondary authentication factors to still be used normally after the user switches the terminal device.

[0096] Optionally, the secondary authentication factors can be the user account login status, the password set by the user, an external UKey, the connection of a specific Bluetooth device, etc.

[0097] Exemplarily, as Figure 5 shown, the process of setting the secondary authentication factors includes: the terminal device side selects the type of secondary authentication factor (account, password, UKey, Bluetooth connection, etc.), the user performs secondary factor authentication input on the terminal device, and can mark the secondary authentication factor option (whether to trigger the enabling of the secondary authentication factor) in the functional module of biometric authentication.

[0098] It should be noted that Figures 5 - 10b in the example of

[0099] 2) Face input stage

[0100] As Figure 6 shown, the user first inputs the face F on the terminal device. After the secondary authentication factor on the terminal device is verified successfully, the terminal device generates additional information A based on the secondary authentication factor. The algorithm for generating the secondary authentication factor is not restricted in this embodiment. It only needs to ensure that after the secondary authentication factor is determined, the generated additional information A is determined and independent of the terminal device where it is located. The terminal device performs superposition or mixing processing on the face information F and the additional information A through a certain algorithm (preset algorithm). The preset algorithm is not specifically limited in this embodiment. For example, a watermark algorithm can be used to superimpose on the face information in a way similar to a watermark, or it can be added / doped as an independent part in the face information. Finally, the mixed information F|A (i.e., the biometric acquisition information in the first implementation simultaneously carries the biometric authentication factor and the secondary authentication factor) is used to complete the input in the face recognition system.

[0101] 3) Face authentication stage

[0102] As Figure 7As shown, the user enters a face F on the terminal device. The terminal device can, according to the configuration, determine that a secondary authentication factor needs to be introduced, prompt the user to verify the secondary authentication factor, and the terminal device generates additional information A based on the second factor. The terminal device mixes the face information F and the additional information A. Specifically, the mixed information F|A is used for authentication in the authentication end. The authentication end is unaware and compares the information in the authentication request with the information stored in the base library and returns an authentication result.

[0103] Exemplary Embodiment 2: The acquisition end performs information acquisition, and the authentication end adds an information acquisition process. The specific process is as follows:

[0104] 1) Set the secondary authentication factor

[0105] As Figure 8 shown, first select the type of secondary authentication factor (account, password, UKey, Bluetooth connection...), and complete the authentication entry of the secondary authentication factor. Mark the second factor option in the terminal biometric module, and the manufacturer's server of the terminal device marks the secondary authentication factor option. It can be understood that in this example process, it is basically the same as the process of Exemplary Embodiment 1. The difference is that on the server side of the terminal manufacturer, a function for recording and querying the verification result of the secondary authentication factor is provided.

[0106] 2) Face entry stage

[0107] As Figure 9 shown, the user enters a face F on the terminal device. The terminal device transmits the face information F, and information such as the additional secondary authentication factor required for authentication and the authentication result query method of the secondary authentication factor to the authentication end; the authentication end completes the entry of the face information F in the face recognition system and simultaneously records the information related to the secondary authentication factor

[0108] 3) Face authentication stage

[0109] As Figure 10a and Figure 10b shown, where Figure 10a is the process on the terminal device side, Figure 10bFor the authentication process on the terminal side, the user enters the face F on the terminal device. The terminal device determines, according to the configuration, that a secondary authentication factor needs to be introduced, and prompts the user to verify the secondary authentication factor. If the verification of the secondary authentication factor passes, the verification result is transmitted to the manufacturer's server of the terminal device. The manufacturer's server of the terminal device generates a query index reqID, and then authenticates the face information F and the query index reqID in the face recognition system. The authentication side queries the manufacturer's server for the verification result of the second factor using reqID according to the previously saved secondary authentication factor information. If the verification passes, the face information F is compared with the information saved in the database, and the authentication result is returned. It should be noted here that this embodiment does not specifically limit the verification order of the secondary authentication factor and the face information. Only the example of verifying the secondary authentication factor first and then the face information is listed. In some embodiments, the face information can also be verified first and then the secondary authentication information. This embodiment does not specifically limit this.

[0110] Please refer to Figure 11 , Figure 11 FIG. is a schematic structural diagram of an identity authentication device based on biometric recognition provided by an embodiment of the present application. The device includes an acquisition module 11, a first verification module 12, and a second verification module 13. Among them,

[0111] The acquisition module 11 is configured to acquire the biometric acquisition information of the user in response to an identity authentication request initiated by the user;

[0112] The first verification module 12 is configured to compare the biometric acquisition information with the first authentication information pre-stored with the verified biometric authentication factor and the verified secondary authentication factor when the biometric acquisition information carries both the biometric authentication factor and the secondary authentication factor at the same time. When the biometric acquisition information is consistent with the first authentication information, it is determined that the identity authentication of the user passes;

[0113] Alternatively, the second verification module 13 is configured to compare the biometric acquisition information with the second authentication information pre-stored with the verified biometric authentication factor when the biometric acquisition information only carries the biometric authentication factor, and retrieve the verification result of the secondary authentication factor of the user. In response to the biometric acquisition information being consistent with the second authentication information and the verification result of the second authentication factor being verified, it is determined that the identity authentication of the user passes.

[0114] In one implementation manner, the biometric authentication factor includes one or a combination of the following information: fingerprint information, palmprint information, or face information; and / or, the secondary authentication factor includes one or a combination of the following information: encrypted text information, encrypted picture information, or encrypted color information.

[0115] In one embodiment, the first authentication information is an authentication object containing corresponding mixed authentication information obtained by performing mixed processing on the verification biometric authentication factor and the verification secondary authentication factor based on a preset algorithm;

[0116] The first verification module 12 is specifically configured to perform mixed processing on the biometric authentication factor and the secondary authentication factor in the biometric acquisition information based on the preset algorithm to obtain mixed information to be authenticated, and compare the mixed information to be authenticated with the mixed authentication information.

[0117] In one embodiment, retrieving the verification result of the user's secondary authentication factor includes: obtaining index information corresponding to the secondary authentication factor, and retrieving the verification result of the user's secondary authentication factor from the authentication database based on the index information; wherein, the index information is a query index established after real-time verification of the user's secondary authentication factor and uploading the verification result to the authentication database, and having a mapping relationship with the verification result.

[0118] In one embodiment, it further includes a second authentication factor verification module configured to perform real-time verification on the user's secondary authentication factor; the second authentication factor verification module is specifically configured to obtain the user's secondary authentication factor, and compare the secondary authentication factor with a preset verification secondary authentication factor. If the comparison is consistent, it is determined that the verification result of the secondary authentication factor is verified.

[0119] In one embodiment, it further includes a preset module configured to preset first authentication information superimposed with a verification biometric authentication factor and a verification secondary authentication factor; the preset is specifically configured to, for each authorized user, respectively collect the biometric authentication information of the authorized user to obtain a verification biometric factor; superimpose the verification secondary authentication factor on the verification biometric factor to obtain first authentication information superimposed with a verification biometric authentication factor and a verification secondary authentication factor; wherein, the superimposing method includes information mixing superimposing and / or layer superimposing.

[0120] In one embodiment, the device further includes:

[0121] A judgment module configured to judge whether an auxiliary function for verifying the secondary authentication factor is triggered and enabled. If it is triggered and enabled, perform the step of comparing the biometric acquisition information with the first authentication information preset with a verification biometric authentication factor and a verification secondary authentication factor; or perform the step of comparing the biometric acquisition information with the second authentication information carrying a verification biometric authentication factor preset and retrieving the verification result of the user's secondary authentication factor.

[0122] Please refer to Figure 12 , Figure 12 an electronic device provided by an embodiment of the present application, including: a memory 121 and a processor 122;

[0123] The memory 121 stores computer-executable instructions;

[0124] The processor 122 executes the computer-executable instructions stored in the memory 121, so that the electronic device executes the biometric verification method based on biometric recognition described above.

[0125] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the biometric verification method based on biometric recognition described above.

[0126] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof. In the hardware implementation, the division of the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component can have multiple functions, or a function or step can be executed by several physical components in cooperation. Some or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium).

[0127] As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.

[0128] In addition, as is well known to those of ordinary skill in the art, a communication medium generally includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.

[0129] In the description of the embodiments of the present application, the term "and / or" only represents an associated relationship for describing associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the term "at least one" represents any one of a plurality or any combination of at least two of a plurality. For example, including at least one of A and B can represent any one or more elements selected from the set including A, B, and C.

[0130] In the description of the embodiments of the present application, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. An authentication method based on biometric recognition, characterized in that, Including: In response to an authentication request initiated by a user, obtaining biometric collection information of the user; When both a biometric authentication factor and a secondary authentication factor are carried in the biometric collection information, comparing the biometric collection information with first authentication information pre-set with a verified biometric authentication factor and a verified secondary authentication factor superimposed thereon; when the biometric collection information is consistent with the first authentication information in comparison, determining that the user's authentication is passed; Alternatively, when only the biometric authentication factor is carried in the biometric collection information, comparing the biometric collection information with second authentication information pre-set with a verified biometric authentication factor carried thereon, and retrieving a verification result of the user's secondary authentication factor; in response to the biometric collection information being consistent with the second authentication information in comparison and the verification result of the secondary authentication factor being verified as passed, determining that the user's authentication is passed.

2. The method according to claim 1, characterized in that, The biometric authentication factor includes one or a combination of the following information: fingerprint information, palmprint information or face information; and / or, the secondary authentication factor includes one or a combination of the following information: encrypted text information, encrypted picture information or encrypted color information.

3. The method according to claim 1 or 2, characterized in that, The first authentication information is an authentication object containing corresponding mixed authentication information obtained by performing a mixed process on the verified biometric authentication factor and the verified secondary authentication factor based on a preset algorithm. The comparing the biometric collection information with the first authentication information pre-set with the verified biometric authentication factor and the verified secondary authentication factor superimposed thereon includes: Based on the preset algorithm, performing a mixed process on the biometric authentication factor and the secondary authentication factor in the biometric collection information to obtain mixed information to be authenticated, and comparing the mixed information to be authenticated with the mixed authentication information.

4. The method according to claim 1 or 2, characterized in that, The retrieving the verification result of the user's secondary authentication factor includes: Obtaining index information corresponding to the secondary authentication factor, and retrieving the verification result of the user's secondary authentication factor from an authentication database based on the index information; wherein, the index information is a query index established after the user's secondary authentication factor is verified in real time and the verification result is uploaded to the authentication database, and having a mapping relationship with the verification result.

5. The method according to claim 4, characterized in that, The verifying the user's secondary authentication factor in real time includes: Obtaining the user's secondary authentication factor, and comparing the secondary authentication factor with the pre-set verified secondary authentication factor; if they are consistent in comparison, determining that the verification result of the secondary authentication factor is verified as passed.

6. The method according to claim 1, characterized in that, Pre-setting the first authentication information with the verified biometric authentication factor and the verified secondary authentication factor superimposed thereon includes: For each authorized user, respectively collecting biometric authentication information of the authorized user to obtain a verified biometric factor; Superimposing the verified secondary authentication factor on the verified biometric factor to obtain the first authentication information with the verified biometric authentication factor and the verified secondary authentication factor superimposed thereon; wherein, the superimposing method includes information mixing superimposing and / or layer superimposing.

7. The method according to claim 1, characterized in that, After obtaining the biometric collection information of the user, it further includes: Determining whether the auxiliary function for verifying the secondary authentication factor is triggered and enabled; If triggered and enabled, performing the step of comparing the biometric collection information with the pre-set first authentication information superimposed with the verification biometric authentication factor and the verification secondary authentication factor; or, performing the step of comparing the biometric collection information with the pre-set second authentication information carrying the verification biometric authentication factor and retrieving the verification result of the user's secondary authentication factor.

8. An authentication device based on biometric recognition, characterized in that, It includes: An acquisition module, which is set to obtain the biometric collection information of the user in response to an identity verification request initiated by the user; A first verification module, which is set to compare the biometric collection information with the pre-set first authentication information superimposed with the verification biometric authentication factor and the verification secondary authentication factor when both the biometric authentication factor and the secondary authentication factor are carried in the biometric collection information; and when the biometric collection information is consistent with the first authentication information, determining that the identity verification of the user is passed; Or, a second verification module, which is set to compare the biometric collection information with the pre-set second authentication information carrying the verification biometric authentication factor and retrieve the verification result of the user's secondary authentication factor when only the biometric authentication factor is carried in the biometric collection information; and in response to the biometric collection information being consistent with the second authentication information and the verification result of the second authentication factor being verified passed, determining that the identity verification of the user is passed.

9. An electronic device, characterized in that, It includes: A memory and a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory, so that the electronic device executes the biometric verification method based on biometric recognition according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by the processor, they are used to implement the biometric verification method based on biometric recognition according to any one of claims 1 to 7.