Real person verification method and system
Through the user biometric verification method based on identity tokens, the actual person verification process is simplified, the efficiency is improved, the problems of user experience, security and privacy protection in the existing technology are solved, and safe and efficient real person verification is achieved.
Patent Information
- Application Number
- CN202510279206.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-20
AI Technical Summary
The existing practical verification methods have problems in user experience, security, privacy protection and compliance. The steps are cumbersome and there is a risk of data leakage. Users are worried about the abuse of information.
The user biometric verification method based on identity tokens is adopted to obtain the information to be verified through biometric recognition, and the information to be verified and the pre-installed identity token certificate are sent to the remote trusted service platform, and the verification results are received to determine whether the actual person's verification has been passed.
On the premise of ensuring security, the actual verification process is simplified, the actual verification efficiency is improved, the user experience is improved, user privacy and data security are protected, and legal and compliance issues are solved.
Smart Images

Figure CN120180411A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of real-person verification, and particularly to a real-person verification method and system. Background Art
[0002] With the development of the Internet, more and more enterprises, institutions, and governments have moved the handling of their services online, such as bank account opening, loan applications, large-amount transfers, social security services, etc. These services require real-person verification to ensure the authenticity of identities and prevent identity theft and fraud.
[0003] For existing real-person verification methods, there are still some problems in terms of user experience, security, privacy protection, and compliance. Specifically, users need to upload ID photos, perform dynamic face recognition, etc., and the steps are cumbersome, which is likely to cause inconvenience to users, especially for those who are not proficient in technology; during the real-person verification process, users' sensitive information (such as ID numbers, photos, etc.) is uploaded to the server, posing a risk of data leakage; users may feel uneasy about uploading personal photos and ID information, fearing that this information will be misused.
[0004] Therefore, there is a need for a new real-person verification method and system that can overcome the above problems. Summary of the Invention
[0005] In view of the above problems, the purpose of the present invention is to provide a real-person verification method and system, particularly a method for real-person verification based on user biometric verification of identity tokens, so as to simplify the real-person verification process and improve the real-person verification efficiency while ensuring security.
[0006] According to one aspect of the present invention, there is provided a real-person verification method, including:
[0007] Performing biometric recognition to obtain information to be verified;
[0008] Sending the information to be verified and a preset identity token certificate, wherein the information to be verified and the preset identity token certificate are sent to a remote trusted service platform via an application server;
[0009] Receiving the verification result of the remote trusted service platform on the information to be verified and the preset identity token certificate,
[0010] wherein it is determined whether the real-person verification passes according to the verification result;
[0011] When the information to be verified matches the information in the preset identity token certificate, the real-person verification passes.
[0012] Optionally, the real-person verification method further includes:
[0013] Invoke the remote trusted service platform to conduct an in-person verification on the person to be registered;
[0014] After the in-person verification is passed, issue an identity token certificate corresponding to the identity of the person to be registered, and return the identity token certificate corresponding to the identity of the person to be registered as the pre-set identity token certificate;
[0015] Store the identity token certificate corresponding to the identity of the person to be registered in the secure environments of the remote trusted service platform and the device side.
[0016] Optionally, the identity token certificate includes a user device identifier;
[0017] The sending of the information to be verified and the pre-set identity token certificate includes:
[0018] Send the user device identifier to the remote trusted service platform.
[0019] Optionally, the in-person verification method further includes:
[0020] Sign the service data with a private key in a secure environment to obtain signature data;
[0021] Send the signature data and the pre-set identity token certificate; the signature data and the identity token certificate are sent to the remote trusted service platform via the application server,
[0022] wherein, a public key corresponding to the private key is stored in the remote trusted service platform; the public key is used for signature verification;
[0023] After the in-person verification is passed, execute the service corresponding to the service data.
[0024] Optionally, the secure environment includes at least one selected from the SE environment, the TEE environment, and the system keystore.
[0025] Optionally, the biometric identification includes at least one selected from fingerprint identification, face recognition, iris recognition, retina recognition, palmprint recognition, vein recognition, and voice recognition.
[0026] Optionally, the in-person verification method further includes:
[0027] Receive an in-person verification request from an application;
[0028] Display service information;
[0029] Initialize a biometric identification control;
[0030] Display the biometric identification control for conducting the biometric identification;
[0031] After the biometric recognition is passed, the private key of the user device certificate is used to sign the service data corresponding to the service information in a secure environment to obtain a real-person verification signature.
[0032] Send the real-person verification signature and the pre-set identity token certificate to the application.
[0033] Optionally, the real-person verification method further includes:
[0034] The application sends the information to be verified, which includes the service information and the real-person verification signature, to the application server.
[0035] The application server requests the remote trusted service platform to verify the information to be verified.
[0036] The remote trusted service platform performs signature verification based on the queried identity token certificate to obtain the verification result.
[0037] The remote trusted service platform sends the verification result to the application server.
[0038] When the verification result is passed, the application server executes the service corresponding to the service data.
[0039] According to another aspect of the present invention, a real-person verification method is provided, including:
[0040] Receive the information to be verified obtained after biometric recognition and the pre-set identity token certificate.
[0041] Send the information to be verified and the pre-set identity token certificate to the remote trusted service platform.
[0042] Receive the verification result of the information to be verified and the pre-set identity token certificate by the remote trusted service platform.
[0043] Wherein, determine whether the real-person verification is passed according to the verification result.
[0044] When the information in the information to be verified matches the information in the pre-set identity token certificate, the real-person verification is passed.
[0045] According to still another aspect of the present invention, a real-person verification system is provided, including:
[0046] A device side, performing biometric recognition on the device side to obtain information to be verified; the device side sends the information to be verified and the pre-set identity token certificate to the remote trusted service platform via the application server.
[0047] The device end receives the verification result of the remote trusted service platform for the information to be verified and the preset identity token certificate.
[0048] Wherein, it is determined whether the real-person verification passes according to the verification result.
[0049] When the information to be verified matches the information in the preset identity token certificate, the real-person verification passes.
[0050] The real-person verification method and system provided by the present invention obtain the real-person verification result according to the verification result of the remote trusted service platform for the information to be verified and the preset identity token certificate after biometric recognition. On the premise of ensuring security, the process of real-person verification is simplified and the efficiency of real-person verification is improved.
[0051] Furthermore, through biometric verification, submitting the user authorization signature data indirectly completes the real-person verification, simplifies operations such as submitting ID card information and dynamic face recognition, and improves the user experience.
[0052] Furthermore, the user is identified through the user device identifier in the identity token certificate, anonymous in ordinary application services and real-name in the remote trusted service platform, ensuring user privacy and data security, preventing the risk of application institutions leaking user identity information privacy, and at the same time, the institution does not need to store user identity information data, and also solves legal and compliance issues.
[0053] Furthermore, the identity token certificate and the like are stored in a secure environment, combined with what you see is what you sign (TUI), ensuring the security and non-repudiation of user operations. Description of the Drawings
[0054] Through the following description of the embodiments of the present invention with reference to the drawings, the above and other objects, features and advantages of the present invention will become clearer. In the drawings:
[0055] Figure 1 Shows the method flow chart of the real-person verification method according to Embodiment 1 of the present invention;
[0056] Figure 2 Shows the interaction flow diagram of the real-person verification method according to Embodiment 2 of the present invention;
[0057] Figure 3 Shows the interaction flow diagram of the identity token activation according to Embodiment 3 of the present invention;
[0058] Figure 4 Shows the method flow chart of the real-person verification method according to Embodiment 4 of the present invention;
[0059] Figure 5 Shows the structural diagram of the real-person verification system according to the embodiment of the present invention. Detailed Embodiments
[0060] Various embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. In the respective drawings, the same elements are denoted by the same or similar reference numerals. For the sake of clarity, the various parts in the drawings are not drawn to scale. In addition, some well-known parts may not be shown in the drawings.
[0061] The following will further describe in detail the specific embodiments of the present invention in conjunction with the accompanying drawings and embodiments. Many specific details of the present invention are described below, such as the structure, materials, dimensions, processing techniques and technologies of components, in order to understand the present invention more clearly. However, as those skilled in the art can understand, the present invention can be implemented without these specific details.
[0062] It should be understood that when describing the structure of a component, when a layer or a region is referred to as being "above" or "over" another layer or another region, it may mean directly above the other layer or another region, or there may be other layers or regions between it and the other layer or another region. And if the component is flipped, this layer or region will be "below" or "beneath" the other layer or region.
[0063] Figure 1 A method flow chart of the real-person verification method according to Embodiment 1 of the present invention is shown. The real-person verification method according to Embodiment 1 of the present invention is executed, for example, in a device terminal, and the device terminal is, for example, a smart phone, a smart watch, etc. As Figure 1 shown, the real-person verification method according to Embodiment 1 of the present invention includes the following steps:
[0064] In step S101, biometric recognition is performed to obtain information to be verified;
[0065] Biometric recognition is performed to obtain information to be verified. Optionally, the device terminal performs biometric recognition on the user. The device terminal is, for example, a device such as a smart phone or a smart watch. The biometric recognition performed includes at least one selected from fingerprint recognition, face recognition, iris recognition, retina recognition, palmprint recognition, vein recognition, and voice recognition, etc. By performing biometric recognition, the identity of the user can be obtained. The information to be verified obtained is, for example, associated with the identity of the user obtained (the information to be verified is associated with the biometric recognition result). The data to be verified includes, for example, user authorized signature data (such as the business data etc. described later). Optionally, the private key required for signing is stored in the secure environment (carrier) of the device terminal.
[0066] In step S102, the information to be verified and a preset identity token certificate are sent;
[0067] The device side sends the information to be verified and the pre-set identity token certificate. Optionally, the device side sends the information to be verified and the pre-set identity token to the application server, and then the application server sends the received information to be verified and the pre-set identity token to the remote trusted service platform. Optionally, the pre-set identity token certificate includes a user device identifier (UserDevice Identifier, UDI), and the user device identifier has the feature of one device one key, which can effectively prevent the identity from being misused. Optionally, the user device identifier is an identification number associated with both the user and the trusted device generated by the remote trusted service platform (RTSP) for the user's trusted device according to rules; the user device identifiers of the same user on different devices are also different, and the user device identifier is bound to the user device certificate.
[0068] In step S103, receive the verification result of the information to be verified and the pre-set identity token certificate from the remote trusted service platform.
[0069] The device side receives the verification result of the information to be verified and the pre-set identity token certificate from the remote trusted service platform. When the information to be verified matches the information in the pre-set identity token certificate, (the remote trusted service platform determines that) the real person verification passes. (The device side) determines whether the real person verification passes according to the verification result.
[0070] In an alternative embodiment of the present invention, the identity token certificate includes a user device identifier. The step of sending the information to be verified and the pre-set identity token certificate includes: sending the user device identifier to the remote trusted service platform.
[0071] In an alternative embodiment of the present invention, the real person verification method further includes: signing the service data with a private key in a secure environment to obtain signature data; sending the signature data and the pre-set identity token certificate; the signature data and the identity token certificate are sent to the remote trusted service platform via the application server, wherein the public key corresponding to the private key is stored in the remote trusted service platform; the public key is used for signature verification; after the real person verification passes, execute the service corresponding to the service data. Optionally, the secure environment includes at least one selected from the group consisting of an SE (Secure Element) environment, a TEE (trusted execution environment) environment, and a system keystore.
[0072] According to the real-person verification method of the embodiments of the present invention, the authorized user operation is verified through biometric identification, replacing the traditional indirect real-person verification by submitting user identity information, with a simple process; the verification signature service provided by the authoritative server ensures the authenticity of the user's real-person verification, ensuring that the user who signs the authorization and activates the identity token is the same person, indirectly completing the real-person verification and ensuring security; for the real-person verification based on the identity token, the general application service can achieve the purpose of real-person verification without contacting the user's identity data, and protects the user's privacy; the data and key of the identity token are stored in a secure environment, and the calculation of the key is all carried out in the secure environment, ensuring the security of the operation.
[0073] Figure 2 Fig. shows the interaction process schematic diagram of the real-person verification method according to the second embodiment of the present invention. As Figure 2 shown, the real-person verification method according to the second embodiment of the present invention includes the following steps:
[0074] Step 1: Initiate a real-person verification service request. The user opens and logs in to the general application program 120, and initiates a real-person verification service request according to the operation that requires real-person verification for business needs (such as large-amount transfer, bank account opening).
[0075] Step 1.1: Request real-person verification (business data). The general application program 120 (to the security carrier 110) calls the system service to request the real-person verification interface to request the real-person verification of the business data.
[0076] Step 1.1.1: The TUI displays the business information. The system service (security carrier 110) displays the business information through the TUI (Trusted UI, trusted UI), and the user confirms the business information.
[0077] Step 1.1.2: Initialize the biometric (feature) recognition control.
[0078] Step 1.1.3: Display the biometric (feature) recognition control.
[0079] Step 1.1.3.1: The user's biometric (feature) recognition verification. The user performs biometric recognition verification according to the prompts of the biometric recognition control, such as pressing the fingerprint / face recognition.
[0080] Step 1.1.4: Use the UDC-SK to sign (the business data, UDI) in the TEE / SE secure environment. After the biometric recognition verification passes, the system service signs the business data with the private key in the secure environment and returns the real-person verification signature and UDI to the general application program 120.
[0081] Step 2: Request real-person verification (business data, real-person verification signature, UDI). The general application 120 requests the application server 200 to send information such as business data, real-person verification signature, and UDI, and requests real-person verification of this information.
[0082] Step 2.1: Signature verification request (signature data, real-person verification signature, UDI). The application server 200 accepts the request and forwards the request data to the remote trusted service platform server (RTSP) 300, requesting verification of the signature data, real-person verification signature, and UDI.
[0083] Step 2.1.1: Find the identity token certificate (UDI).
[0084] Step 2.1.2: Verify the signature of the identity token certificate (signature data, real-person verification signature). The remote trusted service platform server 300 finds the identity UDC (User Device Cert) according to the UDI and uses the UDC to verify the signature to ensure that the business operation is authorized by the person himself.
[0085] Step 2.1.3: Save the verification record information. The remote trusted service platform server 300 saves the verification record information, archives all the data records during the verification process for subsequent query and verification. The remote trusted service platform server 300 returns the real-person verification result to the application server 200.
[0086] Step 2.2: Save the verification record information. The application server 200 saves the verification record information.
[0087] Step 2.3: Complete the business operation according to the verification result. The application server 200 completes the business operation (such as large amount transfer, bank account opening) according to the real-person verification result and returns the real-person verification result to the general application 120.
[0088] In an optional embodiment of the present invention, the real-person verification method further includes (identity token activation):
[0089] Call the remote trusted service platform to conduct real-person review on the to-be-registered real person;
[0090] After the real-person review is passed, issue an identity token certificate corresponding to the identity of the to-be-registered real person, and return the identity token certificate corresponding to the identity of the to-be-registered real person as the preset identity token certificate;
[0091] Store the identity token certificate corresponding to the identity of the to-be-registered real person in the secure environments of the remote trusted service platform and the device side.
[0092] Optionally, the remote trusted service platform invokes an authoritative database (such as the public security system) for real-person verification. The identity token (certificate) is an identity authentication technology based on domestic independent cryptographic technology and carried by an intelligent trusted terminal security environment (such as TEE / SE). It can achieve identity recognition and authentication while protecting personal identity information.
[0093] Figure 3 FIG. 4 shows a schematic diagram of the interaction process for identity token activation according to Embodiment 3 of the present invention. As Figure 3 shown, the interaction for identity token activation according to Embodiment 3 of the present invention occurs among the user, the management application 130, the security carrier 110, and the remote trusted service platform server 300.
[0094] First, a unified description is given for the terms that may be involved in the identity token activation interaction (the real-person verification method and system described in this application):
[0095] Identity Token refers to the identity proof data used to present to the authenticator in this product.
[0096] Identity Token System refers to the technical system that supports the operation of the identity token product.
[0097] Remote Trusted Service Platform (RTSP), that is, the remote trusted service platform server 300.
[0098] Certificate Authority (CA) server, which is a part of the RTSP and is responsible for issuing, managing, storing, and revoking digital certificates.
[0099] User Device Cert (UDC) refers to the digital certificate issued by the RTSP for the user's trusted device.
[0100] User Device Identifier (UDI) refers to an identification number generated by the RTSP for the user's trusted device according to rules and associated with both the user and the trusted device. The UDIs of the same user on different devices are different, and the UDI is bound to the user device certificate.
[0101] Trusted Device Key (TDK) is the trusted device authentication key deployed by the device manufacturer to the device. The TDK can be invoked through the TEE interface and used to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer.
[0102] The Trusted Device Authentication Server, which forms part of the RTSP, is responsible for verifying the data signed with the TDK in the device to ensure that the data originates from a legitimate device trusted by the device manufacturer.
[0103] Provide a unified description of the keys that may be involved in this application:
[0104] The Trusted Device Key (abbreviated as TDK) is the trusted device authentication key deployed by the device manufacturer to the device. The TDK is called through the TEE interface and used to sign data to ensure that the data originates from a legitimate device trusted by the device manufacturer. The trusted device key is generated or pre - installed in the secure carrier 110. The secure carrier 110 holds the private key of the trusted device key, and the RTSP holds the public key or certificate of the trusted device key.
[0105] The RTSP Platform Key (abbreviated as RTSP - TK) is created or pre - installed by the RTSP. The RTSP holds the private key of the RTSP platform key, and the secure carrier 110 pre - installs the public key of the RTSP platform key.
[0106] The CA Root Key (abbreviated as CA - ROOT) is the key used by the certificate issuing server in the RTSP to issue certificates. The CA root key is generated or pre - installed by the RTSP. The RTSP stores the private key and certificate of the CA root key; the CA - ROOT certificate is also distributed to the authentication device 500.
[0107] The public key or public key certificate of the Application Business Authentication Key (abbreviated as ABA - PK) is used for the general application 120 to verify the real - person information service authorization package submitted when calling the secure carrier 100. This authorization package is signed by the RTSP using the corresponding private key. The public key or public key certificate of the application business authentication key is pre - installed or dynamically generated by the RTSP to generate an application authorization verification key pair, and the public key is pre - installed or synchronized (stored) to the secure carrier 110.
[0108] The private key of the Application Authorization Verification Key (abbreviated as ABA - SK) is stored in the RTSP. The RTSP uses this key to authorize and sign the real - person information service submitted by the application.
[0109] The Token Encryption Master Key (abbreviated as TEK - MK) is used to decentralize the master key for each identity token encryption key. The token encryption master key is created or pre - installed by the RTSP and synchronized to the authentication device 500. The token encryption master key is stored in the RTSP / authentication device 500.
[0110] The Token Encryption Sub - Key (abbreviated as TEK - DK) is the key used to encrypt identity token data on the user device side. The token encryption sub - key is decentralized by the RTSP and transmitted (stored) to the secure carrier 110.
[0111] The Secure Channel Key Set (abbreviated as SCKs, specifically including the encryption key SCK-ENC and the verification key SCK-HMAC) is used to establish a secure channel between the secure carrier 110 and RTSP, and is created during the process of opening the user device certificate. The Secure Channel Key Set is randomly generated by RTSP and synchronized to the secure carrier 110. The Secure Channel Key Set is stored in RTSP / secure carrier 110.
[0112] The user device certificate key pair (including the user device certificate private key UDC-SK and the user device certificate public key UDC-PK) is created and generated (randomly generated) by the secure carrier 110, and the public key is exported to RTSP for signing the user device certificate (UDC-PK is exported and sent to RTSP). The private key is used for business confirmation signatures, and the public key is used for signature verification. The secure carrier 110 saves UDC-SK and the UDC signed by RTSP; RTSP saves the UDC.
[0113] The identity information submission temporary asymmetric encryption key (abbreviated as IEK) is used for encrypting and protecting the identity information when submitting the identity information to the application. It is generated by the application server 200 and synchronized to the secure carrier 110 after being authenticated by RTSP. The application server 200 caches or saves the private key of the identity information submission temporary asymmetric encryption key.
[0114] Specifically, the user sends a function activation request to the management application 130 (the user operates the management application 130 for activation); the management application 130 collects the user's identity information and the on-site face (takes a face photo), and the user provides the identity information and the taken on-site face to the management application 130.
[0115] The secure carrier 110 obtains the ciphertext of the face information from the management application 130, calculates and saves the face feature template (calculates and saves the face feature data obtained by using the face photo), and encrypts the identity information and the face photo using the public key of RTSP-TK. Here, RTSP-TK is, for example, the key of the remote trusted service platform server. The secure carrier 110 sends the ciphertext of the identity information to the management application 130.
[0116] The management application 130 submits a live person verification to the remote trusted service platform server 300. The submitted live person verification includes the ciphertext of the identity information (the user's identity information and the face ciphertext). The remote trusted service platform server 300 decrypts the identity information and the photo (the user's identity and face data) using the private key of RTSP-TK, and conducts a comparison with the database of the authoritative agency service (face). The remote trusted service platform server 300 returns the comparison result to the management application 130.
[0117] The management application 130 invokes the security carrier 110 to create an activation request. The security carrier 110 performs a security check on the device status, creates a UDC-SK key pair (the generation of the UDC-SK key has the property of one key per device), assembles the activation request data (including at least the public key of the security key pair, the device identifier, and the self-signature), and uses the TDK (Trusted Device Key) to sign the activation request data (secondarily). Among them, the security carrier 110 requests the user to set the key PIN code (pops up the TUI for the user to set the PIN code). The security carrier 110 returns the activation request data to the management application 130.
[0118] The management application 130 sends the activation request to the remote trusted service platform server 300. The activation request includes the activation request data. The remote trusted service platform server 300 uses the TDK public key to verify the activation request data, generates the UDI, issues the UDC (generates the user device identifier UDI according to the user information and issues the user device certificate UDC), generates the SCKs, uses the TEK-MK (for the user device identifier) to disperse the sub-key TEK-DK, and uses the SCKs to encrypt the UDC, TEK-DK, UDI, and user identity information, and uses the UDC-PK to encrypt the SCKs. The remote trusted service platform server 300 sends the activation response data (including the above data) to the management application 130.
[0119] The management application 130 imports the activation response (activation response data) to the security carrier 110. The security carrier 110 uses the UDC-SK to decrypt the SCKs, and then uses the SCKs to decrypt and save the UDC, UDI, TEK-DK, and user identity information. The security carrier 110 binds the local biometric feature. If the binding is successful, the trusted token can be unlocked by using the local biometric feature verification.
[0120] Figure 4 The method flow chart of the real person verification method according to Embodiment 4 of the present invention is shown. The real person verification method according to Embodiment 4 of the present invention is executed in an application server, for example. The corresponding (ordinary) application program of the application server runs on the device side (such as a smart phone, a smart watch, etc.). As Figure 4 shown, the real person verification method according to Embodiment 4 of the present invention includes the following steps:
[0121] In step S201, the information to be verified obtained after biometric recognition and the preset identity token certificate are received;
[0122] The application server receives the information to be verified obtained after biometric recognition and the preset identity token certificate, that is, receives the information to be verified and the preset identity token certificate provided by the device side.
[0123] In step S202, the information to be verified and the pre-set identity token certificate are sent to the remote trusted service platform;
[0124] The application server sends the information to be verified and the pre-set identity token certificate to the remote trusted service platform.
[0125] In step S203, the verification result of the information to be verified and the pre-set identity token certificate by the remote trusted service platform is received.
[0126] The application server receives the verification result of the information to be verified and the pre-set identity token certificate by the remote trusted service platform. Determine whether the real-person verification passes according to the verification result. Among them, when the information to be verified matches the information in the pre-set identity token certificate, (the remote trusted service platform judges) the real-person verification passes.
[0127] According to another aspect of the present invention, a real-person verification system is provided. The real-person verification system is used to implement the real-person verification method as described above. The real-person verification system according to an embodiment of the present invention includes a device end. The device end is, for example, a smart phone, a smart watch, etc.
[0128] Biometric recognition is performed at the device end to obtain the information to be verified; the device end sends the information to be verified and the pre-set identity token certificate to the remote trusted service platform via the application server.
[0129] The device end receives the verification result of the information to be verified and the pre-set identity token certificate by the remote trusted service platform.
[0130] Among them, it is determined whether the real-person verification passes according to the verification result; when the information to be verified matches the information in the pre-set identity token certificate, the real-person verification passes.
[0131] Figure 5 Shows a schematic structural diagram of the real-person verification system according to an embodiment of the present invention. As Figure 5 As shown, in a specific embodiment of the present invention, the real-person verification system includes at least one of the following components:
[0132] The terminal device (mobile terminal / device end) 100 is a terminal device held by a user, such as a smart phone, a smart watch, etc. The terminal device 100 is integrated with a security carrier (such as TEE or SE or both).
[0133] The secure carrier 110 is a software and hardware module on the terminal device 100. Internally, it accesses the TEE\SE to implement the secure function interface and provides the interface to external applications. Among them, the secure carrier access service program 111 provides the entity program for the external interface of the secure carrier 110. It accesses the TEE\SE to implement the functional interface encapsulation of the identity token and provides external calls. The TEE (Trusted Execution Environment) 112 is a type of secure carrier, which is a logical secure isolation area of the system SOC and can execute secure application programs. The SE (Secure Element) 112 is generally an independent encryption chip. Due to its independent isolation characteristics, it has a higher security level than the TEE. Invoking the SE interface in the TEE can further ensure business security.
[0134] The general application program 120 is an application program that invokes the secure carrier 110 to call various functions of the identity token. The management application program 130 is an application program that invokes the secure carrier 110 to perform identity token activation management.
[0135] The remote trusted service platform server 300 is the general term for services participating in the operation of the identity token service, including but not limited to: authoritative identity authentication service, certificate issuance service, identity token verification service, activation management service, application access service, etc., and also includes the background services related to terminal device manufacturers.
[0136] The application server 200 is the background service of the general application program 120 and processes the authentication requests of the general application program 120.
[0137] The authentication device 500 is a device used to verify and authenticate the identity token generated by the terminal device.
[0138] The real-person verification method and system according to the embodiments of the present invention have an identity token certificate enabled (the real-person verification in the process of enabling the identity token certificate can be implemented using existing technologies). For the identity token certificate, the background server is provided by the RTSP (public security / authority server), and the user identity information data is encrypted end-to-end. Only the RTSP can access the user identity information, ensuring that the user privacy is not leaked to any ordinary application service; the process of enabling the identity token ensures that the UDI can have the feature of one device one key, which can effectively prevent the identity from being misused. After enabling the identity token certificate, the solution of the present application indirectly completes the real-person verification of the user through the biometric verification of the user himself / herself. During the process, the user does not need to submit the user identity information again, solving the user experience problem; only the signed data and UDI after the user's biometric verification and authorization need to be submitted to the ordinary application server, and the RTSP is requested to verify the signature to ensure that the authorized user and the user who enabled the identity token are the same person, indirectly completing the real-person verification; the ordinary application server only records the UDI and the signed data, solving the problems of user privacy, data security, law and compliance. After being authorized by the RTSP, the real-name information of the user can be queried through the UDI.
[0139] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0140] As described above in accordance with the embodiments of the present invention, these embodiments do not describe all the details in detail, nor limit the invention to the specific embodiments described. Obviously, according to the above description, many modifications and variations can be made. The present specification selects and specifically describes these embodiments in order to better explain the principle and practical application of the present invention, so that those skilled in the art can make good use of the present invention and its modifications based on the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A real person verification method, comprising: Perform biometric identification to obtain information to be verified; Sending the information to be verified and the preset identity token certificate, wherein the information to be verified and the preset identity token certificate are sent to the remote trusted service platform via the application server; receiving a verification result of the remote trusted service platform on the information to be verified and the preset identity token certificate, Wherein, determining whether the real person verification has passed according to the verification result; When the information to be verified matches the information in the preset identity token certificate, the real person verification is passed.
2. The real person verification method according to claim 1, wherein: The real person verification method also includes: Calling the remote trusted service platform to conduct a real person review of the real person to be registered; After the real person is reviewed and approved, an identity token certificate corresponding to the real person identity to be registered is issued, and the identity token certificate corresponding to the real person identity to be registered is returned as the preset identity token certificate; The identity token certificate corresponding to the real person identity to be registered is stored in the security environment of the remote trusted service platform and the device end.
3. The real person verification method according to claim 1, wherein: The identity token certificate includes a user device identifier; The sending of the information to be verified and the preset identity token certificate includes: The user equipment identifier is sent to the remote trusted service platform.
4. The real person verification method according to claim 1, wherein: The real person verification method also includes: Use the private key to sign the business data in a secure environment to obtain the signed data; Sending the signature data and the preset identity token certificate; the signature data and the identity token certificate are sent to the remote trusted service platform via the application server, Wherein, the remote trusted service platform stores a public key corresponding to the private key; the public key is used for signature verification; After the real person verification is passed, the business corresponding to the business data is executed.
5. The real person verification method according to claim 4, wherein: The security environment includes at least one selected from a SE environment, a TEE environment, and a system keystore.
6. The real person verification method according to claim 1, wherein: The biometric recognition includes at least one selected from fingerprint recognition, face recognition, iris recognition, retina recognition, palm print recognition, vein recognition and voice recognition.
7. The real person verification method according to claim 1, wherein: The real person verification method also includes: Receive real-person verification requests from applications; Display business information; Initialize biometric controls; Displaying the biometric recognition control to perform the biometric recognition; After the biometric feature recognition is passed, the business data corresponding to the business information is signed using the private key of the user device certificate in a secure environment to obtain a signature verified by a real person; The real person verification signature and the preset identity token certificate are sent to the application.
8. The real person verification method according to claim 7, wherein: The real person verification method also includes: The application sends the information to be verified to the application server, where the information to be verified includes the business information and the real person verification signature; The application server requests the remote trusted service platform to verify the information to be verified; The remote trusted service platform verifies the signature according to the queried identity token certificate to obtain the verification result; The remote trusted service platform sends the verification result to the application server; When the verification result is passed, the application server executes the business corresponding to the business data.
9. A real person verification method, comprising: Receiving the information to be verified and the preset identity token certificate obtained after biometric identification; Sending the information to be verified and the preset identity token certificate to a remote trusted service platform; receiving a verification result of the remote trusted service platform on the information to be verified and the preset identity token certificate, Wherein, determining whether the real person verification has passed according to the verification result; When the information to be verified matches the information in the preset identity token certificate, the real person verification is passed.
10. A real person verification system, comprising: On the device side, biometric identification is performed on the device side to obtain information to be verified; The device sends the information to be verified and the preset identity token certificate to the remote trusted service platform via the application server; The device receives the verification result of the remote trusted service platform on the information to be verified and the preset identity token certificate, Wherein, determining whether the real person verification has passed according to the verification result; When the information to be verified matches the information in the preset identity token certificate, the real person verification is passed.