Real person verification method and system
Through offline real-person verification on the device side and signature verification using identity token certificates, the problems of high network bandwidth, high server pressure, high cost and high data security requirements in the medium and high frequency usage scenarios of the existing technology are solved, and efficient and secure real-person verification is achieved.
Patent Information
- Application Number
- CN202510283095.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-20
AI Technical Summary
In high-frequency usage scenarios, existing practical verification technology has problems such as high network bandwidth, high server pressure, high cost and high demand for sensitive data security.
An offline real-person verification system based on the device side is adopted, and the real-time facial information is obtained through the device side, and the stored facial information is compared with the verification results are obtained. The identity token certificate is used for signature verification, which reduces the number of online verifications and reduces server pressure and cost.
It improves the efficiency of real-person verification, reduces network consumption, reduces the cost of online real-person verification, and ensures the security of data through secure storage and digital signatures.
Smart Images

Figure CN120180412A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of real-person verification, and particularly to a real-person verification method and system. Background Art
[0002] With the rapid development of information technology, the world has entered the digital age, and the Internet has penetrated into all aspects of society widely and deeply. Online business scenarios have shown explosive growth. For example, quick payment in the field of e-finance, diverse social platforms in the mobile Internet environment, online service channels in the government affairs system, and remote office collaboration in enterprise operation have become an indispensable part of people's daily life and work. In this process, the authentication link to ensure the authenticity of user identity faces severe challenges.
[0003] In the prior art, real-person verification is a solution for online verification of personal identity authenticity. It combines multiple biometric technologies and identity information verification means to ensure the authenticity and security of user identity in the network space. Real-person verification is widely applied in multiple fields such as finance, telecommunications, e-commerce, and government affairs, especially in scenarios such as remote account opening, online transactions, and account registration.
[0004] However, in the existing real-person verification, the following problems often exist:
[0005] 1. In scenarios where real-person verification is frequently required, due to the large amount of live video data and large access volume, there is a disadvantage of high network bandwidth requirements, such as in the scenarios of online education and online games;
[0006] 2. Real-person verification requirements are often used in large application scenarios with high penetration rate and usage rate, and there are requirements for high server concurrency and high server pressure;
[0007] 3. Online real-person verification services will use services such as live body recognition and information comparison, and the content of these services all requires corresponding payment costs, and there will be a defect of high cost when the demand is frequent;
[0008] 4. The security requirements for sensitive data such as human portraits and identity information in the real-person verification process are high.
[0009] Therefore, it is hoped that there can be a new real-person verification method and system that can overcome the above problems. Summary of the Invention
[0010] In view of the above problems, the purpose of the present invention is to provide a real-person verification method and system, especially an offline real-person verification system based on the device side, so as to complete real-person verification on the device side and improve the verification efficiency.
[0011] According to one aspect of the present invention, there is provided a real-person verification method, including:
[0012] The device side receives a real - person verification request from the requester;
[0013] The device side acquires real - time face information;
[0014] The device side compares the real - time face information with the stored face information stored in the device side to obtain a verification result;
[0015] Send the verification result to the requester.
[0016] Optionally, the real - person verification method further includes:
[0017] The device side acquires reference face information at a first moment and the corresponding identity information;
[0018] The device side sends the reference face information and the identity information to a remote trusted service platform server and requests the remote trusted service platform server to verify whether the reference face information and the identity information match;
[0019] When the reference face information and the identity information match, an identity token certificate is issued;
[0020] Obtain the stored face information according to the reference face information;
[0021] Store the stored face information and the identity token certificate in the secure storage unit of the device side,
[0022] wherein, the identity token certificate is used for signing the verification result.
[0023] Optionally, the secure storage unit includes at least one selected from the SE environment, the TEE environment, and the system keystore.
[0024] Optionally, the real - person verification method further includes:
[0025] Obtain a public key and the corresponding private key;
[0026] Send the public key to the requester;
[0027] Store the private key in the secure storage unit of the device side,
[0028] wherein, after the device side signs the verification result with the private key, the signed verification result is sent to the requester.
[0029] Optionally, the device side issues an identity token certificate, which includes a public key, and the private key corresponding to the public key is stored in the device side; the device side uses the private key to sign the verification result to obtain a signed verification result;
[0030] The real person verification method further includes:
[0031] The requesting party receives the signed verification result and the identity token certificate;
[0032] The requesting party verifies the identity token certificate;
[0033] The requesting party verifies the signature according to the identity token certificate and confirms the verification result.
[0034] Optionally, the device side issues an identity token certificate, which includes a public key, and the private key corresponding to the public key is stored in the device side; the device side uses the private key to sign the verification result to obtain a signed verification result;
[0035] The real person verification method further includes:
[0036] The requesting party receives the signed verification result;
[0037] The requesting party reports the signed verification result to the application server; the application server applies to the remote trusted service platform server for online verification of the verification result;
[0038] The remote trusted service platform server searches for the pre-stored identity token certificate;
[0039] The remote trusted service platform uses the identity token certificate to verify the signature of the signed verification result to obtain a real person verification result;
[0040] The requesting party receives the real person verification result.
[0041] Optionally, the real person verification method further includes:
[0042] The requesting party invokes system biometric identification for biometric verification;
[0043] After the biometric verification is passed, the device side compares the real-time face information with the stored face information stored in the device side.
[0044] Optionally, the real person verification method further includes:
[0045] When obtaining the real-time face information, liveness detection is performed.
[0046] According to another aspect of the present invention, there is provided a real person verification method, including:
[0047] Obtaining reference face information and identity information;
[0048] Verifying whether the reference face information and the identity information match;
[0049] When the reference face information and the identity information match, allowing the issuance of an identity token certificate,
[0050] wherein the identity token certificate is used to complete the comparison between the real-time face information and the stored face information stored in the device end at the device end.
[0051] According to still another aspect of the present invention, there is provided a real person verification system, including:
[0052] A device end, which receives a real person verification request from a requester and obtains real-time face information; the device end compares the real-time face information with the stored face information stored in the device end to obtain a verification result, and sends the verification result to the requester.
[0053] The real person verification method and system provided by the present invention compare real-time face information with stored face information at the device end for real person verification, without the need for online verification, thereby improving the verification efficiency.
[0054] Further, by performing real person verification through an online verification method, after the verification is passed, an identity token certificate is issued for subsequent offline verification at the device end, thereby reducing the number of online real person verification times, reducing the bandwidth requirements and service processing pressure of the background server, and reducing the verification cost of online real persons; offline real person verification not only reduces network consumption but also improves efficiency.
[0055] Further, sensitive information such as identity token certificates is stored in secure storage units such as TEE and SE, ensuring the security of identity information.
[0056] Further, the verification result is encrypted using a private key and sent to the requester with the corresponding public key, ensuring the security of the transmission of the verification result. Description of the Drawings
[0057] Through the following description of the embodiments of the present invention with reference to the drawings, the above and other objects, features, and advantages of the present invention will become clearer. In the drawings:
[0058] Figure 1 A method flow chart of the real person verification method according to an embodiment of the present invention is shown;
[0059] Figure 2Shows a schematic storage process diagram in the real-person verification method according to an embodiment of the present invention;
[0060] Figure 3 Shows a schematic cancellation process diagram in the real-person verification method according to an embodiment of the present invention;
[0061] Figure 4 Shows a schematic offline verification process diagram in the real-person verification method according to an embodiment of the present invention;
[0062] Figure 5 Shows a schematic online verification process diagram in the real-person verification method according to an embodiment of the present invention;
[0063] Figure 6 Shows an interactive schematic diagram of the identity token activation in real-person authentication according to an embodiment of the present invention;
[0064] Figure 7 Shows a method flow diagram of the real-person verification method according to another embodiment of the present invention;
[0065] Figure 8 Shows a schematic structural diagram of the real-person verification system according to an embodiment of the present invention. Detailed implementation manners
[0066] The various embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. In each of the drawings, the same elements are denoted by the same or similar reference numerals. For clarity, the various parts in the drawings are not drawn to scale. In addition, some well-known parts may not be shown in the figures.
[0067] The following will further describe in detail the specific implementation manners of the present invention in conjunction with the accompanying drawings and embodiments. Many specific details of the present invention are described below, such as the structure, materials, dimensions, processing techniques and technologies of components, in order to understand the present invention more clearly. However, as those skilled in the art can understand, the present invention can be implemented without these specific details.
[0068] It should be understood that when describing the structure of a component, when a layer or a region is referred to as being "above" or "over" another layer or another region, it may mean directly above the other layer or another region, or there may be other layers or regions between it and the other layer or another region. And if the component is flipped, this layer or region will be "below" or "beneath" the other layer or another region.
[0069] Figure 1 Shows a method flow diagram of the real-person verification method according to an embodiment of the present invention. As Figure 1As shown, the real-person verification method according to an embodiment of the present invention is executed by a device terminal (such as a smart phone, a smart watch, etc.), and specifically includes the following steps:
[0070] In step S101, the device terminal receives a real-person verification request from the requester;
[0071] The device terminal receives a real-person verification request from the requester. The device terminal is, for example, a device such as a smart phone or a smart watch, and what receives the real-person verification request is, for example, a security carrier of the device terminal. The requester is, for example, a (general) application program that can run on the device terminal.
[0072] In step S102, the device terminal acquires real-time face information;
[0073] The camera of the device terminal is called to acquire the real-time face information of the user (take a real-time facial image).
[0074] In step S103, the device terminal compares the real-time face information with the face information stored in the device terminal to obtain a verification result;
[0075] The device terminal compares the acquired real-time face information with the face information stored in the device terminal to obtain a verification result. The verification result includes at least two cases: the real-time face information is consistent with the stored face information, and the real-time face information is inconsistent with the stored face information. Optionally, only the face information of one user is stored in the device terminal for the real-person verification of one user. Optionally, the face information of multiple users is stored in the device terminal, which can be used for the real-person verification of multiple users.
[0076] In step S104, the verification result is sent to the requester.
[0077] After obtaining the verification result, the verification result is sent to the requester.
[0078] In an optional embodiment of the present invention, the real-person verification method further includes:
[0079] Acquire a public key and a private key corresponding to the public key;
[0080] Send the public key to the requester;
[0081] Store the private key in the secure storage unit of the device terminal;
[0082] After encrypting the verification result with the private key, send the encrypted verification result to the requester.
[0083] Optionally, the real-person verification method further includes:
[0084] The requester calls the system biometric identification for biometric verification;
[0085] After biometric verification is passed, the device compares the real-time face information with the stored face information stored in the device.
[0086] Optionally, the real person verification method further includes: performing liveness detection when acquiring real-time face information. For example, through various technical means, such as RGB, near-infrared, or 3D structured light, etc., to determine whether the target object is a real person to prevent cheating attacks. Specifically, in order to prevent the system from being deceived by photos, videos, or masks, the real person verification system will adopt liveness detection technology and require the user to perform actions such as blinking and nodding to confirm that the submitted biometric features come from a real human body.
[0087] In an alternative embodiment of the present invention, the real person verification method further includes:
[0088] The device acquires reference face information at a first moment and the corresponding identity information for the reference face information. The reference face information is, for example, facial image information acquired during the registration process; the identity information is, for example, the identity document information submitted by the user, such as ID number, name, photo, etc.
[0089] The device sends the reference face information and the identity information to the remote trusted service platform server and requests the remote trusted service platform server to verify whether the reference face information and the identity information match. The remote trusted service platform server, for example, calls the information of an authoritative CA institution to verify whether the reference face information and the identity information match. For example, the collected information is compared with the records in an authoritative database (such as the household registration database of the Ministry of Public Security) to verify the authenticity of the information.
[0090] In the case where the reference face information and the identity information match, (the device and / or the remote trusted service platform server) issues an identity token certificate. Among them, the identity token certificate is used for signing the verification result.
[0091] The stored face information is obtained according to the reference face information, and the stored face information and the identity token certificate are stored in the secure storage unit of the device. The secure storage unit includes at least one selected from the SE environment, the TEE environment, and the system keystore.
[0092] Further, in combination with Figure 2 the specific embodiment shown, in the real person verification method, the real person information management device of the device stores the real person information. The storage process includes the following steps:
[0093] Step 1: The general application 120 collects user information and face information.
[0094] The general application 120 collects real-time face data through peripherals such as cameras, and collects the user's identity information (name, identity information, etc.) through the interface input method.
[0095] After user information and facial information are collected, enter the identity token (certificate) activation process.
[0096] Step 2: Store face information and identity token certificate.
[0097] After the identity token is activated, the general application 120 calls the security carrier 110 to store the face information and the identity token certificate in the security carrier 110. Among them, the security carrier 110 can determine the specific medium to be used according to the business security requirements, and the reference range can be SE environment, TEE environment, and system keystore.
[0098] Figure 3 FIG. 2 shows a schematic diagram of the cancellation process in the real person verification method according to an embodiment of the present invention. Figure 3 As shown, in the real person verification method, the real person information management device on the device side cancels the real person information. The cancellation process includes the following steps:
[0099] Step 1: Cancel real person information;
[0100] The general application 120 enters the logout real person information.
[0101] Step 1.1: Obtain user logout authorization;
[0102] The common application 120 first obtains user authorization;
[0103] Step 1.2: Sign the cancellation request (cancellation request);
[0104] The general application 120 assembles the deregistration request and calls the secure carrier 110 to obtain the signature;
[0105] Step 1.2.1: Sign with UDC-SK (Deregistration Request);
[0106] The secure element 110 signs the deregistration request using UDC-SK; thereafter, the secure element 110 returns the UDI and the signature to the normal application 120 .
[0107] Step 1.3: Cancellation Request (Cancellation Request, UDI, Signature);
[0108] The common application 120 initiates a logout request to the application server 200 .
[0109] Step 1.3.1: Verify signature (cancellation request, UDI, signature);
[0110] After receiving the request, the application server 200 verifies the signature with the remote trusted service platform server 300 .
[0111] Step 1.3.1.1: Search for the identity token certificate (UDI);
[0112] The remote trusted service platform server 300 searches for the identity token certificate through the UDI.
[0113] Step 1.3.1.2: Verify the signature using the identity token certificate;
[0114] The remote trusted service platform server 300 verifies the signature using the identity token certificate; afterwards, the remote trusted service platform server 300 sends the verification result to the application server 200. The application server 200 then sends the verification result to the ordinary application 120.
[0115] Step 1.4: Cancel the real-person information;
[0116] After receiving the verification result, the ordinary application 120 calls the security carrier 110 to cancel the real-person information.
[0117] Step 1.4.1: Remove the face information and digital certificate.
[0118] The security carrier 110 removes the face information and the certificate.
[0119] In an alternative embodiment of the present invention, the device side issues the identity token certificate. The identity token certificate includes a public key. The private key corresponding to the public key is stored in the device side. The device side uses the private key to sign the verification result to obtain the signed verification result. The real-person verification method further includes:
[0120] The requestor receives the signed verification result and the identity token certificate, and verifies the identity token certificate;
[0121] The requestor verifies the signature according to the identity token certificate and confirms the verification result.
[0122] Further, in combination with Figure 4 the specific embodiment shown, in the real-person verification method, the device-side real-person information usage device performs offline real-person verification. Through the real-time face data collected by the device side, using the built-in offline face recognition algorithm, it is compared with the real-person information securely stored in the device side. Then, through the authorization of the authorized user, the device private key corresponding to the digital certificate is used to sign the offline verification result to ensure the reliability of the verification result when transmitted externally. Figure 4 The real-person verification method shown includes the following steps:
[0123] Step 1: Call the device peripherals to collect real-time face information;
[0124] The ordinary application 120 collects real-time face information through device peripherals (such as cameras).
[0125] Step 2: Invoke the system biometric authentication;
[0126] The general application 120 invokes the system biometric authentication, and the user performs biometric authentication (fingerprint authentication, face ID authentication, etc.).
[0127] Step 3: Real-person verification request (real-time face information);
[0128] The general application 120 calls the security carrier 110 to apply for real-person verification.
[0129] Step 3.1: Verify the biometric authentication result;
[0130] The security carrier 110 first verifies the biometric authentication result.
[0131] Step 3.2: Compare with the offline face recognition algorithm;
[0132] The security carrier 110 uses the offline face recognition algorithm to compare the face information stored locally with the real-time face information transmitted by the general application 120.
[0133] Step 3.3: Use the UDC-SK signature to compare the results;
[0134] The security carrier 110 uses the UDC-SK signature to compare the results; then, it sends the identity token certificate, comparison result, and signature to the general application 120.
[0135] Step 4: Verify the identity token;
[0136] After receiving the response data (identity token certificate, comparison result, and signature), the general application 120 first verifies the identity token certificate.
[0137] Step 5: Sign with the identity token certificate and confirm the verification result.
[0138] The general application 120 uses the identity token certificate to verify the signature and confirm the verification result.
[0139] In the above embodiments of the present invention, face detection and recognition (offline face recognition) can be performed without a network connection. Through the algorithm running on the device side, the face in the video stream is monitored in real time, and tracking, key point positioning, quality monitoring, picture acquisition, and face comparison are performed, etc. The offline real-person verification method avoids data transmission through the network, reduces network latency, reduces the risk of data leakage, protects privacy, and improves security.
[0140] In an alternative embodiment of the present invention, the device side issues an identity token certificate. The identity token certificate includes a public key. The private key corresponding to the public key is stored in the device side. The device side uses the private key to sign the verification result to obtain a signed verification result. The real-person verification method further includes:
[0141] The requester receives the signed verification result;
[0142] The requester reports the signed verification result to the application server, and the application server applies to the remote trusted service platform server for online verification of the verification result;
[0143] The remote trusted service platform server searches for the pre-stored identity token certificate and uses the identity token certificate to verify the signature of the signed verification result to obtain a real-person verification result;
[0144] The requester receives the real-person verification result.
[0145] Further, in combination with Figure 5 the specific embodiment shown, in the real-person verification method, the verification result determining device performs online confirmation of the verification result. In Figure 4 the solution shown, the device-side calling party application obtains the offline verification result data and can confirm the verification result by directly verifying the digital certificate and then verifying the signature of the result data with the public key in the digital certificate; in Figure 4 the solution shown, the device-side offline verification service needs to return the device certificate data. In Figure 5 the solution shown, the device certificate data may not be returned, but the online confirmation of the verification result is performed by means of the calling party background service. Figure 5 The real-person verification method shown includes the following steps:
[0146] Step 1: Receive the offline verification result;
[0147] The general application program 120 receives the offline verification result;
[0148] Step 2: Report the verification result (offline verification result);
[0149] The general application program 120 reports the verification result to the application server 200.
[0150] Step 2.1: Online verification of the verification result (offline verification result);
[0151] The application server 200 applies to the remote trusted service platform server 300 for online verification of the verification result.
[0152] Step 2.1.1: Search for the pre-stored identity token certificate;
[0153] The remote trusted service platform server 300 searches for the pre-stored identity token certificate.
[0154] Step 2.1.2: Verify the signature using the identity token certificate.
[0155] The remote trusted service platform server 300 verifies the signature using the identity token certificate.
[0156] Step 2.1.3: Analyze the offline verification result.
[0157] The remote trusted service platform server 300 analyzes the offline verification result; then, returns the verification result to the application server 200; the application server 200 returns the verification result to the ordinary application program 120.
[0158] Step 3: Execute subsequent operations.
[0159] After receiving the verification result, the ordinary application program 120 executes subsequent operations.
[0160] The real-person verification method and system provided by the embodiments of the present invention first verify the real identity of the user through online real-person verification and store the real-person information of the user on the device side; after the real-person verification is successful, an identity token certificate (digital certificate) is issued to the device side, and subsequent real-person verification can be carried out by means of offline face authentication and the method of authorizing and signing with the device digital certificate to provide real-person verification services; the solution of the present application will greatly reduce the number of online real-person verifications, thereby reducing the bandwidth pressure and service processing pressure on the background service, and also reducing the cost expenditure of the online real-person verification service; placing the processing of real-person verification on the device side can ensure the security of data storage and business processing based on secure environments such as TEE and SE, as well as digital certificate (identity token certificate) signature verification technology; digital signature (identity token certificate) technology is used to verify the integrity and source of digital information, usually including encrypting information or information digest using a private key, and decrypting and verifying using the corresponding public key; digital signature ensures that the information has not been tampered with during transmission and can verify the identity of the information sender.
[0161] Figure 6 Shows an interaction diagram of identity token activation for real-person authentication according to an embodiment of the present invention. As Figure 6 shown, the identity token activation interaction for real-person authentication according to an embodiment of the present invention occurs among the user, the management application program 130, the security carrier 110, and the remote trusted service platform server 300.
[0162] First, a unified description is given to the terms that may be involved in the identity token activation interaction (the real-person verification method and system described in the present application):
[0163] Identity Token refers to the identity proof data used to present to the authenticator in this product.
[0164] Identity Token System, a technical system that supports the operation of identity token products.
[0165] Remote Trusted Service Platform (RTSP), i.e., the Remote Trusted Service Platform Server 300.
[0166] Certificate Authority (CA) server, which is part of the RTSP and is responsible for issuing, managing, storing, and revoking digital certificates.
[0167] User Device Cert (UDC), a digital certificate issued by the RTSP for a user's trusted device.
[0168] User Device Identifier (UDI), an identification number generated by the RTSP for a user's trusted device according to rules, which is associated with both the user and the trusted device. The UDIs of the same user on different devices are different, and the UDI is bound to the user device certificate.
[0169] Trusted Device Key (TDK), a trusted device authentication key deployed by the device manufacturer to the device. The TDK can be called through the TEE interface and used to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer.
[0170] Trusted device authentication server, which is part of the RTSP and is responsible for verifying the data signed with the TDK in the device to ensure that the data comes from a legitimate device trusted by the device manufacturer.
[0171] A unified description of the keys that may be involved in this application:
[0172] The Trusted Device Key (abbreviated as TDK) is a trusted device authentication key deployed by the device manufacturer to the device. The TDK is called through the TEE interface and used to sign data to ensure that the data comes from a legitimate device trusted by the device manufacturer. The Trusted Device Key is generated or pre-set in the security carrier 110. The security carrier 110 holds the private key of the Trusted Device Key, and the RTSP holds the public key or certificate of the Trusted Device Key.
[0173] The RTSP platform key (abbreviated as RTSP-TK) is created or pre-set by the RTSP. The RTSP holds the private key of the RTSP platform key, and the security carrier 110 pre-sets the public key of the RTSP platform key.
[0174] The CA root key (abbreviated as CA-ROOT) is the key used by the certificate issuing server in RTSP to issue certificates. The CA root key is generated or pre-set by RTSP. RTSP stores the private key and certificate of the CA root key; the CA-ROOT certificate is also distributed to the authentication device 500.
[0175] The application business authentication key public key or public key certificate (abbreviated as ABA-PK) is used to verify the submitted real person information service authorization package when the ordinary application program 120 calls the security carrier 100. This authorization package is signed by RTSP using the corresponding private key. The application business authentication key public key or public key certificate is pre-set by RTSP or dynamically generates an application authorization verification key pair, and the public key is pre-set or synchronized (stored) to the security carrier 110.
[0176] The application authorization verification key private key (abbreviated as ABA-SK) is stored in RTSP. RTSP uses this key to authorize and sign the submitted real person information service of the application.
[0177] The token encryption master key (abbreviated as TEK-MK) is used to decentralize the master key of each identity token encryption key. The token encryption master key is created or pre-set by RTSP and synchronized to the authentication device 500. The token encryption master key is stored in RTSP / the authentication device 500.
[0178] The token encryption sub-key (abbreviated as TEK-DK) is the key used to encrypt the identity token data at the user device end. The token encryption sub-key is decentralized by RTSP and transmitted (stored) to the security carrier 110.
[0179] The secure channel key group (abbreviated as SCKs, specifically including the encryption key SCK-ENC and the verification key SCK-HMAC) is used to establish a secure channel between the security carrier 110 and RTSP, and is created during the process of opening the user device certificate. The secure channel key group is randomly generated by RTSP and synchronized to the security carrier 110. The secure channel key group is stored in RTSP / the security carrier 110.
[0180] The user device certificate key pair (including the user device certificate private key UDC-SK and the user device certificate public key UDC-PK) is created and generated (randomly generated) by the security carrier 110, and the public key is exported to RTSP for issuing the user device certificate (UDC-PK is exported and sent to RTSP), the private key is used for service confirmation signature, and the public key is used for signature verification. The security carrier 110 saves UDC-SK and the UDC issued by RTSP; RTSP saves the UDC.
[0181] The Identity Information Submission Temporary Asymmetric Encryption Key (referred to as IEK for short) is used to encrypt and protect identity information when submitting identity information to the application. It is generated by the application server 200 and synchronized to the security carrier 110 through RTSP authentication. The application server 200 caches or saves the private key of the Identity Information Submission Temporary Asymmetric Encryption Key.
[0182] Specifically, the user sends a function activation request to the management application 130 (the user operates the management application 130 to activate); the management application 130 collects the user's identity information and on-site face (takes a face photo), and the user provides the management application 130 with the identity information and the taken on-site face.
[0183] The security carrier 110 obtains the encrypted face information from the management application 130, calculates and saves the face feature template (calculates and saves the face feature data obtained by using the face photo), and encrypts the identity information and the face photo with the RTSP-TK public key. Here, RTSP-TK is, for example, the key of the remote trusted service platform server. The security carrier 110 sends the encrypted identity information to the management application 130.
[0184] The management application 130 submits a live person verification to the remote trusted service platform server 300, and the submitted live person verification includes the encrypted identity information (the user's identity information and the encrypted face). The remote trusted service platform server 300 decrypts the identity information and the photo (the user's identity and face data) with the RTSP-TK private key, and conducts a comparison with the database of the authoritative agency service (for the face). The remote trusted service platform server 300 returns the comparison result to the management application 130.
[0185] The management application 130 calls the security carrier 110 to create an activation request. The security carrier 110 conducts a security check on the device status, creates a UDC-SK key pair (the generation of the UDC-SK key has the property of one key per device), assembles the activation request data (including at least the public key of the security key pair, the device identifier, and the self-signature), and signs the activation request data (for the second time) with the TDK (Trusted Device Key). Here, the security carrier 110 requests the user to set the key PIN code (pops up the TUI for the user to set the PIN code). The security carrier 110 returns the activation request data to the management application 130.
[0186] The management application 130 sends an activation request to the remote trusted service platform server 300. The activation request includes activation request data. The remote trusted service platform server 300 uses the TDK public key to verify the activation request data, generates a UDI, issues a UDC (generates a user device identifier UDI based on user information and issues a user device certificate UDC), generates SCKs, uses the TEK-MK to derive a sub-key TEK-DK for the user device identifier, and encrypts the UDC, TEK-DK, UDI, and user identity information using the SCKs, and encrypts the SCKs using the UDC-PK. The remote trusted service platform server 300 sends the activation response data (including the above data) to the management application 130.
[0187] The management application 130 imports the activation response (activation response data) into the secure carrier 110. The secure carrier 110 decrypts the SCKs using the UDC-SK, and then decrypts and saves the UDC, UDI, TEK-DK, and user identity information using the SCKs. The secure carrier 110 binds the local biometric feature. If the binding is successful, the trusted token can be unlocked using the local biometric feature verification.
[0188] Figure 7 The method flow diagram of the real person verification method according to another embodiment of the present invention is shown. As Figure 7 shown, the real person verification method according to another embodiment of the present invention is, for example, executed by the remote trusted service platform server, and specifically includes the following steps:
[0189] In step S201, reference face information and identity information are obtained;
[0190] (The remote trusted service platform server) obtains reference face information and identity information, where the obtained reference face information and identity information are, for example, provided by the device side.
[0191] In step S202, it is verified whether the reference face information and the identity information match;
[0192] (The remote trusted service platform server) verifies whether the reference face information and the identity information match, for example, by calling the service of an authoritative agency to check the database to verify whether the reference face information and the identity information match.
[0193] In step S203, when the reference face information and the identity information match, permission is given to issue an identity token certificate.
[0194] When the reference face information and the identity information match, permission is given to issue an identity token certificate, where the identity token certificate is issued by the device side (secure carrier) / remote trusted service platform server.
[0195] The identity token certificate is used to complete the comparison between the real-time face information and the stored face information stored on the device side at the device side.
[0196] According to another aspect of the present invention, a real person verification system is provided. The real person verification system is used to implement the real person verification method as described above. Specifically, the real person verification system includes a device side. The device side receives a real person verification request from a requester and obtains real-time face information. The device side compares the real-time face information with the stored face information stored on the device side to obtain a verification result, and sends the verification result to the requester.
[0197] Figure 8 The structural schematic diagram of the real person verification system according to an embodiment of the present invention is shown. The real person verification system according to an embodiment of the present invention is, for example, used to implement the real person verification method as described above. As Figure 8 shown, the real person verification system according to an embodiment of the present invention includes at least one of the following components:
[0198] The terminal device (mobile terminal / device side) 100 is a terminal device held by a user, such as a smart phone, a smart watch, etc. A security carrier (such as TEE or SE or both) is integrated on the terminal device 100.
[0199] The security carrier 110 is a software and hardware module on the terminal device 100. It internally accesses TEE\SE to implement a security function interface and provides the interface to external application programs. Among them, the security carrier access service program 111 provides an entity program for the external interface of the security carrier 110. It encapsulates the function interface of the identity token by accessing TEE\SE and provides external calls. TEE (Trusted Execution Environment) 112 is a type of security carrier, which belongs to a logical security isolation area of the system SOC and can execute security application programs. SE (Secure Element) 112 is generally an independent encryption chip. Due to its independent isolation characteristics, it has a higher security level than TEE. Invoking the SE interface in TEE can further ensure service security.
[0200] The ordinary application program 120 is an application program that invokes the security carrier 110 to invoke various functions of the identity token. The management application program 130 is an application program that invokes the security carrier 110 to perform identity token activation management.
[0201] The remote trusted service platform server 300 is the general term for services participating in the operation of the identity token service, including but not limited to: authoritative identity authentication service, certificate issuance service, identity token verification service, activation management service, application access service, etc., and also includes the relevant background services of the terminal device manufacturer, etc.
[0202] The application server 200 is the background service of the ordinary application program 120 and processes the authentication requests of the ordinary application program 120.
[0203] The authentication device 500 is a device used to verify and authenticate the identity tokens generated by the terminal device.
[0204] According to the real-person verification method and system of the embodiments of the present invention, based on the trust transfer after online real-person verification, the signature verification of the identity token certificate (digital certificate), and the secure storage such as TEE and SE on the device side, the security of the real-person verification method and system is greatly guaranteed; the storage and management of the device-side identity information need to be executed based on the premise of online real-person verification. The device-side offline face recognition is directly compared based on a single user module, without storing a lot of face information and performing face retrieval and comparison, reducing the security requirements for the transmission of sensitive data during communication; the face comparison result needs to obtain the user's authorized digital signature to ensure data security and anti-repudiation.
[0205] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0206] As described above in the embodiments of the present invention, these embodiments do not describe all the details in detail, nor limit the invention to the specific embodiments described. Obviously, according to the above description, many modifications and variations can be made. The present specification selects and specifically describes these embodiments to better explain the principle and practical application of the present invention, so that those skilled in the art can make good use of the present invention and its modifications based on the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A real person verification method, comprising: The device receives the real person verification request from the requesting party; The device obtains real-time facial information; The device end compares the real-time facial information with the stored facial information stored in the device end to obtain a verification result; The verification result is sent to the requesting party.
2. The real person verification method according to claim 1, wherein: The real person verification method also includes: The device end obtains reference facial information at a first moment and identity information corresponding to the reference facial information; The device sends the reference face information and the identity information to a remote trusted service platform server, and requests the remote trusted service platform server to verify whether the reference face information and the identity information match; When the reference facial information and the identity information match, issuing an identity token certificate; Obtaining the stored face information according to the reference face information; storing the stored face information and the identity token certificate in a secure storage unit on the device side, The identity token certificate is used to sign the verification result.
3. The real person verification method according to claim 2, wherein: The secure storage unit includes at least one selected from a SE environment, a TEE environment, and a system keystore.
4. The real person verification method according to claim 1, wherein: The real person verification method also includes: Obtaining a public key and a private key corresponding to the public key; Sending the public key to the requesting party; storing the private key in a secure storage unit on the device, Among them, after the device uses the private key to sign the verification result, the signed verification result is sent to the requesting party.
5. The real person verification method according to claim 1, wherein: The device side issues an identity token certificate, the identity token certificate includes a public key, and the device side stores a private key corresponding to the public key; The device uses the private key to sign the verification result to obtain a signature verification result; The real person verification method also includes: The requesting party receives the signature verification result and the identity token certificate; The requester verifies the identity token certificate; The requesting party verifies the signature based on the identity token certificate and confirms the verification result.
6. The real person verification method according to claim 1, wherein: The device side issues an identity token certificate, the identity token certificate includes a public key, and the device side stores a private key corresponding to the public key; The device uses the private key to sign the verification result to obtain a signature verification result; The real person verification method also includes: The requesting party receives the signature verification result; The requesting party reports the signature verification result to the application server; the application server applies to the remote trusted service platform server for online verification of the verification result; The remote trusted service platform server searches for the pre-stored identity token certificate; The remote trusted service platform uses the identity token certificate to verify the signature of the signature verification result to obtain a real person verification result; The requesting party receives the real-person verification result.
7. The real person verification method according to claim 1, wherein: The real person verification method also includes: The requesting party invokes the system biometrics to perform biometric verification; After the biometric verification is passed, the device side compares the real-time facial information with the stored facial information stored in the device side.
8. The real person verification method according to claim 1, wherein: The real person verification method also includes: When acquiring the real-time face information, liveness detection is performed.
9. A real person verification method, comprising: Obtain reference facial information and identity information; Verifying whether the reference face information and the identity information match; In the case where the reference face information and the identity information match, the identity token certificate is allowed to be issued, Among them, the identity token certificate is used to complete the comparison of real-time facial information on the device side with the stored facial information stored in the device side.
10. A real person verification system, comprising: The device receives a request from a requesting party for real-person verification and obtains real-time facial information; The device side compares the real-time facial information with the stored facial information stored in the device side to obtain a verification result, and sends the verification result to the requesting party.