User identity authentication method, electronic equipment, storage medium and program product
Through the dual dynamic matching of the first identity identifier and the second identity identifier, the problem of low accuracy of identity authentication in the prior art is solved, and high security and efficient user identity authentication is achieved, which is suitable for communication service processing, government services, financial data processing and travel.
Patent Information
- Application Number
- CN202510582875.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-22
AI Technical Summary
The existing identity authentication method based on CTID network certificates has the problem of low accuracy of identity authentication when users apply for identity credentials through other trusted identity authentication platforms, especially because the relationship between PID and user identity information cannot be established, making it difficult to accurately identify the user's identity during the authentication process.
Authentication is realized through dual dynamic matching of the first identity identifier and the second identity identifier, replacing the traditional pre-binding method of PID and user identity information. The user's original identity information is only stored in the trusted identity authentication service platform. The system authenticates through indirect matching of identifiers to ensure high security and accuracy of authentication.
It improves the accuracy of user identity authentication, reduces the rate of misidentification, prevents long-term valid identity identification from being intercepted and abused, and reduces authentication failure caused by information changes or omissions in binding, ensuring the real-time and efficiency of authentication.
Smart Images

Figure CN120528604A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a user identity authentication method, electronic device, storage medium, and program product. Background Art
[0002] With the rapid development and widespread use of the internet, online identity authentication technology has become a crucial tool for ensuring network security and safeguarding the legitimate rights and interests of users. Particularly in the communications industry, user identity authentication is a prerequisite and foundation for accessing various services and businesses. Traditional identity authentication methods rely on physical credentials, but if users forget or lose their credentials, handling services becomes extremely inconvenient. Therefore, online identity authentication technology has emerged, aiming to enable rapid and accurate verification of user identities through digital means.
[0003] Prior art has proposed an identity authentication method based on the Cyber Trusted Identity (CTID) network certificate. The CTID platform is an "Internet Plus" trusted identity authentication platform that digitally represents user identities by issuing CTID identity credentials. These credentials undergo desensitization and de-identification processing, forming an electronic document uniquely tied to the actual identity credential. When a user applies for a CTID identity credential from the CTID platform, the user (such as a telecommunications operator) obtains the encrypted user identity identifier (PID) returned by the CTID platform and associates the corresponding user identity information stored by the user with the PID. When a user authenticates their identity through the user, they provide a QR code, which the user submits to the CTID platform. After verification, the CTID platform returns the user's PID. The user's identity information is determined by querying the association between the PID and the user's identity information.
[0004] However, when users apply for identity credentials through other trusted identity authentication platforms, existing methods have the problem of low identity authentication accuracy. Summary of the Invention
[0005] The user identity authentication method, electronic device, storage medium, and program product provided in the embodiments of the present application are used to solve the problem of low accuracy of identity authentication in existing methods.
[0006] In a first aspect, an embodiment of the present application provides a user identity authentication method, which is applied to a user identity authentication system. The method includes:
[0007] Obtain the user's authentication request and pending service number;
[0008] Based on the authentication request, receiving a first identity identifier sent by the trusted identity authentication service platform, where the first identity identifier is generated based on the authentication credentials submitted by the user in the authentication request;
[0009] Determine the user information stored in the user identity authentication system based on the pending business number;
[0010] Sending user information to the trusted identity authentication service platform and receiving a second identity identifier sent by the trusted identity authentication service platform, where the second identity identifier is generated based on the user information corresponding to the pending service number;
[0011] Determine an identity authentication result of the user according to the first identity identifier and the second identity identifier.
[0012] In one possible implementation, the authentication request is an online authentication request; based on the authentication request, a first identity identifier sent by a trusted identity authentication service platform is received, including: based on the online authentication request, jumping the interactive interface of the user identity authentication system to the login interface of the trusted identity authentication client; based on the real-time authentication credentials submitted by the user in the trusted identity authentication client, receiving the first identity identifier sent by the trusted identity authentication service platform.
[0013] In a possible implementation, the real-time authentication credential is the user's real-time biometrics or a one-time verification code.
[0014] In one possible implementation, the authentication request is an offline authentication request; based on the authentication request, a first identity identifier sent by a trusted identity authentication service platform is received, including: based on the offline authentication request, obtaining a pre-generated credential in a trusted identity authentication client provided by the user; sending the pre-generated authentication credential to the trusted identity authentication platform, and receiving the first identity identifier sent by the trusted identity authentication service platform.
[0015] In a possible implementation, the pre-generated authentication credential is identity authentication QR code information.
[0016] In one possible implementation, determining a user identity authentication result based on a first identity identifier and a second identity identifier includes: comparing the first identity identifier and the second identity identifier; generating an authentication success result if the first identity identifier and the second identity identifier are the same; if the authentication request is an offline authentication request, querying user detailed information stored in a user identity authentication system; and obtaining the user identity authentication result based on the authentication success result and the user detailed information.
[0017] In a possible implementation, the method further includes: generating an authentication failure result if the first identity identifier and the second identity identifier are different; determining the user's identity authentication result based on the authentication failure result and the authentication request, and the identity authentication result is used to notify the user of the offline authentication failure or to remind the user to re-authenticate online.
[0018] In a second aspect, an embodiment of the present application provides a user identity authentication device, comprising:
[0019] The acquisition module is used to obtain the user's authentication request and pending business number;
[0020] A first receiving module is configured to receive, based on an authentication request, a first identity identifier sent by a trusted identity authentication service platform, where the first identity identifier is generated based on an authentication credential submitted by a user in the authentication request;
[0021] The first determination module is used to determine the user information stored in the user identity authentication system according to the pending service number;
[0022] A second receiving module is used to send user information to the trusted identity authentication service platform and receive a second identity identifier sent by the trusted identity authentication service platform, where the second identity identifier is generated based on the user information corresponding to the pending service number;
[0023] The second determining module is used to determine the user's identity authentication result according to the first identity identifier and the second identity identifier.
[0024] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor;
[0025] Memory stores computer-executable instructions;
[0026] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0027] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed, they are used to implement the first aspect and / or various possible implementation methods of the first aspect as described above.
[0028] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0029] The user identity authentication method, electronic device, storage medium and program product provided in the embodiments of the present application obtain the user's authentication request and pending business number; based on the authentication request, receive a first identity identifier sent by a trusted identity authentication service platform, the first identity identifier is generated based on the authentication credentials submitted by the user in the authentication request; according to the pending business number, determine the user information stored in the user identity authentication system; send the user information to the trusted identity authentication service platform, and receive a second identity identifier sent by the trusted identity authentication service platform, the second identity identifier is generated based on the user information corresponding to the pending business number; according to the first identity identifier and the second identity identifier, determine the means of the user's identity authentication result, and realize authentication through dual dynamic matching of the first identity identifier and the second identity identifier. The user's original identity information is only stored in the trusted identity authentication service platform. The system does not need to store sensitive data and indirectly matches authentication through identifiers, thereby realizing dynamic identity authentication with high security and accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0031] Figure 1 A flowchart of the user identity authentication method provided for this application;
[0032] Figure 2 A schematic diagram of the specific process of online authentication in the user identity authentication method provided for this application;
[0033] Figure 3 A schematic diagram of the specific process of offline authentication in the user identity authentication method provided by this application;
[0034] Figure 4 A schematic diagram of the structure of the user identity authentication device provided in this application;
[0035] Figure 5 This is a schematic diagram of the structure of the electronic device provided in this application.
[0036] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0037] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0038] It should be noted that the user information (including but not limited to user device information, user personal information, identity information, detailed information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0039] In existing identity authentication methods based on CTID online identity authentication, when a user applies for a CTID identity credential from the CTID platform, the user (such as a telecommunications operator) obtains the encrypted user identity identifier (PID) returned by the CTID platform and associates the corresponding user identity information stored by the user with the PID. When a user authenticates through the user, they provide a QR code, which the user submits to the CTID platform. After verification, the CTID platform returns the user's PID. The user's identity information is then determined by querying the association between the PID and the user's identity information. However, when users apply for identity credentials through other trusted identity authentication platforms (such as publicly known and trusted online identity authentication public service platforms), the PID is no longer returned to the user for security reasons. This prevents the user from establishing and storing the association between the PID and user identity information as previously done through the CTID platform. This makes it difficult for the user to accurately identify the user's identity using the PID during subsequent authentication, thus affecting the accuracy and effectiveness of authentication. Therefore, achieving efficient and reliable user identity authentication without relying on the association between the PID and user identity information has become a pressing technical issue.
[0040] To address the aforementioned issues, embodiments of the present application provide a user identity authentication method, electronic device, storage medium, and program product. These methods implement authentication through a dual, dynamic matching of a first identity identifier (generated based on user-submitted authentication credentials) and a second identity identifier (generated based on system-stored business-related information). This replaces the traditional method of pre-binding a PID (PID) and identity information, solving the problem of efficient and reliable user identity authentication without relying on the association between the PID and user identity information. Furthermore, they effectively prevent the interception and misuse of long-term valid identity identifiers, thereby improving the accuracy of user identity authentication by reducing the false recognition rate. Furthermore, the user's original identity information is stored only on the trusted identity authentication service platform, and the user's corresponding user identity authentication system does not store sensitive data. This indirect matching through identifiers, rather than raw data interaction, reduces the potential impact of data leakage threats. Furthermore, the trusted identity authentication service platform generates identifiers in real time. When user information is updated, the newly generated identifier automatically takes effect. The user's corresponding system does not need to modify the information association logic between the PID and user identity information, reducing authentication failures caused by user information changes or missing information bindings, thereby ensuring real-time and efficient authentication.
[0041] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0042] The embodiments of the present application provide a user identity authentication method, electronic device, storage medium and program product, which are applied to a user identity authentication system, which may include: a user management system, a business operation support system, and a client. Among them, the user management system: a system responsible for managing user identity information (name, certificate type, certificate number, user's corresponding business number, etc.), and is responsible for connecting with the trusted identity authentication service platform, processing authentication requests and receiving authentication results. The business operation support system: is responsible for receiving authentication results and conducting business acceptance, such as the operator's cBSS (Converged Business Support System). Optionally, the user management system can be combined with the business operation support system or built independently. Client: provides users with a user service terminal for online business processing, such as an operator APP (Application). The system may also include a code scanning device for scanning pre-generated credentials such as QR codes presented by users during offline authentication to achieve functions such as identity information extraction.
[0043] The Trusted Identity Authentication Service Platform is a system developed by professionals, organizations, or institutions specializing in online identity authentication, responsible for issuing online identity authentication credentials (online certificates) and providing identity verification services, such as the CTID platform. Correspondingly, the Trusted Identity Authentication Client corresponds to the Trusted Identity Authentication Service Platform and is developed by professionals, organizations, or institutions specializing in online identity authentication. It serves as a user service for users to apply for and present online certificates. Certificate users can refer to public management or service agencies that use online certificates to verify user identities and provide services (such as telecommunications services, government services, financial data processing, travel, and ticketing). By verifying user information such as online certificates, they simplify processes and improve service efficiency.
[0044] This embodiment does not impose any special restrictions on the selection type of the user identity authentication system, as long as it can obtain the user's authentication request and pending business number; based on the authentication request, receive the first identity identifier sent by the trusted identity authentication service platform, the first identity identifier is generated based on the authentication credentials submitted by the user in the authentication request; according to the pending business number, determine the user information stored in the user identity authentication system; send the user information to the trusted identity authentication service platform, and receive the second identity identifier sent by the trusted identity authentication service platform, the second identity identifier is generated based on the user information corresponding to the pending business number; determine the user's identity authentication result based on the first identity identifier and the second identity identifier.
[0045] Figure 1 The flowchart of the user identity authentication method provided for this application is as follows: Figure 1 As shown, the method may include:
[0046] S101. Obtain the user's authentication request and pending service number.
[0047] An authentication request refers to a user-initiated identity verification request, which may include the authentication type and authentication credentials (e.g., a QR code for an online ID, the user's biometrics, etc.). The authentication type may refer to a specific authentication method selected by the user on a trusted identity authentication service platform. The pending service number may refer to a unique identifier associated with the user's pending service (e.g., the user's mobile phone number).
[0048] In some implementations, a user submits an authentication request online or offline, and provides a pending service number. Online methods may involve the user submitting the authentication request and pending service number through a user identity authentication system client (e.g., a system app, website, or other channels). Offline methods may involve the user submitting the authentication request and pending service number through a paper form, verbal notification, or other offline methods, and the user identity authentication system obtains the information through manual entry or scanning.
[0049] S102: Based on the authentication request, receive a first identity identifier sent by the trusted identity authentication service platform, where the first identity identifier is generated based on the authentication credentials submitted by the user in the authentication request.
[0050] Furthermore, the first identity identifier is a preset identifier (e.g., a PID) generated by the trusted identity authentication service platform based on the user-submitted authentication credentials sent by the user identity authentication system. The authentication credentials can be dynamic and real-time (e.g., a verification code, real-time facial biometric recognition) or static and pre-generated (e.g., a QR code). The type of authentication credential can be determined based on the actual authentication scenario.
[0051] In some implementations, the user authentication system forwards the user's authentication request to a trusted authentication service platform. The trusted authentication service platform generates a first identity identifier based on the authentication credentials (e.g., biometrics) submitted by the user and sends it back to the user authentication system. For example, the trusted authentication service platform can interact with the trusted authentication service platform via an API (Application Programming Interface) to receive and send the identity identifier.
[0052] S103: Determine the user information stored in the user identity authentication system according to the pending service number.
[0053] Furthermore, the user information (e.g., name, ID number) stored in the user authentication system is queried based on the pending service number to determine the correspondence between the service and the user. The user information stored in the user authentication system is the information provided by the user when applying for the pending service number, or when previously applying for the service corresponding to the pending service number. The user authentication system associates the user-provided information with the service number and stores or updates it. Optionally, a database query statement can be used, using the pending service number as a key field for search, or a cache mechanism can be used to query, improving the efficiency of user information search.
[0054] S104: Send user information to the trusted identity authentication service platform, and receive a second identity identifier sent by the trusted identity authentication service platform, where the second identity identifier is generated based on the user information corresponding to the pending service number.
[0055] Furthermore, the second identity identifier is an identifier generated by the trusted identity authentication service platform based on the user information stored in the system and sent by the user identity authentication system, and can be used to compare with the first identifier for identity authentication.
[0056] In some embodiments, the user identity authentication system transmits user information to a trusted identity authentication service platform; the trusted identity authentication service platform generates a first identity identifier based on the user information and transmits it back to the user identity authentication system. Furthermore, encrypted communication can be used to ensure the security of user information during transmission.
[0057] S105: Determine the user's identity authentication result according to the first identity identifier and the second identity identifier.
[0058] Furthermore, the first and second identity identifiers can be compared to see if they are consistent. If they are consistent, the user authentication is considered successful; otherwise, the authentication is considered unsuccessful. For example, a simple string comparison algorithm can be used for the comparison; or, the identity identifiers can be encrypted using a hash algorithm before the comparison to improve security.
[0059] The user identity authentication method provided in the embodiments of the present application achieves authentication through dual dynamic matching of a first identity identifier (generated based on the authentication credentials submitted by the user) and a second identity identifier (generated based on user information associated with the service number stored in the system). This method accurately authenticates the user's identity and solves the problem of efficient and reliable user identity authentication without relying on the association between the PID and user identity information. It also effectively prevents the interception and misuse of long-term valid identity identifiers, thereby improving the accuracy of user identity authentication by reducing the false recognition rate. Furthermore, the user's original identity information is stored only on the trusted identity authentication service platform, and the user's corresponding user identity authentication system does not store sensitive data. Indirect matching through identifiers, rather than raw data interaction, reduces the potential impact of data leakage threats. Furthermore, the trusted identity authentication service platform generates identifiers in real time. When user information is updated, the newly generated identifier automatically takes effect. The user's corresponding system does not need to modify the information association logic between the PID and user identity information, reducing authentication failures caused by information changes or omissions in information binding. This ensures real-time authentication and efficiency, providing reliable identity authentication for various business operations.
[0060] Based on the above embodiment, the authentication request may be an online authentication request; the method described in S102 for receiving the first identity identifier sent by the trusted identity authentication service platform based on the authentication request may include: based on the online authentication request, jumping the interactive interface of the user identity authentication system to the login interface of the trusted identity authentication client; based on the real-time authentication credentials submitted by the user in the trusted identity authentication client, receiving the first identity identifier sent by the trusted identity authentication service platform.
[0061] An online authentication request refers to an authentication request initiated by a user through an internet channel provided by the system (e.g., an app, a website, etc.). A real-time authentication credential refers to verification data (e.g., face or fingerprint) provided instantly by the user.
[0062] For example, after the user submits an authentication request online, the system automatically redirects the user's browser or APP interface to the login interface of the trusted identity authentication client; the user enters real-time authentication credentials (such as face recognition, SMS verification code, etc.) in the trusted identity authentication client and submits it to the trusted identity authentication service platform; after the platform verifies the credentials, it generates a first identity identifier and sends it back to the user identity authentication system.
[0063] By processing online authentication requests, users can quickly and conveniently authenticate their identities. By redirecting users to the trusted authentication client's login interface and utilizing real-time authentication credentials for authentication, the authenticity of the credentials is ensured, phishing attacks are prevented, and the accuracy and security of authentication are improved. This also enhances the user experience, making the authentication process more convenient.
[0064] Based on the above embodiment, the real-time authentication credential is the user's real-time biometric feature or a one-time verification code.
[0065] Among them, real-time biometrics may include faces, irises, fingerprints, etc. for liveness detection. A one-time verification code may be a one-time password sent to the user via SMS, email, or APP push. In addition, for real-time biometrics, fingerprint recognition, facial recognition, and other technologies may be used for collection and verification; for one-time verification codes, they may be sent to users via SMS gateways, email servers, or APP push services, and a validity period and a limit on the number of uses of the verification codes may be set. This embodiment improves the security and accuracy of identity authentication by using real-time biometrics and one-time verification codes as authentication credentials. Real-time biometrics are difficult to copy and counterfeit, and one-time verification codes are time-sensitive. The combined use of the two can effectively prevent identity impersonation and fraud.
[0066] Based on the above embodiment, the authentication request is an offline authentication request; the method described in S102 for receiving the first identity identifier sent by the trusted identity authentication service platform based on the authentication request may include: obtaining the pre-generated credentials in the trusted identity authentication client provided by the user based on the offline authentication request; sending the pre-generated authentication credentials to the trusted identity authentication platform, and receiving the first identity identifier sent by the trusted identity authentication service platform.
[0067] Among them, an offline authentication request may refer to an authentication request initiated by a user through an offline channel (such as a paper form, counter processing, etc.). A pre-generated credential may be an identity credential (such as a QR code, digital code) pre-generated by the user in a trusted identity authentication client for offline authentication. For example, when a user submits an authentication request offline, he or she presents the pre-generated credential (such as a QR code) to a staff member or a scanning device, and the system obtains the pre-generated credential information through scanning or manual input; the system sends the pre-generated credential information to the trusted identity authentication service platform for verification. After the platform verifies the credential, it generates a first identity identifier and sends it back to the user identity authentication system. By using pre-generated credentials in offline scenarios, there is no need for real-time online operation, which improves the efficiency and accuracy of offline authentication and is applicable to network-restricted environments (such as the authentication process for business handling in remote areas).
[0068] Based on the above embodiment, the pre-generated authentication credential is identity authentication QR code information.
[0069] The trusted identity authentication client generates a time-sensitive QR code that can contain encrypted user ID information. Using the identity authentication QR code as a pre-generated credential improves the convenience and security of offline authentication. QR codes are easy to generate and scan and can contain rich identity information, making offline authentication more efficient and accurate. They also facilitate user authentication needs in various scenarios.
[0070] Based on the above embodiment, the method for determining the user's identity authentication result based on the first identity identifier and the second identity identifier may include: comparing the first identity identifier and the second identity identifier; if the first identity identifier and the second identity identifier are the same, generating an authentication success result; if the authentication request is an offline authentication request, querying the user's detailed information stored in the user identity authentication system; and obtaining the user's identity authentication result based on the authentication success result and the user's detailed information.
[0071] Optionally, the system performs a string comparison or hash value comparison on the received first and second identity identifiers. If the two identifiers are identical, the system deems the user's identity authentication successful and generates a corresponding authentication success result. For offline authentication requests, after successful authentication, the system will also query and obtain the user's detailed information (such as name, ID number, issuing authority, address, photo, etc.). The system combines the authentication success result and the user's detailed information into a final authentication result, which it returns to the caller or displays to the user.
[0072] In one example, when the match is successful, the user identity authentication system automatically retrieves user detailed information (such as files) to complete business processing (such as medical insurance reimbursement); when it fails offline, it prompts "Please go to the manual counter to verify your identity documents."
[0073] By differentiating online and offline results and refining identity authentication results, not only is the accuracy of authentication improved, but it also provides users with richer identity information, facilitating subsequent business processing.
[0074] Based on the above embodiment, the method may further include: if the first identity identifier and the second identity identifier are different, generating an authentication failure result; based on the authentication failure result and the authentication request, determining the user's identity authentication result, and the identity authentication result is used to notify the user of the offline authentication failure or remind the user to re-authenticate online.
[0075] In one example, when an inconsistency is detected online, a prompt appears: "Face recognition failed. Please try again or switch verification methods." When an inconsistency is detected offline, an alert is triggered and an exception log is recorded. This clear failure feedback mechanism promptly notifies users of authentication results and guides them through subsequent operations, improving system friendliness and user experience.
[0076] It should be noted that the embodiments of the present application can be used in the fields of communication business processing, government services, financial data processing, travel, ticket purchase, etc. The following takes the example of users conducting online and offline card-using business processing through communication operators to explain the user identity authentication method in detail.
[0077] Figure 2 The specific process diagram of online authentication in the user identity authentication method provided for this application is as follows: Figure 2As shown, 1. The user logs in to the communication operator client using the business number and enters the business processing page where "Trusted Network Identity Authentication" can be used for authentication; 2. The user selects "Trusted Network Identity Authentication" in the identity authentication link; 3. The communication operator client automatically jumps to the trusted identity authentication client for identity verification; 4. The user completes identity verification (such as face recognition) on the trusted identity authentication client; 5. If the verification is successful, the trusted identity authentication service platform returns the identity verification result and PID to the user management system, at which point the communication operator can confirm the user's PID; 6. The communication operator client sends the business number and PID used by the user to log in to the user management system; 7. The user management system obtains the corresponding The corresponding "name and ID number" is then sent to the trusted identity authentication service platform; 8. The trusted identity authentication service platform verifies whether the name and ID number data match. After the verification is passed, the PID is returned to the user management system based on the "name + ID number"; 9. The user management system compares the consistency of the first PID and the second PID. If they are consistent, the user identity authentication is successful, and the user's identity information is the "name + ID number" transmitted to the trusted identity authentication service platform, and the authentication is successful; 10. After the verification is passed, jump back to the communication operator APP and the user continues to handle the business; 11. After the business acceptance is completed, the system records information such as the authentication method and authentication source, and retains information such as the authentication results.
[0078] Figure 3 The specific process diagram of offline authentication in the user identity authentication method provided for this application is as follows: Figure 3As shown, 1. The user asks the salesperson to use the trusted network identity authentication method to handle communication business and provides the business number; 2. The salesperson selects the "Trusted Identity Authentication Service Platform Network Certificate" authentication method in the business operation support system and enters the user's business number; 3. The user opens the "Trusted Identity Authentication Client", calls the network certificate presentation function, and generates an encrypted identity authentication QR code; 4. The salesperson scans the QR code with a code scanning device and transmits the QR code information to the business operation support system; 5. The communication operator's business operation support system sends the QR code information and business number to the user management system, and the user management system transmits the QR code information to the trusted identity authentication service platform; 6. The trusted identity authentication service platform decrypts and verifies the QR code information, and returns the corresponding PID after verification. Based on the PID returned for the first time, the communication operator can confirm the user's PID; 7. The user management system obtains the corresponding user information according to the business number, such as "name, ID number" ( According to the real-name management requirements, users need to provide their name and ID number when registering for the network (the system needs to save the relationship between the name, ID number and business number), and pass the user information to the trusted identity authentication service platform; 8. The trusted identity authentication service platform verifies whether the name and ID number data match. After the verification is passed, the PID is returned to the user management system of the communication operator based on the "name + ID number"; 9. The user management system of the communication operator compares the consistency of the first PID and the second PID. If they are consistent, the user identity authentication is successful, and the user's identity information is the "name + ID number" passed to the trusted identity authentication service platform, and the authentication is successful; 10. The user management system of the communication operator returns the identity authentication result and user detailed information to the business operation support system; 11. After the authentication is passed, the salesperson handles the relevant business for the user; 12. After the business is completed, the system records information such as the authentication method and authentication source, and retains information such as the authentication result.
[0079] The user identity authentication method provided in the embodiments of the present application obtains two PIDs of the same user through different methods (offline by submitting QR code information and submitting "name + ID number"), accurately compares the PIDs obtained by the different methods, and realizes reliable verification of the identity information. If the comparison is consistent, it is confirmed that the user identity information is the "name + ID number" submitted to the trusted identity authentication service platform for verification. On the basis of not reducing the anti-counterfeiting ability and security level of identity authentication, the user no longer needs to rely on the correspondence between PID and user identity information for verification and identification.
[0080] It should be noted that the acquisition, storage and application of user information involved in the technical solution of the present disclosure are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0081] Figure 4The schematic diagram of the user identity authentication device provided in this application is as follows: Figure 4 As shown, the user identity authentication device 40 provided in this embodiment includes:
[0082] Acquisition module 401, used to obtain the user's authentication request and pending service number;
[0083] A first receiving module 402 is configured to receive a first identity identifier sent by a trusted identity authentication service platform based on an authentication request, where the first identity identifier is generated based on an authentication credential submitted by a user in the authentication request;
[0084] The first determining module 403 is used to determine the user information stored in the user identity authentication system according to the pending service number;
[0085] The second receiving module 404 is configured to send user information to the trusted identity authentication service platform and receive a second identity identifier sent by the trusted identity authentication service platform, where the second identity identifier is generated based on the user information corresponding to the pending service number;
[0086] The second determining module 405 is configured to determine the user's identity authentication result according to the first identity identifier and the second identity identifier.
[0087] In one possible implementation, the first receiving module 402 can also be used to: based on an online authentication request, jump the interactive interface of the user identity authentication system to the login interface of the trusted identity authentication client; based on the real-time authentication credentials submitted by the user in the trusted identity authentication client, receive the first identity identifier sent by the trusted identity authentication service platform.
[0088] In one possible implementation, the first receiving module 402 can also be used to: obtain pre-generated credentials in the trusted identity authentication client provided by the user based on the offline authentication request; send the pre-generated authentication credentials to the trusted identity authentication platform, and receive the first identity identifier sent by the trusted identity authentication service platform.
[0089] In one possible implementation, the second determination module 405 can also be used to: compare the first identity identifier and the second identity identifier; if the first identity identifier and the second identity identifier are the same, generate an authentication success result; if the authentication request is an offline authentication request, query the user details stored in the user identity authentication system; obtain the user's identity authentication result based on the authentication success result and the user details.
[0090] In one possible implementation, the second determination module 405 can also be used to: generate an authentication failure result if the first identity identifier and the second identity identifier are different; determine the user's identity authentication result based on the authentication failure result and the authentication request, and the identity authentication result is used to notify the user of the offline authentication failure or remind the user to re-authenticate online.
[0091] The user identity authentication device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effects are similar, and are not described in detail in this embodiment.
[0092] Figure 5 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes: at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected via a bus 504.
[0093] In a specific implementation process, at least one processor 501 executes the computer-executable instructions stored in the memory 502, so that the at least one processor 501 performs the above method.
[0094] The specific implementation process of the processor 501 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0095] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASICs), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules within the processor.
[0096] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage.
[0097] A bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.
[0098] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0099] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0100] The readable storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0101] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.
[0102] The division of units is merely a logical functional division; actual implementations may employ alternative divisions, such as combining or integrating multiple units or components into another system, or omitting or disabling certain features. Furthermore, any direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between devices or units, either through an interface, electrical, mechanical, or other means.
[0103] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0104] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0105] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the method of the present invention. The aforementioned storage medium includes various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.
[0106] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0107] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A user identity authentication method, characterized in that: Applied to a user identity authentication system, the method includes: Obtain the user's authentication request and pending service number; Based on the authentication request, receiving a first identity identifier sent by a trusted identity authentication service platform, where the first identity identifier is generated based on the authentication credentials submitted by the user in the authentication request; Determining user information stored in the user identity authentication system according to the pending service number; Sending the user information to the trusted identity authentication service platform, and receiving a second identity identifier sent by the trusted identity authentication service platform, where the second identity identifier is generated based on the user information corresponding to the pending service number; An identity authentication result of the user is determined according to the first identity identifier and the second identity identifier.
2. The method according to claim 1, characterized in that The authentication request is an online authentication request; The receiving, based on the authentication request, a first identity identifier sent by a trusted identity authentication service platform, includes: Based on the online authentication request, the interactive interface of the user identity authentication system is redirected to the login interface of the trusted identity authentication client; Based on the real-time authentication credentials submitted by the user in the trusted identity authentication client, a first identity identifier sent by a trusted identity authentication service platform is received.
3. The method according to claim 2, characterized in that The real-time authentication credential is the user's real-time biometric feature or a one-time verification code.
4. The method according to claim 1, wherein The authentication request is an offline authentication request; The receiving, based on the authentication request, a first identity identifier sent by a trusted identity authentication service platform, includes: Based on the offline authentication request, obtaining pre-generated credentials in a trusted identity authentication client provided by the user; The pre-generated authentication credential is sent to a trusted identity authentication platform, and a first identity identifier is received from the trusted identity authentication service platform.
5. The method according to claim 4, characterized in that The pre-generated authentication credential is identity authentication QR code information.
6. The method according to any one of claims 1 to 5, characterized in that The determining, based on the first identity identifier and the second identity identifier, an identity authentication result of the user includes: comparing the first identity identifier and the second identity identifier; If the first identity identifier and the second identity identifier are the same, generating an authentication success result; If the authentication request is an offline authentication request, querying the user details stored in the user identity authentication system; The identity authentication result of the user is obtained according to the successful authentication result and the user detailed information.
7. The method according to claim 6, characterized in that The method further comprises: If the first identity identifier and the second identity identifier are different, generating an authentication failure result; Based on the authentication failure result and the authentication request, an identity authentication result of the user is determined, and the identity authentication result is used to notify the user of offline authentication failure or to remind the user to re-authenticate online.
8. A user identity authentication device, characterized in that: include: The acquisition module is used to obtain the user's authentication request and pending business number; A first receiving module is configured to receive, based on the authentication request, a first identity identifier sent by a trusted identity authentication service platform, where the first identity identifier is generated based on the authentication credentials submitted by the user in the authentication request; A first determining module is used to determine the user information stored in the user identity authentication system according to the pending service number; A second receiving module is configured to send the user information to the trusted identity authentication service platform and receive a second identity identifier sent by the trusted identity authentication service platform, where the second identity identifier is generated based on the user information corresponding to the pending service number; The second determining module is configured to determine an identity authentication result of the user according to the first identity identifier and the second identity identifier.
9. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed.
11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when the computer program is executed.