User authentication method and device, electronic equipment and storage medium

By introducing a first functional entity to the communication system to authenticate user bioinformatics, encrypting with the transmission key and comparing it with the second biological information, the problem of AI in the prior art is difficult to identify the authenticity of service-sides, and the communication security and privacy protection are improved.

CN120568320APending Publication Date: 2025-08-29CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410229662.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-29
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

The existing communication systems mainly authenticate user cards, but do not authenticate users themselves, making it difficult for AI to identify the authenticity of service-side and unable to effectively improve the security of the service communication process.

Method used

The first functional entity is introduced, the user's biological information is collected and personality authentication is performed by comparing the biological information code, the information is encrypted using the transmission key, and the second biological information is authenticated during the communication process, authentication information is generated, and the security of information transmission is enhanced.

Benefits of technology

By comparing user biometric information to verify user identity, users are avoided being deceived by false users, improve the security of communication process and protect user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120568320A_ABST
    Figure CN120568320A_ABST
Patent Text Reader

Abstract

The invention provides a user authentication method and device, electronic equipment and a storage medium, and the method comprises the steps: responding to an authentication request of an initiator for a target user, sending a transmission key to target user equipment corresponding to the target user, receiving encrypted information from the target user equipment, and carrying out the authentication of the encrypted information through second biological information, and the authentication information is sent to the initiating end. The method and the device are used for realizing personality authentication of the target user so as to distinguish the authenticity of the target user and further identify whether the service opposite terminal is a real user, so that the security of the service communication process is improved and the privacy of the target user is protected while the confidentiality degree of the first biological information is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of user authentication, and in particular to a user authentication method, device, electronic device, and storage medium. Background Art

[0002] The popularity of large language models (LLMs) demonstrates the unstoppable trend toward general artificial intelligence (AI). AI can perfectly mimic humans in digital interactions and, through rapid evolution, is reaching levels beyond human capabilities at an unimaginable pace. Furthermore, in digital worlds like the metaverse, AI is increasingly being incorporated into social production systems such as online teaching and remote interviews and recruitment. This significantly improves social production efficiency, but also carries significant risks. Preventing AI from engaging in malicious activities through technical means has become a pressing technical challenge that needs to be addressed.

[0003] However, current communication systems primarily authenticate the user ID (USIM) rather than the user. By default, the user is the owner of the phone number and terminal. The emergence of AI makes it difficult for users to verify the authenticity of their counterparties.

[0004] In summary, how to identify whether the business counterpart is a real user and improve the security of the business communication process is a key issue that needs to be urgently addressed in the communications field. Summary of the Invention

[0005] In view of the above problems, the present disclosure is proposed. The present disclosure provides a user authentication method, device, electronic device and storage medium.

[0006] According to one aspect of the present disclosure, a user authentication method is provided, which includes: responding to an authentication request from an initiator for a target user, sending a transmission key to a target user device corresponding to the target user, receiving encrypted information from the target user device, wherein the encrypted information is obtained by encrypting the first biometric information of the target user using the transmission key, authenticating the encrypted information using the second biometric information to obtain authentication information, and sending the authentication information to the initiator.

[0007] In addition, according to a user authentication method according to one aspect of the present disclosure, sending a transmission key to a target user device includes: generating a transmission key based on an intermediate key, wherein the transmission key is a dynamic key and the intermediate key is a periodic key.

[0008] In addition, according to a user authentication method according to one aspect of the present disclosure, before generating a transmission key based on an intermediate key, the method also includes: negotiating with a second functional entity and receiving an intermediate key from the second functional entity, wherein the second functional entity is used to implement an authentication service function, and the first functional entity and the second functional entity communicate through a first interface.

[0009] In addition, the user authentication method according to one aspect of the present disclosure further includes: the initiator is a third functional entity, the third functional entity is used to manage authentication information, and the first functional entity and the third functional entity communicate through the second interface.

[0010] In addition, according to a user authentication method according to one aspect of the present disclosure, the initiating end and the target user are communicating parties, wherein the initiating end is the called party and the target user is the calling party.

[0011] In addition, according to a user authentication method in one aspect of the present disclosure, the initiator is a service platform, and the target user is at least one service object of the service platform.

[0012] In addition, according to an aspect of the user authentication method of the present disclosure, the method further includes: correspondingly storing the second biometric information of each user.

[0013] In addition, according to one aspect of the user authentication method of the present disclosure, the encrypted information is authenticated using the second biometric information to obtain the authentication information, including: decrypting the encrypted information using the transmission key to obtain the first biometric information, and comparing the first biometric information with the second biometric information to obtain the authentication information.

[0014] In addition, according to one aspect of the present disclosure, a user authentication method is applied to a second functional entity, and the method includes: negotiating with the first functional entity, generating an intermediate key, and sending the intermediate key to the first functional entity, wherein the intermediate key is used to generate a transmission key for encrypted information, wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by encrypting the first biometric information of the target user by the target user device corresponding to the target user using the transmission key, and the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

[0015] In addition, a user authentication method according to one aspect of the present disclosure is applied to a third functional entity, and the method includes: sending an authentication request for a target user to a first functional entity, and receiving authentication information sent by the first functional entity, wherein the authentication information is obtained by the first functional entity authenticating encrypted information using the second biometric information, wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by encrypting the first biometric information of the target user by a target user device corresponding to the target user using a transmission key, and the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

[0016] In addition, a user authentication method according to one aspect of the present disclosure is applied to a user device, and the method includes: receiving a transmission key from a first functional entity, encrypting the first biometric information of the target user using the transmission key to obtain encrypted information, and sending the encrypted information to the first functional entity, wherein the transmission key is sent by the first functional entity in response to an authentication request from the sending end, and the encrypted information is used to authenticate with the second biometric information to obtain authentication information.

[0017] In addition, a user authentication method according to one aspect of the present disclosure is applied to a system including a user device and a first functional entity, and the method includes: in response to an authentication request from an initiator for a target user, the first functional entity sends a transmission key to a target user device corresponding to the target user, the target user device uses the transmission key to encrypt the first biometric information of the target user to obtain encrypted information, the target user device sends the encrypted information to the first functional entity, the first functional entity uses the second biometric information to authenticate the encrypted information to obtain authentication information, and the first functional entity sends the authentication information to the sending end.

[0018] In addition, according to a user authentication method according to one aspect of the present disclosure, the system also includes a second functional entity, which is used to implement the authentication service function. The method also includes: the second functional entity negotiates with the first functional entity to generate an intermediate key, and the second functional entity sends the intermediate key to the first functional entity, wherein the intermediate key is used to generate a transmission key.

[0019] In addition, according to the user authentication method in one aspect of the present disclosure, the system further includes a third functional entity, which is used to manage authentication information. The method further includes: the third functional entity sends an authentication request to the first functional entity.

[0020] In addition, the user authentication method according to one aspect of the present disclosure further includes: the third functional entity receiving authentication information sent by the first functional entity.

[0021] According to another aspect of the present disclosure, a user authentication device is provided, which includes: a key sending module, configured to send a transmission key to a target user device corresponding to the target user in response to an authentication request from an initiator for a target user; an information receiving module, configured to receive encrypted information from the target user device, wherein the encrypted information is obtained by encrypting the first biometric information of the target user using the transmission key; an information generating module, configured to authenticate the encrypted information using the second biometric information to obtain authentication information; and an information sending module, configured to send the authentication information to the initiator.

[0022] In addition, according to one aspect of the present disclosure, a user authentication device is provided, wherein the device includes: a request sending module, configured to send an authentication request for a target user to a first functional entity, and an information receiving module, configured to receive authentication information sent by the first functional entity, wherein the authentication information is used to represent the authentication result of the target user, wherein the authentication information is obtained by the first functional entity authenticating the encrypted information using the second biometric information, wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by the target user device corresponding to the target user using the transmission key to encrypt the first biometric information of the target user, and the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

[0023] In addition, according to one aspect of the present disclosure, a user authentication device is provided, wherein the device includes: a key negotiation module, configured to negotiate with a first functional entity to generate an intermediate key, and an intermediate key sending module, configured to send the intermediate key to the first functional entity, wherein the intermediate key is used to generate a transmission key for encrypted information, wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by encrypting the first biometric information of the target user by a target user device corresponding to the target user using the transmission key, and the transmission key is sent by the first functional entity to the target user device in response to an authentication request.

[0024] In addition, according to one aspect of the present disclosure, a user device includes: a key receiving module, configured to receive a transmission key from a first functional entity, an encryption information generating module, configured to generate encryption information based on the first biometric information of the target user and the transmission key, and an information sending module, configured to send encryption information to the first functional entity, wherein the transmission key is obtained by the first functional entity in response to an authentication request from the sending end, and the encryption information is used to authenticate with the second biometric information to obtain authentication information, and the authentication information is received by the sending end.

[0025] According to yet another aspect of the present disclosure, an electronic device is provided, including: a memory for storing computer-readable instructions; and a processor for executing the computer-readable instructions so that the electronic device performs the user authentication method as described above.

[0026] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium is provided for storing computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, the processor executes the user authentication method as described above.

[0027] As will be described in detail below, according to the user authentication method of the embodiment of the present disclosure, the present disclosure is used to realize the personality authentication of the target user. The first functional entity established in the present disclosure can obtain the second biometric information that can represent the identity of the target user, and distinguish the authenticity of the target user by using the second biometric information to authenticate the first biometric information sent by the target device corresponding to the target user, and then identify whether the business counterpart is a real user, thereby avoiding AI "evil" situations such as users being deceived by fake users, and to a certain extent, it can improve the security of the communication process; and, in the present disclosure, the first functional entity can also obtain a transmission key and send it to the user device for encrypting the first biometric information, while strengthening the confidentiality of the first biometric information, further improving the security of the business communication process, and protecting the privacy of the target user. In summary, the technical solution provided by the present disclosure can identify whether the business counterpart is a real user and improve the security of the business communication process.

[0028] It is to be understood that both the foregoing general description and the following detailed description are exemplary, and are intended to provide further explanation of the technology as claimed. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The above and other purposes, features, and advantages of the present disclosure will become more apparent through a more detailed description of the embodiments of the present disclosure in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the present disclosure and are not intended to limit the present disclosure. In the drawings, the same reference numerals generally represent the same components or steps.

[0030] Figure 1 is a schematic diagram illustrating the structure of a mobile device;

[0031] FIG2( a ) is a schematic diagram illustrating a non-roaming network architecture according to a service-oriented presentation approach;

[0032] FIG2( b ) is a diagram illustrating a non-roaming network architecture according to a reference point presentation method;

[0033] Figure 3 is a schematic diagram illustrating a user authentication system according to an embodiment of the present disclosure;

[0034] Figure 4 is an interaction diagram illustrating another user authentication method according to an embodiment of the present disclosure;

[0035] Figure 5 is a schematic diagram illustrating another user authentication system according to an embodiment of the present disclosure;

[0036] Figure 6 is an interaction diagram illustrating another user authentication method according to an embodiment of the present disclosure;

[0037] Figure 7 It is a diagram illustrating the security ranking of functional entities in the existing network architecture;

[0038] Figure 8 is a schematic diagram illustrating another user authentication system according to an embodiment of the present disclosure;

[0039] Figure 9 is an interaction diagram illustrating another user authentication method according to an embodiment of the present disclosure;

[0040] Figure 10 is a schematic diagram illustrating a user authentication device according to an embodiment of the present disclosure;

[0041] Figure 11 is a schematic diagram illustrating a user equipment according to an embodiment of the present disclosure;

[0042] Figure 12 is a schematic diagram illustrating another user authentication device according to an embodiment of the present disclosure;

[0043] Figure 13 is a schematic diagram illustrating another user authentication device according to an embodiment of the present disclosure;

[0044] Figure 14 is a hardware block diagram illustrating an electronic device according to an embodiment of the present disclosure; and

[0045] Figure 15 is a schematic diagram illustrating a computer-readable storage medium according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of the present disclosure more apparent, the following will describe in detail exemplary embodiments of the present disclosure with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the exemplary embodiments described herein.

[0047] In current technical solutions, fourth-generation mobile communication technology (4G) networks often use enterprise-level professional security (EPS-AKA) authentication. However, due to the vulnerability of the signaling protocol used by 4G networks to verify and authorize messages and distribute information, EPS-AKA is vulnerable to attacks. In addition, because EPS-AKA in 4G networks uses plain text to transmit user identity information during the authentication process, the possibility of user information leakage increases. Furthermore, based on EPS-AKA, fifth-generation mobile communication technology (5G) authentication inherits the AKA framework of EPS-AKA and enhances its mechanisms and capabilities. For example, 5G networks introduce more logical network elements, such as the access and mobility management function (AMF) network element, the session management function (SMF) network element, and the user plane function (UPF) network element.

[0048] Furthermore, Figure 1 is a schematic diagram illustrating the structure of a mobile device, such as Figure 1 As shown, the USIM is a subscriber identity module, typically embedded in a mobile equipment (ME). It stores user identity information, authentication keys, and other security information to ensure secure use of mobile communication networks. A mutual authentication relationship exists between the ME and the USIM, confirming the legitimacy of the USIM and the identity of the ME's owner or user. The authentication process assumes that the owner of the number and terminal is the user.

[0049] The emergence of AI makes it difficult for users to distinguish the authenticity of their business counterparts.

[0050] To address the aforementioned issues, this disclosure proposes a first functional entity that receives and processes user identity authentication requests from services. The terminal device collects the user's biometric information, compares it with the user's biometric information code, and returns the authentication result to authenticate the user. Furthermore, the first functional entity collaborates with other logical network elements to encrypt the biometric information during transmission, ensuring secure transmission within the communication network and protecting the user's privacy.

[0051] In a possible embodiment, the present disclosure can inherit and reuse the initial access authentication of existing communication networks (such as the above-mentioned EPS-AKA, 5G-AKA), and realize the personality verification of users by introducing the above-mentioned first functional entity as a new logical network element in the existing network architecture. The present disclosure can also use other communication networks, which can be selected according to actual conditions, without any specific restrictions.

[0052] Specifically, Figure 2(a) is a schematic diagram illustrating a non-roaming network architecture based on a service-oriented presentation method. As shown in Figure 2(a), the network architecture may include: user equipment (UE), radio access network ((R)AN), user plane function (UPF), data network (DN), session management function (SMF), authentication server function (AUSF), AMF, anomaly detection function (AF), unified data management (UDM), personality authentication function logical network element (AKMP Function, AKMPF) and NEF and other logical network elements. Among them, AKMPF is used to manage the keys and user biometric information in the personality authentication (AKMP) business process. Figure 2(b) is a schematic diagram illustrating a non-roaming network architecture based on a reference point presentation method. As shown in Figure 2(b), AKMPF can interact with functional entities such as AUSF and AMF.

[0053] It is worth noting that the existing non-roaming network architecture does not include personality authentication function, nor does it have the AKMPF functional entity. The technical solution provided by the present disclosure can be used in, for example Figure 2(a) 、 2(b) The solution is implemented by adding AKMPF to the network architecture of the prior art, which has strong scalability and is simple and easy to implement.

[0054] Figure 3 This is a schematic diagram illustrating a user authentication system according to an embodiment of the present disclosure. The system may include a first functional entity and a target user equipment. The specific authentication scheme of the user authentication system is described in detail below. Furthermore, when the system is applied to an existing network architecture, such as EPS-AKA or 5G-AKA, the target user equipment may be understood as a UE, and the first functional entity may be understood as an AKMPF. Figure 4 is an interactive diagram illustrating a user authentication method according to an embodiment of the present disclosure, such as Figure 4 As shown, the present disclosure provides a user authentication method, comprising:

[0055] Step S401: In response to an authentication request from an initiator for a target user, a first functional entity sends a transmission key to a target user equipment corresponding to the target user.

[0056] Step S402: The target user equipment receives a transmission key from the first functional entity.

[0057] Step S403: The target user device encrypts the first biometric information of the target user using the transmission key to obtain encrypted information.

[0058] Step S404: The target user equipment sends encrypted information to the first functional entity.

[0059] In step S405 , the first functional entity receives encrypted information from the target user device, wherein the encrypted information is obtained by encrypting the first biometric information of the target user based on the transmission key.

[0060] Step S406: The first functional entity authenticates the encrypted information using the second biometric information to obtain authentication information.

[0061] Step S407: The first functional entity sends authentication information to the initiating end.

[0062] In an embodiment of the present disclosure, as shown in step S401, the authentication request is a personality authentication initiated by the initiator for a user who is not the initiator, and the target user device refers to the device used by the target user when using specific software or services. Specifically, during the communication process, the user at one end of the communication can initiate personality authentication for the user at the other end of the communication, wherein the user initiating the personality authentication is the initiator, and the user whose personality authentication is initiated is the target user, the device used by the target user when communicating is the target user device, and the personality authentication initiated by the initiator is the authentication request. The authentication request can be issued by the initiator after completing the pre-authentication, or it can be issued directly by the initiator, and no further restrictions are made here.

[0063] In one possible embodiment, to increase the fun of user interaction, the initiator can initiate a personality authentication for itself, that is, the initiator can also be the target user. For example, the user initiating communication can initiate a personality authentication for themselves while waiting for the other user to connect, making the waiting period more interesting.

[0064] In response to the authentication request, the first functional entity may send a transmission key to the target user device. The transmission key may be used to encrypt information. The transmission key may be used to encrypt information symmetrically or asymmetrically, with no particular limitation on the encryption method. Furthermore, the transmission key may be generated in a variety of ways. Specifically, the transmission key may be generated directly by the first functional entity, may be received by the first functional entity from a transmission key generated and sent by another functional entity, or may be generated by the first functional entity from an intermediate key received from another functional entity. These limitations are not specific here.

[0065] In the embodiment of the present disclosure, as shown in step S402, the target user equipment may receive a transmission key from the first functional entity.

[0066] In an embodiment of the present disclosure, as shown in step S403, the target user device can obtain the target user's biometric information based on the transmission of the key. The first biometric information can be the target user's biometric information collected by the target user device. The target user device can be any device with a communication function, such as a computer, a mobile phone, a tablet computer, etc. Furthermore, the target user device can be any device with a biometric information collection function, and can also control other devices to collect biometric information by communicating with other devices. For example, a computer can communicate with smart home devices (such as monitors, smart speakers, etc., not to be exhaustive), control the smart home devices to collect the target user's biometric information, and receive the biometric information sent by the smart home devices. The first biometric information is a biometric feature that can be used to distinguish the identity of the user. Preferably, it can be a unique feature of the user. Exemplarily, the biometric information involved in the present disclosure (including the first biometric information and the second biometric information) can include but is not limited to: iris, voiceprint, fingerprint, genetic information, palm print, biometric code, etc., one or more combinations of information. After obtaining the first biometric information, the target user device can use the transmission key to encrypt the first biometric information of the target user to obtain encrypted information, thereby enhancing the protection of the biometric information of the target user and protecting the privacy of the target user.

[0067] In the disclosed embodiment, as shown in step S404, after generating the encrypted information, the target user device may send the encrypted information to the first functional entity. Furthermore, because the security of user devices is affected by multiple factors, such as the user device's hardware and software configuration, the security technology used, and the user's security awareness, it is impossible to uniformly define the security of user devices. User devices with weaker security may be more vulnerable to attacks. To protect the privacy of each user and prevent the target user device from leaking the user's biometric information when attacked, the first biometric information collected by the target user device may be deleted after the target user device completes the operation of sending the encrypted information to the first functional entity.

[0068] In the disclosed embodiment, as shown in step S405, the first functional entity may receive encrypted information generated by encrypting the first biometric information using the transmission key. The encrypted information includes, but is not limited to, the first biometric information. For example, the encrypted information may be a combination of a user identifier (SUPI), a user equipment identifier (PEI), or a user personality authentication identifier (SPPI) and the first biometric information. Other information may also be included in the encrypted information, without particular limitation.

[0069] In an embodiment of the present disclosure, as shown in step S406, the first functional entity can use the second biometric information and the encrypted information for authentication to obtain authentication information. The second biometric information can be stored in the first functional entity; or, it can also be stored in other functional entities. In this case, the first functional entity can call the second biometric information according to actual needs. For example, after obtaining the encrypted information, the first functional entity can send a request to other functional entities to call the second biometric information. After receiving the second biometric information replied by the other functional entity, the second biometric information is used to compare with the encrypted information to obtain a comparison result. In order to ensure the privacy of the user, the second biometric information can be stored in a functional entity with higher security. Except for specific functional entities, other functional entities or operators have no right to call the information. For example, in this solution, except for the first functional entity used to implement the user authentication scenario, other entities have no right to call the user's biometric information.

[0070] After obtaining the comparison results, the first functional entity can generate authentication information based on the comparison results. The comparison can be performed in various ways, such as by similarity. If the similarity meets the authentication criteria, authentication is passed; if it does not, authentication is considered failed. For example, the authentication criteria may be that the similarity between the first and second biometric information is greater than or equal to 80%. If the similarity is less than 80%, the target user's authentication is considered failed; otherwise, the target user's authentication is considered passed.

[0071] In the disclosed embodiment, as shown in step S407, the first functional entity can generate authentication information in different forms based on different authentication results. Furthermore, the authentication information sent can have various forms. For example, the authentication information can display a similarity score between the encrypted information and the second biometric information, and / or can directly indicate whether the target user is the intended user or a real person. The specific form is not limited here and can be customized in actual application scenarios.

[0072] In summary, the present disclosure can verify the user's identity by comparing the user's biometric information, thereby avoiding AI "evil" situations such as users being deceived by fake users, and can improve the security of the communication process to a certain extent.

[0073] In summary, the present disclosure provides a user authentication method, which is applied to a first functional entity, including: the first functional entity responds to an authentication request from an initiator for a target user, the first functional entity sends a transmission key to a target user device corresponding to the target user, the first functional entity receives encrypted information from the target user device, wherein the encrypted information is obtained by encrypting the first biometric information of the target user using the transmission key, the first functional entity authenticates the encrypted information using the second biometric information to obtain authentication information, and sends the authentication information to the initiator.

[0074] The present disclosure also provides a user authentication method, which is applied to a target user device, and includes: sending an authentication request for a target user to a first functional entity, and receiving authentication information sent by the first functional entity.

[0075] The present disclosure also provides a system, such as Figure 3 As shown, it may specifically include: in response to an authentication request from the initiator for the target user, the first functional entity sends a transmission key to the target user device corresponding to the target user, the target user device uses the transmission key to encrypt the first biometric information of the target user to obtain encrypted information, the target user device sends the encrypted information to the first functional entity, the first functional entity uses the second biometric information to authenticate the encrypted information to obtain authentication information, and the first functional entity sends the authentication information to the sending end.

[0076] In the present disclosure, the second biometric information can be stored in a custom location, and the first functional entity has the ability to call this information. For example, in the memory of the server, in the first functional entity, or in any other functional entity. In one possible embodiment, the second biometric information of the target user can be stored in other functional entities, which can reduce the storage burden of the first functional entity. Alternatively, in another possible embodiment, the first functional entity can store the second biometric information of each user, which can improve the efficiency of user authentication and reduce the time for information call. The present disclosure does not strictly limit the specific storage location, and it can be adjusted in actual operation.

[0077] In a possible embodiment, the first functional entity may use the transmission key to decrypt the encrypted information to obtain the first biometric information of the target user, and compare the first biometric information with the second biometric information to obtain authentication information.

[0078] In the disclosed embodiments, decryption using the transmission key can restore the first biometric information in the encrypted information. Directly comparing the decrypted biometric information with other information may be more efficient than decrypting each data block individually. This can reduce the number of decryption operations and the amount of computation required, thereby improving data processing efficiency. Furthermore, the encryption process can be used to verify whether there were any problems with the transmission key during transmission.

[0079] Due to problems such as weak password policies, weak encryption algorithms, and management and security vulnerabilities in the network structure, data leakage may occur, making it impossible to guarantee the security of users' biometric information and privacy during the authentication process.

[0080] In the disclosed embodiment, before obtaining the transmission key, the first functional entity can use an intermediate key to generate a transmission key, which is then sent to the target user device. To enhance the security of the user's first biometric information during transmission, the transmission key can be a dynamic key, meaning that the key transmitted by the first functional entity is different each time, increasing the difficulty of attack. Because the transmission key changes dynamically, a cracker can only crack one of the historical keys, but cannot compromise the entire system. This reduces the cost of cracking and reduces security risks.

[0081] Furthermore, the first functional entity can obtain an intermediate key and generate a dynamic key based on the intermediate key. The intermediate key itself can be generated based on a secure key generation and management mechanism, and additional security measures can be added when generating a new key, such as the use of an encryption algorithm and a random number generator. On the basis of the random key, the confidentiality of the key is further improved, protecting the security of the user's biometric information, thereby protecting the user's privacy. Furthermore, the intermediate key can be a periodic key. The first functional entity can regenerate or obtain the intermediate key at fixed time intervals to prevent it from being stolen by others, thereby leaking the target user's biometric information. By regularly updating the intermediate key, the risk of the intermediate key being cracked can be reduced, and the security of network transportation data can be improved. The intermediate key can be used to generate a transmission key using methods such as random number generation, hash function, and pseudo-random number generator. The specific generation method is not limited here.

[0082] Furthermore, in order to protect user privacy, an entity specifically used to implement authentication service management functions can be used to assist in determining intermediate keys, so as to further improve the security level of the keys and reduce the risk of leakage of user biometric information during communication transmission. Figure 5 is a schematic diagram illustrating another user authentication system according to an embodiment of the present disclosure, such as Figure 5 As shown, the present disclosure is reused Figure 3 Based on the system in [1], a second functional entity is added. The second functional entity can be used to implement the authentication service management function, and the second functional module can negotiate with the first functional module to generate a key. In actual applications, the first functional entity and the second functional entity can exist independently or be integrated into the same device or system and interact with the target user device. Among them, the device is a component that processes digital signals and can process input signals according to preset logical rules and generate corresponding output signals. For example, servers, computers, digital control systems, and communication equipment, etc., are not limited here. The system can be a base station system, a core network system, etc.

[0083] Figure 6 is an interactive diagram illustrating another user authentication method according to an embodiment of the present disclosure, such as Figure 6The specific interaction process is as follows:

[0084] Step S601: The second functional entity negotiates with the first functional entity to generate an intermediate key.

[0085] Step S602: The second functional entity sends an intermediate key to the first functional entity.

[0086] Step S603: The first functional entity negotiates with the second functional entity and receives an intermediate key from the second functional entity.

[0087] Step S604: The first functional entity generates a transmission key based on the intermediate key.

[0088] Afterwards, the first functional entity can interact with the target user device to implement personality authentication of the target user. Figure 6 As shown, in the specific implementation, you can refer to Figure 4 Any implementation of the illustrated embodiments will not be described in detail here.

[0089] In the disclosed embodiment, as shown in step S601, considering that the intermediate key can be generated through negotiation by multiple functional entities, the joint participation of multiple functions can provide stronger anti-attack capabilities and reduce the risk of key cracking. This mechanism also provides forward secrecy and prevents eavesdropping, further enhancing communication security. Specifically, the first functional entity can negotiate with other functional entities, and the intermediate key can be generated by the other functional entities.

[0090] In step S602, other functional entities that negotiate with the first functional entity to generate intermediate keys are defined as second functional entities. The second functional entity may have an authentication service management function, and the management methods may include distribution, storage, encryption and protection. Furthermore, since the functional entity with the authentication service function itself has higher security, the security risks are reduced and the security of the entire system is enhanced by realizing the joint collaboration of identity authentication, authorization control, data protection, and event tracking functions. When this embodiment is applied to the network architecture shown in Figure 2(a), the second functional entity may be specifically AUSF. AUSF adopts multi-dimensional data organization security protection, such as tenant isolation, access security, and sensitive data encrypted storage, and provides hardware and software security encryption mechanisms for sensitive data to protect user data. Figure 7 It is a diagram illustrating the functional entity security ranking of the existing network architecture, such as Figure 7 As shown in Figure 1, the more peripheral the functional entity is, the lower the security. Compared with other functional entities, AUSF has higher security, further increasing the difficulty of deciphering the intermediate key, improving the security of the network architecture, and thus improving the security of user privacy.

[0091] In the disclosed embodiment, as shown in step S603, the first functional entity may receive the intermediate key from the second functional entity. Thereafter, the first functional entity may execute step S604 to generate a transmission key based on the intermediate key. After obtaining the transmission key, the first functional entity may perform the user biometric information encryption and user authentication procedures of steps S401 to S407 with the target user device.

[0092] In the present disclosure, a first functional entity can communicate with a second functional entity via a first interface. The first interface can at least be responsible for personality authentication key negotiation. When applied to a specific network architecture, the first interface can be understood as Nakmpf_Ausf_*, i.e., the interface between AKMPF and AUSF. It should be understood that the first functional entity has interfaces for communicating with other functional entities. This disclosure does not impose any particular restrictions on the actual naming methods and names of these interfaces, and custom designs can be used in actual scenarios.

[0093] In summary, the present disclosure provides a user authentication method applied to a second functional entity, including: the second functional entity negotiates with a first functional entity to generate an intermediate key, and the second functional entity sends the intermediate key to the first functional entity.

[0094] In a possible embodiment, the first functional entity may communicate directly with the user equipment or platform, or may receive authentication information from other functional entities within the network architecture. Figure 8 As shown, the present disclosure is multiplexed as shown in Figure 3 On the basis of the system, a third functional entity is added, which is used to manage authentication information and authentication requests, and can interact with the first functional entity and send authentication information to the first functional entity. In actual applications, the first functional entity and the third functional entity can exist independently, or they can be integrated into the same device or system to interact with the target user device. There are not many specific restrictions, and you can choose according to the actual situation. Among them, the first functional entity can communicate with the third functional entity through the second interface, and the second interface can at least be responsible for receiving user authentication requests and returning results. If the first interface is applied to a specific network architecture, it can be understood as Nakmpf_Amf_*, that is, the interface between AKMPF and AMF. Similarly, the present disclosure has no special restrictions on the actual naming method and name of the second interface, and a custom design can be used in the actual scenario.

[0095] In this embodiment, the user who initiates the authentication request can trigger the instruction through input (such as keyboard, mouse operation or touch screen), specific external events (such as user clicking a button, receiving a message, etc.) and external triggers. The third functional entity can receive the request sent by the business server and send a personality authentication request to the first functional entity. When the third functional entity is applied to the network structure in Figure 2(a), the third functional entity can be specifically understood as AMF. AMF is responsible for processing signaling interactions related to the connection, such as network configuration, parameter negotiation, etc., and can manage authentication information and authentication requests more efficiently.

[0096] In one possible embodiment, considering that users may object to electronic devices collecting biometric information, an indication of whether the user supports biometric verification may be stored. This indication may be stored in the first functional entity or in another functional entity, without further limitation. Furthermore, when the indication is stored in another functional entity, the functional entity storing the indication of whether the user supports biometric verification may be considered a fourth functional entity, which may be integrated with the first and second functional entities into the same system. Before the first functional entity sends the transmission key to the target user device, it may obtain the indication from the fourth functional entity. If the target user does not support biometric verification, the first functional entity may directly generate authentication information. If the target user supports biometric verification, steps S401-S407 may be executed. When the fourth functional entity is applied to the network structure shown in Figure 2(a), it may be specifically understood as a unified data management function (UDM), which may store the indication of whether the subscriber supports biometric verification.

[0097] Furthermore, in a possible embodiment, the system may further include a first functional entity, a second functional entity, a third functional entity and a target user equipment. In this case, it can be regarded as: Figure 5 A third functional entity is added to the system. For ease of understanding, the following will use the existing network architecture to illustrate the interaction between these functional entities to achieve the process of personality authentication. Specifically, the system at this time may include: AKMPF (i.e., the first functional entity of the present disclosure), AMF (i.e., the third functional entity of the present disclosure), AUSF (i.e., the second functional entity of the present disclosure) and UE (i.e., the target user equipment of the present disclosure). At this time, please refer to Figure 9 , Figure 9 FIG1 is an interaction diagram illustrating another user authentication method according to an embodiment of the present disclosure. The specific interaction process is as follows:

[0098] 1. The AMF sends a request for personality verification to the AKMPF.

[0099] 2. AKMPF initiates the negotiation process of the personality authentication private key (Key AKMP) with AUSF and receives the Key AKMP from AUSF.

[0100] Among them, Key AKMP can be understood as the above-mentioned intermediate key.

[0101] 3. AKMPF generates the user biometric information encoding transmission key (Key AP).

[0102] Key AP can be understood as the transport key mentioned above in this disclosure. The intermediate key and transport key are not specifically named. Key AP and Key AKMP are simply the names of the intermediate key and transport key in this embodiment. This is a possible naming method in actual application scenarios and is not specifically limited by this disclosure.

[0103] 4. AKMPF notifies UE Key AP.

[0104] 5. The UE collects user biometric information (i.e., the first biometric information mentioned above in this disclosure) and forms a user biometric information code after processing.

[0105] 6. The UE uses the Key AP to encrypt the user’s biometric information and sends it to the AKMPF.

[0106] At this time, the information sent by the UE to the AKMPF is the encrypted information described above in this disclosure.

[0107] 7. AKMPF will receive the encrypted user biometric information and compare it to the received information before giving the verification result.

[0108] After the AKMPF receives the encrypted user biometric information code, it can be compared with the second biometric information stored in the AKMPF or other functional entities.

[0109] 8. AKMPF returns the personality authentication result to AMF.

[0110] It is worth noting that the technical solution disclosed in this disclosure can be used in combination with other authentication solutions. Specifically, it can be combined with existing user authentication solutions.

[0111] At this time, in a further possible embodiment based on this embodiment, in order to further protect the security of user privacy, as Figure 9As shown, USIM primary authentication can be performed before identity authentication, that is, determining whether the USIM owner is the user. After the USIM primary authentication is completed, this solution is automatically executed. In this case, the third functional entity can be the initiator of the USIM primary authentication process. After completing the USIM primary authentication, the third functional entity can send a personality verification request to the first functional entity to initiate the aforementioned personality authentication process.

[0112] The present disclosure provides a user authentication method, which is applied to a third functional entity and includes: sending an authentication request for a target user to a first functional entity, and receiving authentication information sent by the first functional entity.

[0113] In a possible embodiment, when the initiator is a terminal device, the initiator and the target user are the communicating parties. The communication method may include but is not limited to at least one of the following: video communication, voice communication, network communication, data transmission (such as Bluetooth, Wi-Fi, USB connection, etc.), text communication (such as SMS, email, instant messaging, etc.), near-field communication, remote desktop connection, screen sharing, application sharing, etc., without exhaustive enumeration. The initiator is the initiator of the personality authentication request. In actual communication scenarios, it can be either the initiator of the communication or the called party, and no further limitation is made here.

[0114] In actual application scenarios, it is considered that there are situations where fraudsters use AI to change faces or use other people's devices to disguise themselves as relatives or friends of the called party or other identities (such as entrepreneurs, etc.) to reduce the vigilance of the called party and thus commit fraud. Therefore, the technical solution provided by the present disclosure can be used for personality authentication. For example, an automatic personality authentication function can be set, that is, when the called party receives a communication invitation or text letter, the called party device automatically authenticates the personality of the opposite user. Alternatively, sensitive word monitoring or data packet sniffing can be set. That is, after designing pre-set sensitive words or data during the communication process, the personality authentication function is automatically initiated. When the personality authentication of the opposite end fails, a reminder is sent to the initiating end to prevent others from using AI to do evil. Or, for example, the user can also actively initiate personality authentication, for example, before the user accepts the communication invitation of others or during the communication process, personality authentication can be initiated for the opposite user.

[0115] In another possible embodiment, when the initiating end is a platform, the target user is at least one business object of the business platform. A business platform can refer to a client, application, or mini-program that provides business services, such as a video conferencing platform, e-commerce platform, online education platform, social media platform, or human resources management platform. These business platforms all require online communication with other users. If a user commits fraud or other criminal acts against other users through these platforms, it may affect the reputation of the business platform and the user experience of other users. The business objects of a business platform can be users of the business platform, regardless of whether the user is registered with the platform. In practical applications, when the business platform is a video conferencing platform, the business objects are users of the video conferencing platform. To prevent participants from using AI face-changing to disguise themselves and infringe on the rights of others, the video conferencing platform can initiate identity verification for all participants. In this case, the video conferencing platform is the initiating end, and all participants can be considered target users. The platform can mark business objects that fail authentication or send reminders to other business objects participating in the meeting or viewing the video. The specific response plan is not limited here.

[0116] The user authentication method according to the embodiment of the present disclosure is described above. Below, a user authentication device for implementing the above user authentication method will be further described.

[0117] In a first aspect, the present disclosure provides a user authentication device, Figure 10 is a schematic diagram illustrating a user authentication device according to an embodiment of the present disclosure, such as Figure 10 As shown, the user authentication device 1000 is used to implement the user authentication method performed by the first functional entity as described above, and the device may include:

[0118] The key sending module 1001 sends a transmission key to a target user device corresponding to the target user in response to an authentication request from the initiator for the target user.

[0119] The information receiving module 1002 receives encrypted information from a target user device, wherein the encrypted information is obtained by encrypting the first biometric information of the target user using a transmission key.

[0120] The information generating module 1003 uses the second biometric information to authenticate the encrypted information to obtain authentication information.

[0121] The information sending module 1004 sends authentication information to the initiator.

[0122] In one embodiment, the key sending module 1001 is specifically configured to generate a transmission key based on an intermediate key, wherein the transmission key is a dynamic key and the intermediate key is a periodic key.

[0123] In one embodiment, the key sending module 1001 is specifically used to: before generating a transmission key based on the intermediate key, it also includes: negotiating with the second functional entity and receiving the intermediate key from the second functional entity, wherein the second functional entity is used to implement the authentication service function, and the first functional entity and the second functional entity communicate through the first interface.

[0124] In one embodiment, the key sending module 1001 is specifically configured to: the initiator is a third functional entity, the third functional entity is configured to manage authentication information, and the first functional entity communicates with the third functional entity via the second interface.

[0125] In one embodiment, the key sending module 1001 is specifically configured to: an initiating end and a target user are communicating parties, wherein the initiating end is the called party and the target user is the calling party.

[0126] In one embodiment, the key sending module 1001 is specifically configured to: the initiating end is a service platform, and the target user is at least one service object of the service platform.

[0127] In one embodiment, the information generation module 1003 is specifically configured to store the second biometric information of each user.

[0128] In one embodiment, the key sending module 1001 is specifically used to: use the second biometric information to authenticate the encrypted information to obtain authentication information, including: using the transmission key to decrypt the encrypted information to obtain the first biometric information, and using the first biometric information to compare with the second biometric information to obtain authentication information.

[0129] In a second aspect, in addition to the above-mentioned user authentication apparatus, a user device 1100 may be provided to implement the user authentication method executed by the target user device as described above. Figure 11 is a schematic diagram illustrating a user equipment according to an embodiment of the present disclosure, such as Figure 11 As shown, the user equipment 1100 may include:

[0130] The key receiving module 1101 is configured to receive a transmission key from the first functional entity.

[0131] The encryption information generation module 1102 is configured to generate encryption information based on the first biometric information and transmission key of the target user, wherein the transmission key is sent by the first functional entity in response to the authentication request of the sending end, and the encryption information is used to authenticate with the second biometric information to obtain authentication information.

[0132] The information sending module 1103 is configured to send encrypted information to the first functional entity.

[0133] Thirdly, Figure 12 is a schematic diagram illustrating another user authentication device according to an embodiment of the present disclosure, such as Figure 12 As shown, the user authentication device 1200 is used to implement the user authentication method performed by the second functional entity as described above, and the device may include:

[0134] The key negotiation module 1201 is configured to negotiate with the first functional entity to generate an intermediate key.

[0135] The intermediate key sending module 1202 is configured to send an intermediate key to the first functional entity, wherein the intermediate key is used to generate a transmission key for encrypted information, wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by encrypting the first biometric information of the target user by the target user device corresponding to the target user using the transmission key, and the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

[0136] Fourthly, Figure 13 is a schematic diagram illustrating another user authentication device according to an embodiment of the present disclosure, such as Figure 13 As shown, the user authentication device 1300 is used to implement the user authentication method performed by the third functional entity as described above. The device may include: a request sending module 1301, configured to send an authentication request for a target user to the first functional entity.

[0137] The information receiving module 1302 is configured to receive authentication information sent by the first functional entity, wherein the authentication information is obtained by the first functional entity authenticating the encrypted information using the second biometric information, wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by the target user device corresponding to the target user using the transmission key to encrypt the first biometric information of the target user, and the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

[0138] The present disclosure also provides a user authentication system, as shown in the attached Figure 3 and Figure 5 As shown in any of the figures, the method described in any of the above embodiments can be applied. The system includes:

[0139] In response to an authentication request from the initiator for a target user, the first functional entity sends a transmission key to a target user equipment corresponding to the target user.

[0140] The target user device encrypts the first biometric information of the target user using the transmission key to obtain encrypted information.

[0141] The target user equipment sends the encrypted information to the first functional entity.

[0142] The first functional entity authenticates the encrypted information using the second biometric information to obtain authentication information.

[0143] The first functional entity sends authentication information to the sending end.

[0144] In one embodiment, the system also includes a second functional entity, which is used to implement an authentication service function, and also includes: the second functional entity negotiates with the first functional entity to generate an intermediate key, and the second functional entity sends the intermediate key to the first functional entity, wherein the intermediate key is used to generate a transmission key.

[0145] In one embodiment, the system further includes a third functional entity, and the third functional entity is used for managing authentication information. The method further includes: the third functional entity sends an authentication request to the first functional entity.

[0146] In one embodiment, it further includes: a third functional entity receiving authentication information sent by the first functional entity.

[0147] Figure 14 1400 is a hardware block diagram illustrating an electronic device according to an embodiment of the present disclosure. The electronic device according to an embodiment of the present disclosure includes at least a processor and a memory for storing computer-readable instructions. When the computer-readable instructions are loaded and executed by the processor, the processor executes the user authentication method described above.

[0148] Figure 14 The electronic device 1400 shown specifically includes: a central processing unit (CPU) 1401, a graphics processing unit (GPU) 1402, and a memory 1403. These units are interconnected via a bus 1404. The central processing unit (CPU) 1401 and / or the graphics processing unit (GPU) 1402 can be used as the above-mentioned processor, and the main memory 1403 can be used as the above-mentioned memory for storing computer-readable instructions. In addition, the electronic device 1400 may also include a communication unit 1405, a storage unit 1406, an output unit 1407, an input unit 1408, and an external device 1409, which are also connected to the bus 1404.

[0149] Figure 15 Schematic diagram of a computer-readable storage medium according to an embodiment of the present disclosure. Figure 15As shown, a computer-readable storage medium 1500 according to an embodiment of the present disclosure has computer-readable instructions 1501 stored thereon. When the computer-readable instructions 1501 are executed by a processor, the user authentication method according to the embodiment of the present disclosure described with reference to the above figures is executed. The computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, optical disk, magnetic disk, etc.

[0150] The user authentication method, device, electronic device and storage medium according to the embodiments of the present disclosure are described above with reference to the accompanying drawings. The present disclosure is used to realize personality authentication of the target user. The first functional entity established in the present disclosure can obtain the second biometric information that can represent the identity of the target user, and distinguish the authenticity of the target user by using the second biometric information to authenticate the first biometric information sent by the target device corresponding to the target user, and then identify whether the business counterpart is a real user, thereby avoiding AI "evil" situations such as users being deceived by fake users, and to a certain extent, it can improve the security of the communication process; and, in the present disclosure, the first functional entity can also obtain a transmission key and send it to the user device for encrypting the first biometric information, while strengthening the confidentiality of the first biometric information, further improving the security of the business communication process, and protecting the privacy of the target user. In summary, the technical solution provided by the present disclosure can identify whether the business counterpart is a real user and improve the security of the business communication process.

[0151] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0152] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this disclosure are merely illustrative and not restrictive, and should not be construed as necessarily possessed by each embodiment of the present disclosure. Furthermore, the specific details disclosed above are provided for illustrative purposes and to facilitate understanding, rather than as limitations. These details do not limit the present disclosure to necessarily being implemented using these specific details.

[0153] The block diagrams of the devices, devices, equipment, and systems involved in this disclosure are intended to be illustrative examples only and are intended to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including," "comprising," "having," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.

[0154] Additionally, as used herein, "or" used in a list of items beginning with "at least one" indicates a separate list, so that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not mean that the example described is preferred or better than other examples.

[0155] It should also be noted that in the system and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.

[0156] Various changes, substitutions, and modifications may be made to the technology described herein without departing from the teachings defined by the appended claims. Moreover, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of things, means, methods, and actions described above. Currently existing or later developed processes, machines, manufactures, compositions of things, means, methods, or actions that perform substantially the same function or achieve substantially the same results as the corresponding aspects described herein may be utilized. Accordingly, the appended claims include within their scope such processes, machines, manufactures, compositions of things, means, methods, or actions.

[0157] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is intended to be limited to the aspects shown herein, but to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0158] The above description has been provided for the purpose of illustration and description. In addition, this description is intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, changes, additions and sub-combinations thereof.

Claims

1. A user authentication method, characterized in that: Applied to the first functional entity, the method includes: In response to an authentication request from the initiator for a target user, sending a transmission key to a target user device corresponding to the target user; Receiving encrypted information from the target user device; wherein the encrypted information is obtained by encrypting the first biometric information of the target user using the transmission key; authenticating the encrypted information using the second biometric information to obtain authentication information; and Send the authentication information to the initiator.

2. The user authentication method according to claim 1, wherein: The sending of the transmission key to the target user equipment includes: The transmission key is generated based on the intermediate key; wherein the transmission key is a dynamic key and the intermediate key is a periodic key.

3. The user authentication method according to claim 2, wherein: Before generating the transmission key based on the intermediate key, the method further includes: negotiating with a second functional entity and receiving the intermediate key from the second functional entity; wherein the second functional entity is used to implement an authentication service function; The first functional entity communicates with the second functional entity through a first interface.

4. The user authentication method according to claim 1, wherein: Also includes: The initiator is a third functional entity, and the third functional entity is used for managing the authentication information; The first functional entity communicates with the third functional entity through a second interface.

5. The user authentication method according to claim 1, wherein: The initiating end and the target user are communicating parties, wherein the initiating end is the called party and the target user is the calling party.

6. The user authentication method according to claim 1, wherein: The initiating end is a service platform, and the target user is at least one service object of the service platform.

7. The user authentication method according to claim 1, wherein: The method further comprises: The second biometric information of each user is stored accordingly.

8. The user authentication method according to claim 1, wherein: The step of authenticating the encrypted information using the second biometric information to obtain authentication information includes: decrypting the encrypted information using the transmission key to obtain the first biometric information; The first biometric information is compared with the second biometric information to obtain the authentication information.

9. A user authentication method, characterized in that: Applied to the second functional entity, the method includes: Negotiating with the first functional entity to generate an intermediate key; and sending the intermediate key to the first functional entity; The intermediate key is used to generate a transmission key for encrypted information; the encrypted information is received by the first functional entity, and the encrypted information is obtained by encrypting the first biometric information of the target user by the target user device corresponding to the target user using the transmission key, and the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

10. A user authentication method, characterized in that: Applied to the third functional entity, the method includes: Sending an authentication request for the target user to the first functional entity; and receiving authentication information sent by the first functional entity; The authentication information is obtained by the first functional entity authenticating the encrypted information using the second biometric information; the encrypted information is received by the first functional entity, and the encrypted information is obtained by the target user device corresponding to the target user using the transmission key to encrypt the first biometric information of the target user; the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

11. A user authentication method, characterized in that: Applied to user equipment, the method includes: receiving a transmission key from the first functional entity; Encrypting the first biometric information of the target user using the transmission key to obtain encrypted information; and Sending the encrypted information to the first functional entity; The transmission key is sent by the first functional entity in response to an authentication request from the sending end, and the encrypted information is used to perform authentication with the second biometric information to obtain authentication information.

12. A user authentication method, characterized in that: Applied to a system including a user device and a first functional subject, the method includes: In response to an authentication request from the initiator for a target user, the first functional entity sends a transmission key to a target user equipment corresponding to the target user; The target user device encrypts the first biometric information of the target user using the transmission key to obtain encrypted information; The target user equipment sends the encrypted information to the first functional entity; The first functional entity authenticates the encrypted information using the second biometric information to obtain authentication information; The first functional entity sends the authentication information to the sending end.

13. The user authentication method according to claim 12, wherein: The system further includes a second functional entity, where the second functional entity is configured to implement an authentication service function. The method further includes: The second functional entity negotiates with the first functional entity to generate an intermediate key; The second functional entity sends the intermediate key to the first functional entity; wherein the intermediate key is used to generate the transmission key.

14. The user authentication method according to claim 12, wherein: The system further includes a third functional entity; the third functional entity is used for managing the authentication information; and the method further includes: The third functional entity sends the authentication request to the first functional entity.

15. The user authentication method according to claim 14, wherein: Also includes: The third functional entity receives the authentication information sent by the first functional entity.

16. A user authentication device, characterized in that: The device comprises: a key sending module, configured to send a transmission key to a target user device corresponding to the target user in response to an authentication request from the initiator for the target user; An information receiving module is configured to receive encrypted information from the target user device; wherein the encrypted information is obtained by encrypting the first biometric information of the target user using the transmission key; an information generating module configured to authenticate the encrypted information using the second biometric information to obtain authentication information; and The information sending module is configured to send the authentication information to the initiating end.

17. A user authentication device, characterized in that: The device comprises: a request sending module, configured to send an authentication request for a target user to the first functional entity; and An information receiving module is configured to receive authentication information sent by the first functional entity; wherein the authentication information is used to represent the authentication result of the target user; wherein the authentication information is obtained by the first functional entity authenticating encrypted information using the second biometric information; wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by the target user device corresponding to the target user using a transmission key to encrypt the first biometric information of the target user; the transmission key is sent by the first functional entity to the target user device in response to the authentication request.

18. A user authentication device, characterized in that: The device comprises: a key negotiation module, configured to negotiate with the first functional entity to generate an intermediate key; and An intermediate key sending module is configured to send the intermediate key to the first functional entity; wherein the intermediate key is used to generate a transmission key for encrypted information; wherein the encrypted information is received by the first functional entity, and the encrypted information is obtained by encrypting the first biometric information of the target user by the target user device corresponding to the target user using the transmission key, and the transmission key is sent by the first functional entity to the target user device in response to an authentication request.

19. A user equipment, characterized in that: include: A key receiving module is configured to receive a transmission key from the first functional entity; an encryption information generating module configured to generate encryption information based on the first biometric information of the target user and the transmission key; as well as an information sending module configured to send the encrypted information to the first functional entity; wherein the transmission key is obtained by the first functional entity in response to the authentication request of the sending end, and the encrypted information is used to authenticate with the second biometric information to obtain authentication information; The authentication information is received by the sending end.

20. An electronic device, characterized in that: include: a memory for storing computer-readable instructions; as well as A processor is configured to execute the computer-readable instructions so that the electronic device performs the user authentication method according to any one of claims 1 to 14.

21. A non-transitory computer-readable storage medium for storing computer-readable instructions, characterized in that: When the computer-readable instructions are executed by a processor, the processor is caused to perform the user authentication method according to any one of claims 1 to 15.