Multi-identity authentication method, device and equipment for electronic contract of mobile terminal and medium

By employing multiple authentication methods on mobile devices, including mobile phone number input, liveness detection, and facial recognition, the security risks of electronic contract authentication have been addressed, ensuring the authenticity and legality of user identities, avoiding the risk of proxy signing, and improving the accuracy and reliability of identity authentication.

CN121508934APending Publication Date: 2026-02-10ZHEJIANG HUIRONG NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511611462.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-05
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, electronic contracts rely on a single method of identity authentication, which poses security risks and makes them vulnerable to malicious attacks and identity forgery, resulting in a high risk of proxy signing.

Method used

The system employs a multi-factor authentication method on mobile devices, including first-factor authentication (phone number input), second-factor authentication (liveness verification), and third-factor authentication (facial recognition). This multi-factor authentication process ensures the authenticity and legitimacy of the user's identity.

Benefits of technology

It effectively improves the security of user information, avoids the misuse and proxy signing of electronic contracts, and enhances the accuracy and reliability of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508934A_ABST
    Figure CN121508934A_ABST
Patent Text Reader

Abstract

The invention provides an electronic contract multi-identity authentication method and device of a mobile terminal, equipment and a medium, and the method comprises the steps: determining whether to transmit an identity verification code to user equipment according to the response identity data and response behavior data of the user equipment to first identity authentication information; determining whether the user equipment passes the first identity authentication according to the input behavior data when the user equipment inputs the identity verification code; determining whether the user equipment passes the second identity authentication or not according to a real-time response behavior made by the user equipment for the second identity authentication information and the waiting response duration; determining whether the user equipment passes the third identity authentication according to a video frame sequence of the user equipment corresponding to the third identity authentication information and a shooting waiting time length; and if the user equipment passes the third identity authentication, determining that the multiple identity authentication of the user equipment is successful, and displaying an electronic contract to the user equipment. Therefore, the problems of false use and signing-for-another of the electronic contract are effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this disclosure relate to the field of identity authentication technology, and more specifically, to a method, apparatus, device, and medium for multi-identity authentication of electronic contracts applicable to a mobile terminal. Background Technology

[0002] When authenticating identities for electronic contracts, it is essential to ensure the authenticity and validity of user information. The system will verify the identity of logged-in users to confirm their legitimacy.

[0003] In related technologies, a single authentication method, such as SMS verification, is typically used. This method has certain security vulnerabilities and is susceptible to malicious attacks and identity forgery. Consequently, it is difficult to effectively guarantee user information security, leading to a significant risk of proxy signing of electronic contracts. Summary of the Invention

[0004] The embodiments described herein provide a method, apparatus, device, and medium for multi-factor authentication of electronic contracts on mobile devices, overcoming the aforementioned problems.

[0005] Firstly, based on the content of this disclosure, a multi-factor authentication method for electronic contracts on mobile devices is provided, including: After detecting that the user device has logged into the browser authentication page, the first layer of identity authentication information is displayed on the browser authentication page; Based on the user equipment's response identity data and response behavior data to the first authentication information, it is determined whether to send an authentication code to the user equipment; if it is determined to send an authentication code to the user equipment, then after detecting that the user equipment has entered the authentication code, it is determined whether the user equipment has passed the first authentication based on the user equipment's input behavior data when entering the authentication code. If the user equipment passes the first authentication, the second authentication information is displayed on the browser authentication page; Based on the real-time response behavior and response waiting time of the user equipment in response to the second authentication information, it is determined whether the user equipment has passed the second authentication. If the user equipment passes the second authentication, the third authentication information is displayed on the browser authentication page; Based on the video frame sequence of the user equipment corresponding to the third-level authentication information and the waiting time for shooting, it is determined whether the user equipment has passed the third-level authentication. If the user equipment passes the third authentication, the multi-factor authentication of the user equipment is determined to be successful, and the electronic contract is displayed to the user equipment.

[0006] Secondly, according to the present disclosure, a mobile electronic contract multi-identity authentication device is provided, comprising: The first display module is used to display the first layer of identity authentication information on the browser authentication page after detecting that the user device has logged into the browser authentication page; The first authentication module is used to determine whether to send an authentication code to the user equipment based on the user equipment's response identity data and response behavior data to the first authentication information; if it is determined to send an authentication code to the user equipment, then after detecting that the user equipment has entered the authentication code, it determines whether the user equipment has passed the first authentication based on the user equipment's input behavior data when entering the authentication code. The second display module is used to display second authentication information on the browser authentication page if the user equipment passes the first authentication. The second authentication module is used to determine whether the user equipment has passed the second authentication based on the real-time response behavior and waiting time of the user equipment in response to the second authentication information. The third display module is used to display third-level authentication information on the browser authentication page if the user equipment passes the second-level authentication. The third authentication module is used to determine whether the user equipment has passed the third authentication based on the video frame sequence corresponding to the third authentication information and the waiting shooting time. The display module is used to determine that the user equipment's multi-factor authentication is successful if the user equipment passes the third-level authentication, and then display the electronic contract to the user equipment.

[0007] Thirdly, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the electronic contract multi-identity authentication method for mobile terminals as described in any of the above embodiments.

[0008] Fourthly, a computer-readable storage medium is provided, on which a computer program is stored, and when executed by a processor, the computer program implements the steps of the electronic contract multi-identity authentication method for mobile terminals as described in any of the above embodiments.

[0009] The mobile electronic contract multi-identity authentication method provided in this application embodiment detects that a user device has logged into the browser authentication page, and displays first-level authentication information on the browser authentication page; based on the user device's response identity data and response behavior data to the first-level authentication information, it determines whether to send an authentication code to the user device; if it is determined to send an authentication code to the user device, after detecting that the user device has entered the authentication code, it determines whether the user device has passed the first-level authentication based on the user device's input behavior data when entering the authentication code; if the user device has passed the first-level authentication, it displays second-level authentication information on the browser authentication page; based on the user device's real-time response behavior and waiting response time to the second-level authentication information, it determines whether the user device has passed the second-level authentication; if the user device has passed the second-level authentication, it displays third-level authentication information on the browser authentication page; based on the user device's video frame sequence corresponding to the third-level authentication information and waiting shooting time, it determines whether the user device has passed the third-level authentication; if the user device has passed the third-level authentication, it is determined that the user device's multi-level authentication is successful, and the electronic contract is displayed to the user device. In this way, by conducting triple authentication of user identity, the security of user information is guaranteed, and the problems of impersonation and proxy signing of electronic contracts are effectively avoided.

[0010] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more obvious and understandable, specific implementation methods of this application are described below. Attached Figure Description

[0011] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments will be briefly described below. It should be understood that the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure, wherein: Figure 1 This is a flowchart illustrating a multi-identity authentication method for mobile electronic contracts provided in this publication.

[0012] Figure 2 This is a schematic diagram of the structure of a mobile electronic contract multi-identity authentication device provided in this disclosure.

[0013] Figure 3 This is a schematic diagram of the structure of a computer device provided in this disclosure.

[0014] It should be noted that the elements in the attached diagram are schematic and not drawn to scale. Detailed Implementation

[0015] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are also within the scope of protection of this disclosure.

[0016] Unless otherwise defined, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this subject matter pertains. It will be further understood that terms such as those defined in commonly used dictionaries shall be interpreted as having the meaning consistent with their meaning in the context of the specification and in the relevant art, and shall not be interpreted in an idealized or overly formal form unless otherwise explicitly defined herein. As used herein, the statement of “connecting” or “coupling” two or more parts together shall mean that these parts are directly joined together or joined through one or more intermediate components.

[0017] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of the phrase "embodiment" in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0018] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists, A and B exist simultaneously, or B exists. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Terms such as "first" and "second" are only used to distinguish one component (or part of a component) from another component (or another part of a component).

[0019] In the description of this application, unless otherwise stated, "multiple" means two or more (including two), and similarly, "multiple groups" means two or more (including two groups).

[0020] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0021] Figure 1 This is a flowchart illustrating a multi-identity authentication method for mobile electronic contracts provided in this embodiment of the disclosure, as follows: Figure 1As shown, the specific process of the multi-factor authentication method for electronic contracts on mobile devices includes: S110. After detecting that the user device has logged into the browser authentication page, the first layer of identity authentication information is displayed on the browser authentication page.

[0022] Users can access the H5 page for electronic contract signing and identity authentication via bank SMS links or QR code sharing. The H5 page automatically adapts to iOS / Android devices and displays content correctly on all platforms. The first layer of authentication information instructs users to enter their mobile phone number. Users can enter their complete mobile phone number in the authentication information area displayed on the browser's authentication page. The page automatically masks the middle 6 digits of the mobile phone number and encrypts the complete number using either the national standard SM4 or AES encryption algorithm before transmitting it to the server for identity verification.

[0023] S120. Based on the user equipment's response identity data and response behavior data to the first authentication information, determine whether to send an authentication code to the user equipment; if it is determined to send an authentication code to the user equipment, then after detecting that the user equipment has entered the authentication code, determine whether the user equipment has passed the first authentication based on the user equipment's input behavior data when entering the authentication code.

[0024] The first layer of authentication is used to verify whether the current user operating the user device is the registered user corresponding to the user device.

[0025] The user device's response to the first layer of authentication information: Identity data describes the complete mobile phone number entered by the user. Response behavior data describes the user's actions in obtaining the mobile phone number during the input process, such as a mobile phone number manually entered by the user without any page switching, or a mobile phone number manually entered by the user after switching pages, or a mobile phone number obtained and copied / pasted from other sources (such as contacts, social media, or voice communication) after switching pages.

[0026] In some embodiments, determining whether to send an authentication code to the user equipment based on the user equipment's response identity data and response behavior data to the first authentication information includes: The response identity data of the first-level authentication information is checked for consistency based on the reserved identity data corresponding to the user device. If the response identity data of the first-level authentication information passes the check, behavioral analysis is performed on the response behavior data to identify whether there is an ownership relationship between the user device and the response identity data. If there is an ownership relationship between the user device and the response identity data, it is determined to send an authentication code to the user device. If there is no ownership relationship between the user device and the response identity data, it is determined not to send an authentication code to the user device.

[0027] The user device's registered identity data is the user's registered mobile phone number within the bank. Consistency verification is performed by comparing the registered mobile phone number with the complete mobile phone number entered by the user.

[0028] When performing behavioral analysis on response behavior data, if the response behavior data describes a mobile phone number manually entered by a user without any page switching, then the user device and the response identity data are determined to have an ownership relationship; if the response behavior data describes a mobile phone number obtained and copied / pasted / entered by a user from other places (such as contacts, social software, or voice communication) after page switching, then the user device and the response identity data are determined to have a non-ownership relationship.

[0029] Therefore, by determining whether to send an authentication code to the user device based on whether there is an ownership relationship between the user device and the response identity data, the impersonation or substitution of the user device can be effectively prevented.

[0030] In some embodiments, the method further includes: if it is determined that an authentication code should not be sent to the user device, then sending an authentication prompt message to the user device and locking the browser authentication page.

[0031] The identity authentication prompt message indicates that the user's current mobile phone number has a low affinity with the user's device. After locking the browser authentication page, the current page will be locked, and mobile phone number input will no longer be allowed. The page can only be unlocked by contacting a bank account manager. Additionally, the browser authentication page will also be locked after the user enters the wrong mobile phone number five times consecutively.

[0032] This not only enhances users' trust in account security but also reduces authentication failures caused by misoperation or malicious behavior.

[0033] If the phone number is entered correctly, a verification code will be automatically sent. The front end will encrypt the phone number using a pre-set public key and send it to the server. The server will decrypt the code, verify the validity of the number, and send an SMS verification code. The user will then enter the verification code to complete the phone number ownership verification.

[0034] In some embodiments, determining whether a user device has passed the first layer of authentication based on input behavior data when the user device enters an authentication code includes: Based on the input behavior data when the user device enters the authentication code, it is determined whether the user device and the device receiving the authentication code are the same device; if the user device and the device receiving the authentication code are the same device, it is determined that the user device has passed the first layer of authentication; if the user device and the device receiving the authentication code are not the same device, it is determined that the user device has failed the first layer of authentication.

[0035] The input behavior data when a user device enters an authentication code describes the user's behavior in obtaining the verification code. This could be a verification code obtained from an SMS notification on the user device and manually entered, or a verification code copied and pasted from another source (such as social media or voice communication). If the input behavior data describes a verification code obtained from an SMS notification on the user device and manually entered, then the user device and the device receiving the authentication code are determined to be the same device. If the input behavior data describes a verification code obtained from another source (such as social media or voice communication) and copied / pasted / entered, then the user device and the device receiving the authentication code are determined to be different devices.

[0036] Therefore, by using the input behavior data when the user device enters the authentication code, it is possible to identify whether the user device and the device receiving the authentication code are the same device, ensuring that the operator holds the mobile phone number. This determines the first layer of identity authentication results for the user device, effectively avoiding potential security risks and improving the accuracy and reliability of identity authentication.

[0037] S130. If the user device passes the first authentication, the second authentication information is displayed on the browser authentication page; the user device's real-time response to the second authentication information and the waiting time are used to determine whether the user device has passed the second authentication.

[0038] The second layer of authentication information is used to instruct the current user operating the device to perform liveness authentication. During liveness authentication, the system prompts "Please read the random number displayed on the screen and blink," and then clicks confirm. This accesses the device's camera, calls the getUserMedia method to obtain camera permissions, records a video of the user's actions, and correctly reads the random number displayed in the video, which lasts approximately 1-3 seconds.

[0039] The real-time response behavior of the user device to the second layer of authentication information is the prompt action performed by the user device according to the system requirements, such as "reading aloud the random numbers displayed on the screen and blinking". The response waiting time is the interval between the system issuing the authentication prompt and the user's prompt action. For example, if the system issues the authentication prompt at 10:00 on January 1, 2025, and the user only starts to perform the prompt action at 10:02 on January 1, 2025, the response waiting time is 2 minutes.

[0040] In some embodiments, determining whether the user equipment has passed the second-level authentication based on the user equipment's real-time response behavior to the second-level authentication information and the waiting time for the response includes: Liveness detection is performed based on the real-time response behavior of the user equipment to the second-level authentication information. If the liveness detection is successful, the waiting response time is compared with the preset response time. If the waiting response time is greater than or equal to the preset response time, it is determined that the user equipment has failed the second-level authentication. If the waiting response time is less than the preset response time, it is determined that the user equipment has passed the second-level authentication.

[0041] This involves transmitting the user's real-time responses to a third-party platform (such as Face++'s third-party authentication platform's liveness detection service) for liveness detection. After a successful liveness detection, the system compares the waiting response time with a preset response time to determine if the person performing the liveness authentication is the current user operating the device. If the waiting response time is greater than or equal to the preset response time, it may indicate that a non-current user is temporarily recording the screen, in which case the user's device has failed the second layer of authentication. This effectively avoids the problem of other users performing the liveness detection on behalf of the user.

[0042] In some embodiments, the method further includes sending a liveness detection prompt message to the user equipment if the liveness detection fails, instructing the user equipment to adjust the liveness detection distance and / or the ambient light. For example, it may provide a friendly reminder to the user that the distance should not be too close or too far, and the light should not be too dim, to instruct the user to re-authenticate.

[0043] S140. If the user equipment passes the second layer of authentication, the third layer of authentication information is displayed on the browser authentication page; based on the video frame sequence of the user equipment corresponding to the third layer of authentication information and the waiting shooting time, it is determined whether the user equipment has passed the third layer of authentication.

[0044] The third layer of authentication information is used to indicate whether the current user operating the user equipment is the same user who performed the aforementioned mobile phone number authentication. The video frame sequence of the user equipment corresponding to the third layer of authentication information can be the video frames recorded during the aforementioned liveness authentication process, thereby ensuring that the user authenticated by all three layers is the same person.

[0045] In some embodiments, determining whether the user equipment has passed the third-level authentication based on the video frame sequence corresponding to the third-level authentication information and the waiting time for recording includes: Facial image data is extracted from the video frame sequence corresponding to the third-level authentication information of the user device; and the facial image data is matched with the OCR recognition data of the corresponding identity; if the facial image data matches the OCR recognition data of the corresponding identity, the waiting shooting time is compared with the preset shooting time; if the waiting shooting time is greater than or equal to the preset shooting time, it is determined that the user device has not passed the third-level authentication; if the waiting shooting time is less than the preset shooting time, it is determined that the user device has passed the third-level authentication.

[0046] The OCR recognition data corresponding to the identity is the OCR image of the unique user ID card corresponding to the mobile phone number entered during the first layer of identity authentication. A clear facial image is extracted from the liveness video; a 1:1 facial comparison is performed with the ID photo uploaded by the user or provided by the bank; the comparison result must reach a preset similarity threshold (e.g., ≥95%) to confirm that the facial image data matches the corresponding identity's OCR recognition data. If the comparison fails, a selfie needs to be uploaded again for re-comparison.

[0047] The waiting time for face detection is the interval between the user device receiving the detection instruction and the user entering the detection frame. For example, if the system issues a detection instruction at 10:10 AM on January 1, 2025, and the user only enters the detection frame at 10:12 AM on the same day, the waiting time is 2 minutes. By comparing the waiting time with the preset detection time, the system identifies whether the person undergoing face authentication is the current user operating the device. If the waiting time is greater than or equal to the preset detection time, it may indicate that a face image other than the current user is being used, in which case the user device has failed third-party authentication. This effectively avoids the problem of other users performing face detection on behalf of the user during the face detection process.

[0048] S150. If the user equipment passes the third-party authentication, the user equipment's multi-factor authentication is confirmed to be successful, and the electronic contract is displayed to the user equipment.

[0049] After successful multi-factor authentication, the PDF contract content is displayed, and the user needs to carefully read the contract and check the box to agree to the terms and conditions. The user clicks "Sign" to call the handwritten signature component and draws the signature on the Canvas. The signature image, along with the user's identity information, timestamp, and authentication result hash value, is submitted to the backend service. The platform generates a PDF contract with a digital certificate and returns a download link and a certificate number.

[0050] In addition, the bank's system receives a successful contract signing callback and updates the business status; all process data (encrypted mobile phone number, liveness video, signature file) can be encrypted and stored on a trusted internal server for subsequent auditing or judicial evidence.

[0051] In this embodiment, after detecting that a user device has logged into the browser authentication page, the first layer of authentication information is displayed on the browser authentication page. Based on the user device's response identity data and response behavior data to the first layer of authentication information, it is determined whether to send an authentication code to the user device. If it is determined to send an authentication code to the user device, after detecting that the user device has entered the authentication code, it is determined whether the user device has passed the first layer of authentication based on the user device's input behavior data when entering the authentication code. If the user device has passed the first layer of authentication, the second layer of authentication information is displayed on the browser authentication page. Based on the user device's real-time response behavior and waiting time for the second layer of authentication information, it is determined whether the user device has passed the second layer of authentication. If the user device has passed the second layer of authentication, the third layer of authentication information is displayed on the browser authentication page. Based on the user device's video frame sequence corresponding to the third layer of authentication information and the waiting time for recording, it is determined whether the user device has passed the third layer of authentication. If the user device has passed the third layer of authentication, it is determined that the user device's multi-layer authentication has been successful, and the electronic contract is displayed to the user device. In this way, by performing triple authentication on the user's identity, the security of user information is ensured, and the problems of impersonation and proxy signing of electronic contracts are effectively avoided.

[0052] Figure 2 This is a schematic diagram of the structure of a mobile electronic contract multi-identity authentication device provided in this embodiment. The mobile electronic contract multi-identity authentication device may include: The first display module 210 is used to display the first layer of identity authentication information on the browser authentication page after detecting that the user device has logged into the browser authentication page.

[0053] The first authentication module 220 is used to determine whether to send an authentication code to the user equipment based on the user equipment's response identity data and response behavior data to the first authentication information; if it is determined to send an authentication code to the user equipment, then after detecting that the user equipment has entered the authentication code, it determines whether the user equipment has passed the first authentication based on the user equipment's input behavior data when entering the authentication code.

[0054] The second display module 230 is used to display the second authentication information on the browser authentication page if the user device passes the first authentication.

[0055] The second authentication module 240 is used to determine whether the user equipment has passed the second authentication based on the user equipment's real-time response behavior and the waiting time for the response.

[0056] The third display module 250 is used to display third-level authentication information on the browser authentication page if the user device passes the second-level authentication.

[0057] The third authentication module 260 is used to determine whether the user equipment has passed the third authentication based on the video frame sequence corresponding to the third authentication information and the waiting shooting time.

[0058] The display module 270 is used to determine that the user equipment's multi-factor authentication is successful if the user equipment passes the third-party authentication, and then display the electronic contract to the user equipment.

[0059] In this embodiment, optionally, the first authentication module 220 is specifically used for: The response identity data of the first-level authentication information is checked for consistency based on the reserved identity data corresponding to the user device. If the response identity data of the first-level authentication information passes the check, behavioral analysis is performed on the response behavior data to identify whether there is an ownership relationship between the user device and the response identity data. If there is an ownership relationship between the user device and the response identity data, it is determined to send an authentication code to the user device. If there is no ownership relationship between the user device and the response identity data, it is determined not to send an authentication code to the user device.

[0060] In this embodiment, optionally, a processing module may also be included.

[0061] The processing module is used to send an authentication prompt message to the user device and lock the browser authentication page if it is determined that no authentication code should be sent to the user device.

[0062] In this embodiment, optionally, the first authentication module 220 is specifically used for: Based on the input behavior data when the user device enters the authentication code, it is determined whether the user device and the device receiving the authentication code are the same device; if the user device and the device receiving the authentication code are the same device, it is determined that the user device has passed the first layer of authentication; if the user device and the device receiving the authentication code are not the same device, it is determined that the user device has failed the first layer of authentication.

[0063] In this embodiment, optionally, the second authentication module 240 is specifically used for: Liveness detection is performed based on the real-time response behavior of the user equipment to the second-level authentication information. If the liveness detection is successful, the waiting response time is compared with the preset response time. If the waiting response time is greater than or equal to the preset response time, it is determined that the user equipment has failed the second-level authentication. If the waiting response time is less than the preset response time, it is determined that the user equipment has passed the second-level authentication.

[0064] In this embodiment, optionally, the second authentication module 240 is specifically used for: If the liveness detection fails, a liveness detection prompt message is sent to the user equipment to instruct the user equipment to adjust the liveness detection distance and / or the ambient light.

[0065] In this embodiment, optionally, the third authentication module 260 is specifically used for: Facial image data is extracted from the video frame sequence corresponding to the third-level authentication information of the user device; and the facial image data is matched with the OCR recognition data of the corresponding identity; if the facial image data matches the OCR recognition data of the corresponding identity, the waiting shooting time is compared with the preset shooting time; if the waiting shooting time is greater than or equal to the preset shooting time, it is determined that the user device has not passed the third-level authentication; if the waiting shooting time is less than the preset shooting time, it is determined that the user device has passed the third-level authentication.

[0066] The mobile electronic contract multi-identity authentication device provided in this disclosure can execute the above-described method embodiments. Its specific implementation principle and technical effects can be found in the above-described method embodiments, and will not be repeated here.

[0067] This application also provides a computer device. Please refer to the following for details. Figure 3 , Figure 3 This is a basic structural block diagram of the computer device in this embodiment.

[0068] The computer device includes a memory 310 and a processor 320 that are interconnected via a system bus. It should be noted that only a computer device with memory 310 and processor 320 is shown in the figure; however, it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented alternatively. Those skilled in the art will understand that the computer device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0069] Computer devices can include desktop computers, laptops, handheld computers, and cloud servers. These devices allow for human-computer interaction with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0070] The memory 310 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. RAM may include static RAM or dynamic RAM. In some embodiments, the memory 310 may be an internal storage unit of a computer device, such as the hard disk or memory of the computer device. In other embodiments, the memory 310 may also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, or flash card equipped on the computer device. Of course, the memory 310 may include both internal storage units and external storage devices of the computer device. In this embodiment, the memory 310 is typically used to store the operating system and various application software installed on the computer device, such as the program code of the method described above. In addition, the memory 310 can also be used to temporarily store various types of data that have been output or will be output.

[0071] Processor 320 is typically used to perform overall operations of a computer device. In this embodiment, memory 310 is used to store program code or instructions, including computer operation instructions, and processor 320 is used to execute the program code or instructions stored in memory 310 or process data, such as program code that runs the methods described above.

[0072] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus system can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0073] Another embodiment of this application also provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads computer-readable program code stored in the computer-readable medium, enabling the processor to execute the functional actions specified in each step or combination of steps in the above method; and to generate means for implementing the functional actions specified in each block or combination of blocks in the block diagram.

[0074] Computer-readable media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any suitable combination thereof, wherein the memory is used to store program code or instructions, the program code including computer operation instructions, and the processor is used to execute the program code or instructions of the above-described methods stored in the memory.

[0075] The definitions of memory and processor can be found in the description of the foregoing computer device embodiments, and will not be repeated here.

[0076] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0077] In the various embodiments of this application, the functional units or modules can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0078] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0079] In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" as described in this application does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. This application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims listing several means, several units of these means may be embodied by the same item of hardware. The use of "first," "second," and "third," etc., does not indicate any order and these words should be interpreted as names. Unless otherwise specified, the steps in the above embodiments should not be construed as limiting the order of execution.

[0080] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for multi-factor authentication of electronic contracts on a mobile device, characterized in that, include: After detecting that the user device has logged into the browser authentication page, the first layer of identity authentication information is displayed on the browser authentication page; Based on the user equipment's response identity data and response behavior data to the first authentication information, it is determined whether to send an authentication code to the user equipment; if it is determined to send an authentication code to the user equipment, then after detecting that the user equipment has entered the authentication code, it is determined whether the user equipment has passed the first authentication based on the user equipment's input behavior data when entering the authentication code. If the user equipment passes the first authentication, the second authentication information is displayed on the browser authentication page; Based on the real-time response behavior and response waiting time of the user equipment in response to the second authentication information, it is determined whether the user equipment has passed the second authentication. If the user equipment passes the second authentication, the third authentication information is displayed on the browser authentication page; Based on the video frame sequence of the user equipment corresponding to the third-level authentication information and the waiting time for shooting, it is determined whether the user equipment has passed the third-level authentication. If the user equipment passes the third authentication, the multi-factor authentication of the user equipment is determined to be successful, and the electronic contract is displayed to the user equipment.

2. The method according to claim 1, characterized in that, The step of determining whether to send an authentication code to the user equipment based on the user equipment's response identity data and response behavior data to the first authentication information includes: The consistency of the response identity data of the first identity authentication information is verified based on the reserved identity data corresponding to the user equipment. If the response identity data of the first authentication information passes the verification, then the response behavior data is analyzed to identify whether there is an ownership relationship between the user device and the response identity data. If the user equipment and the response identity data have an ownership relationship, then it is determined that an authentication code will be sent to the user equipment; if the user equipment and the response identity data do not have an ownership relationship, then it is determined that an authentication code will not be sent to the user equipment.

3. The method according to claim 2, characterized in that, Also includes: If it is determined that no authentication code will be sent to the user device, then an authentication prompt message will be sent to the user device, and the browser authentication page will be locked.

4. The method according to claim 1, characterized in that, The step of determining whether the user equipment has passed the first level of authentication based on the input behavior data when the user equipment inputs the authentication code includes: Based on the input behavior data when the user equipment inputs the authentication code, identify whether the user equipment and the receiving device of the authentication code are the same device; If the user equipment and the device receiving the authentication code are the same device, then the user equipment is determined to have passed the first layer of authentication; if the user equipment and the device receiving the authentication code are not the same device, then the user equipment is determined to have failed the first layer of authentication.

5. The method according to claim 1, characterized in that, The step of determining whether the user equipment has passed the second authentication based on the user equipment's real-time response behavior and response waiting time in response to the second authentication information includes: Liveness detection is performed based on the real-time response behavior of the user equipment to the second authentication information; if the liveness detection is successful, the waiting response time is compared with the preset response time. If the waiting response time is greater than or equal to the preset response time, it is determined that the user equipment has failed the second authentication; if the waiting response time is less than the preset response time, it is determined that the user equipment has passed the second authentication.

6. The method according to claim 5, characterized in that, Also includes: If the liveness detection fails, a liveness detection prompt message is sent to the user equipment to instruct the user equipment to adjust the liveness detection distance and / or the ambient light.

7. The method according to claim 1, characterized in that, The step of determining whether the user equipment has passed the third-level authentication based on the video frame sequence corresponding to the third-level authentication information and the waiting time for shooting includes: Facial image data is extracted from the video frame sequence of the user equipment corresponding to the third-level identity authentication information; and the facial image data is matched with the OCR recognition data of the corresponding identity. If the facial image data matches the corresponding identity's OCR recognition data, then the waiting time for shooting is compared with the preset shooting time. If the waiting time for shooting is greater than or equal to the preset shooting time, it is determined that the user equipment has failed the third-party authentication; if the waiting time for shooting is less than the preset shooting time, it is determined that the user equipment has passed the third-party authentication.

8. A mobile-based electronic contract multi-identity authentication device, characterized in that, include: The first display module is used to display the first layer of identity authentication information on the browser authentication page after detecting that the user device has logged into the browser authentication page; The first authentication module is used to determine whether to send an authentication code to the user equipment based on the user equipment's response identity data and response behavior data to the first authentication information; if it is determined to send an authentication code to the user equipment, then after detecting that the user equipment has entered the authentication code, it determines whether the user equipment has passed the first authentication based on the user equipment's input behavior data when entering the authentication code. The second display module is used to display second authentication information on the browser authentication page if the user equipment passes the first authentication. The second authentication module is used to determine whether the user equipment has passed the second authentication based on the real-time response behavior and waiting time of the user equipment in response to the second authentication information. The third display module is used to display third-level authentication information on the browser authentication page if the user equipment passes the second-level authentication. The third authentication module is used to determine whether the user equipment has passed the third authentication based on the video frame sequence corresponding to the third authentication information and the waiting shooting time. The display module is used to determine that the user equipment's multi-factor authentication is successful if the user equipment passes the third-level authentication, and then display the electronic contract to the user equipment.

9. A computer device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the electronic contract multi-identity authentication method for mobile terminals as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When a computer program is executed by a processor, it implements the multi-identity authentication method for electronic contracts on a mobile terminal as described in any one of claims 1 to 7.