Identity authentication method, device, equipment, medium and program product

By reading the encrypted text of ID cards and extracting anti-counterfeiting features on mobile devices, and combining electronic and physical authentication for dual verification, the system solves the security deficiencies of existing identity authentication methods, achieving higher accuracy and security in identity authentication.

CN121585433APending Publication Date: 2026-02-27CHINA CONSTRUCTION BANK +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511764060.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing mobile authentication methods have security deficiencies, including the ease with which passwords can be guessed, the risk of mismatched biometric identification, the ease with which SMS verification codes can be intercepted, and the difficulty of identifying invalid documents with built-in cloned chips or physical counterfeits using a single verification method.

Method used

By calling the near-field communication module of the mobile terminal to read the encrypted text of the ID card, and combining it with the camera module to obtain the image information of the ID card, the anti-counterfeiting features are extracted using a pre-trained feature extraction model and sent to the verification server for verification, thus forming a dual protection of electronic authentication and physical authentication.

Benefits of technology

It improves the accuracy and security of identity authentication, effectively prevents invalid documents with built-in copying chips or physical high-quality forgeries, and enhances the security of business transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121585433A_ABST
    Figure CN121585433A_ABST
Patent Text Reader

Abstract

The invention provides an identity authentication method and device, equipment, a medium and a program product, which can be applied to the technical field of security authentication and artificial intelligence. The method comprises the following steps: calling a near field communication module of a mobile terminal of a target client, reading a certificate ciphertext of an identity certificate of the target client, and sending the certificate ciphertext to an empirical server for verification; calling a camera module of the mobile terminal to obtain image information of the identity document, inputting a pre-trained feature extraction model to output anti-counterfeiting features, and sending the anti-counterfeiting features to an anti-counterfeiting verification server for verification; wherein the feature extraction model is obtained according to training of an identity document sample, and the identity document sample is marked with at least one item of optically variable ink, a directional photochromic film or micro characters; responding to the received certificate ciphertext and the anti-counterfeiting feature verification passing result, and confirming that the identity certificate is true and effective; the verification result of the identity document is used as a basis for identity authentication when the target customer handles the business.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security authentication and artificial intelligence, and in particular to an identity authentication method, device, equipment, medium and program product. BACKGROUND

[0002] With the acceleration of the online and mobile trend of banking business, the importance of real-name authentication of mobile customers is increasingly prominent, and at the same time, it also puts forward higher requirements on banks in protecting user information security and preventing abnormal transactions.

[0003] At present, the main identity authentication methods of mobile terminals are: 1. password; 2. biometric features such as fingerprint, voiceprint, face recognition and live body detection; 3. SMS verification code. Although the password authentication of method 1 is a widely used and relatively simple method, it is not very secure due to problems such as easy to guess, forget and static; although the biometric feature recognition technology of method 2 has the advantages of high precision and high efficiency, it also has problems such as personal non-avoidable copying, certain probability of false matching and false rejection; although the SMS verification code of method 3 is simple and low-cost, it also has many shortcomings, such as the risk of interception of the plaintext sent verification code, easy to be induced to input, the sending arrival rate is not 100% or be mistaken for spam SMS, the risk of user changing mobile phone number, etc.

[0004] Generally, one or more of the above methods are combined to authenticate the user. Therefore, the existing identity authentication method needs to be improved. SUMMARY

[0005] In view of the above problems, the present application provides an identity authentication method, device, equipment, medium and program product.

[0006] According to a first aspect of the present application, an identity authentication method is provided, comprising: calling a near field communication module of a mobile terminal of a target customer, reading a certificate ciphertext of an identity certificate of the target customer, and sending the certificate ciphertext to a real certificate server for verification; calling a camera module of the mobile terminal, obtaining image information of the identity certificate, inputting a pre-trained feature extraction model to output an anti-fake feature, and sending the anti-fake feature to an anti-fake verification server for verification; wherein the feature extraction model is obtained according to an identity certificate sample, and the identity certificate sample is labeled with at least one of optically variable ink, directional optically variable film or microtext; in response to receiving the results of the certificate ciphertext and the anti-fake feature verification passing, confirming that the identity certificate is real and valid; and the verification result of the identity certificate is used as the basis for identity authentication when the target customer handles business.

[0007] According to an embodiment of the present application, the method further comprises: sending the identity information of the target customer pre-stored on the business application server side to the real evidence server for verification; and in response to receiving a result returned by the real evidence server that the identity information is consistent with the reading information of the certificate ciphertext, approving the business handling operation of the target customer on the mobile terminal.

[0008] According to an embodiment of the present application, the method further comprises: obtaining a risk checking item of the mobile terminal, wherein the risk checking item comprises at least one of a device feature, an environment feature, a behavior feature, or an operation risk feature, the device feature reflecting the trustworthiness of the mobile terminal device, the environment feature reflecting the environment safety degree of the mobile terminal, the behavior feature reflecting whether the operation industry of the target customer on the mobile terminal is abnormal, and the operation risk feature reflecting the risk degree of the business handled by the target customer; determining a score and a corresponding risk level of the mobile terminal according to the risk checking item and a preset score and level rule; and determining an authentication mode to be performed on the target customer according to a preset mapping relationship between the risk level and the authentication mode, the authentication mode comprising at least one of an identity certificate verification, an SMS verification code, a biological feature, a static password, or a live body authentication, and the authentication mode being used to authenticate the identity of the target customer during the business handling.

[0009] According to an embodiment of the present application, the image information of the identity certificate is obtained, and the image information is processed by using a pre-trained feature extraction model to obtain an anti-forgery feature, comprising: obtaining image information of the identity certificate taken at at least two different angles; processing the image information by using the pre-trained feature extraction model to extract color values of the optically variable ink and / or the directional optically variable film of the identity certificate at different angles; and obtaining the anti-forgery feature according to the different angles and the color values.

[0010] According to an embodiment of the present application, the image information of the identity certificate is obtained, and the image information is processed by using a pre-trained feature extraction model to obtain an anti-forgery feature, comprising: intercepting image information in a pre-defined coordinate range to obtain a micro-text area; calculating a gray value variance of the micro-text area and / or a size of the micro-text; and obtaining an anti-forgery feature of the micro-text according to the gray value variance and / or the size of the micro-text.

[0011] According to an embodiment of the present application, the method further comprises: sending the certificate ciphertext to the real evidence server to obtain a return result of the identity certificate version from the real evidence server; determining one target feature extraction model from N pre-trained candidate feature extraction models according to the return result of the identity certificate version and a mapping relationship with the feature extraction model, N being an integer greater than or equal to 2; and processing the image information by using the target feature extraction model.

[0012] According to an embodiment of the present application, image information of an identity certificate is acquired, and the image information is processed by using a pre-trained feature extraction model, including: performing optical character recognition on the image information of the identity certificate; determining a version of the identity certificate according to a recognition result of the optical character recognition; determining one target feature extraction model from N pre-trained candidate feature extraction models according to a mapping relationship between the version of the identity certificate and the feature extraction model, N being an integer greater than or equal to 2; and processing the image information by using the target feature extraction model.

[0013] A second aspect of the present application provides an identity authentication device, including: a certificate ciphertext reading module configured to call a near field communication module of a mobile terminal of a target customer, read certificate ciphertext of an identity certificate of the target customer, and send the certificate ciphertext to a real certificate server for verification; a forgery-proof feature extraction module configured to call a camera module of the mobile terminal, acquire image information of the identity certificate, input a pre-trained feature extraction model to output a forgery-proof feature, and send the forgery-proof feature to a forgery-proof verification server for verification; wherein the feature extraction model is obtained by training according to identity certificate samples, and the identity certificate samples are labeled with at least one of optically variable ink, directional optically variable film or microtext; and a verification result confirmation module configured to confirm that the identity certificate is real and valid in response to receiving a result that the certificate ciphertext and the forgery-proof feature pass verification; and a verification result of the identity certificate is used as a basis for identity authentication when the target customer handles a business.

[0014] A third aspect of the present application provides an electronic device, including: one or more processors; a memory configured to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the above method.

[0015] A fourth aspect of the present application further provides a computer-readable storage medium having stored executable instructions, which, when executed by a processor, cause the processor to perform the above method.

[0016] A fifth aspect of the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements the above method.

[0017] According to the identity authentication method, device, equipment, medium and program product provided in the application, the identity document ciphertext is read by the near field communication module and sent to the real evidence server for verification, the camera module is called to obtain the identity document image information, the anti-fake feature is output by inputting the pre-trained feature extraction model, and the anti-fake verification server is sent for verification. When both of them pass, it is confirmed that the identity document is real and valid. Since the scheme combines digital verification of the identity document electronic ciphertext and image verification of the physical anti-fake feature, and the feature extraction model can accurately identify the key anti-fake feature, forming double protection of electronic authentication and physical authentication, therefore, at least part of the problem of single verification mode being difficult to identify invalid certificates with built-in copied chips or physical high imitation is solved, the technical effect of improving the identity authentication accuracy and security and effectively guaranteeing the identity authenticity in business handling is realized. BRIEF DESCRIPTION OF DRAWINGS

[0018] The above and other objects, features and advantages of the present application will become more apparent from the following description of embodiments of the present application, taken in conjunction with the accompanying drawings, in which:

[0019] Figure 1 An application scenario diagram of the identity authentication method, device, equipment, medium and program product according to the embodiments of the present application is schematically shown;

[0020] Figure 2 A flowchart of the identity authentication method according to the embodiments of the present application is schematically shown;

[0021] Figure 3 A flowchart of the second identity authentication method according to the embodiments of the present application is schematically shown;

[0022] Figure 4 A flowchart of the risk level authentication according to the embodiments of the present application is schematically shown;

[0023] Figure 5 A flowchart of obtaining the anti-fake feature according to the color value according to the embodiments of the present application is schematically shown;

[0024] Figure 6 A flowchart of selecting the feature extraction model according to the return result of the real evidence server according to the embodiments of the present application is schematically shown;

[0025] Figure 7 A structural block diagram of the identity authentication device according to the embodiments of the present application is schematically shown; and

[0026] Figure 8 A block diagram of an electronic device suitable for implementing the identity authentication method according to the embodiments of the present application is schematically shown. DETAILED DESCRIPTION

[0027] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. It is to be understood, however, that the description is merely exemplary of the present application, and is not intended to limit the scope of the present application. In the following detailed description of the embodiments of the present application, numerous specific details are set forth in order to provide a thorough understanding of the present application. However, it will be apparent to one skilled in the art that the present application can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring aspects of the present application.

[0028] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. As used herein, the term "comprising" or "comprises" or "including" or "includes" or "containing" or "contains" or "has" or "having" or the like is used to indicate the presence of stated features, steps, operations, and / or components, but does not preclude the presence or addition of one or more other features, steps, operations, or components.

[0029] All terms used herein, including technical and scientific terms, have the meanings commonly understood by one of ordinary skill in the art unless otherwise defined herein. It should be noted that the terms used herein are defined as having meanings that are consistent with the context of the specification in which the terms are used and should not be interpreted in an overly idealized or overly formal way.

[0030] In the case of using expressions similar to "at least one of A, B, and C, etc.", it is generally to be interpreted as including one or more of the items enumerated in the list (e.g., "a system having at least one of A, B, and C" should be interpreted to include a system having A alone, a system having B alone, a system having C alone, a system having both A and B together, a system having both A and C together, a system having both B and C together, and / or a system having all of A, B, and C together, etc.).

[0031] It should be noted that in the embodiments of the present application, some software, components, models, etc. of the prior art can be mentioned, which should be considered as exemplary, and the purpose is only to illustrate the feasibility in the implementation of the technical solutions of the present application, but it does not mean that the applicant has or will necessarily use the scheme.

[0032] In the technical solutions of the present application, the collection, storage, use, processing, transmission, provision, application and use of user personal information comply with the relevant legal regulations, necessary security measures are taken, and do not violate public order and good customs.

[0033] In the technical solutions of the present application, the acquisition, collection, storage, use, processing, transmission, provision, application and use of data comply with the relevant legal regulations, necessary security measures are taken, and do not violate public order and good customs.

[0034] The general process of the authentication method of the bank mobile APP (Chinese: application, English: Application) is as follows: the user logs in the APP, and when the user enters the high-risk business interface, the user is prompted to perform one or more combinations of static password, SMS verification code, and biometric identification. Most of the transaction scenarios only use the above authentication methods, and a small number of banks will issue a dynamic password token for high-risk businesses such as large amount transfer. After inputting the dynamic password on the token, the user can continue to execute, in order to improve security.

[0035] Although one or more combinations of static password, SMS verification code, and biometric identification can meet most ordinary business scenarios, they are not sufficient for high-risk scenarios such as large amount transfer. For example, face recognition may be attacked by masks or headsets, leading to false recognition, and SMS verification code may be intercepted.

[0036] The above-mentioned authentication methods can be completed on a mobile phone terminal without the participation of external entity hardware. Although it has high convenience, it also increases the security risk of the account after the mobile phone is lost.

[0037] Some banks have added the measure of inputting dynamic passwords in such high-risk scenarios. Since each dynamic password is used only once, and the dynamic password token is completely physically isolated from the mobile phone, it is difficult to be imitated or attacked through the mobile phone, and the security has been significantly improved. However, the dynamic password token needs to be carried with the user, and there is a risk of loss or damage, which affects the user experience. In addition, compared with other authentication methods such as static password, biometric identification, and verification code, the dynamic password token requires additional hardware, which may significantly increase the user's use cost and the bank's management cost.

[0038] Embodiments of the present application provide an identity authentication method, which introduces reading and authentication of entity identity documents in the authentication process of the business, which can greatly improve the security of risk business operations. Based on the NFC (Chinese: near field communication technology, English: Near Field Communication) reading capability commonly possessed by mobile phones at present, the user's identity document ciphertext is read, and the ciphertext information of the document is decoded by the server and compared with the identity information of the account to realize the real authentication of the user. The security of the authentication is enhanced based on the verification of the anti-fake identification extraction features of the identity document. The entity identity document issued by the authority has universality, high security, and privacy, which can effectively confirm that the current user is the holder of the entity document. Compared with relying entirely on the authentication on the mobile phone terminal, the security is improved without significantly increasing the convenience of the user.

[0039] Figure 1 The application scenario of the identity authentication method, device, equipment, medium, and program product according to the embodiments of the present application is schematically shown.

[0040] As Figure 1 shown, the application scenario 100 according to this embodiment can include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links, or fiber optic cables, and the like.

[0041] A user can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, and the like. Various communication client applications can be installed on the terminal devices 101, 102, 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, and the like (only as examples).

[0042] The terminal devices 101, 102, 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smartphones, tablet computers, laptop computers, desktop computers, and the like.

[0043] The server 105 can be a server providing various services, such as a background management server providing support for websites browsed by users using the terminal devices 101, 102, 103 (only as an example). The background management server can analyze and process received user requests and the like, and feed back the processing results (such as web pages, information, or data, and the like obtained or generated according to user requests) to the terminal devices.

[0044] It should be noted that the identity authentication method provided by the embodiments of the present application can generally be executed by the server 105. Correspondingly, the identity authentication apparatus provided by the embodiments of the present application can generally be arranged in the server 105. The identity authentication method provided by the embodiments of the present application can also be executed by a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105. Correspondingly, the identity authentication method provided by the embodiments of the present application can also be arranged in a server or a server cluster different from the server 105 and capable of communicating with the terminal devices 101, 102, 103 and / or the server 105.

[0045] It should be understood that Figure 1 the number of terminal devices, networks, and servers in

[0046] The following will be described based on Figure 1 the scenario described in the foregoing embodiments, through Figures 2-6The identity authentication method of the application embodiment is described in detail.

[0047] Figure 2 A flowchart of the identity authentication method according to the application embodiment is schematically shown.

[0048] As shown in Figure 2 The identity authentication method of the embodiment includes operations S210-S230.

[0049] In operation S210, the near field communication module of the mobile terminal of the target customer is called, the certificate ciphertext of the identity certificate of the target customer is read, and the certificate ciphertext is sent to the real certificate server for verification.

[0050] This operation verifies whether the digital information of the identity certificate is legal through the chip built-in the identity certificate. Specifically, the bank APP of the mobile terminal calls the NFC hardware function of the mobile phone through SDK (Chinese: Software Development Kit, English: Software Development Kit), and the NFC module establishes near field communication with the chip built-in the identity certificate.

[0051] The identity certificate is issued by an authoritative organ and stores the personal information of the certificate holder. The electronic ciphertext stored in the chip of the identity certificate can be transmitted to the mobile terminal SDK through NFC. The mobile terminal SDK can transmit the electronic ciphertext to the real certificate server, and the real certificate server is an authorized identity certificate verification platform, which can decrypt the electronic ciphertext and verify whether the decrypted information conforms to the coding rules of the identity certificate.

[0052] In operation S220, the camera module of the mobile terminal is called to obtain the image information of the identity certificate, the anti-fake feature is output by inputting the pre-trained feature extraction model, and the anti-fake feature is sent to the anti-fake verification server for verification.

[0053] This operation avoids copying the certificate chip by collecting the physical anti-fake features of the identity certificate, and verifies the authenticity of the identity certificate from the physical point of view.

[0054] This operation can call the mobile phone camera on the mobile terminal to shoot the front and back images of the identity certificate. The image needs to include the anti-fake area, such as the light-changing ink seal on the front, the directional light-changing color film and micro-text on the back, etc.

[0055] The shot image is input into the pre-trained feature extraction model to extract the anti-fake feature. The feature extraction model can be a lightweight neural network deployed on the mobile terminal, which extracts image features through layers such as depth separable convolution, linear bottleneck, attention mechanism and activation function, etc. By deploying a lightweight neural network on the mobile terminal, the original image can be destroyed locally immediately after extraction, and only the obtained feature vector is retained to prevent sensitive data from being left behind.

[0056] The color of the real certificate changes obviously, and the color of the abnormal certificate changes weakly or not. For the light-changing ink, the color difference value at 0° to 45° angle can be extracted. The pattern of the real certificate is clear, and the pattern of the abnormal certificate is blurred or missing. For the directional light-changing color film, the integrity of the holographic pattern at a specific angle can be extracted. The text of the real certificate is clear and continuous, and the text of the abnormal certificate is easy to break, the size is out of standard, and not clear. For the micro-text, the clarity, stroke continuity or size of the text can be analyzed to determine whether it is in compliance.

[0057] The feature extraction model outputs the quantitative anti-counterfeiting features, for example: light-changing ink color difference value = 35, micro-text continuity rate = 98%. The anti-counterfeiting features are transmitted to the anti-counterfeiting verification server, and the anti-counterfeiting verification server can compare the anti-counterfeiting features with the real certificate anti-counterfeiting feature library to determine whether they meet the standard of the real certificate.

[0058] The feature extraction model is trained according to the identity certificate sample, and the identity certificate sample is labeled with at least one of the light-changing ink, the directional light-changing color film or the micro-text.

[0059] In operation S230, in response to receiving the certificate ciphertext and the result of passing the anti-counterfeiting feature verification, it is confirmed that the identity certificate is real and valid; the verification result of the identity certificate is used as the basis for identity authentication when the target customer handles the business.

[0060] The server of the mobile APP (such as the bank backend) receives the ciphertext verification result from the real certificate service server and the physical anti-counterfeiting pass result from the anti-counterfeiting verification server, and determines whether the identity certificate is real and valid. After passing the verification, the mobile APP associates the result to the user's business application, completes the identity authentication link, and allows the user to continue to handle the subsequent business process. Using NFC certificate reading to authenticate the identity of the customer can significantly improve the security of analyzing business handling, while not reducing the user experience.

[0061] In this embodiment, the near field communication module reads the certificate ciphertext of the identity certificate and sends it to the real certificate service server for verification, the camera module is called to obtain the image information of the identity certificate, the feature extraction model is inputted to output the anti-counterfeiting features, and the anti-counterfeiting verification server is sent for verification. When both of them pass the verification, it is confirmed that the identity certificate is real and valid. Since this scheme combines digital verification of the electronic ciphertext of the identity certificate and image verification of the physical anti-counterfeiting features, and the feature extraction model can accurately identify the key anti-counterfeiting features, forming double protection of electronic authentication and physical authentication, therefore, at least part of the problem of invalid certificate with built-in copied chip or physical high imitation which is difficult to identify by single verification method is solved, the technical effect of improving the accuracy and security of identity authentication and effectively protecting the identity authenticity in business handling is realized.

[0062] In some embodiments of the present application, the method further comprises: sending the target customer's pre-stored identity information on the business application server side to the real evidence server for verification; and in response to receiving a result returned by the real evidence server that the identity information is consistent with the reading information of the certificate ciphertext, approving the target customer's business handling operation on the mobile terminal.

[0063] Figure 3 A flowchart of a second identity authentication method according to an embodiment of the present application is schematically shown.

[0064] As shown in Figure 3 , at the beginning of the present embodiment, the mobile terminal APP enters the NFC reading interface. The operation mode is prompted, such as prompting the user to take out the identity certificate and place it in the designated position, and prompting the user to be ready and then click Start Reading. The NFC reading SDK calls the NFC reading identity certificate of the mobile phone. After the SDK reads the certificate ciphertext, it is sent to the NFC real evidence server for decoding.

[0065] Preferably, the rear camera of the mobile phone is called to guide the user to take pictures of the front and back of the identity certificate. The mobile terminal APP inputs the front and back images of the identity certificate into the pre-trained feature extraction model to output the anti-fake features, and sends the anti-fake features to the anti-fake verification server for verification.

[0066] The NFC real evidence server decodes the certificate ciphertext and returns the reading result success or not. The anti-fake verification server compares the anti-fake features with the real certificate anti-fake feature library to determine whether they meet the standard of the real certificate.

[0067] If the results of the certificate ciphertext and the anti-fake feature verification are passed, the identity certificate is confirmed to be real and valid. The business application server sends the pre-stored customer identity information to be verified to the NFC real evidence server for verification, and obtains the result of whether the pre-stored information is consistent with the reading information.

[0068] According to the verification result, the next step is continued, and the process is ended.

[0069] In the present embodiment, the target customer's identity information pre-stored by the business application server is trusted and has no tampering risk, and it is sent to the real evidence server for accurate comparison with the reading information of the certificate ciphertext, which can eliminate the problem of identity impersonation caused by tampering of the mobile terminal information from the source, and finally realize the safe and compliant business handling of the target customer on the mobile terminal.

[0070] In some embodiments of the present application, the method further comprises: obtaining a risk inspection item of the mobile terminal, wherein the risk inspection item comprises at least one of a device feature, an environment feature, a behavior feature, or an operation risk feature, the device feature reflects the trustworthiness of the mobile terminal device, the environment feature reflects the environmental safety degree of the mobile terminal, the behavior feature reflects whether the operation industry of the target customer on the mobile terminal is abnormal, and the operation risk feature reflects the risk degree of the business handled by the target customer; determining the score of the mobile terminal and the corresponding risk level according to the risk inspection item and a preset score and level rule; and determining the authentication mode performed on the target customer according to a preset mapping relationship between the risk level and the authentication mode, the authentication mode comprising at least one of identity document verification, and short message verification code, biometric feature, static password, or living body authentication, and the authentication mode being used to authenticate the identity of the target customer when the business is handled.

[0071] The embodiment discards the method of issuing security authentication hardware by the bank for the risk transaction of the mobile terminal, such as large amount of transfer and modification of key security information, and introduces the reading of the identity document and the face living body detection and recognition. Before the operation in the risk scene, the NFC function on the mobile terminal is used to read the identity document ciphertext information of the user, which is decoded by the server. After the decoding by the server, the identity information reserved by the customer is checked to confirm that the identity document is consistent with the customer. The face living body detection and recognition is performed on the customer to confirm that the current operator is matched with the face information on the identity document, thereby confirming the consistency of the current operator and the customer to which the current account belongs.

[0072] Figure 4 A flowchart of authentication according to a risk level is schematically shown according to the embodiment of the present application.

[0073] As shown in Figure 4 , the flow starts when the user handles the business on the mobile terminal APP; the mobile terminal is monitored for risk, and the risk level is determined according to the device, environment, account daily behavior mode, and operation risk.

[0074] The device feature is used to determine whether the mobile terminal used by the user is a safe and commonly used device, to avoid logging in by a strange device, such as whether the device is in the developer mode, whether the device is in the blacklist, and the like. The environment feature is used to determine whether the network, time, and place operated by the user are consistent with the daily habits, to avoid operation in a risk environment. The behavior feature can be used to determine whether the operation path and transaction object of the user are consistent with the historical habits, to avoid non-personal operation. The operation risk feature is used to determine whether the business handled by the user is self-brought with high risk factors, such as large amount of transfer and modification of mobile phone number.

[0075] According to the risk level, one or more modes are selected from the authentication tool library to authenticate the customer. The optional authentication modes include short message verification code, biometric feature, static password, NFC reading of the identity document, and living body authentication, and the like.

[0076] For example, a Z user transfers 800,000 yuan through a bank APP. Device feature aspect: Z user has only logged in with mobile phone A in the past three months, and still uses mobile phone A this time; mobile phone A has not been opened in developer mode, and there is no abnormal transaction association record. Environmental feature aspect: Z user logs in to the bank APP at 2 a.m. this time. Behavior feature aspect: The recipient this time is a foreign account; Z user is used to checking the balance before transferring, and this time directly skips the balance check and directly transfers a large amount. Operation risk feature aspect: 800,000 yuan transfer is a large amount of high-risk business.

[0077] The preset score rule is: total score = device feature score + environmental feature score + behavior feature score + operation risk feature score. The preset risk level and authentication mode mapping is shown in Table 1.

[0078] Table 1. Preset risk level and authentication mode mapping table

[0079]

[0080] Suppose that according to the preset rule, Z user's operation score this time is 110 points = 0 + 35 + 30 + 45. Since the risk is extremely high, the authentication mode of "ID card NFC + physical anti-fraud verification + biometric + payment password" is performed for Z user's operation this time. After authentication, the relevant operation is performed and the process ends.

[0081] Combining NFC authentication, biometric authentication, and static password authentication can ensure the security and accuracy of identity authentication. Among them: 1. NFC authentication belongs to "I have"; 2. Biometric authentication belongs to "I am"; 3. Static password authentication belongs to "I know". The combination of the above three elements can determine the consistency of the current operation user and the legal user with a high probability, and ensure the security of the transaction and operation.

[0082] This embodiment first checks the mobile terminal through multi-dimensional risk check items covering device, environment security, operation behavior, and business risk; determines the risk level of the mobile terminal through the preset score and level rule, and matches the authentication mode based on the risk level, to avoid excessive authentication in low-risk scenarios and provide security for high-risk scenarios, thereby realizing risk adaptation and taking into account user experience.

[0083] In some embodiments of the present application, the image information of the identity certificate is obtained; and the image information is processed by using a pre-trained feature extraction model to obtain an anti-forgery feature, including: obtaining image information of the identity certificate taken at at least two different angles; processing the image information by using a pre-trained feature extraction model to extract color values of the optically variable ink and / or the directional optically variable film of the identity certificate at different angles; and obtaining the anti-forgery feature according to the different angles and the color values.

[0084] Figure 5 A flowchart illustrating the process of obtaining anti-counterfeiting features based on color values ​​according to an embodiment of this application is shown.

[0085] like Figure 5 As shown, in this embodiment, images of the optically variable ink area on the ID card are acquired from multiple different angles. The acquired images include first angle image information, second angle image information, etc. The multiple different angles can be 2, 3, 4 or more angles.

[0086] By using a pre-trained feature extraction model to analyze image information from the first angle and the second angle, the color features of the photochromic ink under different angles are extracted.

[0087] Since the color change curves corresponding to different angles have a fixed pattern, the anti-counterfeiting features based on the color changes at different angles can be used to determine whether the document is genuine.

[0088] This embodiment acquires image information by shooting from multiple angles and captures the color changes of the anti-counterfeiting mark; then, it uses a pre-trained feature extraction model to obtain color values ​​from different angles, and combines the anti-counterfeiting features formed by the angle dimension and color values ​​to build a more comprehensive security barrier. At the same time, the model can be lightweight and adapted to mobile devices, achieving efficient verification without increasing the user's operational burden.

[0089] In some embodiments of this application, image information of an identity document is obtained; and the image information is processed using a pre-trained feature extraction model to obtain anti-counterfeiting features, including: cropping image information within a predefined coordinate range to obtain a microtext region; calculating the grayscale variance of the microtext region and / or the size of the microtext; and obtaining the anti-counterfeiting features of the microtext based on the grayscale variance and / or the size of the microtext.

[0090] For ID cards with a defined version, the position of the microtext is fixed. Only a fixed area needs to be cropped, eliminating the need to analyze the entire ID card image, thus reducing computational load. The cropping method can be implemented on mobile devices by using image edge detection to automatically calibrate the image ratio, and then cropping the microtext area according to predefined pixel coordinates, eliminating interference from other areas of the ID card.

[0091] Gray-level variance is the degree to which the gray-level values ​​of pixels in an image deviate from the average value. The larger the value, the stronger the contrast between strokes and background; the smaller the value, the blurrier the image. The gray-level variance is obtained by calculating the average of the squared deviations of the gray-level value of each pixel from μ.

[0092] Since different ambient light can cause the image quality difference of the micro-text area, the image information can be corrected in brightness and contrast before calculating the variance of the gray value. The brightness correction can divide the image into multiple small areas, for example, and perform local equalization on the histogram of each area. The contrast correction can calculate the current contrast of the micro-text area, and if the contrast is lower than a threshold, adjust the contrast of the image through a gray scale stretching algorithm.

[0093] The embodiment intercepts the image information in a predefined coordinate range to determine the micro-text area, adapts to the limited computing power of the mobile terminal, and improves the positioning accuracy. Since the variance of the gray value can intuitively reflect the text clarity, and the size can reflect the compliance, these two key indicators are used as quantifiable feature characteristics, and the anti-fake features are extracted according to the two key indicators, which can identify the defects of the problematic certificate in the micro-text area, realize lightweight extraction, guarantee high recognition accuracy, and adapt to the efficiency and security requirements of the mobile terminal identity authentication.

[0094] In some embodiments of the present application, the method further comprises: sending the certificate ciphertext to the real evidence server, obtaining the return result of the real evidence server on the identity certificate version; according to the return result of the identity certificate version and the mapping relationship with the feature extraction model, determining one from the pre-trained N candidate feature extraction models as a target feature extraction model, N is an integer greater than or equal to 2; processing the image information using the target feature extraction model.

[0095] Figure 6 The flowchart of selecting a feature extraction model according to the return result of the real evidence server is schematically shown.

[0096] As shown in Figure 6 the above embodiments, the mobile terminal obtains the electronic ciphertext, the first angle image information, the second angle image information, and the micro-text area based on the identity certificate respectively.

[0097] The electronic ciphertext is sent to the real evidence server, and the version information of the identity certificate is obtained, such as identifiers V1, V2, and V3. Different identifiers correspond to different versions of the identity certificate.

[0098] Suppose the return result of the real evidence server on a certain identity certificate version is V3, and the first target feature extraction model and the second target feature extraction model correspond to V3. The first target feature extraction model is used to process the first angle image information and the second angle image information, and the first anti-fake feature is obtained; the second target feature extraction model is used to process the micro-text area, and the second anti-fake feature is obtained.

[0099] The embodiment demonstrates the service end to parse the identity certificate ciphertext to obtain the identity certificate version, and according to the mapping relationship between the version and the model, the target feature extraction model is screened from the corresponding candidate model, the adaptation of the single general model is avoided, the model can focus on the corresponding version of the anti-fake feature, the image information is processed by the target model, the accuracy and efficiency of feature extraction are improved, and finally the problems of poor adaptability and high misjudgment rate of different versions of identity certificate anti-fake feature recognition are solved.

[0100] In some embodiments of the present application, the image information of the identity certificate is obtained, and the pre-trained feature extraction model is used to process the image information, including: performing optical character recognition on the image information of the identity certificate; determining the version of the identity certificate according to the recognition result of the optical character recognition; determining one as a target feature extraction model from the pre-trained N candidate feature extraction models according to the version of the identity certificate and the mapping relationship with the feature extraction model, N is an integer greater than or equal to 2; and processing the image information by using the target feature extraction model.

[0101] The version of the identity certificate can be identified by its appearance, for example, the issuance date of a certain version of the identity certificate is from 2004 to 2016, and the issuance date of another version of the identity certificate is from 2017. For example, the identity certificate version corresponding to some areas is different, which can be obtained from the corresponding address code identification.

[0102] For example, a user uses a mobile phone APP to shoot an image of the front of an identity card, the APP performs optical character recognition on the image, and extracts the issuance date: 2019.03.15-Long. According to the optical character recognition result, it is judged that the identity certificate is a 2017 version of the second generation identity certificate. According to the version of the identity certificate and the mapping relationship with the feature extraction model, model A is determined as the target feature extraction model from the two pre-trained candidate models, and the image information is processed by using the target feature extraction model to output the anti-fake feature for anti-fake verification.

[0103] The embodiment determines the version of the identity certificate by extracting the key information in the image of the identity certificate through optical character recognition; determines the target feature extraction model from N candidate models based on the preset mapping relationship between the version and the model, which not only avoids the adaptation limitation of a single model, but also makes the model focus on the core anti-fake feature of the corresponding version; the image information is processed by the target model, the accuracy and efficiency of feature extraction are improved, and finally the problems of poor adaptability and high misjudgment rate of different versions of identity certificate anti-fake feature recognition are solved.

[0104] Based on the above identity authentication method, the present application also provides an identity authentication device. The following will be combined with Figure 7 The device will be described in detail.

[0105] Figure 7A structural block diagram of an identity authentication apparatus according to an embodiment of the present application is shown schematically.

[0106] As shown in Figure 7 The identity authentication apparatus 700 of this embodiment includes a certificate ciphertext reading module 710, a forgery-proof feature extraction module 720, and a verification result confirmation module 730.

[0107] The certificate ciphertext reading module 710 is configured to invoke a near field communication module of a mobile terminal of a target customer, read certificate ciphertext of an identity certificate of the target customer, and send the certificate ciphertext to a real certificate server for verification.

[0108] The forgery-proof feature extraction module 720 is configured to invoke a camera module of the mobile terminal, acquire image information of the identity certificate, input a pre-trained feature extraction model to output a forgery-proof feature, and send the forgery-proof feature to a forgery-proof verification server for verification. The feature extraction model is trained according to identity certificate samples, and the identity certificate samples are labeled with at least one of optically variable ink, directional optically variable film, or microtext.

[0109] The verification result confirmation module 730 is configured to, in response to receiving a result that the certificate ciphertext and the forgery-proof feature pass the verification, confirm that the identity certificate is real and valid. The verification result of the identity certificate is used as a basis for identity authentication when the target customer handles a business.

[0110] According to an embodiment of the present application, the verification result confirmation module 730 is further configured to send identity information of the target customer pre-stored in a business application server to the real certificate server for verification. In response to receiving a result that the identity information returned by the real certificate server is consistent with the reading information of the certificate ciphertext, the target customer's business handling operation on the mobile terminal is approved.

[0111] According to an embodiment of the present application, the verification result confirmation module 730 is further configured to acquire a risk check item of the mobile terminal. The risk check item includes at least one of a device feature, an environment feature, a behavior feature, or an operation risk feature. The device feature reflects the trustworthiness of the mobile terminal device, the environment feature reflects the environmental safety of the mobile terminal, the behavior feature reflects whether the target customer's operation industry on the mobile terminal is abnormal, and the operation risk feature reflects the risk degree of the business handled by the target customer. According to the risk check item and a pre-set score and level rule, a score and a corresponding risk level of the mobile terminal are determined. According to a pre-set mapping relationship between the risk level and an authentication mode, an authentication mode performed on the target customer is determined. The authentication mode includes at least one of identity certificate verification, and a short message verification code, a biological feature, a static password, or a live body authentication. The authentication mode is used to authenticate the identity of the target customer when handling a business.

[0112] According to an embodiment of the present application, the anti-counterfeiting feature extraction module 720 is further configured to acquire image information of the identity certificate taken at at least two different angles; process the image information using a pre-trained feature extraction model to extract color values of the optically variable ink and / or the directional optically variable film of the identity certificate at different angles; and obtain the anti-counterfeiting feature according to the different angles and the color values.

[0113] According to an embodiment of the present application, the anti-counterfeiting feature extraction module 720 is further configured to intercept image information in a predefined coordinate range to acquire a microtext region; calculate a gray value variance of the microtext region and / or a size of the microtext; and obtain the anti-counterfeiting feature of the microtext according to the gray value variance and / or the size of the microtext.

[0114] According to an embodiment of the present application, the certificate ciphertext reading module 710 is further configured to send the certificate ciphertext to a real certificate server to acquire a return result of the identity certificate version from the real certificate server; the anti-counterfeiting feature extraction module 720 is further configured to determine one of N pre-trained candidate feature extraction models as a target feature extraction model according to the return result of the identity certificate version and a mapping relationship with the feature extraction model, N being an integer greater than or equal to 2; and process the image information using the target feature extraction model.

[0115] According to an embodiment of the present application, the anti-counterfeiting feature extraction module 720 is further configured to perform optical character recognition on the image information of the identity certificate; determine the version of the identity certificate according to a recognition result of the optical character recognition; determine one of N pre-trained candidate feature extraction models as a target feature extraction model according to the version of the identity certificate and a mapping relationship with the feature extraction model, N being an integer greater than or equal to 2; and process the image information using the target feature extraction model.

[0116] According to the embodiments of the present application, any of the document cryptogram reading module 710, the anti-forgery feature extraction module 720 and the verification result confirmation module 730 can be combined in one module, or any of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of the modules can be combined with at least part of the functions of other modules, and implemented in one module. According to the embodiments of the present application, at least one of the document cryptogram reading module 710, the anti-forgery feature extraction module 720 and the verification result confirmation module 730 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable manner of integrating or packaging a circuit, etc. hardware or firmware, or implemented in any one of software, hardware and firmware or in a proper combination of any of them. Alternatively, at least one of the document cryptogram reading module 710, the anti-forgery feature extraction module 720 and the verification result confirmation module 730 can be at least partially implemented as a computer program module which can perform the corresponding functions when the computer program module is run.

[0117] The method and device of the embodiments of the present application have the following advantages:

[0118] 1) Low cost. The identity document is issued by the relevant authorities and is universal, without additional cost to the customer. The bank side only reads the document information for authentication comparison, without the need for additional maintenance of the customer's identity document information. Only one set of identity document reading service needs to be built, and the cost is relatively low.

[0119] 2) High security. The identity document is issued by a security authority and stores personal information of the document holder. Various anti-forgery technologies and encryption measures are used to effectively prevent illegal reading or modification.

[0120] 3) Convenient to use. Smartphones supporting NFC are already quite popular, and identity documents are universal, with almost no barriers for ordinary users. Secondly, as an important personal document, the identity document is well maintained and carried with the person, and does not increase the burden of the customer.

[0121] In summary, using NFC document reading to authenticate the identity of the customer can significantly improve the security of risk business handling, while not reducing the customer's experience.

[0122] Figure 8 A block diagram of an electronic device suitable for implementing the identity authentication method according to the embodiments of the present application is schematically shown.

[0123] AsFigure 8 As shown, an electronic device 800 according to an embodiment of this application includes a processor 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage portion 808 into a random access memory (RAM) 803. The processor 801 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 801 may also include onboard memory for caching purposes. The processor 801 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.

[0124] RAM 803 stores various programs and data required for the operation of electronic device 800. Processor 801, ROM 802, and RAM 803 are interconnected via bus 804. Processor 801 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 802 and / or RAM 803. It should be noted that the programs may also be stored in one or more memories other than ROM 802 and RAM 803. Processor 801 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in said one or more memories.

[0125] According to embodiments of this application, the electronic device 800 may further include an input / output (I / O) interface 805, which is also connected to a bus 804. The electronic device 800 may also include one or more of the following components connected to the I / O interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the I / O interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 810 as needed so that computer programs read from it can be installed into the storage section 808 as needed.

[0126] The application further provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or can exist independently without being assembled into the device / apparatus / system. The computer readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the application.

[0127] According to the embodiments of the application, the computer readable storage medium can be a non-volatile computer readable storage medium, which can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any appropriate combination thereof. In this application, a computer readable storage medium can be any tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. For example, in the embodiments of the application, the computer readable storage medium can include the ROM 802 and / or the RAM 803 described above, and / or one or more memory other than the ROM 802 and the RAM 803.

[0128] The embodiments of the application also include a computer program product, which includes a computer program containing program codes for executing the method shown in the flow chart. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the item recommendation method provided by the embodiments of the application.

[0129] The above functions defined in the system / apparatus of the embodiments of the application are performed when the computer program is executed by the processor 801. According to the embodiments of the application, the system, apparatus, module, unit, etc. described above can be implemented by computer program modules.

[0130] In one embodiment, the computer program can rely on a tangible storage medium such as an optical storage device, a magnetic storage device, etc. In another embodiment, the computer program can also be transmitted, distributed, and downloaded in the form of a signal on a network medium, and be downloaded and installed through the communication part 809, and / or installed from the detachable medium 811. The program codes contained in the computer program can be transmitted by any appropriate network medium, including but not limited to wireless, wired, etc., or any appropriate combination thereof.

[0131] In such embodiments, the computer program can be downloaded and installed from the network via the communication section 809, and / or installed from the removable media 811. When the computer program is executed by the processor 801, the above-described functions defined in the system of the embodiments of the present application are performed. According to the embodiments of the present application, the system, device, apparatus, module, unit, and the like described above can be realized by the computer program module.

[0132] According to the embodiments of the present application, the program code for executing the computer program provided by the embodiments of the present application can be written in any combination of one or more programming languages, and specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming language, and / or assembly / machine language. The programming language includes, but is not limited to, such as Java, C++, python, "C" language, or similar programming language. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, connected to the Internet through an Internet service provider).

[0133] The flowcharts and block diagrams in the drawings illustrate the possible architectures, functionality, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowcharts or block diagrams can represent a module, a segment, or a portion of code, which contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks noted in succession can in fact be executed substantially concurrently or in the reverse order, depending on the functionality involved. It will also be noted that each block in the flowcharts or block diagrams, and combinations of blocks in the flowcharts or block diagrams, can be implemented by special-purpose hardware-based systems that perform the specified functions or operations, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0134] Those skilled in the art can understand that the features described in various embodiments and / or claims of the present application can be combined or / and integrated, even if such combinations or integrations are not explicitly described in the present application. In particular, the features described in various embodiments and / or claims of the present application can be combined and / or integrated in various combinations, without departing from the spirit and teachings of the present application. All such combinations and / or integrations are within the scope of the present application.

[0135] The above describes embodiments of the present application. However, these embodiments are merely for illustrative purposes and are not intended to limit the scope of the present application. Although each embodiment is described above separately, this does not mean that the measures in each embodiment cannot be advantageously used in combination. The scope of the present application is defined by the appended claims and their equivalents. Various alternatives and modifications can be made to the embodiments of the present application without departing from the scope of the present application, and such alternatives and modifications should fall within the scope of the present application.

Claims

1. An identity authentication method, comprising: The system invokes the near-field communication module of the target customer's mobile terminal to read the encrypted text of the target customer's ID card and sends the encrypted text to the verification server for verification. The mobile terminal's camera module is invoked to acquire image information of the ID card, and a pre-trained feature extraction model is input to output anti-counterfeiting features. The anti-counterfeiting features are then sent to an anti-counterfeiting verification server for verification. The feature extraction model is trained based on an ID card sample, which is labeled with at least one of optically variable ink, directional optically variable film, or microtext. Upon receiving the encrypted document and the result of successful verification of the anti-counterfeiting features, the authenticity and validity of the identity document are confirmed; the verification result of the identity document is used as the basis for identity authentication when the target customer conducts business.

2. The method according to claim 1, characterized in that, Also includes: Send the target customer's pre-stored identity information on the business application server to the verification server for verification; Upon receiving a result from the verification server indicating that the identity information matches the encrypted document information, the system approves the target customer's business processing operation on the mobile device.

3. The method according to claim 2, characterized in that, Also includes: The risk check items of the mobile terminal are obtained, wherein the risk check items include at least one of device characteristics, environmental characteristics, behavioral characteristics or operational hazard characteristics. The device characteristics reflect the trustworthiness of the mobile terminal device, the environmental characteristics reflect the environmental security of the mobile terminal, the behavioral characteristics reflect whether the target customer's operation industry on the mobile terminal is abnormal, and the operational hazard characteristics reflect the risk level of the business handled by the target customer. Based on the risk check items and the preset scoring and grading rules, the score and corresponding risk level of the mobile terminal are determined. Based on the preset mapping relationship between the risk level and the authentication method, the authentication method to be performed on the target customer is determined. The authentication method includes ID card verification, as well as at least one of SMS verification code, biometrics, static password or liveness detection. The authentication method is used to authenticate the identity of the target customer during business processing.

4. The method according to claim 1, characterized in that, The process of acquiring the image information of the identity document and processing the image information using a pre-trained feature extraction model to obtain anti-counterfeiting features includes: Obtain image information of the ID document taken from at least two different angles; The image information is processed using a pre-trained feature extraction model to extract the color values ​​of the optically variable ink and / or directional optically variable film of the ID card at different angles. The anti-counterfeiting features are obtained based on the different angles and color values.

5. The method according to claim 1, characterized in that, The process of acquiring the image information of the identity document and processing the image information using a pre-trained feature extraction model to obtain anti-counterfeiting features includes: Extract image information within a predefined coordinate range to obtain the microtext region; Calculate the variance of the grayscale values ​​of the microtext region and / or the size of the microtext; The anti-counterfeiting feature is obtained based on the grayscale variance and / or the size of the microtext.

6. The method according to any one of claims 1 to 5, further comprising: Send the encrypted document to the verification server and obtain the return result of the verification server for the version of the ID document; Based on the returned results of the ID card version and its mapping relationship with the feature extraction model, one of the N pre-trained candidate feature extraction models is selected as the target feature extraction model, where N is an integer greater than or equal to 2. The image information is processed using the target feature extraction model.

7. The method according to any one of claims 1 to 5, obtaining the image information of the identity document; The image information is processed using a pre-trained feature extraction model, including: Optical character recognition is performed on the image information of the identity document; The version of the identity document is determined based on the recognition result of the optical character recognition. Based on the version of the ID card and its mapping relationship with the feature extraction model, one of the N pre-trained candidate feature extraction models is selected as the target feature extraction model, where N is an integer greater than or equal to 2. The image information is processed using the target feature extraction model.

8. An identity authentication device, comprising: The document encrypted text reading module is used to call the near-field communication module of the target customer's mobile terminal, read the document encrypted text of the target customer's ID card, and send the document encrypted text to the verification server for verification; The anti-counterfeiting feature extraction module is used to call the camera module of the mobile terminal to obtain the image information of the ID card, input the pre-trained feature extraction model to output the anti-counterfeiting features, and send the anti-counterfeiting features to the anti-counterfeiting verification server for verification; wherein, the feature extraction model is trained based on the ID card sample, and the ID card sample is marked with at least one of optically variable ink, directional optically variable film or microtext; as well as The verification result confirmation module is used to confirm the authenticity and validity of the ID card in response to receiving the encrypted document and the result of successful verification of the anti-counterfeiting features; the verification result of the ID card is used as the basis for identity authentication when the target customer conducts business.

9. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 7.

11. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 7.