Identity verification method and device, equipment, medium and product
By combining multimodal biometric data with liveness detection technology and dynamic prioritization strategies, the security and user experience issues of identity authentication in ATM systems have been resolved, achieving more reliable identity verification and risk assessment.
Patent Information
- Application Number
- CN202511713502.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-20
- Publication Date
- 2026-03-03
AI Technical Summary
Existing ATM systems suffer from insufficient security in their identity authentication technology. Single biometric features are easily forged, there is a lack of multimodal fusion verification mechanisms, the risk control system has a low level of intelligence, the privacy protection mechanism is weak, and the user experience is poor.
The system employs multimodal biometric data (fingerprint, iris, voiceprint, and facial images) combined with liveness detection technology to dynamically adjust biometric verification priority strategies. Based on the liveness detection results and priority strategies, it generates identity verification results and performs dynamic risk assessment and three-factor authentication through a federated learning model.
It improves the reliability and anti-fraud capabilities of identity verification, optimizes the verification process, enhances security and user experience, and adapts to the risk needs of different business types.
Smart Images

Figure CN121598356A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of biometrics, and more particularly to an authentication method, apparatus, device, medium, and product. Background Technology
[0002] An Automated Teller Machine (ATM), also known as an automated teller machine, is a specialized financial self-service device deployed in public environments. It establishes an encrypted connection with the bank's back-end core system through a security authentication module, providing users with transaction functions such as cash deposit and withdrawal, account inquiry, and fund transfer.
[0003] The current ATM systems employ a two-factor authentication system using a bank card and a static PIN code. However, static PINs are vulnerable to attacks such as snooping, keylogging, and phishing. Furthermore, some ATMs integrate fingerprint or facial recognition as supplementary authentication, but single biometric features (such as fingerprints) are easily forged. Therefore, the current challenge is to improve the reliability of ID card verification. Summary of the Invention
[0004] This application provides an identity verification method, apparatus, device, medium, and product to improve the reliability of ID card verification.
[0005] Firstly, this application provides an authentication method, including:
[0006] The system acquires the user's multimodal biometric data and analyzes it using liveness detection technology. The multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image. The system dynamically adjusts the priority strategy for biometric verification based on the type of business the user is to perform. Based on the liveness detection results and the priority strategy, the system generates an identity verification result, which indicates whether the user is authorized to perform the business.
[0007] Secondly, this application provides an authentication device, comprising:
[0008] The acquisition module is used to acquire the user's multimodal biometric data and analyze the multimodal biometric data through liveness detection technology. The multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image. The adjustment module is used to dynamically adjust the priority strategy of biometric verification according to the type of business to be performed by the user. The verification module is used to generate an identity verification result based on the liveness detection result and the priority strategy. The identity verification result indicates whether the user is authorized to perform the business.
[0009] Thirdly, this application provides an electronic device, including: a processor and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the above method.
[0010] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the above-described method.
[0011] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method described above.
[0012] The authentication method, apparatus, device, medium, and product provided in this application include: acquiring a user's multimodal biometric data and analyzing the multimodal biometric data using liveness detection technology; wherein the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; dynamically adjusting the priority strategy of biometric verification according to the type of business to be performed by the user; and generating an authentication result based on the liveness detection result and the priority strategy. The solution of this application, through the combination of multimodal biometric data and the integration of liveness detection technology, enhances the diversity and anti-spoofing capabilities of authentication. Simultaneously, the dynamic priority strategy can adaptively adjust based on the business type, optimizing the authentication process while improving authentication security, thereby enhancing the reliability of authentication. Attached Figure Description
[0013] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0014] Figure 1 A flowchart illustrating the authentication method provided in this application embodiment;
[0015] Figure 2 A flowchart illustrating the authentication method provided in this application embodiment;
[0016] Figure 3 A flowchart illustrating the authentication method provided in this application embodiment;
[0017] Figure 4 A flowchart illustrating the authentication method provided in this application embodiment;
[0018] Figure 5 A flowchart illustrating the authentication method provided in this application embodiment;
[0019] Figure 6A flowchart illustrating the authentication method provided in this application embodiment;
[0020] Figure 7 A schematic diagram of the structure of the authentication device provided in the embodiments of this application;
[0021] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0022] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0023] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0024] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, have taken necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation access points for users to choose to authorize or refuse.
[0025] Furthermore, the technical solution involved in this application, which involves big data analysis of user information (including but not limited to personal biometrics, identity data, consumption data, asset data, electronic terminal operation data, etc.) and the use of artificial intelligence technology for automated decision-making, and makes decisions that have a significant impact on personal rights based on the results of automated decision-making, provides users with corresponding operation entry points for users to choose to agree to or reject the results of automated decision-making; if the user chooses to reject, the process will proceed to the expert decision-making process.
[0026] It should be noted that the authentication methods, devices, equipment, media and products provided in this application can be used in the field of biometrics, or in any field other than biometrics. This application does not limit the application field of the authentication methods, devices, equipment, media and products.
[0027] Current ATM systems primarily rely on two-factor authentication using bank cards and static passwords, with some high-end models integrating single biometric identification (such as fingerprints or facial recognition) as supplementary methods. Regarding transaction risk control, the system uses blacklists and whitelists based on preset rules (such as transaction amount, frequency, and geographical location), but lacks dynamic risk assessment capabilities and cannot identify new fraud patterns (such as decentralized small-amount skimming). Cross-institutional risk data sharing depends on the central bank's credit reporting system or limited industry alliance databases, making it difficult to detect fraudulent activities in a timely manner. At the hardware level, some older ATMs still use outdated operating systems with unpatched security vulnerabilities. Biometric data is typically stored in plaintext on bank servers, posing a high risk of privacy breaches. Furthermore, complex user procedures (such as multiple verifications) lead to a poor user experience and increased error rates.
[0028] Therefore, the limitations of existing technical solutions are reflected in the following aspects: Insufficient identity authentication security: static passwords are vulnerable to attacks, single biometric features are easily forged, and there is a lack of multimodal fusion verification mechanisms; Low level of intelligence in risk control systems: rule engines cannot dynamically adapt to new fraud patterns, and cross-institutional data sharing is lagging behind; Weak privacy protection mechanisms: centralized storage of biometric data makes it easy to become a target of attacks, and there is a lack of encryption and anonymization processing; Lack of user experience optimization: complex security processes reduce user operation efficiency, and there are no adaptation functions for special user groups (such as the elderly and international users).
[0029] The specific application scenario of this application is a self-service scenario in the financial field, such as ATMs in bank branches, remote video teller machines, and cross-channel transaction scenarios with collaborative verification of mobile devices.
[0030] The technical content provided in this application aims to solve the above-mentioned technical problems of the prior art. The authentication method, apparatus, device, medium, and product provided in the embodiments of this application include: acquiring multimodal biometric data of a user and analyzing the multimodal biometric data through liveness detection technology; wherein the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; dynamically adjusting the priority strategy of biometric verification according to the type of business to be performed by the user; and generating an authentication result based on the liveness detection result and the priority strategy. The solution of this application, through the combination of multimodal biometric data and the integration of liveness detection technology, enhances the diversity and anti-spoofing capabilities of authentication. Simultaneously, the dynamic priority strategy can adaptively adjust based on the business type, optimizing the authentication process while improving authentication security, thereby improving the reliability of authentication.
[0031] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0032] Figure 1 A flowchart illustrating the authentication method provided in this application embodiment is shown below. Figure 1 As shown, the method includes:
[0033] S101. Acquire the user's multimodal biometric data and analyze the multimodal biometric data through liveness detection technology; wherein, the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image;
[0034] S102. Dynamically adjust the priority strategy of biometric verification according to the type of business to be performed by the user;
[0035] S103. Based on the liveness detection results and priority policies, generate authentication results. The authentication results indicate whether the user is authorized to perform business.
[0036] In practical applications, the execution subject of this method can be an authentication device, which can be implemented in various ways. For example, it can be implemented through a computer program, such as application software; or it can be implemented as a medium storing the relevant computer program, such as a cloud drive; or it can be implemented through a physical device that integrates or installs the relevant computer program, such as a chip.
[0037] For example, the implementing entity may take many forms, including self-service terminals such as bank ATMs or information kiosks. These devices may integrate various biometric acquisition sensors, such as fingerprint readers and facial cameras, built-in cameras and microphones, iris scanners, and voiceprint recording devices on self-service terminals.
[0038] In some embodiments, at least two biometric features are acquired in real time using dedicated sensors or device components. For example, fingerprint images are acquired using capacitive or optical sensors, iris texture is captured using a near-infrared camera, facial images are captured using a high-resolution camera, and voice samples of the user are recorded via a microphone to extract voiceprint features. Optionally, the data acquisition process needs to ensure environmental adaptability, such as adjusting camera parameters under changing lighting conditions, or processing voiceprint data using noise reduction algorithms.
[0039] In some optional embodiments, user interaction guidance, such as prompting the user to perform specific actions (e.g., blinking or speaking), can be incorporated to enhance data integrity. Furthermore, the collected multimodal biometric data is then transmitted to a processing unit for standardization and encryption, providing input for subsequent liveness detection and thus reducing the risk of forgery.
[0040] In some embodiments, when analyzing multimodal biometric data using liveness detection technology, various techniques can be employed to distinguish genuine biometrics from spoofing attacks. For example, 3D depth sensing technology uses structured light or time-of-flight cameras to acquire three-dimensional information of the face or iris, analyzing depth maps to detect anomalies in planar photographs or masks. This process includes calculating curvature changes and motion trajectories to confirm liveness characteristics. Infrared liveness detection emits infrared light and analyzes the skin's reflectance spectrum, as real tissue has unique optical properties that can identify fake features from silicone or printed materials. Voiceprint liveness detection analyzes the frequency domain characteristics and dynamic changes of speech, such as detecting differences between recorded playback and real speech, using machine learning models to assess the probability of liveness. These techniques, combined with multimodal data cross-validation, such as simultaneously examining facial micro-expressions and voiceprint fluctuations, improve the robustness of the analysis and reduce the possibility of deception.
[0041] In some embodiments, the priority strategy for biometric verification is dynamically adjusted based on the type of business the user is about to perform. This can be understood as optimizing the verification order or weight in real time based on the security criticality of the business. For example, for high-value businesses such as large-sum fund transfers, the priority strategy may set iris verification to the highest level because iris features have high uniqueness and anti-spoofing properties, and the system will prioritize calling the iris sensor and performing strict matching. For low-risk businesses such as information queries, the strategy may prioritize facial image or voiceprint verification to improve efficiency and reduce the user's operational burden. This dynamic adjustment is achieved through predefined rules or machine learning models, making the verification process more adaptive.
[0042] For example, when generating authentication results based on liveness detection results and priority policies, the output of liveness detection can be evaluated first, such as confirming whether the biometric features represent a real live person. Then, the priority policy is used to select the dominant verification mode. For instance, if liveness detection shows that the facial image passes the liveness check but the voiceprint fails, and the business type requires high security, the policy may prioritize iris verification results for the final decision. By calculating the matching scores of each biometric feature and weighting them according to the policy, if the overall score exceeds a threshold, an authorization result is generated; otherwise, it is rejected.
[0043] In some optional embodiments, behavioral features such as typing rhythm and force, and gait characteristics can also be used as supplementary biometric data. The introduction of these features further enriches the dimensions of multimodal biometric data, enhancing the authentication system's ability to cope with complex attacks and adapt to different environments.
[0044] For example, the authentication result ultimately represents whether the user is authorized to perform business, and is usually presented in the form of binary output (such as pass or deny) or confidence level, for subsequent business logic processing.
[0045] In some embodiments, authentication results are based on the overall verification of multimodal biometrics. For example, when a liveness detection confirms the authenticity of the biometrics and a successful match, the result is positive authorization, allowing the user to conduct transactions or access the system. Conversely, if a liveness detection fails or the biometrics do not match, the result is negative authorization, triggering rejection or additional verification. The results may include detailed metadata such as timestamps and confidence levels to support audit trails.
[0046] The authentication method provided in this application includes: acquiring a user's multimodal biometric data and analyzing the multimodal biometric data using liveness detection technology; wherein the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; dynamically adjusting the priority strategy of biometric verification according to the type of business to be performed by the user; and generating an authentication result based on the liveness detection result and the priority strategy. This application's solution, through the combination of multimodal biometric data and the integration of liveness detection technology, enhances the diversity and anti-spoofing capabilities of authentication. Simultaneously, the dynamic priority strategy can adaptively adjust based on the business type, optimizing the authentication process while improving authentication security, thereby enhancing the reliability of authentication.
[0047] Figure 2 This is a flowchart illustrating the authentication method provided in this application embodiment; for example, multimodal biometric data includes iris data and facial image data. Figure 2 As shown, S101 analyzes multimodal biometric data using liveness detection technology, including:
[0048] S201. Determine the iris texture change data in the iris data and the micro-expression data corresponding to the facial image data;
[0049] S202. Based on iris texture change data and micro-expression data, a deep learning model is used to determine whether the subject is a real living person.
[0050] It's important to note that the necessity of using iris and facial image data for liveness detection lies in the complementary advantages of these two biometric features, which can synergistically enhance anti-spoofing capabilities. Specifically, the iris possesses high uniqueness and stability; its complex texture and patterns are difficult to replicate. However, static iris images are still susceptible to forgery by high-precision printed images or contact lenses. Facial images, on the other hand, contain rich dynamic information, but their two-dimensional features are vulnerable to attacks from photographs, videos, or three-dimensional masks. Combining the two, by analyzing the physiological micro-movements of the iris texture and involuntary micro-expression changes in the face, can effectively distinguish between non-liveness attacks.
[0051] In some embodiments, determining the iris texture change data corresponding to the iris data typically requires acquiring a continuous sequence of eye images and using image processing algorithms to track subtle deformations or texture fluctuations in the iris region over a short period. For example, under natural light or near-infrared light sources, the system can capture the pupil's dilation and contraction caused by changes in light or physiological rhythms. During this process, the movement of the iris sphincter and dilatation muscles leads to unique stretching and wrinkling patterns in the iris texture. By calculating the temporal changes in texture features in a specific region, the iris texture change data can be quantified.
[0052] In some embodiments, determining the micro-expression data corresponding to facial image data relies on a detailed analysis of the displacement of key facial points. For example, a high frame rate camera is used to record the user's brief facial reaction when being detected. By analyzing the involuntary, minimally sized movement trajectories and muscle tremor patterns of areas such as the eyebrows, corners of the mouth, or corners of the eyes in a very short time (e.g., tens to hundreds of milliseconds), micro-expression features that are difficult to imitate artificially can be extracted.
[0053] It should be understood that the process of determining whether a person is a real living being based on iris texture change data and micro-expression data using a deep learning model is a multimodal information fusion and classification task. First, preprocessed iris image sequences and facial video frames are input into specific feature extraction network branches, such as using convolutional neural networks to learn the spatiotemporal features of iris texture changes, while another network structure is used to capture the transient dynamic patterns of micro-expressions. Subsequently, the model fuses the high-level feature representations learned from these two channels, for example, through concatenation or weighted combination using attention mechanisms. Finally, the fused feature vector is fed into a classifier (such as a fully connected layer and a softmax activation function), which outputs a probability value to determine whether the submitted biometric sample comes from a real living being or is a forgery. The entire model is trained end-to-end, enabling it to automatically learn the complex, nonlinear discriminative rules associated with vitality in both biometric features.
[0054] In some embodiments, the specific deep learning model available may include a hybrid architecture based on convolutional neural networks and recurrent neural networks, such as using a three-dimensional convolutional neural network to directly process video sequences to capture spatiotemporal features, or using a two-stream network to process appearance information and optical flow information respectively, and then combining it with a long short-term memory network to model the temporal dependence of micro-expressions and iris changes.
[0055] In practical applications, the model training process first requires constructing a large-scale dataset containing a large amount of real live iris and facial video data, as well as data samples from various forgery attacks (such as high-definition printed photos, electronic screen playback, high-fidelity masks, etc.), and accurately labeling each data point with its true or false label. During training, the data is input into the network, and the model parameters (such as weights and biases) are optimized through the backpropagation algorithm to minimize the loss function between the predicted result and the true label, such as cross-entropy loss, so that the model gradually learns to distinguish the key discrimination patterns between real live features and non-live forgery features.
[0056] The solution presented in this example improves upon the limitations of single-feature liveness detection by integrating two deep-level liveness features—iris texture changes and facial micro-expressions—and using a deep learning model for comprehensive discrimination. This results in a more robust identification capability against high-level forgery attacks.
[0057] Figure 3 A flowchart illustrating the authentication method provided in this application embodiment is shown below. Figure 3 As shown, the method also includes:
[0058] S301. Obtain the user's historical transaction amount distribution data and historical operation data;
[0059] S102 dynamically adjusts the priority strategy for biometric verification based on the type of business the user needs to perform, including:
[0060] S302. Generate risk level labels for business types based on users' historical transaction amount distribution data and historical operation data;
[0061] S303. Based on the risk level label, dynamically configure the number and combination of biometric verification modalities; wherein, the first risk level adopts multimodal biometric verification combination, the second risk level adopts single-modal biometric verification, and the first risk level is higher than the second risk level.
[0062] In some embodiments, a user’s historical transaction amount distribution data and historical operation data typically need to be extracted from relevant business databases or behavior log systems in a secure manner.
[0063] For example, historical transaction amount distribution data can come from a user's past transfer, payment or consumption records. By statistically analyzing the frequency and total amount distribution of transactions in different amount ranges within a specific time period (such as the last three months), a profile of their fund usage pattern can be formed.
[0064] For example, historical operation data may include user login time, frequently used device identifiers, operation locations, business processing duration, password change frequency, and even the number of operational errors. The acquisition of this data must be conducted within the framework of user authorization and privacy protection regulations, and it must be encrypted and aggregated through data interfaces to provide a data foundation for subsequent risk assessment.
[0065] In this example, historical transaction amount distribution data primarily reflects a user's habits and scale in financial transactions. For example, does the user typically make multiple small payments or occasionally conduct large transactions? The distribution pattern helps identify abnormal transactions that deviate significantly from the norm. Historical operation data, on the other hand, focuses more on characterizing the user's behavioral patterns in interacting with the system, such as typically logging in at fixed times and locations, using specific types of devices, and having a unique operational rhythm. These two types of data together constitute the user's behavioral fingerprint. Transaction amount distribution reveals risk from an economic perspective, while historical operation data provides supplementary judgment from a behavioral consistency perspective. Combining the two allows for a more comprehensive assessment of the contextual risk of the current business request.
[0066] It should be understood that generating risk level labels for business types based on users' historical transaction amount distribution data and historical operation data is a data mining and risk assessment process.
[0067] In some embodiments, a baseline model of a user's normal behavior is established based on historical data. When a new business request is initiated, the deviation of the current transaction amount from the user's historical amount distribution is calculated in real time (e.g., whether it is the first time a huge transaction far exceeding the average level has occurred), and the characteristics of the current operation session (such as login device, geographical location, operation time) are comprehensively analyzed to determine their matching degree or outliers with their historical operation patterns. Then, through a predefined risk scoring rule engine or machine learning model, these quantified deviations and outlier indicators are aggregated to calculate a comprehensive risk score, and finally, the score range is mapped to a preset risk level label, such as "low risk," "medium risk," or "high risk."
[0068] In some embodiments, if a "high-risk" level label (i.e., the first risk level) is generated for the current business, the system may be dynamically configured to require verification through a combination of bimodal biometric features, including fingerprints and facial images, supplemented by strict liveness detection. Conversely, if the evaluation result is a "low-risk" level label (i.e., the second risk level), the system may be configured to require only single-modal biometric verification, such as verifying only fingerprints or only voiceprints, to simplify the process and improve efficiency.
[0069] In some alternative embodiments, there are often more than two risk levels, which may include an intermediate "medium risk" level. Corresponding to this level, a modality may be configured but a more stringent liveness detection threshold may be enabled, or the user may be allowed to choose between two modalities specified by the system for verification, thereby achieving a balance between safety and convenience.
[0070] The solution in this example improves the rigidity of static verification rules by introducing dynamic risk assessment based on the distribution data of users' historical transaction amounts and historical operation data to configure biometric verification strategies, thereby achieving adaptive matching between verification strength and real-time risk levels.
[0071] Figure 4 A flowchart illustrating the authentication method provided in this application embodiment is shown below. Figure 4 As shown, after generating the authentication result in S103, the method further includes:
[0072] S401. Based on historical operational data and the user's current environmental data, the current risk threshold is determined through a federated learning model; wherein, the federated learning model is a joint update of the model gradient by multiple institutions without sharing the original biometric data, using homomorphic encryption technology.
[0073] S402. If the user's current operation data deviates from the historical baseline by more than the risk threshold, then a two-factor authentication process will be executed.
[0074] In some embodiments, a user's current environmental data typically includes the terminal device model used for authentication, the device's network connection type and IP address location, the current GPS location or connected base station information, whether the specific time of the operation is during an unusual period, and even the surrounding ambient noise level or light intensity. This environmental data collectively depicts a snapshot of the scene when the user initiates the request. Comparing this snapshot with a baseline of normal behavior formed by historical operational data stored in the system can effectively reveal potential risk signals. For example, logging in late at night in an unfamiliar area, or using a completely new and unknown device for sensitive operations, these environmental anomalies may indicate the risk of account theft.
[0075] It is understandable that determining the current risk threshold based on historical operational data and the user's current environmental data through a federated learning model is a dynamic risk assessment process that incorporates privacy-preserving computing technologies.
[0076] Specifically, each participating institution trains a local risk identification model using its own users' historical operational data and environmental data, but they do not directly share any raw data. Using homomorphic encryption, each institution only encrypts the updated model parameters calculated by its local model before uploading them to a central coordinator. This coordinator aggregates these encrypted gradient updates to construct a more powerful global federated learning model. This trained global model can output a dynamic, personalized risk probability score based on the difference between the input user's current environmental data and its historical baseline. The implementer of this method maps this score or uses it directly as the real-time risk threshold for the current session, allowing the threshold to be flexibly adjusted according to the context, rather than remaining fixed.
[0077] In some embodiments, federated learning is a distributed machine learning framework whose core objective is to collaboratively train a high-quality machine learning model while multiple participants hold local data and the data remains on their local machines. During training, a central server first distributes an initial global model to each participating institution. Each institution trains this model locally using its own data, calculating the model's update increments. These updates are then encrypted and sent to the central server. The server uses homomorphic encryption to securely aggregate the received encrypted updates, generating an improved global model. This process iterates continuously, enabling the model to learn patterns inherent in the data from all participants while strictly protecting the data privacy of all parties and avoiding the risk of direct transmission and leakage of sensitive raw biometric or behavioral data.
[0078] In some embodiments, determining the risk threshold is a dynamic and personalized process, not an absolutely fixed value. This threshold is primarily determined by the aforementioned federated learning model based on the current risk level assessed in real time. The model comprehensively analyzes the multidimensional deviation between the current operating environment and the user's historical baseline, outputting a quantified risk value. This risk value itself serves as the dynamic threshold for determining whether to trigger subsequent measures. For example, in a normal environment, the model may output a lower risk score, with a correspondingly more lenient threshold; while when multiple anomalous features are detected, the model will output a higher risk score, meaning the system automatically adopts a stricter threshold standard.
[0079] Two-factor authentication refers to an additional verification step triggered after the initial authentication result is successful, due to the detection of abnormal risks, aiming to provide a deeper layer of security confirmation. For example, when the system determines that the deviation of a user's current operation data from the historical baseline exceeds the dynamic risk threshold determined by the federated learning model, it may initiate various two-factor authentication methods. For instance, it might require the user to receive and enter a one-time dynamic verification code via their registered mobile phone number or email address; or it might redirect to a more complex multimodal biometric verification step, such as adding voiceprint verification on top of facial recognition; in extremely high-risk scenarios, it might even trigger a manual review process, with customer service personnel verifying information with the user via video call. Optionally, the user can also be required to complete a rapid biometric re-verification on a separate, high-security authentication application.
[0080] The solution presented in this example improves upon the limitations of static security policies by introducing an environment-aware dynamic risk threshold based on federated learning and performing secondary authentication when anomalies are detected. This results in a more adaptive and accurate risk interception capability against abnormal operational behaviors.
[0081] Figure 5 A flowchart illustrating the authentication method provided in this application embodiment is shown below. Figure 5 As shown, after generating the authentication result in S103, the method further includes:
[0082] S501, Obtain the user's business transaction status;
[0083] S502. When it is detected that a user has ended a business transaction, the identity verification result and the hash value of the business transaction are stored in the predetermined blockchain based on the smart contract.
[0084] In some embodiments, the detection of a user ending a business transaction typically relies on the state machine or event notification mechanism of the business system itself. When a user explicitly clicks the "Confirm," "Complete," or "Exit" button on the interactive interface, or when the system backend receives a success callback signal from the payment gateway or database update operation, the transaction can be determined to be complete. For example, in a transfer operation, when the bank's core system processes the fund transfer and returns a "Transaction Successful" status code to the application server, or when the user actively clicks to return to the main menu after executing a query, the application logic will trigger a transaction completion detection event.
[0085] In this example, the characteristics of blockchain technology are used to create an immutable and verifiable audit log. Specifically, at the time a business transaction is completed, a pre-defined smart contract automatically executes and permanently writes the key credentials for this transaction—the initial authentication result (such as "passed" or "failed")—along with the digital fingerprint (i.e., hash value) of the transaction content, as a complete record unit, into the designated blockchain network. This process does not store the original business data itself, but rather its cryptographic hash and verification conclusion, thereby providing highly credible evidence for potential future disputes while protecting user privacy and business secrets.
[0086] In some embodiments, upon detection of the completion of a business transaction, the authentication result and the key data summary of the business transaction are immediately combined and packaged, and a unique hash value is calculated as the fingerprint of the transaction record. Subsequently, a smart contract pre-deployed on the target blockchain is invoked, and the hash value and necessary metadata are passed to the contract as parameters. After the smart contract is triggered, it automatically verifies the calling permissions and writes the received data (mainly the hash value) as a new transaction into a new block of the blockchain. After confirmation by the consensus mechanism of the network nodes, the record becomes immutable and traceable. Finally, the system may receive and store the transaction receipt returned by the blockchain as a local index, thereby completing the entire evidence preservation process.
[0087] This example solution improves upon the low reliability of traditional centralized log storage by using smart contracts to store the key hash value on the blockchain after performing identity verification and business transactions, achieving a high degree of tamper-proofness and traceability of verification and transaction records.
[0088] Figure 6 A flowchart illustrating the authentication method provided in this application embodiment is shown below. Figure 6 As shown, the method also includes:
[0089] S601. When biometric verification fails, switch to three-factor authentication; where three-factor authentication includes fingerprint verification, SMS verification and ID card sensor verification.
[0090] S602. After the three-factor authentication is successful, a temporary token is generated to enable the user to complete the transaction within the first time period and the preset transaction limit; the temporary token is bound to the current transaction device.
[0091] S603. Remind users to supplement the failed biometric data verification within the second time period.
[0092] In some embodiments, users may encounter situations where they have urgent transaction needs but biometric verification fails. Three-factor authentication, by introducing the physical credentials (ID card) that users usually carry with them and their communication channels (mobile phone text messages), provides a backup path with a relatively high level of security and a more convenient acquisition method when biometrics temporarily fails. It aims to balance security and business continuity, ensuring that users are not turned away in emergency situations, while controlling potential risks through additional conditions.
[0093] In some embodiments, the three-factor authentication can be performed on a user's mobile device, such as a smartphone or tablet. On such devices, fingerprint verification can be easily performed using an integrated fingerprint sensor; SMS verification receives a one-time dynamic verification code sent by the system via the device's cellular or wireless network; and ID card verification uses the device's chip reader to read and compare non-sensitive public information within the ID card chip. This design fully leverages the portability, versatility, and high user engagement of mobile devices, enabling users to quickly and relatively securely complete a backup verification process using readily available devices when the primary biometric authentication process is unexpectedly interrupted. This is suitable for emergency transactions occurring in non-fixed locations.
[0094] In this example, a temporary token can be understood as a short-term digital pass generated by the system backend with strict usage restrictions. It represents a temporary transaction authorization granted under specific conditions. Specifically, the determination of the initial time period and the preset transaction limit is usually based on a risk assessment strategy. For example, the validity period of the temporary token may be set to a very short initial time period, such as ten or thirty minutes, to ensure the short duration of the authorization. The preset transaction limit will be set at a relatively low amount, such as allowing only small payments or basic business transactions, thereby controlling potential risks within a limited scope.
[0095] In some embodiments, the specific implementation of binding a temporary token to the current transaction device typically involves recording and associating one or more sets of immutable unique hardware identifiers of the device when generating the token. For example, the system can collect and hash information such as the device's International Mobile Equipment Identity (IMEI), serial number, or unique key of a secure element. When a user initiates a transaction using the temporary token, the execution entity of the method requires the application to read these hardware identifiers of the current device again and compare them in real time with the records from when the token was bound. Only if both match perfectly is the token considered valid. This mechanism ensures that even if the token itself is accidentally leaked, it cannot be used on another unauthorized device, thus locking the temporary authorization to the device that initially initiated the verification, greatly enhancing the security of temporary access permissions.
[0096] In some embodiments, users are prompted to replenish the biometric data that failed to verify within a second time period, typically through proactive outreach via various channels such as in-system push notifications, SMS, or email. For example, a notification message or SMS will be sent to the user's mobile device immediately after a temporary token expires. The system implementing the method may set periodic reminders within the second time period, such as prompting again a few hours before the expiration date. These reminders aim to urge users to restore their account verification status to a higher security level as soon as possible, compensating for any security degradation that may have occurred due to previous verification failures.
[0097] This example solution provides a three-factor authentication approach that integrates fingerprint, SMS, and ID card sensing as an emergency path when biometric authentication fails. It also introduces a temporary token mechanism that is bound to the device and has strict time, space, and limit restrictions. This approach ensures that core security elements are not missing while maintaining business continuity and reducing the risk of temporary authorization.
[0098] The authentication method provided in this application includes: acquiring a user's multimodal biometric data and analyzing the multimodal biometric data using liveness detection technology; wherein the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; dynamically adjusting the priority strategy of biometric verification according to the type of business to be performed by the user; and generating an authentication result based on the liveness detection result and the priority strategy. This application's solution, through the combination of multimodal biometric data and the integration of liveness detection technology, enhances the diversity and anti-spoofing capabilities of authentication. Simultaneously, the dynamic priority strategy can adaptively adjust based on the business type, optimizing the authentication process while improving authentication security, thereby enhancing the reliability of authentication.
[0099] Figure 7 This is a schematic diagram of the structure of the authentication device provided in the embodiments of this application, such as... Figure 7 As shown, the device includes:
[0100] The acquisition module 71 is used to acquire the user's multimodal biometric data and analyze the multimodal biometric data through liveness detection technology; wherein, the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image;
[0101] Adjustment module 72 is used to dynamically adjust the priority strategy of biometric verification according to the type of business to be performed by the user;
[0102] The verification module 73 is used to generate an authentication result based on the liveness detection result and priority policy. The authentication result indicates whether the user is authorized to perform business.
[0103] In practical applications, there are various ways to implement authentication devices. For example, they can be implemented through computer programs, such as application software; or they can be implemented as a medium storing relevant computer programs, such as cloud storage; or they can be implemented through physical devices that integrate or install relevant computer programs, such as chips.
[0104] For example, the implementing entity may take many forms, including self-service terminals such as bank ATMs or information kiosks. These devices may integrate various biometric acquisition sensors, such as fingerprint readers and facial cameras, built-in cameras and microphones, iris scanners, and voiceprint recording devices on self-service terminals.
[0105] In some embodiments, at least two biometric features are acquired in real time using dedicated sensors or device components. For example, fingerprint images are acquired using capacitive or optical sensors, iris texture is captured using a near-infrared camera, facial images are captured using a high-resolution camera, and voice samples of the user are recorded via a microphone to extract voiceprint features. Optionally, the data acquisition process needs to ensure environmental adaptability, such as adjusting camera parameters under changing lighting conditions, or processing voiceprint data using noise reduction algorithms.
[0106] In some optional embodiments, user interaction guidance, such as prompting the user to perform specific actions (e.g., blinking or speaking), can be incorporated to enhance data integrity. Furthermore, the collected multimodal biometric data is then transmitted to a processing unit for standardization and encryption, providing input for subsequent liveness detection and thus reducing the risk of forgery.
[0107] In some embodiments, when analyzing multimodal biometric data using liveness detection technology, various techniques can be employed to distinguish genuine biometrics from spoofing attacks. For example, 3D depth sensing technology uses structured light or time-of-flight cameras to acquire three-dimensional information of the face or iris, analyzing depth maps to detect anomalies in planar photographs or masks. This process includes calculating curvature changes and motion trajectories to confirm liveness characteristics. Infrared liveness detection emits infrared light and analyzes the skin's reflectance spectrum, as real tissue has unique optical properties that can identify fake features from silicone or printed materials. Voiceprint liveness detection analyzes the frequency domain characteristics and dynamic changes of speech, such as detecting differences between recorded playback and real speech, using machine learning models to assess the probability of liveness. These techniques, combined with multimodal data cross-validation, such as simultaneously examining facial micro-expressions and voiceprint fluctuations, improve the robustness of the analysis and reduce the possibility of deception.
[0108] In some embodiments, the priority strategy for biometric verification is dynamically adjusted based on the type of business the user is about to perform. This can be understood as optimizing the verification order or weight in real time based on the security criticality of the business. For example, for high-value businesses such as large-sum fund transfers, the priority strategy may set iris verification to the highest level because iris features have high uniqueness and anti-spoofing properties, and the system will prioritize calling the iris sensor and performing strict matching. For low-risk businesses such as information queries, the strategy may prioritize facial image or voiceprint verification to improve efficiency and reduce the user's operational burden. This dynamic adjustment is achieved through predefined rules or machine learning models, making the verification process more adaptive.
[0109] For example, when generating authentication results based on liveness detection results and priority policies, the output of liveness detection can be evaluated first, such as confirming whether the biometric features represent a real live person. Then, the priority policy is used to select the dominant verification mode. For instance, if liveness detection shows that the facial image passes the liveness check but the voiceprint fails, and the business type requires high security, the policy may prioritize iris verification results for the final decision. By calculating the matching scores of each biometric feature and weighting them according to the policy, if the overall score exceeds a threshold, an authorization result is generated; otherwise, it is rejected.
[0110] In some optional embodiments, behavioral features such as typing rhythm and force, and gait characteristics can also be used as supplementary biometric data. The introduction of these features further enriches the dimensions of multimodal biometric data, enhancing the authentication system's ability to cope with complex attacks and adapt to different environments.
[0111] For example, the authentication result ultimately represents whether the user is authorized to perform business, and is usually presented in the form of binary output (such as pass or deny) or confidence level, for subsequent business logic processing.
[0112] In some embodiments, authentication results are based on the overall verification of multimodal biometrics. For example, when a liveness detection confirms the authenticity of the biometrics and a successful match, the result is positive authorization, allowing the user to conduct transactions or access the system. Conversely, if a liveness detection fails or the biometrics do not match, the result is negative authorization, triggering rejection or additional verification. The results may include detailed metadata such as timestamps and confidence levels to support audit trails.
[0113] The authentication device provided in this application includes: acquiring a user's multimodal biometric data and analyzing the multimodal biometric data using liveness detection technology; wherein the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; dynamically adjusting the priority strategy of biometric verification according to the type of business to be performed by the user; and generating an authentication result based on the liveness detection result and the priority strategy. The solution of this application, through the combination of multimodal biometric data and the integration of liveness detection technology, enhances the diversity and anti-spoofing capabilities of authentication. Simultaneously, the dynamic priority strategy can adaptively adjust based on the business type, optimizing the authentication process while improving authentication security, thereby enhancing the reliability of authentication.
[0114] As yet another example, module 71 is used specifically for:
[0115] Determine the iris texture variation data in the iris data and the micro-expression data corresponding to the facial image data;
[0116] Based on iris texture change data and micro-expression data, a deep learning model is used to determine whether the person is a real living being.
[0117] As yet another example, module 71 is also used for:
[0118] Obtain the user's historical transaction amount distribution data and historical operation data;
[0119] Module 71 is used specifically for:
[0120] Based on the distribution data of users' historical transaction amounts and historical operation data, risk level labels for business types are generated;
[0121] Based on the risk level labels, the number and combination of biometric verification modalities are dynamically configured; the first risk level uses a combination of multimodal biometric verification, the second risk level uses a single-modal biometric verification, and the first risk level is higher than the second risk level.
[0122] As yet another example, verification module 73 is also used for:
[0123] Based on historical operational data and the user's current environmental data, the current risk threshold is determined through a federated learning model. The federated learning model involves multiple institutions jointly updating the model gradient using homomorphic encryption technology without sharing the original biometric data.
[0124] If a user's current operation data deviates from the historical baseline by more than a risk threshold, a two-factor authentication process will be executed.
[0125] As yet another example, verification module 73 is also used for:
[0126] Obtain the user's business transaction status;
[0127] Once a user's transaction is detected to have ended, the authentication result and the hash value of the transaction are stored in the designated blockchain based on a smart contract.
[0128] As yet another example, verification module 73 is also used for:
[0129] When biometric verification fails, it switches to three-factor authentication; three-factor authentication includes fingerprint verification, SMS verification and ID card sensor verification.
[0130] Once the three-factor authentication is successful, a temporary token is generated to enable the user to complete the transaction within the first time period and preset transaction limit; the temporary token is bound to the current transaction device.
[0131] Users are reminded to supplement the biometric data that failed to be verified within the second time period.
[0132] The authentication device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0133] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 8 As shown, the electronic device provided in this embodiment includes a processor 291 and a memory 292; it may also include a communication interface 293 and a bus 294. The processor 291, memory 292, and communication interface 293 can communicate with each other via the bus 294. The communication interface 293 can be used for information transmission. The processor 291 can call logical instructions in the memory 292 to execute the method described above.
[0134] Furthermore, the logic instructions in the aforementioned memory 292 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium.
[0135] The memory 292, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of this application. The processor 291 executes functional applications and data processing by running the software programs, instructions, and modules stored in the memory 292, that is, it implements the methods in the above method examples.
[0136] The memory 292 may include a program storage area and a data storage area. The program storage area may store the operating system and application programs required for at least one function; the data storage area may store data created based on the use of the terminal device. Furthermore, the memory 292 may include high-speed random access memory and may also include non-volatile memory.
[0137] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the methods described in the above embodiments.
[0138] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method described in the above embodiments.
[0139] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0140] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0141] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0142] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0143] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0144] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0145] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0146] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. An authentication method, characterized in that, include: The system acquires multimodal biometric data of users and analyzes the multimodal biometric data using liveness detection technology; wherein the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; The priority strategy for biometric verification is dynamically adjusted based on the type of business to be performed by the user. Based on the liveness detection result and the priority policy, an authentication result is generated, which indicates whether the user is authorized to perform the service.
2. The method according to claim 1, characterized in that, The multimodal biometric data includes iris data and facial image data; the analysis of the multimodal biometric data using liveness detection technology includes: Determine the iris texture change data in the iris data and the micro-expression data corresponding to the facial image data; Based on the iris texture change data and the micro-expression data, a deep learning model is used to determine whether the person is a real living being.
3. The method according to claim 1, characterized in that, The method further includes: Obtain the user's historical transaction amount distribution data and historical operation data; The strategy of dynamically adjusting the priority of biometric verification based on the type of service to be performed by the user includes: Based on the distribution data of users' historical transaction amounts and historical operation data, a risk level label for the business type is generated; Based on the risk level labels, the number and combination of biometric verification modalities are dynamically configured; wherein, the first risk level adopts a combination of multimodal biometric verification, the second risk level adopts a single-modal biometric verification, and the first risk level is higher than the second risk level.
4. The method according to claim 3, characterized in that, After generating the authentication result, the method further includes: Based on the historical operation data and the user's current environmental data, the current risk threshold is determined through a federated learning model; wherein, the federated learning model is a joint update of the model gradient by multiple institutions without sharing the original biometric data, using homomorphic encryption technology. If the user's current operation data deviates from the historical baseline by more than the risk threshold, a two-factor authentication process is executed.
5. The method according to claim 1, characterized in that, After generating the authentication result, the method further includes: Obtain the user's business transaction status; Once the user's business transaction is detected to have ended, the authentication result and the hash value of the business transaction are stored in a predetermined blockchain based on a smart contract.
6. The method according to any one of claims 1-5, characterized in that, The method further includes: When the biometric verification fails, it switches to three-factor authentication; wherein, the three-factor authentication includes fingerprint verification, SMS verification and ID card sensor verification. Once the three-factor authentication is successful, a temporary token is generated to enable the user to complete the transaction within a first time period and a preset transaction limit; wherein, the temporary token is bound to the current transaction device; The user is reminded to supplement the biometric data that failed to be verified within the second time period.
7. An authentication device, characterized in that, include: The acquisition module is used to acquire the user's multimodal biometric data and analyze the multimodal biometric data through liveness detection technology; wherein, the multimodal biometric data includes a combination of at least two of the following biometric features: fingerprint, iris, voiceprint, and facial image; The adjustment module is used to dynamically adjust the priority strategy of biometric verification according to the type of business to be performed by the user; The verification module is used to generate an authentication result based on the liveness detection result and the priority policy, wherein the authentication result indicates whether the user is authorized to execute the service.
8. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-6.
Citation Information
Cited By
Dispensing authority control method and system based on multi-modal biological characteristic comparison
CN121921853A