Identity authentication method and device, electronic equipment, storage medium and program product
By randomly selecting questions from a question database, obtaining user answers for semantic analysis and feature extraction, and using a latent variable model to generate a unique authentication identifier, the problem of insufficient recognition accuracy in existing identity authentication methods is solved, achieving efficient, secure, and fair identity verification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-17
- Publication Date
- 2026-03-27
AI Technical Summary
Existing identity authentication methods are difficult to achieve efficient, secure, and fair identity verification, and they also suffer from insufficient recognition accuracy.
By randomly selecting multiple questions from a question database, obtaining user answers, performing semantic analysis and feature extraction, using a latent variable model for feature enhancement, generating a unique authentication identifier, and performing identity authentication by similarity matching with a preset reference authentication identifier.
It improves the accuracy, security, and fairness of identity authentication, ensures the uniqueness and reliability of authentication identifiers, and prevents data leakage and abuse.
Smart Images

Figure CN121744281A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computer technology, and in particular to technologies such as artificial intelligence, big data, security, cloud computing, big data and edge computing. Specifically, it relates to identity authentication methods, devices, electronic devices, storage media and program products, applicable to a variety of identity authentication scenarios. Background Technology
[0002] In the digital age, ensuring the authenticity and legitimacy of user identities is the first line of defense for information system security. Identity authentication technology, as the foundation of access control, focuses on verifying the crucial claim of "who the user is." Mainstream identity authentication methods include: biometric-based authentication (such as fingerprint recognition, facial recognition, iris recognition, and voiceprint recognition) and behavioral-based authentication (such as keyboard input and mouse movement). Summary of the Invention
[0003] This disclosure provides identity authentication methods, devices, electronic devices, storage media, and program products that can capture potential characteristics through user responses and generate unique authentication identifiers based on these characteristics, thereby achieving efficient, secure, and fair identity authentication.
[0004] In a first aspect, embodiments of this disclosure provide an identity authentication method, including: Multiple first questions are randomly selected from a question database, and the questions in the question database cover multiple information dimensions; Obtain the user's answers to the extracted first questions; Semantic analysis and feature extraction are performed on the user's answer to obtain key answer features, which include one or more of the following: semantic features, sentiment features, and grammatical structure features. The key features of the answer are enhanced by a latent variable model, and the enhanced feature vector is used as the authentication identifier to be verified. The authentication identifier to be verified is matched with a preset reference authentication identifier for similarity to authenticate the user's identity.
[0005] Secondly, embodiments of this disclosure provide an identity authentication device, comprising: The question extraction module is used to randomly extract multiple first questions from a question library, wherein the questions in the question library cover multiple information dimensions; The answer acquisition module is used to acquire the user's answers to the extracted multiple first questions; The semantic analysis and feature extraction module is used to perform semantic analysis and feature extraction on the user's answer content to obtain key answer features, which include one or more of the following: semantic features, sentiment features, and grammatical structure features. The authentication identifier generation module is used to enhance the key features of the answer through a latent variable model, and use the enhanced feature vector as the authentication identifier to be verified. The identity authentication module is used to perform similarity matching between the authentication identifier to be verified and the preset reference authentication identifier in order to authenticate the user's identity.
[0006] Thirdly, embodiments of this disclosure provide an electronic device, including: One or more processors; The processor is used to invoke instructions to cause the electronic device to perform the method described in the first aspect above.
[0007] Fourthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on an electronic device, cause the electronic device to perform the method described in the first aspect above.
[0008] Fifthly, embodiments of this disclosure provide a program product including at least one of a program and instructions, wherein when the program and instructions are executed by an electronic device, they implement the steps of the method described in the first aspect.
[0009] According to the technical solution disclosed herein, by performing semantic analysis and feature extraction on user answers and combining latent variable modeling to capture latent features in user answers, the recognition accuracy can be improved, and the uniqueness, security and fairness of authentication can be enhanced.
[0010] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0011] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.
[0012] Figure 1 This is a flowchart illustrating an identity authentication method according to an exemplary embodiment.
[0013] Figure 2 This is a flowchart illustrating an identity authentication method according to an exemplary embodiment.
[0014] Figure 3 This is a block diagram illustrating an identity authentication device according to an exemplary embodiment.
[0015] Figure 4 This is a schematic diagram of the architecture of a system for implementing identity authentication, according to an exemplary embodiment.
[0016] Figure 5 This is a block diagram of an electronic device according to an embodiment of the present disclosure. Detailed Implementation
[0017] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0018] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0019] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0020] It should be noted that the acquisition, transmission, storage, use, and processing of data in this disclosed technical solution comply with the relevant provisions of national laws and regulations and do not violate public order and good morals.
[0021] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this disclosure are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0022] It is worth noting that in the embodiments disclosed herein, certain software, components, models, and other existing solutions in the industry may be mentioned. These should be considered as exemplary, and their purpose is only to illustrate the feasibility of implementing the technical solutions disclosed herein. However, this does not mean that the applicant has used or necessarily used such solutions.
[0023] The following description, with reference to the accompanying drawings, describes an authentication method, apparatus, electronic device, storage medium, and program product according to embodiments of the present disclosure.
[0024] It should be noted that the entity executing the identity authentication method in this embodiment of the disclosure may be an identity authentication device, which may be implemented by software and / or hardware, and may be configured in an electronic device, which may include a terminal or a server.
[0025] Figure 1 This is a flowchart illustrating an identity authentication method according to an exemplary embodiment. For example... Figure 1 As shown, the authentication method may include, but is not limited to, the following steps.
[0026] In step 101, multiple first questions are randomly selected from the question bank.
[0027] In the embodiments of this disclosure, the questions in the aforementioned question bank can cover multiple information dimensions. For example, considering the influence of multiple fields such as security, psychology, anthropology, sociology, identification and authentication, and medicine, multiple questions can be designed, covering multiple information dimensions, to ensure the uniqueness and fairness of the identification. For instance, as shown in Table 1, the question bank may include multiple questions covering multiple different information dimensions. The question bank may also include answer requirements, requiring each answer to meet at least a word count requirement (e.g., 30-50 words) to ensure sufficient information.
[0028] Table 1: Example Table of Question Bank
[0029] The question bank design can be categorized as follows: By designing questions that cover multiple information dimensions (including personal experiences, values, interests, and preferences), each question can provide sufficient information. Optimizing the question design to increase the information content of each question can reduce the number of questions. It is important to emphasize that each question provides sufficient information to ensure that user answers also provide enough information. This allows for the generation of unique authentication identifiers for identity verification. The amount of information required for each question can be related to the global population; for example, assuming a global population of 8 billion (…),... N =8×10 9 The amount of information needed to uniquely identify a person I It can be calculated using the information content formula: I = log 2( N )= log 2(8×10⁹) ≈ 33 bits. Assume each question provides the following information: I qTaking a question bank containing 10 questions as an example, the total information content of the 10 questions is: I 总 =10× I q In order to satisfy I 总 ≥33 bits, each question needs to provide at least I q =3.3 bits of information.
[0030] In embodiments of this disclosure, when authentication is required, multiple first questions can be randomly selected from a question library. For example, when authentication is required, five questions can be randomly selected from the question library and provided to the user for answering. Optionally, answer requirements for these questions can also be provided to the user, allowing the user to answer the corresponding questions according to these requirements, thereby ensuring that the user's answers provide more information.
[0031] In step 102, the user's answers to the extracted first questions are obtained.
[0032] In embodiments of this disclosure, multiple first questions extracted from a question bank can be provided to the user to facilitate the user's answering of these questions. The user's answers to the multiple first questions can be obtained. The user's answers can be in the form of text input, but are not limited to this; for example, they can also be in the form of voice input.
[0033] In step 103, semantic analysis and feature extraction are performed on the user's answer to obtain key features of the answer.
[0034] In the embodiments of this disclosure, the key features of the answer may include, but are not limited to, one or more of the following: semantic features, sentiment features, and syntactic structure features. For example, the key features of the answer may include semantic features. Alternatively, for example, the key features of the answer may include semantic features, sentiment features, or may also include syntactic structure features, etc.
[0035] In some embodiments, a large model can be used to perform semantic analysis and feature extraction on the user's answer content to obtain key features of the answer. This large model can be a BERT (Bidirectional Encoder Representations from Transformers, a pre-trained language model), but is not limited to it; for example, it can also be a GPT (Generative Pre-trained Transformer) model, etc. For instance, by using a large model to perform semantic analysis and feature extraction on the user's answer content, deep semantic information can be extracted from the user's answer, thereby ensuring the uniqueness and reliability of the authentication identifier.
[0036] In step 104, the key features of the answer are enhanced using a latent variable model, and the enhanced feature vector is used as the authentication identifier to be verified.
[0037] In the embodiments of this disclosure, latent variable models can be used to enhance the key features of user responses, obtain latent variables, capture latent features in user responses, and generate authentication identifiers to be verified. The latent variable model can further increase the information content of each question, effectively improving recognition accuracy.
[0038] In the embodiments of this disclosure, the latent variable model can be a variational autoencoder (VAE), but is not limited to this; for example, the latent variable model can also be a generative adversarial network (GAN) model. For instance, taking a VAE model as the latent variable model, the encoder in the VAE model can map the key features of the user's answer to the latent space, and the decoder in the VAE model can reconstruct the feature vector. The reconstructed feature vector is then used as the authentication identifier to be verified. That is, through the non-invertibility of the latent variable model, the key features of the user's answer content are converted into an irreversible authentication identifier.
[0039] It is worth noting that after obtaining the key features of the user's answer, this disclosure can enhance these key features using a latent variable model to obtain latent variables, thereby generating an authentication identifier. This means that the encoding process of a latent variable model (such as VAE) is irreversible, preventing attackers from reverse-engineering the original answer content through the authentication identifier vector. Latent variable models not only achieve feature dimensionality compression but also capture deeper psychological features through latent space learning, which can be used as a unique identifier for identity authentication.
[0040] In some embodiments, the authentication identifier in this disclosure may also be referred to as a "heartprint (HP)".
[0041] In step 105, the authentication identifier to be verified is matched with a preset reference authentication identifier for similarity matching in order to authenticate the user's identity.
[0042] In the embodiments of this disclosure, the similarity between the authentication identifier to be verified and a preset reference authentication identifier can be calculated. For example, a similarity measurement method (such as cosine similarity, but not limited to this) can be used to calculate the similarity between the authentication identifier to be verified and the reference authentication identifier. If the similarity is greater than or equal to a similarity threshold, the user's identity authentication can be considered successful; if the similarity is less than the similarity threshold, the user's identity authentication can be considered unsuccessful.
[0043] It should be noted that in some embodiments, the aforementioned similarity threshold can be set based on experimental data. For example, if experiments show that the average similarity of matched users is 0.8 and the average similarity of non-matching users is 0.2, then T=0.6 can be set. The false recognition rate (FAR) and false negative rate (FRR) can be balanced through optimization using experimental data to determine whether user identities match. Here, the false recognition rate (FAR) refers to the probability of mistaking a non-matching user for a matched user. The false negative rate (FRR) refers to the probability of mistaking a matched user for a non-matching user. When the false recognition rate (FAR) equals the false negative rate (FRR), the similarity threshold can be optimized.
[0044] It should also be noted that the aforementioned reference authentication identifier can be generated during the user registration phase. This generated identifier can be stored for use in subsequent identity authentication phases. Optionally, in some embodiments, during the user registration phase, multiple questions can be randomly selected from a question database and provided to the user for answering. The user's answers to the selected questions are obtained, and semantic analysis and feature extraction are performed on the answers to obtain key features. These key features are then enhanced using a latent variable model, and the enhanced feature vector is used as the reference authentication identifier. This reference authentication identifier is stored for use in subsequent identity authentication phases. In other words, the generation method of the reference authentication identifier is similar to the generation method of the identifier to be authenticated described above; please refer to the implementation method for generating the identifier to be authenticated described above, which will not be repeated here.
[0045] To further enhance security and prevent data leakage and misuse, the reference authentication identifier can be stored in encrypted form. For example, a symmetric encryption algorithm, such as AES (Advanced Encryption Standard), can be used to encrypt the reference authentication identifier, resulting in ciphertext. Storing this ciphertext in a database improves the security of the reference authentication identifier. During the authentication phase, the ciphertext can be retrieved from the database and decrypted to facilitate similarity matching with the authentication identifier to be verified.
[0046] To ensure the uniqueness and reliability of authentication identifiers, the information content of user responses can be calculated in real time. This information content can serve as an auxiliary evaluation metric for calculating the similarity between the authentication identifier to be verified and the reference authentication identifier. Optionally, in some embodiments, word segmentation and word frequency statistics are performed on the user's response content to obtain the information entropy of the user's response content; the information content of the user's response content is calculated using information entropy and latent variable models, and this information content can serve as an auxiliary evaluation metric for authentication identifier similarity matching.
[0047] For example, a user's answer can be broken down into words or phrases, and the frequency of each word in the answer can be calculated to obtain word frequency statistics. The information entropy of the user's answer can then be calculated using word segmentation and word frequency statistics. This information entropy, combined with a latent variable model, allows for real-time calculation of the information content of the user's answer. For instance, the latent variable model can be used to extract latent features from the user's answer (which can be viewed as the probability distribution of words in the answer). These latent features, combined with the information entropy of the answer, can then be used to calculate the information content using the information content calculation formula. This information content can serve as an auxiliary evaluation indicator for authentication identifier similarity matching. For example, a low information content may indicate that the authentication identifier similarity calculation result is not valid.
[0048] Optionally, in some embodiments, if the amount of information in a user's response does not meet a preset information content condition, questions can be extracted from a question database to dynamically increase the number of questions. The added questions can be provided to the user, and user responses can continue to be acquired, thereby ensuring that the user's responses provide sufficient information, thus ensuring that the generated verification identifier is valid and satisfies uniqueness and reliability.
[0049] In the above embodiments, by performing semantic analysis and feature extraction on user answers and combining latent variable modeling to capture latent features in user answers, the recognition accuracy can be improved, and the uniqueness, security and fairness of authentication can be enhanced.
[0050] To further improve the security and reliability of identity authentication, multimodal data can be used for authentication. Figure 2 This is a flowchart illustrating an identity authentication method according to an exemplary embodiment. For example... Figure 2 As shown, the authentication method may include, but is not limited to, the following steps.
[0051] In step 201, multiple first questions are randomly selected from the question library.
[0052] In the embodiments of this disclosure, the questions in the aforementioned question bank may cover multiple information dimensions.
[0053] Optionally, step 201 can be implemented using any of the implementation methods in the various embodiments of this disclosure. This disclosure does not limit this implementation and will not elaborate further.
[0054] In step 202, the user's answers to the extracted first questions are obtained.
[0055] Optionally, step 202 can be implemented using any of the implementation methods in the various embodiments of this disclosure. This disclosure does not limit this implementation and will not elaborate further.
[0056] In step 203, semantic analysis and feature extraction are performed on the user's answer to obtain key features of the answer.
[0057] In the embodiments disclosed herein, the key features of the above-mentioned answer may include, but are not limited to, one or more of the following: semantic features, emotional features, and grammatical structure features.
[0058] Optionally, step 203 can be implemented using any of the implementation methods in the various embodiments of this disclosure. This disclosure does not limit this implementation and will not elaborate further.
[0059] In step 204, the user's multimodal features are obtained. The multimodal features include one or more of the following: voice features and image features.
[0060] In some embodiments, the multimodal features may include speech features. For example, when a user's answer is input via speech, the speech input during the question can be directly used for audio feature extraction to obtain the speech features. Alternatively, for example, the speech features may also be generated based on specific speech content input by the user. For instance, during the authentication phase, specific content is provided to the user and they are asked to read it aloud. This specific speech content is then obtained, and audio features are extracted from it to obtain the speech features. These speech features are then used as multimodal features for fusion with the aforementioned key answer features.
[0061] In some embodiments, the multimodal features may include image features. For example, an image may be presented to a user, who may be asked to select specified image elements within the image. Features from this process may be extracted as image features and then fused with the aforementioned key answer features.
[0062] In some embodiments, the multimodal features may include speech features and image features. The methods for obtaining the speech features and image features can be found in the relevant descriptions of the above examples, and will not be repeated here.
[0063] It should be noted that in some embodiments, steps 203 and 204 above can be executed simultaneously or in an interchangeable order.
[0064] It should also be noted that in some embodiments, when the amount of information in the user's answer does not meet the preset information amount condition, an authentication identifier can be generated based on the key features of the user's answer and combined with the user's multimodal features, which can improve the effectiveness and uniqueness of the authentication identifier.
[0065] In step 205, the multimodal features and key answer features are fused to obtain fused features, and the fused features are enhanced using a latent variable model. The enhanced feature vector is then used as the authentication identifier to be verified.
[0066] In the embodiments of this disclosure, the multimodal features can be fused with key answer features. For example, the multimodal features and key answer features can be concatenated, and the resulting feature vector can be used as the fused feature. The fused feature can be enhanced using a latent variable model to obtain latent variables, capture latent features, and generate an authentication identifier to be verified.
[0067] In step 206, the authentication identifier to be verified is matched with a preset reference authentication identifier for similarity matching in order to authenticate the user's identity.
[0068] Optionally, step 206 can be implemented using any of the implementation methods in the various embodiments of this disclosure. This disclosure does not limit this implementation and will not elaborate further.
[0069] In the above embodiments, by combining user responses with multimodal data such as voice and images, the recognition accuracy and applicability can be further improved, and the security and reliability of identity authentication can be further enhanced.
[0070] To prevent data leakage and ensure privacy protection, alternatively, in some embodiments, differential privacy technology can be used to process personal data during the data analysis process to protect privacy. For example, noise can be added to protect user privacy and ensure that individual data is unidentifiable during the data analysis process.
[0071] To improve long-term applicability, a dynamic update mechanism can be used to update the user's reference authentication identifier. Optionally, in some embodiments, the aforementioned reference authentication identifier can be dynamically updated in the following ways: when the user's identity authentication is successful, it is determined that the authentication identifier update cycle has arrived, multiple second questions are randomly selected from the question database, and the user's answers to the second questions are obtained to update the reference authentication identifier; or, when the user's identity authentication is successful, it is determined that the user's new answers to the questions in the question database do not match the historical answers, and the reference authentication identifier is updated based on the new answers.
[0072] For example, users can be allowed to periodically update their reference authentication identifier. That is, when user authentication is successful and the authentication identifier update cycle is reached, multiple second questions can be randomly selected from the question library, and the user's answers to the second questions can be obtained. The key features of the user's answers can be enhanced using a latent variable model, and the enhanced feature vector can be used to update the user's reference authentication identifier. For example, the enhanced feature vector can be directly stored as the user's new reference authentication identifier for identity authentication.
[0073] For example, during the user registration phase or the historical identity authentication phase (if the user's identity authentication is successful), the user's answers to questions can be stored. In this way, when the user wants to update the answers to questions in the question database after the user's identity authentication is successful, the user's new answers to questions in the question database can be obtained. If the new answers do not match the stored historical answers (e.g., the semantic similarity is less than a threshold), semantic analysis and feature extraction can be performed on the new answers to obtain key features of the answers. The key features of the answers can then be enhanced using a latent variable model, and the enhanced feature vector can be used to update the user's reference authentication identifier.
[0074] To improve long-term applicability, a dynamic update mechanism can be used to update the question database. Optionally, in some embodiments, the question database can be dynamically updated through one or more of the following methods: collecting user feedback on questions and authentication processes in the question database and optimizing the question database based on the feedback; dynamically adjusting the question database based on the information content of user answers and the recognition accuracy of authentication identifiers.
[0075] For example, user feedback on questions in the question bank and the authentication process can be collected, and the question bank can be optimized based on this feedback. For instance, the feedback could be user preferences for questions in the question bank; if a user doesn't like answering a question, it can be removed from the question bank. Alternatively, if a user adds a question they like, it can be added to the question bank, provided that the question meets relevant requirements (such as being legal and compliant and providing a certain amount of information).
[0076] For example, the question database can be dynamically adjusted based on the information content of the user's answer and the recognition accuracy of the authentication identifier. For instance, if the information content of the user's answer is less than a threshold, and / or the recognition accuracy of the authentication identifier is lower than a preset threshold, new questions can be designed by incorporating information from multiple fields such as security, psychology, anthropology, sociology, identification and authentication, and medicine to update the question database. Alternatively, the question database can be optimized based on the changing trends of the information content and / or the changing trends of the recognition accuracy of the user's answer, adjusting the question weights and frequencies of occurrence.
[0077] It is worth noting that in this disclosure, latent variable models (such as VAEs) play a core role in the authentication identifier generation stage and can also play a supporting role in the question base update (optimization) stage. In the question base update (optimization) stage, latent variable models are used to analyze the information distribution of different questions, evaluate the discriminative power of questions in the latent space, and optimize the question design.
[0078] It is also worth noting that in this disclosure, information content is a full-process indicator, spanning multiple stages, and relying on information entropy calculation at every stage from problem design to authentication updates. The specific applications of information content at each stage are as follows: (1) Question bank design phase: Calculate the theoretical information content for each problem to ensure that the uniqueness requirement is met (e.g., ≥3.3 bits for each problem). The rationality of the problem design is evaluated using information entropy.
[0079] (2) User registration stage: The system calculates the actual amount of information in the user's response in real time. If insufficient information is detected (e.g., <3.3 bits), the system can dynamically increase the number of questions, prompt the user to enrich their response, and supplement information by combining multimodal data.
[0080] (3) Identity authentication stage: Continuously monitor changes in the amount of information during the authentication process as an auxiliary evaluation indicator for similarity calculation.
[0081] (4) Dynamic update stage: Optimize the question database based on the trend of information volume changes, and adjust the question weights and frequency of occurrence.
[0082] As can be seen, the latent variable model is the core of authentication identifier generation, responsible for converting key features of user responses into irreversible authentication identifiers. Information content is a comprehensive indicator, spanning multiple stages, from question design to authentication updates, all relying on information entropy calculation. Working together, the latent variable model ensures feature quality, while information content ensures authentication reliability, jointly constructing the system's security foundation. This design accurately identifies user identities while effectively protecting user privacy and resisting various attack methods.
[0083] Figure 3 This is a block diagram illustrating an identity authentication device according to an exemplary embodiment. Figure 3 As shown, the identity authentication device may include: a question extraction module 301, an answer acquisition module 302, a semantic analysis and feature extraction module 303, an authentication identifier generation module 304, and an identity authentication module 305.
[0084] Among them, the question extraction module 301 is used to randomly extract multiple first questions from the question library, and the questions in the question library cover multiple information dimensions.
[0085] The answer acquisition module 302 is used to acquire the user's answers to multiple extracted first questions.
[0086] The semantic analysis and feature extraction module 303 is used to perform semantic analysis and feature extraction on the user's answer content to obtain key features of the answer. The key features of the answer include one or more of the following: semantic features, sentiment features, and grammatical structure features.
[0087] The authentication identifier generation module 304 is used to enhance the key features of the answer through a latent variable model, and use the enhanced feature vector as the authentication identifier to be verified.
[0088] The identity authentication module 305 is used to perform similarity matching between the authentication identifier to be verified and the preset reference authentication identifier in order to authenticate the user's identity.
[0089] In some embodiments, the identity authentication device may further include an information content calculation module. This information content calculation module is used to: perform word segmentation and word frequency statistics on the user's response content to obtain the information entropy of the user's response content; and calculate the information content of the user's response content using information entropy and a latent variable model, with the information content serving as an auxiliary evaluation indicator for authentication identifier similarity matching.
[0090] In some embodiments, the question extraction module is further configured to: extract questions from the question database to dynamically increase the number of questions when the amount of information in the answer content does not meet the preset information amount condition.
[0091] In some embodiments, the identity authentication device may further include a multimodal feature acquisition module. This multimodal feature acquisition module is used to: acquire the user's multimodal features, which include one or more of the following: voice features, image features. In embodiments of this disclosure, the authentication identifier generation module is used to: fuse the multimodal features with key answer features to obtain fused features, and enhance the fused features using a latent variable model, using the enhanced feature vector as the authentication identifier to be verified.
[0092] In some embodiments, the reference authentication identifier is dynamically updated in the following ways: when user authentication is successful, it is determined that the authentication identifier update cycle has arrived, multiple second questions are randomly selected from the question database, and the user's answers to the second questions are obtained to update the reference authentication identifier; or, when user authentication is successful, it is determined that the user's new answers to the questions in the question database do not match the historical answers, and the reference authentication identifier is updated according to the new answers.
[0093] In some embodiments, the question database is dynamically updated through one or more of the following methods: collecting user feedback on questions and authentication processes in the question database and optimizing the question database based on the feedback; dynamically adjusting the question database based on the information content of user answers and the recognition accuracy of authentication identifiers.
[0094] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0095] Figure 4 This is a schematic diagram of the architecture of a system for implementing identity authentication, according to an exemplary embodiment. Figure 4As shown, the system may include a user registration module, an identity authentication module, a dynamic update module, a large model core module, a security and privacy module, and a data analysis module. Optionally, the identity authentication system may also include a user feedback module. The user registration module is responsible for generating a question database and, in conjunction with the large model core module, generating a reference authentication identifier, which can be stored encrypted. The identity authentication module can randomly select questions from the question database, obtain user answers, and send these answers to the large model core module for feature extraction and authentication identifier generation. The large model core module includes a large model (such as the BERT model) and a latent variable model (such as a VAE). The large model performs semantic analysis and feature extraction on the user answers to obtain key features; the latent variable model enhances these key features and uses the enhanced feature vector as the authentication identifier. The identity authentication module calculates the similarity between the identifier to be verified generated by the large model core module and the reference authentication identifier generated during user registration for user authentication. The security and privacy module can encrypt data, such as encrypting the reference authentication identifier, and can use differential privacy technology to protect the privacy of data during the data analysis process. The dynamic update module is responsible for periodically updating the reference authentication identifier and the issue database. The data analysis module is responsible for information calculation and issue optimization. The user feedback module is responsible for collecting user feedback and user behavior information, and analyzing the user feedback and behavior information to assist the dynamic update module in updating the reference authentication identifier and the issue database.
[0096] According to embodiments of this disclosure, this disclosure also provides an electronic device and a readable storage medium.
[0097] like Figure 5 The diagram shown is a block diagram of an electronic device according to an embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0098] like Figure 5As shown, the electronic device includes one or more processors 501, a memory 502, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components are interconnected via different buses and can be mounted on a common motherboard or otherwise as required. The processors can process instructions executed within the electronic device, including instructions stored in or on memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In other embodiments, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple electronic devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 5 Take a processor 501 as an example.
[0099] The memory 502 is the non-transitory computer-readable storage medium provided in this disclosure. The memory stores instructions executable by at least one processor to cause the at least one processor to perform the authentication method provided in this disclosure. The non-transitory computer-readable storage medium of this disclosure stores computer instructions for causing a computer to perform the authentication method provided in this disclosure.
[0100] Memory 502, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as the program instructions / modules corresponding to the authentication method in the embodiments of this disclosure (e.g., appendix). Figure 3 The module shown comprises a question extraction module 301, an answer acquisition module 302, a semantic analysis and feature extraction module 303, an authentication identifier generation module 304, and an identity authentication module 305. The processor 501 executes various server functions and data processing by running non-transient software programs, instructions, and modules stored in the memory 502, thereby implementing the identity authentication method described in the above method embodiments.
[0101] Memory 502 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device. Furthermore, memory 502 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory 502 may optionally include memory remotely located relative to processor 501, and these remote memories can be connected to the electronic device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0102] The electronic device may also include an input device 503 and an output device 504. The processor 501, memory 502, input device 503, and output device 504 can be connected via a bus or other means. Figure 5 Taking the example of a connection between China and Israel via a bus.
[0103] Input device 503 can receive input numerical or character information, and generate key signal inputs related to user settings and function control of the electronic device, such as touch screens, keypads, mice, trackpads, touchpads, joysticks, one or more mouse buttons, trackballs, joysticks, etc. Output device 504 may include display devices, auxiliary lighting devices (e.g., LEDs), and haptic feedback devices (e.g., vibration motors). The display device may include, but is not limited to, liquid crystal displays (LCDs), light-emitting diode (LED) displays, and plasma displays. In some embodiments, the display device may be a touch screen.
[0104] Various implementations of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, application-specific integrated circuits (ASICs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0105] These computational programs (also referred to as programs, software, software applications, or code) include machine instructions for a programmable processor and can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. As used herein, the terms “machine-readable medium” and “computer-readable medium” refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device (PLD)) used to provide machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term “machine-readable signal” refers to any signal used to provide machine instructions and / or data to a programmable processor.
[0106] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0107] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), the Internet, and blockchain networks.
[0108] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0109] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0110] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
Claims
1. An identity authentication method, characterized by, include: Multiple first questions are randomly selected from a question database, and the questions in the question database cover multiple information dimensions; Obtain the user's answers to the extracted first questions; Semantic analysis and feature extraction are performed on the user's answer to obtain key answer features, which include one or more of the following: semantic features, sentiment features, and grammatical structure features. The key features of the answer are enhanced by a latent variable model, and the enhanced feature vector is used as the authentication identifier to be verified. The authentication identifier to be verified is matched with a preset reference authentication identifier for similarity to authenticate the user's identity.
2. The method of claim 1, wherein, The method further includes: The user's answer content is segmented into words and word frequency is statistically analyzed to obtain the information entropy of the user's answer content; The information content of the user's answer is calculated using the information entropy and the latent variable model, and this information content serves as an auxiliary evaluation indicator for authentication identifier similarity matching.
3. The method according to claim 2, characterized in that, The method further includes: If the amount of information in the response does not meet the preset information content condition, questions are extracted from the question bank to dynamically increase the number of questions.
4. The method according to claim 1, characterized in that, The method further includes: The user's multimodal features are obtained, including one or more of the following: voice features and image features; The step of enhancing the key features of the answer using a latent variable model, and using the enhanced feature vector as the authentication identifier to be verified, includes: The multimodal features are fused with the key features of the answer to obtain fused features. The fused features are then enhanced using the latent variable model, and the enhanced feature vector is used as the authentication identifier to be verified.
5. The method according to claim 1, characterized in that, The reference authentication identifier is dynamically updated in the following ways: If the user identity authentication is successful, determine that the authentication identifier update cycle has arrived, randomly select multiple second questions from the question database, and obtain the user's answers to the second questions to update the reference authentication identifier; or, If the user's identity authentication is successful, it is determined that the user's new answer to a question in the question database does not match the historical answer content, and the reference authentication identifier is updated according to the new answer content.
6. The method according to any one of claims 1-5, characterized in that, The question bank is dynamically updated through one or more of the following methods: Collect user feedback on questions and authentication processes in the question bank, and optimize the question bank based on the feedback. The question database is dynamically adjusted based on the amount of information in the user's answer and the recognition accuracy of the authentication identifier.
7. An identity authentication device, characterized in that, include: The question extraction module is used to randomly extract multiple first questions from a question library, wherein the questions in the question library cover multiple information dimensions; The answer acquisition module is used to acquire the user's answers to the extracted multiple first questions; The semantic analysis and feature extraction module is used to perform semantic analysis and feature extraction on the user's answer content to obtain key answer features, which include one or more of the following: semantic features, sentiment features, and grammatical structure features. The authentication identifier generation module is used to enhance the key features of the answer through a latent variable model, and use the enhanced feature vector as the authentication identifier to be verified. The identity authentication module is used to perform similarity matching between the authentication identifier to be verified and the preset reference authentication identifier in order to authenticate the user's identity.
8. An electronic device, characterized in that, include: One or more processors; The processor is used to invoke instructions to cause the electronic device to perform the method of any one of claims 1-6.
9. A storage medium storing instructions, characterized in that, When the instructions are executed on an electronic device, the electronic device causes the electronic device to perform the method of any one of claims 1-6.
10. A program product comprising at least one of a program and instructions, characterized in that, When at least one of the programs or instructions is executed by an electronic device, it implements the steps of the method according to any one of claims 1-6.