Identity authentication method, device, equipment, storage medium and product
By constructing an evidence chain information database and integrating authentication identifiers for faces, devices, and applications, the security issues of single-subject identity authentication technology are solved, achieving highly secure and reliable multimodal identity authentication and improving the security and reliability of identity authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD
- Filing Date
- 2024-12-03
- Publication Date
- 2026-06-05
Smart Images

Figure CN122153860A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of identity authentication technology, and in particular to identity authentication methods, devices, equipment, storage media and products. Background Technology
[0002] The mobile internet, public security, and cybersecurity supervision sectors all have significant demands for highly reliable identity authentication. Currently, there is research on various single-entity authentication technologies. These include: 1) human-based biometric authentication, which relies on facial, iris, and voiceprint features to identify the uniqueness of the individual; 2) device-based authentication, which uses various device parameters to construct a device fingerprint representing the user's unique ID; and 3) application-based authentication, which uses various application parameters to construct an application fingerprint representing the user's unique ID. However, these single-entity authentication technologies still have several problems. First, human-based biometric authentication, such as facial recognition (the most widely used biometric authentication technology), relies solely on visual features, which has limited dimensions and is vulnerable to attacks, with numerous cases of breaches. Second, device-based authentication relies on device fingerprints, which have a recognized weakness: susceptibility to environmental attacks. Third, application-based authentication faces the same problems. In summary, the existing single-subject representation has limited dimensions. Relying solely on the identity authentication features of a single subject is insufficient to achieve highly secure and reliable authentication capabilities. It still carries the risk of being compromised and cannot meet the application scenarios that require high reliability and high security. Therefore, it is urgent to research new authentication technologies to address the aforementioned pain points. Summary of the Invention
[0003] The main purpose of this application is to provide an identity authentication method, apparatus, device, storage medium, and product, which aims to solve the technical problem of low reliability of existing single-subject authentication identity identifiers.
[0004] To achieve the above objectives, this application proposes an identity authentication method, which includes:
[0005] An evidence chain information database is constructed based on facial data, device data, and application data.
[0006] Based on the evidence chain information database and the preset identity authentication calculation model, the face authentication identifier, device authentication identifier, and application authentication identifier are obtained.
[0007] According to the authentication identifier fusion strategy, the face authentication identifier, the device authentication identifier, and the application right identifier are fused to obtain the target authentication identifier, and the encrypted target authentication identifier is stored in the user identification card.
[0008] When an authentication request is requested, the current authentication identifier is sent to the user identification card, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted authentication result.
[0009] The target identity authentication result is determined based on the encrypted authentication result.
[0010] In one embodiment, the step of constructing an evidence chain information database based on facial source data, device source data, and application source data includes:
[0011] Data cleaning is performed on face source data, device source data, and application source data to obtain face cleaned data, device cleaned data, and application cleaned data.
[0012] Based on the structured information extracted from the fields, the face cleaning data, the device cleaning data, and the application cleaning data are respectively extracted to obtain face feature data, device feature data, and application feature data;
[0013] An evidence chain information database is constructed based on the facial feature data, the device feature data, and the application feature data.
[0014] In one embodiment, the step of obtaining the face authentication identifier, device authentication identifier, and application authentication identifier based on the evidence chain information database and the preset identity authentication calculation model includes:
[0015] The evidence chain information database is processed based on the embedded vector network in the preset identity authentication calculation model to obtain face vector data, device vector data and application vector data.
[0016] Based on the backbone network in the preset identity authentication calculation model, feature extraction is performed on the face vector data, the device vector data and the application vector data to obtain face characteristic data, device characteristic data and application characteristic data.
[0017] Based on the dense network in the preset identity authentication calculation model, dense calculations are performed on the face feature data, the device feature data, and the application feature data to obtain the face authentication identifier, the device authentication identifier, and the application authentication identifier.
[0018] In one embodiment, the step of fusing the face authentication identifier, the device authentication identifier, and the application right identifier according to the authentication identifier fusion strategy to obtain the target authentication identifier includes:
[0019] The face authentication code, the device authentication code, and the application right code are densely processed according to the authentication code fusion strategy to obtain dense face features, dense device features, and dense application features.
[0020] For the dense features of the face and the dense features of the device,
[0021] In one embodiment, the step of sending the current authentication identifier to the user identification card when an authentication request is requested includes:
[0022] When an authentication request is requested, obtain the current facial information, current device information, and current application information;
[0023] The current authentication identifier is calculated by performing identifier code generation on the current face information, the current device information, and the current application information according to the preset identifier code generation model.
[0024] Send the current authentication identifier to the user identification card.
[0025] In one embodiment, after the step of fusing the face authentication identifier, the device authentication identifier, and the application right identifier according to the authentication identifier fusion strategy to obtain the target authentication identifier, the method further includes:
[0026] The target authentication identifier is encrypted according to a preset encryption strategy to obtain the encrypted target authentication identifier.
[0027] The encrypted target authentication code is transmitted to the user identification card through a preset data transmission channel.
[0028] Furthermore, to achieve the above objectives, this application also proposes an identity authentication device, which includes:
[0029] The module is used to build an evidence chain information database based on face source data, device source data, and application source data;
[0030] The calculation module is used to obtain the face authentication identifier, device authentication identifier, and application authentication identifier based on the evidence chain information database and the preset identity authentication calculation model.
[0031] The fusion module is used to fuse the face authentication code, the device authentication code and the application right code according to the authentication code fusion strategy to obtain the target authentication code, and store the encrypted target authentication code in the user identification card.
[0032] The transmission module is used to send the current authentication identifier to the user identification card when there is an authentication request, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted authentication result.
[0033] The authentication module is used to determine the authentication result of the target identity based on the encrypted authentication result.
[0034] In addition, to achieve the above objectives, this application also proposes an identity authentication device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the identity authentication method as described above.
[0035] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the identity authentication method described above.
[0036] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the identity authentication method described above.
[0037] This application constructs an evidence chain information database based on facial source data, device source data, and application source data; obtains facial authentication identifiers, device authentication identifiers, and application authentication identifiers based on the evidence chain information database and a preset identity authentication calculation model; merges these multiple authentication identifiers to obtain a target authentication identifier, and stores the encrypted target authentication identifier in a user identification card; sends the current authentication identifier to the user identification card, and the user identification card compares the current authentication identifier with the encrypted target authentication identifier; determines the target identity authentication result based on the encrypted identity verification result fed back by the user identification card. By fusing the identity identifier features of face, device, and application, and then performing identity authentication comparison, high security and reliability are achieved throughout the entire chain from generation, storage, communication transmission, to authentication comparison. Attached Figure Description
[0038] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0039] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 This is a flowchart illustrating the identity authentication method of this application in Implementation Example 1;
[0041] Figure 2 A schematic diagram of the overall framework of the cross-subject identity authentication ID generation method for mobile terminals provided in Embodiment 1 of the identity authentication method of this application;
[0042] Figure 3 This is a schematic diagram of a single-modal subject identity authentication ID extraction neural network provided in Embodiment 1 of the identity authentication method of this application;
[0043] Figure 4 This is a schematic diagram of the overall framework for cross-subject ID identity authentication comparison provided in Embodiment 1 of the identity authentication method of this application;
[0044] Figure 5 A schematic diagram illustrating the cross-subject ID authentication process based on SDK and SIM collaboration, implemented using the BIP method in Embodiment 1 of the identity authentication method of this application;
[0045] Figure 6 This is a flowchart illustrating the second embodiment of the identity authentication method in this application.
[0046] Figure 7 This is a schematic diagram of a multimodal cross-subject identity authentication ID fusion neural network provided in Embodiment 2 of the identity authentication method of this application;
[0047] Figure 8 This is a schematic diagram of the SIM and SDK secure channel design and the overall framework of SIM secure storage provided in Embodiment 2 of the identity authentication method of this application;
[0048] Figure 9 This is a schematic diagram of the secure channel design and SIM secure storage process for SIM-SDK communication implemented using the BIP method in Embodiment 2 of the identity authentication method of this application.
[0049] Figure 10 This is a schematic diagram of the module structure of the identity authentication device according to an embodiment of this application;
[0050] Figure 11 This is a schematic diagram of the device structure of the hardware operating environment involved in the identity authentication method in the embodiments of this application.
[0051] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0052] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0053] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0054] The main solution of this application embodiment is as follows: An evidence chain information database is constructed based on face source data, device source data, and application source data; face authentication identifier, device authentication identifier, and application authentication identifier are obtained according to the evidence chain information database and a preset identity authentication calculation model; the face authentication identifier, device authentication identifier, and application authentication identifier are fused according to an authentication identifier fusion strategy to obtain a target authentication identifier, and the encrypted target authentication identifier is stored in a user identification card; when an identity authentication request exists, the current authentication identifier is sent to the user identification card, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted identity verification result; the target identity authentication result is determined based on the encrypted identity verification result.
[0055] The mobile internet, public security, and cybersecurity supervision sectors all have significant demands for highly reliable identity authentication. Currently, there is research on various single-entity authentication technologies. These include: 1) human-based biometric authentication, which relies on facial, iris, and voiceprint features to identify the uniqueness of the individual; 2) device-based authentication, which uses various device parameters to construct a device fingerprint representing the user's unique ID; and 3) application-based authentication, which uses various application parameters to construct an application fingerprint representing the user's unique ID. However, these single-entity authentication technologies still have several problems. First, human-based biometric authentication, such as facial recognition (the most widely used biometric authentication technology), relies solely on visual features, which has limited dimensions and is vulnerable to attacks, with numerous cases of breaches. Second, device-based authentication relies on device fingerprints, which have a recognized weakness: susceptibility to environmental attacks. Third, application-based authentication faces the same problems. In summary, the existing single-subject representation has limited dimensions. Relying solely on the identity authentication features of a single subject is insufficient to achieve highly secure and reliable authentication capabilities. It still carries the risk of being compromised and cannot meet the application scenarios that require high reliability and high security. Therefore, it is urgent to research new authentication technologies to address the aforementioned pain points.
[0056] This application constructs an evidence chain information database based on facial source data, device source data, and application source data; obtains facial authentication identifiers, device authentication identifiers, and application authentication identifiers based on the evidence chain information database and a preset identity authentication calculation model; merges these multiple authentication identifiers to obtain a target authentication identifier, and stores the encrypted target authentication identifier in a user identification card; sends the current authentication identifier to the user identification card, and the user identification card compares the current authentication identifier with the encrypted target authentication identifier; determines the target identity authentication result based on the encrypted identity verification result fed back by the user identification card. By fusing the identity identifier features of face, device, and application, and then performing identity authentication comparison, high security and reliability are achieved throughout the entire chain from generation, storage, communication transmission, to authentication comparison.
[0057] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an identity authentication device capable of performing the above functions. The following description uses an identity authentication device as the executing entity, for example, a mobile terminal, to illustrate this embodiment and the subsequent embodiments.
[0058] Based on this, the embodiments of this application provide an identity authentication method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the identity authentication method of this application.
[0059] In this embodiment, the identity authentication method includes steps S10 to S50:
[0060] Step S10: Construct an evidence chain information database based on face source data, device source data, and application source data;
[0061] It should be noted that this embodiment addresses the significant demand for highly reliable identity authentication in fields such as mobile internet, public safety, and cybersecurity supervision. This embodiment proposes a cross-subject identity authentication technology and system device, which uses the telecommunications operator's code as the center, associating and deeply integrating the unique identification features of three subjects—user, device, and application—to generate a multimodal, cross-subject user-unique identity ID. Compared to single-subject authentication, this significantly improves the high-security level of trusted identity authentication capabilities. Furthermore, it proposes a highly secure storage and identity authentication service that collaborates with an SDK (Software Development Kit) and a SIM (Subscriber Identity Module). This combines the high-security storage advantages of the SIM, the high-security communication service of the SIM card and SDK, and the advantage of the complete evidence chain of the multimodal, cross-subject deeply integrated identity authentication ID mentioned above, forming a complete end-to-end highly secure and trusted identity authentication system and authentication service.
[0062] It is understandable that, such as Figure 2 As shown, firstly, a cross-subject raw data evidence chain library is constructed, centered on the telecom operator's code number, through data preprocessing such as association, alignment, cleaning, and processing. Secondly, a deep learning neural network computing model is designed and built to simultaneously calculate unique identity authentication IDs for three single subjects. This model is used to extract face authentication IDs, device authentication IDs, and application authentication IDs from the raw high-dimensional information of faces, devices, and applications, respectively, possessing unique user identity characteristics representing each subject. Then, a fusion algorithm is designed to perform fusion calculations on the three single-subject authentication IDs, resulting in a cross-subject authentication ID. Irreversible encryption is applied to this fused ID for enhanced security. A secure channel is designed between the SDK and the SIM card to enable secure communication and ID transmission. The encrypted authentication ID is then transmitted to the SIM card for storage, completing the registration phase. During the authentication phase, mobile devices collect the customer's facial information, device information, and application information via cameras. The SDK's model engine calculates the customer's current authentication ID in real time and transmits it to the terminal's SIM card. The underlying SIM's computing power is used for matching calculations to verify the consistency of the authentication IDs. Finally, the authentication result is encrypted in the SIM card and transmitted to the APP service. The server decrypts the encrypted result and verifies its validity. The communication method between the SIM and SDK is more secure, reliable, and efficient than public network communication in the cloud.
[0063] It is understandable that facial source data refers to the original image or video data of a user's face, device source data refers to various information of the user's terminal device, application source data refers to various information of the user's application, and the evidence chain information database refers to a database that centrally stores and manages the original data and processing results of each subject in a multimodal cross-subject identity authentication system.
[0064] In practice, the system centers on the telecom operator's code, linking three main entities: people, devices, and applications. It collects original images or structured data fields corresponding to each entity, and after data preprocessing such as association, alignment, cleaning, and processing, constructs a cross-entity original data evidence chain library with the telecom operator's code as the key. This provides the raw feature data for training samples for deep learning models used in identity authentication ID calculation, offering a crucial raw database foundation.
[0065] In one feasible implementation, step S10 may include steps A11 to A13:
[0066] Step A11: Perform data cleaning on the face source data, device source data, and application source data to obtain face cleaning data, device cleaning data, and application cleaning data.
[0067] It should be noted that face cleansing data refers to the cleaned face source data, device cleansing data refers to the cleaned device source data, and application cleansing data refers to the cleaned application source data.
[0068] In practice, to remove abnormal data, face source data, device source data, and application source data can be cleaned separately to obtain cleaned face source data, device source data, and application source data, namely face cleaned data, device cleaned data, and application cleaned data.
[0069] Step A12: Extract structured information based on the fields to extract data from the face cleaning data, the device cleaning data, and the application cleaning data to obtain face feature data, device feature data, and application feature data.
[0070] It is understandable that field extraction of structured information refers to pre-defined structured information used for feature extraction. Facial feature data refers to structured information extracted from user facial images or videos, including RGB (Red, Green, Blue) three-channel image data. Device feature data refers to structured information extracted from user terminal devices, including the user's current terminal brand, current terminal model, current terminal operating system, current device camera parameters, etc. Application feature data refers to structured information extracted from applications used by the user, including system fonts, screen resolution, IP information, audio context fingerprint, browser canvas, etc.
[0071] In practice, based on the pre-defined structured information for feature extraction, the cleaned face source data, device source data, and application source data are processed with field structure. Specifically, RGB three-channel image data, the user's current terminal brand, current terminal model, current terminal operating system, current device camera parameters, system font, screen resolution, IP information, audio context fingerprint, browser canvas, etc. are extracted to obtain face feature data, device feature data, and application feature data.
[0072] Step A13: Construct an evidence chain information database based on the facial feature data, the device feature data, and the application feature data.
[0073] In practice, facial feature data, device feature data, and application feature data are directly spliced together as input data, thus constructing a cross-subject evidence chain information database.
[0074] It should be noted that this embodiment performs feature collection and preprocessing on the source data of face, device, and application information respectively. According to the data structure requirements of the input model, an evidence chain information database is constructed. Centered on the user's mobile phone number, based on the face biometric information, device information, and application information collected by the SDK, the raw information is processed through pre-designed fields to extract structured information, which is then stored in the evidence chain information database for subsequent network training for ID extraction. The multimodal information across subjects includes the following three modalities: face biometric data, device information, and application information, as described in detail below:
[0075] ① For facial biometric data, commonly used RGB three-channel image data is directly used as input to a deep learning model for attack detection based on facial visual features. Assume Data... <face>The input data represents the terminal information related to the data after being structured and concatenated according to the designed fields.
[0076]
[0077] ② Regarding terminal data, this embodiment proposes to design terminal-type input field data based on basic data related to device attributes, including: the user's current terminal brand, current terminal model, current terminal operating system, and current device camera parameters. All of the above input field data have multiple data types, including numeric, binary, and text types. This embodiment proposes to perform field structuring processing on these multiple data types, that is, assuming Data... <terminal>The input data represents the terminal information related to the data after being structured and concatenated according to the designed fields.
[0078] Data <terminal>={dt1,dt2,…,dt n1 }
[0079] Where {dt1,dt2,…,dt n1 Each element in} represents the input field structure designed in this embodiment, namely {terminal brand, terminal model, sensor, ..., device fingerprint, ..., camera parameters}.
[0080] ③ Regarding application data, this embodiment proposes terminal class input field data designed based on basic data related to application attributes, including: system font, screen resolution, IP information, audio context fingerprint, browser canvas, etc., and performs field structured processing on these raw data, that is, assuming Data <application>If the input data represents the application information related to the structured and concatenated data based on the designed fields, then:
[0081] Data <application>={da1,da2,…,da m1 }
[0082] Where {da1,da2,…,da m1 Each element in} represents the input field structure designed in this embodiment, namely: {system font, screen resolution, IP information, ..., audio context fingerprint, ..., browser canvas}. Data of all data types are directly concatenated as input data and sent into the model. Afterwards, an embedding vector calculation network will be added to the front end of the deep neural network to convert it into numerical data. The relevant networks and methods will be introduced in detail in the following modules.
[0083] Step S20: Obtain the face authentication identifier, device authentication identifier, and application authentication identifier based on the evidence chain information database and the preset identity authentication calculation model;
[0084] It is understandable that the preset identity authentication calculation model refers to a deep neural network model that extracts the identity authentication IDs (identity codes) of three single-modal subjects associated with the user: face, device, and application. The face authentication code refers to the identification code used for personal identity verification, the device authentication code refers to the identification code used for device identity verification, and the application authentication code refers to the identification code used for application identity verification.
[0085] In its implementation, this embodiment first designs a deep neural network for extracting the identity authentication IDs of three single-modal entities: face, device, and application, all associated with the user. This network consists of three main parts: a backbone network for extracting unique representations of each modality; a network for calculating dense features to ensure the stability of the condensed vector for the identity ID; and a target optimization loss function designed to drive iterative optimization of the network parameters towards accurate extraction of the unique identity ID feature vectors for each entity, minimizing the loss. The effects achieved are: first, extraction of dense features uniquely representing the identity ID of each modality; second, semantic alignment of each modality with the unique identifier; and third, realization of unique representation of the identity authentication ID from multiple dimensions, improving the comprehensiveness of the ID representation and the integrity of the evidence chain.
[0086] In one feasible implementation, step S20 may include steps A21 to A23:
[0087] Step A21: Based on the embedded vector network in the preset identity authentication calculation model, the evidence chain information database is processed to obtain face vector data, device vector data and application vector data.
[0088] It is understandable that embedding vector networks refer to the feature vectors used to compute the input of the model, face vector data refers to the vector data used to train the face authentication ID extraction network, device vector data refers to the vector data used to train the device authentication ID extraction network, and application vector data refers to the vector data used to train the application authentication ID extraction network.
[0089] In practical implementation, an embedded vector network is designed at the front end of the backbone network to quantify and vectorize the input data of the three modalities of face, device, and application. That is, the embedded vector network calculates the feature vectors of the data in the cross-subject evidence chain information database to enter the model, thereby obtaining face vector data, device vector data, and application vector data.
[0090] Step A22: Based on the backbone network in the preset identity authentication calculation model, feature extraction is performed on the face vector data, the device vector data, and the application vector data to obtain face characteristic data, device characteristic data, and application characteristic data.
[0091] Understandably, the backbone network is used to extract features reflecting unique ID characteristics from face data, device data, and application data, layer by layer from low-level features to higher-level semantic features. Face feature data refers to the feature data of face characteristics, device feature data refers to the feature data of face characteristics, and application feature data refers to the feature data of face characteristics.
[0092] In practice, based on the backbone network in the preset identity authentication calculation model, features reflecting unique ID characteristics are extracted layer by layer from face data, device data, and application data, from low-level features to higher-level semantic features, to obtain face characteristic data, device characteristic data, and application characteristic data.
[0093] Step A23: Based on the dense network in the preset identity authentication calculation model, perform dense calculations on the face feature data, the device feature data, and the application feature data respectively to obtain the face authentication identifier, the device authentication identifier, and the application authentication identifier.
[0094] Understandably, the denser network is used to flatten and densely compute a series of feature maps. The denser network in the preset identity authentication calculation model performs dense computation on the feature data of face, device and application characteristics, and outputs feature vectors through the last fully connected layer, finally obtaining face authentication identifier, device authentication identifier and application authentication identifier.
[0095] It should be noted that the technical concept of the feature matrix construction principle in this embodiment is as follows: (1) First, for the original discrete and high-dimensional original data of the original evidence chain, the feature vectors entering the model are calculated through the embedding vector network; (2) Three ID extraction deep neural networks are designed respectively, including a feature calculation backbone network and a feature densification network; (3) In order to cooperate with the extraction of unique ID feature vectors, a target optimization loss function is designed to drive the network parameters to accurately extract the unique identity ID feature vectors of each subject through iterative optimization by minimizing the loss. The final calculated single-subject identity ID will be used to calculate the customer identity authentication ID of the three modalities of face-device-application in step three. The technical principle diagram is as follows. Figure 3 As shown, the specific construction steps are as follows:
[0096] 1) Embedded Vector Network Calculation of Original Evidence Chain Information: This embodiment proposes designing an embedded vector network at the front end of the backbone network to quantify and vectorize the input data from three modalities: face, device, and application. Face data undergoes preprocessing via a preprocessing convolutional layer (Conv), primarily used for preprocessing the 3-channel image. For the device and application information modalities, an embedded vector network is designed to quantify and vectorize the information. This network consists of three layers: an input layer (V neurons), a hidden layer (N neurons), and an output layer (V×N neurons). The parameters of the embedded vector network are trained by back-calculating the overall network based on the optimization objective. The main function of the embedded vector network is to convert non-numerical data, such as text data and category data, into corresponding one-dimensional numerical vectors.
[0097] 2) Feature Extraction Backbone Network and Feature Vector Descaling Network Calculation: This step mainly involves designing three backbone networks to extract features reflecting unique ID characteristics from face data, device data, and application data layer by layer, from low-level features to higher-level semantic features. The face feature backbone network is constructed using a preprocessing convolutional network with three RGB color channels, a residual convolutional network, and a fully connected network. The residual convolutional network primarily extracts features from visual information. The device feature backbone network and application feature backbone network each have two corresponding backbone networks, constructed using stacked and multi-layer residual networks, designed as three ReLU fully connected layers with 1024, 512, and 256 neurons per layer, respectively. The calculation formulas are given below:
[0098] h i+1 =ReLU(W i x i +b i )
[0099] The main function of the stacked layers is to concatenate different embedding vectors and numerical features together. The main function of the multi-layer residual network is to fully cross-combine the feature vectors corresponding to devices and applications from various dimensions to enhance the model's ability to express the uniqueness of identity. The dense vector computation layer in the network is mainly used to flatten and densely compute a series of feature maps, and outputs the feature vector through the last fully connected layer, converting it into a 1×2 vector.
[0100] 3) Design a joint objective loss calculation method for multi-ID classification to optimize network parameters. For the single-subject ID calculation network built above, a corresponding loss function needs to be designed to support the back-iterative update calculation of parameters for three single-subject ID calculation networks. To solve this problem, this embodiment designs a multi-ID classification objective loss function and, with the help of the gradient descent algorithm, calculates all the parameters of the aforementioned deep neural network through continuous iterative optimization calculations, thereby training an inference network for three single-modal identity authentication IDs. The loss function is as follows:
[0101]
[0102] Where P represents the optimization objective. C represents the estimate of the target by the feedforward network, C(·) represents the classification network, and R(·) represents the backbone network.
[0103] Step S30: The face authentication identifier, the device authentication identifier, and the application right identifier are fused according to the authentication identifier fusion strategy to obtain the target authentication identifier, and the encrypted target authentication identifier is stored in the user identification card.
[0104] It is understandable that the authentication identifier fusion strategy refers to the strategy used for multimodal cross-subject identity authentication ID fusion, the target authentication identifier refers to the multimodal cross-subject identity authentication identifier, and the user identification card refers to the SIM (Subscriber Identity Module) card.
[0105] In practical implementation, the unique ID feature corresponding to a single modality has unique identity representation. This embodiment proposes to further integrate the unique IDs calculated separately for each modality into a multimodal cross-subject identity authentication ID through algorithms or models, forming a unique identity authentication ID for the user. Then, this identity authentication ID is encrypted using an encryption algorithm before transmission or storage, and the encryption technology is irreversible to prevent the identity authentication ID from being stolen and decrypted. The encrypted identity authentication ID is not only irreversible and undecryptable, but also requires matching capabilities. The effects achieved through the above steps are: first, to realize a complete multimodal evidence chain of the customer's unique ID (face-device-application), improving the anti-attack capability of the unique identity identifier and the robustness against device or application information; second, to prevent the identity authentication ID from being attacked or stolen by malicious actors during transmission and use through encryption technology.
[0106] Step S40: When an authentication request exists, the current authentication identifier is sent to the user identification card so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted authentication result.
[0107] As can be understood, an authentication request refers to a request initiated by a client (such as a user device, application, etc.) to a server or authentication service during the authentication process. The purpose is to verify whether the user's identity information is legal and valid. The current authentication identifier refers to the authentication identifier that the client currently has, calculated in real time. The authentication result refers to the verification result of whether the current authentication identifier matches the target authentication identifier.
[0108] In specific implementation, such as Figure 4 As shown, real-time user information is collected and calculated using the SDK (Software Development Kit, a set of tools and resources for developing software applications), and the extracted and encrypted ID is stored in the user's SIM card. Entering the identity authentication stage, this embodiment designs an authentication method and process. First, portable terminals such as mobile phones collect the customer's facial information, device information, and application information through cameras, etc., and calculate the customer's current authentication ID in real time using the SDK's model engine. This ID is then transmitted to the terminal's SIM. This embodiment designs all of these processes as part of the SDK. Second, this embodiment designs a matching algorithm and stores it in the underlying SIM's computing power for matching calculations to verify whether the authentication IDs match. If they match, the authentication is successful; otherwise, it fails. Finally, this embodiment proposes encrypting the authentication result in the SIM and transmitting the encrypted result to the APP service. The server decrypts the result and verifies whether it is successful. The communication method between the SIM and SDK is more secure, reliable, and efficient than public network communication in the cloud.
[0109] In one feasible implementation, step S40 may include steps A41 to A43:
[0110] Step A41: When an identity authentication request is requested, obtain the current face information, current device information, and current application information;
[0111] It is understandable that current facial information refers to real-time facial information obtained through collection devices such as cameras, current device information refers to real-time user device information, and current application information refers to real-time user application information.
[0112] In practice, when there is information requesting identity authentication, portable terminals such as mobile phones collect the customer's facial information, device information, and application information through cameras, thus obtaining the current facial information, current device information, and current application information.
[0113] Step A42: Calculate the current authentication identifier code by performing identifier code generation on the current face information, the current device information, and the current application information according to the preset identifier code generation model;
[0114] It is understandable that the preset identifier generation model refers to a pre-defined model used to generate identity authentication identifiers, such as the model engine of the SDK.
[0115] In practice, the SDK's model engine calculates the identity authentication code based on the facial information, device information, and application information collected by mobile phones and other portable terminals, and obtains the current authentication code based on the calculation result.
[0116] Step A43: Send the current authentication identifier to the user identification card.
[0117] In specific implementation, during the registration phase, the user has already used the SDK's data collection and computing capabilities to store the extracted and encrypted ID into the SIM card of the user's device. Entering the identity authentication phase, this embodiment designs an authentication method. First, the mobile phone or other portable terminal collects the customer's facial information, device information, and application information through a camera, etc., and calculates the customer's current authentication ID in real time through the SDK's model engine, transmitting the ID to the terminal's SIM. This embodiment designs all of these processes as part of the SDK. Second, this embodiment designs a matching algorithm and stores it in the underlying SIM's computing power for matching calculations to verify whether the authentication IDs match. If they match, the identity verification is successful; otherwise, it is unsuccessful. Finally, this embodiment proposes encrypting the identity verification result in the SIM and transmitting the encrypted result to the APP service. The server decrypts the result and verifies whether the verification is successful. The communication method between the SIM and the SDK is more secure, reliable, and efficient than public network communication in the cloud. Figure 5 As shown, the secure channel design for SIM-SDK communication and the ID authentication process are described in BIP format. Furthermore, for extremely high-security use cases, user PIN verification is added here to further enhance the security level of identity authentication. The SIM card and data SMS methods are similar and will not be elaborated upon.
[0118] Step S50: Determine the target identity authentication result based on the encrypted identity verification result.
[0119] In practice, the target identity authentication result refers to whether the identity authentication obtained by the mobile terminal is successful. The mobile terminal decrypts the encrypted identity authentication result fed back by the SIM card to check whether the verification result is successful, thus obtaining the target identity authentication result.
[0120] This embodiment constructs an evidence chain information database based on facial source data, device source data, and application source data. Based on this database and a preset identity authentication calculation model, it obtains facial authentication identifiers, device authentication identifiers, and application authentication identifiers. These multiple authentication identifiers are then fused to obtain a target authentication identifier, which is then stored in a user identification card. The current authentication identifier is sent to the user identification card, which compares it with the encrypted target authentication identifier. The target identity authentication result is determined based on the encrypted identity verification result returned by the user identification card. By fusing the identity features of face, device, and application before performing identity authentication comparison, high security and reliability are achieved across the entire chain, from generation, storage, and communication transmission to authentication comparison.
[0121] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 6 The identity authentication method further includes steps S31 to S32 in step S30:
[0122] Step S31: Perform dense processing on the face authentication identifier, the device authentication identifier, and the application right identifier according to the authentication identifier fusion strategy to obtain dense face features, dense device features, and dense application features.
[0123] It is understandable that dense facial features refer to high-level dense features of a face, dense device features refer to high-level dense features of a device, and dense application features refer to high-level dense features of an application.
[0124] In practice, to facilitate the uniqueness comparison and calculation of identity authentication IDs, high-level dense feature IDs are further calculated through the fully connected networks FC1 and FC2. That is, the face authentication identifier, device authentication identifier, and application right identifier are calculated through the fully connected networks FC1 and FC2 to obtain the high-level dense features of the face, device, and application.
[0125] Step S32: The dense features of the face, the dense features of the device, and the dense features of the application are linked together to obtain the target authentication identifier code.
[0126] In practice, the three single-modal identity authentication IDs are concatenated and linked together to form a one-dimensional vector of length 1×3n, which serves as the final extracted multimodal cross-subject identity authentication ID, i.e., the target authentication identifier.
[0127] It should be noted that, such as Figure 7 As shown, (1) First, through algorithms or models, a multimodal cross-subject identity authentication ID is further integrated to uniquely identify the user, thereby realizing a complete multimodal evidence chain of face-device-application for the customer's unique ID. For example, through step one, the unique ID feature corresponding to a single modality is obtained, which has the uniqueness of identity representation. The unique ID corresponding to each modality is calculated separately. Among them, the face authentication ID is represented as ID_F = (idf0, idf1, ..., idf j , ...,idf N The device authentication ID is represented as ID_T = (idt0, idt1, ..., idt...). j , ..., idt N The application authentication ID is represented as ID_A = (ida0, ida1, ..., ida...). j , ...,ida N ).
[0128] (2) Subsequently, in order to facilitate the uniqueness comparison calculation of the identity authentication ID, this embodiment further calculates the high-level dense feature ID through the fully connected networks FC1 and FC2, and then concatenates the identity authentication IDs corresponding to the three single modes, i.e., ID = {ID_F n ID_T n ID_A n This forms a one-dimensional vector of length 1×3n, which serves as the final extracted multimodal cross-subject identity authentication ID, thereby improving the unique identity identifier's anti-attack capability and robustness against device or application information. The loss function for objective optimization is calculated as follows:
[0129]
[0130] In one feasible implementation, step S30 may further include steps A31 to A32:
[0131] Step A31: Encrypt the target authentication identifier code according to the preset encryption strategy to obtain the encrypted target authentication identifier code.
[0132] It is understandable that the preset encryption strategy refers to the pre-set encryption strategy for the identity authentication identifier. For example, MD5 (Message-Digest Algorithm 5) is a widely used hash function used to generate a digest (i.e., hash value) of data.
[0133] In practical implementation, to prevent the identity authentication ID from being attacked or stolen by malicious actors during transmission and use, this embodiment proposes to encrypt the calculated cross-subject multimodal identity authentication ID before transmission or storage. The encryption technology adopts an irreversible encryption method to prevent the identity authentication ID from being stolen and decrypted. The encrypted identity authentication ID is not only irreversible and undecryptable, but also requires the ability to match. In summary, the encryption technology needs to have both of the above capabilities. For example, this embodiment proposes to use MD5 encryption to achieve the above two objectives.
[0134] Step A32: Transmit the encrypted target authentication code to the user identification card through a preset data transmission channel.
[0135] It is understandable that the preset data transmission channels include the card-to-machine channel, BIP (Binary Interchange Protocol) communication, and digital SMS.
[0136] In specific implementation, such as Figure 8 As shown, to avoid attacks by malicious actors during the transmission of IDs obtained from existing SDK collection and calculation to the cloud service side, this embodiment proposes a more secure method. Specifically, during the registration phase, the user's multimodal cross-subject identity authentication ID, obtained from SDK collection and calculation, and encrypted, is stored in the user terminal's SIM card. This leverages the high-security storage capabilities of the SIM card hardware to achieve secure and reliable storage of the identity authentication ID. To ensure the security and reliability of the identity authentication ID writing process and eliminate the risk of eavesdropping and theft, this embodiment designs a security scheme between the SDK and the SIM card. First, a remote method (BIP and SMS) is used to establish a secure channel between the upper-layer application on the terminal side and the lower-layer SIM card. The identity authentication ID is encrypted and MAC calculated using SCP80 and SCP81 keys to complete the SIM data writing. Second, the local terminal-SIM card channel capability between the mobile terminal and the SIM card is utilized, with the identity authentication ID encrypted and MAC calculated under the protection of the SCP02 secure channel to complete the SIM data writing.
[0137] It should be noted that the SIM card channel method utilizes the SIM card channel capability between the mobile terminal and the SIM card to complete the writing of the authentication ID. This method requires the SDK to be authorized by the mobile operator to access the SIM card. Authorization is achieved by writing the SDK's hash value into the SIM card's AC access file and associating the SIM card's authentication application AID with the current SDK to ensure the SDK can access the authentication application. The SDK will asynchronously connect to the operator's TSM (hereinafter referred to as SEI-TSM) to establish a secure channel with the SIM card, negotiate a secure channel line protection key, and then use this key to encrypt the authentication ID before writing it locally via the SIM card channel.
[0138] BIP Communication Method: The SDK connects to SEI-TSM and completes the writing of the authentication ID via BIP. This scheme requires SEI-TSM to authorize the service interface of the SDK and exchange secure communication keys (generally SM2 keys; both parties exchange SM2 public keys, encrypt data using the other party's public key during data exchange, and decrypt the received data using their own private key). This secure key serves as the encryption key for the communication data process between SEI-TSM and the SDK, ensuring absolute security of the communication link. The SDK encrypts the authentication ID using the SEI-TSM secure communication key with SM2 and organizes the data according to the SEI-TSM interface security policy before sending it to SEI-TSM. SEI-TSM sends a BIP connection request to the current mobile number. After successful connection establishment, SEI-TSM encrypts the authentication ID twice before sending it to the SIM card. During this stage, the authentication ID undergoes double encryption using the BIP process key and the SIM card secure channel key, and is protected by MAC. All keys used are one-time pads, ensuring that the data cannot be eavesdropped on or cracked.
[0139] Digital SMS Method: The SDK connects to SEI-TSM and completes the authentication ID writing via digital SMS. This method requires SEI-TSM to authorize the service interface of the SDK and exchange secure communication keys (consistent with the BIP method). The SDK encrypts the authentication ID using the SEI-TSM secure communication key with SM2 and organizes the data according to the SEI-TSM interface security policy before sending it to SEI-TSM. SEI-TSM then sends a digital SMS to the current SIM card. The authentication ID is first encrypted according to the digital SMS security policy and then organized into a secure message before being sent to the SIM card to complete the data writing process.
[0140] The three methods described above differ in their scope of application and characteristics. The SIM-SDK method requires the terminal to be a mobile phone, and the SDK must use the Google API or OMA API to establish the SIM-SDK connection. The BIP method is more suitable for scenarios involving large amounts of data exchange between the two parties, while data SMS, due to its 140-byte limit per message, is more efficient for interactions within 140 bytes. The secure channel design for SIM-SDK communication and the process of secure SIM storage using the BIP method are described below. Figure 9 As shown.
[0141] This embodiment performs dense processing on the face authentication code, device authentication code, and application authorization code according to an authentication code fusion strategy to obtain dense face features, dense device features, and dense application features. These dense face features, device features, and application features are then concatenated to obtain the target authentication code. Using the three single-subject identity IDs (person, device, and application) calculated by the aforementioned network, a corresponding multilayer perceptron is designed. Through cross-entropy loss accurately represented by the unique ID, the three different modal single-subject identity ID vectors are further constrained to align to the same semantic space, ultimately forming a multimodal cross-subject unique identity authentication ID.
[0142] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the identity authentication method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0143] This application also provides an identity authentication device, please refer to... Figure 10 The identity authentication device includes:
[0144] Module 10 is used to build an evidence chain information database based on face source data, device source data and application source data;
[0145] The calculation module 20 is used to obtain the face authentication identifier, device authentication identifier, and application authentication identifier based on the evidence chain information database and the preset identity authentication calculation model.
[0146] The fusion module 30 is used to fuse the face authentication code, the device authentication code and the application right code according to the authentication code fusion strategy to obtain the target authentication code, and store the encrypted target authentication code in the user identification card.
[0147] The transmission module 40 is used to send the current authentication identifier to the user identification card when there is an authentication request, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted authentication result.
[0148] The authentication module 50 is used to determine the authentication result of the target identity based on the encrypted authentication result.
[0149] Optionally, the building module 10 is further configured to:
[0150] Data cleaning is performed on face source data, device source data, and application source data to obtain face cleaned data, device cleaned data, and application cleaned data.
[0151] Based on the structured information extracted from the fields, the face cleaning data, the device cleaning data, and the application cleaning data are respectively extracted to obtain face feature data, device feature data, and application feature data;
[0152] An evidence chain information database is constructed based on the facial feature data, the device feature data, and the application feature data.
[0153] Optionally, the computing module 20 is further configured to:
[0154] The evidence chain information database is processed based on the embedded vector network in the preset identity authentication calculation model to obtain face vector data, device vector data and application vector data.
[0155] Based on the backbone network in the preset identity authentication calculation model, feature extraction is performed on the face vector data, the device vector data and the application vector data to obtain face characteristic data, device characteristic data and application characteristic data.
[0156] Based on the dense network in the preset identity authentication calculation model, dense calculations are performed on the face feature data, the device feature data, and the application feature data to obtain the face authentication identifier, the device authentication identifier, and the application authentication identifier.
[0157] Optionally, the fusion module 30 is further configured to:
[0158] The face authentication code, the device authentication code, and the application right code are densely processed according to the authentication code fusion strategy to obtain dense face features, dense device features, and dense application features.
[0159] The dense features of the face, the dense features of the device, and the dense features of the application are linked together to obtain the target authentication identifier code.
[0160] Optionally, the transmission module 40 is further configured to:
[0161] When an authentication request is requested, obtain the current facial information, current device information, and current application information;
[0162] The current authentication identifier is calculated by performing identifier code generation on the current face information, the current device information, and the current application information according to the preset identifier code generation model.
[0163] Send the current authentication identifier to the user identification card.
[0164] Optionally, the fusion module 30 is further configured to:
[0165] The target authentication identifier is encrypted according to a preset encryption strategy to obtain the encrypted target authentication identifier.
[0166] The encrypted target authentication code is transmitted to the user identification card through a preset data transmission channel.
[0167] The identity authentication device provided in this application, employing the identity authentication method described in the above embodiments, can solve the technical problem of low reliability of identity identifiers in existing single-entity authentication. Compared with the prior art, the beneficial effects of the identity authentication device provided in this application are the same as those of the identity authentication method described in the above embodiments, and other technical features in the identity authentication device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0168] This application provides an identity authentication device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the identity authentication method in the first embodiment described above.
[0169] The following is for reference. Figure 11 The diagram illustrates a structural schematic of an identity authentication device suitable for implementing embodiments of this application. The identity authentication device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 11 The identity authentication device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0170] like Figure 11 As shown, the authentication device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the authentication device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the authentication device to communicate wirelessly or wiredly with other devices to exchange data. While the figures show authentication devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.
[0171] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0172] The identity authentication device provided in this application, employing the identity authentication method described in the above embodiments, can solve the technical problem of low reliability of existing single-subject authentication identity identifiers. Compared with the prior art, the beneficial effects of the identity authentication device provided in this application are the same as those of the identity authentication method provided in the above embodiments, and other technical features in this identity authentication device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0173] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0174] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0175] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the identity authentication method in the above embodiments.
[0176] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0177] The aforementioned computer-readable storage medium may be included in the identity authentication device; or it may exist independently and not be assembled into the identity authentication device.
[0178] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the identity authentication device, the identity authentication device: constructs an evidence chain information database based on face source data, device source data, and application source data; obtains a face authentication identifier, a device authentication identifier, and an application authentication identifier based on the evidence chain information database and a preset identity authentication calculation model; fuses the face authentication identifier, the device authentication identifier, and the application authentication identifier according to an authentication identifier fusion strategy to obtain a target authentication identifier, and stores the encrypted target authentication identifier in a user identification card; when an identity authentication request exists, it sends the current authentication identifier to the user identification card, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted identity verification result; and determines the target identity authentication result based on the encrypted identity verification result.
[0179] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0180] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0181] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0182] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described identity authentication method, which can solve the technical problem of low reliability of identity identifiers in existing single-subject authentication. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the identity authentication method provided in the above embodiments, and will not be repeated here.
[0183] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the identity authentication method described above.
[0184] The computer program product provided in this application can solve the technical problem of low reliability of identity identifiers in existing single-entity authentication. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the identity authentication method provided in the above embodiments, and will not be repeated here.
[0185] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.< / application> < / terminal> < / terminal> < / face>
Claims
1. An identity authentication method, characterized in that, The identity authentication method includes: An evidence chain information database is constructed based on facial data, device data, and application data. Based on the evidence chain information database and the preset identity authentication calculation model, the face authentication identifier, device authentication identifier, and application authentication identifier are obtained. According to the authentication identifier fusion strategy, the face authentication identifier, the device authentication identifier, and the application right identifier are fused to obtain the target authentication identifier, and the encrypted target authentication identifier is stored in the user identification card. When an authentication request is requested, the current authentication identifier is sent to the user identification card, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted authentication result. The target identity authentication result is determined based on the encrypted authentication result.
2. The method as described in claim 1, characterized in that, The step of constructing an evidence chain information database based on facial source data, device source data, and application source data includes: Data cleaning is performed on face source data, device source data, and application source data to obtain face cleaned data, device cleaned data, and application cleaned data. Based on the structured information extracted from the fields, the face cleaning data, the device cleaning data, and the application cleaning data are respectively extracted to obtain face feature data, device feature data, and application feature data; An evidence chain information database is constructed based on the facial feature data, the device feature data, and the application feature data.
3. The method as described in claim 1, characterized in that, The steps of obtaining the face authentication identifier, device authentication identifier, and application authentication identifier based on the evidence chain information database and the preset identity authentication calculation model include: The evidence chain information database is processed based on the embedded vector network in the preset identity authentication calculation model to obtain face vector data, device vector data and application vector data. Based on the backbone network in the preset identity authentication calculation model, feature extraction is performed on the face vector data, the device vector data and the application vector data to obtain face characteristic data, device characteristic data and application characteristic data. Based on the dense network in the preset identity authentication calculation model, dense calculations are performed on the face feature data, the device feature data, and the application feature data to obtain the face authentication identifier, the device authentication identifier, and the application authentication identifier.
4. The method as described in claim 1, characterized in that, The step of fusing the face authentication identifier, the device authentication identifier, and the application right identifier according to the authentication identifier fusion strategy to obtain the target authentication identifier includes: The face authentication code, the device authentication code, and the application right code are densely processed according to the authentication code fusion strategy to obtain dense face features, dense device features, and dense application features. The dense features of the face, the dense features of the device, and the dense features of the application are linked together to obtain the target authentication identifier code.
5. The method as described in claim 1, characterized in that, The step of sending the current authentication identifier to the user identification card when an authentication request is requested includes: When an authentication request is requested, obtain the current facial information, current device information, and current application information; The current authentication identifier is calculated by performing identifier code generation on the current face information, the current device information, and the current application information according to the preset identifier code generation model. Send the current authentication identifier to the user identification card.
6. The method as described in claim 1, characterized in that, After the step of fusing the face authentication identifier, the device authentication identifier, and the application right identifier according to the authentication identifier fusion strategy to obtain the target authentication identifier, the method further includes: The target authentication identifier is encrypted according to a preset encryption strategy to obtain the encrypted target authentication identifier. The encrypted target authentication code is transmitted to the user identification card through a preset data transmission channel.
7. An identity authentication device, characterized in that, The device includes: The module is used to build an evidence chain information database based on face source data, device source data, and application source data; The calculation module is used to obtain the face authentication identifier, device authentication identifier, and application authentication identifier based on the evidence chain information database and the preset identity authentication calculation model. The fusion module is used to fuse the face authentication code, the device authentication code and the application right code according to the authentication code fusion strategy to obtain the target authentication code, and store the encrypted target authentication code in the user identification card. The transmission module is used to send the current authentication identifier to the user identification card when there is an authentication request, so that the user identification card compares the current authentication identifier with the encrypted target authentication identifier and returns the encrypted authentication result. The authentication module is used to determine the authentication result of the target identity based on the encrypted authentication result.
8. An identity authentication device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the authentication method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the identity authentication method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the identity authentication method as described in any one of claims 1 to 6.