Identity authentication method, computer device and readable storage medium

CN122778366APending Publication Date: 2026-09-18NANCHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611126452.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-28
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

[0003]然而,传统技术中,业务系统借助用户的身份证件号来判定用户是否具有进入的权限,但身份证件号包含了很多个人的隐私信息,频繁地将身份证件号进行数据开放共享,容易泄露用户的隐私信息

Benefits of technology

[0010] In this embodiment, after a user completes authentication on the unified identity authentication platform, the system determines whether the user has permission to access the business system by combining the user's basic identity code with the identity type and status in the user's basic information table, rather than relying on the user's ID card number. This avoids the leakage of the user's personal privacy information and thus improves the security of the user's personal privacy information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122778366A_ABST
    Figure CN122778366A_ABST
Patent Text Reader

Abstract

The application discloses an identity authentication method, a computer device and a readable storage medium, and belongs to the technical field of user identification. The method comprises the following steps: after a user completes authentication of a unified identity authentication platform, in response to an identity authentication request input by the user, a personnel basic information table corresponding to the user is determined based on a personnel basic identity code corresponding to the user provided by the unified identity authentication platform, wherein the personnel basic identity code is used for uniquely identifying the user; an identity type and an identity state corresponding to the user are found from the personnel basic information table; and if the identity type and the identity state indicate that the user has the permission to enter a business system, it is determined that the authentication is passed. The application can improve the security of personal privacy information of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of user authentication technology, specifically relating to an identity authentication method, computer equipment, and readable storage medium. Background Technology

[0002] Currently, after users complete authentication on the unified identity authentication platform using their employee ID, mobile phone number, or ID card number, the platform displays the "One-Stop Government Service" interface. This interface integrates entry points to multiple business systems, allowing users to quickly access the corresponding systems.

[0003] However, in traditional technologies, business systems rely on users' ID card numbers to determine whether users have access permissions. But ID card numbers contain a lot of personal privacy information, and frequently sharing ID card numbers can easily leak users' privacy information. Summary of the Invention

[0004] The purpose of this application is to provide an identity authentication method, computer device, and readable storage medium that can improve the security of users' personal privacy information.

[0005] To solve the above-mentioned technical problems, this application is implemented as follows: In a first aspect, embodiments of this application provide an identity authentication method applied to a computer device with a business system deployed thereon, the method comprising: After a user completes authentication on the unified identity authentication platform, in response to the user's authentication request, the platform determines the user's basic information table based on the user's basic identity code provided by the unified identity authentication platform; wherein, the basic identity code is used to uniquely identify the user. The user's identity type and identity status are retrieved from the basic personnel information table; If the identity type and identity status indicate that the user has permission to access the business system, then authentication is successful.

[0006] Secondly, embodiments of this application provide an identity authentication device, the identity authentication device comprising: The first determining module is used to, after the user completes authentication on the unified identity authentication platform, respond to the identity authentication request input by the user and determine the basic personnel information table corresponding to the user based on the basic personnel identity code provided by the unified identity authentication platform; wherein, the basic personnel identity code is used to uniquely identify the user; The search module is used to retrieve the user's corresponding identity type and identity status from the basic personnel information table; The second determining module is used to determine that authentication is successful if the identity type and the identity status indicate that the user has permission to enter the business system.

[0007] Thirdly, embodiments of this application provide a computer device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method described in the first aspect.

[0008] Fourthly, embodiments of this application provide a computer-readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect.

[0009] Fifthly, embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.

[0010] In this embodiment, after a user completes authentication on the unified identity authentication platform, the system determines whether the user has permission to access the business system by combining the user's basic identity code with the identity type and status in the user's basic information table, rather than relying on the user's ID card number. This avoids the leakage of the user's personal privacy information and thus improves the security of the user's personal privacy information. Attached Figure Description

[0011] Figure 1 This is one of the flowcharts illustrating the identity authentication method provided in some embodiments of this application; Figure 2 This is one of the flowcharts illustrating the identity authentication method provided in some embodiments of this application; Figure 3 This is a data association diagram provided by some embodiments of this application; Figure 4 This is one of the flowcharts illustrating the identity authentication method provided in some embodiments of this application; Figure 5 This is a structural block diagram of an identity authentication device provided in some embodiments of this application; Figure 6 These are internal structural diagrams of a computer device provided in some embodiments of this application. Detailed Implementation

[0012] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0013] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0014] The embodiments of this application can be applied to a variety of application scenarios, such as the scenario of one-stop online service in universities.

[0015] The identity authentication method provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0016] In one exemplary embodiment, this application proposes an identity authentication method, referring to... Figure 1 The method includes steps 102-106. Wherein: Step 102: After the user completes authentication on the unified identity authentication platform, in response to the identity authentication request input by the user, the basic personnel information table corresponding to the user is determined based on the basic personnel identity code provided by the unified identity authentication platform; wherein, the basic personnel identity code is used to uniquely identify the user.

[0017] In some embodiments, the basic personnel information table includes a basic personnel identification code, a business personnel identification code, an ID card number, a mobile phone number, an identity type, an identity status, a facial image, fingerprint features, and iris features. The facial image, fingerprint features, and iris features can be recorded in the basic personnel information table in an coded form.

[0018] In some embodiments, the basic identification code for personnel may be meaningless and may be a randomly generated string of numbers.

[0019] In some embodiments, a personnel basic identity code generation mechanism based on multimodal biometric fusion is constructed. This means the personnel basic identity code can be a string of numbers generated based on a user's ID card number and biometric information. The biometric information can include, but is not limited to, facial images, fingerprint features, and iris features. When generating the personnel basic identity code, a national-level cryptographic hash algorithm and feature encoding technology can be used to transform unstructured biometric data (i.e., biometric information) combined with the ID card number into a standardized, unique, and irreversible digital identity code. This achieves trusted identity governance with "one code per person, code and person matching, and universal applicability across multiple domains," thereby constructing a unified, secure, and reliable personnel identity identification system across all domains.

[0020] In some embodiments, the basic personnel identification code may be used only for internal management of computer equipment (such as computer equipment with a unified identity authentication platform, business system, etc. deployed), and general managers and users do not need to know or use it.

[0021] In some embodiments, a basic identification code can be generated when a user first enters the school and remains unchanged throughout their life. Computer devices can access a user's entire historical information at the school through this basic identification code.

[0022] In some embodiments, a personnel business identification code is used to identify a user's business identity and can be provided to both the user and general management personnel. The personnel business identification code may include, but is not limited to, student ID, employee ID, and visitor ID.

[0023] In some embodiments, the personnel business identification code has a certain meaning, such as a student's student ID representing a student's identity, or a faculty member's employee ID representing a teacher's identity, so that managers can understand the user's basic information through the personnel business identification code without using computer equipment.

[0024] In some embodiments, a personnel business identification code is generated when a user enters the school, but it changes as the user's attributes change. For example, if a user's identity changes from a student to a faculty member, the personnel business identification code must also change accordingly.

[0025] In some embodiments, the basic personnel identification code uses a unique, random string of numbers. The personnel business identification code may use meaningless or meaningful encoding rules depending on the specific business of the university.

[0026] In some embodiments, the user's identity type may include, but is not limited to: students (such as undergraduates, graduate students, doctoral students, etc.), faculty and staff, visitors, members of the public, family members, and staff of affiliated units (such as staff of affiliated hospitals, staff of affiliated middle schools, etc.).

[0027] In some embodiments, a user's identity status corresponds to their identity type. For example, if a user's identity type is an undergraduate student, the corresponding identity status could be currently enrolled, graduated, or dropped out.

[0028] In some embodiments, the structure of the personnel basic information table can be found in Table 1.

[0029] Table 1: An example of a personnel basic information table.

[0030] Based on the aforementioned basic personnel information table, the unified identity authentication platform and business systems can access the basic personnel information table to perform identity authentication and permission authentication for logged-in users.

[0031] For unified identity authentication platforms, refer to Figure 2 In some embodiments, the unified identity authentication platform authenticates users based on their business identity code, ID card number, and mobile phone number. Specifically, when a user logs into the unified identity authentication platform, the user can log in using their student ID, employee ID, ID card number, or mobile phone number. The unified identity authentication platform can use the business identity code to access the user's basic information table to obtain the user's basic identity code, as well as all the user's identity types and statuses from the basic information table, thereby determining whether the user can successfully log in to the unified identity authentication platform.

[0032] In some embodiments, if the identity status corresponding to any of the user's identity types is valid, the unified identity authentication platform can determine that the authentication is successful, and the user has successfully logged into the unified identity authentication platform. Here, "valid" refers to being a student, employed, etc.

[0033] Here are some specific scenario examples: Example 1: A user's current identity is a graduate student, and he also studied at the same university for his undergraduate degree. When the user logs into the unified identity authentication platform using his undergraduate student ID, graduate student ID, ID card number, or mobile phone number, the unified identity authentication platform can recognize that his current valid identity is that of a graduate student, and he can successfully log in to the unified identity authentication platform.

[0034] Example 2: A user's current identity is either a doctoral student or a faculty member. When the user logs into the unified identity authentication platform using their doctoral student ID, faculty member ID, ID card number, or mobile phone number, the unified identity authentication platform can recognize that their current valid identity is that of a doctoral student or a faculty member, and the user can successfully log in to the unified identity authentication platform.

[0035] After a user successfully logs into the unified identity authentication platform, the platform provides the user's basic identity code to each single sign-on business system.

[0036] In some embodiments, the business system may include, but is not limited to: a student and faculty service hall system, a logistics system, a library management system, and a dormitory access control system.

[0037] In some embodiments, the authentication request entered by the user is carried out by the user's single sign-on operation. For example, after successfully logging into the unified identity authentication platform, the user can trigger a single sign-on operation for a specific business system by clicking on the entry point of that business system on the "One-Stop Government Service" interface.

[0038] Step 104: Find the user's identity type and identity status from the basic personnel information table.

[0039] In some embodiments, the system queries the user's basic personnel information table to retrieve all identity records under the user's basic identity code. Specifically, it retrieves the user's corresponding identity type and the identity status corresponding to each identity type. There may be one or more identity types and corresponding identity statuses, with the number of identity types being the same as the number of identity statuses.

[0040] Step 106: If the identity type and identity status indicate that the user has permission to access the business system, then authentication is confirmed to be successful.

[0041] In some embodiments, when the identity type includes the identity type specified by the business system, and the identity status corresponding to the specified identity type is the target identity status, it indicates that the user has permission to enter the business system. It can be understood that the target identity status refers to an identity status that is valid.

[0042] It is understandable that different business systems may target different users. For example, the student and faculty service hall system targets users with the identity type of students and faculty members, but not users with the identity type of visitors.

[0043] Therefore, for the business system, the first step is to determine whether the user's identity type is the identity type it serves, i.e., whether it is the designated identity type. Secondly, if the identity type is the designated identity type, then it is determined whether the corresponding identity state is the target identity state. If the identity state is the target identity state, then the user is determined to have permission to enter the business system. If the identity type is not the designated identity type, or if the identity type is the designated identity type but the corresponding identity state is not the target identity state, then the user is determined not to have permission to enter the business system.

[0044] This embodiment determines a user's access to the business system by combining their basic identity code with their identity type and status from the basic information table after the user completes authentication on the unified identity authentication platform, rather than relying on the user's ID card number. This avoids the leakage of users' personal privacy information and thus improves the security of users' personal privacy information.

[0045] Furthermore, when both the identity type and the identity status indicating that the user has permission to access the business system are at least two, the method further includes: In response to the user's selection of a target service, the rules engine is invoked to determine the target identity type of the user when using the target service from at least two identity types.

[0046] In some embodiments, indicating that a user has permission to access the business system is at least two identity types and at least two identity states, means that there are at least two specified identity types and at least two identity states corresponding to the specified identity types are the target identity states.

[0047] In some embodiments, after querying the basic information table of the users mentioned above, query results can be obtained. The query results may include the specified identity type and the corresponding target identity status. For example, if the business system is a service hall system for teachers and students, the query results for a certain user may be: [{Identity type: "Doctoral student", Identity status: "Student"}, {Identity type: "Faculty and staff", Identity status: "Employed"}].

[0048] In some embodiments, the target service refers to a service selected by the user from among the services provided by the business system. For example, if the business system is a student and faculty service hall system, the target service is student ID card replacement.

[0049] In some embodiments, the step of invoking a rules engine in response to the user's selection of a target service to determine the target identity type of the user when using the target service from at least two identity types includes: In response to the user's selection of a target service, obtain the time information corresponding to the selection operation.

[0050] Based on the time information, the call rule engine determines the target identity type that matches the time information when the user uses the target service, from at least two identity types.

[0051] In this embodiment, time information may include, but is not limited to: current time, day of the week, whether it is a holiday, whether it is during a semester, and whether it is exam week.

[0052] For example, if the business system is a library management system, the time information is "within the exam week," and the user's identity type includes doctoral students and faculty members, with the corresponding identity status being the target identity status, then when a user uses the reservation service, it can be determined that the doctoral student matches the time information, meaning the doctoral student is the target identity type.

[0053] For example, if the business system is a research system, the time information is "during winter and summer vacations," and the user's identity type includes doctoral students and faculty members, and the corresponding identity status is the target identity status, then when a user uses the research funding application service, it can be determined that the faculty member matches the time information, i.e., the faculty member is the target identity type.

[0054] In some embodiments, the step of invoking a rules engine in response to the user's selection of a target service to determine the target identity type of the user when using the target service from at least two identity types includes: In response to the user's selection of a target service, retrieve the user's previous service after this business system interaction.

[0055] Based on the previous service call rule engine, the target identity type that matches the previous service when the user uses the target service is determined from at least two identity types.

[0056] In some embodiments, the previous service is associated with the current service (i.e., the target service), and the two services are usually handled by the same identity type.

[0057] For example, if the business system is a service hall system for teachers and students, and the previous service is course selection, and the user selects courses as a doctoral student, and the target service is textbook reservation, then the target identity type is also a doctoral student.

[0058] In some embodiments, the step of invoking a rules engine in response to the user's selection of a target service to determine the target identity type of the user when using the target service from at least two identity types includes: In response to the user's selection operation for the target service, the rule engine is invoked to determine the user's historical identity type when using the target service from at least two identity types as the target identity type.

[0059] In some embodiments, a historical identity type refers to an identity type whose selection rate in the user's historical identity selection records for the target service is greater than a preset selection rate. For example, if the selection rate for a certain identity type is 80%, while the preset selection rate is 70%, then that identity type can be identified as a historical identity type.

[0060] In some embodiments, if none of the above rules are met, an identity selection prompt pop-up can be output. This identity selection prompt pop-up is used to allow users to select the target identity type from all available identity types when using the target service.

[0061] In some embodiments, when there are at least two identity types and identity states indicating that the user has permission to access the business system, after invoking the rule engine in response to the user's selection operation for a target service, the time information corresponding to the selection operation can be obtained first. If the target identity type cannot be determined through the time information, the user's previous service after this access to the business system can be obtained. If the target identity type cannot be determined through the previous service, historical identity types can be obtained. If historical identity types still cannot be obtained successfully, an identity selection prompt pop-up is output for the user to select the target identity type.

[0062] In some embodiments, the service targets of different services in the business system may be only a certain identity type. For example, if the business system is a service hall system for teachers and students, the student ID card replacement service is only for students, and the faculty and staff email application service is only for faculty and staff.

[0063] Based on this, when there are at least two identity types and identity states that indicate that the user has permission to enter the business system, and when the user may only use different services of a certain identity type, the business system automatically selects the corresponding identity type of the user to provide services to the user without the user having to select an identity, thereby realizing seamless business processing for the user.

[0064] For example, in a service system for faculty and students, users can be categorized as doctoral students or faculty members. When a user uses the student ID card replacement service, the system will process the replacement as a doctoral student. Similarly, when a user uses the faculty email application service, the system will process the email application as a faculty member, creating a personal university email account. Furthermore, the system will separately store data records for student ID card replacements and email application applications.

[0065] In some embodiments, based on the aforementioned basic personnel information table, a personal data center application can also be built. Specifically: Reference Figure 3Using the basic personnel identification code as a link, it connects to the personnel's business identification code, and then links to all user data, such as library borrowing data, campus card consumption data, online service data, access control data, venue usage data, internet access data, etc. Based on the full lifecycle data of personnel, it constructs a system for recording personnel's entire campus lifecycle data and displaying data analysis results. It should be noted that the data association relationships are shown in Table 2.

[0066] Table 2: A data association relationship for the same user.

[0067] It should be noted that the first column in Table 2 represents the basic personnel identification code of the same user, the second column represents the business identification codes of different personnel of the same user, and the third column represents the data records under different identities of the same user.

[0068] Users can log in to their personal data center using any of their identification codes (i.e., basic personnel identification codes and personnel business identification codes, such as student codes, faculty / staff codes, visitor codes, etc.). The personal data center displays all data records and data analysis results for each individual, not just data records and analysis results for a specific student ID or employee ID. The specific logic is as follows: Figure 4 As shown.

[0069] In some embodiments, the display module of a personal data center may include, but is not limited to: Campus Time is used to display an individual's entire activity record during their time on campus, including spending records, borrowing records, travel records, class records, errand records, internet browsing records, awards records, thesis defense records, internship records, etc. It can also be categorized and displayed according to different stages, such as visitor stage, undergraduate stage, master's stage, doctoral stage, and faculty / staff stage.

[0070] My teaching is used to demonstrate the number of courses I taught and the number of class hours I took during my time at school.

[0071] My grades are used to showcase my academic performance, including grades and GPA, during my time at university. They are also analyzed and displayed in categories such as undergraduate, master's, and doctoral studies.

[0072] My research is used to showcase my research projects, achievements, and awards during my time at university, and is analyzed and presented in categories such as undergraduate, master's, doctoral, and faculty / staff stages.

[0073] My assets section is used to showcase my personal asset allocation during my time at school.

[0074] My students is used to showcase the students I taught during my time at the school.

[0075] My Borrowings section is used to display an overview of the books I have borrowed during my time at the university, and it is analyzed and displayed in categories such as undergraduate, master's, doctoral, and faculty / staff.

[0076] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0077] Based on the same inventive concept, this application also provides an identity authentication device for implementing the aforementioned identity authentication method. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more identity authentication device embodiments provided below can be found in the limitations of the identity authentication method described above, and will not be repeated here.

[0078] In one exemplary embodiment, such as Figure 5 As shown, an identity authentication device is provided, comprising: a first determining module 100, a searching module 200, and a second determining module 300, wherein: The first determining module 100 is used to, after the user completes authentication on the unified identity authentication platform, respond to the identity authentication request input by the user and determine the basic personnel information table corresponding to the user based on the basic personnel identity code provided by the unified identity authentication platform; wherein, the basic personnel identity code is used to uniquely identify the user.

[0079] The lookup module 200 is used to retrieve the user's corresponding identity type and identity status from the basic personnel information table.

[0080] The second determining module 300 is used to determine that authentication is successful if the identity type and the identity status indicate that the user has permission to enter the business system.

[0081] In some embodiments, the personnel basic information table includes personnel basic identity code, personnel business identity code, ID card number, mobile phone number, identity type, identity status, facial image, fingerprint features, and iris features.

[0082] In some embodiments, the unified identity authentication platform performs authentication based on the personnel's business identity code, the ID card number, and the mobile phone number.

[0083] If the identity type includes the identity type specified by the business system, and the identity status corresponding to the specified identity type is the target identity status, then the user is instructed to have permission to enter the business system.

[0084] In some embodiments, where both the identity type and the identity state indicating that the user has permission to access the business system are at least two, the identity authentication device further includes: The invocation module is used to invoke the rule engine in response to the user's selection operation for the target service, and to determine the target identity type of the user when using the target service from at least two of the identity types.

[0085] In some embodiments, the calling module is specifically used for: In response to the user's selection of a target service, obtain the time information corresponding to the selection operation.

[0086] Based on the time information, the call rule engine determines the target identity type that matches the time information when the user uses the target service, from at least two identity types.

[0087] In some embodiments, the calling module is specifically used for: In response to the user's selection of a target service, retrieve the user's previous service after this business system interaction.

[0088] Based on the previous service call rule engine, the target identity type that matches the previous service when the user uses the target service is determined from at least two identity types.

[0089] In some embodiments, the calling module is specifically used for: In response to the user's selection operation for the target service, the rule engine is invoked to determine the user's historical identity type when using the target service from at least two identity types; wherein, the historical identity type is the identity type whose selection rate in the historical identity selection records corresponding to the target service is greater than a preset selection rate.

[0090] In some embodiments, where both the identity type and the identity state indicating that the user has permission to access the business system are at least two, the identity authentication device further includes: The output module is used to output an identity selection prompt pop-up window, wherein the identity selection prompt pop-up window is used to allow the user to select the target identity type from all available identity types when using the target service.

[0091] Each module in the aforementioned identity authentication device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0092] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements an authentication method.

[0093] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0094] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0095] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0096] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0097] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0098] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. An identity authentication method, characterized in that, The authentication method, applied to computer equipment with deployed business systems, includes: After a user completes authentication on the unified identity authentication platform, in response to the user's authentication request, the platform determines the user's basic information table based on the user's basic identity code provided by the unified identity authentication platform; wherein, the basic identity code is used to uniquely identify the user. The user's identity type and identity status are retrieved from the basic personnel information table; If the identity type and identity status indicate that the user has permission to access the business system, then authentication is successful.

2. The identity authentication method according to claim 1, characterized in that, The basic personnel information table includes personnel basic identity code, personnel business identity code, ID card number, mobile phone number, identity type, identity status, facial image, fingerprint features, and iris features.

3. The identity authentication method according to claim 2, characterized in that, The unified identity authentication platform authenticates individuals based on their business identity code, ID card number, and mobile phone number. If the identity type includes the identity type specified by the business system, and the identity status corresponding to the specified identity type is the target identity status, then the user is instructed to have permission to enter the business system.

4. The identity authentication method according to claim 1, characterized in that, When both the identity type and the identity status indicating that the user has permission to access the business system are at least two, the method further includes: In response to the user's selection of a target service, the rules engine is invoked to determine the target identity type of the user when using the target service from at least two identity types.

5. The identity authentication method according to claim 4, characterized in that, In response to the user's selection of a target service, the rule engine is invoked to determine the target identity type of the user when using the target service from at least two identity types, including: In response to the user's selection operation for the target service, obtain the time information corresponding to the selection operation; Based on the time information, the call rule engine determines the target identity type that matches the time information when the user uses the target service, from at least two identity types.

6. The identity authentication method according to claim 4, characterized in that, In response to the user's selection of a target service, the rule engine is invoked to determine the target identity type of the user when using the target service from at least two identity types, including: In response to the user's selection of a target service, retrieve the user's previous service after this business system interaction; Based on the previous service call rule engine, the target identity type that matches the previous service when the user uses the target service is determined from at least two identity types.

7. The identity authentication method according to claim 4, characterized in that, In response to the user's selection of a target service, the rule engine is invoked to determine the target identity type of the user when using the target service from at least two identity types, including: In response to the user's selection operation for the target service, the rule engine is invoked to determine the user's historical identity type when using the target service from at least two identity types; wherein, the historical identity type is the identity type whose selection rate in the historical identity selection records corresponding to the target service is greater than a preset selection rate.

8. The identity authentication method according to claim 1, characterized in that, When both the identity type and the identity status indicating that the user has permission to access the business system are at least two, the method further includes: An identity selection prompt pop-up is output, wherein the identity selection prompt pop-up is used to allow the user to select the target identity type from all available identity types when using the target service.

9. A computer device, characterized in that, It includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the authentication method as described in any one of claims 1-8.

10. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the authentication method as described in any one of claims 1-8.