Method and device for providing security identity information and method and device for capturing security identity information
Patent Information
- Application Number
- DE602019072449
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2018-11-16
- Filing Date
- 2019-10-09
- Publication Date
- 2025-07-09
- Estimated Expiration
- 2039-10-09
AI Technical Summary
Conventional identity verification methods face challenges in ensuring security and convenience, particularly in offline scenarios where users may not carry identity documents and require partial information verification, and digitized identity verification is susceptible to security threats.
A method and apparatus using a trusted application to scan a QR code generated by a registration platform, which collects user identity information, verifies it through third-party sources, and encrypts it with the service provider's public key before transmission.
Ensures accurate and secure identity verification by leveraging third-party verification sources and encryption, providing flexibility and convenience in offline identity information provision.
Description
TECHNICAL FIELD
[0001] One or more embodiments of the present specification relate to the field of secure authentication of identity, and relate, in particular, to a method and an apparatus for providing and obtaining secure identity information.BACKGROUND
[0002] In various offline application scenarios, conventional identity verification for a user is usually implemented based on an identity document, i.e., following the logic of "verifying the authenticity of a person's identity by an identity document." In a specific implementation, a natural person provides an identity document (such as an identity card, a passport, etc.), and a natural person representing a scenario merchant (such as a front desk staff of a hotel and a window clerk in an administrative service hall) confirms a corresponding relationship between the user and the identity document through visual inspection, and confirms the authenticity of the identity document through visual inspection or with the assistance of a card reader. On this basis, the required verification information is obtained from the identity document and may be considered as trusted identity information, and services are then provided according to the service logic of the scenario merchant.
[0003] However, with the continuous enhancement of user privacy protection (such as the minimum viable principle) and the increasingly high requirements of users for convenience, the above conventional offline verification method for user identity is currently facing increasingly more challenges, and cannot meet requirements in many scenarios. For example: --a user may not carry his / her identity card; --in some low-level offline application scenarios, a user is unwilling to hand over a core document such as an identity card to others for verification or even keeping a copy; and --a service itself needs only a part of user information, not all key element information in the identity card.
[0004] With the continuous development of online commercialization and the popularization of real-name / real-person / real-identity document and other authentication methods in cyberspace, digitization of identity documents has become a future trend. However, identity verification based on the digitization of identity documents also faces security threats. For example, a photo of the electronic version of an identity card may be photoshopped (an attack against the real-name verification), face verification may be compromised (an attack against the real-name and real-person verifications), and the like. A trusted verification source is thus required to provide identity verification services, for example, the identity document database of the Ministry of Public Security, the population database, and the like.
[0005] Therefore, it is expected to have an improved solution to implement identity verification more safely and conveniently.
[0006] EP2834959A1 (corresponding to WO2013151854A1) states that "A user device transmits a login request. A provider server, receives a random number from and transmits other information to an authentication server. The provider server transmits the random number to the device. The random number is transferred to a second user device, which transmits it to the authentication server. The authentication server transmits provider authentication policy requirements and further transmits the other information to the second device. The second device transmits user validation information to the authentication server. The authentication server determines that the transmitted validation information corresponds to the service provider authentication policy requirements, compares the validation information with stored validation information for the user to authenticate the user. The second device transmits a message, including the random number and the other information, signed with a user credential to the authentication server. The authentication server transmits notice of authentication and the signed message to the provider server."
[0007] EP3319070A1 in an abstract states that "The invention relates to a method for authenticating a user, the method comprising: receiving from a secure processor (ASRV, SE), a software component (GC) configured to generate an image frame comprising random pixels (PXi) having a probability lower than 100% to be visible in the image frame; executing the software component a plurality of times to generate a plurality of image frames; displaying the plurality of image frames at a frame display rate, the image frames including information (ND) which is machine unintelligible as being formed of the random pixels, the frame display rate being such that the information becomes intelligible to the user, the information specifying a biometric challenge to enter by the user; acquiring biometric data (BIOD) from the user; and transmitting the biometric data to the secure processor."SUMMARY
[0008] The present invention is set out in the independent claims, with some optional features set out in the claims dependent thereto.
[0009] One or more embodiments of the present specification describe a method and an apparatus for providing and obtaining secure identity information. Through such method and apparatus, a user can use a trusted application offline to safely and conveniently providing verified secure identity information to the service provider, by scanning a two-dimensional code displayed by a service provider.
[0010] According to the first aspect, a method for providing secure identity information is provided, wherein the method is performed by a trusted obtaining QR code information corresponding to a QR code scanned by a user, wherein the QR code is generated by a registration platform in advance for a first service provider; sending a query request to the registration platform, wherein the query request comprises the QR code information; receiving a query result from the registration platform, wherein the query result comprises identification information of the first service provider, a public key of the first service provider, and first identity information required by the first service provider; obtaining second identity information of the user; sending the second identity information of the user to a verification source to obtain a verification result; generating secure identity information, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, the encrypted information is obtained by encrypting the verified first identity information by using the public key of the first service provider, and the verified first identity information is determined based on the second identity information and the verification result; and sending the secure identity information to the registration platform, such that the registration platform sends the encrypted information to the first service provider.
[0011] According to one implementation manner, obtaining the second identity information of the user comprises collecting the second identity information through a terminal where a client of the trusted application is located.
[0012] Further, in a specific embodiment, collecting the second identity information may comprise one or more of the following: collecting face information through a camera on the terminal; and reading identity card information through an NFC function of the terminal and controls thereon.
[0013] According to another implementation manner, obtaining the second identity information of the user comprises receiving input information of the user through the client of the trusted application.
[0014] In a possible design, the above method further comprises determining the verification source and a required verification mode according to the required first identity information and the obtained second identity information.
[0015] Further, in one embodiment, the obtained second identity information comprises the required first identity information; in this case, determining the verification source and the required verification mode comprises determining that the required verification mode is an authentication mode, and in the authentication mode, the verification result is a notification result of whether the verification is successful.
[0016] In another embodiment, the obtained second identity information is a part of the required first identity information; in this case, determining the verification source and the required verification mode comprises determining that the required verification mode is an information mode, and in the information mode, the verification result comprises a notification of whether the verification is successful, and supplementary identity information determined based on at least a part of the successfully verified second identity information.
[0017] According to one embodiment, it is determined that the required verification source comprises a first verification source and a second verification source; in this case, sending the second identity information of the user to the verification source to obtain a verification result specifically comprises: sending a first part of the second identity information to the first verification source, and sending a second part of the second identity information to the second verification source; receiving a first result from the first verification source, and receiving a second result from the second verification source; and combining the first result and the second result to obtain the verification result.
[0018] In one embodiment, the secure identity information is generated in the following manner: obtaining verified first identity information based on the second identity information and the verification result; encrypting the verified first identity information by using the public key of the first service provider to obtain the encrypted information; and generating the secure identity information based on the encrypted information and the identification information of the first service provider.
[0019] In one example, the above verification result is a notification result of successful verification in the authentication mode; at this time, the successfully verified second identity information may be used as the verified first identity information.
[0020] In another example, the above verification result comprises a notification of successful verification and supplementary identity information determined based on at least a part of the successfully verified second identity information; at this time, the successfully verified second identity information and the supplementary identity information may be used as the verified first identity information.
[0021] According to the second aspect, a method for obtaining secure identity information is provided, wherein the method is performed by a registration platform, comprising: receiving a query request from a first application, wherein the query request comprises QR code information, and the QR code information is obtained by scanning, by using the first application, a QR code generated by the registration platform in advance for a first service provider; determining registration information of the first service provider based on the QR code information, wherein the registration information comprises at least a public key of the first service provider and first identity information required by the first service provider; sending a query result to the first application, wherein the query result comprises identification information of the first service provider, the public key of the first service provider, and the first identity information; receiving secure identity information from the first application, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, and the encrypted information is obtained by encrypting the verified first identity information by using the public key of the first service provider; and sending the encrypted information to the first service provider according to the identification information of the first service provider.
[0022] In one embodiment, before receiving a query request from the first application, the method further comprises: receiving the registration information from the first service provider; and generating a QR code for the first service provider based on the registration information.
[0023] In one embodiment, the registration information further comprises routing information of the first service provider; and sending the encrypted information to the first service provider specifically comprises: extracting the identification information of the first service provider and the encrypted information respectively from the secure identity information; determining the routing information of the first service provider according to the identification information of the first service provider; and sending the encrypted information to a terminal corresponding to the first service provider according to the routing information.
[0024] According to a possible design, the registration center and a server of a specific application are located in the same physical entity; moreover, the query request comprises a first field, in the case that the first field has a first value, the first application is indicated to be the specific application, and in the case that the first field has a second value, the first application is indicated not to be the specific application.
[0025] Further, in one embodiment, the first field has a first value; at this time, the query result may be provided locally to application logic of the first application; and the secure identity information is obtained locally from the application logic of the first application.
[0026] According to the third aspect, an apparatus for providing secure identity information is provided, wherein the apparatus is deployed in a trusted application server, comprising: a QR code obtaining unit configured to obtain QR code information corresponding to a QR code scanned by a user, wherein the QR code is generated by a registration platform in advance for a first service provider; a query request sending unit configured to send a query request to the registration platform, wherein the query request comprises the QR code information; a query result receiving unit configured to receive a query result from the registration platform, wherein the query result comprises identification information of the first service provider, a public key of the first service provider, and first identity information required by the first service provider; an identity information obtaining unit configured to obtain second identity information of the user; a verification sending unit configured to send the second identity information of the user to a verification source to obtain a verification result; a secure information generation unit configured to generate secure identity information, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, the encrypted information is obtained by encrypting the verified first identity information by using the public key of the first service provider, and the verified first identity information is determined based on the second identity information and the verification result; and a secure information sending unit configured to send the secure identity information to the registration platform, such that the registration platform sends the encrypted information to the first service provider.
[0027] According to the fourth aspect, an apparatus for obtaining secure identity information is provided, wherein the apparatus is deployed in a registration platform, comprising: a query request receiving unit configured to receive a query request from a first application, wherein the query request comprises QR code information, and the QR code information is obtained by scanning, by using the first application, a QR code generated by the registration platform in advance for a first service provider; a registration information determination unit configured to determine registration information of the first service provider based on the QR code information, wherein the registration information comprises at least a public key of the first service provider and first identity information required by the first service provider; a query result sending unit configured to send a query result to the first application, wherein the query result comprises identification information of the first service provider, the public key of the first service provider, and the first identity information; a secure information receiving unit configured to receive secure identity information from the first application, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, and the encrypted information is obtained by encrypting the verified first identity information by using the public key of the first service provider; and an encrypted information sending unit configured to send the encrypted information to the first service provider according to the identification information of the first service provider.
[0028] According to the fifth aspect, a computer-readable storage medium having a computer program stored thereon is provided, wherein when executed in a computer, the computer program causes the computer to perform the method in the first aspect to the second aspect.
[0029] According to the sixth aspect, a computing device comprising a memory and a processor is provided, wherein the memory stores executable code, and when the processor executes the executable code, the methods in the first aspect to the second aspect are performed.
[0030] Through the method and apparatus provided in the embodiments of the present specification, in situations where identity verification is required, a user uses a trusted application to scan a QR code displayed by a service provider, thereby providing verified identity information to the service provider through a registration platform. Before providing the identity information, the trusted application first sends the identity information of the user to a third-party verification source for verification, thus ensuring the accuracy and authority of the provided identity information. Moreover, in the above process, interconnection between different service providers and different trusted applications is implemented through the registration platform. In this way, the service provider does not need to pay attention to an application used by the user to provide the identity information, and the verification is more flexible and convenient.BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to explain the technical solutions of the embodiments of the present invention more clearly, accompanying drawings used in the description of the embodiments will briefly introduced below. It is apparent that the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other accompanying drawings can be obtained from these accompanying drawings without creative efforts. FIG. 1 is a schematic diagram of an implementation scenario of an embodiment disclosed in the present specification FIG. 2 shows a method for obtaining secure identity information according to an embodiment; FIG. 3 shows a method for obtaining secure identity information according to another embodiment; FIG. 4 is a schematic block diagram of an apparatus for providing secure identity information according to an embodiment; and FIG. 5 is a schematic block diagram of an apparatus for obtaining secure identity information according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] The solutions provided by the present specification are described below with reference to the accompanying drawings.
[0033] FIG. 1 is a schematic diagram of an implementation scenario of an embodiment disclosed in the present specification. According to the embodiment of FIG. 1, various service providers (that is, the foregoing scenario merchants) that require secure identity information register with a registration platform in advance, and the registration platform generates exclusive QR codes for the various service providers. In an offline scenario where identity verification or provision of identity information is required, a user does not need to directly provide identity information to the staff of a service provider, but uses a trusted application to scan a QR code displayed by the service provider, and then the obtained user identity information is submitted to an authoritative third-party verification source for identity verification. After the verification is successful, the trusted application provides encrypted identity information to the service provider through the registration platform.
[0034] Specifically, in the case that the user needs to perform identity verification or provide secure identity information, the user first scans, by using a scanning function in the trusted application, the QR code displayed by the service provider. Then, the trusted application initiates a query to the registration platform for the QR code. The QR code is generated by the registration platform for the service provider, and therefore, the registration platform can obtain information corresponding to the QR code by query, including information regarding what identity information is required by which service provider. Once a query result containing the above information is obtained, the trusted application may correspondingly obtain the identity information of the user, such as name, identity card information, and face information, and then send the information to a third-party verification source for verification. If the verification is successful, the trusted application encrypts the successfully verified identity information and sends the same to the registration platform. After parsing, the registration platform forwards the encrypted identity information to the service provider. In this way, the service provider can obtain the required identity information through decryption. Specific implementation steps of the above process are described below.
[0035] FIG. 2 shows a method for obtaining secure identity information according to an embodiment. As shown in FIG. 2, the method at least involves a trusted application, a verification source, a registration platform, and a service provider.
[0036] The verification source, also referred to as a trusted verification source or a third-party verification source, is a third party that provides a trusted identity information verification service. The third-party verification source usually possesses a trusted database and is configured with a verification strategy for trusted electronic identity, usually supports trusted credentials, and verifies, according to provided user information, whether it is true and accurate. Moreover, a verification result thereof is considered accurate and effective. The above verification source includes, for example, the cyber trusted identification CTID platform currently established by the First Research Institute of the Ministry of Public Security, the population database, and the like.
[0037] The service provider, or referred to as a scenario merchant, is a service application party that requires secure identity information in an offline application scenario. The service provider originally needs to confirm the user identity offline according to a physical identity document, and conducts services according to service logic after determining the trusted identity information of the user, such as a hotel, an administrative service hall, an Internet café, etc., that require identity verification.
[0038] The trusted application is an application trusted by the scenario merchant and the third-party verification source. The trusted application interfaces with the trusted verification source, and the credibility of both parties is ensured through signatures. The trusted application is, for example, Alipay.
[0039] The registration platform is responsible for maintaining the registration of the service provider, the registration of the trusted application, and the mapping and parsing of registration information and code strings. The registration platform can interface with several trusted applications and many service providers.
[0040] In the following, a process of obtaining and displaying a QR code by a service provider is first described, which corresponds to steps S101 to S104 in FIG. 2.
[0041] First, in step S101, a service provider that requires secure identity information submits registration information to a registration platform to request a QR code. Generally, the registration information includes at least a name of the service provider (such as a merchant id), a public key of the service provider, routing information of the service provider (such as a destination address and gateway information), and identity information required by the service provider, referred to as first identity information hereinafter. Optionally, the registration information may also include other information, such as some description information.
[0042] In different embodiments, the first identity information may include one or more of name, identity card number, ethnicity, validity period of the identity document, face photo, driver's license information, and the like. The specific content is set by the service provider according to service logic thereof or is uniformly regulated by the industry to which the service provider belongs.
[0043] The registration platform generates a service index, or referred to as a service token, for the registration information submitted by the service provider and binds the service index to the registration information, in other words, stores the service index and the registration information associatively and correspondingly.
[0044] Next, in step S102, the registration platform generates QR code information according to the registration information of the service provider. It could be understood that each QR code may correspond to a code string, and the code string may be mapped to a QR code. Therefore, the QR code information referred to herein may be either the QR code itself or the code string corresponding to the QR code.
[0045] Specifically, in one example, the registration platform may compile the above service index into a code string to generate a QR code. In another example, the registration platform may also compile registration information into a code string to generate a QR code.
[0046] In step S103, the registration platform returns the QR code information to the service provider. In this step, the registration platform may return either a QR code pattern or a code string to the service provider, such that the service provider can map the code string to a QR code according to an agreed method.
[0047] Therefore, in step S104, the service provider can display the QR code according to the obtained QR code information for a user in need to scan. For example, the service provider may print out the QR code and display the same at the reception; or, the service provider may use an electronic display device to display the QR code.
[0048] It should be understood that the above process of obtaining and displaying the QR code is a preliminary step for the user to perform security verification through the QR code, which is performed in advance before the user performs the identity verification and provides the secure identity information.
[0049] A process in which the user performs identity verification by code scanning using the trusted application and then provides secure identity information to the service provider is described below.
[0050] It could be understood that the user is usually a natural person and is also a subject of electronic identity verification, such as an Alipay user. When the user encounters a scenario that requires identity verification offline, for example, when checking in a hotel that requires identity verification, instead of providing the identity card to the receptionist of the hotel, the user may open the trusted application and request the trusted application to scan the QR code displayed by the service provider. In other words, as shown in FIG. 2, in step S201, the user sends a request to the trusted application for requesting the trusted application to perform code scanning and read the QR code displayed by the service provider. For example, in one example, the user may open Alipay and click "Scan" to send a code scanning request.
[0051] In step S202, the trusted application performs code scanning to obtain QR code information corresponding to the QR code scanned by the user. It could be understood that the QR code is generated by the registration platform in advance for the service provider, as shown in the foregoing steps S101-S104.
[0052] More specifically, a client of the trusted application reads an image of the QR code by calling a camera equipped on a terminal where the client resides, obtains corresponding QR code information, and transmits the QR code information to a server.
[0053] It could be understood that the QR code will carry information of a generator of the QR code, such as an identification or address. Therefore, after scanning the QR code, the trusted application may parse the QR code in a conventional manner, determine the registration platform that generates the QR code, and obtain a code string corresponding to the QR code. However, it should be understood that the above QR code information is generated by the registration platform performing various operations such as encoding and mapping based on the registration information of the service provider according to a certain rule (as shown in the foregoing step S102). Although the trusted application can read the code string corresponding to the QR code, it cannot obtain the service provider information by parsing the code string. Therefore, the trusted application still needs to interact with the registration platform to obtain information related to the service provider by query.
[0054] Therefore, in step S203, the trusted application (server) sends a query request to the registration platform, and the query request includes the QR code information.
[0055] In step S204, the registration platform performs query according to the received query request. Specifically, the query includes at least determining a corresponding service provider and registration information of the service provider based on the QR code information contained in the query request. In one example, the registration platform may determine the corresponding service index based on the QR code information, and then determine associatively stored registration information based on the service index. As mentioned above, the registration information includes at least the name of the service provider, the public key of the service provider, the routing information of the service provider, and the identity information required by the service provider. The identity information required by the service provider is referred to as first identity information below. It should be understood that the "first" and "second" herein are merely used for clear expression to mark and distinguish similar concepts, and do not have other limiting effects.
[0056] It could be understood that the QR code displayed by the service provider is generated by the registration platform according to the registration information of the service provider in the previous step S102. Therefore, the registration platform can reversely determine the registration information of the service provider from the QR code information according to a reverse operation of the operation used when the QR code is generated.
[0057] After the registration information of the service provider is obtained by query, in step S205, the registration platform returns a query result to the trusted application, which includes the identification information of the service provider, the public key of the service provider, and the first identity information required by the service provider. Here, the registration platform may use the name of the service provider in the registration information as the identification information of the service provider, or use the service index generated by the registration platform therefor as the identification information, as long as the registration platform can determine information of the corresponding service provider according to the identification information.
[0058] Subsequent to receiving such query result, in step S206, the trusted application obtains various types of identity information of the user according to the first identity information required by the service provider, and the obtained user identity information is referred to as second identity information.
[0059] Specifically, the identity information of the user may be obtained by adopting a plurality of methods such as hardware collection, manual input by the user, and reading of existing information. In one implementation manner, the trusted application first determines a method of obtaining user identity information according to content of the to-be-obtained identity information, as well as the configuration status of hardware and control of the terminal where it is located.
[0060] In one embodiment, the terminal is configured with corresponding hardware and controls, and then obtaining second identity information in step S206 may include collecting the second identity information through the terminal where the client of the trusted application is located. For example, in one example, the face information can be collected through a camera on the terminal; and in another example, the identity card information can be read through an NFC function of the terminal and controls thereon.
[0061] In another embodiment, obtaining second identity information in the step S206 may include rendering an input interface through the client of a trusted application, and receiving input information of the user. For example, the input information may include a user name, an identity card number, a password, and the like.
[0062] In another embodiment, obtaining second identity information in the step S206 may include reading user identity information stored in the trusted application. For example, the user may store his / her name and identity card number in the client or server of the trusted application in advance. In this way, in step 206, the user identity information that has been stored in the trusted application can be directly extracted, so as to reduce the number of manual inputs by the user and improve the convenience of the user.
[0063] The above embodiments may be used in combination. For example, in one example, a second-generation identity card of the user can be read through an NFC function and corresponding controls of a terminal to obtain the name, identity card number, and validity period of the identity document, and a face photo can be collected through the camera of the terminal to be used as the second identity information.
[0064] In another example, the name and identity card number manually input by the user can be received through the client, and the face photo can be collected through the camera to be used as the second identity information.
[0065] In this way, in step S206, the trusted application obtains the second identity information of the user through a plurality of methods.
[0066] After obtaining the identity information of the user, the trusted application needs to submit the obtained identity information to the verification source for verification to ensure the security and accuracy of the identity information. In the case that an interfaced verification source is not unique, and / or a verification mode is not unique, in one embodiment, after the trusted application obtains the second identity information, in step S207, the required verification source and the required verification mode are determined according to the required first identity information and the obtained second identity information.
[0067] It could be understood that the trusted application may interface with a plurality of verification sources in advance. When interfacing with each verification source, the two parties will have a clear agreement on what information to be verified and a supported verification mode. Therefore, the required verification sources and the required verification mode may be determined according to information content of the first identity information and the second identity information.
[0068] Generally, the verification mode provided by the verification source includes an authentication mode and an information mode. In the authentication mode, after verifying the sent identity information, the verification source returns a notification result of whether the verification is successful. In the information mode, the verification result returned by the verification source includes a notification of whether the verification is successful, and supplementary identity information determined based on the successfully verified identity information.
[0069] In one implementation manner, the second identity information obtained in step S206 is the first identity information required by the service provider, and may even contain more content. In this case, it can be determined in step S207 that only the authentication mode is required. In other words, it only needs to know whether each item of the second identity information is successfully verified.
[0070] In another possible implementation manner, due to difficulty in collection or other reasons, the obtained second identity information may also be a part of the first identity information. At this time, it is necessary to provide supplementary information by assistance of the verification source. Therefore, in this case, it can be determined in step S207 that the required verification mode is the information mode.
[0071] Therefore, in step S208, the trusted application sends the second identity information to the corresponding verification source according to the verification source and verification mode determined above, and requests verification in the corresponding verification mode. In this process, the trusted application and the verification source may establish a trust relationship through a signature and signature verification, thus ensuring data security and effectiveness.
[0072] In step S209, the verification source verifies the obtained identity information according to the requested verification mode.
[0073] In the authentication mode, the verification of the verification source for the identity includes comparison of information. In one example, the verification source stores complete user information. In this case, the verification source performs user identity verification by directly comparing the obtained second identity information with the stored user information. In another example, in order to avoid being attacked and leaking user information in batches, the verification source may therefore configure a policy to store only a hash value of the user information. In this case, the verification source performs the same hash operation on the received user identity information, and compares the computed hash value with the stored hash value to thus perform user identity verification. Further, the verification source may delete the received user information within a certain time interval to increase the security.
[0074] In the information mode, the verification source first compares the received identity information with the stored corresponding information, and after confirming that the received identity information is accurate and contains no error, determines supplementary identity information based on such information.
[0075] For example, as a verification source, the population database may perform verification on the received user name and identity card number in the information mode. After the verification is successful, ethnic information of the user is determined as the supplementary identity information based on the name and identity card number.
[0076] After the verification, in step S210, the verification source returns a verification result to the trusted application. As mentioned above, in the authentication mode, the verification source may feed back the notification result of successful / failed verification, and in the information mode, the verification source may also return the supplementary identity information.
[0077] The process of performing identity verification through a single verification source is described above. However, in some cases, a single verification source is not enough to verify and obtain the first identity information. Therefore, in step S207, it can be determined that multiple verification sources are required. For simplicity and convenience of description, it is assumed that the required verification sources include a first verification source and a second verification source.
[0078] In this case, in step S208, the trusted application sends a first part of the second identity information to the first verification source, and sends a second part of the second identity information to the second verification source. In one embodiment, the above first part and second part may have an intersection.
[0079] In step S209, the first verification source verifies the first part of the second identity information, and the second verification source verifies the second part of the second identity information.
[0080] In step S210, the trusted application receives a first result from the first verification source and a second result from the second verification source. After that, the trusted application further combines the first result and the second result to obtain an overall verification result.
[0081] The above multiple verification sources may each have a different verification mode. Therefore, embodiments of different numbers of verification sources can be combined with embodiments of performing verification in different modes.
[0082] For example, in one embodiment, the first identity information required by the service provider includes: user name, identity card number, face, and user ethnicity. In step S206, the obtained second identity information includes: the name and identity card number manually input by the user, and the collected face photo. According to the above first identity information and second identity information, the trusted application determines that the verification source of the First Research Institute of the Ministry of Public Security (the first verification source) may be adopted to verify the name, identity card number, and face in the authentication mode, and the population database (the second verification source) may be adopted to obtain, in the information mode, ethnic information through the user name + identity card number and use the same as supplementary identity information.
[0083] Therefore, in step S208, the trusted application sends the user name, identity card number, and face to the First Research Institute of the Ministry of Public Security to request verification in the authentication mode, and sends the user name and identity card number to the population database to request verification in the information mode.
[0084] In another embodiment, the first identity information required by the service provider includes: user name, identity card number, face, and user ethnicity. In step S206, the obtained second identity information includes: the name, identity card number, and ethnicity manually input by the user, and the collected face photo. According to the above first identity information and second identity information, the trusted application determines that the verification source of the First Research Institute of the Ministry of Public Security (the first verification source) may be adopted to verify the name, identity card number, and face in the authentication mode, and the population database (the second verification source) may be adopted to verify the ethnic information of the user in the authentication mode.
[0085] Therefore, in step S208, the trusted application sends the user name, identity card number, and face to the First Research Institute of the Ministry of Public Security to request verification in the authentication mode, and sends the user name, identity card number, and ethnicity to the population database to request verification in the authentication mode.
[0086] In step S210, the trusted application obtains verification results of various verification sources, and combines the verification results. According to the verification modes of the different verification sources, the combined verification result can be expressed in different forms.
[0087] In one example, the combined verification result includes content of various verified information items. For example, in a specific example, the verification result may be expressed as: the user name is **, the user identity card number is **, the user ethnicity is ***, and the user face is consistent with the face on the identity card.
[0088] In another example, the combined verification result includes a result of whether various information items obtained in the authentication mode are correct. For example, in a specific example, the verification result may be expressed as: the user name is correct, the user identity card number is correct, the user ethnicity is correct, and the user face is consistent with the face on the identity card.
[0089] In another example, the combined verification result includes content of various information items obtained in the authentication mode, and a result of whether the content is correct, as well as supplementary identity information provided in the information mode. For example, in one example, the verification result may be expressed as: the user name is *** and is correct, the user identity card number is *** and is correct, the user ethnicity is *** (supplementary identity information), the user face is consistent with the face on the identity card.
[0090] It could be understood that the specific expression form of the verification result may not be limited to the above examples.
[0091] Based on the verification result obtained above, in step S211, the trusted application generates secure identity information.
[0092] Specifically, in one embodiment, the trusted application may first obtain the verified first identity information based on the second identity information and the above verification result.
[0093] More specifically, in one example, the obtained second identity information has information items consistent with those of the required first identity information, or even contains more content. Moreover, in the foregoing steps, it is requested to perform verification on the second identity information in the authentication mode. If the verification result shows that the various information items of the second identity information are successfully verified, then the successfully verified second identity information can be used as the verified first identity information.
[0094] In another example, the obtained second identity information is a part of the required first identity information. Moreover, in the foregoing steps, it is requested to perform verification on the second identity information in the information mode. If the verification result in the information mode includes the notification of successful verification and the supplementary identity information determined based on the information items that are successfully verified, then in this step, the successfully verified second identity information and the supplementary identity information are together used as the verified first identity information.
[0095] Then, the trusted application uses the public key of the service provider obtained in step S205 to encrypt the verified first identity information obtained in the foregoing, to obtain encrypted information.
[0096] In addition, the trusted application further attaches the identification information of the service provider in addition to the above encrypted information, and then generates the secure identity information.
[0097] Next, in step S212, the trusted application sends the abovementioned generated secure identity information to the registration platform.
[0098] In step S213, the registration platform sends the encrypted information in the secure identity information to the service provider.
[0099] Specifically, after receiving the above secure identity information, the registration platform may extract the encrypted information and the identification information of the service provider therefrom. Once the identification information of the service provider is obtained, the registration platform can determine the corresponding service provider, and determine routing information of the service provider, such as a destination address, according to the information when the service provider is registered. Then, the trusted application sends the encrypted information to the terminal corresponding to the first service provider according to the routing information (for example, the destination address).
[0100] After receiving the encrypted information, the service provider decrypts the encrypted information in step S214 to obtain the required first identity information.
[0101] It could be understood that the encrypted information is obtained by the trusted application encrypting the verified first identity information using the public key of the service provider, and the service provider locally stores a private key corresponding to the public key. The public key is a key paired with the private key, and can be used to decrypt data encrypted by the other key. Therefore, in one embodiment, the service provider uses its own private key to decrypt the received encrypted information, so as to obtain the verified first identity information of the user.
[0102] After obtaining the required identity information, the service provider may conduct services based on its service logic. For example, an Internet cafe may determine whether the age of a user meets a standard, a hotel may perform check-in based on the name and identity card number of a user, and the like.
[0103] As can be seen from the above description, in an offline scenario where identity verification or provision of identity information is required, a user does not need to hand over an identity document to the staff of a service provider, but can use a trusted application to scan a QR code displayed by the service provider, wherein the QR code is generated by the service provider registering with the registration platform in advance. After scanning the code, the trusted application obtains, by making a query to the registration platform, information regarding what identity information is required by the service provider, and then collects and obtains the identity information of the user. After that, the trusted application sends the obtained identity information to a verification source for verification, encrypts the successfully verified identity information, and forwards the same to the service provider through the registration platform. In this process, a public registration platform is introduced to implement interconnection between different service providers and different trusted applications. Therefore, a service provider only needs to display a QR code, which can be applied to a plurality of types of trusted applications interfaced with the registration platform, and it is unnecessary to display a QR code for each application. In addition, only after sending the identity information of the user to a third-party verification source for verification, the trusted application provides the verified identity information to the service provider, thus ensuring the accuracy and authority of the provided identity information.
[0104] As known by those skilled in the art, generally, a trusted application includes a client and a server. The client is, for example, an App installed on a mobile terminal (for example, the Alipay App), or an application software client on a PC. In the method shown in FIG. 2, interactions between the trusted application and the user are all performed through the client. For example, in step S201, the user sends a code scanning request through the client, for example, clicks a corresponding option in a client interface, such as "Scan." In step S202, the client calls the camera of the terminal to read the QR code, obtains the QR code information, and sends the QR code information to the server. In step S206, according to one implementation manner, at least a part of the second identity information of the user may be collected or received through the client. In addition, other steps, including the steps of the trusted application interacting with the verification source, as well as the steps of interacting with the registration platform, are all performed through the server.
[0105] FIG. 3 shows a method for obtaining secure identity information according to another embodiment. In the embodiment of FIG. 3, a registration center and a specific application are located in the same physical entity, so it is simply shown as a trusted application + a registration platform. Hereinafter, the entity where the trusted application and the registration platform are located is referred to as a unified server.
[0106] In this case, the registration platform can still interface with multiple trusted applications, including a local specific application and other applications. The service provider still initiates a registration request to the registration platform in advance by using the registration information to obtain and display a QR code. Each trusted application still obtains QR code information of the service provider through scanning and initiates a query request to the registration platform for the read QR code. In one embodiment, the query request may include a specific field (hereinafter referred to as a first field), which is used to indicate whether the trusted application initiating the request is a local trusted application of the registration platform.
[0107] It is assumed that the registration platform receives a query request from a first application. In addition to the QR code information, the query request further includes the first field. In the case that the first field has a first value (for example, the value is 1), the first application is indicated to be a local specific application of the registration platform, and in the case that the first field has a second value (for example, the value is 0), the first application is indicated not to be a local specific application.
[0108] If the first field has the second value, that is, request information received by the registration platform comes from a non-local trusted application, and then the subsequent steps will be performed according to the communication interaction method shown in FIG. 2.
[0109] If the first field has the first value, that is, request information received by the registration platform comes from a local trusted application, then interactions between the registration platform and the trusted application can be performed locally, that is, performed inside the unified server as shown in FIG. 3.
[0110] Specifically, after receiving the query request, the registration platform performs query on the QR code information to obtain the registration information of the service provider, and generates a query result based on the registration information. In the case that the first application is a local specific application, the registration platform may locally provide the above query result to application logic of the first application. Therefore, steps S203 to S205 in FIG. 2 may be performed inside the unified server, and are shown as query steps in FIG. 3.
[0111] After the trusted application (in its application logic) generates secure identity information based on the verified first identity information, the registration platform can locally obtain the secure identity information from the application logic of the first application, obtain encrypted information from the secure identity information, and provide the encrypted information to the service provider. In other words, steps S211 to S212 in FIG. 2 can be performed inside the unified server, as shown in FIG. 3.
[0112] Other steps, such as identity verification steps from S207 to S210 and interaction steps with the service provider, are the same as those shown in FIG. 2, and will not be repeated.
[0113] Through the methods in the embodiments shown in FIG. 2 to FIG. 3, in the case of requiring identity verification, a user uses a trusted application to scan a QR code displayed by a service provider, thereby providing verified identity information to the service provider through a registration platform. Before providing the identity information, the trusted application first sends the identity information of the user to a third-party verification source for verification, thus ensuring the accuracy and authority of the provided identity information. Moreover, in the above process, interconnection between different service providers and different trusted applications is implemented through the registration platform. In this way, the service provider does not need to pay attention to which application is used by the user to provide the identity information, and the verification is more flexible and convenient.
[0114] The above process of obtaining secure identity information involves multi-party interactions among the trusted application, the registration platform, and the service provider. Apparatus configurations of the above parties are described below.
[0115] FIG. 4 is a schematic block diagram of an apparatus for providing secure identity information according to an embodiment, and the apparatus is deployed in a trusted application server. As shown in FIG. 4, apparatus 400 includes: a QR code obtaining unit 41 configured to obtain QR code information corresponding to a QR code scanned by a user, wherein the QR code is generated by a registration platform in advance for a first service provider; a query request sending unit 42 configured to send a query request to the registration platform, wherein the query request includes the QR code information; a query result receiving unit 43 configured to receive a query result from the registration platform, wherein the query result includes identification information of the first service provider, a public key of the first service provider, and first identity information required by the first service provider; an identity information obtaining unit 44 configured to obtain second identity information of the user; a verification sending unit 45 configured to send the second identity information of the user to a verification source to obtain a verification result; a secure information generation unit 46 configured to generate secure identity information, wherein the secure identity information includes the identification information of the first service provider and encrypted information, the encrypted information is obtained by encrypting the verified first identity information by using the public key of the first service provider, and the verified first identity information is determined based on the second identity information and the verification result; and a secure information sending unit 47 configured to send the secure identity information to the registration platform, such that the registration platform sends the encrypted information to the first service provider.
[0116] According to one implementation manner, the identity information obtaining unit 44 is configured to collect the second identity information through a terminal where a client of the trusted application is located.
[0117] Further, in a specific embodiment, the identity information obtaining unit 44 may collect the second identity information as follows: collecting face information through a camera on the terminal; and / or, reading identity card information through an NFC function of the terminal and controls thereon.
[0118] According to another implementation manner, the identity information obtaining unit 44 is configured to receive input information of the user through the client of the trusted application.
[0119] In a possible design, the above apparatus further includes a determination unit (not shown) configured to determine the verification source and a required verification mode based on the required first identity information and the obtained second identity information.
[0120] Further, in one embodiment, the obtained second identity information includes the required first identity information; in this case, the determination unit may determine that the required verification mode is an authentication mode, and in the authentication mode, the verification result is a notification result of whether the verification is successful.
[0121] In another embodiment, the obtained second identity information is a part of the required first identity information; in this case, the determination unit may determine that the required verification mode is an information mode, and in the information mode, the verification result includes a notification of whether the verification is successful, and supplementary identity information determined based on at least a part of the successfully verified second identity information.
[0122] According to one embodiment, the required verification source determined by the determination unit includes a first verification source and a second verification source; in this case, the verification sending unit 45 is configured to: send a first part of the second identity information to the first verification source, and send a second part of the second identity information to the second verification source; receive a first result from the first verification source, and receive a second result from the second verification source; and combine the first result and the second result to obtain the verification result.
[0123] In one embodiment, secure information generation unit 46 is specifically configured to: obtain verified first identity information based on the second identity information and the verification result; encrypt the verified first identity information by using the public key of the first service provider to obtain the encrypted information; and generate the secure identity information based on the encrypted information and the identification information of the first service provider.
[0124] In one example, the above verification result is a notification result of successful verification in the authentication mode; at this time, secure information generation unit 46 may use the successfully verified second identity information as the verified first identity information.
[0125] In another example, the above verification result includes a notification of successful verification and supplementary identity information determined based on at least a part of the successfully verified second identity information; at this time, secure information generation unit 46 may use the successfully verified second identity information and the supplementary identity information as the verified first identity information.
[0126] FIG. 5 is a schematic block diagram of an apparatus for obtaining secure identity information according to an embodiment, and the apparatus is deployed in a registration platform. As shown in FIG. 5, apparatus 500 includes: a query request receiving unit 51 configured to receive a query request from a first application, wherein the query request comprises QR code information, and the QR code information is obtained by scanning, by using the first application, a QR code generated by the registration platform in advance for a first service provider; a registration information determination unit 52 configured to determine registration information of the first service provider based on the QR code information, wherein the registration information comprises at least a public key of the first service provider and first identity information required by the first service provider; a query result sending unit 53 configured to send a query result to the first application, wherein the query result comprises identification information of the first service provider, the public key of the first service provider, and the first identity information; a secure information receiving unit 54 configured to receive secure identity information from the first application, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, and the encrypted information is obtained by encrypting the verified first identity information by using the public key of the first service provider; and an encrypted information sending unit 55 configured to send the encrypted information to the first service provider according to the identification information of the first service provider.
[0127] In one embodiment, the above apparatus 500 further includes a QR code generation unit 50 configured to receive the registration information from the first service provider; and generate a QR code for the first service provider based on the registration information.
[0128] In one embodiment, the registration information further includes routing information of the first service provider; and the encrypted information sending unit 55 is specifically configured to: extract the identification information of the first service provider and the encrypted information respectively from the secure identity information; determine the routing information of the first service provider according to the identification information of the first service provider; and send the encrypted information to a terminal corresponding to the first service provider according to the routing information.
[0129] According to a possible design, the registration center and a server of a specific application are located in the same physical entity; moreover, the query request received by query request receiving unit 51 includes a first field. In the case that the first field has a first value, the first application is indicated to be the specific application, and in the case that the first field has a second value, the first application is indicated not to be the specific application.
[0130] Further, in one embodiment, the first field has a first value; at this time, query result sending unit 53 may locally provide the query result to application logic of the first application; moreover, secure information receiving unit 54 may obtain the secure identity information locally from the application logic of the first application.
[0131] According to an embodiment of another aspect, a computer-readable storage medium having a computer program stored thereon is further provided, wherein when the computer program is executed in a computer, the computer is caused to perform the method described with reference to FIG. 2 to FIG. 3.
[0132] According to an embodiment of still another aspect, a computing device including a memory and a processor is further provided, wherein the memory stores executable code, and when the processor executes the executable code, the methods described with reference to FIG. 2 to FIG. 3 are implemented.
[0133] Those skilled in the art should be aware that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented by software, these functions may be stored in a computer-readable medium, or transmitted as one or more instructions or as one or more pieces of code in the computer-readable medium.
[0134] The specific implementation manners described above further describe the objectives, technical solutions, and beneficial effects of the present invention in further detail. It should be understood that the cope of protection sought to be conferred is delimited by the appending claims.
Claims
1. A method for providing secure identity information, wherein the method is performed by a trusted application server, comprising: obtaining QR code information corresponding to a QR code scanned by a user, wherein the QR code is generated by a registration platform in advance for a first service provider; sending a query request to the registration platform, wherein the query request comprises the QR code information; receiving a query result from the registration platform, wherein the query result comprises identification information of the first service provider, a public key of the first service provider, and first identity information required by the first service provider; obtaining (S06) second identity information of the user; sending (S08) the second identity information of the user to a verification source to obtain a verification result; generating secure identity information, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, the encrypted information is obtained by encrypting verified first identity information by using the public key of the first service provider, and the verified first identity information is determined based on the second identity information and the verification result; and sending the secure identity information to the registration platform, such that the registration platform sends the encrypted information to the first service provider; further comprising determining (S07) the verification source and a required verification mode according to the required first identity information and the obtained second identity information; wherein the obtained second identity information is a part of the required first identity information; wherein determining the verification source and the required verification mode comprises determining that the required verification mode is an information mode, and in the information mode, the verification result comprises a notification of whether the verification is successful, and supplementary identity information determined based on at least a part of the successfully verified second identity information; wherein determining the verification source and the required verification mode further comprises determining that the verification source comprises a first verification source and a second verification source; and wherein sending the second identity information of the user to the verification source to obtain a verification result comprises: sending a first part of the second identity information to the first verification source, and sending a second part of the second identity information to the second verification source; receiving a first result from the first verification source, and receiving a second result from the second verification source; and combining the first result and the second result to obtain the verification result.
2. The method according to claim 1, wherein obtaining the second identity information of the user comprises collecting the second identity information through a terminal where a client of the trusted application is located.
3. The method according to claim 2, wherein collecting the second identity information comprises one or more of: collecting face information through a camera on the terminal; and reading identity card information through an NFC function of the terminal and controls thereon.
4. The method according to claim 1, wherein obtaining the second identity information of the user comprises receiving input information of the user through the client of the trusted application.
5. The method according to claim 1, wherein the obtained second identity information comprises the required first identity information; and wherein determining the verification source and the required verification mode comprises determining that the required verification mode is an authentication mode, and in the authentication mode, the verification result is a notification result of whether the verification is successful.
6. The method according to claim 1, wherein generating the secure identity information comprises: wherein the verification result is a notification result of successful verification in the authentication mode; and wherein obtaining the verified first identity information based on the second identity information and the verification result comprises: using the successfully verified second identity information as the verified first identity information.
7. A method for obtaining secure identity information, wherein the method is performed by a registration platform, comprising: receiving a query request from a first application, wherein the query request comprises QR code information, and the QR code information is obtained by scanning, by using the first application, a QR code generated by the registration platform in advance for a first service provider; determining registration information of the first service provider based on the QR code information, wherein the registration information comprises at least a public key of the first service provider and first identity information required by the first service provider; sending a query result to the first application, wherein the query result comprises identification information of the first service provider, the public key of the first service provider, and the first identity information; receiving secure identity information from the first application, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, and the encrypted information is obtained by encrypting verified first identity information by using the public key of the first service provider; and sending the encrypted information to the first service provider according to the identification information of the first service provider; further comprising determining the verification source and a required verification mode according to the required first identity information and the obtained second identity information; wherein the obtained second identity information is a part of the required first identity information; wherein determining the verification source and the required verification mode comprises determining that the required verification mode is an information mode, and in the information mode, the verification result comprises a notification of whether the verification is successful, and supplementary identity information determined based on at least a part of the successfully verified second identity information; wherein determining the verification source and the required verification mode comprises determining that the verification source comprises a first verification source and a second verification source; and wherein sending the second identity information of the user to the verification source to obtain a verification result comprises: sending a first part of the second identity information to the first verification source, and sending a second part of the second identity information to the second verification source; receiving a first result from the first verification source, and receiving a second result from the second verification source; and combining the first result and the second result to obtain the verification result.
8. The method according to claim 7, before receiving a query request from the first application, further comprising: receiving the registration information from the first service provider; and generating a QR code for the first service provider based on the registration information; and optionally further comprising generating a service index for the registration information; and storing the service index and the registration information associatively; or optionally wherein the registration information further comprises routing information of the first service provider; and the sending the encrypted information to the first service provider comprises: extracting the identification information of the first service provider and the encrypted information respectively from the secure identity information; determining the routing information of the first service provider according to the identification information of the first service provider; and sending the encrypted information to a terminal corresponding to the first service provider according to the routing information.
9. The method according to claim 7, wherein the registration platform and a server of a specific application are located in the same physical entity; and wherein the query request comprises a first field, in the case that the first field has a first value, the first application is indicated to be the specific application, and in the case that the first field has a second value, the first application is indicated not to be the specific application.
10. The method according to claim 9, wherein the first field has a first value; wherein sending the query result to the first application comprises providing an application logic of the first application with the query result locally; and wherein receiving secure identity information from the first application comprises obtaining the secure identity information locally from the application logic of the first application.
11. An apparatus for providing secure identity information, wherein the apparatus is deployed in a trusted application server, the apparatus comprising: a QR code obtaining unit, configured to obtain QR code information corresponding to a QR code scanned by a user, wherein the QR code is generated by a registration platform in advance for a first service provider; a query request sending unit, configured to send a query request to the registration platform, wherein the query request comprises the QR code information; a query result receiving unit, configured to receive a query result from the registration platform, wherein the query result comprises identification information of the first service provider, a public key of the first service provider, and first identity information required by the first service provider; an identity information obtaining unit, configured to obtain second identity information of the user; a verification sending unit, configured to send the second identity information of the user to a verification source to obtain a verification result; a secure information generation unit, configured to generate secure identity information, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, the encrypted information is obtained by encrypting verified first identity information by using the public key of the first service provider, and the verified first identity information is determined based on the second identity information and the verification result; and a secure information sending unit, configured to send the secure identity information to the registration platform, such that the registration platform sends the encrypted information to the first service provider; wherein the verification source and a required verification mode are determined according to the required first identity information and the obtained second identity information; wherein the obtained second identity information is a part of the required first identity information; wherein determining the verification source and the required verification mode comprises determining that the required verification mode is an information mode, and in the information mode, the verification result comprises a notification of whether the verification is successful, and supplementary identity information determined based on at least a part of the successfully verified second identity information; wherein determining the verification source and the required verification mode comprises determining that the verification source comprises a first verification source and a second verification source; and wherein sending the second identity information of the user to the verification source to obtain a verification result comprises: sending a first part of the second identity information to the first verification source, and sending a second part of the second identity information to the second verification source; receiving a first result from the first verification source, and receiving a second result from the second verification source; and combining the first result and the second result to obtain the verification result.
12. An apparatus for obtaining secure identity information, wherein the apparatus is deployed in a registration platform, the apparatus comprising: a query request receiving unit, configured to receive a query request from a first application, wherein the query request comprises QR code information, and the QR code information is obtained by scanning, by using the first application, a QR code generated by the registration platform in advance for a first service provider; a registration information determination unit, configured to determine registration information of the first service provider based on the QR code information, wherein the registration information comprises at least a public key of the first service provider and first identity information required by the first service provider; a query result sending unit, configured to send a query result to the first application, wherein the query result comprises identification information of the first service provider, the public key of the first service provider, and the first identity information; a secure information receiving unit, configured to receive secure identity information from the first application, wherein the secure identity information comprises the identification information of the first service provider and encrypted information, and the encrypted information is obtained by encrypting verified first identity information by using the public key of the first service provider; and an encrypted information sending unit, configured to send the encrypted information to the first service provider according to the identification information of the first service provider; wherein the verification source and a required verification mode are determined according to the required first identity information and the obtained second identity information; wherein the obtained second identity information is a part of the required first identity information; wherein determining the verification source and the required verification mode comprises determining that the required verification mode is an information mode, and in the information mode, the verification result comprises a notification of whether the verification is successful, and supplementary identity information determined based on at least a part of the successfully verified second identity information; wherein determining the verification source and the required verification mode comprises determining that the verification source comprises a first verification source and a second verification source; and wherein sending the second identity information of the user to the verification source to obtain a verification result comprises: sending a first part of the second identity information to the first verification source, and sending a second part of the second identity information to the second verification source; receiving a first result from the first verification source, and receiving a second result from the second verification source; and combining the first result and the second result to obtain the verification result.
13. A computer-readable storage medium, having a computer program stored thereon, wherein when the computer program is executed in a computer, the computer is caused to perform the method according to any one of claims 1 to 10.
14. A computing device, comprising a memory and a processor, and characterized in that an executable code is stored in the memory, and when the processor executes the executable code, the method according to any one of claims 1 to 10 is performed.