Identity recognition method and apparatus, electronic device, and storage medium
By setting up a super administrator at the identity verification site, using their terminal to collect biometric information and send it to the verification server, identity can be quickly confirmed, solving the timeliness problem of identity verification in media replacement scenarios and improving response efficiency and security in emergency situations.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2026-04-02
AI Technical Summary
In media replacement scenarios, the inability to quickly verify the identity of the object can lead to delays in notifying family members in extreme cases such as drowning incidents, resulting in timeliness issues.
By setting up a super administrator at the identity verification site, the administrator's terminal collects biometric information and sends it to the verification server. Based on the candidate biometric information set, the identity can be quickly confirmed, reducing the difficulty of identification and improving efficiency.
In media replacement scenarios, it enables rapid identity verification, improving response efficiency and security management efficiency in emergency situations.
Smart Images

Figure CN2025112795_02042026_PF_FP_ABST
Abstract
Description
An identity recognition method and device, electronic equipment and storage medium
[0001] Related applications
[0002] The present application claims priority to the Chinese patent application No. 2024113953979, filed on September 30, 2024, and entitled "An identity recognition method, device, electronic equipment and storage medium", the contents of which are hereby incorporated by reference in their entirety. TECHNICAL FIELD
[0003] The present application relates to the technical field of computers, and in particular to an identity recognition method, device, electronic equipment and storage medium. BACKGROUND
[0004] With the development of artificial intelligence technology, there are more and more application scenarios for verifying the identity of an object through biological information, such as face recognition, fingerprint recognition, iris recognition, voiceprint recognition, palm verification recognition, etc. Taking palm verification recognition as an example, it can be further divided into palm verification recognition for access control, palm verification recognition for payment, palm verification recognition for clocking in, palm verification recognition for storage, etc. These applications not only improve the convenience and security of services, but also bring the trend of medium replacement, i.e., the object no longer needs traditional physical media such as keys, cards or wristbands, but can complete various services through the recognition of biological information.
[0005] For example, palm verification technology is used for identity verification and storage services in a swimming pool. On the basis of binding the identity through palm verification, the object can swim through the gate after storing through palm verification, without the need to wear a wristband. However, in some extreme scenarios, such as when a swimmer drowns, the safety officer needs to know the identity of the swimmer and quickly notify the family members. At this time, due to the replacement of the medium, the personal belongings cannot be taken out through the association of the wristband with the storage cabinet door to locate the identity, which may cause a certain timeliness problem in notifying the family members.
[0006] In summary, how to quickly confirm the identity of an object in a medium replacement scenario is an urgent problem to be solved. SUMMARY
[0007] The present application provides an identity recognition method, device, electronic equipment and storage medium to quickly confirm the identity of an object in a medium replacement scenario.
[0008] An identity recognition method provided by an embodiment of the present application is executed by a verification server, and includes:
[0009] receive a verification instruction sent by a first object terminal; wherein the verification instruction comprises a site identifier of an identity verification site and second object biological information; the second object biological information is biological information of a second object collected by the first object terminal in response to a verification operation triggered by a first object; the first object is an object having a business management right in the identity verification site;
[0010] determine a candidate biological information set according to the site identifier; the candidate biological information set comprises candidate biological information of at least one candidate object; each candidate object is an object that has handled a business after successfully verifying an identity by using biological recognition in the identity verification site; and
[0011] when the second object biological information hits the candidate biological information set, determine identity information of the second object based on the hit candidate biological information, and return the identity information to the first object terminal.
[0012] Another identity recognition method provided by an embodiment of the present application is executed by a first object terminal, and comprises the following steps.
[0013] collect second object biological information of a second object in response to a verification operation triggered by a first object; wherein the first object is an object having a business management right in an identity verification site;
[0014] send a site identifier of the identity verification site and the second object biological information to a verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the site identifier, and when the second object biological information hits the candidate biological information set, determines identity information of the second object based on the hit candidate biological information; the candidate biological information set comprises candidate biological information of at least one candidate object; each candidate object is an object that has handled a business after successfully verifying an identity by using biological recognition in the identity verification site; and
[0015] after receiving the identity information returned by the verification server, confirm the identity of the second object according to the identity information.
[0016] An identity recognition device provided by an embodiment of the present application comprises the following.
[0017] a receiving unit, configured to receive a verification instruction sent by a first object terminal; wherein the verification instruction comprises a site identifier of an identity verification site and second object biological information; the second object biological information is biological information of a second object collected by the first object terminal in response to a verification operation triggered by a first object; the first object is an object having a business management right in the identity verification site;
[0018] The processing unit is configured to determine a candidate biological information set according to the site identifier; the candidate biological information set comprises candidate biological information of at least one candidate object, each of the candidate objects being an object that has handled a service in the identity verification site after successfully verifying the identity by using biological recognition.
[0019] The identity confirmation unit is configured to, when the second object biological information hits the candidate biological information set, determine identity information of the second object based on the hit candidate biological information, and return the identity information to the first object terminal.
[0020] Another identity recognition device provided by an embodiment of the present application includes:
[0021] The response unit is configured to, in response to a verification operation triggered by a first object, collect second object biological information of a second object; the first object is an object having a service management right in an identity verification site.
[0022] The sending unit is configured to send a site identifier of the identity verification site and the second object biological information to a verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the site identifier, and determines identity information of the second object based on hit candidate biological information when the second object biological information hits the candidate biological information set; the candidate biological information set comprises candidate biological information of at least one candidate object, each of the candidate objects being an object that has handled a service in the identity verification site after successfully verifying the identity by using biological recognition.
[0023] The identity confirmation unit is configured to, after receiving the identity information returned by the verification server, confirm the identity of the second object according to the identity information.
[0024] An electronic device provided by an embodiment of the present application includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the computer program causes the processor to perform the steps of any of the above identity recognition methods.
[0025] A computer readable storage medium provided by an embodiment of the present application includes a computer program, and when the computer program runs on an electronic device, the computer program is used to cause the electronic device to perform the steps of any of the above identity recognition methods.
[0026] The embodiment of the present application provides a computer program product, the computer program product comprises a computer program, the computer program is stored in a computer readable storage medium; when the processor of an electronic device reads the computer program from the computer readable storage medium, the processor executes the computer program, so that the electronic device executes the steps of any one of the identity recognition methods.
[0027] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be achieved and obtained by the structure particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of the disclosed drawings.
[0029] Fig. 1 is an optional schematic diagram of an application scenario in the embodiment of the present application;
[0030] Fig. 2 is a schematic diagram of a verification terminal in the embodiment of the present application;
[0031] Fig. 3 is an implementation flowchart of an identity recognition method in the embodiment of the present application;
[0032] Fig. 4 is a schematic diagram of a sub-application jump in the embodiment of the present application;
[0033] Fig. 5 is a schematic diagram of a palm verification recognition scenario in the embodiment of the present application;
[0034] Fig. 6 is a schematic diagram of another palm verification recognition scenario in the embodiment of the present application;
[0035] Fig. 7 is a schematic diagram of a palm verification storage article in the embodiment of the present application;
[0036] Fig. 8 is a schematic diagram of a one-key cabinet opening and article taking in the embodiment of the present application;
[0037] Fig. 9 is an implementation flowchart of another identity recognition method in the embodiment of the present application;
[0038] Fig. 10 is a schematic diagram of a screening process of a candidate palmprint set in the embodiment of the present application;
[0039] Fig. 11 is an identity recognition service architecture based on an instant messaging application palm verification recognition technology in the embodiment of the present application;
[0040] Fig. 12 is a flow chart of a multi-end interaction for identity recognition according to an embodiment of the present application;
[0041] Fig. 13 is a schematic diagram of a structure of an identity recognition device according to an embodiment of the present application;
[0042] Fig. 14 is a schematic diagram of a structure of another identity recognition device according to an embodiment of the present application;
[0043] Fig. 15 is a schematic diagram of a hardware structure of an electronic device according to an embodiment of the present application;
[0044] Fig. 16 is a schematic diagram of a hardware structure of another electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0045] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0046] Some concepts involved in the embodiments of the present application will be introduced below.
[0047] 1. Biological information: refers to data extracted from inherent physiological characteristics or behavioral characteristics of an object (such as a human body) and used for identity recognition. These information has uniqueness and stability, and is often used for security authentication and identity verification. The biological information in the embodiments of the present application includes but is not limited to at least one of the following:
[0048] Fingerprint, facial feature (such as face), iris, voiceprint, palm print, vein, etc.
[0049] 2. Biometric verification: a technology that exchanges object identity information (such as object account) through palm media information (i.e. palm data). For example, a palm verification payment device is a device realized by using biometric verification technology, and the palm verification payment device can be used for an object to complete payment for a target order through palm verification.
[0050] 3. Place and sub-place: Place generally refers to a specific geographical location or physical space, which can be a building, an area or any other place with clear boundaries, which can accommodate activities or services. For example, a shopping center, a restaurant, a stadium, etc. can be regarded as a place. Sub-place refers to a smaller functional area or an independently operated space within a larger place. Sub-place is usually a small place with its own specific purpose within the structure of a large place. For example, in a shopping center, each independent store can be considered a sub-place within the large place of the shopping center; in a university campus, each teaching building, library or sports field is a sub-place of the campus.
[0051] In the embodiments of the present application, places and sub-places support biometric verification. For example: a shopping center as a comprehensive commercial place can use biometric verification technology to provide convenient member services such as fast payment, points exchange, etc. The stadium as a place to hold sports events and concerts, etc. can verify ticketing through biometric verification to improve entry efficiency and security.
[0052] For another example, a swimming pool as a specific type of sports and leisure place can use biometric verification to unlock lockers, pass through gates, etc. The swimming pool can also set up multiple sub-places such as children's water play area, professional training area, leisure area, etc. For another example, the swimming pool can also set up multiple sub-places such as men's area, women's area, family area and general area, etc. Biometric verification can distinguish the permissions of different members to ensure that each area is only open to eligible objects, thereby improving the operation efficiency and security of the entire swimming pool.
[0053] For another example, a water park as a place that combines entertainment and leisure functions can use biometric verification technology to improve the object experience and place management efficiency. The water park can also set up multiple sub-places such as children's water play area, adult swimming pool, water slide, wave pool, etc.
[0054] 4. Biometric information set: refers to a set of biometric information of a plurality of objects. These biometric information includes biometric image of the object and its corresponding biometric feature information, which is used for subsequent identity verification or identification process. Biometric feature information includes but is not limited to fingerprint, facial feature, iris, voiceprint, palm print, vein, etc.
[0055] In the embodiments of the present application, according to the function and size, the biometric information set can be divided into the following two categories:
[0056] Large set for general recognition: refers to the set of biological information of all registered objects in the biological information recognition system. This set covers a wide range of object groups, and the purpose is to support high-flow, high-concurrency identity verification requirements.
[0057] Small set for auxiliary recognition: this is a relatively small set of biological information, mainly used for identification needs in specific scenarios or special object groups, to ensure efficiency and accuracy in specific application scenarios, such as the place biological information set, reference biological information combination and candidate biological information combination in this application are all small sets for auxiliary recognition related to identity verification places or identity verification sub-places.
[0058] 5, object: refers to an individual or entity participating in a certain system or business process, which can be a person (such as a user, administrator). In the embodiments of the present application, there are first objects, second objects, etc. Among them, the first object usually refers to an administrator or staff who initiates a verification operation to verify the identity of other objects in an emergency, while the second object refers to a user whose identity needs to be verified. For example, in the scenario of a swimming pool, the first object may be a security officer of the swimming pool, and the second object may be a swimmer in the swimming pool. When the first object discovers an emergency, it can verify the identity of the second object through biological recognition verification and take appropriate action. For example, in the scenario of a gym, the first object may be a staff or manager of the gym, and the second object may be a member of the gym. If the second object encounters an emergency during exercise and needs emergency assistance, the first object can verify the identity of the second object through biological recognition verification and take appropriate action; other scenarios are similar and will not be described here.
[0059] 6, sub-application: refers to a small application running inside another application (which can be denoted as a main application), also known as a small program or light application. Sub-applications have the characteristics of small size and fast startup, and do not need to be installed independently, but can run directly in the environment of the main application. They often rely on a larger platform and use the infrastructure and service interfaces provided by the platform to implement specific functions or services, such as instant messaging application small programs, third-party payment platform small programs, or operating system widgets. Sub-applications can provide a use experience close to that of native applications, while also having the advantages of easy development and low maintenance cost, making them very suitable for providing on-demand services.
[0060] 7. Three-dimensional (3D) camera: Similar to a traditional camera, it adds living-related hardware and software such as depth cameras and infrared cameras to ensure information security. 3D cameras have face recognition, gesture recognition, three-dimensional measurement, environmental perception, image acquisition, and other functions, and are widely used in TVs, mobile phones, robots, autonomous driving, biometric verification, and other fields. For example, 3D cameras can be deployed on palm verification payment devices to obtain palm media information as palm data.
[0061] The design idea of the embodiments of the present application is briefly introduced as follows:
[0062] With the development of artificial intelligence technology, biometric verification is applied in more and more scenarios, such as biometric verification for opening access control, biometric verification for payment, biometric verification for clocking in, biometric verification for storage, and the like. These applications not only improve the convenience and security of services, but also bring the trend of medium replacement, i.e., objects no longer need traditional physical media such as keys, cards, or wristbands for identity verification, but can complete various services through biometric verification.
[0063] In the scenario of palm verification replacing media, for example, in a swimming pool, palm verification technology is used for identity verification and storage services. As a new medium, when an object uses the service for the first time, it needs to be bound to personal identity through palm verification. This means that the object's biometric information is registered and associated with their personal information, becoming a new identity verification medium. After that, the object can perform identity verification through palm verification without carrying any additional physical media (such as a wristband).
[0064] In the above scenario, before the introduction of palm verification technology, objects may need to wear wristbands to complete identity verification and storage services. With the introduction of palm verification technology, objects can complete these services directly through palm verification, eliminating the need for wristbands. This medium replacement achieves a seamless transition from traditional media (wristbands) to new media (palm verification), improving object experience and service efficiency, and objects no longer need to worry about forgetting to carry a wristband or losing a wristband. They only need their own palm to complete the service, while improving the security of identity verification.
[0065] However, medium replacement also has some drawbacks. Taking the above scenario as an example, in some extreme cases, such as when a swimmer drowns, the safety officer needs to know the identity of the swimmer and quickly notify the family. At this time, due to the replacement of media, it is no longer possible to associate the wristband with the storage cabinet door to retrieve the swimmer's personal belongings for identity positioning, which may cause a timeliness problem in notifying the family.
[0066] Therefore, the application provides an identity recognition method and device, an electronic device and a storage medium. Specifically, the application sets a super administrator for each site, such as a first object with business management authority in an identity verification site, and opens a biological recognition verification capability for such an object. In this way, in some special scenarios (such as an emergency), the first object can collect the biological information of a second object (i.e., second object biological information) through a first object terminal logged in by the first object, so as to quickly realize identity verification and efficient response in an emergency, and only the first object with authority can perform a key operation in an emergency, thereby improving the security management efficiency and enhancing the site security.
[0067] Further, by sending the site identifier and the verification instruction of the identity verification site to the verification server, the verification server can determine the candidate biological information set matched with the identity verification site based on the received verification instruction. The candidate biological information set is only related to the identity verification site and contains only the candidate biological information of the object that has handled business in the identity verification site. It is a small set for auxiliary recognition, rather than a large set for general recognition (which can contain the biological information of all objects that have opened the biological recognition verification function). Based on the candidate biological information set, the identity of the second object can be quickly recognized, the recognition difficulty is reduced, and the identity confirmation efficiency is improved.
[0068] On this basis, after the verification server determines the identity information of the second object based on the candidate biological information set, the verification server can return the identity information to the first object terminal. The first object terminal can confirm the actual identity of the second object based on the identity information, so as to quickly confirm the identity of the object in the medium replacement scenario.
[0069] The preferred embodiments of the application are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the application, and are not used to limit the application, and the embodiments in the application and the features in the embodiments can be combined with each other without conflict.
[0070] As shown in FIG. 1, it is an application scenario diagram of the embodiment of the application. The application scenario diagram includes a first object terminal 110, a verification terminal 120 and a verification server 130.
[0071] The first object terminal 110 and the verification terminal 120 both belong to electronic devices capable of implementing biometric verification. The first object terminal 110 refers to a terminal device used by the first object, such as a mobile phone, a tablet computer, a multimedia playback device, a personal computer (PC), a smart robot, a vehicle terminal, a smart home appliance, a smart voice interaction device, an access control device, a purchase device, and any electronic device with a biometric verification function, which is not limited in the embodiments of the present application.
[0072] Optionally, the first object terminal 110 can be installed with a target client, which can be a browser, an instant messaging client, a payment client, a shopping client, an access control client, and any client supporting biometric verification, which is not limited in the embodiments of the present application. In addition, the target client can be software, a webpage, an applet, etc.
[0073] The verification terminal 120 is an electronic device deployed in a certain place or sub-place, which is specially used for performing biometric and verification tasks. Such terminals are usually fixedly installed at the entrance, service counter or other key positions of the place or sub-place where identity verification is required. Their design purpose is to provide a stable and professional biometric verification solution to quickly and accurately verify the identity of the object.
[0074] Optionally, the verification terminal 120 is provided with a biometric verification module, which can be divided into an image acquisition submodule and an interface display submodule. The image acquisition submodule can be implemented by a 3D camera, as shown in FIG. 2, which is a schematic diagram of a verification terminal in the embodiments of the present application. When the verification terminal is a palm verification terminal, 21 in FIG. 2 is the image acquisition submodule in the verification terminal 120, which is also the palm collection area, used for collecting images such as palm images. For example, 22 in FIG. 2 is the interface display submodule, which can be implemented as a touch display screen, used for displaying interfaces to realize the human-computer interaction between the object and the verification terminal 120, and to show information to the object. Exemplarily, the verification terminal 120 can be a biometric verification device used for purchasing tickets in subway, bus, high-speed rail, etc. scenarios. The verification terminal 120 can also be a biometric verification device used for payment and purchase of goods in supermarket, shopping mall, etc. scenarios. The verification terminal 120 can also be a biometric verification device used for payment and identity verification in organization, business, personal, etc. scenarios, which is not limited in the embodiments of the present application.
[0075] It should be noted that, in FIG. 1 or FIG. 2, the palm verification terminal is taken as an example of the verification terminal, and in addition to this, the verification terminal can also be other types of terminals, which are related to biological information for biological identification, for example, it can also be: a fingerprint identification terminal, such as a fingerprint lock, an attendance machine; a face recognition terminal, such as a smart camera, a face recognition payment device; an iris recognition terminal, such as an iris access control system, a high-end security device; a voiceprint recognition terminal, such as a voice assistant, a telephone banking system; a vein recognition terminal, such as a vein access control, a payment terminal; and the like.
[0076] The verification server 130 can refer to a target client in the first object terminal 110 and a back-end service platform of the verification terminal 120. For example, the verification server 130 can be used to provide background services such as permission verification, biological identification verification, payment processing, etc. for the target client in the first object terminal 110 and the verification terminal 120.
[0077] Optionally, the verification server 130 can be implemented as a server, which can be a standalone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content distribution networks (CDN), and big data and artificial intelligence platforms, etc. basic cloud computing services. That is, the verification server 130 can be implemented as a server, a server cluster composed of multiple servers, or a cloud computing service center.
[0078] In an optional embodiment, the first object terminal 110 and the verification server 130 can communicate with each other through a communication network, and the verification terminal 120 and the verification server 130 can communicate with each other through a communication network. The communication network can be a wired network or a wireless network.
[0079] In an optional embodiment, the communication network is a wired network or a wireless network.
[0080] It should be noted that FIG. 1 is only an example, and in fact, the number of terminals and servers is not limited, and is not specifically limited in the embodiments of the present application.
[0081] In the embodiments of the present application, when the number of servers is multiple, the multiple servers can be composed of a blockchain, and the servers are nodes on the blockchain; for example, the identity recognition method disclosed in the embodiments of the present application, wherein the related data involved can be saved on the blockchain, for example, biological information, identity information, etc. In order to ensure information security, the related data can be encrypted and saved on the blockchain.
[0082] In addition, the embodiments of the present application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, intelligent transportation, and auxiliary driving scenarios, and are particularly suitable for business scenarios related to biometric verification in these scenarios. For example, palm verification and identification can be used in scenarios such as traffic / door access palm verification, locker / pick-up cabinet palm verification, palm verification check-in, palm verification clock-in, palm verification payment, and medical institution palm verification registration.
[0083] The present application mainly relates to some business scenarios of media replacement through biometric identification verification, which are simply listed as follows:
[0084] (1) In office buildings, school dormitories, gyms, and other places, biometric identification verification can be used instead of traditional access cards or passwords. For example, the subject can unlock the access by face recognition or palm verification.
[0085] (2) In sports venues, swimming pools, and entertainment venues, the subject can bind the locker service through palm verification without wearing a bracelet or key. The subject can open the locker by face recognition or palm verification.
[0086] In addition, biometric identification verification can also be used for quick channel verification in these places. The subject can quickly pass through by face recognition or palm verification.
[0087] (3) In some public places, such as airports, train stations, and supermarkets, the subject can use the biometric identification verification to register the locker without using traditional keys or cards.
[0088] In addition, in the luggage storage service at the airport or train station, the subject can also use biometric identification verification for luggage storage service without using traditional luggage tags or vouchers. For example, the subject can pick up the luggage by face recognition or palm verification.
[0089] (4) In the field of public transportation, biometric identification verification technology can significantly improve the passenger's riding experience. For example, after installing biometric identification verification gates at subway stations or buses, passengers can complete identity verification by placing their palms on the identifier and passing through the gate, or by swiping their faces in front of the identifier and passing through the gate.
[0090] (5) The introduction of biometric identification verification technology in medical institutions can greatly simplify the patient's medical process. When the patient arrives at the hospital, they can complete the registration or registration procedures by palm verification, and the system will automatically associate the patient's personal information and medical records.
[0091] (6) In the activities such as conferences, exhibitions, etc., the recognition and verification of biological information is used instead of paper sign-in sheets or electronic sign-in cards. Specifically, the participants register the sign-in system through palm verification, and the system binds the biological information of the object with the conference qualification. Then, the participants can complete the sign-in through palm verification, etc.
[0092] It should be noted that the above-mentioned several scenarios are only simple examples, and other scenarios are also applicable to the embodiments of the present application, which will not be repeated here.
[0093] It should be emphasized that in the specific embodiments of the present application, the related data of the object identity, such as the biological information, account information, location information, etc. listed above, are involved. When the above embodiments of the present application are applied to specific products or technologies, the permission or consent of the object is required, and the collection, use and processing of the related data need to comply with the relevant laws, regulations and standards of the country and region.
[0094] The identity recognition method provided by the exemplary embodiments of the present application will be described below in combination with the above-described application scenarios and with reference to the accompanying drawings. It should be noted that the above-mentioned application scenarios are only shown to facilitate the understanding of the spirit and principles of the present application, and the embodiments of the present application are not limited in this respect.
[0095] Referring to FIG. 3, it is an implementation flowchart of an identity recognition method provided by an embodiment of the present application, taking a first object terminal as an execution subject, the specific implementation flow of the method is as follows S31-S33:
[0096] S31: In response to the verification operation triggered by the first object, the second object biological information of the second object is collected; wherein the first object is an object with business management authority in the identity verification place.
[0097] In the embodiments of the present application, one or more super administrators can be set for each place, that is, the object with business management authority in the place in this paper. For such objects, the object terminal based on itself can be opened to collect the biological information of other objects, thereby helping other objects to perform biological recognition verification.
[0098] In an optional embodiment, each site can be provided with only one super administrator who manages the entire site. In another optional embodiment, each site can be provided with multiple super administrators, each of which can manage the entire site, and these super administrators can manage the site simultaneously or in time periods. In yet another optional embodiment, each sub-site in a site is provided with one super administrator, and each super administrator manages the respective sub-site. In another optional embodiment, each sub-site in a site is provided with multiple super administrators, each of which manages the respective sub-site, and there are multiple super administrators managing the same sub-site, and these super administrators can manage the sub-site simultaneously or in time periods. Of course, to avoid some extreme cases, the same super administrator can also be allowed to manage different sub-sites in the same site, which is not limited herein.
[0099] It should be noted that the super administrator herein is pre-set for each site, and in actual application, the setting conditions of the super administrator include but are not limited to the following aspects:
[0100] (1) Post responsibility: the candidate should have key post responsibilities and be able to assume the business management responsibilities in the site / sub-site, such as site / sub-site manager or supervisor. (2) Trustworthiness: the candidate should be a highly trustworthy employee with good moral and credit records. (3) Technical ability: having certain technical knowledge and being able to master biometric verification technology and related terminal equipment. (4) Emergency handling ability: having the ability to handle emergencies and being able to make quick decisions in emergency situations. (5) Work experience: having certain work experience and being familiar with the operation process and service standards of the site / sub-site.
[0101] It should be noted that the above-mentioned setting conditions are only simple examples, and other conditions are also applicable, which are not limited herein.
[0102] In S31, the first object refers to the super administrator of the identity verification site, so that in some special scenarios, the first object can collect the second object biological information of the second object through the first object terminal logged in by the first object, so as to quickly realize identity verification and efficient response in emergency situations.
[0103] The biological information in the embodiments of the application includes but is not limited to at least one of the following: fingerprint, facial feature (such as face), iris, voiceprint, palm print, vein, etc.
[0104] Correspondingly, the verification operation in the present application is an identity verification operation related to the biological information, such as a palm verification operation, a fingerprint recognition operation, a face recognition operation, an iris recognition operation, a voiceprint recognition operation, a vein recognition operation, etc. Through one or more verification operations, the identity of the object can be verified, and the combination of multiple verification operations can confirm the identity of the object with higher accuracy.
[0105] For ease of understanding, the following mainly takes the palmprint as an example, and correspondingly, the verification operation can also be referred to as a palm verification operation. Of course, other types of biological information and palm verification operations are equally applicable, and this application will not be repeated here.
[0106] In an optional embodiment, the first object needs to register and bind the administrator account information corresponding to the current place in advance, and only this account can perform the key operation in an emergency.
[0107] For example, the merchants of sports venues, swimming pools, entertainment places, etc. as super administrators need to register and bind the administrator account information corresponding to the current place on the merchant platform, and only this account information can trigger the verification operation of the biological information of other objects, such as a palm verification operation, for quick positioning by taking pictures. Of course, it can also be other verification operations, such as a face recognition operation, or an iris recognition operation, etc. This application will not be repeated here.
[0108] For example, the train attendants of subways, buses, etc. as super administrators need to register and bind the administrator account information corresponding to the current place on the corresponding transportation platform, and only this account information can trigger the verification operation of the biological information of other objects, such as a palm verification operation, for quick positioning by taking pictures.
[0109] For example, the staff of airports or train stations need to register and bind the administrator account information corresponding to the current place on the corresponding transportation platform, and only this account information can trigger the verification operation of other objects, such as a palm verification operation, for quick positioning by taking pictures; etc.
[0110] Based on the above-mentioned method, the account information of the super administrator can be bound with the corresponding place, which is convenient for subsequent authentication.
[0111] The present application considers that generally, in some emergency or special situation, the second object cannot normally perform biometric verification, and thus needs to perform biometric verification on the second object through the authorized first object to perform identity verification. Therefore, in order to improve the efficiency and security of the identity verification process, the first object is supported to trigger the verification operation through a specific portal. For example, the first object can jump to a verification sub-application specially used for identity verification through palm verification through an associated business sub-application to collect the biological information of the second object. The specific interaction logic is as follows: when the first object triggers a jump operation in the business sub-application, the business sub-application sends a jump request to the main application. After the main application receives the request, the permission information of the first object is checked (which can be obtained by querying the local stored permission table or requesting authentication from the verification server). If the permission verification is passed, the main application will load the verification sub-application and pass the relevant context information (such as the place identifier, the first object account information, etc.) to the verification sub-application. After the verification sub-application is started, it is initialized according to the received context information, and a biometric verification interface is displayed, waiting for the first object to collect the biological information of the second object.
[0112] For example, the first object can jump to a verification sub-application specially used for identity verification through palm verification through an associated business sub-application to collect the biological information of the second object. An optional implementation is as follows:
[0113] Before S31, the following step S30 (not shown in FIG. 3) can also be performed:
[0114] S30: In response to the first jump operation, the business sub-application associated with the first object jumps to the verification sub-application.
[0115] During the jump process, the business sub-application encapsulates the current business state information (such as the selected service type, the current operation step, etc.) and the necessary parameters (such as the place identifier, the first object account information, etc.) into a data object. Then, through the jump interface provided by the main application, the data object is passed to the verification sub-application. After the verification sub-application receives the data object, the information in the data object is parsed, and the business state is recovered according to the information to ensure the continuity of the data and the coherence of the operation during the jump process. At the same time, in order to prevent data loss or errors, the transmitted data can be cached in the main application so that the data can be retransmitted when the verification sub-application abnormally.
[0116] The business sub-application refers to a small application program or functional module running in a certain main application (such as an instant messaging application, a third-party payment platform, etc.), and is used to provide specific services or functions. The business sub-application associated with the first object corresponding to different places can be different. For example, in the swimming pool scene, the business sub-application can be a small program provided by the swimming pool merchant on its service platform, which can provide services such as ticket purchase and locker rental.
[0117] The verification sub-application is a small program or functional module specially used for performing biometric identification verification. It can be embedded in the same or different main application as the business sub-application, and is used for identity verification, payment confirmation, etc. Taking the small program as an example, there are palm verification small program, fingerprint verification small program, face recognition small program, iris recognition small program, voiceprint recognition small program, and vein recognition small program, etc.
[0118] In an emergency, the authorized first object (such as a security guard, a staff member, etc. super administrator) can quickly verify the identity of the second object (such as a person in need of help) by jumping to the verification sub-application through the business sub-application.
[0119] In the embodiments of the present application, the first object corresponding to different places is not necessarily the same, and accordingly, the business sub-application associated with the first object can also be different.
[0120] For example, in the swimming pool scene, the business sub-application can be a small program provided by the swimming pool merchant on its service platform, which can provide various services of the swimming pool, such as ticket purchase, locker rental, course reservation, payment, and member management. In an emergency, the security guard can jump to the palm verification small program through this small program to perform identity verification, so as to quickly identify and help the person in need of help.
[0121] As shown in FIG. 4, it is a schematic diagram of sub-application jumping in the embodiments of the present application; wherein, in the swimming pool scene, the business sub-application can be a merchant small program, the verification sub-application can be a palm verification small program, and the merchant small program and the palm verification small program can run in a main application, such as an instant messaging application. The interface of the merchant small program contains a shortcut entrance of the palm verification small program, such as 40 in FIG. 4, and the security guard can jump to the palm verification small program through the shortcut entrance to trigger identity verification.
[0122] In the embodiments of the present application, the security guard of the swimming pool can quickly verify the identity of the customer by using the palm verification small program of the instant messaging application. Especially in an emergency, the security guard can quickly identify the person in need of help, so as to take timely action.
[0123] Among them, as a widely used social application, the built-in palm verification function of the instant messaging application can be seamlessly integrated into the services of the swimming pool, so that the swimming pool security personnel do not need to download other applications, and only need to jump through the merchant applet to complete the identity verification, simplifying the operation steps.
[0124] Similar to the swimming pool, in the scenario of the gym, a member management sub-application can also be developed, and the business sub-application refers to a small program provided by the gym on its service platform, which can provide various services of the gym, such as member check-in, fitness records, private coaching course reservation, etc. In the case of needing to quickly verify the identity, the staff can quickly start the palm verification identification function through the sub-application.
[0125] For example, for a sports stadium holding large-scale sports events or activities, the event sub-application can help participants verify tickets, arrange seats, etc. In an emergency, staff can quickly jump to the verification sub-application through the business sub-application to verify the identity of the audience and assist in emergency evacuation or provide timely help, etc.
[0126] It should be noted that the above-mentioned several cases are only simple examples, of course, other places and related business sub-applications are also applicable to the present application, which are not limited herein.
[0127] On the basis of S30, one optional implementation of S31 is as follows, including S311-S312 (not shown in FIG. 3):
[0128] S311: In response to the verification operation triggered by the first object, the verification sub-application sends the account information of the first object to the verification server through an authentication instruction to authenticate the first object through the verification server.
[0129] Specifically, when collecting the second object biological information of the second object, the first object needs to be authenticated.
[0130] The verification sub-application responds to the verification operation triggered by the first object, and then prepares to call the collection device. In the present application, before actually collecting the second object biological information (such as face information, palm information, etc.) of the second object, the system needs to confirm the authority of the current operator to ensure that only the legal administrator can continue to operate.
[0131] Therefore, the verification sub-application responds to the verification operation triggered by the first object, and sends an authentication instruction containing the account information of the first object to the verification server, and the verification server authenticates the first object to analyze whether the first object has a business management right in the identity verification place.
[0132] Specifically, the verification server side can store a mapping relationship between the place identifier and the super administrator account information. The authentication instruction can further include the place identifier of the identity verification place. Thus, after receiving the authentication instruction including the account information of the first object and the place identifier of the identity verification place, the verification server extracts the account information and the place identifier in the authentication instruction, and then analyzes whether the super administrator under the identity verification place is the first object or includes the first object according to the pre-stored mapping relationship. If yes, it is determined that the first object has the business management right in the identity verification place, and the authentication result is returned to the first object terminal, and then the following process is executed.
[0133] In S312, if it is determined through the authentication that the first object is the object having the business management right in the identity verification place, a collection device is called to collect the second object biological information of the second object through the collection device.
[0134] The collection device is also related to the type of biological information. For example, the collection device can be a camera, a special palm print scanner, a fingerprint scanner, a microphone, a vein scanner, etc. These collection devices can be integrated in the terminal as components or modules of the terminal, or can be independent devices of the terminal, which are not limited herein.
[0135] After the first object terminal receives the authentication result returned by the verification server and the authentication result indicates that the first object is the object having the business management right in the identity verification place, the collection device can be called to ensure that the first object can collect the second object biological information of the second object through the collection device.
[0136] Of course, the first object terminal can also store a mapping relationship between the place identifier and the super administrator account information locally. Thus, when the verification sub-application responds to the verification operation triggered by the first object, the authentication instruction does not need to be sent to the verification server, but the mapping relationship stored locally is directly used to analyze whether the super administrator under the identity verification place is the first object or includes the first object, etc.
[0137] Of course, if the authentication fails, it indicates that the current first object is not actually the object having the business management right in the identity verification place, and thus the biological information of the second object cannot be collected.
[0138] In the embodiments of the present application, the authentication process is a key step to ensure security and correct operation. The authentication can also occur at the following time points:
[0139] Specifically, the first object can be authenticated when the first object triggers the first jump operation. If the authentication is passed, it can be indicated that the first object is the object with the business management permission in the identity verification place, so that the business sub-application associated with the first object jumps to the verification sub-application. If the authentication is not passed, it cannot jump to the verification sub-application, and therefore cannot continue to collect the biological information of the second object.
[0140] For example, when a user attempts to jump from a merchant applet to a palm verification applet, the merchant applet first verifies the administrator identity of the current user. In addition to being performed by the verification server as described above, the authentication process can also be performed by the first object terminal. Specifically, the authentication can be directly performed on the merchant applet (i.e., the business sub-application), such as the merchant applet checking the super administrator account information in the local storage to confirm whether the user has been authenticated as a super administrator of the identity verification place, and the like. Through this process, it can be ensured that only the authenticated administrator can jump from the merchant applet to the palm verification applet, thereby ensuring the security of the system and the integrity of the data.
[0141] Of course, the first object can also be authenticated when the first object enters the business sub-application. If the authentication is passed, it can be indicated that the first object is the object with the business management permission in the identity verification place, so that the first jump operation can be triggered, and the business sub-application associated with the first object jumps to the verification sub-application to collect the biological information of the second object through the verification sub-application. If the authentication is not passed, it cannot enter the business sub-application, and therefore cannot jump to the verification sub-application, and thus cannot continue to collect the biological information of the second object.
[0142] For example, when a user logs in to a merchant applet, the first object terminal or the palm verification server (one of the verification servers in this document) checks whether the identity of the logged-in user matches the super administrator account information bound during registration. If the logged-in user is not the registered super administrator, it is not allowed to access functions related to sensitive operations (such as palm verification).
[0143] It should be noted that the time points and processes of the above-mentioned authentication processes are only simple examples, and in addition to this, other authentication methods are also applicable to the present application, as long as they are implemented before the first object collects the biological information of the second object, which is not limited herein.
[0144] In the above-mentioned embodiments, when an emergency occurs, the first object can jump to the verification sub-application through the business sub-application, and after the authentication is passed, the collection device is called based on the verification sub-application to collect the biological information of the other object. Through the above-mentioned authentication process, it can be ensured that only the first object with the permission can perform the key operation in the emergency, thereby improving the security management efficiency and enhancing the security of the place.
[0145] In addition, through the way of jumping between sub-applications, the biometric verification service can be centrally managed, the background operation is simplified, the super administrator can perform permission management and emergency response on a unified platform, and the management efficiency is improved.
[0146] Of course, in addition to the above-mentioned sub-application jump way to trigger the verification operation, in the embodiments of the present application, in order to improve the efficiency and security of the identity verification process, and considering the actual needs in emergency situations, the verification operation can also be triggered in the following ways:
[0147] Triggering method one, two-dimensional code scanning.
[0148] The first object (i.e. authorized super administrator or other authorized personnel) can trigger the biometric verification process by scanning a specific two-dimensional code. Such a two-dimensional code can be placed in key locations of the swimming pool, such as lifeguard stations, first aid points, etc. Once an emergency situation occurs, the first object only needs to use a mobile terminal to scan the two-dimensional code to quickly enter the biometric verification interface and perform identity verification on the second object (i.e. the person needing help). This method is simple and fast, and is suitable for quick response in emergency situations.
[0149] Triggering method two, voice command.
[0150] The first object can quickly enter the biometric verification interface by using a pre-set voice command such as "xx, start emergency identity verification". This method is especially suitable for situations where both hands are not convenient or quick response is needed. Only a simple voice command is needed to activate the identity verification process, which not only improves the speed of operation, but also increases flexibility, especially in emergency situations, resources can be quickly mobilized to respond.
[0151] Triggering method three, physical button or hardware device.
[0152] A dedicated physical button or hardware device can be set up in the place. When these devices are pressed or activated, they can immediately start the biometric verification related program. For example, in a certain place, emergency buttons can be installed in each key area. When these buttons are pressed, the application program connected to the mobile terminal or fixed terminal of the first object will automatically open the biometric verification interface. This method is particularly suitable for situations that require immediate action, and can minimize response time.
[0153] Of course, under some of the triggering methods listed above, the first object can also be authenticated before performing the verification operation, which is not limited in this paper.
[0154] It should be noted that the above-mentioned several triggering modes are only simple examples, and these modes can effectively support the first object to quickly and accurately perform palm verification identity verification in an emergency, thereby improving the efficiency of rescue or coping with an emergency. Of course, in addition to this, other triggering modes are also applicable to the embodiments of the present application, which will not be repeated here.
[0155] S32: The place identifier of the identity verification place and the second object biological information are sent to the verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the place identifier, and when the second object biological information hits the candidate biological information set, the identity information of the second object is determined based on the hit candidate biological information; the candidate biological information set contains candidate biological information of at least one candidate object, and each candidate object is an object that has handled business after successfully verifying identity in the identity verification place by using biological recognition.
[0156] Specifically, according to the place identifier, a candidate biological information set matching the place identifier is screened from a plurality of pre-stored place biological information sets; the candidate biological information set contains candidate biological information of at least one candidate object, and each candidate object is an object that has handled business after successfully verifying identity in the identity verification place by using biological recognition. Wherein, the screening process can be realized by comparing the place identifier with the place identifier associated with each place biological information set, if they are consistent, then the place biological information set is the candidate biological information set.
[0157] In the embodiments of the present application, the object can handle business after verifying identity by biological recognition in some places. For example, in the place of a swimming pool, the business includes but is not limited to: passing through the gate, storing, payment, etc.; for example, in the place of a gym, the business includes but is not limited to: passing through the gate, signing in, storing, payment, etc.; for example, in the place of a library, the business includes but is not limited to: borrowing books, reservation and cancellation, payment, etc.
[0158] Taking a swimming pool as an example, as shown in FIG. 5, it is a schematic diagram of a palm verification identification scene in the embodiments of the present application. Among them, FIG. 5 represents an example of palm verification gate passing, in the swimming pool, the object can pass through the changing room by palm verification, and pass through the gate to swim, etc. Specifically, when the object arrives at the gate, it only needs to place the palm on the palm verification terminal installed on the gate, and the identity information of the object can be quickly and accurately identified. Once the verification is successful, the gate will automatically open, allowing the object to smoothly enter the changing room or the pool area.
[0159] Still taking the swimming pool as an example, as shown in FIG. 6, which is a schematic diagram of another palm verification identification scene in the embodiment of the present application. FIG. 6 represents an example of palm verification for accessing articles. In the swimming pool, the object can access articles in the locker room through palm verification. Specifically, when the object uses the locker, the object only needs to place the palm on the palm verification terminal installed on the locker, and the process of accessing articles can be completed through a simple palm verification action.
[0160] In order to ensure that the object can quickly identify its identity when an emergency occurs in the place, simplify the identity verification process, and improve the identification efficiency, the present application supports collecting and storing the biological information of the object, such as the place biological information set in the present application, through a small set for assisting identification.
[0161] Specifically, the verification instruction is sent after the first object collects the biological information of the second object, and the verification server can confirm the identity of the second object based on the verification instruction. The second object biological information in the verification instruction is used to confirm the identity information of the second object, and the place identifier is used to confirm the place biological information set. Based on the place identifier, the matching place biological information set, i.e., the candidate biological information set in the present application, can be filtered out, and then it is determined whether the second object biological information hits in the candidate biological information set, so as to improve the retrieval efficiency.
[0162] In the embodiment of the present application, the verification server side can construct a plurality of place biological information sets. Each place biological information set is a database or data set storing the biological information of the object in the corresponding place (such as a swimming pool, a gym, a stadium, etc.) who has handled a business (such as gate passing, article storage, payment, identity verification, etc.) after verifying the identity through biological identification. In addition, each place can construct one or more such sets according to different business needs, so each place can correspond to one or more place biological information sets.
[0163] When each place biological information set is regarded as a database, a structured query language (Structured Query Language, SQLite) database can be used. The database is a lightweight database, which is an atomicity-consistency-isolation-durability (Atomicity-Consistency-Isolation-Durability, ACID) compliant relational database management system. By storing the biological information of the object in the SQLite database, the security, operation efficiency and management convenience of the system can be improved, and the consistency and persistence of the data are also guaranteed.
[0164] The candidate biological information set in the present application is determined from the biological information sets of these sites, and is a site biological information set related to the identity verification site. After the candidate biological information set is determined, a search can be performed in the candidate biological information set. Specifically, the second object biological information is compared with each candidate biological information in the candidate biological information set. If there is a candidate biological information that matches the comparison, the candidate biological information is hit. The identity information of the second object can be determined according to the candidate biological information.
[0165] Specifically, the candidate biological information set in the embodiment of the present application is a smaller database (referred to as a small database) relative to a large set used for general recognition. The small database supports data retrieval through a single condition (specifically, the second object biological information). Because the data set is small and only involves one search condition, the search process is usually very fast. Using a single condition for searching generally does not result in multiple record matching, so the accuracy of the search result is high.
[0166] Optionally, the candidate biological information includes, but is not limited to, at least one of the following:
[0167] Standard biological information uploaded by a candidate object when the biological recognition verification function is opened; and biological information newly collected by the candidate object when handling a business through palm verification in the identity verification site.
[0168] In the embodiment of the present application, each object uploads a standard biological information when the biological recognition verification function is opened. The standard biological information is collected by the object through a corresponding object terminal (such as a smart phone, a tablet computer, etc.) or a verification terminal (such as a special biological recognition verification device installed in the site) when the object is registered for the first time or opens the biological recognition verification function. For example, when the object opens the palm verification function for the first time, the object needs to place the palm on a designated position of a special palm verification recognition device according to the indication, so as to capture a clear palm image.
[0169] The standard biological information is the basis for subsequent identity verification of the object. Subsequently, the verification server compares the biological information (such as a palm image) collected each time the object uses the biological recognition verification function with the standard biological information, so as to confirm the identity of the object and ensure that only a legally registered object can use related services and handle a business.
[0170] Taking the swimming pool as an example, if the object needs to open the palm verification storage cabinet and swim through the gate, the palm of the object can be collected at the offline palm verification terminal. After collection, the palm verification terminal will display a two-dimensional code associated with the palm print. The object needs to scan the code through the instant messaging application to associate the current instant messaging application identity. Then, the object is further redirected to the merchant applet of the swimming pool for authorization verification, so as to open the palm verification recognition ability of the object and the application of the related place. After the object opens, the object can handle the business in the swimming pool through the palm verification, such as opening the storage cabinet or the gate to the swimming pool.
[0171] In addition, when the object performs a business operation in a place supporting palm verification identification, such as a swimming pool, a gym, a library, etc., for example, through palm verification to pass through the gate or access the goods, the palm verification terminal installed in the place will collect the palm image of the object in real time. Specifically, when the object places the palm on the palm verification terminal, the palm verification terminal will capture the current palm image and take it as the latest palm print data. This newly collected palm print can be used for the identity recognition process of the second object in the subsequent emergency. The real-time collected palm print can reflect the current state of the palm and adapt to the slight changes of the palm features, so that the latest palm print data collected in real time can be used as a candidate palm print to confirm the identity faster, especially in an emergency, which can improve the accuracy and reliability of the identification.
[0172] In addition, in order to protect the privacy of the object, optimize the storage space and improve the system performance, a deletion strategy for the place biological information set can also be set, such as periodic deletion or irregular deletion. The specific deletion time interval can be flexibly set according to business needs, etc.
[0173] For example, a place does not allow the object to stay overnight, so a daily deletion strategy can be set, which empties the place biological information set corresponding to the place once a day and only keeps the data of the last day. Taking the swimming pool as an example, in the early morning period (such as between 1 a.m. and 2 a.m.), the verification server will automatically delete the biological information of the object that handled the business (such as storage and swimming through the gate) in the swimming pool the previous day, so as to ensure that the place biological information set only stores the activity records of the current day and ensure the freshness and safety of the data.
[0174] For example, in addition to daily deletion, a fixed period can also be set for deletion according to business needs, such as every two days, once a week or once a month; for example, a fixed time window can also be set, such as 7 days or 30 days, and the system will delete the data exceeding the time window every day to keep the access records within a certain period of time; a deletion can also be triggered after a certain event, etc.
[0175] The above-mentioned several ways are only simple examples, and these deletion strategies can be adjusted according to the specific business needs of the site and the behavior patterns of the objects, etc., to achieve the best privacy protection and system performance optimization effect.
[0176] In the above manner, periodically / irregularly deleting a part of historical data can reduce the potential data leakage risk, ensure that only the latest and relevant data is retained, and at the same time release a certain amount of storage space to improve the response speed and performance of the system.
[0177] In addition, considering that there may be some places with large flow of people, in this case, if only the auxiliary identification small set is divided according to the site, there may be many candidate biological information in a small set. In order to further improve the retrieval efficiency, a time factor can be introduced to further mark or divide the site biological information set according to the time interval.
[0178] Therefore, an optional implementation of S32 is as follows:
[0179] First, the collection time of collecting the second object biological information in the identity verification site is determined; then the collection time, the site identifier and the second object biological information are sent to the verification server through the verification instruction, so that the verification server determines the candidate biological information set according to the site identifier and the collection time; correspondingly, each candidate object is an object that has handled business in the identity verification site by using biological recognition to verify identity successfully in the time interval to which the collection time belongs. That is, the candidate biological information in the candidate biological information set is the biological information of the object that has handled business in the identity verification site by using biological recognition to verify identity successfully in the time interval to which the collection time belongs.
[0180] Specifically, each site can correspond to multiple site biological information sets, and different site biological information sets are bound to different time intervals, so that each site biological information set only stores the biological information of the object that has handled business in this site by using biological recognition to verify identity in the corresponding time interval.
[0181] For example, the time interval is one day, so each site will generate a site biological information set every day. For another example, the time interval is two days, so each site will generate a site biological information set every two days. For another example, a more detailed time interval can also be divided according to the business hours of the site, for example, assuming that the business hours of the swimming pool are from 8 am to 10 pm every day, the business hours can be used as the time interval, or further divided based on the business hours, etc., which is not limited in this paper.
[0182] In the embodiments of the present application, in order to achieve efficient biometric verification service in the identity verification site, the first object terminal needs to determine the specific time (i.e. the collection time) of collecting the second object biological information. After collecting the second object biological information, the first object terminal sends the collection time, the site identifier (such as the unique ID of the swimming pool), and the second object biological information to the verification server through the verification instruction. The collection time in the verification instruction belongs to a time interval, and each site biological information set is also bound to a time interval. After receiving the verification instruction, the verification server can filter out the matching candidate biological information set according to the site identifier and the time interval to which the collection time belongs. This set contains the biological information of all objects who have handled business in the identity verification site after passing the biometric identity verification in the time interval to which the collection time belongs. Then, the verification server searches the candidate biological information set to check whether the second object biological information hits, so as to improve the search efficiency.
[0183] For example, each day can be a time interval, and the identity verification site is a swimming pool. For this swimming pool, there will be a site biological information set every day. If someone (i.e. the second object) drowns in the swimming pool on that day, the security guard (i.e. the first object) of the swimming pool as a super administrator can collect the second object biological information of the drowning person through the above-mentioned method. Assuming that the collection time is xx year 9 month 5 day 10:12 (which can also be accurate to the hour position, or even accurate to the date position), the time interval to which it belongs is (xx year) 9 month 5 day, and the corresponding site biological information set of the swimming pool on 9 month 5 day is the candidate biological information set. The verification server can search the stored candidate biological information set to check whether the second object has handled business through palm verification on that day.
[0184] In this way, the range of identity verification can be quickly narrowed down, the identification efficiency and accuracy can be improved, and only the biological information of the candidate object who really appears in the swimming pool in the relevant time period can be used for matching and verification.
[0185] In addition, considering that there may be some sites that are divided into different functional areas, i.e. sub-sites, in this case, if only the site is used to divide the small set for auxiliary identification, there may be many candidate biological information in a small set. In order to further improve the search efficiency, time can be introduced to further mark or divide the site biological information set according to the sub-site.
[0186] Therefore, if the identity verification site contains multiple sub-sites, one optional implementation of S32 is as follows:
[0187] Firstly, the identity authentication sub-scene in which the first object collects the second object biological information is determined in multiple sub-scenes; then, the scene identifier, the sub-scene identifier of the identity authentication sub-scene, and the second object biological information are sent to the verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the scene identifier and the sub-scene identifier; each candidate object is an object that handles a business in the identity authentication sub-scene after identity verification through biological recognition.
[0188] Specifically, the verification server can filter out a matched scene biological information set, that is, the candidate biological information set in this paper, from multiple scene biological information sets according to the scene identifier and the sub-scene identifier, and then search whether the second object biological information hits in the candidate biological information set, so as to improve the search efficiency.
[0189] In the embodiment of the application, there are many ways to determine the identity authentication sub-scene, for example, the position information of the first object currently located can be determined through the positioning of the first object terminal, and based on the position information, it is determined which sub-scene of the identity authentication scene the identity authentication sub-scene is.
[0190] Alternatively, the identity authentication sub-scene is determined according to the first jump operation of the first object, for example, different sub-scene pages can be set in the business sub-application, and the first object can trigger the first jump operation in any sub-scene page or the sub-scene page with its own permission, and jump to the verification sub-application by the business sub-application. Therefore, the sub-scene page in which the first object triggers the first jump operation can also be used to determine which sub-scene of the identity authentication scene the identity authentication sub-scene is.
[0191] Taking the identity authentication scene as a swimming pool as an example, the swimming pool can include the following four sub-scenes: male guest area, female guest area, family area and general area.
[0192] Suppose that in the merchant applet of the swimming pool, each sub-scene corresponds to a sub-scene page, for example, after the first object enters the sub-scene page corresponding to the male guest area, the first jump operation is triggered through the shortcut entrance (similar to 40 in FIG. 4) of the palm verification applet in the sub-scene page, and the palm verification applet is entered. Then, the identity authentication sub-scene is the male guest area in the swimming pool.
[0193] Alternatively, the identity authentication sub-scene is determined according to the selection of the first object, for example, in the business sub-application, the first object can trigger the first jump operation in the main page corresponding to the identity authentication scene, and jump to the verification sub-application by the business sub-application. Before the sub-application jumps, the object can be prompted to select the sub-scene, and the identity authentication sub-scene is determined according to the selection of the object, which is which sub-scene of the identity authentication scene.
[0194] It should be noted that the above-mentioned several identity authentication sub-site determination methods are only simple examples, and other determination methods are also applicable to the embodiments of the present application, which will not be repeated here.
[0195] In the above-mentioned embodiments, the first object terminal sends the sub-site identifier to the verification server, so that the verification server can efficiently find the most relevant candidate biological information set from a large amount of biological information data, thereby improving the accuracy and efficiency of identity verification. This method not only reduces unnecessary data processing, but also ensures accurate identity verification in a specific site and sub-site.
[0196] In addition, it should be noted that whether the time factor or the sub-site identifier is introduced, the site biological information set can also be optimized by the above-mentioned deletion strategy, such as periodically / irregularly deleting some site biological information sets or part of the biological information in some site biological information sets, etc., which will not be repeated here.
[0197] It should be noted that the verification instruction can also include the sub-site identifier and the collection time, so that the verification server can also find the most relevant candidate biological information set from a large amount of biological information data based on the hierarchical screening mechanism. The specific implementation is not limited herein. In addition, the information contained in the above-mentioned several verification instructions is only a simple example, in addition to this, some auxiliary information for quickly realizing the identity recognition of the second object can also be included, such as, the gender information of the second object can also be further included, which means that the site biological information set can also be labeled with different genders when it is constructed, or different site biological information sets can be constructed according to different genders, etc., which will not be limited herein.
[0198] S33: After receiving the identity information returned by the verification server, the identity of the second object is confirmed according to the identity information.
[0199] In the embodiments of the present application, the verification server will return the identity information bound to the object after verifying the palm image of the second object, and the first object terminal can confirm the real identity of the second object according to the identity information.
[0200] The identity information is data used to uniquely identify and verify the identity of an individual. In the embodiments of the present application, the identity information refers to the information related to the identity of the object, such as account information, which is bound when the object opens the biological recognition verification function, in addition to this, it can also be the real name of the object, mobile phone number, email address, member number, and even in some higher security level scenarios, it can also be an ID number, digital certificate, etc.
[0201] The information listed above can be used alone or in combination to enhance the security and accuracy of identity verification.
[0202] Taking the scenario of a swimming pool as an example, as shown in FIG. 7, which is a schematic diagram of palm verification for storing items in an embodiment of the present application, the figure shows the process of an object using palm verification technology to store items in a locker room of a swimming pool. It is assumed that a second object (which can be any object other than the super administrator of the xx swimming pool) comes to the xx swimming pool on September 5, 2021 (Friday) and performs a storage business by palm verification at 10:12. As shown in FIG. 7, before the object palm verification, the display interface of the palm verification terminal installed on the locker room locker can display the time, the number of available cabinets (such as 50) and the total number of cabinets (such as 54), and there is also a "storage access" button on the display interface. Click to select the palm verification method, the object can use the palm verification terminal installed on the locker room locker to open the locker. After the palm verification is passed, the display interface on the palm verification terminal can remind the customer: "No. 6 cabinet door is open, please take your items and close the cabinet door".
[0203] It is assumed that after the second object stores, the identity is verified by palm verification to open the gate to the swimming pool and swim through the gate.
[0204] After an emergency such as drowning occurs during swimming, the first object (the super administrator of the xx swimming pool) can collect the target palm print of the second object by the above-mentioned method, send it to the palm verification server for identity verification, to confirm the identity information of the second object.
[0205] Considering that it is crucial to quickly confirm the identity of the second object in an emergency, and the identity information fed back by the palm verification server may not directly indicate the identity of the second object, but the second object has previously performed a storage business, and if the locker contains personal items of the second object, this can be used as a basis for further verifying the identity of the second object, therefore, the present application also provides a one-key locker opening function.
[0206] In an optional implementation, the identity information is the account information bound by the second object when the biological recognition verification function is opened, and the business includes a storage business. An optional implementation of S33 includes the following processes S331-S333 (not shown in FIG. 3):
[0207] S331: In response to the second jump operation, the verification sub-application jumps to the business sub-application associated with the first object.
[0208] As described above, the first object can trigger the first jump operation to jump to the verification sub-application through the business sub-application, and then collect the second object biological information of the second object through the verification sub-application. After collecting the second object biological information and sending the corresponding verification instruction to the verification server, if the second object biological information hits the candidate biological information set, the verification server will return the verification result. At this time, as in S331, the second jump operation is executed by the first object, and the verification sub-application jumps to the business sub-application associated with the first object. In the business sub-application, the verification result returned by the verification server can be presented.
[0209] For example, in the case of verification failure, it means that the second object biological information does not hit the candidate biological information set (i.e. when the second object biological information fails to match any candidate biological information in the candidate biological information set), at this time, the identity information of the second object cannot be confirmed, and the verification server can feed back a prompt of verification failure to the first object terminal, in addition, it can also prompt the first object to re-collect the biological information of the second object to improve the verification success rate, etc.
[0210] For another example, in the case of verification success, it means that the second object biological information hits the candidate biological information set (i.e. when the second object biological information matches the candidate biological information in the candidate biological information set), at this time, based on the hit candidate biological information, the identity information of the second object can be determined, and the verification server can feed back a prompt of verification success to the first object terminal, in addition, it can also return the identity information of the second object, including but not limited to the account information of the second object, based on which the last locker used by the second object can be automatically identified as the target locker, and it is opened through the remote control service, the specific process is as follows:
[0211] S332: responding to the opening operation triggered by the first object through the business sub-application, opening the target locker through the remote control service in combination with the identity information; the target locker is the locker last used by the second object when performing the storage business through biological recognition verification in the identity verification place.
[0212] Specifically, considering that the second object may use different lockers when performing the storage business in the identity verification place at different times, the target locker in this paper refers to the last used locker.
[0213] In the embodiment of the present application, the business sub-application supports one-key locker opening. Specifically, by responding to the opening operation triggered by the first object through the business sub-application, the last locker used by the second object when performing the storage business through biological recognition verification in the identity verification place is opened through the remote control service in combination with the identity information of the second object.
[0214] The remote control service can be implemented based on Internet of Things technology, and each locker is equipped with a smart lock and a communication module. After the first object triggers the opening operation, the business sub-application sends the identity information (such as account information) of the second object to the server of the remote control service. After the server receives the identity information, it queries the pre-stored locker use record database to find the latest used locker number associated with the identity information. Then, the server sends an opening instruction to the corresponding locker smart lock through a communication protocol (such as MQTT, HTTP, etc.). The smart lock receives the instruction and verifies its legality (such as checking the signature and timestamp of the instruction). If the verification is passed, the locker door is opened.
[0215] In actual application, after the business sub-application responds to the opening operation triggered by the first object, an opening instruction can be sent to the service server corresponding to the business sub-application, which contains the account information of the second object and / or the locker identifier of the target locker. The target locker is opened through the service server.
[0216] Of course, the service server can also directly feed back the locker identifier of the target locker corresponding to the account information, which can be presented through pop-up windows, floating layers, etc. Based on the locker identifier, the target locker can be remotely controlled to be opened.
[0217] As shown in FIG. 8, it is a schematic diagram of one-key opening of a locker to take an article in an embodiment of the present application. It shows an application page named “merchant applet”. A pop-up window is displayed in the application page, which writes “xx swimming pool” on the top and a dialogue box writes “Is it one-key opening of No. 2-6 locker for men?” on the bottom. There are two options “Yes” and “No” below. If the first object clicks “Yes”, the corresponding locker in the changing room of the swimming pool can be remotely opened to take out the article of the second object.
[0218] Further, the identity information of the second object can be further confirmed according to the article in the locker. The specific process is as follows:
[0219] S333: Determine the identity information of the second object according to the article in the target locker.
[0220] Because the articles in the locker often have personal characteristics and can be used as a basis for auxiliary verification, after the locker is opened, the first object can quickly confirm the actual identity of the second object according to the articles in the locker, such as personal articles or other identity proof materials.
[0221] In addition, opening the locker can also help the first object to quickly find some other important information of the second object, such as the contact information of the emergency contact person, medical information, etc., thereby improving the efficiency and pertinence of rescue.
[0222] In addition, if the locker contains first-aid supplies or medications, the first subject can immediately take them out and use them to assist the second subject, further improving the effectiveness of first aid, and so on.
[0223] Through the above implementation, not only the accuracy and security of identity verification are improved, but also efficient and automated operation processes are realized through remote control and service integration, reducing the time of manual intervention, ensuring that the identity of the second subject can be quickly and accurately confirmed in an emergency and appropriate measures are taken. At the same time, the user experience is also considered, and the operation process is simplified through one-key opening of the locker and other functions.
[0224] Optionally, to ensure the security of identity information transmission, the verification server can also securely return the determined identity information of the second subject to the first subject terminal through a serial port. The serial port is an interface used for data transmission between two devices (such as the first subject terminal and the verification server), which is used in the present application to securely return the identity information of the second subject and other data. By selecting appropriate serial communication protocols (such as RS-485), using encryption algorithms (such as symmetric encryption algorithms or asymmetric encryption algorithms), adding data integrity check and time stamp, and other technical solutions, secure communication between two ends can be realized, ensuring the integrity, confidentiality and availability of data during transmission.
[0225] Therefore, before S33, the first subject terminal can receive the identity information returned by the verification server through the serial port. The specific implementation of realizing secure communication between two ends based on the serial port can be referred to the related description of the verification server side below, which will not be repeated here.
[0226] Secure communication between two ends refers to a communication mode that ensures the integrity, confidentiality and availability of data when transmitting data between two communication endpoints (such as the first subject terminal and the verification server). In the present application, secure communication between two ends can be realized by selecting appropriate serial communication protocols (such as RS-485), using encryption algorithms (such as symmetric encryption algorithms or asymmetric encryption algorithms), adding data integrity check and time stamp, using hardware acceleration modules, and other technical solutions.
[0227] Of course, in addition to identity information, other information can also be transmitted through the serial port to further improve communication security, such as the first subject terminal and the verification server can transmit verification instructions, authentication instructions, authentication results and other information through the serial port, which is not limited in detail herein.
[0228] It should be noted that the above is an introduction to the identity recognition method in the embodiments of the present application from the first subject terminal side, and the identity recognition method in the embodiments of the present application will be further introduced from the verification server side as follows:
[0229] Referring to FIG. 9, an embodiment of an identity recognition method provided by the present application is shown in a flowchart, and the service end is taken as an example for performing a subject, and the specific implementation process of the method is as follows S91-S93:
[0230] S91: receiving a verification instruction sent by a first object terminal; wherein the verification instruction contains a place identifier of an identity verification place and second object biological information; the second object biological information is biological information of a second object collected by the first object terminal in response to a verification operation triggered by the first object; the first object is an object with business management authority in the identity verification place.
[0231] In the embodiment of the present application, after the first object collects the biological information of the second object through the first object terminal, the first object can send the biological information to the verification service end for analysis, so as to confirm the identity information of the second object and return the identity information to the first object terminal. However, in order to ensure that only the first object with authority can perform a key operation in an emergency, improve the efficiency of safety management, and enhance the security of the place, the first object is authenticated before collecting the biological information of the second object.
[0232] Correspondingly, before determining the candidate biological information set according to the place identifier, an optional authentication method is as follows:
[0233] Firstly, an authentication instruction sent by the first object terminal is received. The authentication instruction is sent by the first object terminal in response to a verification operation triggered by the first object. Then, the first object is authenticated according to the account information of the first object in the authentication instruction. Specifically, according to the account information of the first object in the authentication instruction, a mapping relationship between the place identifier and the super administrator account information is queried from the pre-stored mapping relationship, if there is account information corresponding to the place identifier of the identity verification place in the mapping relationship, and the account information is consistent with the account information of the first object, it is determined that the first object has business management authority in the identity verification place, and the authentication is completed; if there is no matching account information, the authentication is not passed.
[0234] As described above, in actual application, the first object needs to register and bind the administrator account information corresponding to the current place in advance, and only the account can perform a key operation in an emergency.
[0235] In the embodiment of the present application, the verification service end side can store a mapping relationship between the place identifier and the super administrator account information, which can reflect the super administrator corresponding to each place, even each sub-place. Specifically, the mapping relationship can be stored in a database, such as a SQLite database or other database.
[0236] Specifically, when the first object triggers a verification operation through the first object terminal, the first object terminal responds to the operation and sends an authentication instruction to the verification server, where the authentication instruction can contain the administrator account information of the first object when the first object previously registered and bound the current site, and in addition, can contain the corresponding site identifier (even the sub-site identifier). In this way, after the verification server receives the authentication instruction containing the account information of the first object and the site identifier of the identity verification site, the verification server extracts the account information and the site identifier in the authentication instruction, and then queries the pre-stored mapping relationship in the database to analyze whether the super administrator under the identity verification site is the first object or contains the first object.
[0237] If the first object is contained, it can be determined that the first object has business management authority in the identity verification site, and the authentication result is returned to the first object terminal. Subsequently, the first object terminal can call the collection device to collect the second object biological information of the second object, and then send the second object biological information together with some other information to the verification server to identify the second object through the verification server.
[0238] If the first object is not contained, it can be determined that the first object does not have business management authority in the identity verification site, and the authentication result is returned to the first object terminal. Subsequently, the first object terminal cannot call the collection device to collect the second object biological information of the second object, so as to protect the privacy of the second object.
[0239] In the above embodiment, when an emergency occurs, the first object (such as an administrator) is authenticated by the verification server, and it is ensured that only when the authentication is passed, the first object terminal can call the collection device to collect the biological information of the second object. Through the above authentication process, it is effectively ensured that only the first object with authority can perform critical operations in an emergency, which improves the safety management efficiency and enhances the security of the site.
[0240] Specifically, after the verification server receives the verification instruction containing the second object biological information and the site identifier sent by the first object terminal, the identity recognition process of the second object can be triggered, and the specific implementation is as follows:
[0241] S92: Determine a candidate biological information set according to the site identifier; the candidate biological information set contains candidate biological information of at least one candidate object, and each candidate object is an object that has handled business after successfully verifying the identity by biological recognition in the identity verification site.
[0242] Specifically, the verification instruction is sent after the first object collects the biological information of the second object, and the verification server can confirm the identity of the second object based on the verification instruction. Wherein, the second object biological information in the verification instruction is used to confirm the second object identity information, and the place identifier is used to confirm the place biological information set. Based on the place identifier, the matched place biological information set, i.e. the candidate biological information set in this paper, can be screened out, and then it is further searched from the candidate biological information set whether the second object biological information hits, so as to improve the retrieval efficiency.
[0243] In the embodiment of the application, the verification server side can construct a plurality of place biological information sets. Each place can construct one or more such sets according to different business needs, so each place can correspond to one or more place biological information sets. The specific implementation is the same as the related description of the first object terminal side, which will not be repeated here.
[0244] Optionally, considering that there may be some places with large flow of people, in this case, in order to further improve the retrieval efficiency, a time factor can also be introduced to further mark or divide the place biological information set according to the time interval. In this way, each place biological information set only stores the biological information of the object who has handled the business in this place after passing the biological recognition verification of identity within the corresponding time interval. For details, please refer to the related description of the first object terminal side, which will not be repeated here.
[0245] Optionally, the biological information of the object stored in the place biological information set can include the standard biological information uploaded by the object when the biological recognition verification function is opened. Correspondingly, the candidate biological information in the candidate biological information set also includes the standard biological information. Therefore, before performing S92, the standard biological information uploaded by each object when the biological recognition verification function is opened can also be stored, and at least one place biological information set can be constructed by the following method:
[0246] For each place, if there is an object who has handled the business in this place after passing the biological recognition verification of identity within the specified time interval, the standard biological information of the object is added to the place biological information set corresponding to the place.
[0247] For example, each day can be taken as a time interval, and the pool has 5, respectively, recorded as: swimming pool 1, swimming pool 2, …, swimming pool 5, then in each day, for each swimming pool, a place palm print set (a biological information set in this paper) can be constructed, such as on September 1, 2024, for the above-mentioned 5 swimming pools, swimming pool 1-palm print set 1, swimming pool 2-palm print set 1, …, swimming pool 5-palm print set 1 are constructed respectively; on September 2, 2024, for the above-mentioned 5 swimming pools, swimming pool 1-palm print set 2, swimming pool 2-palm print set 2, …, swimming pool 5-palm print set 2 are constructed respectively; ….
[0248] If the sub-places are divided, then in each day, for each swimming pool, multiple place palm print sets can be constructed, which will not be described one by one here. The place palm print set is a biological information set, which stores the palm print information of the object in the corresponding place who handles the business after identity verification by biological recognition. Each place can construct one or more such sets according to different business needs, which can be further divided according to time intervals and sub-places.
[0249] In this way, the object in each place who handles the business after identity verification by biological recognition can be effectively managed, and the daily (i.e. each time interval) place biological information set is formed. This way can update and maintain biological information data in time, improve the accuracy and timeliness of identity verification, avoid recognition errors caused by outdated data, facilitate subsequent identity verification, and thus improve the accuracy of identity verification.
[0250] In addition, in order to protect the privacy of the object, optimize the storage space and improve the system performance, a deletion strategy for the place biological information set can also be set, which can be referred to the related description of the first object terminal side, such as deleting the historical place biological information set every two days, or deleting the historical place biological information set every day, etc., which is not limited here.
[0251] On this basis, an optional implementation of S92 is as follows:
[0252] First, determine the time interval to which the collection time belongs; then, for at least one place biological information set, check whether its associated place identifier is consistent with the place identifier of the identity verification place, and check whether its associated time interval is consistent with the time interval to which the collection time belongs, if both meet, the place biological information set is screened out as a candidate biological information set; wherein each candidate object is: an object who handles the business in the identity verification place after identity verification by biological recognition in the time interval.
[0253] The collection time represents the time at which the first subject collects the second subject biological information, which can be a time point or a small time period, and correspondingly, the second subject biological information can also be one or more biological information. If the collection time is a small time period, the second subject biological information can be multiple palm images or a video stream containing palm images collected in the small time period.
[0254] In the above manner of constructing the site biological information set, each site biological information set is also bound to a time interval. After the verification server receives the verification instruction, the matching candidate biological information set can be filtered according to the site identifier and the time interval to which the collection time belongs. This set contains the biological information of all subjects who have handled business in the identity verification site and passed the biological recognition identity verification in the time interval to which the collection time belongs. Then, it is determined whether the second subject biological information hits from the candidate biological information set, so as to improve the retrieval efficiency.
[0255] In the above embodiment, the time interval is combined to filter the candidate biological information set, which can quickly narrow the range of identity verification and improve the recognition efficiency and accuracy, so as to ensure that only the biological information of the candidate subject who actually appears in the swimming pool in the relevant time period is used for matching and verification.
[0256] In addition, when checking whether the second subject biological information hits the candidate biological information set, the second subject biological information needs to be compared with each candidate biological information in the candidate biological information set. The comparison method can be various, which is not limited in detail herein.
[0257] Different comparison algorithms are used for different types of biological information. For image type biological information such as palmprint and face, a feature extraction and matching method can be used. For example, the key feature points F target of the target biological information are extracted and compared with the feature points F candidate of the candidate biological information, and the feature similarity S between the two is calculated. The calculation formula is as follows: Wherein n is the number of feature points, and δ is a feature point matching function. If the feature similarity S exceeds a preset threshold T, it is considered that the two match. For fingerprints, the comparison can be based on minutiae features (such as end points and bifurcation points). The number of feature matches is calculated. If the number of matches exceeds a certain threshold, it is considered that the two match. For voiceprints, the comparison can be based on the spectral features of the sound. The spectral similarity is calculated. If the similarity exceeds a threshold, it is considered that the two match. For veins, the comparison can be based on the features of the vein pattern. The pattern similarity is calculated. If the similarity exceeds a threshold, it is considered that the two match.
[0258] The following will take palmprint as an example for a brief description:
[0259] For example, key feature points of the target palmprint can be extracted and compared with those of each candidate palmprint in the candidate palmprint set to calculate the feature similarity between the target palmprint and each candidate palmprint. If the feature similarity exceeds a preset threshold, it is considered that the two are matched. This process usually involves comparison of the positions, directions and texture details of the feature points to ensure accurate identification even in the case of light, angle or quality differences. By comparing the candidate palmprints one by one, the palm verification server can determine whether the target palmprint exists in the set, thereby completing the identity verification of the second object. The candidate palmprint set is a candidate biological information set containing candidate palmprint information of at least one candidate object, which is an object that has handled business after successfully verifying the identity by biological recognition in the identity verification site, and is used for comparison with the target palmprint in the identity recognition process. The preset threshold can be adjusted according to the actual application scenario, and the value range is generally between [0.7, 0.9], and the specific threshold can be determined through a large amount of experimental data and actual tests.
[0260] For another example, the images of the target palmprint and the candidate palmprint can also be converted into fixed-length feature vectors, and then the distance (such as Euclidean distance or cosine similarity) between the target palmprint and the candidate palmprint is calculated. By comparing these distances, the overall similarity of the two palmprint images can be evaluated to obtain the feature similarity, so as to determine whether they are matched. This method can capture the overall structural information of the palmprint and improve the robustness of identification.
[0261] It should be noted that the two comparison methods listed above are only simple examples, and other comparison methods are also applicable to the embodiments of the present application, which will not be described one by one here.
[0262] Optionally, if the second object biological information has multiple, the identity information of the second object can also be determined by the following method:
[0263] Based on the second object biological information whose information quality meets the preset quality requirement in the multiple second object biological information, the second object biological information feature of the second object is extracted; the candidate biological information in the candidate biological information set, whose feature similarity with the second object biological information feature is higher than the preset threshold, is taken as the hit candidate biological information; and the account information associated with the hit candidate biological information is taken as the identity information of the second object.
[0264] Specifically, for multiple second object biological information, the information quality thereof is evaluated from multiple dimensions. Taking a palmprint image as an example, the evaluation dimensions include hand size S, angle θ, image contrast C, image brightness L and clarity D and other coefficient indicators. For each indicator, a corresponding preset range is set, such as the hand size range [S min ,S maxan angle range of [θ min ,θ max ], etc. If all indicators of the second object biological information meet the preset range, it is considered that the information quality meets the preset quality requirement, and the second object biological information features of the second object are extracted based on the information.
[0265] The account information of each candidate object in the candidate biological information set is bound when the corresponding object opens the biological recognition verification function. The preset threshold value can be determined according to the type of biological information and actual application requirements. Generally, for palmprint information, the preset threshold value can be set to 0.8; for face information, the preset threshold value can be set to 0.75, and specific optimization and adjustment can be performed through experiments and actual tests.
[0266] In the embodiments of the present application, the information quality in the second object biological information refers to the accuracy and integrity of the collected biological information. For example, a clear fingerprint image, a palmprint image, complete face features, and a stable voiceprint spectrum are all high-quality information, which helps to ensure the effectiveness and security of biological recognition. Taking palmprint as an example, when judging the quality of the collected palm image containing palmprint, the palm size, angle, image contrast, image brightness, and clarity coefficient indicators can be used for comprehensive evaluation. When these indicators meet the preset range, it is considered that the palm image meets the preset quality requirement.
[0267] The plurality of second object biological information can be collected at multiple angles, or collected multiple times in a short time, or in a video stream, so as to obtain more information samples and increase the accuracy of optimization.
[0268] It should be noted that the collection of biological information in the present application can be obtained by biopsy, which means that the collected biological information comes from a real human body, not a photo, a mold, or a fake product, to prevent fraud using fake hands or digital images.
[0269] On this basis, when there are multiple second object biological information, it is necessary to select one second object biological information whose information quality meets the preset quality requirement from the multiple second object biological information. This process can be understood as optimization, that is, selecting the second object biological information with the best information quality for matching to ensure accurate identity verification.
[0270] Taking palmprint as an example, when optimizing the collected palm image containing palmprint, the palm size, angle, image contrast, image brightness, and clarity coefficient indicators can be used for comprehensive evaluation to select the optimal palm image, that is, the target palmprint that meets the preset quality requirement. Of course, before optimization, each collected palm image can also be preprocessed, including denoising, contrast adjustment, edge detection, etc., to improve the image quality.
[0271] The de-noising can adopt a Gaussian filtering algorithm, which performs a weighted average on each pixel point and its neighborhood pixels in the image, and the weight is determined by a Gaussian function, and the formula is where (x, y) is the coordinate of the pixel point, and σ is the standard deviation of the Gaussian function. The contrast adjustment can adopt a histogram equalization algorithm, which adjusts the gray histogram of the image to make the gray distribution of the image more uniform and enhance the contrast of the image. The edge detection can adopt a Canny edge detection algorithm, which includes steps of Gaussian smoothing, gradient amplitude and direction calculation, non-maximum suppression, double threshold detection and edge connection, and can accurately detect the edge information in the image.
[0272] Next, the high-quality second object biological information screened out is subjected to feature extraction to obtain second object biological information features (such as key points or feature vectors, etc.), and the second object biological information features are compared with each candidate biological information in the candidate biological information set, and the feature similarity is calculated, and the specific calculation method is as above, which will not be repeated here. If there is a candidate biological information in the candidate biological information, the similarity of the candidate biological information features and the second object biological information features is higher than the preset threshold, the candidate biological information is regarded as the hit candidate biological information, of course, if there are multiple candidate biological information features with a similarity higher than the preset threshold, the one with the highest feature similarity can be regarded as the hit candidate biological information. Further, the account information associated with the hit candidate biological information is taken as the identity information of the second object, and these account information is bound when the object opens the biological recognition verification function
[0273] In the above embodiments, by screening high-quality biological information images and extracting their features, and performing high-precision comparison with the candidate biological information set, the accuracy and reliability of identity verification can be effectively improved. By setting the preset quality requirement and the feature similarity threshold, the system can exclude the interference of low-quality images and focus on the feature matching of high-quality biological information. This not only reduces the possibility of misidentification, but also improves the robustness of the verification process. Finally, the identity of the second object is determined based on the account information associated with the hit candidate biological information, ensuring the security and effectiveness of identity verification.
[0274] In addition, considering that there may be some places that are divided into different functional areas, i.e. sub-places, in this case, if only the place is used to divide the small set of auxiliary identification, there may be many candidate biological information in one small set. In order to further improve the retrieval efficiency, time can be introduced to further mark or divide the place biological information set according to the sub-place.
[0275] Therefore, if the identity verification site includes multiple sub-sites, and the first object collects the second object biological information at an identity verification sub-site in the multiple sub-sites through the first object terminal, the verification instruction further includes a sub-site identifier of the identity verification sub-site. On this basis, one optional implementation of S92 is as follows:
[0276] The verification server first filters multiple reference biological information sets matching the site identifier from the multiple site biological information sets, and then filters a candidate biological information set matching the sub-site identifier from the multiple reference biological information sets. In this way, each candidate object in the candidate biological information set is an object that has handled business in the identity verification sub-site after identity verification through biological recognition.
[0277] The reference biological information set is a biological information set matching a specific site identifier filtered from the multiple site biological information sets, and is an intermediate result of further filtering the candidate biological information set, used to narrow the search range and only keep biological information data related to the specified site.
[0278] Further, the verification server first filters multiple reference biological information sets matching a specific site identifier (such as the swimming pool 4) from the multiple site biological information sets to narrow the search range and only keep biological information data related to the specified site, and then further filters a candidate biological information set matching a specific sub-site identifier (such as a certain area in the swimming pool 4) from the multiple reference biological information sets filtered in the previous step to further refine the search range and ensure that only objects that have handled business in the specified sub-site after identity verification through biological recognition are considered.
[0279] In one specific example, the verification server first traverses the multiple site biological information sets, checks whether the associated site identifier of each site biological information set is consistent with the site identifier of the identity verification site, and if so, filters the site biological information set as a reference biological information set. Then, for the multiple reference biological information sets filtered, check whether the associated sub-site identifier is consistent with the sub-site identifier of the identity verification sub-site, and if so, filter the reference biological information set as a candidate biological information set. In this way, each candidate object in the candidate biological information set is an object that has handled business in the identity verification sub-site after identity verification through biological recognition.
[0280] As shown in FIG. 10, which is a schematic diagram of a screening process of a candidate palmprint set in an embodiment of the present application. There can be multiple venue palmprint sets for assisting in identification. Taking the above five swimming pools as an example, it is assumed that swimming pool 1 has two sub-venues, corresponding to swimming pool 1-sub-venue 1 palmprint set and swimming pool 1-sub-venue 2 palmprint set, swimming pool 4 has four sub-venues, corresponding to swimming pool 4-sub-venue 1 palmprint set, swimming pool 4-sub-venue 2 palmprint set, swimming pool 4-sub-venue 3 palmprint set, and swimming pool 4-sub-venue 4 palmprint set, swimming pool 2 and 3 are not divided into sub-venues, corresponding to swimming pool 2 palmprint set and swimming pool 3 palmprint set respectively. Assuming that the venue identifier in the verification instruction represents swimming pool 4, the first screening locks swimming pool 4, and the reference palmprint set has four, i.e., swimming pool 4-sub-venue 1 palmprint set, swimming pool 4-sub-venue 2 palmprint set, swimming pool 4-sub-venue 3 palmprint set, and swimming pool 4-sub-venue 4 palmprint set, corresponding to the black marked part in FIG. 10. Assuming that the sub-venue identifier represents sub-venue 2, the second screening locks the candidate palmprint set, i.e., swimming pool 4-sub-venue 2 palmprint set, corresponding to the black marked part in FIG. 10.
[0281] Through the above hierarchical screening mechanism, the verification server can efficiently find the most relevant candidate biological information set from a large amount of biological information data, thereby improving the accuracy and efficiency of identity verification. This method not only reduces unnecessary data processing, but also ensures accurate identity verification in a specific venue and sub-venue.
[0282] It should be noted that the verification instruction can also include a sub-venue identifier and a collection time. In this way, the verification server can also find the most relevant candidate biological information set from a large amount of biological information data based on the hierarchical screening mechanism. The specific implementation is not limited in this document. In addition to the above-mentioned several verification instructions, some auxiliary information for quickly realizing the identity recognition of the second object can also be included, such as gender information of the second object. In other words, different genders can be marked when building the venue biological information set, or different venue biological information sets can be built according to different genders. The specific implementation is not limited in this document.
[0283] S93: When the biological information of the second object hits the candidate biological information set, the identity information of the second object is determined based on the hit candidate biological information, and the identity information is returned to the first object terminal.
[0284] In an embodiment of the present application, the verification server returns the identity information bound to the object after verifying the palm image of the second object. The first object terminal can confirm the real identity of the second object according to the identity information. The specific implementation is described on the first object terminal side and will not be repeated here.
[0285] Optionally, in order to ensure the security of the identity information transmission, the verification server can also securely return the determined identity information of the second object to the first object terminal through a serial port.
[0286] Specifically, the secure return of the identity information through the serial port involves ensuring the integrity and security of the data during transmission. In the embodiments of the present application, the following technical solutions can be used to achieve secure communication between two ends based on a serial port:
[0287] Firstly, RS-232, RS-422, RS-485 and other related protocols can be selected as the serial port communication protocol between the two ends. Among them, the RS-485 communication protocol supports multi-point communication and differential signal transmission, and can achieve high data transmission rate and long transmission distance. Therefore, RS-485 is selected as the serial port communication protocol in the present application.
[0288] Further, in order to ensure the security of the communication data, symmetric encryption algorithm or asymmetric encryption algorithm can be used to encrypt the data. Among them, symmetric encryption algorithm is suitable for small data encryption, such as Advanced Encryption Standard (AES) algorithm, which uses the same key for encryption and decryption, ensuring that even if the data is intercepted, it cannot be easily read; asymmetric encryption algorithm is suitable for large data encryption, such as RSA (Rivest-Shamir-Adleman) algorithm, which uses public and private keys to encrypt and decrypt data, ensuring that only the party holding the correct private key can decrypt the data.
[0289] The communication data in this paper can be the identity information of the second object, which has a small data volume and can use symmetric encryption algorithm. If symmetric encryption algorithm is used to transmit communication data, the key negotiation method can also be used when establishing a secure connection between the two ends, that is, the two parties generate a consistent key through a certain key negotiation algorithm, and use the key for communication encryption, further improving the security of data transmission.
[0290] If symmetric encryption algorithm (such as Advanced Encryption Standard (AES) algorithm) is used to transmit communication data, the key negotiation method can also be used when establishing a secure connection between the two ends, that is, the two parties generate a consistent key through Diffie-Hellman key negotiation algorithm. The principle of Diffie-Hellman algorithm is that the two parties first agree on a large prime number p and a primitive root g, and each party selects a random number as a private key (for example, the first object terminal selects a and the verification server selects b), then calculates the public key (the first object terminal calculates A = ga mod p, and the verification server calculates B = gb mod p), and then the two parties exchange the public keys, and each party calculates the common key (the first object terminal calculates k = B a mod p, and the verification server calculates k = A b mod p). amod p, the server calculates B = g b mod p) and exchange. After that, both sides each calculate the same shared key according to the other's public key and their own private key (the first object terminal calculates K1 = B a mod p, the server calculates K2 = A b mod p, K1 = K2), and uses the key for communication encryption, further improving the security of data transmission.
[0291] In the communication process, the communication data can also be transmitted in a certain format to form a data frame, and the data frame is parsed at the receiving end (such as the first object terminal). Among them, the design of the data frame can include frame header, data length, data field, frame tail and other contents, to ensure the integrity and correctness of the communication data.
[0292] Taking the account information of the second object as an example, the data field in the corresponding data frame is the account information, the frame header identifies the beginning of the data frame, helps the receiving end to identify the existence of the data frame, the data length indicates the actual length of the data field, helps the receiving end to correctly parse the data, and the frame tail identifies the end of the data frame, helps the receiving end to identify the end position of the data frame.
[0293] Optionally, to avoid data tampering or repeated sending, data integrity checksum and timestamp information can be added in the data frame to ensure the correctness and uniqueness of the data.
[0294] Among them, the data integrity checksum is used to detect errors in the data transmission process, and the receiving end compares the checksum of the received data with the checksum provided by the sending end to ensure the integrity of the data. The timestamp is used to ensure the freshness of the data and prevent replay attacks, and the receiving end checks the timestamp to verify the freshness of the data and prevent replay attacks.
[0295] Optionally, to improve communication efficiency and security, a hardware acceleration module such as a hardware encryption chip or a field-programmable gate array (FPGA) can be selected to accelerate encryption and decryption operations and improve system security.
[0296] In addition to the above-mentioned technical solutions for implementing two-way secure communication based on serial ports, other serial port methods can also be used. For example, a two-way authentication mechanism can be implemented to ensure that the identities of both parties are trustworthy. For another example, an encrypted communication protocol such as Transport Layer Security (TLS) or Secure Sockets Layer (SSL) can be used to provide a secure tunnel for data transmission. For another example, a strict access control policy can be implemented to allow only authorized devices to communicate through the serial port. For another example, the security of the serial port connection can be ensured to prevent unauthorized physical access. For another example, error detection codes such as cyclic redundancy check can be used to detect errors in data transmission and request retransmission if necessary. For another example, anti-tampering measures can be implemented through hardware or firmware to ensure that the serial port device is not subject to malicious modification. For another example, the firmware of the serial port device can be updated periodically to fix known security vulnerabilities, and so on.
[0297] Through these technical solutions, the security of the information returned through the serial port can be significantly improved. In addition, it should be noted that the specific technical solution should be selected according to the requirements and security requirements of the application scenario, and this document does not make specific limitations.
[0298] It should be noted that the above is an introduction of the identity recognition method in the embodiments of the present application from the perspective of the verification server side. To facilitate understanding, the identity recognition method in the embodiments of the present application is briefly described from the perspective of multi-end interaction as follows:
[0299] Taking a swimming pool as an example, assume that the first object is a security guard of a certain swimming pool, the business sub-application is a merchant applet of the swimming pool, and the verification sub-application is a palm verification applet. Both applets can run in a certain instant messaging application.
[0300] As shown in FIG. 11, it is an identity recognition service architecture based on the palm verification technology of the instant messaging application in the embodiments of the present application. The entire system is composed of multiple parts, wherein the front end includes a place administrator mobile terminal (a first object terminal), a locker and a gate (two palm verification terminals), and the back end includes an instant messaging application back end (a palm verification server) service (which can be a cloud-related recognition service) and a merchant back end service. The following is a brief description of each part:
[0301] (I) Locker and gate.
[0302] The swimming pool can be provided with a storage cabinet and a gate, and the instant messaging application palm verification module is arranged respectively. The instant messaging application palm verification module in the storage cabinet is a palm verification and identification hardware device integrated in the storage cabinet, which is used to identify the palm print of the object. The instant messaging application palm verification module on the gate is a palm verification and identification hardware device installed on the gate, which is also used to identify the palm print of the object.
[0303] In actual application, the above-mentioned modules are manifested as a palm verification application in the front end. The palm verification application is an independent palm verification and identification application program, which provides more abundant functions and experiences including a palm verification and identification module for identifying the palm print of the object. The process involves biopsy and optimization, which will not be repeated here. The palm verification application is a palm swiping identification application program, which is manifested as an application corresponding to the palm swiping identification hardware device integrated in the storage cabinet or installed on the gate in the front end. The application provides more abundant functions and experiences including a palm swiping identification module for identifying the palm print of the object. The process involves biopsy and optimization.
[0304] Specifically, after the second object performs palm verification through the palm verification application on the storage cabinet, the palm verification application further collects the palm information of the current object and sends the current data to the instant messaging application backend service for identification. Technically, the palm verification application mainly calls the 3D camera to collect the current palm streaming media data of the second object. After obtaining the streaming media data, optimization is performed on the streaming media data. Meanwhile, the instant messaging application backend service receives the palm data uploaded by the palm verification module corresponding to the storage cabinet and performs feature extraction, further obtains the information related to the object, and returns the current information to the cabinet machine of the storage cabinet in the place in a safe manner through a serial port. After the cabinet machine further verifies the identity of the current object, the object can open the cabinet to store the object. After the object completes the storage, the storage cabinet is automatically locked to ensure the safety of the object.
[0305] After the second object stores the object, the object can also verify the identity through the palm verification mode and pass through the gate installed in front of the swimming pool to swim. The specific process is similar to the above-mentioned storage process, which will not be repeated here.
[0306] (II) Instant messaging application backend service.
[0307] The instant messaging application backend service includes the administrator authorization service related to the merchant platform, the instant messaging application palm verification and identification service (used to provide the core algorithm and service support of palm verification and identification), and the large database used for general identification and the small database used for auxiliary identification.
[0308] In practical applications, the swimming pool safety officer as a super administrator will register and bind the administrator account information corresponding to the current place in advance, and the administrator authorization service is used to grant or revoke the super administrator's permission of certain specific objects. Other objects will also open the palm verification and identification capability under the current place in advance, and the standard palmprints uploaded by all objects when opening the palm verification and identification will be stored in the large database.
[0309] In addition, the instant messaging application backend service will also establish a small database based on the objects such as gate passing and storage, which is used for the rapid positioning and identification of the second object identity in this text in an emergency, to ensure that in the no-hand ring scene, the first object can quickly locate the current object identity when an emergency occurs.
[0310] (Three) Place administrator mobile terminal.
[0311] The place administrator mobile terminal refers to the mobile terminal used by the first object of the swimming pool site. The mobile terminal is installed with an instant messaging application, and the instant messaging application can run a merchant applet and a palm verification applet.
[0312] When an emergency occurs, the first object can jump to the palm verification applet through the merchant applet. After the palm verification applet is started, the first object can be authenticated by the authentication module. After the authentication is passed, the first object's mobile phone camera (such as the front camera) is further called to guide the first object to shoot the palm information (i.e. target palmprint) of the second object. After shooting the object's palm information, the palm verification applet can send an authentication instruction to the instant messaging application backend service through the identity confirmation module to upload the collected palm information. The instant messaging application backend service will further search and confirm the identity of the second object in the previously established gate passing small database in combination with the current date and the information of the venue. For specific processes, please refer to the above embodiments, and the repeated parts will not be described here.
[0313] (Four) Merchant backend service.
[0314] The merchant backend service includes a storage cabinet remote control service, which is used to provide remote control functions for the storage cabinet, such as one-key cabinet opening and closing. Specifically, after the instant messaging application backend service confirms the identity of the second object, it will return the current identity information to the merchant applet, and the first object can associate the current second object identity to the storage cabinet and open the cabinet by one key. The storage cabinet remote control service in the merchant backend service can respond to the one-key cabinet opening. For specific implementation manners, please refer to the above embodiments, and the repeated parts will not be described here.
[0315] It should be noted that the above is a simple example of a swimming pool, and other places are also applicable, which will not be described one by one here.
[0316] By setting a security guard as a super administrator for a site, opening a clap palm image recognition capability for the super administrator, providing a small library single-factor search capability, based on the service architecture shown in FIG. 11, when an emergency occurs, the super administrator can jump to the palm verification applet through the merchant applet of the site, and after confirming the identity, when the identity is returned to the merchant applet, the cabinet is opened with one key, ensuring the ability of the palm verification application scenario in the medium replacement scenario.
[0317] Referring to FIG. 12, which is a flowchart of multi-end interaction for identity recognition in an embodiment of the present application, a site security guard is a first object, a user is a second object, a site security guard mobile terminal is a first object terminal, and a palm verification terminal can be installed on a site storage cabinet. The following is a detailed description of the process:
[0318] S1201: The user collects a palm image through the palm verification terminal.
[0319] S1202: Identity recognition. Specifically, the palm verification terminal notifies the palm verification server to identify the user according to the collected palm image.
[0320] S1203: Return identity. Specifically, the palm verification server returns the result of the user's identity recognition to the palm verification terminal.
[0321] S1204: Return identity. Specifically, the palm verification terminal returns the result of the user's identity recognition to the site storage cabinet.
[0322] S1205: Open the cabinet and store. Specifically, the user opens the cabinet and stores.
[0323] In summary, S1201-S1205 represent that the user collects his own palm image through the palm verification terminal, the photographed palm image is sent to the palm verification server for identity recognition, the recognition result is returned, and the cabinet is opened and stored according to the recognition result. For specific embodiments, refer to the above embodiments, and repeated descriptions are omitted.
[0324] S1206: The site security guard opens the palm verification applet through the mobile terminal.
[0325] S1207: Photograph the user's palm image. Specifically, the site security guard calls the mobile camera through the palm verification applet in the site security guard mobile terminal to take a picture.
[0326] S1208: Identity recognition. Specifically, the site security guard mobile terminal notifies the palm verification server to identify the user according to the photographed palm image.
[0327] S1209: Return the identity. Specifically, the palm verification terminal returns the result of the identity recognition of the user to the place security guard mobile terminal.
[0328] S1210: Jump to the merchant applet. Specifically, the place security guard jumps back to the merchant applet through the palm verification applet in the place security guard mobile terminal.
[0329] S1211: Open the cabinet to take the object and confirm the identity. Specifically, the place security guard opens the cabinet through the merchant applet.
[0330] In summary, S1206-S1211 represent that when an emergency occurs, the place security guard opens the palm verification applet through the place security guard mobile terminal, takes a photo of the user's palm, sends it to the palm verification server for identity recognition, and returns the recognition result. If the recognition is successful, jump back to the merchant applet to open the cabinet, the cabinet receives the instruction and automatically opens, the place security guard opens the cabinet to take the object and confirms the identity. For specific implementation, refer to the above embodiments, and the repeated parts will not be described here.
[0331] It should be noted that the process shown in FIG. 12 is only a simple example, and other interaction modes are also applicable to the embodiments of the present application, which will not be described here.
[0332] Based on the same inventive concept, the embodiments of the present application also provide an identity recognition device. As shown in FIG. 13, it is a structural schematic diagram of the identity recognition device 1300, which can include:
[0333] The receiving unit 1301 is configured to receive a verification instruction sent by a first object terminal; wherein the verification instruction contains a place identifier of an identity verification place and second object biological information; the second object biological information is biological information of a second object collected by the first object terminal in response to a verification operation triggered by a first object; the first object is an object with business management authority in the identity verification place;
[0334] The processing unit 1302 is configured to determine a candidate biological information set according to the place identifier; the candidate biological information set contains candidate biological information of at least one candidate object, and each candidate object is an object that has handled business after successfully verifying the identity by biological recognition in the identity verification place;
[0335] The identity confirmation unit 1303 is configured to, when the second object biological information hits the candidate biological information set, determine the identity information of the second object based on the hit candidate biological information, and return the identity information to the first object terminal.
[0336] Optionally, the verification instruction further includes the collection time corresponding to the second object biological information, and the processing unit 1302 is specifically configured to:
[0337] determining a time interval to which the collection time belongs;
[0338] screening, from the at least one site biological information set, a candidate biological information set matched with the site identifier and the time interval; wherein each of the candidate objects is an object that has handled a business in the identity verification site after successfully verifying identity by using biological recognition in the time interval.
[0339] Optionally, the candidate biological information includes standard biological information uploaded by an object when the object opens a biological recognition verification function, and the apparatus further includes:
[0340] a construction unit 1304, configured to store standard biological information uploaded by each object when the object opens a biological recognition verification function before the processing unit 1302 determines a candidate biological information set according to the site identifier, and construct the at least one site biological information set in the following manner:
[0341] for each site, if there is an object that has handled a business in the site after successfully verifying identity by using biological recognition in the time interval, the standard biological information of the object is added to the site biological information set corresponding to the site.
[0342] Optionally, if the identity verification site includes a plurality of sub-sites, and the first object collects the second object biological information in an identity verification sub-site in the plurality of sub-sites through the first object terminal, the verification instruction further includes a sub-site identifier of the identity verification sub-site.
[0343] The processing unit 1302 is specifically configured to:
[0344] screening, from a plurality of site biological information sets, a plurality of reference biological information sets matched with the site identifier;
[0345] screening, from the plurality of reference biological information sets, a candidate biological information set matched with the sub-site identifier; wherein each of the candidate objects is an object that has handled a business in the identity verification sub-site after successfully verifying identity by using biological recognition.
[0346] Optionally, the apparatus further includes:
[0347] an authentication unit 1305, configured to receive an authentication instruction sent by the first object terminal before the processing unit 1302 determines a candidate biological information set according to the site identifier; the authentication instruction is sent by the first object terminal in response to a verification operation triggered by the first object;
[0348] authenticating the first object according to account information of the first object in the authentication instruction;
[0349] If it is determined through authentication that the first object is an object having a business management right in the identity authentication place, the first object terminal is notified to call a collection device to collect second object biological information of the second object through the collection device.
[0350] Optionally, the second object biological information has a plurality of second object biological information, and the identity confirmation unit 1303 is specifically configured to:
[0351] extracting second object biological information features of the second object based on second object biological information in the plurality of second object biological information meeting preset quality requirements;
[0352] taking candidate biological information in the candidate biological information set having a feature similarity higher than a preset threshold with the second object biological information features as hit candidate biological information;
[0353] taking account information associated with the hit candidate biological information as identity information of the second object;
[0354] The account information of each candidate object in the candidate biological information set is bound when the corresponding object opens a biological recognition verification function.
[0355] Based on the same inventive concept, the embodiments of the present application also provide another identity recognition device. As shown in FIG. 14, it is a structural schematic diagram of an identity recognition device 1400, which can include:
[0356] The response unit 1401 is configured to collect second object biological information of a second object in response to a verification operation triggered by a first object, wherein the first object is an object having a business management right in an identity authentication place;
[0357] The sending unit 1402 is configured to send a place identifier of the identity authentication place and the second object biological information to a verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the place identifier, and determines identity information of the second object based on hit candidate biological information when the second object biological information hits the candidate biological information set. The candidate biological information set contains candidate biological information of at least one candidate object, and each candidate object is an object that has handled a business after successfully verifying the identity by biological recognition in the identity authentication place;
[0358] The identity confirmation unit 1403 is configured to confirm the identity of the second object according to the identity information after receiving the identity information returned by the verification server.
[0359] Optionally, the sending unit 1402 is specifically configured to:
[0360] determine a collection time of collecting the second object biological information in the identity verification site;
[0361] send the site identifier, the second object biological information, and the collection time to a verification server through the verification instruction, so that the verification server determines the candidate biological information set according to the site identifier and the collection time; correspondingly, each candidate object is an object that has handled a business in the identity verification site after successfully verifying the identity by using biological recognition in a time interval to which the collection time belongs.
[0362] Optionally, if the identity verification site includes a plurality of sub-sites, the sending unit 1402 is specifically configured to:
[0363] determine an identity verification sub-site in which the first object collects the second object biological information in the plurality of sub-sites;
[0364] send the site identifier, a sub-site identifier of the identity verification sub-site, and the second object biological information to the verification server through the verification instruction, so that the verification server determines a candidate biological information set according to the site identifier and the sub-site identifier; wherein each candidate object is an object that has handled a business in the identity verification sub-site after successfully verifying the identity by using biological recognition.
[0365] Optionally, the response unit 1401 is further configured to:
[0366] in response to a first jump operation triggered by the first object before collecting the second object biological information of the second object in response to a verification operation triggered by the first object, jump, by a business sub-application associated with the first object, to a verification sub-application;
[0367] then the response unit 1401 is specifically configured to:
[0368] respond to the verification operation triggered by the first object through the verification sub-application, send account information of the first object to the verification server through an authentication instruction, so as to authenticate the first object through the verification server;
[0369] if it is determined through authentication that the first object is an object having a business management right in the identity verification site, call a collection device, and collect the second object biological information of the second object through the collection device.
[0370] Optionally, the identity information is account information bound when the second object opens the biometric verification function, and the service includes a storage service, and the identity confirmation unit 1403 is specifically configured to:
[0371] In response to a second jump operation, the verification sub-application jumps to the service sub-application associated with the first object;
[0372] Through the service sub-application, the opening operation triggered by the first object is responded to, and through the remote control service, the target storage cabinet is opened in combination with the identity information; the target storage cabinet is the storage cabinet that the second object uses most recently when performing the storage service through biometric verification in the identity verification site;
[0373] According to the items in the target storage cabinet, the identity information of the second object is determined.
[0374] Since the present application sets a super administrator for each site, such as the first object having a service management right in the identity verification site, and opens the biometric verification capability for such object, in some special scenarios (such as emergency), the first object can collect the biological information of the second object (i.e., the second object biological information) through the first object terminal logged in by the first object, so as to quickly realize identity verification and efficient response in emergency, and only the first object with the right can perform the key operation in the emergency, which improves the safety management efficiency and enhances the site security.
[0375] Further, by sending the site identifier and the verification instruction of the identity verification site to the verification server, the verification server can determine the candidate biological information set matched with the identity verification site based on the verification instruction, the candidate biological information set is only related to the identity verification site and contains only the candidate biological information of the object that has handled the service in the identity verification site, which is a small set for auxiliary identification, rather than a large set (containing the biological information of all objects that have opened the biometric verification function) for general identification. Based on the candidate biological information set, the identity of the second object can be quickly identified, the identification difficulty is reduced, and the identity confirmation efficiency is improved.
[0376] On this basis, after the verification server determines the identity information of the second object based on the candidate biological information set, the identity information can be returned to the first object terminal, and the first object terminal can confirm the actual identity of the second object based on the identity information, so as to quickly confirm the identity of the object in the medium replacement scenario.
[0377] For the convenience of description, the above parts are divided into modules (or units) according to functions and are described respectively. Of course, the functions of the modules (or units) can be realized in the same or multiple software or hardware in the implementation of the present application.
[0378] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an integral module or unit that contains the functions of the module or unit.
[0379] After introducing the identity recognition method and device of the example embodiments of the present application, next, the electronic device according to another example embodiment of the present application is introduced.
[0380] Those skilled in the art can understand that each aspect of the present application can be implemented as a system, a method or a program product. Therefore, each aspect of the present application can be specifically implemented as follows: a complete hardware embodiment, a complete software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software, which can be collectively referred to as "circuitry", "module" or "system".
[0381] Based on the same inventive concept as the above method embodiments, the electronic device is also provided in the embodiments of the present application. In one embodiment, the electronic device can be a server, such as the verification server shown in FIG. 1. In this embodiment, the structure of the electronic device can be as shown in FIG. 15, including a memory 1501, a communication module 1503 and one or more processors 1502.
[0382] The memory 1501 is used to store the computer program executed by the processor 1502. The memory 1501 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and programs required for running instant messaging functions, etc.; the data storage area can store various instant messaging information and operation instruction sets, etc.
[0383] The memory 1501 can be a volatile memory, such as a random-access memory (RAM); the memory 1501 can also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or the memory 1501 can be any other medium capable of carrying or storing desired computer programs in the form of instructions or data structures and capable of being accessed by a computer, but not limited to this. The memory 1501 can be a combination of the above memories.
[0384] The processor 1502 can include one or more central processing units (CPUs) or digital processing units, etc. The processor 1502 is used to implement the above identity recognition method when calling the computer program stored in the memory 1501.
[0385] The communication module 1503 is used to communicate with terminals and other servers.
[0386] The specific connection medium between the above memory 1501, the communication module 1503, and the processor 1502 is not limited in the embodiments of the present application. In FIG. 15, the memory 1501 and the processor 1502 are connected through the bus 1504, which is described by a thick line in FIG. 15. The connection mode between other components is only schematically described, and is not limited. The bus 1504 can be divided into an address bus, a data bus, a control bus, etc. For the convenience of description, only one thick line is described in FIG. 15, but only one bus or one type of bus is not described.
[0387] The memory 1501 stores a computer storage medium, and the computer storage medium stores computer executable instructions. The computer executable instructions are used to implement the identity recognition method of the embodiments of the present application. The processor 1502 is used to execute the above identity recognition method, as shown in FIG. 9.
[0388] In another embodiment, the electronic device can also be other electronic devices, such as the first object terminal, the verification terminal, etc. (hereinafter referred to as terminal) shown in FIG. 1. In this embodiment, the structure of the electronic device can be as shown in FIG. 16, which includes a communication component 1610, a memory 1620, a display unit 1630, a camera 1640, a sensor 1650, an audio circuit 1660, a Bluetooth module 1670, a processor 1680, and the like.
[0389] The communication component 1610 is configured to communicate with a server. In some embodiments, a wireless fidelity (WiFi) module can be included, which belongs to a short-range wireless transmission technology. The electronic device can help the user to send and receive information through the WiFi module.
[0390] The memory 1620 can be used to store software programs and data. The processor 1680 executes various functions and data processing of the terminal 110 by running the software programs or data stored in the memory 1620. The memory 1620 can include a high-speed random access memory, and can further include a non-volatile memory such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device. The memory 1620 stores an operating system that enables the terminal to operate. In this application, the memory 1620 can store an operating system and various application programs, and can also store a computer program for implementing the identity recognition method of the embodiments of the application.
[0391] The display unit 1630 can also be used to display information input by the user or information provided to the user, as well as the graphical user interface (GUI) of various menus of the terminal 110. Specifically, the display unit 1630 can include a display screen 1632 arranged on the front of the terminal. The display screen 1632 can be configured in the form of a liquid crystal display, a light-emitting diode, etc. The display unit 1630 can be used to display the display interface in the embodiments of the application, etc.
[0392] The display unit 1630 can also be used to receive input digital or character information, and generate signal input related to user settings and function control of the terminal 110. Specifically, the display unit 1630 can include a touch screen 1631 arranged on the front of the terminal 110, which can collect touch operations of the user thereon or therearound, such as clicking buttons, dragging scroll boxes, etc.
[0393] The touch screen 1631 can be overlaid on the display screen 1632, or the touch screen 1631 and the display screen 1632 can be integrated to realize the input and output functions of the terminal. After integration, it can be referred to as a touch display screen. In this application, the display unit 1630 can display application programs and corresponding operation steps.
[0394] The camera 1640 can be used to capture still images, which a user can post through an application using the images taken by the camera 1640. The camera 1640 can be one or more. An object generates an optical image through a lens and projects the optical image onto a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, which is then transmitted to the processor 1680 to convert into a digital image signal.
[0395] The terminal can also include at least one sensor 1650, such as an acceleration sensor 1651, a distance sensor 1652, a fingerprint sensor 1653, a temperature sensor 1654. The terminal can also be configured with a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, a light sensor, a motion sensor, and other sensors.
[0396] The audio circuit 1660, the speaker 1661, and the microphone 1662 can provide an audio interface between the user and the terminal 110. The audio circuit 1660 can convert the received audio data into an electrical signal and transmit it to the speaker 1661, which converts the electrical signal into an audible signal and outputs it. The terminal can also be configured with a volume button for adjusting the volume of the audible signal. On the other hand, the microphone 1662 converts the collected sound signal into an electrical signal, which is received by the audio circuit 1660 and converted into audio data, which is then output to the communication component 1610 for transmission to, for example, another terminal, or to the memory 1620 for further processing.
[0397] The Bluetooth module 1670 is used to interact with other Bluetooth devices with Bluetooth modules through Bluetooth protocols. For example, the terminal can establish a Bluetooth connection with a wearable electronic device (e.g., a smart watch) that also has a Bluetooth module through the Bluetooth module 1670, thereby interacting with data.
[0398] The processor 1680 is the control center of the terminal, connects various parts of the terminal through various interfaces and lines, and performs various functions of the terminal and processes data by running or executing software programs stored in the memory 1620 and calling data stored in the memory 1620. In some embodiments, the processor 1680 can include one or more processing units; the processor 1680 can also integrate an application processor and a baseband processor, wherein the application processor mainly processes the operating system, user interface, and application program, and the baseband processor mainly processes wireless communication. It can be understood that the above-mentioned baseband processor can also not be integrated into the processor 1680. In the present application, the processor 1680 can run the operating system, the application program, the user interface display and the touch response, and the identity recognition method of the embodiment of the present application. In addition, the processor 1680 is coupled with the display unit 1630.
[0399] In some possible implementation manners, various aspects of the identity recognition method provided by the present application can also be implemented in the form of a program product, which includes a computer program for causing an electronic device to perform the steps of the identity recognition method according to various exemplary embodiments of the present application described above in the specification when the program product is run on the electronic device, for example, the electronic device can perform the steps as shown in FIG. 3 or FIG. 9.
[0400] The program product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium may, for example, be but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples (non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0401] The program product of the embodiment of the present application can adopt a portable compact disc read-only memory (CD-ROM) and include a computer program, and can be run on an electronic device. However, the program product of the present application is not limited to this, and in this document, the readable storage medium can be any tangible medium containing or storing a program that can be used or combined with a command execution system, device or apparatus.
[0402] A readable signal medium can include a computer program readable computer program code, data signals, or any other medium of the like, which is based, at least in part, on transmission of the computer program code.
[0403] The computer program code product can be transmitted as a carrier wave, by a computer program product, over a channel. Based on these teachings, a person of ordinary skill in the art will appreciate that equivalent circuits, structures, and methods inherently can perform the same functions, and are, therefore, equivalent within the scope and spirit of the claimed application.
[0404] A computer program used by or in connection with the embodiments disclosed herein can be written in any suitable programming language by a programmer based on the teachings of the disclosure. Suitable programming languages include, for example, Java, C++, and / or C.
[0405] It should be noted that, although the above detailed description refers to several units or sub-units of the apparatus, such a division is merely exemplary and not mandatory. Indeed, according to an embodiment of the application, the features and functionalities of two or more units described above can be embodied in one unit. Conversely, the features and functionalities of one unit described above can be further divided into units embodied by several units.
[0406] Further, although the operations of the method(s) herein can be described in a particular, sequential order, this order is not meant to be a limitation and is not intended to imply that the described operations must be performed in the order described. Further, one or more of the described operations can be performed concurrently, in parallel, or in any order that is practicable. In addition, it is within the scope of the present application that one or more of the operations described can be combined into a single operation where appropriate or practicable, or further separated into additional operations where appropriate or practicable.
[0407] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, a system or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable code.
[0408] The present application is described in reference to the flow diagrams and / or block diagrams of the methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing system or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks.
[0409] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flow diagrams and / or block diagrams block or blocks.
[0410] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks.
[0411] To sum up, the present application provides an identity recognition method and device, electronic equipment, computer readable storage medium and computer program product. The verification server receives the verification instruction sent by the first object terminal, which contains the place identifier of the identity verification place and the second object biological information. In the traditional identity recognition scene, if there is no place identifier limit, it may be necessary to search in a huge general biological information set, which not only consumes a lot of time and computing resources, but also is easy to cause misidentification due to too large data volume. The present application determines the candidate biological information set of the candidate object who successfully verifies the identity by biological recognition in the place through the place identifier, accurately reduces the search range to the relevant biological information of the specific place, and avoids invalid search in irrelevant data. If the second object biological information hits the set, the identity information of the second object is determined based on the hit candidate biological information and returned to the first object terminal. This method greatly improves the efficiency of identity recognition, enables quick response in emergency situations, and also enhances the accuracy of identity recognition, because the data in the candidate biological information set are all valid information related to the place, reducing interference factors and improving the response ability of the system to handle emergency situations.
[0412] Further, when the verification instruction further includes the collection time corresponding to the second object biological information, the verification server determines the time interval to which the collection time belongs, and screens the candidate biological information set matched with the place identifier and the time interval from the at least one place biological information set. In some places with large flow of people, the personnel flow situation in the same place is quite different at different times. If the time factor is not considered, the candidate biological information set may contain a lot of historical data irrelevant to the current situation. After introducing the time factor, the range of the candidate biological information set is further reduced, so that the identity recognition is more focused on the personnel appearing in the place within a specific time. In this way, unnecessary data processing can be reduced, the processing efficiency of the system is improved, the identity of the second object can be determined within a specific time range more quickly, and time waste and resource consumption caused by processing a large amount of irrelevant data are avoided.
[0413] On the basis of the above, if the candidate biological information includes the standard biological information uploaded by the object when opening the biological recognition verification function, the verification server stores the standard biological information uploaded by each object when opening the function before determining the candidate biological information set, and constructs a biological information set for each site. The standard biological information of the object that successfully verifies the identity by using biological recognition to handle business in the site within a specified time interval is added to the corresponding set. With the passage of time, biological information may change due to various factors such as environmental changes, equipment accuracy, etc. If only the currently collected biological information is used for identification, it may cause identification errors due to the instability of the information. Storing standard biological information and constructing a biological information set for the site can update and maintain biological information data in a timely manner, ensuring the timeliness of the biological information. Comparing the currently collected biological information with the standard biological information each time of identification can avoid identification errors caused by outdated data, thereby improving the accuracy and reliability of identity verification.
[0414] If the identity verification site contains multiple sub-sites, and the first object collects the second object's biological information at the identity verification sub-site, the verification instruction contains the sub-site identifier of the identity verification sub-site, and the verification server first filters out multiple reference biological information sets matching the site identifier from the multiple site biological information sets, and then filters out the candidate biological information set matching the sub-site identifier from these reference biological information sets. In large sites, personnel activities in different sub-sites have certain independence and professionalism. If only the site identifier is used for filtering, the candidate biological information set may still contain a large amount of irrelevant information. After introducing the sub-site identifier, the filtering process is further refined, and the biological information related to the second object can be more accurately located. Through this hierarchical filtering mechanism, the interference of irrelevant data is reduced, the efficiency and accuracy of identity recognition are improved, and the identity of the second object can be quickly and accurately determined within a specific sub-site.
[0415] Before determining the candidate biological information set, the verification server receives the authentication instruction sent by the first object terminal, authenticates the first object according to the account information of the first object in the authentication instruction, and notifies the first object terminal to collect the biological information of the second object by calling the collection device if the authentication is passed. In the identity recognition system, security is crucial. If anyone can trigger the identity recognition process at will, it may lead to information leakage and abuse. The authentication process ensures that only the first object with business management authority can trigger the identity recognition process, and the rights of the first object are strictly verified by querying the mapping relationship between the site identifier and the super administrator account information stored in advance. This can enhance the security of the system, prevent unauthorized operations, protect the privacy and information security of the object, and avoid system chaos and data leakage caused by illegal operations.
[0416] When there are multiple second object biological information, the verification server extracts the biological information features of the second object based on the second object biological information whose information quality meets the preset quality requirement among the multiple second object biological information, takes the candidate biological information in the candidate biological information set which has a high similarity with the features as the hit candidate biological information, and takes the account information associated with the hit candidate biological information as the identity information of the second object. In the actual biological information collection process, due to the influence of environment, equipment and other factors, the quality of the collected biological information may be uneven. If all the collected biological information is directly used for identification, it may cause identification errors due to the interference of low-quality information. By screening high-quality biological information for feature matching, the interference of low-quality information is excluded, and the accuracy and reliability of identity recognition are improved. At the same time, setting a preset threshold can further ensure the accuracy of matching, reduce the probability of misidentification, and make the identity recognition more accurate.
[0417] The verification server returns the identity information to the first object terminal through the serial port, and realizes secure communication between the two ends by selecting a suitable serial communication protocol (such as RS-485), using an encryption algorithm (such as a symmetric encryption algorithm), adding data integrity check and timestamp, etc. In the process of data transmission, there may be security risks such as data interception, tampering or replay. Selecting a suitable serial communication protocol can ensure the stability and efficiency of data transmission, encryption algorithm can encrypt data to ensure that even if the data is intercepted, it cannot be easily read, data integrity check can detect errors in the data transmission process, and timestamp can prevent replay attacks. These technical solutions ensure the integrity, confidentiality and availability of data during transmission, prevent identity information from being leaked or tampered with during transmission, and ensure the security of information.
[0418] The first object terminal collects the second object biological information of the second object in response to the verification operation triggered by the first object, sends the place identifier of the identity verification place and the second object biological information to the verification server through a verification instruction, and confirms the identity of the second object according to the identity information returned by the verification server after receiving the identity information. In the media replacement scenario, the traditional identity recognition method may not meet the needs of quickly confirming the identity of the object in an emergency. This multi-end interaction method enables the identity recognition process to be quickly started in an emergency, and the first object terminal can collect biological information and send it to the verification server in time, the verification server returns the identity information after processing, and the first object terminal confirms again. Through this way, the response speed is improved, and through the professional processing of the verification server, the accuracy of identity recognition is ensured, ensuring that the identity of the object can be quickly confirmed in the case of no traditional media such as wristbands.
[0419] Further, the first object terminal determines a collection time of collecting the second object biological information in the identity verification site, and sends the site identifier, the second object biological information and the collection time to the verification server through the verification instruction, so that the server determines a candidate biological information set according to the information. In some sites, the personnel flow is frequent, and the personnel situation at different times may differ greatly. The introduction of the collection time can make the verification server more accurately filter out the relevant candidate biological information, and according to the time interval to which the collection time belongs, only search in the site biological information set in this time period, avoiding searching in irrelevant historical data. In this way, unnecessary search operations can be reduced, the efficiency and accuracy of identity recognition can be improved, and the system can quickly determine the identity of the second object within a specific time range.
[0420] If the identity verification site includes multiple sub-sites, the first object terminal determines the identity verification sub-site of the first object collecting the second object biological information, and sends the site identifier, the sub-site identifier of the identity verification sub-site and the second object biological information to the verification server through the verification instruction. In large sites, the functions and personnel usage of different sub-sites are different. If the sub-site factor is not considered, a large amount of irrelevant biological information may be searched. By providing the sub-site identifier, the verification server can further narrow the range of the candidate biological information set, so that it can more accurately locate the biological information related to the second object. This way reduces the interference of irrelevant data, improves the accuracy of identity recognition, and ensures that the identity of the second object can be quickly and accurately determined within a specific sub-site.
[0421] Before collecting the second object biological information, the first object terminal responds to the first jump operation, and jumps from the business sub-application associated with the first object to the verification sub-application. The verification sub-application responds to the verification operation triggered by the first object, and sends the account information of the first object to the verification server through the authentication instruction for authentication. If the authentication is passed, the collection device collects the biological information of the second object. The sub-application jump mode centrally manages the biological recognition verification service, modularizes different functions, so that the super administrator can manage permissions and emergency response on a unified platform. This way simplifies the background operation, improves the management efficiency, and also facilitates the maintenance and upgrade of the system. The authentication process ensures that only authorized first objects can perform identity recognition operations, and by verifying the account information of the first object, unauthorized personnel are prevented from entering the identity recognition process, enhancing the security of the system.
[0422] When the identity information is the account information bound by the second object opening the biometric verification function, and the business includes the storage business, the first object terminal responds to the second jump operation by jumping from the verification sub-application to the business sub-application associated with the first object, and opens the target storage cabinet in combination with the identity information through the business sub-application in response to the opening operation triggered by the first object, and determines the identity information of the second object according to the items in the target storage cabinet. In an emergency, only biometric information recognition may not be able to completely confirm the identity of the second object, while the items in the storage cabinet often have personal characteristics and can be used as a basis for auxiliary verification. The one-key cabinet opening function provides an additional verification means for identity recognition, which can more accurately confirm the identity of the second object in an emergency. At the same time, opening the cabinet can also help the first object quickly find some other important information of the second object, such as the contact information of the emergency contact person, medical information, etc., thereby improving the efficiency of rescue or response to emergency situations.
[0423] Centralized management of biometric verification services through sub-application jumping: Through the jumping between sub-applications, the biometric verification service can be centrally managed. The super administrator can manage permissions and emergency responses on a unified platform, and different sub-applications are responsible for different functional modules, such as business sub-applications providing specific services or functions, and verification sub-applications specifically performing biometric verification. This centralized management simplifies the background operation, reduces the complexity of the system, and improves the management efficiency. The super administrator can more conveniently configure and maintain the system, and at the same time, it is convenient for users to switch between different functions, improving the user experience.
[0424] Multiple ways to trigger verification operations: In addition to sub-application jumping, two-dimensional code scanning, voice commands, physical buttons or hardware devices can also be used to trigger verification operations. The two-dimensional code scanning method is simple and fast, suitable for quick response in emergency situations, and the first object only needs to scan the two-dimensional code in a specific position using a mobile terminal to quickly enter the biometric verification interface. The voice command method is particularly suitable for situations where both hands are inconvenient or quick response is required, and only a simple voice command is needed to activate the identity verification process, increasing the flexibility of the operation. The physical button or hardware device method is particularly suitable for situations that require immediate action, which can minimize response time. These diversified triggering methods improve the efficiency and security of the identity verification process, meet the actual needs of different scenarios, and ensure that identity verification can be quickly and accurately performed in emergency situations.
[0425] Setting deletion policy for the place biological information set: In order to protect the privacy of the object, optimize the storage space and improve the system performance, set the deletion policy for the place biological information set, such as periodic deletion or irregular deletion. With the passage of time, a large amount of historical data will accumulate in the place biological information set, which not only occupies storage space, but also may exist the risk of data leakage. Periodically or irregularly deleting a part of historical data can reduce the potential risk of data leakage and ensure that only the latest and relevant data is retained. At the same time, the released storage space can improve the response speed and performance of the system, so that the system can more efficiently process new biological information and perform identity recognition operations.
[0426] Although the preferred embodiments of the present application have been described, those skilled in the art who are familiar with the basic inventive concept can make additional changes and modifications to the embodiments. Therefore, the appended claims are intended to include the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0427] The technical features of the above embodiments can be combined in any way. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.
[0428] The above embodiments only express several implementation manners of the present application, and the description is specific and detailed, but it should not be understood as a limitation on the scope of the patent. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of the patent of the present application should be subject to the appended claims.
Claims
An identity recognition method is executed by a verification server, and the method comprises: receiving a verification instruction sent by a first object terminal; wherein the verification instruction comprises a site identifier of an identity verification site and second object biological information; the second object biological information is biological information of a second object collected by the first object terminal in response to a verification operation triggered by a first object; the first object is an object having a business management right in the identity verification site; determining a candidate biological information set according to the site identifier; the candidate biological information set comprises candidate biological information of at least one candidate object; each candidate object is an object that has handled a business in the identity verification site after successfully verifying an identity by using biological recognition; when the second object biological information hits the candidate biological information set, determining identity information of the second object based on the hit candidate biological information, and returning the identity information to the first object terminal. The method of claim 1, wherein the verification instruction further comprises a collection time corresponding to the second object biological information, and the determining of the candidate biological information set according to the site identifier comprises: determining a time interval to which the collection time belongs; screening a candidate biological information set matching the site identifier and the time interval from at least one site biological information set; wherein each candidate object is an object that has handled a business in the identity verification site after successfully verifying an identity by using biological recognition within the time interval. The method of claim 2, wherein the candidate biological information comprises: Standard biological information uploaded by an object when the object opens a biological recognition verification function, and before the determining of the candidate biological information set according to the site identifier, the method further comprises: storing the standard biological information uploaded by each object when the object opens the biological recognition verification function, and constructing the at least one site biological information set by the following method: for each site, if there is an object that has handled a business in the site after successfully verifying an identity by using biological recognition within the time interval, adding the standard biological information of the object to a site biological information set corresponding to the site. The method of any one of claims 1-3, wherein if the identity verification site comprises a plurality of sub-sites, and the first object collects the second object biological information in an identity verification sub-site of the plurality of sub-sites through the first object terminal, the verification instruction further comprises a sub-site identifier of the identity verification sub-site; the determining of the candidate biological information set according to the site identifier comprises: screening a plurality of reference biological information sets matching the site identifier from a plurality of site biological information sets; screening a candidate biological information set matching the sub-site identifier from the plurality of reference biological information sets; wherein each candidate object is an object that has handled a business in the identity verification sub-site after successfully verifying an identity by using biological recognition. The method of any one of claims 1-4, before the determining of the candidate biological information set according to the site identifier, the method further comprises: receiving an authentication instruction sent by the first object terminal; The authentication instruction is sent by the first object terminal in response to a verification operation triggered by the first object; According to the account information of the first object in the authentication instruction, the first object is authenticated; If it is determined through authentication that the first object is an object with business management authority in the identity verification place, the first object terminal is notified to call a collection device to collect second object biological information of the second object through the collection device. The method of any one of claims 1-5, wherein the second object biological information has a plurality of second object biological information, and when the second object biological information hits the candidate biological information set, the identity information of the second object is determined based on the hit candidate biological information, comprising: Based on the second object biological information in the plurality of second object biological information meeting the preset quality requirement, the second object biological information feature of the second object is extracted; The candidate biological information in the candidate biological information set, which has a feature similarity higher than a preset threshold with the second object biological information feature, is taken as the hit candidate biological information; The account information associated with the hit candidate biological information is taken as the identity information of the second object; The account information of each candidate object in the candidate biological information set is bound when the biological recognition verification function of the corresponding object is opened. The method of any one of claims 1-6, wherein the identity information is returned to the first object terminal, comprising: The identity information is returned to the first object terminal through a serial port. An identity recognition method is executed by a first object terminal, the method comprising: In response to a verification operation triggered by a first object, second object biological information of a second object is collected; wherein the first object is an object with business management authority in an identity verification place; The place identifier of the identity verification place and the second object biological information are sent to a verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the place identifier, and when the second object biological information hits the candidate biological information set, the identity information of the second object is determined based on the hit candidate biological information; the candidate biological information set contains candidate biological information of at least one candidate object, and each candidate object is an object that has handled a business after successfully verifying the identity by biological recognition in the identity verification place; and After receiving the identity information returned by the verification server, the identity of the second object is confirmed according to the identity information. The method of claim 8, wherein the place identifier of the identity verification place and the second object biological information are sent to the verification server through the verification instruction, so that the verification server determines a candidate biological information set according to the place identifier, comprising: Determine the collection time of the second object biological information in the identity verification place; The place identifier, the second object biological information, and the collection time are sent to a verification server through the verification instruction, so that the verification server determines the candidate biological information set according to the place identifier and the collection time; correspondingly, each candidate object is an object that has handled a business after successfully verifying an identity in the identity verification place within a time interval to which the collection time belongs. The method of claim 8 or 9, if the identity verification place includes a plurality of sub-places, the sending, by the verification instruction, the place identifier of the identity verification place and the second object biological information to the verification server to cause the verification server to determine a candidate biological information set according to the place identifier, comprises: determining an identity verification sub-place in the plurality of sub-places where the first object collects the second object biological information; sending, by the verification instruction, the place identifier, a sub-place identifier of the identity verification sub-place, and the second object biological information to the verification server to cause the verification server to determine a candidate biological information set according to the place identifier and the sub-place identifier; wherein each candidate object is an object that has handled a business after successfully verifying an identity in the identity verification sub-place. The method of any one of claims 8-10, before the collecting, by the first object, the second object biological information of the second object in response to the verification operation triggered by the first object, further comprising: in response to a first jump operation, jumping, by a business sub-application associated with the first object, to a verification sub-application; the collecting, by the first object, the second object biological information of the second object in response to the verification operation triggered by the first object, comprises: sending, by the verification sub-application, account information of the first object to the verification server through an authentication instruction in response to the verification operation triggered by the first object, to authenticate the first object by the verification server; if the first object is determined to be an object having a business management right in the identity verification place through the authentication, calling a collection device to collect the second object biological information of the second object by the collection device. The method of any one of claims 8-11, the identity information is account information bound by the second object when opening a biological recognition verification function, and the business includes a storage business; the determining the identity of the second object according to the identity information, comprises: in response to a second jump operation, jumping, by the verification sub-application, to a business sub-application associated with the first object; opening, by a remote control service, a target storage cabinet in combination with the identity information in response to an opening operation triggered by the first object through the business sub-application; the target storage cabinet is a storage cabinet that is newly used by the second object when performing a storage business through biological recognition verification in the identity verification place; determining the identity information of the second object according to the objects in the target storage cabinet. An identity recognition device, the device comprising: A receiving unit is configured to receive a verification instruction sent by a first object terminal, wherein the verification instruction comprises a site identifier of an identity verification site and second object biological information; the second object biological information is biological information of a second object collected by the first object terminal in response to a verification operation triggered by a first object; the first object is an object having a business management right in the identity verification site; A processing unit is configured to determine a candidate biological information set according to the site identifier; the candidate biological information set comprises candidate biological information of at least one candidate object; each candidate object is an object that has handled a business after successfully verifying an identity by using biological recognition in the identity verification site; and An identity confirmation unit is configured to, when the second object biological information hits the candidate biological information set, determine identity information of the second object based on the hit candidate biological information, and return the identity information to the first object terminal. An identity recognition device, the device comprising: A response unit is configured to collect second object biological information of a second object in response to a verification operation triggered by a first object; wherein the first object is an object having a business management right in an identity verification site; A sending unit is configured to send a site identifier of the identity verification site and the second object biological information to a verification server through a verification instruction, so that the verification server determines a candidate biological information set according to the site identifier, and when the second object biological information hits the candidate biological information set, determines identity information of the second object based on the hit candidate biological information; the candidate biological information set comprises candidate biological information of at least one candidate object; each candidate object is an object that has handled a business after successfully verifying an identity by using biological recognition in the identity verification site; and An identity confirmation unit is configured to, after receiving the identity information returned by the verification server, confirm the identity of the second object according to the identity information. An electronic device comprising a processor and a memory, wherein, The memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the method in any one of claims 1-12. A computer readable storage medium comprises a computer program, and when the computer program runs on an electronic device, the computer program is used to make the electronic device execute the steps of the method in any one of claims 1-12. A computer program product comprises a computer program stored in a computer readable storage medium; when a processor of an electronic device reads the computer program from the computer readable storage medium, the processor executes the computer program, so that the electronic device executes the steps of the method in any one of claims 1-12.
Citation Information
Patent Citations
User information management and biometric authentication system suitable for cascade deployment
CN111062016A
Child lock management module and device
CN115935316A
Identity recognition method and device, computer equipment and storage medium
CN117635974A
Identity recognition system and method based on intelligent physical characteristics collecting and processing terminal
CN1951326A
Fixed-point authorization identity recognition method and apparatus, and server
US20220058250A1