WO2017012238A1 - 身份认证方法和装置 - Google Patents

身份认证方法和装置 Download PDF

Info

Publication number
WO2017012238A1
WO2017012238A1 PCT/CN2015/096343 CN2015096343W WO2017012238A1 WO 2017012238 A1 WO2017012238 A1 WO 2017012238A1 CN 2015096343 W CN2015096343 W CN 2015096343W WO 2017012238 A1 WO2017012238 A1 WO 2017012238A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
user
living body
feature information
password
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/096343
Other languages
English (en)
French (fr)
Inventor
石爽
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Baidu Online Network Technology Beijing Co Ltd
Original Assignee
Baidu Online Network Technology Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Baidu Online Network Technology Beijing Co Ltd filed Critical Baidu Online Network Technology Beijing Co Ltd
Publication of WO2017012238A1 publication Critical patent/WO2017012238A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3231Biological data, e.g. fingerprint, voice or retina

Definitions

  • the present invention relates to the field of security authentication technologies, and in particular, to an identity authentication method and apparatus.
  • the commonly used security authentication method is that the user enters a password and authenticates the password.
  • the password is difficult to remember and the input efficiency is low, the password is easy to be stolen, and the security is low.
  • the present invention aims to solve at least one of the technical problems in the related art to some extent.
  • an object of the present invention is to provide an identity authentication method which can improve input efficiency in identity authentication, reduce memory cost, and improve security.
  • Another object of the present invention is to provide an identity authentication apparatus.
  • the identity authentication method of the first aspect of the present invention includes: collecting living feature information of a user to be authenticated; and transmitting the living feature information to a server, so that the server is configured according to the living body.
  • the feature information and the stored biometric password corresponding to the user are obtained, and the biometric password is obtained based on the living feature information of the user collected in advance.
  • the identity authentication method can collect the living body feature information, can eliminate the need for human memory passwords, and does not need human input, can improve the input efficiency during identity authentication, reduce the memory cost, and the collection is
  • the living body feature information and the living body feature information can be changed over time, and the security can be improved with respect to the fixed password mode.
  • an identity authentication apparatus includes: an acquisition module, configured to collect living feature information of a user to be authenticated; and a sending module, configured to send the living body feature information to a server, The server is authenticated according to the living body feature information and the stored living body password corresponding to the user, and the living body password is obtained according to the living feature information of the user collected in advance.
  • the identity authentication device provided by the embodiment of the second aspect of the present invention may not need to collect the feature information of the living body.
  • the artificial memory password does not require human input, which can improve the input efficiency during identity authentication and reduce the memory cost.
  • the collected live feature information, the living feature information can be changed with time, and the security can be improved relative to the fixed password mode. degree.
  • An embodiment of the present invention further provides an electronic device, including: one or more processors; a memory; one or more programs, the one or more programs being stored in the memory when the one or more When the processor is executed: the method according to any of the first aspect of the invention is performed.
  • Embodiments of the present invention also provide a non-volatile computer storage medium having one or more modules stored when the one or more modules are executed: performing the first aspect of the present invention The method of any of the preceding claims.
  • FIG. 1 is a schematic flow chart of an identity authentication method according to an embodiment of the present invention.
  • FIG. 2 is a schematic diagram of an identity authentication system in an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of an identity authentication method according to another embodiment of the present invention.
  • FIG. 4 is a schematic flowchart of an identity authentication method according to another embodiment of the present invention.
  • FIG. 5 is a schematic structural diagram of an identity authentication apparatus according to another embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of an identity authentication apparatus according to another embodiment of the present invention.
  • FIG. 1 is a schematic flowchart of an identity authentication method according to an embodiment of the present invention, where the method includes:
  • S11 Collect living feature information of the user to be authenticated.
  • the vital feature information refers to information that can be changed over time.
  • the living body feature information may include at least one of the following items: face information, action information, voiceprint information.
  • the face information includes, for example, facial features, hairstyles, facial expressions, and the like.
  • the motion information includes, for example, muscle changes of the face, limb movements, and the like.
  • the voiceprint information includes, for example, an audio tone color feature in a user's voice, a pronunciation feature of a character, and the like.
  • the camera information on the user equipment can be used to collect facial information and motion information, and the voiceprint information is collected by using a microphone on the user equipment.
  • the living body feature information is collected, and the living body feature information can be changed with time. For example, based on the intrinsic and extrinsic characteristics of the time axis, intrinsic variations such as changes in the face or form, externally varying features such as hairstyles, apparel, jewelry, and the like.
  • the living feature information may be collected according to the active behavior of the user. For example, when a password is required, the user actively recites a piece of text, and collects voiceprint information, face information, and action information at this time.
  • the living feature information may be that the system displays the prompt information to the user, and the user recites the corresponding text according to the prompt information. For example, if the system displays "I love Beijing” to the user, the user can recite “I love Beijing" and collect the voiceprint information, face information and action information at this time.
  • S12 Send the living body feature information to the server, so that the server performs authentication according to the living body feature information and the stored living body password corresponding to the user, where the living body password is collected according to history in advance.
  • the living characteristics information of the user is obtained.
  • an identification module 21 is provided on a client (such as a user's mobile phone), and the recognition module performs face recognition, motion recognition, and voiceprint recognition, thereby acquiring user face information, motion information, and voiceprint information, and the client.
  • the collected information is sent to the cloud, and the live password database 22 is set in the cloud, and the live password can be stored in the live password database.
  • the live password can be associated with the user identifier during storage.
  • the client sends the user identifier to the cloud when sending the live feature information, and the cloud can obtain and receive according to the received user identifier and the stored association information.
  • the user ID corresponds to the live password.
  • the cloud can compare the received biometric feature information with the found live password to compare the two to obtain the authentication result.
  • the living body password is obtained by training based on the previously collected face information, action information, and voiceprint information.
  • the face information, the action information and the voiceprint information can be separately trained to obtain a corresponding model, and in the authentication, respectively, the received face information, the motion information and the voiceprint information are compared, in all three When matching, it is determined that the authentication is successful, otherwise the authentication fails.
  • the face information, the motion information and the voiceprint information are trained, the corresponding model is obtained, and whether the matching of a message with its corresponding model can be implemented in an existing manner.
  • the server when the server performs the authentication to obtain the authentication result, the authentication result may be sent to the client, and the client receives the authentication result sent by the server, and displays the authentication result to the user.
  • the authentication result is that the authentication fails, the user's living feature information may be re-acquired for re-authentication.
  • the identity authentication method further includes:
  • S31 Collect the living characteristic information of the user when setting the living password.
  • the collecting the living body feature information of the user when the user sets the living body password includes:
  • the prompt information is displayed to the user, where the prompt information corresponding to different authenticators is the same or different;
  • the system prompts the user to complete a simple specified action, and recites the prompt text.
  • the user can perform corresponding actions and recitation according to the system prompt, and the corresponding face information, action information and voiceprint information are collected through the camera and the microphone sensor.
  • the prompt information may be different according to the authenticator.
  • the user needs to input the password in the merchant A, and also needs to input the password in the merchant B.
  • the merchant A and the merchant B may be set to be the same or different. Live password.
  • the system will record five times of video sounds (including face information, motion information and voiceprint information) to generate a living password.
  • S32 Send the living body feature information to the server, so that the server generates a live password according to the living body feature information.
  • the client sends the five-pass image and sound collected by the client to the server.
  • the server can use the five-pass image and sound as a training sample, and collect machine learning algorithms to generate a living password.
  • the client when the client sends the video and audio to the server, the user can also send the user identifier of the user at the same time.
  • the server After the server generates the living password according to the video voice, the server can store the user identifier and the live password, so that the client can obtain the authentication.
  • the biometric password is updated after being set according to the received new vital feature information.
  • an initial live password can be generated based on the initial video sound. After that, the authentication process will appear. At each authentication, the client will collect new in vivo feature information. On the one hand, the in vivo feature information can be used for authentication. On the other hand, the in vivo feature information can be used as a new sample. The end updates the live password based on the new sample. For example, the new vital characteristics information may include replacement of daily information such as a hairstyle.
  • the identity authentication method further includes:
  • the security guard module 23 can be set in the cloud to perform network-wide warning. For example, after comparing the collected image sound with the stored living password, the authentication result can be obtained if a person's behavior exceeds the preset
  • the danger threshold allows you to post warning messages for that person throughout the network. For example, the person has tried the password input in multiple merchants and the number of input errors exceeds the preset value. Because the living body feature information is collected, the person's face information, action information and voiceprint information can be obtained, so that the whole network can be obtained. The person's face information, action information and voiceprint information are posted to serve as a warning.
  • the living body feature information by collecting the living body feature information, the human memory password can be eliminated, and no human input is needed, the input efficiency during identity authentication can be improved, and the memory cost can be reduced.
  • the living body feature information is collected, and the living body feature information can be Change over time, compared to a fixed password method, can improve security.
  • a living password with a brand sense can be generated to meet the personalized needs.
  • dynamic encryption and self-learning of the living password can be realized.
  • network-wide notification can be achieved to ensure security.
  • FIG. 5 is a schematic structural diagram of an identity authentication apparatus according to another embodiment of the present invention.
  • the apparatus may be located on a client, such as a user's mobile phone.
  • the device 50 includes:
  • the collecting module 51 is configured to collect living feature information of the user to be authenticated
  • the vital feature information refers to information that can be changed over time.
  • the living body feature information may include at least one of the following items: face information, action information, voiceprint information.
  • the face information includes, for example, facial features, hairstyles, facial expressions, and the like.
  • the motion information includes, for example, muscle changes of the face, limb movements, and the like.
  • the voiceprint information includes, for example, an audio tone color feature in a user's voice, a pronunciation feature of a character, and the like.
  • the camera information on the user equipment can be used to collect facial information and motion information, and the voiceprint information is collected by using a microphone on the user equipment.
  • the living body feature information is collected, and the living body feature information can be changed with time. For example, based on the intrinsic and extrinsic characteristics of the time axis, intrinsic variations such as changes in the face or form, externally varying features such as hairstyles, apparel, jewelry, and the like.
  • the living feature information may be collected according to the active behavior of the user. For example, when a password is required, the user actively recites a piece of text, and collects voiceprint information, face information, and action information at this time.
  • the living feature information may be that the system displays the prompt information to the user, and the user recites the corresponding text according to the prompt information. For example, if the system displays "I love Beijing” to the user, the user can recite “I love Beijing" and collect the voiceprint information, face information and action information at this time.
  • the sending module 52 is configured to send the living body feature information to the server, so that the server end authenticates according to the living body feature information and the stored living body password corresponding to the user, where the living body password is based on Historically collected information about the living characteristics of the user.
  • an identification module 21 is set on a client (such as a user's mobile phone), and the recognition module performs facial recognition. No, motion recognition and voiceprint recognition, to obtain the user's face information, motion information and voiceprint information, after the client obtains the information, the collected information is sent to the cloud, and the living password library 22 is set in the cloud, the living password library
  • the live password can be stored.
  • the live password can be associated with the user identifier during storage.
  • the client sends the user identifier to the cloud when sending the live feature information, and the cloud can obtain and receive according to the received user identifier and the stored association information.
  • the user ID corresponds to the live password. After that, the cloud can compare the received biometric feature information with the found live password to compare the two to obtain the authentication result.
  • the living body password is obtained by training based on the previously collected face information, action information, and voiceprint information.
  • the face information, the action information and the voiceprint information can be separately trained to obtain a corresponding model, and in the authentication, respectively, the received face information, the motion information and the voiceprint information are compared, in all three When matching, it is determined that the authentication is successful, otherwise the authentication fails.
  • the face information, the motion information and the voiceprint information are trained, the corresponding model is obtained, and whether the matching of a message with its corresponding model can be implemented in an existing manner.
  • the apparatus 50 further includes:
  • the setting module 53 is configured to: collect the living body feature information of the user when the user sets the living body password; and send the living body feature information to the server, so that the server is configured according to the living body feature information Generate a live password.
  • the setting module 53 is configured to collect the living body feature information of the user when the user sets the living body password, including:
  • the prompt information is displayed to the user, where the prompt information corresponding to different authenticators is the same or different;
  • the system prompts the user to complete a simple specified action, and recites the prompt text.
  • the user can perform corresponding actions and recitation according to the system prompt, and the corresponding face information, action information and voiceprint information are collected through the camera and the microphone sensor.
  • the prompt information may be different according to the authenticator.
  • the user needs to input the password in the merchant A, and also needs to input the password in the merchant B.
  • the merchant A and the merchant B may be set to be the same or different. Live password.
  • the system will record five times of video sounds (including face information, motion information and voiceprint information) to generate a living password.
  • the client sends the five-pass image and sound collected by the client to the server.
  • the server can use the five-pass image and sound as a training sample, and collect machine learning algorithms to generate a living password.
  • the client when the client sends the video and sound to the server, the client can also send the user ID of the user at the same time.
  • the user identifier After the biometric password is generated according to the video sound, the user identifier can be stored in association with the biometric password, so that the biometric password corresponding to the user to be authenticated can be obtained during the authentication.
  • the biometric password is updated after being set according to the received new vital feature information.
  • an initial live password can be generated based on the initial video sound. After that, the authentication process will appear. At each authentication, the client will collect new in vivo feature information. On the one hand, the in vivo feature information can be used for authentication. On the other hand, the in vivo feature information can be used as a new sample. The end updates the live password based on the new sample. For example, the new vital characteristics information may include replacement of daily information such as a hairstyle.
  • the apparatus 50 further includes:
  • the obtaining module 54 is configured to obtain warning information, where the warning information is sent after the server determines that a network-wide warning needs to be performed according to the authentication result.
  • the security guard module 23 can be set in the cloud to perform network-wide warning. For example, after the captured image sound is compared with the stored living password, the authentication result can be obtained. If a person's behavior exceeds a preset risk threshold, the warning information for the person can be issued on the entire network. For example, the person has tried the password input in multiple merchants and the number of input errors exceeds the preset value. Because the living body feature information is collected, the person's face information, action information and voiceprint information can be obtained, so that the whole network can be obtained. The person's face information, action information and voiceprint information are posted to serve as a warning.
  • the living body feature information by collecting the living body feature information, the human memory password can be eliminated, and no human input is needed, the input efficiency during identity authentication can be improved, and the memory cost can be reduced.
  • the living body feature information is collected, and the living body feature information can be Change over time, compared to a fixed password method, can improve security.
  • a living password with a brand sense can be generated to meet the personalized needs.
  • dynamic encryption and self-learning of the living password can be realized.
  • network-wide notification can be achieved to ensure security.
  • An embodiment of the present invention further provides an electronic device, including: one or more processors; a memory; one or more programs, the one or more programs being stored in the memory when the one or more When the processor executes:
  • the server Sending the living body feature information to the server, so that the server performs authentication according to the living body feature information and the stored living body password corresponding to the user, and the living body password is the user collected according to history in advance.
  • the in vivo feature information is obtained.
  • the server Sending the living body feature information to the server, so that the server performs authentication according to the living body feature information and the stored living body password corresponding to the user, and the living body password is the user collected according to history in advance.
  • the in vivo feature information is obtained.
  • portions of the invention may be implemented in hardware, software, firmware or a combination thereof.
  • multiple steps or methods may be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system.
  • a suitable instruction execution system For example, if implemented in hardware, as in another embodiment, it can be implemented by any one or combination of the following techniques well known in the art: having logic gates for implementing logic functions on data signals. Discrete logic circuits, application specific integrated circuits with suitable combinational logic gates, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
  • each functional unit in each embodiment of the present invention may be integrated into one processing module, or each unit may exist physically separately, or two or more units may be integrated into one module.
  • the above integrated modules can be implemented in the form of hardware or in the form of software functional modules.
  • the integrated modules, if implemented in the form of software functional modules and sold or used as stand-alone products, may also be stored in a computer readable storage medium.
  • the above mentioned storage medium may be a read only memory, a magnetic disk or an optical disk or the like.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Biomedical Technology (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Biodiversity & Conservation Biology (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Collating Specific Patterns (AREA)
  • Storage Device Security (AREA)

Abstract

本发明提出一种身份认证方法和装置,该身份认证方法包括:采集待认证用户的活体特征信息;将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。该方法能够提高身份认证时的输入效率,降低记忆成本,并且提高安全度。

Description

身份认证方法和装置
相关申请的交叉引用
本申请要求百度在线网络技术(北京)有限公司于2015年07月17日提交的、发明名称为“身份认证方法和装置”的、中国专利申请号“201510425042.4”的优先权。
技术领域
本发明涉及安全认证技术领域,尤其涉及一种身份认证方法和装置。
背景技术
目前常用的安全认证方式是用户输入密码,对密码进行认证。但是,密码难以记忆并且输入效率较低,密码也容易被盗,安全度低。
发明内容
本发明旨在至少在一定程度上解决相关技术中的技术问题之一。
为此,本发明的一个目的在于提出一种身份认证方法,该方法可以提高身份认证时的输入效率,降低记忆成本,并且提高安全度。
本发明的另一个目的在于提出一种身份认证装置。
为达到上述目的,本发明第一方面实施例提出的身份认证方法,包括:采集待认证用户的活体特征信息;将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
本发明第一方面实施例提出的身份认证方法,通过采集活体特征信息,可以不需要人为记忆密码,也不需要人为输入,可以提高身份认证时的输入效率,降低记忆成本,另外,采集的是活体特征信息,活体特征信息可以随时间改变,相对于固定的密码方式,可以提高安全度。
为达到上述目的,本发明第二方面实施例提出的身份认证装置,包括:采集模块,用于采集待认证用户的活体特征信息;发送模块,用于将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
本发明第二方面实施例提出的身份认证装置,通过采集活体特征信息,可以不需要 人为记忆密码,也不需要人为输入,可以提高身份认证时的输入效率,降低记忆成本,另外,采集的是活体特征信息,活体特征信息可以随时间改变,相对于固定的密码方式,可以提高安全度。
本发明实施例还提出了一种电子设备,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时:执行如本发明第一方面实施例任一项所述的方法。
本发明实施例还提出了一种非易失性计算机存储介质,所述计算机存储介质存储有一个或者多个模块,当所述一个或者多个模块被执行时:执行如本发明第一方面实施例任一项所述的方法。
本发明附加的方面和优点将在下面的描述中部分给出,部分将从下面的描述中变得明显,或通过本发明的实践了解到。
附图说明
本发明上述的和/或附加的方面和优点从下面结合附图对实施例的描述中将变得明显和容易理解,其中:
图1是本发明一实施例提出的身份认证方法的流程示意图;
图2是本发明实施例中身份认证系统的示意图;
图3是本发明另一实施例提出的身份认证方法的流程示意图;
图4是本发明另一实施例提出的身份认证方法的流程示意图;
图5是本发明另一实施例提出的身份认证装置的结构示意图;
图6是本发明另一实施例提出的身份认证装置的结构示意图。
具体实施方式
下面详细描述本发明的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的模块或具有相同或类似功能的模块。下面通过参考附图描述的实施例是示例性的,仅用于解释本发明,而不能理解为对本发明的限制。相反,本发明的实施例包括落入所附加权利要求书的精神和内涵范围内的所有变化、修改和等同物。
图1是本发明一实施例提出的身份认证方法的流程示意图,该方法包括:
S11:采集待认证用户的活体特征信息。
活体特征信息是指能够随着时间而改变的信息。
例如,活体特征信息可以包括如下项中的至少一项:人脸信息,动作信息,声纹信息。
人脸信息例如包括:五官、发型、面部表情等。
动作信息例如包括:面部的肌肉变化、肢体动作等。
声纹信息例如包括:用户声音中的音频音色特征、字符的发音特征等。
其中,可以使用用户设备上的摄像头采集人脸信息和动作信息,使用用户设备上的麦克风采集声纹信息。
与现有固定不变的密码或指纹不同的是,本实施例中采集的是活体特征信息,活体特征信息能够随着时间的不同而改变。例如,基于时间轴的内在变化特征和外在变化特征,内在变化特征例如面部或者形体的变化,外在变化特征例如发型、服饰、首饰等。
可选的,活体特征信息可以是根据用户的主动行为采集的,例如,在需要输入密码时,用户主动朗诵一段文字,采集此时的声纹信息,人脸信息和动作信息。或者,活体特征信息也可以是系统向用户显示提示信息,用户根据该提示信息朗诵相应的文字。例如,系统向用户显示“我爱北京”,则用户可以朗诵“我爱北京”,采集此时的声纹信息,人脸信息和动作信息。
S12:将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
例如,参见图2,在客户端(如用户手机上)设置识别模块21,识别模块进行人脸识别,动作识别和声纹识别,从而获取用户的人脸信息,动作信息和声纹信息,客户端获取这些信息后,将采集的信息发送给云端,云端内设置活体密码库22,活体密码库内可以存储活体密码。另外,在存储时可以将活体密码与用户标识关联,在用户认证时,客户端在发送活体特征信息时还发送用户标识给云端,云端根据接收的用户标识以及存储的关联信息,可以获取与接收的用户标识对应的活体密码,之后,云端可以比对接收的活体特征信息与查找到的活体密码,将两者进行比对,得到认证结果。
假设活体特征信息包括:人脸信息,动作信息和声纹信息,则活体密码是根据之前采集的人脸信息,动作信息和声纹信息进行训练后得到的。其中,可以分别对人脸信息,动作信息和声纹信息进行训练,得到相应的模型,在认证时,再分别与接收的人脸信息,动作信息和声纹信息进行比对,在三者都匹配时,确定认证成功,否则认证失败。根据人脸信息,动作信息和声纹信息进行训练,得到相应的模型的方式,以及比对一个信息与其对应的模型是否匹配可以采用已有的方式实现。
另外,当服务端进行认证得到认证结果,可以将该认证结果发送给客户端,客户端接收服务端发送的认证结果,并将认证结果展示给用户。当认证结果是认证失败时,可以重新采集用户的活体特征信息进行再次认证。
一些实施例中,参见图3,该身份认证方法还包括:
S31:在设定活体密码时,采集用户的活体特征信息。
一些实施例中,所述在所述用户设定活体密码时,采集所述用户的活体特征信息,包括:
在所述用户设定活体密码时,向所述用户展示提示信息,其中,不同认证方对应的提示信息相同或不同;
采集所述用户根据所述提示信息生成的活体特征信息。
例如,系统提示用户完成简单的指定动作,以及朗诵提示文本,用户根据系统提示,可以进行相应的动作和朗诵,通过摄像头、麦克风传感器会采集到相应的人脸信息,动作信息和声纹信息。
另外,提示信息可以根据认证方的不同而不同,例如,用户需要在商户A中输入密码,也需要在商户B中输入密码,则在设置时,可以对应商户A和商户B设置相同或不同的活体密码。
例如,让用户说“我爱北京”,或者微笑状态下说“你好”。另外,可以提示用户重复预设次数,例如,用户重复五遍的“我爱北京”。系统将会整体记录五遍的影像声音(例如包括人脸信息,动作信息和声纹信息),从而生成活体密码。
S32:将所述活体特征信息发送给所述服务端,以使所述服务端根据所述活体特征信息生成活体密码。
例如,客户端将整体采集的五遍的影像声音发送给服务端,服务端可以将这五遍的影像声音作为训练样本,采集机器学习算法等训练生成活体密码。
另外,客户端在向服务端发送影像声音时,还可以同时发送用户的用户标识,服务端在根据影像声音生成活体密码后,可以将用户标识与活体密码关联存储,从而在认证时,可以获取与待认证的用户对应的活体密码。
一些实施例中,所述活体密码在设定之后,根据接收的新的活体特征信息进行更新。
例如,在初始设定后,可以根据初始的影像声音生成初始的活体密码。之后,会出现认证流程,在每次认证时,客户端会采集到新的活体特性信息,一方面该活体特性信息可以用于认证,另一方面该活体特征信息可以作为新的样本,由服务端根据新的样本更新活体密码。例如,新的活体特性信息可以包括发型等日常信息的更换。
一些实施例中,参见图4,该身份认证方法还包括:
S41:获取警告信息,所述警告信息是所述服务端根据认证结果确定需要进行全网预警后发送的。
如图2所示,云端可以设置安全警卫模块23,以进行全网预警。例如,根据采集的影像声音与存储的活体密码进行比对后,可以得到认证结果,如果一个人的行为超过预设的 危险阈值,则可以在全网发布针对该人的警告信息。例如,该人在多个商户均尝试了密码输入且输入错误次数超过预设值,由于通过采集活体特征信息,可以获取该人的人脸信息,动作信息和声纹信息,因此可以在全网发布该人的人脸信息,动作信息和声纹信息,以起到警示作用。
本实施例中,通过采集活体特征信息,可以不需要人为记忆密码,也不需要人为输入,可以提高身份认证时的输入效率,降低记忆成本,另外,采集的是活体特征信息,活体特征信息可以随时间改变,相对于固定的密码方式,可以提高安全度。进一步的,通过对应不同的认证方设置不同的活体密码,可以生成具有品牌感的活体密码,满足个性化需求。通过对活体密码的更新,可以实现活体密码的动态升级和自我学习。通过设置安全警卫模块,可以实现全网通报,保证安全性。
图5是本发明另一实施例提出的身份认证装置的结构示意图,该装置可以位于客户端,例如用户手机上。该装置50包括:
采集模块51,用于采集待认证用户的活体特征信息;
活体特征信息是指能够随着时间而改变的信息。
例如,活体特征信息可以包括如下项中的至少一项:人脸信息,动作信息,声纹信息。
人脸信息例如包括:五官、发型、面部表情等。
动作信息例如包括:面部的肌肉变化、肢体动作等。
声纹信息例如包括:用户声音中的音频音色特征、字符的发音特征等。
其中,可以使用用户设备上的摄像头采集人脸信息和动作信息,使用用户设备上的麦克风采集声纹信息。
与现有固定不变的密码或指纹不同的是,本实施例中采集的是活体特征信息,活体特征信息能够随着时间的不同而改变。例如,基于时间轴的内在变化特征和外在变化特征,内在变化特征例如面部或者形体的变化,外在变化特征例如发型、服饰、首饰等。
可选的,活体特征信息可以是根据用户的主动行为采集的,例如,在需要输入密码时,用户主动朗诵一段文字,采集此时的声纹信息,人脸信息和动作信息。或者,活体特征信息也可以是系统向用户显示提示信息,用户根据该提示信息朗诵相应的文字。例如,系统向用户显示“我爱北京”,则用户可以朗诵“我爱北京”,采集此时的声纹信息,人脸信息和动作信息。
发送模块52,用于将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
例如,参见图2,在客户端(如用户手机上)设置识别模块21,识别模块进行人脸识 别,动作识别和声纹识别,从而获取用户的人脸信息,动作信息和声纹信息,客户端获取这些信息后,将采集的信息发送给云端,云端内设置活体密码库22,活体密码库内可以存储活体密码。另外,在存储时可以将活体密码与用户标识关联,在用户认证时,客户端在发送活体特征信息时还发送用户标识给云端,云端根据接收的用户标识以及存储的关联信息,可以获取与接收的用户标识对应的活体密码,之后,云端可以比对接收的活体特征信息与查找到的活体密码,将两者进行比对,得到认证结果。
假设活体特征信息包括:人脸信息,动作信息和声纹信息,则活体密码是根据之前采集的人脸信息,动作信息和声纹信息进行训练后得到的。其中,可以分别对人脸信息,动作信息和声纹信息进行训练,得到相应的模型,在认证时,再分别与接收的人脸信息,动作信息和声纹信息进行比对,在三者都匹配时,确定认证成功,否则认证失败。根据人脸信息,动作信息和声纹信息进行训练,得到相应的模型的方式,以及比对一个信息与其对应的模型是否匹配可以采用已有的方式实现。
一些实施例中,参见图6,该装置50还包括:
设置模块53,用于在所述用户设定活体密码时,采集所述用户的活体特征信息;将所述活体特征信息发送给所述服务端,以使所述服务端根据所述活体特征信息生成活体密码。
可选的,所述设置模块53用于在所述用户设定活体密码时,采集所述用户的活体特征信息,包括:
在所述用户设定活体密码时,向所述用户展示提示信息,其中,不同认证方对应的提示信息相同或不同;
采集所述用户根据所述提示信息生成的活体特征信息。
例如,系统提示用户完成简单的指定动作,以及朗诵提示文本,用户根据系统提示,可以进行相应的动作和朗诵,通过摄像头、麦克风传感器会采集到相应的人脸信息,动作信息和声纹信息。
另外,提示信息可以根据认证方的不同而不同,例如,用户需要在商户A中输入密码,也需要在商户B中输入密码,则在设置时,可以对应商户A和商户B设置相同或不同的活体密码。
例如,让用户说“我爱北京”,或者微笑状态下说“你好”。另外,可以提示用户重复预设次数,例如,用户重复五遍的“我爱北京”。系统将会整体记录五遍的影像声音(例如包括人脸信息,动作信息和声纹信息),从而生成活体密码。
例如,客户端将整体采集的五遍的影像声音发送给服务端,服务端可以将这五遍的影像声音作为训练样本,采集机器学习算法等训练生成活体密码。
另外,客户端在向服务端发送影像声音时,还可以同时发送用户的用户标识,服务端 在根据影像声音生成活体密码后,可以将用户标识与活体密码关联存储,从而在认证时,可以获取与待认证的用户对应的活体密码。
一些实施例中,所述活体密码在设定之后,根据接收的新的活体特征信息进行更新。
例如,在初始设定后,可以根据初始的影像声音生成初始的活体密码。之后,会出现认证流程,在每次认证时,客户端会采集到新的活体特性信息,一方面该活体特性信息可以用于认证,另一方面该活体特征信息可以作为新的样本,由服务端根据新的样本更新活体密码。例如,新的活体特性信息可以包括发型等日常信息的更换。
一些实施例中,参见图6,该装置50还包括:
获取模块54,用于获取警告信息,所述警告信息是所述服务端根据认证结果确定需要进行全网预警后发送的。
如图2所示,云端可以设置安全警卫模块23,以进行全网预警。例如,根据采集的影像声音与存储的活体密码进行比对后,可以得到认证结果,如果一个人的行为超过预设的危险阈值,则可以在全网发布针对该人的警告信息。例如,该人在多个商户均尝试了密码输入且输入错误次数超过预设值,由于通过采集活体特征信息,可以获取该人的人脸信息,动作信息和声纹信息,因此可以在全网发布该人的人脸信息,动作信息和声纹信息,以起到警示作用。
本实施例中,通过采集活体特征信息,可以不需要人为记忆密码,也不需要人为输入,可以提高身份认证时的输入效率,降低记忆成本,另外,采集的是活体特征信息,活体特征信息可以随时间改变,相对于固定的密码方式,可以提高安全度。进一步的,通过对应不同的认证方设置不同的活体密码,可以生成具有品牌感的活体密码,满足个性化需求。通过对活体密码的更新,可以实现活体密码的动态升级和自我学习。通过设置安全警卫模块,可以实现全网通报,保证安全性。
本发明实施例还提出了一种电子设备,包括:一个或者多个处理器;存储器;一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时:
采集待认证用户的活体特征信息;
将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
本发明实施例还提出了一种非易失性计算机存储介质,所述计算机存储介质存储有一个或者多个模块,当所述一个或者多个模块被执行时:
采集待认证用户的活体特征信息;
将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
需要说明的是,在本发明的描述中,术语“第一”、“第二”等仅用于描述目的,而不能理解为指示或暗示相对重要性。此外,在本发明的描述中,除非另有说明,“多个”的含义是指至少两个。
流程图中或在此以其他方式描述的任何过程或方法描述可以被理解为,表示包括一个或更多个用于实现特定逻辑功能或过程的步骤的可执行指令的代码的模块、片段或部分,并且本发明的优选实施方式的范围包括另外的实现,其中可以不按所示出或讨论的顺序,包括根据所涉及的功能按基本同时的方式或按相反的顺序,来执行功能,这应被本发明的实施例所属技术领域的技术人员所理解。
应当理解,本发明的各部分可以用硬件、软件、固件或它们的组合来实现。在上述实施方式中,多个步骤或方法可以用存储在存储器中且由合适的指令执行系统执行的软件或固件来实现。例如,如果用硬件来实现,和在另一实施方式中一样,可用本领域公知的下列技术中的任一项或他们的组合来实现:具有用于对数据信号实现逻辑功能的逻辑门电路的离散逻辑电路,具有合适的组合逻辑门电路的专用集成电路,可编程门阵列(PGA),现场可编程门阵列(FPGA)等。
本技术领域的普通技术人员可以理解实现上述实施例方法携带的全部或部分步骤是可以通过程序来指令相关的硬件完成,所述的程序可以存储于一种计算机可读存储介质中,该程序在执行时,包括方法实施例的步骤之一或其组合。
此外,在本发明各个实施例中的各功能单元可以集成在一个处理模块中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。所述集成的模块如果以软件功能模块的形式实现并作为独立的产品销售或使用时,也可以存储在一个计算机可读取存储介质中。
上述提到的存储介质可以是只读存储器,磁盘或光盘等。
在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本发明的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不一定指的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任何的一个或多个实施例或示例中以合适的方式结合。
尽管上面已经示出和描述了本发明的实施例,可以理解的是,上述实施例是示例性的, 不能理解为对本发明的限制,本领域的普通技术人员在本发明的范围内可以对上述实施例进行变化、修改、替换和变型。

Claims (12)

  1. 一种身份认证方法,其特征在于,包括:
    采集待认证用户的活体特征信息;
    将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
  2. 根据权利要求1所述的方法,其特征在于,所述活体特征信息包括如下项中的至少一项:人脸信息,动作信息,声纹信息。
  3. 根据权利要求1-2任一项所述的方法,其特征在于,还包括:
    在所述用户设定活体密码时,采集所述用户的活体特征信息;
    将所述活体特征信息发送给所述服务端,以使所述服务端根据所述活体特征信息生成活体密码。
  4. 根据权利要求3所述的方法,其特征在于,所述在所述用户设定活体密码时,采集所述用户的活体特征信息,包括:
    在所述用户设定活体密码时,向所述用户展示提示信息,其中,不同认证方对应的提示信息相同或不同;
    采集所述用户根据所述提示信息生成的活体特征信息。
  5. 根据权利要求3-4任一项所述的方法,其特征在于,所述活体密码在设定之后,根据接收的新的活体特征信息进行更新。
  6. 根据权利要求1-5任一项所述的方法,其特征在于,还包括:
    获取警告信息,所述警告信息是所述服务端根据认证结果确定需要进行全网预警后发送的。
  7. 一种身份认证装置,其特征在于,包括:
    采集模块,用于采集待认证用户的活体特征信息;
    发送模块,用于将所述活体特征信息发送给服务端,以使所述服务端根据所述活体特征信息以及存储的与所述用户对应的活体密码进行认证,所述活体密码是预先根据历史采集的所述用户的活体特征信息得到的。
  8. 根据权利要求7所述的装置,其特征在于,还包括:
    设置模块,用于在所述用户设定活体密码时,采集所述用户的活体特征信息;将所述活体特征信息发送给所述服务端,以使所述服务端根据所述活体特征信息生成活体密码。
  9. 根据权利要求8所述的装置,其特征在于,所述设置模块用于在所述用户设定活体 密码时,采集所述用户的活体特征信息,包括:
    在所述用户设定活体密码时,向所述用户展示提示信息,其中,不同认证方对应的提示信息相同或不同;
    采集所述用户根据所述提示信息生成的活体特征信息。
  10. 根据权利要求7-9任一项所述的装置,其特征在于,还包括:
    获取模块,用于获取警告信息,所述警告信息是所述服务端根据认证结果确定需要进行全网预警后发送的。
  11. 一种电子设备,其特征在于,包括:
    一个或者多个处理器;
    存储器;
    一个或者多个程序,所述一个或者多个程序存储在所述存储器中,当被所述一个或者多个处理器执行时:
    执行如权利要求1-6任一项所述的方法。
  12. 一种非易失性计算机存储介质,其特征在于,所述计算机存储介质存储有一个或者多个模块,当所述一个或者多个模块被执行时:
    执行如权利要求1-6任一项所述的方法。
PCT/CN2015/096343 2015-07-17 2015-12-03 身份认证方法和装置 Ceased WO2017012238A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510425042.4A CN105100097A (zh) 2015-07-17 2015-07-17 身份认证方法和装置
CN201510425042.4 2015-07-17

Publications (1)

Publication Number Publication Date
WO2017012238A1 true WO2017012238A1 (zh) 2017-01-26

Family

ID=54579642

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/096343 Ceased WO2017012238A1 (zh) 2015-07-17 2015-12-03 身份认证方法和装置

Country Status (2)

Country Link
CN (1) CN105100097A (zh)
WO (1) WO2017012238A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108960835A (zh) * 2017-05-21 2018-12-07 未来科技(襄阳)有限公司 金融结算系统以及金融刷卡终端
CN109800642A (zh) * 2018-12-15 2019-05-24 深圳壹账通智能科技有限公司 人员身份信息获取方法、装置、计算机设备及存储介质

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105100097A (zh) * 2015-07-17 2015-11-25 百度在线网络技术(北京)有限公司 身份认证方法和装置
CN107766785B (zh) * 2017-01-25 2022-04-29 丁贤根 一种面部识别方法
CN107657428A (zh) * 2017-09-30 2018-02-02 四川民工加网络科技有限公司 一种多级式农民工招工方法
CN108108603A (zh) * 2017-12-04 2018-06-01 阿里巴巴集团控股有限公司 登录方法及装置和电子设备
CN109831441B (zh) * 2019-02-22 2021-10-22 深圳市信锐网科技术有限公司 一种身份认证的方法、系统及相关组件
CN114978546A (zh) * 2022-05-24 2022-08-30 中国银行股份有限公司 用户身份验证方法及装置

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020007462A1 (en) * 2000-07-11 2002-01-17 Masaki Omata User authentication system
WO2008098029A1 (en) * 2007-02-06 2008-08-14 Vidoop, Llc. System and method for authenticating a user to a computer system
CN103384234A (zh) * 2012-05-04 2013-11-06 深圳市腾讯计算机系统有限公司 人脸身份认证方法和系统
CN103546622A (zh) * 2012-07-12 2014-01-29 百度在线网络技术(北京)有限公司 基于声纹的识别登录控制方法、装置及系统
CN104135489A (zh) * 2014-08-13 2014-11-05 百度在线网络技术(北京)有限公司 一种登录认证方法及装置
CN104639517A (zh) * 2013-11-15 2015-05-20 阿里巴巴集团控股有限公司 利用人体生物特征进行身份验证的方法和装置
CN105100097A (zh) * 2015-07-17 2015-11-25 百度在线网络技术(北京)有限公司 身份认证方法和装置

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20020007462A1 (en) * 2000-07-11 2002-01-17 Masaki Omata User authentication system
WO2008098029A1 (en) * 2007-02-06 2008-08-14 Vidoop, Llc. System and method for authenticating a user to a computer system
CN103384234A (zh) * 2012-05-04 2013-11-06 深圳市腾讯计算机系统有限公司 人脸身份认证方法和系统
CN103546622A (zh) * 2012-07-12 2014-01-29 百度在线网络技术(北京)有限公司 基于声纹的识别登录控制方法、装置及系统
CN104639517A (zh) * 2013-11-15 2015-05-20 阿里巴巴集团控股有限公司 利用人体生物特征进行身份验证的方法和装置
CN104135489A (zh) * 2014-08-13 2014-11-05 百度在线网络技术(北京)有限公司 一种登录认证方法及装置
CN105100097A (zh) * 2015-07-17 2015-11-25 百度在线网络技术(北京)有限公司 身份认证方法和装置

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108960835A (zh) * 2017-05-21 2018-12-07 未来科技(襄阳)有限公司 金融结算系统以及金融刷卡终端
CN109800642A (zh) * 2018-12-15 2019-05-24 深圳壹账通智能科技有限公司 人员身份信息获取方法、装置、计算机设备及存储介质

Also Published As

Publication number Publication date
CN105100097A (zh) 2015-11-25

Similar Documents

Publication Publication Date Title
US11704939B2 (en) Liveness detection
CN105100097A (zh) 身份认证方法和装置
JP6619847B2 (ja) 身元認証方法、端末装置、およびコンピュータ可読記憶媒体{identity authentication method, terminal equipment and computer readable storage medium}
US11132430B2 (en) Login method and apparatus and electronic device
CN108804884B (zh) 身份认证的方法、装置及计算机存储介质
JP5856330B2 (ja) ビデオシグネチャを用いる認証
CN111492357A (zh) 用于生物识别用户认证的系统和方法
US20180075848A1 (en) Dialogue apparatus and method
TW201512880A (zh) 電子裝置、身份驗證系統及方法
WO2017201912A1 (zh) 基于深度学习的声纹认证方法和装置
TW202024998A (zh) 考勤管理系統、方法及電子設備
CN109993025B (zh) 一种关键帧提取方法及设备
CN107995979A (zh) 使用凝视信息的用户识别和/或认证
KR20170047255A (ko) 신원 인증 방법 및 장치, 단말기 및 서버
CN115315699A (zh) 用于语音用户接口的耳内活性检测
JPWO2018051948A1 (ja) 個人認証装置、個人認証方法および個人認証プログラム
CN104935438A (zh) 用于身份验证的方法和装置
EP3001343B1 (en) System and method of enhanced identity recognition incorporating random actions
CN109815806B (zh) 人脸识别方法及装置、计算机设备、计算机存储介质
CN109190528B (zh) 活体检测方法及装置
CN110516426A (zh) 身份认证方法、认证终端、装置及可读存储介质
CN108985174A (zh) 会员认证方法和装置
CN112185422A (zh) 提示信息生成方法及其语音机器人
WO2016058540A1 (zh) 身份验证方法、装置和存储介质
WO2024123218A1 (en) Two-factor facial recognition authentication

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15898794

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15898794

Country of ref document: EP

Kind code of ref document: A1