WO2018040946A1 - 一种身份验证的方法及装置 - Google Patents

一种身份验证的方法及装置 Download PDF

Info

Publication number
WO2018040946A1
WO2018040946A1 PCT/CN2017/097955 CN2017097955W WO2018040946A1 WO 2018040946 A1 WO2018040946 A1 WO 2018040946A1 CN 2017097955 W CN2017097955 W CN 2017097955W WO 2018040946 A1 WO2018040946 A1 WO 2018040946A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
vibration
server
metadata
instruction
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2017/097955
Other languages
English (en)
French (fr)
Inventor
向东
李才伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Publication of WO2018040946A1 publication Critical patent/WO2018040946A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint

Definitions

  • the present application relates to the field of information technology, and in particular, to a method and an apparatus for identity verification.
  • FIG. 1 it is a schematic diagram of a terminal connected to a server through a network in the prior art.
  • the terminal is a terminal that has logged in to the account, so it can be considered that the terminal establishes a data connection with the server through the account.
  • one server can provide services for multiple accounts, regardless of which terminal the account is in. When you log in, you can use this account to verify your identity with the server. Therefore, in the prior art, the identity of the account that is logged in on the terminal can be verified, and only the account that is authenticated can perform the service, thereby ensuring security.
  • the prior art begins to perform identity verification based on biometric information.
  • the server collects and stores the biometric information (such as fingerprint information, voiceprint information, iris information, appearance information, and the like) of the account holder as standard biometric information corresponding to the account, wherein the biometric information can be used by the mobile terminal.
  • the sensor is collected, and each time the identity verification is performed, the mobile terminal re-acquires the biometric information and uses the biometric information to be verified as the account and sends the biometric information to the server, and the server can be based on the stored standard.
  • the biological information determines whether the biological information to be verified is consistent with the standard biological information, and determines whether the identity verification is passed according to the judgment result.
  • the terminal collects the user's biological information
  • the user is required to actively operate the terminal, so that the terminal collects the user's biological information (eg, using a finger to press the sensor, making the eye face the camera, talking to the microphone, etc. ), so the use of biometric information for authentication increases user operations, making the authentication process cumbersome.
  • the collection of biological information usually has certain requirements on the collection environment. For example, if the finger is wet, the fingerprint collection may fail, and the environment may be too noisy, which may cause the voiceprint collection to fail, and the ambient light is too dark, which may cause the iris information to fail to be collected. , which in turn leads to an increased likelihood of authentication failures and reduces the efficiency of authentication.
  • the existing authentication technology has the problem of low efficiency of identity verification.
  • the embodiment of the present invention provides a method for authenticating an identity, which is used to solve the problems of cumbersome user operations, low user willingness, high requirements for the collection environment, and low efficiency of identity verification.
  • the embodiment of the present invention provides an apparatus for authenticating an identity, which is used to solve the problems of cumbersome user operations, low user willingness, high requirements on the collection environment, and low efficiency of identity verification when using the prior art for identity verification.
  • a method of authentication including:
  • the terminal collects metadata generated when the vibration operation is performed when performing a vibration operation according to the verification trigger instruction
  • the terminal sends an authentication request carrying the metadata and the device identifier of the terminal to the server, where the verification request is used to request the server to use the terminal according to the metadata and the device identifier of the terminal.
  • the user authenticates.
  • a method of authentication including:
  • the server sends a verification trigger instruction to the terminal, where the verification trigger instruction is used to instruct the terminal to collect metadata generated when the vibration operation is performed when performing a vibration operation according to the verification trigger instruction;
  • the server determines and receives according to a correspondence between a preset device identifier and a reference vibration parameter. a reference vibration parameter corresponding to the device identifier of the terminal;
  • User authentication using the terminal is performed based on the reference vibration parameter and the metadata.
  • An authentication device includes:
  • Receiving module receiving a verification trigger instruction sent by the server
  • a vibration module performing a vibration operation according to the verification trigger instruction
  • An acquisition module when the vibration module performs a vibration operation according to the verification trigger instruction, collecting metadata generated when the vibration operation is performed;
  • a sending module configured to send, to the server, an authentication request that carries the metadata and a device identifier of the device, where the verification request is used to request the server to use the device according to the metadata and a device identifier of the device The user authenticates.
  • An apparatus for authenticating comprising a vibration motor and a sensor, comprising:
  • the sending module sends a verification triggering instruction to the terminal, where the verification triggering instruction is used to instruct the terminal to collect metadata generated when the vibration operation is performed when performing a vibration operation according to the verification triggering instruction;
  • a receiving module receiving the metadata sent by the terminal and a device identifier of the terminal
  • the verification module performs identity verification on the user using the terminal according to the reference vibration parameter and the metadata.
  • the terminal may perform a vibration operation according to the server sending the verification trigger instruction, and return the metadata corresponding to the vibration operation collected when the vibration operation is performed to the server, so that the server may according to the correspondence between the preset device identifier and the reference vibration parameter. Determining a reference vibration parameter corresponding to the received device identifier of the terminal, and performing identity verification on the user using the terminal according to the reference vibration parameter and the metadata. It can be seen that, by using the method provided by the embodiment of the present application, the user can complete the collection and return of the metadata without any operation of the terminal, and the user does not need to collect his own biological information, thereby avoiding the problem of personal privacy involved in the prior art. It also simplifies user operations and improves the efficiency of authentication.
  • FIG. 1 is a schematic diagram of a terminal connected to a server through a network in the prior art
  • FIG. 3 is a process of another identity verification provided by an embodiment of the present application.
  • FIG. 4 is a schematic diagram of a process for a server to send a verification trigger command to a terminal and return the metadata to the terminal according to an embodiment of the present disclosure
  • FIG. 5 is a schematic diagram of an acceleration variation of an acceleration sensor collected by a terminal according to an embodiment of the present disclosure
  • FIG. 6 is a schematic diagram of waveforms corresponding to the vibration operation provided by the embodiment of the present application.
  • FIG. 7 is a schematic structural diagram of an apparatus for identity verification according to an embodiment of the present disclosure.
  • FIG. 8 is a schematic structural diagram of another apparatus for identity verification according to an embodiment of the present application.
  • FIG. 2 is a process of the identity verification provided by the embodiment of the present application, which specifically includes the following steps:
  • the terminal receives a verification trigger instruction sent by the server, where the verification trigger instruction is used to instruct the terminal to perform a vibration operation.
  • the terminal may receive the verification trigger command sent by the server, and the verification trigger command received by the terminal may be when the server determines that the terminal sends the Sent when status information is abnormal.
  • the terminal sends its own state information to the server, where the state information may include: mac address information, ip address information, geographical location information, service information, and the like of the terminal, that is, the status information is Various types of information reflecting the status of the terminal (the status of the terminal can be generally classified into: the environmental status of the terminal, such as geographical location information, time information, etc., and the operating status of the terminal, such as the system version number.
  • the state information may include: mac address information, ip address information, geographical location information, service information, and the like of the terminal, that is, the status information is Various types of information reflecting the status of the terminal (the status of the terminal can be generally classified into: the environmental status of the terminal, such as geographical location information, time information, etc., and the operating status of the terminal, such as the system version number.
  • the ip address information, the service information, and the like of course, the application is not limited to only the last two types of conditions can be used as the status information of the terminal), and the specific information includes the information that can be set according to actual needs, and the application does not Specifically, it is to be noted that the service information may be information related to the service, such as a service execution request, and may be related information of the service being executed by the terminal. Thus, the terminal can be based on the history of the terminal at the server When the status information determines that the status information sent by the terminal is abnormal, the verification trigger command sent by the server is received.
  • the verification trigger instruction is used to instruct the terminal to perform a vibration operation.
  • the verification triggering instruction may be a scripting language (JavaScript, JS) code, and after the terminal receives the verification triggering instruction, by running the JS code, determining the vibration frequency information included in the verification triggering instruction, At least one of vibration time interval information and vibration intensity information, and then the terminal may perform a vibration operation according to at least one of the vibration frequency information, the vibration time interval information, and the vibration intensity information.
  • JS scripting language
  • This vibration operation can be performed by a vibration motor in the terminal. Since the vibration triggering command may include at least one of vibration frequency information, vibration time interval information, and vibration intensity information, the vibration motor may perform vibration operation only based on vibration frequency information, vibration time interval information, or vibration intensity. The information performs a vibration operation. Of course, when the vibration triggering instruction includes accurate vibration frequency information, vibration time interval information, and vibration intensity information, the vibration operation performed by the vibration motor is more accurate, which is more favorable for subsequent steps and accurate final verification results. Sex.
  • the terminal may be a terminal including a vibration motor and a hand held by a user such as a mobile phone or a tablet computer.
  • the terminal collects metadata generated when the vibration operation is performed when performing a vibration operation according to the verification trigger instruction.
  • the terminal may determine the vibration operation according to the verification trigger instruction, and enable the vibration motor of the terminal to perform the vibration operation, and the sensor of the terminal may also collect the vibration operation.
  • the vibration motor since the vibration motor is a part of the terminal, the vibration motor generates vibration as a whole when the vibration operation is performed, and the vibration is reflected in the acceleration change of the terminal as a whole.
  • the angular velocity changes, the vibration acceleration and/or the vibration angular velocity generated by the vibration sensor by the sensor of the terminal, or the vibration acceleration and/or the vibration angular velocity generated by the vibration operation, and
  • the vibration acceleration and/or the vibration angular velocity is used as metadata generated by the terminal when the vibration operation is performed.
  • the sensor collected by the sensor of the terminal may be affected.
  • the vibration motor performs the vibration acceleration and/or the vibration angular velocity generated by the vibration operation, and the posture of each user holding the terminal is unique (that is, the probability that two users hold the same terminal exactly the same) is extremely low, Therefore, the metadata of the vibration operation collected by the terminal may be metadata uniquely corresponding to each user and terminal, ie, This metadata is globally unique.
  • the metadata can be used as data for authenticating the user using the terminal.
  • the sensor of the terminal may also collect the vibration acceleration and/or the vibration angular velocity of the terminal by running the JS code, and use the vibration acceleration and/or the vibration angular velocity as The metadata generated by the terminal when performing the vibration operation.
  • the senor may include: an acceleration sensor, a gravity sensor, a magnetic sensor, a direction sensor, a gyro sensor, a light sensor, a pressure sensor, a temperature sensor, a proximity sensor, a linear acceleration sensor, a rotation vector sensor, and a global positioning system ( Global Positioning System, GPS) sensors, heart rate sensors, blood oxygen sensors, ultraviolet sensors, etc.
  • the vibration motor of the terminal may have at least one, that is, there may be a plurality of vibration motors in the terminal, and when there are a plurality of vibration motors in the terminal, each vibration motor may perform different vibration operations according to the verification trigger command. .
  • the terminal may collect not only the vibration acceleration and/or the vibration angular velocity, but also other data generated by the vibration, and the vibration triggering command may be set according to requirements, which is not specifically limited in the present application.
  • the present application is not limited to carrying the JS code in the verification trigger instruction, as long as the verification trigger instruction can enable the vibration motor of the terminal to perform a corresponding operation, and the sensor of the terminal collects data.
  • the terminal sends an authentication request that carries the metadata and the device identifier of the terminal to a server.
  • the verification request carrying the metadata and the device identifier of the terminal may be sent to the server, and the server is configured according to the metadata and the device of the terminal. Identifies the identity of the user who uses the terminal.
  • the results determined by the identity verification process described in this application may also be Used in conjunction with the results determined by other authentication methods, that is, the server can authenticate the terminal by using the authentication results obtained by multiple authentication methods, for example, determining the identity of the terminal through three methods. If the verification fails, the security of the terminal is very low, and it is likely that it has been stolen by criminals.
  • the terminal receives the verification trigger command sent by the server, the user does not need to perform any operation on the terminal, and the terminal can return the metadata and the device identifier of the terminal to the server. So that the server authenticates the user who uses the terminal based on the metadata and the device identification of the terminal. Wherein, for each user, the user holds the posture of the terminal and holds the other user The probability that the posture of the terminal is completely the same is extremely low, and the posture of the user holding the terminal must have a certain influence on the metadata generated by the vibration operation of the vibration motor collected by the sensor of the terminal, so whether the metadata can be used It is the user who holds the terminal to distinguish, and then authenticates the user who uses the terminal.
  • the method provided by the embodiment of the present application can complete the process of identity verification without user operation, and because the collected information is unique to the user, but the biometric information of the user does not involve the personal privacy of the user. Therefore, it is easier for users to accept, the operating cost is lower, and there is almost no requirement for the collection environment, and the authentication efficiency is higher.
  • the account trigger identifier can be carried in the verification trigger command received by the terminal in step S101, and after the terminal determines the metadata in step S102,
  • the terminal may also send the verification request of the account identifier of the terminal to the server, where the verification request is used to request the server to be based on the element.
  • the data, the device identifier of the terminal, and the account identifier authenticate the user who uses the terminal.
  • the embodiment of the present application further provides a method for performing identity verification by a server, as shown in FIG. 3.
  • FIG. 3 is a process of identity verification according to an embodiment of the present application, which specifically includes the following steps:
  • S201 The server sends a verification trigger instruction to the terminal.
  • the server usually needs to perform an identity verification process before the corresponding service is sent according to the service request sent by the terminal, so as to prove that the service request is sent by the holder of the terminal, so in the present application,
  • the authentication process actually verifies whether the terminal is being used by the holder of the terminal, ie, authenticating the user using the terminal.
  • the server may first determine the timing of sending the verification trigger instruction to the terminal.
  • the server can establish a communication connection with multiple terminals and receive status information sent by each terminal, so the server can receive status information of each terminal, and for each The terminal with abnormal status information determines a verification trigger instruction corresponding to the device identifier of the terminal according to the stored correspondence of each device identifier, each verification trigger command, and each reference vibration parameter, and sends the verification trigger instruction to the terminal.
  • the server may receive the status information sent by the terminal for each terminal.
  • the server may send a verification trigger instruction to the terminal, and the status information is in step S101.
  • the corresponding description has been made and will not be described again.
  • the method for determining whether the status information of each terminal is abnormal may be consistent with the prior art, for example, according to the historical geographical location information and historical service of the terminal. The information and the like determine whether the status information of each terminal is abnormal. This application does not specifically limit this.
  • the server since the ultimate purpose of the authentication is to ensure the security when performing the service, the server initiates a service request and when the account logs in to the terminal, the server may also send a verification trigger instruction to the terminal without determining the terminal.
  • the status information sent is abnormal.
  • the timing of sending the verification trigger command may also be set according to requirements.
  • the timing of sending the verification trigger instruction is not specifically limited in this application.
  • the server may be a single device or a system composed of multiple devices (eg, a distributed system).
  • the server X monitors the status information of each terminal corresponding to each of the setting identifiers shown in Table 1.
  • the device identifier may be used to identify the uniqueness of the terminal (equivalent to the identity of the terminal), for example, a mac address, an International Mobile Equipment Identity (IMEI), an identity number of the motherboard, and the like. Etc., and the device identification may also be a unique identification code added by the manufacturer that produced the terminal to the terminal, such as a production number, a product serial number, and the like. And the device identifier of the terminal can be read, so that the identity of the terminal is determined by the device identifier. Therefore, in the present application, the specific format of the device identifier is not limited, as long as the device identifier can be uniquely determined.
  • the terminal can be.
  • the server X may determine that the verification trigger command needs to be sent to the terminal whose device identifier is A001. Further, the server X may be based on the device identifier. :A001 determines, by Table 1, that the verification trigger command sent to the terminal identified as A001 by the device is: Prov001.
  • the verification triggering instruction may cause the vibration motor of the terminal identified by the device as A001 to perform the vibration operation corresponding to the verification trigger command Prov001, and the sensor of the terminal may return the collected metadata of the vibration operation to the server.
  • the above process schematic diagram can be as shown in Figures 4a to 4c.
  • FIG. 4a-4c are schematic diagrams of a process for a server to send a verification trigger command to a terminal and return the metadata to the terminal according to an embodiment of the present application.
  • FIG. 4a shows that the server sends a verification trigger command to the terminal
  • FIG. 4b The verification trigger command causes the vibration motor of the terminal to perform a vibration operation corresponding to the verification trigger command
  • FIG. 4c is to cause the terminal to return metadata to the server.
  • S202 The server receives the metadata sent by the terminal and a device identifier of the terminal.
  • S203 The server determines, according to a correspondence between the preset device identifier and the reference vibration parameter, a reference vibration parameter corresponding to the received device identifier of the terminal.
  • the server may further receive the metadata returned by the terminal and the device identifier of the terminal, and then the server may further pass the Metadata to authenticate the terminal.
  • the server may determine the device by using the stored device identifiers, the verification trigger commands, and the correspondence between the reference vibration parameters as shown in Table 1. Identify the corresponding reference vibration parameters.
  • the corresponding relationship between the stored device identifiers, the verification triggering commands, and the reference vibration parameters may be preset and stored by the server, that is, for each device identifier, the device identifier is determined first.
  • Corresponding verification trigger instruction and reference vibration parameter and then storing the device identifier, the verification trigger instruction, and the reference vibration parameter and the corresponding relationship in the server.
  • the server since the server needs to determine the reference vibration parameter corresponding to the device identifier of the terminal in advance, in order to determine the relationship between the device identifier and the reference vibration parameter, the server may further send a test instruction to the terminal, and receive the The metadata returned by the test instruction returned by the terminal, and the metadata is used as a reference vibration parameter for the terminal, and finally the corresponding relationship between the device identifier, the reference vibration parameter, and the verification trigger instruction is established and stored.
  • the server may further send the test instruction to the terminal by repeating the same test instruction. And receiving metadata generated by each test instruction to reduce the determined error of the reference vibration parameter for the terminal, that is, the reference vibration parameter may be determined by a plurality of metadata.
  • the server may send at least one test instruction to the terminal, and receive metadata generated by the terminal for each test instruction and a device identifier of the terminal, and then determine, according to the metadata generated by each test instruction, the terminal Refer to the vibration parameter, and determine the test trigger instruction that generates the parameter as the verification trigger instruction, and finally establish and store the corresponding relationship between the device identifier, the verification trigger instruction, and the reference vibration parameter.
  • the server may determine whether the quantity of metadata generated for each test instruction returned by the terminal according to the received terminal reaches a threshold, and if yes, according to an average value of each metadata Determining a reference vibration parameter for the terminal, and if not, continuing to send a test command to the terminal, Until the received quantity of metadata generated by the terminal for each test instruction reaches a threshold, that is, receiving a preset number of metadata generated by the test instruction, and averaging each metadata as a target for the terminal Reference vibration parameters.
  • the server determines an average value of the differences between the metadata for each metadata generated by the test instruction, and determines whether the average value of the differences is less than a set threshold, and if so, determines each metadata.
  • the average value is the reference vibration parameter for the terminal, and if not, the test command is continued to be sent to the terminal until it is determined that the average value of the differences between the metadata is less than the set threshold.
  • the sending timing of the test command may be randomly determined or manually determined according to experience (for example, when receiving any information sent by the terminal, sending a test command to the terminal), wherein the test command may be repeatedly sent multiple times. Therefore, even if the timing of the transmission of the test command is randomly determined, the final determined reference vibration parameter for the terminal will not be affected.
  • the server may determine the identity verification result of the terminal by using a method consistent with the prior art before transmitting the test instruction, and send the test instruction when the identity verification result is passed. That is, the present application does not limit when to send the test instruction.
  • the terminal may use vibration acceleration, vibration angular velocity, and the like as metadata, and may also collect other data as metadata through various sensors, so in the present application, the server is determined to target
  • the reference vibration parameter may also include vibration acceleration and/or vibration angular velocity, and other data, which will not be further described herein.
  • the metadata returned by the terminal identified by the device as A001 is Z.
  • the server determines that the reference vibration parameter corresponding to the device identifier is Stand001 according to the corresponding relationship shown in Table 1 according to the device identifier A001.
  • S204 Perform identity verification on a user using the terminal according to the reference vibration parameter and the metadata.
  • the server determines the reference vibration parameter corresponding to the received device identifier of the terminal
  • the user who uses the terminal may be authenticated according to the reference vibration parameter and the metadata.
  • the server may compare the reference vibration parameter and the similarity of the metadata. If the similarity is within the specified range, it may be determined that the identity of the user using the terminal is higher, if the similarity is not specified. Within the scope, it is determined that the identity of the user who uses the terminal is less reliable. When determining that the user’s identity is highly trusted When the terminal sends an execution service request, the terminal can perform a corresponding service.
  • the server may further authenticate the user who uses the terminal by using other authentication methods that are the same as the prior art, and finally determine whether to perform the service corresponding to the service request, or the server may also perform the authentication.
  • the result is used in the risk control and the like, that is, the server can flexibly utilize the identity verification result determined by the application, and of course, the specific subsequent operation of the application is not specifically limited.
  • the server compares the reference vibration parameter and the similarity of the metadata
  • the reference vibration parameter and the metadata since the reference vibration parameter and the metadata are data collected by the sensor of the terminal, and the sensor of the terminal may be multiple Therefore, the reference vibration parameter and the metadata may only include a plurality of types of data. For convenience of description, the following only takes the data collected by the acceleration sensor of the terminal as an example for description.
  • the acceleration sensor of the terminal may be in FIG. 5 according to the vibration mode of the vibration motor of the terminal.
  • the amount of change in the acceleration of the terminal is measured in the x-axis, the y-axis, and the z-axis direction of the terminal, wherein the amount of change in the acceleration may include the maximum value, the minimum value, the maximum value occurrence time, and the minimum value of the acceleration.
  • the time, the time interval between each acceleration change, and the like, and the amount of change in the acceleration is compared with the amount of acceleration change included in the reference vibration parameter.
  • FIG. 5 is a schematic diagram of an acceleration variation of an acceleration sensor collected by a terminal according to an embodiment of the present disclosure.
  • the server can determine whether the similarity between the metadata and the reference vibration parameter is within a prescribed range, wherein the prescribed range can be set by the staff according to experience.
  • the acceleration sensor can collect a variety of data, for example, only the acceleration sensor can collect various data such as the maximum value, the minimum value, the maximum value occurrence time, and the minimum value occurrence time of the acceleration, so the judgment is similar.
  • Whether the degree is within the specified range may also be determined whether the proportion of the data type in which the similarity of the metadata and the reference vibration parameter is within a prescribed range reaches a preset threshold (for example, determining the similarity of 75% of the data)
  • the degree is within the specified range, as long as the maximum value, the minimum value, the maximum value occurrence time, and the minimum value occurrence time of the acceleration are specified in the three types of data.
  • the similarity between the metadata and the reference vibration parameter is within a prescribed range.
  • the server X determines the reference vibration parameter Stand001 and the metadata Z as shown in Table 2.
  • the server X needs to determine whether the similarity between the metadata and the reference vibration parameter is within a range of 0.2%
  • the maximum value of the acceleration of the reference vibration parameter may be: 0.1002-0.0998 G/s
  • the time point range may be: 0.1002 ⁇ 0.0998s
  • the minimum value of the acceleration may be: 0.0001002 ⁇ 0.0000998G/s
  • the range of the minimum occurrence time point may be: 0.501 ⁇ 0.499s.
  • the maximum acceleration occurrence time point is a duration between a time point at which the terminal performs vibration according to the corresponding test instruction to a time point at which the maximum acceleration is acquired
  • the minimum acceleration occurrence time point is The duration between the point in time when the terminal performs the vibration according to the corresponding test command and the time point at which the minimum acceleration is acquired.
  • the identity verification process described in the present application may also be combined with other The authentication process, that is, the server can use the authentication result obtained by multiple authentication methods to authenticate the terminal. For example, if the authentication of the terminal is not passed through three methods, the server The security of the terminal is very low and it is very likely that it has been stolen by criminals.
  • the types of the metadata Z as shown in Table 2 are only the embodiments provided by the present application.
  • the type of the metadata may also be multiple (for example, the number of times the acceleration is higher than the set threshold, the time when the acceleration is higher than the set threshold, etc.), and the present application does not limit the The type of metadata, as long as the metadata of the vibration that the sensor of the terminal can collect, can be used as the metadata described in this application.
  • the terminal triggers the verification trigger sent by the receiving server.
  • the terminal can return the metadata and the device identifier of the terminal to the server, so that the server identifies the user who uses the terminal according to the metadata and the device identifier of the terminal. verification.
  • the probability that the posture of the user holding the terminal is exactly the same as the posture of the other user holding the terminal is extremely low, and the posture of the user holding the terminal is collected by the sensor of the terminal.
  • the metadata generated by the vibration motor to perform the vibration operation must have a certain influence, so the metadata can be used to distinguish whether the user is holding the terminal, and then the user who uses the terminal is authenticated. It can be seen that the method provided by the embodiment of the present application can complete the process of identity verification without user operation, and because the collected information is unique to the user, but the biometric information of the user does not involve the personal privacy of the user. Therefore, it is easier for users to accept, the operating cost is lower, and there is almost no requirement for the collection environment, and the authentication efficiency is higher.
  • the server when the server sends the verification trigger instruction to the terminal, the server needs to receive the status information sent by the terminal, so in order to alleviate the running pressure of the server, the identity verification process described in the present application may also be
  • the terminal initiates the initiative, that is, the terminal sends an identity verification request to the server, and the identity verification request causes the server to send a verification trigger instruction to the terminal.
  • the server when the server performs identity verification on the terminal, the user who uses the terminal is authenticated by determining whether the reference vibration parameter and the metadata similarity are within a prescribed range. Therefore, the accuracy of the reference vibration parameter is closely related to the accuracy of the identity verification process described in this application.
  • the reference vibration parameter is determined by the terminal acquiring, when the vibration operation is performed according to the testing instruction, the metadata generated when the vibration operation is performed,
  • the test instruction causes the terminal to acquire a vibration operation generated according to the verification trigger instruction and the metadata generated during the execution of the vibration operation has low stability and low discrimination, the accuracy of the identity verification may be low.
  • the stability of the reference vibration parameter when the stability of the reference vibration parameter is low, for the verification triggering instruction, even if the user who uses the terminal is the same person, the similarity between the metadata returned by the terminal and the reference vibration parameter may not be within the specified range. .
  • the discrimination degree of the reference vibration parameter when the discrimination degree of the reference vibration parameter is low, for the verification triggering instruction, even if the user who uses the terminal is not the same person, the similarity between the metadata returned by the terminal and the reference vibration parameter may be within a prescribed range. It can be seen that when the stability of the reference vibration parameter determined is low and the degree of discrimination is low, the identity verification process described in the present application is prone to misjudgment and missed judgment.
  • the server can pass the test to determine the reference vibration parameter for the terminal.
  • the terminal repeatedly sends a plurality of test instructions, that is, for each test instruction, the server repeatedly sends the terminal to the terminal, and the server can receive the metadata generated by the multiple test instructions returned by the terminal, and determine that the stability reaches the first condition.
  • the metadata generated by the test instruction whose degree of discrimination reaches the second condition is determined as a reference vibration parameter for the terminal, and the correspondence between the device identifier, the verification trigger instruction, and the reference vibration parameter is established and stored for subsequent identity
  • the terminal can be authenticated with the reference vibration parameter.
  • the first condition and the second condition may be values respectively set according to manual experience.
  • the server may obtain the difference between the different metadata obtained by calculating the at least one metadata generated by the terminal for the same test instruction. And sum determining the stability of the test instruction to generate metadata based on the sum of the differences.
  • the server may first determine the average value of the metadata generated by the different test instructions when obtaining the metadata corresponding to the different test instructions, and for each test instruction Determining the difference between the average value of the metadata generated by the test instruction and the average value of the metadata generated by the other test instructions, and then using the sum of the determined difference values as the degree of discrimination of the metadata generated by the test instruction, The discrimination of different test instructions can be determined.
  • the purpose of the identity verification process in the present application is to determine whether the user of the terminal is the holder of the terminal when sending the test command, so for the method described in the present application, it is only necessary to verify whether the user is The holder of the terminal can be sent to send a test command without verifying who the user of the terminal is.
  • the test does not need to be considered. Whether the metadata generated by the test instruction corresponding to the instruction is similar to the metadata generated by the test instruction corresponding to the test instruction sent to other terminals, that is, only the metadata generated by the test instruction returned by the same terminal is compared.
  • each terminal for example, the terminal whose device identifier is A001 shown in Table 1
  • the server can send different test instructions to the terminal, wherein different test instructions can make the terminal
  • the vibration motor performs different vibration operations, specifically, at least one of vibration frequency information, vibration time interval information, and vibration intensity information, and the terminal may return the test instruction to the server for each different test instruction. Metadata.
  • the server may repeat the test command to the terminal to reduce the error of the metadata generated by the test command.
  • the server can also determine the user who uses the terminal When the identity is trusted, each test command is sent to the terminal.
  • the server determines the degree of discrimination between the metadata generated by the various test instructions and the stability of the metadata generated by each of the test instructions for the metadata generated by the different test instructions returned by the same terminal. For example, the metadata generated for the three test instructions shown in Table 3.
  • the maximum acceleration, the maximum acceleration occurrence time point, the minimum acceleration, and the minimum acceleration occurrence time point are average values, that is, the average value of each metadata generated by the same test instruction.
  • the various values are very indistinguishable, and for the metadata generated by the test instruction I, the test instruction produces the element of the I.
  • the values corresponding to the data differ greatly from the metadata generated by the test command II and the metadata generated by the test command III, so it can be determined that the degree of discrimination of the metadata I generated by the test command is high.
  • the maximum acceleration and the minimum acceleration may be changed according to different postures of the user holding the terminal (for example, different grip strengths of the user may cause different accelerations to be collected, and different grip postures of the user may also cause different accelerations to be collected),
  • the maximum acceleration and the minimum acceleration may also be changed according to the device corresponding to the terminal (for example, the device corresponding to the terminal has different weights and different volumes, which may result in different accelerations of the acquisition).
  • the posture of the user holding the terminal and the device corresponding to the terminal may also affect the time point of occurrence of the maximum acceleration and the time point at which the minimum acceleration occurs (eg, when the user's grip strength is large, the maximum acceleration may occur.
  • the degree of discrimination is: maximum acceleration (0.1000 G/s - 0.0600 G/s) + (0.1000 G/s - 0.0580 G/s), and the maximum acceleration occurrence time point. (0.100s-0.050s) + (0.100s-0.040s), minimum acceleration 0, minimum acceleration occurrence time point (0.900s-0.550s) + (0.900s-0.530s), the same reason can be determined by test command II Metadata and Test Directive III The degree of differentiation of the generated metadata.
  • the stability mentioned above refers to the stability of the metadata generated by the terminal for each test command returned by the terminal for the same test command (ie, For the same kind of test instruction, the difference between the metadata generated by each test instruction returned by the terminal), if the same test instruction, the metadata generated by the terminal each time the test instruction returns has a large difference, Then, the metadata generated by the test instruction is difficult to determine whether the difference is due to the data itself or the user of the terminal, so it is difficult to perform authentication by using the test instruction as a verification trigger instruction.
  • the server repeatedly sends 4 test instructions I and 4 test instructions II to the same terminal, and receives the metadata generated by the test command I shown in Table 4 and the metadata generated by the test command II returned by the terminal.
  • the stability of the metadata generated by the test instruction I is better, the difference between the metadata generated by each test instruction I is small, and the difference between the metadata generated by each test instruction II is large. It is difficult to use for authentication.
  • the stability of the maximum acceleration is: (0.1000 G/s - 0.1020 G/s) + (0.1020 G/s - 0.1050 G/s) + (0.1050 G / s-0.1001G/s).
  • step S204 the present application does not limit the type of the metadata
  • the present application does not limit that the terminal can only collect the metadata as shown in Table 3 after executing the above test command.
  • the metadata shown in FIG. 3 is only an example and does not form a limitation on the present application.
  • each of the above test instructions may also respectively correspond to a plurality of types of metadata.
  • the metadata generated by the test instruction may have lower-discrimination metadata
  • the lower-discrimination metadata has little meaning for the test instruction, so When it is determined that the degree of discrimination of the metadata is low, when the test instruction is subsequently sent, the metadata may not be collected.
  • test command I it is assumed that all the metadata generated by the test command I is as shown in Table 3. Since the degree of discrimination of the minimum acceleration generated by the test command I is 0, the meaning of the minimum acceleration for the test command I is not Large, then for the test command I, the sensor of the terminal can no longer collect the minimum acceleration, so that the test command I is executed
  • the raw metadata is only the maximum acceleration, the time point at which the maximum acceleration occurs, and the time point at which the minimum acceleration occurs.
  • the server can use the same signal processing method as the prior art for each metadata generated by each test command sent to the same terminal, and determine each test data generated by the same test command as a test data.
  • the metadata generated by the test instruction wherein the simplest method is, for each test instruction, the average value of each metadata generated by the test instruction is used as the metadata generated by the test instruction, and whenever When the server receives the metadata corresponding to the test instruction again, the metadata generated by the test instruction may be subjected to signal processing to determine that the metadata generated by the test instruction is more accurate.
  • the server can repeatedly send various test instructions (that is, repeatedly send the test instructions for each test instruction) until the stability of the metadata generated by the test instructions corresponding to the various test instructions reaches the first
  • the condition and the degree of discrimination reaches the metadata generated by the test instruction of the second condition
  • the metadata generated by the test instruction that reaches the first condition and the degree of discrimination reaches the second condition is used as the reference vibration parameter
  • the reference vibration is The test instruction corresponding to the parameter is used as the verification trigger instruction
  • the reference vibration parameter, the verification trigger instruction, and the device identifier are associated and stored locally.
  • the test command may also have only one type, and the server may repeatedly send the test instruction until the stability occurring in each metadata generated by the test instruction reaches the first condition.
  • the metadata is up to now.
  • the server since the server only sends one type of test instruction, there is no need to consider the problem of discrimination. It is only necessary to determine that the stability of the metadata generated by the test instruction reaches the first condition, wherein the method for determining stability may be as described above. The method is consistent.
  • the first condition described in the embodiment of the present application may be that the data corresponding to the stability reaches the set first value
  • the second condition may be that the degree of discrimination reaches the second value, and may be other conditions, which are not specifically limited herein. .
  • the server determines the stability and the discrimination of the metadata generated by any test instruction, since the stability is only for the metadata generated by the same test instruction, as long as the server receives the same test instruction.
  • the server can determine the stability of the metadata generated by the test instruction, and when receiving the metadata generated by the test instruction again, update the stable value of the number of elements generated by the test instruction. Since the degree of discrimination exists only when metadata generated by more than one different test instruction occurs, the server can determine the element generated by different test instructions only when the server receives metadata generated by one or more different test instructions. The degree of discrimination of the data.
  • the reference vibration parameter may also be determined by a plurality of metadata by a signal processing method of the prior art, wherein the signal processing method further includes: discrete Fourier Fast method of leaf transform, short-time Fourier transform, wavelet analysis, order analysis, cepstrum, Hilbert transform, warp Traditional signal processing methods such as mode decomposition, eigenmode function, Hilbert yellow transform, etc., of course, the staff can determine the specific signal processing method according to the requirements, which is not specifically limited in this application.
  • various test instructions may cause the terminal to perform different vibration operations, wherein the difference in the vibration operation may include: a frequency of vibration of the vibration motor, a time interval between each vibration, and an intensity of the vibration. As shown in Figure 6.
  • FIG. 6 is a schematic diagram of waveforms corresponding to the vibration operation provided by the embodiment of the present application.
  • the abscissa represents time
  • the ordinate represents the amplitude of vibration in a certain axis direction of the terminal
  • 01 represents the frequency of the vibration
  • 02 represents the vibration time interval
  • 03 represents the vibration intensity
  • the sensor collects the unit time in 01
  • the acceleration changes 12 times, which is the frequency of the vibration.
  • test instructions described in the present application may be preset by a staff member, but since the types of test instructions manually set are limited, and various test instructions do not necessarily exist, the test instructions may be generated.
  • the stability of the number of elements reaches the first condition and the degree of discrimination reaches the test condition of the second condition, so in its own embodiment, the server can also train the test instructions to obtain better test instructions.
  • a genetic algorithm for example, a genetic algorithm, an annealing algorithm, an ant colony algorithm, a particle swarm algorithm, etc. are used to train each test instruction to obtain a test instruction whose stability and the discrimination degree reach a threshold.
  • the server may randomly set the vibration frequency information, the vibration time interval information, and the vibration intensity information of the test command.
  • each account can only communicate with the server based on the hardware of the terminal and perform the service by using the terminal, the terminal can also log in multiple accounts, so the server can only The account status of each account that is already in the login state is monitored, and it is not necessary to monitor all the accounts, thereby reducing the running pressure of the server.
  • the verification trigger command sent by the server to the terminal may carry the account identifier.
  • the server may further determine the device identifier of the terminal that the account is logged in to determine the terminal that the account is logged in.
  • the server may determine the verification trigger instruction corresponding to the account identifier of the account, according to the corresponding relationship between each account identifier, each device identifier, each verification trigger command, and each reference vibration parameter.
  • the account identifier A can correspond to multiple device identifiers, and each device identifier corresponds to different verification trigger instructions and standard information.
  • the server may send the determined verification trigger command corresponding to the account identifier of the account to the account, so that the terminal logged in by the account can perform a subsequent identity verification process.
  • the purpose of the verification triggering instruction is to enable the terminal that the account to log in to return to the server information that can prove identity (ie, metadata for the server to perform. Subsequent authentication step), so the verification triggering instruction can enable the terminal that the account to log in to perform a corresponding operation according to the verification triggering instruction, and return metadata to the server, the device identifier of the terminal, and the verification to trigger the instruction to carry Account ID.
  • the server can receive the verification request carrying the metadata, the account identifier, and the device identifier, the server can determine the reference vibration parameter according to the device identifier and the account identifier. Determine together.
  • the server may pass the stored account identifiers, device identifiers, verification trigger commands, and corresponding reference vibration parameters as shown in Table 1. Determining the reference vibration parameter corresponding to the verification trigger instruction sent in step S201, and the verification trigger instruction that the server may send is the same for different account identification and device identification, but for the same verification trigger instruction, the verification trigger
  • the reference vibration parameters corresponding to different account identifiers and device identifiers may be different, as shown in Table 6. Therefore, in the present application, the reference vibration parameters may also have a one-to-one correspondence with the account identifier and the device identifier.
  • the verification trigger command Prov001 when corresponding to different account identifiers A, B and C, the corresponding reference vibration parameters are also different, and corresponding to the account identifier B, the verification trigger command Prov001 corresponds to different devices. Identifications A003 and A004, the verification trigger commands corresponding to different reference vibration parameters Stand003 and Stand004, respectively.
  • the server needs to determine standard information corresponding to the account identifier, the device identifier, and the verification triggering instruction.
  • the server may also determine different verification triggering instructions for different account identifiers and device identifiers, for example, for the table.
  • the verification trigger command Porv001 in 6 says that the server can also store the corresponding relationship shown in Figure 7.
  • the verification trigger instruction may be different from other verification trigger instructions, so the server may determine and verify the verification only according to the corresponding relationship between each verification trigger instruction and each reference vibration parameter. The only corresponding reference vibration parameter of the trigger command.
  • the foregoing only enumerates two implementation manners, and the application does not specifically limit how to determine the corresponding reference vibration parameter by using the verification triggering instruction, as long as the verification triggering instruction can determine the reference vibration parameter corresponding to the account identifier and the device identifier. Just fine.
  • the reference vibration parameter is also in one-to-one correspondence with the account identifier, the device identifier, and the verification triggering instruction. Therefore, the reference vibration parameter can be considered to correspond to the metadata, so after the server receives the metadata and determines the corresponding reference vibration parameter, the server can determine whether the reference vibration parameter and the metadata are Consistent to determine if the authentication for the account has passed.
  • the execution bodies of the steps of the method provided by the embodiments of the present application may all be the same device.
  • the method is also performed by a different device.
  • the execution subject of step S201 and step S202 may be device 1
  • the execution subject of step S203 may be device 2
  • the execution subject of step S201 may be device 1
  • the execution subject of step S202 and step S203 may be device 2
  • the server can be a distributed server composed of multiple devices.
  • the embodiment of the present application further provides an apparatus for identity verification, as shown in FIG. 7.
  • FIG. 7 is a schematic structural diagram of an apparatus for identity verification according to an embodiment of the present disclosure, including:
  • the receiving module 301 receives a verification trigger command sent by the server
  • the vibration module 302 performs a vibration operation according to the verification trigger instruction
  • An acquisition module when the vibration module 302 performs a vibration operation according to the verification trigger instruction, collecting metadata generated when the vibration operation is performed;
  • the sending module 303 is configured to send, to the server, an authentication request that carries the metadata and the device identifier of the device, where the verification request is used to request the server to use the device according to the metadata and the device identifier of the device.
  • the user of the device authenticates.
  • the vibration module 302 determines at least one of vibration frequency information, vibration time interval information, and vibration intensity information included in the verification trigger instruction, according to the vibration frequency information, the vibration time interval information, and the vibration At least one of the intensity information performs a vibration operation.
  • the acquisition module collects the vibration acceleration and/or the vibration angular velocity of the terminal, and performs the vibration acceleration and/or the vibration angular velocity as the terminal Metadata generated during the vibration operation.
  • the receiving module 301 the terminal sends status information to the server, and the terminal receives the verification trigger instruction sent by the server, where the verification trigger instruction is sent when the server determines that the status information is abnormal.
  • the verification triggering instruction carries an account identifier; the sending module 303, when transmitting the metadata and the device identifier of the device to the server, The account identifier of the terminal is sent to the server in the verification request, and the verification request is used to request the server to use the device according to the metadata, the device identifier of the device, and the account identifier.
  • the user authenticates.
  • the device for authenticating as shown in FIG. 7 may be located in a terminal, and the terminal may be a device such as a mobile phone or a tablet computer.
  • the embodiment of the present application further provides a device for performing identity verification performed by the terminal, as shown in FIG. 8.
  • FIG. 8 is a schematic structural diagram of another apparatus for authenticating according to an embodiment of the present disclosure, including:
  • the sending module 401 is configured to send a verification trigger instruction to the terminal, where the verification trigger instruction is used to instruct the terminal to perform a vibration operation according to the verification trigger instruction;
  • the receiving module 402 is configured to receive the metadata sent by the terminal and the device identifier of the terminal, where the metadata is collected by the terminal when performing the vibration operation;
  • the determining module 403 determines, according to a correspondence between the preset device identifier and the reference vibration parameter, a reference vibration parameter corresponding to the received device identifier of the terminal;
  • the verification module 404 performs identity verification on the user using the terminal according to the reference vibration parameter and the metadata.
  • the device also includes:
  • the test module 405 is configured to preset a correspondence between the device identifier and the reference vibration data.
  • the test module 405 sends at least one test instruction to the terminal, where the test instruction is used to instruct the terminal to collect metadata generated when the vibration operation is performed when performing a vibration operation according to the test instruction,
  • the test instruction includes at least one of vibration frequency information, vibration time interval information, and vibration intensity information, and receives the metadata generated by the terminal for each of the test instructions and a device identifier of the terminal, according to the Deriving the metadata generated by the test instruction to determine a reference vibration parameter of the terminal, wherein the reference vibration parameter includes a vibration acceleration and/or a vibration angular velocity, and establishing a device identifier of the terminal and the determined reference vibration parameter Correspondence between the two.
  • the test module 405 when determining that the quantity of the metadata generated by the test instruction reaches a threshold, determining a reference vibration parameter for the terminal according to the average value of the generated metadata, or determining the test An average of the differences between the different metadata generated by the instructions, and when the average of the differences is less than the set threshold, determining an average of the metadata as a reference vibration parameter for the terminal.
  • the test module 405 performs the following operations for the same test command: determining, for the test command Determining an average value of at least one of the metadata generated by the terminal, using the average value as a reference vibration parameter of the terminal when the test instruction is satisfied, and obtaining, by the server, different reference vibrations corresponding to the test instruction
  • the parameter establishes a correspondence between the device identifier of the terminal and the obtained reference vibration parameter.
  • the sending module 401, the vibration frequency information, the vibration time interval information, and the vibration intensity information included in the test instruction sent to the terminal are preset, or the vibration frequency information, the The vibration time interval information and the vibration intensity information are randomly generated.
  • the test module 405 calculates the at least one metadata generated by the terminal for the same test instruction before establishing a correspondence between the device identifier of the terminal and the obtained reference vibration parameter. Differentiating the difference between the metadata, and determining the stability of the test instruction generating metadata according to the sum of the differences, when different reference vibration parameters corresponding to the test instruction are obtained, according to different The average value of the metadata generated by the test instruction determines different degrees of discrimination of the test instruction, and from the different reference vibration parameters corresponding to the different test instructions, the selection stability is greater than the first condition and the distinction is The reference vibration parameter corresponding to the test instruction of the second condition is greater than the reference vibration parameter of the second condition, and the correspondence between the terminal identifier of the terminal device and the selected reference vibration parameter is established.
  • the sending module 401 sends a verification trigger instruction corresponding to the account identifier to the terminal, and the receiving module 402 receives the sent by the terminal.
  • the determining module 403 determines, according to the correspondence between the preset device identifier, the account identifier, and the reference vibration parameter, the metadata, the account identifier, and the device identifier of the terminal, and the received terminal.
  • the device identification corresponds to the reference vibration parameter.
  • the device for authenticating as shown in FIG. 7 may be located in a server, and the server may be a device or a system composed of multiple devices, that is, a distributed server.
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
  • computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the device is implemented in a flow or a block diagram of a flow or a block diagram or The functions specified in multiple boxes.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
  • a computing device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
  • processors CPUs
  • input/output interfaces network interfaces
  • memory volatile and non-volatile memory
  • the memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium, such as read only memory (ROM) or flash memory.
  • RAM random access memory
  • ROM read only memory
  • Memory is an example of a computer readable medium.
  • Computer readable media includes both permanent and non-persistent, removable and non-removable media.
  • Information storage can be implemented by any method or technology.
  • the information can be computer readable instructions, data structures, modules of programs, or other data.
  • Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, Magnetic tape cartridges, magnetic tape storage or other magnetic storage devices or any other non-transportable media can be used to store information that can be accessed by a computing device.
  • computer readable media does not include temporary storage of computer readable media, such as modulated data signals and carrier waves.
  • embodiments of the present application can be provided as a method, system, or computer program product.
  • the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment in combination of software and hardware.
  • the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Power Engineering (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Telephonic Communication Services (AREA)
  • Telephone Function (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请公开了一种身份验证的方法,终端可以根据服务器发送验证触发指令执行振动操作,并将执行振动操作时采集的该振动操作对应的元数据返回该服务器,使得该服务器可根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的该终端的设备标识对应的参考振动参数,并根据该参考振动参数以及该元数据,对使用该终端的用户进行身份验证。可见通过本申请实施例提供的方法,用户无需任何操作该终端即可完成元数据的采集以及返回,并且,该用户也无需采集自己的生物信息,避免了现有技术中涉及个人隐私的问题,并且简化了用户操作,提高了身份验证的效率。

Description

一种身份验证的方法及装置
本申请要求2016年08月31日递交的申请号为201610798122.9、发明名称为“一种身份验证的方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及信息技术领域,尤其涉及一种身份验证的方法及装置。
背景技术
随着信息化社会的发展,人们越来越依赖于网络执行各种业务,而随着移动终端的功能越来越强大,人们开始更多的使用移动终端通过网络执行各种业务。于是,如何更好的在移动终端上提供各种业务也就成了近年来关注的热点,其中,如何保证用户在使用移动终端执行业务时的安全性(以下简称安全性)更是其重中之重。
具体的,用户可先在终端上登录持有的账号,再通过网络与提供服务的服务器建立数据连接,并执行各种业务。如图1所示,为现有技术中终端通过网络连接服务器的示意图。其中,该终端为登录了账号的终端,所以可以视为是该终端通过账号与该服务器建立了数据连接,从图1中可见一个服务器可为多个账号提供服务,不论该账号在哪一个终端上登录,均可以通过该账号向该服务器验证自己的身份。于是,在现有技术中,可对该终端上登录的账号的身份进行验证,并使只有通过身份验证的账号才能执行业务,从而保证安全性。
进一步地,人们一般采用身份验证的方法,防止非账号持有人通过该账号执行业务,从而保证业务执行的安全性。随着生物识别技术的发展以及传感器技术的进步,由于对每一个人来说,个人的生物信息是唯一的,所以使用用户的生物信息进行身份验证的准确性更高,并且由于无需进行传统的密码输入过程,使得身份验证的效率也得到了提高。
于是,现有技术开始根据生物信息进行身份验证。
具体的,服务器将预先采集并存储账号持有人的生物信息(如,指纹信息、声纹信息、虹膜信息、相貌信息等)作为该账号对应的标准生物信息,其中,该生物信息可由移动终端的传感器采集,而在每一次进行身份验证时,使移动终端重新采集该生物信息并作为该账号的待验证生物信息并发送至该服务器,则该服务器可以根据已存储的标准 生物信息,判断该待验证生物信息与该标准生物信息是否一致,并依据判断结果确定身份验证是否通过。
但是,由于终端在采集用户的生物信息时,往往需要用户主动的操作该终端,以使得该终端采集用户的生物信息(如,使用手指按压传感器、使眼部正对摄像头、对麦克风说话等等),所以采用生物信息进行身份验证时增加了用户操作,使得身份验证过程变得繁琐。
进一步地,生物信息的采集通常对采集环境有一定的要求,例如,手指沾水则可能导致指纹采集失败、环境太吵闹则可能导致声纹采集失败、环境光线太暗则可能导致虹膜信息采集失败,进而导致身份验证失败的可能性增加,降低了身份验证的效率。
综上,可见现有的身份验证技术存在身份验证效率低的问题。
发明内容
本申请实施例提供一种身份验证的方法,用于解决在采用现有技术进行身份验证时,存在用户操作繁琐、用户使用意愿不高、对采集环境要求较高、身份验证效率低等问题。
本申请实施例提供一种身份验证的装置,用于解决在采用现有技术进行身份验证时,存在用户操作繁琐、用户使用意愿不高、对采集环境要求较高、身份验证效率低等问题。
本申请实施例采用下述技术方案:
一种身份验证的方法,包括:
终端接收服务器发送的验证触发指令,所述验证触发指令用于指示所述终端执行振动操作;
所述终端在根据所述验证触发指令执行振动操作时,采集在执行所述振动操作时产生的元数据;
所述终端将携带所述元数据和所述终端的设备标识的验证请求发送至服务器,所述验证请求用于请求所述服务器根据所述元数据和所述终端的设备标识对使用所述终端的用户进行身份验证。
一种身份验证的方法,包括:
服务器向终端发送验证触发指令,所述验证触发指令用于指示所述终端在根据所述验证触发指令执行振动操作时采集在执行所述振动操作时产生的元数据;
所述服务器接收所述终端发送的所述元数据以及所述终端的设备标识;
所述服务器根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的 所述终端的设备标识对应的参考振动参数;
根据所述参考振动参数以及所述元数据,对使用所述终端的用户进行身份验证。
一种身份验证的装置,包括:
接收模块,接收服务器发送的验证触发指令;
振动模块,根据所述验证触发指令执行振动操作;
采集模块,在所述振动模块根据所述验证触发指令执行振动操作时,采集在执行所述振动操作时产生的元数据;
发送模块,将携带所述元数据和所述装置的设备标识的验证请求发送至服务器,所述验证请求用于请求所述服务器根据所述元数据和所述装置的设备标识对使用所述装置的用户进行身份验证。
一种身份验证的装置,所述装置包含振动马达以及传感器,包括:
发送模块,向终端发送验证触发指令,所述验证触发指令用于指示所述终端在根据所述验证触发指令执行振动操作时采集在执行所述振动操作时产生的元数据;
接收模块,接收所述终端发送的所述元数据以及所述终端的设备标识;
确定模块,根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数;
验证模块,根据所述参考振动参数以及所述元数据,对使用所述终端的用户进行身份验证。
本申请实施例采用的上述至少一个技术方案能够达到以下有益效果:
终端可以根据服务器发送验证触发指令执行振动操作,并将执行振动操作时采集的该振动操作对应的元数据返回该服务器,使得该服务器可根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的该终端的设备标识对应的参考振动参数,并根据该参考振动参数以及该元数据,对使用该终端的用户进行身份验证。可见通过本申请实施例提供的方法,用户无需任何操作该终端即可完成元数据的采集以及返回,并且,该用户也无需采集自己的生物信息,避免了现有技术中涉及个人隐私的问题,并且简化了用户操作,提高了身份验证的效率。
附图说明
此处所说明的附图用来提供对本申请的进一步理解,构成本申请的一部分,本申请的示意性实施例及其说明用于解释本申请,并不构成对本申请的不当限定。在附图中:
图1为现有技术中终端通过网络连接服务器的示意图;
图2为本申请实施例提供的身份验证的过程;
图3为本申请实施例提供的另一种身份验证的过程;
图4a~图4c为本申请实施例提供的服务器向终端发送验证触发指令并使该终端返回元数据的过程示意图;
图5为本申请实施例提供的终端的加速度传感器采集加速度变化量的示意图;
图6为本申请实施例提供的振动操作对应的波形示意图;
图7为本申请实施例提供的一种身份验证的装置的结构示意图;
图8为本申请实施例提供的另一种身份验证的装置的结构示意图。
具体实施方式
为使本申请的目的、技术方案和优点更加清楚,下面将结合本申请具体实施例及相应的附图对本申请技术方案进行清楚、完整地描述。显然,所描述的实施例仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
以下结合附图,详细说明本申请各实施例提供的技术方案。
图2为本申请实施例提供的身份验证的过程,具体包括以下步骤:
S101:终端接收服务器发送的验证触发指令,所述验证触发指令用于指示所述终端执行振动操作。
由于通常身份验证过程的发起方通常是服务器,所以在本申请实施例中,该终端可以接收服务器发送的验证触发指令,并且该终端接收到的验证触发指令可以是当该服务器确定该终端发送的状态信息出现异常时发送的。
具体的,该终端向该服务器发送自身的状态信息,其中,该状态信息可以包含:该终端的mac地址信息、ip地址信息、地理位置信息、业务信息等等,也就是说该状态信息是可以反映该终端所处状况的各类信息(该终端所处状况通常可归类为:该终端所处环境状况,如,地理位置信息、时间信息等,以及该终端运行状况,如,系统版本号、ip地址信息、业务信息等,当然,本申请也不限定仅有上两类状况可作为该终端的状态信息),具体该状态信息包含何种信息可根据实际需求设置,本申请并不做具体限定,另外,需要说明的是,该业务信息可以是业务执行请求等与业务相关的信息,具体可以是该终端正在执行的业务的相关信息。于是,该终端可以在该服务器根据该终端的历史 状态信息判断该终端发送的状态信息出现异常时,接收到该服务器发送的验证触发指令。
进一步地,该验证触发指令用于指示该终端执行振动操作。
具体的,该验证触发指令中可以是脚本语言(JavaScript,JS)代码,则当该终端接收到该验证触发指令后,通过运行该JS代码,可确定该验证触发指令中包含的振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种,之后该终端可再根据该振动频率信息、该振动时间间隔信息以及该振动强度信息中的至少一种,执行振动操作。
该振动操作可以由该终端中的振动马达执行。由于该振动触发指令可以包含振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种,所以该振动马达在执行该振动操作时,可仅根据振动频率信息、振动时间间隔信息或者振动强度信息执行振动操作。当然,当该振动触发指令中包含准确的振动频率信息、振动时间间隔信息以及振动强度信息时,该振动马达执行的振动操作更加精准,更有利于后续的步骤的操作以及最终身份验证的结果准确性。
需要说明的是,该终端可以是手机、平板电脑等包含振动马达的且可由用户手持的终端。
S102:所述终端在根据所述验证触发指令执行振动操作时,采集在执行所述振动操作时产生的元数据。
在本申请实施例中,该终端在接收到该验证触发指令后,便可根据该验证触发指令确定振动操作,并使该终端的振动马达执行该振动操作,同时该终端的传感器还可以采集该振动马达在执行该振动操作时产生的该振动操作的元数据。
具体的,由于该振动马达是该终端的一部分,所以以该终端为一个整体来看,该振动马达在执行振动操作时使该终端整体产生了振动,该振动体现在该终端整体的加速度变化以及角速度变化,则该终端的传感器可采集到的由于该振动马达执行该振动操作所产生的振动加速度和/或振动角速度,或者由于该振动操作所产生的振动加速度和/或振动角速度变化,并将该振动加速度和/或该振动角速度作为该终端在执行该振动操作时产生的元数据。
并且,由于每一个用户握持终端的姿势(如,手掌的姿势、手臂的姿势等)、握持不同终端的姿势以及终端的重量等等因素,均可以影响到该终端的传感器采集到的该振动马达执行该振动操作所产生的振动加速度和/或振动角速度,而每一个用户握持终端的姿势具有唯一性(即,出现两个用户握持同一终端的姿势完全相同的几率极低),所以该终端采集到的该振动操作的元数据可以是唯一对应于每一个用户和终端的元数据,即, 该元数据具有全局唯一性。于是,该元数据可以作为对使用该终端的用户进行身份验的数据。
另外,由于该验证触发指令可以是JS代码,所以该终端的传感器也可以是通过运行该JS代码,采集该终端的振动加速度和/或振动角速度,并将该振动加速度和/或该振动角速度作为该终端在执行该振动操作时产生的元数据。
需要说明的是,该传感器可包括:加速度传感器、重力传感器、磁力传感器、方向传感器、陀螺仪传感器、光线传感器、压力传感器、温度传感器、接近传感器、线性加速度传感器、旋转矢量传感器、全球定位系统(Global Positioning System,GPS)传感器、心率传感器、血氧传感器、紫外线传感器等。该终端的振动马达可有至少一个,即,在该终端中可有多个振动马达,并且当该终端中的振动马达有多个时,各振动马达可根据该验证触发指令执行不同的振动操作。
于是,该终端采集的可以不仅仅是该振动加速度和/或该振动角速度,还可以是其他由振动产生的数据,具体可根据需要对该振动触发指令进行设置,本申请对此不作具体限定。
需要说明的是,本申请并不限定以该验证触发指令中携带JS代码,只要该验证触发指令可以实现使该终端的振动马达执行对应操作,以及使该终端的传感器采集数据即可。
S103:所述终端将携带所述元数据和所述终端的设备标识的验证请求发送至服务器。
在本申请实施例中,当该终端确定了元数据之后,便可将携带该元数据和该终端的设备标识的验证请求发送至该服务器,并使该服务器根据该元数据和该终端的设备标识对使用该终端的用户进行身份验证。
另外,由于现有技术中还存在其它多种的身份验证方法(如根据地理位置信息、用户行为习惯信息等进行身份验证的方法),所以本申请所述的身份验证过程所确定的结果也可与其他的身份验证方法确定的结果结合使用,即,该服务器可以利用多种身份验证方法得出的身份验证结果,对该终端进行身份验证,如,通过3种方法,均判断该终端的身份验证不通过,则该终端的安全性非常低,很有可能已经被不法分子盗用。
当然,具体的如何利用本申请确定的身份验证结果,本申请并不做限定。
通过如图2所示的身份验证的方法,可见该终端在接收服务器发送的验证触发指令后,用户无需对该终端执行任何操作,该终端便可向该服务器返回元数据以及该终端的设备标识,从而使该服务器根据该元数据和该终端的设备标识对使用该终端的用户进行身份验证。其中,由于对于每一个用户来说,该用户握持终端的姿势与其他用户握持该 终端的姿势完全相同的几率极低,而该用户握持该终端的姿势对于该终端的传感器采集的该振动马达执行振动操作产生的元数据必定产生一定的影响,所以通过该元数据可以对是否是该用户在握持该终端进行区分,进而对使用该终端的用户进行身份验证。可见,本申请实施例提供的方法,可以无需用户操作便完成身份验证的过程,并且由于采集的虽然是该对应于该用户唯一的信息,但是不是该用户的生物信息不涉及该用户的个人隐私,所以更加容易使用户接受,运行成本更低,且对采集环境几乎无要求,身份验证效率更高。
另外,由于针对同一终端,该终端上可以登陆多个账号,则在步骤S101中该终端接收到的该验证触发指令中可携带账号标识,则当该终端在步骤S102中确定了元数据之后,该终端在将携带该元数据、该终端的设备标识发送给服务器时,还可将该终端的账号标识携带者所述验证请求中发送至该服务器,该验证请求用于请求该服务器根据该元数据、该终端的设备标识以及该账号标识,对使用该终端的用户进行身份验证。
基于图2所示的身份验证过程,本申请实施例还对应提供一种服务器执行的身份验证的方法,如图3所示。
图3是本申请实施例提供的一种身份验证的过程,具体包括以下步骤:
S201:服务器向终端发送验证触发指令。
在现有技术中,服务器通常在根据终端发送的业务请求执行对应的业务之前,需要先进行身份验证过程,以便证明该业务请求是由该终端的持有人发送的,所以在本申请中的身份验证过程,实际上就是验证该终端是否是由该终端的持有人在使用,即,对使用所述终端的用户进行身份验证。
于是,在本申请实施例中,该服务器首先可确定向该终端发送验证触发指令的时机。
具体的,由于实际应用环境中如图1所示,该服务器可与多个终端建立通讯连接,并接收各终端发送的状态信息,所以,该服务器可接收各终端的状态信息,并针对每一个状态信息异常的终端,根据已存储的各设备标识、各验证触发指令以及各参考振动参数的对应关系,确定该终端的设备标识对应的验证触发指令,并向该终端发送该验证触发指令。
其中,针对每一个终端,该服务器可接收该终端发送的状态信息,当确定该终端发送的状态信息出现异常时,该服务器便可向该终端发送验证触发指令,另外,该状态信息在步骤S101中已经进行相应说明,不再赘述。需要说明的是,确定各终端的状态信息是否异常的方法,可与现有技术一致,如,根据该终端的历史地理位置信息、历史业务 信息等等确定各终端的状态信息是否异常,本申请对此并不做具体限定。
进一步地,由于身份验证的最终目的是保证执行业务时的安全性,所以在该终端发起业务请求以及当该账号登录终端时,该服务器也可以向该终端发送验证触发指令,而无需确定该终端发送的状态信息出现异常,当然,具体发送该验证触发指令的时机也可根据需求进行设置,本申请对该验证触发指令的发送时机并不做具体限定。
更进一步地,该服务器可以是单独的一台设备,也可是由多台设备组成的系统(如,分布式系统)。
例如,假设服务器X监测如表1所示的各设别标识分别对应的各终端的状态信息。
设备标识 验证触发指令 参考振动参数
A001 Prov001 Stand001
A002 Prov002 Stand002
A003 Prov003 Stand003
A004 Prov004 Stand004
A005 Prov005 Stand005
表1
其中,该设备标识可以是用于标识该终端的唯一性的(相当于该终端的身份标识),例如,mac地址、国际移动设备标识(International Mobile Equipment Identity,IMEI)、主板的身份标识号等等,并且该设备标识也可是生产该终端的厂家为该终端添加的唯一识别码,例如,生产编号、产品序列号等等。并且通常该终端的该设备标识都可以被读取,以便通过该设备标识确定该终端的身份,所以在本申请中,并不限定该设备标识的具体形式,只要通过该设备标识可以唯一的确定该终端即可。
并且,该服务器X接收到了设备标识为A001的终端发送的业务执行请求,则该服务器X可确定需要向该设备标识为A001的终端发送验证触发指令,进一步地,该服务器X可根据该设备标识:A001通过表1确定向该设备标识为A001的终端发送的验证触发指令为:Prov001。
更进一步地,该验证触发指令可使该设备标识为A001的终端的振动马达执行该验证触发指令Prov001对应的振动操作,而该终端的传感器则可将采集的该振动操作的元数据返回该服务器X,上述过程示意图可如图4a~图4c所示。
图4a~图4c为本申请实施例提供的服务器向终端发送验证触发指令并使该终端返回元数据的过程示意图,其中可见图4a为该服务器向该终端发送验证触发指令,图4b为 该验证触发指令使得该终端的振动马达执行与该验证触发指令对应的振动操作,图4c为使该终端向该服务器返回元数据。
S202:所述服务器接收所述终端发送的所述元数据以及所述终端的设备标识。
S203:所述服务器根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数。
在本申请实施例中,当该服务器在向任一终端发送了验证触发指令之后,该服务器还可接收到该终端返回的元数据以及该终端的设备标识,于是,后续该服务器可以进一步通过该元数据来对该终端进行身份验证。
具体的,该服务器在接收到该元数据以及该设备标识后,便可通过如表1所示的已存储的各设备标识、各验证触发指令以及各参考振动参数的对应关系,确定与该设备标识对应的参考振动参数。其中,需要说明的是,该已存储的各设备标识、各验证触发指令以及各参考振动参数的对应关系可以是该服务器预先设置并存储的,即,针对每一个设备标识,先确定该设备标识对应的验证触发指令以及参考振动参数,之后再将该设备标识、该验证触发指令以及该参考振动参数以及该对应关系存储在该服务器中。
进一步地,由于该服务器需要预先确定该终端的设备标识对应的参考振动参数,所以为了确定该设备标识与该参考振动参数之间的关系,该服务器还可以向该终端发送测试指令,并接收该终端返回的该测试指令产生的元数据,并将该元数据作为针对该终端的参考振动参数,最终建立并存储该设备标识、参考振动参数以及验证触发指令的对应关系。
更进一步的,由于任何数据采集过程都可能出现误差,所以为了减少参考振动参数的误差,提高该参考振动参数的准确性,针对同一测试指令,该服务器还可以通过重复向该终端发送该测试指令,并接收每一个测试指令产生的元数据,来减少确定的针对该终端的参考振动参数的误差,也就是说,该参考振动参数可以是由多个元数据确定的。
具体的,该服务器可以向该终端发送至少一个测试指令,并接收该终端返回的针对每一个测试指令产生的元数据以及该终端的设备标识,再根据各测试指令产生的元数据确定针对该终端的参考振动参数,并确定产生该的参数的测试触发指令为验证触发指令,最后建立并存储该设备标识、验证触发指令以及该参考振动参数的对应关系。
其中,在确定针对该终端的参考震动参数时,该服务器可以判断根据接收到的该终端返回的针对每一个测试指令产生的元数据的数量是否达到阈值,若是,则根据各元数据的平均值,确定针对该终端的参考振动参数,若否,则继续向该终端发送测试指令, 直到接收到的该终端返回的针对每一个测试指令产生的元数据的数量达到阈值为止,即,接收预设数量的该测试指令产生的元数据,并对各元数据取平均值作为针对该终端的参考振动参数。
或者,该服务器针对每一个测试指令产生的元数据,确定各元数据之间的差值的平均值,并判断该差值的平均值是否小于设定门限值,若是,则确定各元数据的平均值为针对该终端的参考振动参数,若否,则继续向该终端发送测试指令,直到确定各元数据之间的差值平均值小于该设定门限值为止。当然,现有技术中还存在更多的确定误差更小,更加准确的参考振动参数的方法,本申请对采用何种方法并不做具体限定,上述仅为本申请提供的两种实施方式。
其中,该测试指令的发送时机可随机确定或者由人工根据经验确定(例如,在接收到该终端发送的任意信息时,向该终端发送测试指令),其中,由于该测试指令可以重复发送多次,所以即使随机确定该测试指令的发送时机也不会影响到最终确定的针对该终端的参考振动参数,当然,由于该参考振动参数的准确与否可影响到身份验证的准确性,所以处于替考该参考振动参数准确性的考虑,该服务器可在发送该测试指令之前采用与现有技术一致的方法确定该终端的身份验证结果,并且当该身份验证结果为通过时,发送该测试指令,即,本申请并不限制何时发送该测试指令。
另外,如本申请在步骤S102中所述该终端可将振动加速度、振动角速度等作为元数据,并且还可通过多种传感器采集其他数据作为元数据,所以在本申请中,该服务器在确定针对该终端的参考振动参数时,该参考振动参数也可包含振动加速度和/或振动角速度,以及其他数据,本申请对此不再赘述。
继续沿用上例,假设该设备标识为A001的终端返回的元数据为Z,该服务器根据该设备标识A001通过表1所示的对应关系确定该设备标识对应的参考振动参数为Stand001。
S204:根据所述参考振动参数以及所述元数据,对使用所述终端的用户进行身份验证。
在本申请实施例中,当该服务器确定与接收到的该终端的设备标识对应的参考振动参数之后,便可根据该参考振动参数以及该元数据,对使用该终端的用户经行身份验证。
具体的,该服务器可以对比该参考振动参数以及该元数据的相似度,若相似度在规定的范围内,则可确定使用该终端的用户的身份可信度较高,若相似度不在规定的范围内,则可确定使用该终端的用户的身份可信度较低的。当确定该用户的身份可信度较高 时,当该终端发送的执行业务请求时,该终端可以执行对应的业务。
而当确定该用户的身份可信度较低时,说明该终端存在较高风险,对于该终端发送的业务执行请求等信息需要谨慎处理(例如,当该服务器接收到该终端发送的执行业务请求时,该服务器还可通过与现有技术相同的其他身份验证方法进一步对使用该终端的用户进行身份验证,并最终确定是否执行该业务请求对应的业务),或者该服务器也可将该身份验证结果用于风险控制中等等,即,该服务器可以灵活的利用本申请确定的身份验证结果,当然具体后续如何操作本申请并不做具体限定。
进一步的,该服务器在对比该参考振动参数以及该元数据的相似度时,由于该参考振动参数和该元数据均是由该终端的传感器采集的数据,并且该终端的传感器可以由有多个,所以该参考振动参数和该元数据仅可包含多种数据,为了方便描述,以下仅以该终端的加速度传感器采集的数据为例进行说明。
由于在步骤S201中该验证触发指令使得该终端的振动马达根据该服务器发送的验证触发指令执行了振动操作,所以根据该终端的振动马达的振动方式,该终端的加速度传感器可以在如图5中所示的该终端的x轴、y轴以及z轴方向上测得该终端的加速度的变化量,其中该加速度的变化量可以包含加速度的最大值、最小值、最大值出现时间、最小值出现时间、每一次加速的变化之间的时间间隔等等数据,并将该加速度的变化量,与该参考振动参数中包含的加速度变化量进行对比。
图5为本申请实施例提供的终端的加速度传感器采集加速度变化量的示意图。
进一步地,由于用户在每一次握持终端时使用的力量,姿势不可能完全一致,所以该元数据与该参考振动参数之间可能存在细微差别,所以在本申请中判断该元数据与该参考振动参数是否相似时,该服务器可以判断在该元数据与该参考振动参数的相似度是否在规定的范围内,其中,该规定的范围可以由工作人员根据经验设定。
具体的,该元数据与该参考振动参数的相似度是否在规定的范围内,具体可以是该元数据与该参考振动参数之间的差值是否超出了该规定的范围(如2%),则判断该元数据的数值是否落入该参考振动参数数值的±2%范围之内。并且,由于该加速度传感器可以采集多种数据,如仅以该加速度传感器来说,便可采集到加速度的最大值、最小值、最大值出现时间、最小值出现时间等多种数据,所以判断相似度是否在规定的范围内,还可以是确定该元数据与该参考振动参数相似度在规定的范围内的数据种类所占的比例是否达到预设的阈值(例如,确定75%的数据的相似度在规定的范围内,则只要该加速度的最大值、最小值、最大值出现时间、最小值出现时间中有3种数据的相似度在规定 的范围内即可确定该元数据与该参考振动参数的相似度在规定的范围内)。
继续沿用上例,假设该服务器X确定该参考振动参数Stand001与该元数据Z如表2所示。
Figure PCTCN2017097955-appb-000001
表2
并且假设该服务器X需要判断该元数据与该参考振动参数的相似度是否在0.2%的范围内,则该参考振动参数的加速度的最大值范围可以是:0.1002~0.0998G/s;最大值出现时间点范围可以是:0.1002~0.0998s;加速度的最小值范围可以是:0.0001002~0.0000998G/s;最小值出现时间点的范围可以是:0.501~0.499s。则该服务器X可以确定该元数据落入了该参考振动参数的范围内,即,该元数据与该参考振动参数的相似度在规定的范围内,确定使用该终端的用户的身份可信度较高,其中,该最大加速度出现时间点为该终端根据对应的测试指令执行振动的时间点至采集到该的最大加速度的时间点之间的时长,同理,该最小加速度出现时间点是该终端根据对应的测试指令执行振动的时间点至采集到该的最小加速度的时间点之间的时长。
进一步地,由于现有技术中还存在其它多种的身份验证方法(如根据地理位置信息、用户行为习惯信息等进行身份验证的方法),所以本申请所述的身份验证过程也可与其他的身份验证过程结合使用,即,该服务器可以利用多种身份验证方法得出的身份验证结果,对该终端进行身份验证,如,通过3种方法,均判断该终端的身份验证不通过,则该终端的安全性非常低,很有可能已经被不法分子盗用。
当然,具体的如何利用本申请确定的身份验证结果,本申请并不做限定。
需要说明的是,如表2所示的元数据Z的类型(即,最大加速度、最大加速度出现时间点、最小加速度、最小加速度出现时间点这四类),仅为本申请提供的实施例,在实际应用过程中,该元数据的类型还可以有多种(如,高于设定阈值的加速度出现的次数、高于设定阈值的加速度出现的时长等等),本申请并不限定该元数据的类型,只要该终端的传感器可以采集到的该振动的元数据均可以作为本申请中所述的元数据。
通过如图3所示的身份验证的方法,可见该终端在接收服务器发送的验证触发指令 后,用户无需对该终端执行任何操作,该终端便可向该服务器返回元数据以及该终端的设备标识,从而使该服务器根据该元数据和该终端的设备标识对使用该终端的用户进行身份验证。其中,由于对于每一个用户来说,该用户握持终端的姿势与其他用户握持该终端的姿势完全相同的几率极低,而该用户握持该终端的姿势对于该终端的传感器采集的该振动马达执行振动操作产生的元数据必定产生一定的影响,所以通过该元数据可以对是否是该用户在握持该终端进行区分,进而对使用该终端的用户进行身份验证。可见,本申请实施例提供的方法,可以无需用户操作便完成身份验证的过程,并且由于采集的虽然是该对应于该用户唯一的信息,但是不是该用户的生物信息不涉及该用户的个人隐私,所以更加容易使用户接受,运行成本更低,且对采集环境几乎无要求,身份验证效率更高。
另外,在本申请步骤S201中,由于该服务器向终端发送验证触发指令时,需要该服务器接收该终端发送的状态信息,所以为了减轻该服务器的运行压力,本申请所述的身份验证过程也可由该终端主动发起,即,该终端向服务器发送身份验证请求,该身份验证请求使得该服务器向该终端发送验证触发指令。
当然,不论是由该终端还是该服务器发起身份验证的过程,对身份验证的过程并无本质区别,该服务器具体通过何种方法确定向该终端发送验证触发指令,可采用与现有技术中进行身份验证时一致的方法,本申请对此并不做具体限定。
进一步地,本申请实施例中,由于该服务器对终端进行身份验证时,是通过判断该参考振动参数与该元数据相似度是否在规定的范围内,来对使用所述终端的用户进行身份验证,所以该参考振动参数的准确与否,就密切关系到本申请所述的身份验证过程的准确性。
而对于一个设备标识、验证触发指令和参考振动参数的对应关系来说,该参考振动参数是该终端根据该测试指令执行振动操作时采集在执行所述振动操作时产生的元数据而确定的,但是,如果该测试指令使得该终端在根据该验证触发指令执行振动操作时采集在执行该振动操作时产生的元数据的稳定性低、区分度低,则可造成身份验证的准确性低。
其中,当该参考振动参数的稳定性低时,针对该验证触发指令,即使使用该终端的用户为同一人,该终端返回的元数据与该参考振动参数的相似度也可能不在规定的范围内。而当该参考振动参数的区分度低,针对该验证触发指令,即使使用该终端的用户不是同一人,该终端返回的元数据与该参考振动参数的相似度也可能在规定的范围内,可 见当确定的该参考振动参数的稳定性低、区分度低时,本申请所述的身份验证过程容易出现误判和漏判的情况。
于是,所以为了使该参考振动参数更加准确,以使得身份验证的准确度更高,在本申请中,针对每一个终端,该服务器在测试确定针对该终端的参考振动参数时,可以通过向该终端重复发送多种测试指令,即针对每一种测试指令,该服务器向该终端重复发送,则该服务器可接收该终端返回的多种测试指令产生的元数据,并确定稳定性达到第一条件且区分度达到第二条件的测试指令产生的元数据确定为针对所述终端的参考振动参数,建立并存储将该设备标识、该验证触发指令以及该参考振动参数的对应关系,以便后续进行身份验证过程时,可以以该参考振动参数对该终端进行身份验证。其中,该第一条件和该第二条件可以是分别根据人工经验进行设置的数值。
具体的,对于测试指令产生的元数据的稳定性来说,该服务器可在得到针对同一个测试指令该终端产生的至少一个元数据时,通过计算得到的不同所述元数据之间的差值之和,并根据所述差值之和确定所述测试指令产生元数据的稳定性。对于测试指令产生的元数据的区分度来说,该服务器在得到不同的所述测试指令对应的元数据时,可先确定不同的测试指令产生的元数据的平均值,并且针对每一个测试指令,确定该测试指令产生的元数据的平均值与其他测试指令产生的元数据的平均值之间的差值,再将确定的差值之和作为该测试指令产生的元数据的区分度,则可确定不同的测试指令的区分度。
另外,由在本申请中该身份验证过程的目的是,确定该终端的使用人是否是发送测试指令时该终端的持有人,所以对本申请所述的方法来说,仅需验证该用户是否为发送测试指令时该终端的持有人即可,而无需验证该终端的使用人是什么人。
在本申请中,对于发送同一终端的各种测试指令来说,只要有一种测试指令所对应的测数数据能够区别于其他测试指令对应的测试指令产生的元数据即可,而无需考虑该测试指令对应的测试指令产生的元数据是否与发送至其他终端的测试指令所对应的测试指令产生的元数据相似,即,仅需对同一个终端返回的测试指令产生的元数据进行对比。
具体的,针对每一个终端(如,在表1中所示设备标识为A001的终端),首先,当该服务器可向该终端发送不同的测试指令,其中,不同的测试指令可使该终端的振动马达执行不同的振动操作,具体可以是振动频率信息、振动时间间隔信息以及振动强度信息中至少一种不同,则该终端可对于每一种不同的测试指令向该服务器返回该测试指令产生的元数据。并且,针对同一种测试指令,该服务器可向该终端重复该测试指令,以减少该测试指令产生的元数据的误差。其中,该服务器也可在确定使用该终端的用户 的身份可信时,向该终端发送每一个测试指令。
其次,该服务器针对同一个终端返回的不同的测试指令产生的元数据,判断各种测试指令产生的元数据之间的区分度以及每一种测试指令产生的元数据的稳定性。如,对于表3所示的3种测试指令产生的元数据。
Figure PCTCN2017097955-appb-000002
表3
需要说明的是,其中最大加速度、最大加速度出现时间点、最小加速度、最小加速度出现时间点均是平均值,即,同一测试指令产生的各元数据的平均值。
可见,对于测试指令II产生的元数据和测试指令III产生的元数据来说,各种数值均很接近难以区分,而对于测试指令I产生的元数据来说,该测试指令产I生的元数据对应的各数值与测试指令II产生的元数据和测试指令III产生的元数据的数值差别很大,所以可以确定该测试指令产生的元数据I的区分度较高。
其中,该最大加速度以及该最小加速度可根据用户握持终端的姿势的不同而产生变化(如,用户的握力不同可能导致采集的加速度不同,用户的握姿不同也可能导致采集的加速度不同),该最大加速度以及该最小加速度也可根据该终端对应的设备不同产生变化(如,该终端对应的设备重量不同、体积不同,都可能导致采集的加速度不同)。并且,上述的用户握持终端的姿势以及该终端对应的设备,也可影响到该最大加速度出现时间点以及该最小加速出现的时间点(如,用户握力较大则可能使最大加速度出现时间点和最小加速度出现时间点更接近,用户握力较小则可能使最大加速度出现时间点和最小加速度出现时间点更疏远),当然,影响该加速度数值以及时间点的因素还有很多本申请不再一一列举。
具体的,仅以测试指令I产生的元数据为例,区分度为:最大加速度(0.1000G/s-0.0600G/s)+(0.1000G/s-0.0580G/s)、最大加速度出现时间点(0.100s-0.050s)+(0.100s-0.040s)、最小加速度0、最小加速度出现时间点(0.900s-0.550s)+(0.900s-0.530s),同理可以确定测试指令II产生的元数据和测试指令III 产生的元数据的区分度。
而由于对于同一种测试指令,该服务器可以向该终端发送多次,所以上述的稳定性则是指该终端对于同一个测试指令,每一次返回的测试指令产生的元数据的稳定性(即,针对同一个种测试指令,该终端返回的各测试指令产生的元数据之间的差别大小),若对于同一个测试指令,该终端每一次返回的测试指令产生的元数据的差别都很大,则通过该测试指令产生的元数据难以确定该差别是由于该数据本身还是由于该终端的使用人造成的,所以难以以该测试指令作为验证触发指令来进行身份验证。例如,表4所示的2种测试指令产生的元数据。
Figure PCTCN2017097955-appb-000003
表4
可见,该服务器重复向同一终端发送了4次测试指令I和4次测试指令II,并接收到了该终端返回的如表4所示的测试指令I产生的元数据和测试指令II产生的元数据,其中,测试指令I产生的元数据的稳定性更好,每个测试指令I产生的元数据之间的差别都很小,而每一个测试指令II产生的元数据之间的差别均很大,难以用于身份验证。
具体的,仅以测试指令I产生的元数据为例,最大加速度的稳定性为:(0.1000G/s-0.1020G/s)+(0.1020G/s-0.1050G/s)+(0.1050G/s-0.1001G/s)。
进一步地,由于在步骤S204中的描述,本申请并不限定该元数据的类型,所以本申请并不限定该终端执行上述测试指令后仅可采集到如表3所示的各元数据,表3中所示的各元数据仅为举例示意,并不形成对本申请的限定,在本申请中,上述各测试指令还可分别对应多种元数据。
更进一步地,针对每个测试指令,由于该测试指令产生的各元数据中可能存在区分度较低的元数据,而区分度较低的元数据对该测试指令来说存在意义不大,所以当确定该元数据的区分度较低时,后续再发送该测试指令时,可以不再采集该元数据。
以该测试指令I为例,假设该测试指令I产生的全部元数据如表3所示,由于该测试指令I产生的最小加速度的区分度为0,所以最小加速度对于该测试指令I的意义不大,则对于该测试指令I,该终端的传感器可不再采集最小加速度,使得执行该测试指令I产 生的各元数据仅为最大加速度、最大加速度出现的时间点、最小加速度出现的时间点。
另外,该服务器对于发送给同一终端的每一种测试指令产生的各元数据,均可采用与现有技术相同的信号处理方法,将同一测试指令产生的各元数据确定出一个测试数据,作为该测试指令所产生的元数据,其中,最简单的方法是,针对每一种测试指令,将该测试指令所产生的各元数据的取平均值作为该测试指令产生的元数据,则每当服务器再次接收到该测试指令对应的元数据时,对该测试指令产生的元数据可以进行一次信号处理,以便确定出的测试指令产生的元数据更加准确。
最后,该服务器可一直重复发送各种测试指令(即,针对每一种测试指令,重复发送该测试指令),直到各种测试指令对应的测试指令产生的元数据中,出现稳定性达到第一条件且区分度达到第二条件的测试指令产生的元数据为止,并且将该稳定性达到第一条件且区分度达到第二条件的测试指令产生的元数据作为参考振动参数,将与该参考振动参数对应的测试指令作为验证触发指令,并将该参考振动参数、验证触发指令、设备标识建立对应关系并存储在本地。
当然,在本申请所述的该测试过程中,该测试指令也可以只有一种,则该服务器可重复发送该测试指令,直至该测试指令产生的各元数据中出现的稳定性达到第一条件的元数据为止。并且,由于该服务器仅发送一种测试指令,所以无需考虑区分度的问题,仅需确定该测试指令产生的元数据的稳定性达到第一条件即可,其中,确定稳定性的方法可如前述方法一致。
本申请实施例中所记载的第一条件可以是指稳定性对应的数据达到设定第一数值,第二条件可以是指区分度达到第二数值,还可以是其他条件,这里不做具体限定。
需要说明的是,在该服务器确定任一测试指令产生的元数据的稳定性和区分度时,由于稳定性仅针对同一测试指令产生的元数据,所以只要当该服务器接收到同一测试指令产生的一个以上的元数据时,该服务器即可确定该测试指令产生的元数据的稳定性,并且在再次接收到该测试指令产生的元数据时,更新该测试指令产生的元数的稳定值。而由于区分度只有在出现一个以上不同的测试指令产生的元数据时才存在,所以只有当该服务器接收到一个以上不同测试指令产生的元数据时,该服务器才可以确定不同测试指令产生的元数据的区分度。
进一步地,上述仅为本申请的一种实施方式,该参考振动参数也可以是由多个元数据通过现有技术的信号处理方法来确定的,其中,该信号处理方法还包括:离散傅里叶变换的快速方法、短时傅里叶变换、小波分析、阶比分析、倒频谱、希尔伯特变换、经 验模态分解、本征模函数、希尔伯特黄变换等传统的信号处理方法,当然,工作人员可根据需求确定具体的信号处理方法,本申请对此并不做具体限定。
更进一步地,各种测试指令可以使该终端执行不同的振动操作,则其中,该振动操作的区别可以包括:振动马达的振动的频率、每一次振动之间的时间间隔以及振动的强度。如图6所示。
图6为本申请实施例提供的振动操作对应的波形示意图。其中,横坐标表示时间,纵坐标表示该终端某一轴方向上的振动幅度,并且01代表振动的频率、02代表振动时间间隔、03表示振动强度,其中,01中该传感器采集到单位时间内加速度变化12次,也就是该振动的频率。
更进一步地,在本申请中所述的各种测试指令,可由工作人员预先设置,但是由于人工设置的测试指令的种类终究有限,且各种测试指令中,并不一定存在能使测试指令产生的元数稳定性达到第一条件且区分度达到第二条件的测试指令,所以在本身实施例中,该服务器还可以对测试指令进行训练,以获得更优的测试指令。
例如,采用遗传算法、退火算法、蚁群算法、粒子群算法等,训练各测试指令,以获得稳定性以及区分度达到阈值的测试指令。
或者,该服务器还可以随机设置该测试指令的振动频率信息、振动时间间隔信息以及振动强度信息。
另外,由于各账号只有通过在终端上登录,才可以基于该终端的硬件与该服务器进行通讯,并执行业务,所以在本申请中,该终端上还可以登录多个账号,于是该服务器可仅监测各已经处于登录状态的账号的账号状态,而无需对所有账号进行监测,从而减轻该服务器的运行压力。
于是,在本申请中,该服务器向该终端发送的验证触发指令中可携带账号标识。
具体的,针对每一个状态异常的账号,首先,由于该账号可以在不同的终端上登录,而在本申请中,在进行身份验证时该账号登录的终端与身份验证过程存在较为密切的联系,所以该服务器在该账号建立数据连接后,还可以进一步确定该账号登录的终端的设备标识,以确定该账号登录的终端。
其次,该服务器可根据预先存储的各账号标识、各设备标识、各验证触发指令以及各参考振动参数的对应关系,如表5所示,确定该账号的账号标识所对应的验证触发指令。
Figure PCTCN2017097955-appb-000004
表5
可见对于同一个账号(如,账号标识A)来说,该账号标识A可以对应多个设备标识,并且,每一个设备标识均分别对应于不同的验证触发指令以及标准信息。
最后,该服务器可将确定的该账号的账号标识所对应的验证触发指令发送至该账号,以使得该账号登录的终端可以进行后续的身份验证过程。
进一步地,该服务器在向该账号发送该验证触发指令后,由于该验证触发指令的目的是使该账号登陆的终端向该服务器返回可以证明身份的信息(即,元数据,以供该服务器进行后续的身份验证步骤),所以该验证触发指令可以使该账号登陆的终端,根据该验证触发指令执行对应的操作,并向该服务器返回元数据、该终端的设备标识以及该验证才能触发指令携带的账号标识。
进一步的,由于同一终端可登录有多个账号,且该服务器可接收携带有元数据、账号标识以及设备标识的验证请求,所以该服务器在确定该参考振动参数时,可以根据设备标识以及账号标识共同确定。
具体的,该服务器在接收到该元数据以及该设备标识后,便可通过如表1所示的已存储的各账号标识、各设备标识、各验证触发指令以及各参考振动参数的对应关系,确定在步骤S201中发送的该验证触发指令对应的参考振动参数,并且,由于对于不同的账号标识以及设备标识,该服务器可能发送的验证触发指令相同,但是对于同一个验证触发指令,该验证触发指令对应于不同的账号标识以及设备标识的参考振动参数可能不同,如表6所示,所以在本申请中该参考振动参数与该账号标识以及该设备标识也可以是一一对应的。
Figure PCTCN2017097955-appb-000005
Figure PCTCN2017097955-appb-000006
表6
可见对于验证触发指令Prov001来说,在对应于不同的账号标识A、B和C时,其对应的参考振动参数也不同,并且对应账号标识B来说,该验证触发指令Prov001对应于不同的设备标识A003和A004,该验证触发指令分别对应于不同的参考振动参数Stand003和Stand004。
所以该服务器需要确定与账号标识、设备标识以及验证触发指令均应的标准信息,当然,为了方便区分,该服务器也可以为不同的账号标识以及设备标识确定不同的验证触发指令,例如,对于表6中的验证触发指令Porv001俩说,该服务器也可存储成图表7所示的对应的关系。
Figure PCTCN2017097955-appb-000007
表7
则,由于对于每一个验证触发指令来说,该验证触发指令均可与其他验证触发指令不同,所以该服务器也可仅根据各验证触发指令与各参考振动参数的对应的关系,确定与该验证触发指令唯一对应的参考振动参数。
当然,上述仅列举了两种实施方式,本申请并不具体限定通过该验证触发指令如何确定对应的参考振动参数,只要该验证触发指令可以确定对应于该账号标识以及该设备标识的参考振动参数即可。
更进一步的,由于该元数据实际上与该账号标识、设备标识以及该验证触发指令是一一对应的,而该参考振动参数也是与该账号标识、设备标识以及该验证触发指令是一一对应的,所以该参考振动参数可以认为是与该元数据对应的,所以当该服务器接收到该元数据并确定了对应的参考振动参数之后,该服务器便可以判断该参考振动参数与该元数据是否一致,以便确定该账号的身份验证是否通过。
需要说明的是,本申请实施例所提供方法的各步骤的执行主体均可以是同一设备, 或者,该方法也由不同设备作为执行主体。比如,步骤S201和步骤S202的执行主体可以为设备1,步骤S203的执行主体可以为设备2;又比如,步骤S201的执行主体可以为设备1,步骤S202和步骤S203的执行主体可以为设备2;等等,即,该服务器可以是由多台设备组成的分布式服务器。
基于图2所示的数据存储过程,本申请实施例还对应提供一种身份验证的装置,如图7所示。
图7为本申请实施例提供的一种身份验证的装置的结构示意图,包括:
接收模块301,接收服务器发送的验证触发指令;
振动模块302,根据所述验证触发指令执行振动操作;
采集模块,在所述振动模块302根据所述验证触发指令执行振动操作时,采集在执行所述振动操作时产生的元数据;
发送模块303,将携带所述元数据和所述装置的设备标识的验证请求发送至服务器,所述验证请求用于请求所述服务器根据所述元数据和所述装置的设备标识对使用所述装置的用户进行身份验证。
所述振动模块302,确定所述验证触发指令中包含的振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种,根据所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息中的至少一种,执行振动操作。
所述振动模块302在执行所述振动操作时,所述采集模块,采集所述终端的振动加速度和/或振动角速度,并将所述振动加速度和/或所述振动角速度作为所述终端在执行所述振动操作时产生的元数据。
所述接收模块301,终端向服务器发送状态信息,所述终端接收所述服务器发送的验证触发指令,所述验证触发指令为所述服务器在确定状态信息为异常状态时发送的。
在本申请的另一个实施例中,所述验证触发指令中携带账号标识;所述发送模块303,在将携带所述元数据、所述装置的设备标识发送给所述服务器时,还将所述终端的账号标识携带者所述验证请求中发送至服务器,所述验证请求用于请求所述服务器根据所述元数据、所述装置的设备标识以及所述账号标识,对使用所述装置的用户进行身份验证。
具体的,上述如图7所示的身份验证的装置可以位于终端中,所述终端可以是手机、平板电脑等设备。
基于图3所示的数据存储过程,本申请实施例还对应提供一种终端执行的身份验证的装置,如图8所示。
图8为本申请实施例提供的另一种身份验证的装置的结构示意图,包括:
发送模块401,向终端发送验证触发指令,所述验证触发指令用于指示所述终端在根据所述验证触发指令执行振动操作;
接收模块402,接收所述终端发送的元数据以及所述终端的设备标识,所述元数据为所述终端在执行所述振动操作时采集的;
确定模块403,根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数;
验证模块404,根据所述参考振动参数以及所述元数据,对使用所述终端的用户进行身份验证。
所述装置还包括:
测试模块405,预设设备标识与参考振动数据之间的对应关系;
所述测试模块405,向所述终端发送至少一个测试指令,所述测试指令用于指示所述终端在根据所述测试指令执行振动操作时采集执行所述振动操作时产生的元数据,所述测试指令包括振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种,接收所述终端发送的针对每一个所述测试指令产生的所述元数据以及所述终端的设备标识,根据所述测试指令产生的所述元数据,确定所述终端的参考振动参数,所述参考振动参数中包括振动加速度和/或振动角速度,建立所述终端的设备标识与确定的所述参考振动参数之间的对应关系。
所述测试模块405,在确定所述测试指令产生的所述元数据的数量达到阈值时,根据产生的所述元数据的平均值确定针对所述终端的参考振动参数,或者,确定所述测试指令产生的不同元数据之间的差值的平均值,当所述差值的平均值小于设定门限值时,确定所述元数据的平均值为针对所述终端的参考振动参数。
当所述发送模块401向所述终端发送的多个测试指令中包含的执行振动操作的参数不同时,所述测试模块405,针对同一个测试指令,执行以下操作:确定针对所述测试指令所述终端产生的至少一个所述元数据的平均值,将所述平均值作为在满足所述测试指令时所述终端的参考振动参数,所述服务器在得到不同的所述测试指令对应的参考振动参数时,建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系。
所述发送模块401,向所述终端发送的测试指令中包含的所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息为预设的,或者,所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息为随机生成的。
所述测试模块405,在建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系之前,在得到针对同一个测试指令所述终端产生的至少一个元数据时,计算得到的不同所述元数据之间的差值之和,并根据所述差值之和确定所述测试指令产生元数据的稳定性,在得到不同的所述测试指令对应的参考振动参数时,根据不同的所述测试指令产生的元数据的平均值,确定不同的所述测试指令的区分度,从得到不同的所述测试指令对应的参考振动参数中,选择稳定性大于第一条件且所述区分度大于第二条件的测试指令对应的参考振动参数,并建立所述终端设备的终端标识与选择的所述参考振动参数之间的对应关系。
当所述装置确定所述终端的设备标识对应多个的账号标识时,所述发送模块401所述服务器向终端发送对应账号标识的验证触发指令,所述接收模块402,接收所述终端发送的所述元数据、所述账号标识以及所述终端的设备标识,所述确定模块403,根据预设的设备标识、账号标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数。
具体的,上述如图7所示的身份验证的装置可以位于服务器中,该服务器具体的可以是一台设备,也可以是由多台设备组成的系统,即,分布式服务器。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或 多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
在一个典型的配置中,计算设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。
还需要说明的是,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、商品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、商品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、商品或者设备中还存在另外的相同要素。
本领域技术人员应明白,本申请的实施例可提供为方法、系统或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
以上所述仅为本申请的实施例而已,并不用于限制本申请。对于本领域技术人员来 说,本申请可以有各种更改和变化。凡在本申请的精神和原理之内所作的任何修改、等同替换、改进等,均应包含在本申请的权利要求范围之内。

Claims (24)

  1. 一种身份验证的方法,其特征在于,所述方法包括:
    终端接收服务器发送的验证触发指令,所述验证触发指令用于指示所述终端执行振动操作;
    所述终端在根据所述验证触发指令执行振动操作时,采集在执行所述振动操作时产生的元数据;
    所述终端将携带所述元数据和所述终端的设备标识的验证请求发送至服务器,所述验证请求用于请求所述服务器根据所述元数据和所述终端的设备标识对使用所述终端的用户进行身份验证。
  2. 如权利要求1所述的方法,其特征在于,所述终端根据所述验证触发指令执行振动操作,包括:
    所述终端确定所述验证触发指令中包含的振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种;
    所述终端根据所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息中的至少一种,执行振动操作。
  3. 如权利要求1或2所述的方法,其特征在于,采集在执行所述振动操作时产生的元数据,具体包括:
    所述终端在执行所述振动操作时,采集所述终端的振动加速度和/或振动角速度,并将所述振动加速度和/或所述振动角速度作为所述终端在执行所述振动操作时产生的元数据。
  4. 如权利要求1所述的方法,其特征在于,终端接收服务器发送的验证触发指令,包括:
    终端向服务器发送状态信息;
    所述终端接收所述服务器发送的验证触发指令,所述验证触发指令为所述服务器在确定状态信息为异常状态时发送的。
  5. 如权利要求1所述的方法,其特征在于,所述终端在将所述元数据、所述终端的设备标识发送给所述服务器时,还将所述终端的账号标识携带在所述验证请求中发送至服务器,所述验证请求用于请求所述服务器根据所述元数据、所述终端的设备标识以及所述账号标识,对使用所述终端的用户进行身份验证。
  6. 一种身份验证的方法,其特征在于,包括:
    服务器向终端发送验证触发指令,所述验证触发指令用于指示所述终端在根据所述验证触发指令执行振动操作;
    所述服务器接收所述终端发送元数据以及所述终端的设备标识,所述元数据为所述终端在执行所述振动操作时采集的;
    所述服务器根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数;
    根据所述参考振动参数以及所述元数据,对使用所述终端的用户进行身份验证。
  7. 如权利要求6所述的方法,其特征在于,所述服务器预设设备标识与参考振动数据之间的对应关系,包括:
    所述服务器向所述终端发送至少一个测试指令,所述测试指令用于指示所述终端在根据所述测试指令执行振动操作时采集执行所述振动操作时产生的元数据,所述测试指令包括振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种;
    所述服务器接收所述终端发送的针对每一个所述测试指令产生的所述元数据以及所述终端的设备标识;
    所述服务器根据所述测试指令产生的所述元数据,确定所述终端的参考振动参数,所述参考振动参数中包括振动加速度和/或振动角速度;
    所述服务器建立所述终端的设备标识与确定的所述参考振动参数之间的对应关系。
  8. 如权利要求7所述的方法,其特征在于,所述服务器根据所述测试指令产生的所述元数据,确定所述终端的参考振动参数,包括:
    所述服务器在确定所述测试指令产生的所述元数据的数量达到阈值时,根据产生的所述元数据的平均值确定所述终端的参考振动参数;或者
    所述服务器确定所述测试指令产生的不同元数据之间的差值的平均值,当所述差值的平均值小于设定门限值时,确定所述平均值为所述终端的参考振动参数。
  9. 如权利要求7所述的方法,其特征在于,当所述服务器向所述终端发送的多个测试指令中包含的执行振动操作的参数不同时,所述方法还包括:
    所述服务器针对同一个测试指令,执行以下操作:
    确定针对所述测试指令所述终端产生的至少一个所述元数据的平均值,将所述平均值作为在满足所述测试指令时所述终端的参考振动参数;
    所述服务器在得到不同的所述测试指令对应的参考振动参数时,建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系。
  10. 如权利要求9所述的方法,其特征在于,所述服务器在建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系之前,所述方法还包括:
    所述服务器在得到针对同一个测试指令所述终端产生的至少一个元数据时,计算得到的不同所述元数据之间的差值之和,并根据所述差值之和确定所述测试指令产生元数据的稳定性;
    所述服务器在得到不同的所述测试指令对应的参考振动参数时,建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系,包括:
    所述服务器根据不同的所述测试指令产生的元数据的平均值,确定不同的所述测试指令的区分度;
    所述服务器从得到不同的所述测试指令对应的参考振动参数中,选择稳定性大于第一条件且所述区分度大于第二条件的测试指令对应的参考振动参数,并建立所述终端设备的终端标识与选择的所述参考振动参数之间的对应关系。
  11. 如权利要求7所述的方法,其特征在于,所述服务器向所述终端发送的测试指令中包含的所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息为预设的;或者,
    所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息为随机生成的。
  12. 如权利要求6所述的方法,其特征在于,所述验证触发指令中携带账号标识;
    确定与接收到的所述终端的设备标识对应的参考振动参数,包括:
    所述服务器根据预设的设备标识、账号标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数。
  13. 一种身份验证的装置,其特征在于,包括:
    接收模块,接收服务器发送的验证触发指令;
    振动模块,根据所述验证触发指令执行振动操作;
    采集模块,在所述振动模块根据所述验证触发指令执行振动操作时,采集在执行所述振动操作时产生的元数据;
    发送模块,将携带所述元数据和所述装置的设备标识的验证请求发送至服务器,所述验证请求用于请求所述服务器根据所述元数据和所述装置的设备标识对使用所述装置的用户进行身份验证。
  14. 如权利要求13所述的装置,其特征在于,所述振动模块,确定所述验证触发指令中包含的振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种,根据 所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息中的至少一种,执行振动操作。
  15. 如权利要求13或14所述的装置,其特征在于,所述振动模块在执行所述振动操作时,所述采集模块,采集终端的振动加速度和/或振动角速度,并将所述振动加速度和/或所述振动角速度作为所述终端在执行所述振动操作时产生的元数据。
  16. 如权利要求13所述的装置,其特征在于,所述接收模块,终端向服务器发送状态信息,所述终端接收所述服务器发送的验证触发指令,所述验证触发指令为所述服务器在确定状态信息为异常状态时发送的。
  17. 如权利要求13所述的装置,其特征在于,所述发送模块,在将携带所述元数据、所述装置的设备标识发送给所述服务器时,还将终端的账号标识携带者所述验证请求中发送至服务器,所述验证请求用于请求所述服务器根据所述元数据、所述装置的设备标识以及所述账号标识,对使用所述装置的用户进行身份验证。
  18. 一种身份验证的装置,其特征在于,包括:
    发送模块,向终端发送验证触发指令,所述验证触发指令用于指示所述终端在根据所述验证触发指令执行振动操作;
    接收模块,接收所述终端发送的元数据以及所述终端的设备标识,所述元数据为所述终端在执行所述振动操作时采集的;
    确定模块,根据预设的设备标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数;
    验证模块,根据所述参考振动参数以及所述元数据,对使用所述终端的用户进行身份验证。
  19. 如权利要求18所述的装置,其特征在于,所述装置还包括:
    测试模块,预设设备标识与参考振动数据之间的对应关系;
    所述测试模块,向所述终端发送至少一个测试指令,所述测试指令用于指示所述终端在根据所述测试指令执行振动操作时采集执行所述振动操作时产生的元数据,所述测试指令包括振动频率信息、振动时间间隔信息以及振动强度信息中的至少一种,接收所述终端发送的针对每一个所述测试指令产生的所述元数据以及所述终端的设备标识,根据所述测试指令产生的所述元数据,确定所述终端的参考振动参数,所述参考振动参数中包括振动加速度和/或振动角速度,建立所述终端的设备标识与确定的所述参考振动参数之间的对应关系。
  20. 如权利要求19所述的装置,其特征在于,所述测试模块,在确定所述测试指令产生的所述元数据的数量达到阈值时,根据产生的所述元数据的平均值确定针对所述终端的参考振动参数,或者,确定所述测试指令产生的不同元数据之间的差值的平均值,当所述差值的平均值小于设定门限值时,确定所述平均值为针对所述终端的参考振动参数。
  21. 如权利要求19所述的装置,其特征在于,当所述发送模块向所述终端发送的多个测试指令中包含的执行振动操作的参数不同时,所述测试模块,针对同一个测试指令,执行以下操作:确定针对所述测试指令所述终端产生的至少一个所述元数据的平均值,将所述平均值作为在满足所述测试指令时所述终端的参考振动参数,在得到不同的所述测试指令对应的参考振动参数时,建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系。
  22. 如权利要求21所述的装置,其特征在于,所述测试模块,在建立所述终端的设备标识与得到的所述参考振动参数之间的对应关系之前,在得到针对同一个测试指令所述终端产生的至少一个元数据时,计算得到的不同所述元数据之间的差值之和,并根据所述差值之和确定所述测试指令产生元数据的稳定性,在得到不同的所述测试指令对应的参考振动参数时,根据不同的所述测试指令产生的元数据的平均值,确定不同的所述测试指令的区分度,从得到不同的所述测试指令对应的参考振动参数中,选择稳定性大于第一条件且所述区分度大于第二条件的测试指令对应的参考振动参数,并建立所述终端设备的终端标识与选择的所述参考振动参数之间的对应关系。
  23. 如权利要求19所述的装置,其特征在于,所述发送模块,向所述终端发送的测试指令中包含的所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息为预设的,或者,所述振动频率信息、所述振动时间间隔信息以及所述振动强度信息为随机生成的。
  24. 如权利要求18所述的装置,其特征在于,当所述装置确定所述终端的设备标识对应多个的账号标识时,所述发送模块向终端发送对应账号标识的验证触发指令,所述接收模块,接收所述终端发送的所述元数据、所述账号标识以及所述终端的设备标识,所述确定模块,根据预设的设备标识、账号标识与参考振动参数之间的对应关系,确定与接收到的所述终端的设备标识对应的参考振动参数。
PCT/CN2017/097955 2016-08-31 2017-08-18 一种身份验证的方法及装置 Ceased WO2018040946A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610798122.9 2016-08-31
CN201610798122.9A CN107786340A (zh) 2016-08-31 2016-08-31 一种身份验证的方法及装置

Publications (1)

Publication Number Publication Date
WO2018040946A1 true WO2018040946A1 (zh) 2018-03-08

Family

ID=61300037

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/097955 Ceased WO2018040946A1 (zh) 2016-08-31 2017-08-18 一种身份验证的方法及装置

Country Status (3)

Country Link
CN (1) CN107786340A (zh)
TW (1) TWI670619B (zh)
WO (1) WO2018040946A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113468007A (zh) * 2021-06-30 2021-10-01 完美世界(北京)软件科技发展有限公司 设备标识信息验证方法、装置、设备和存储介质

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108449348B (zh) * 2018-03-22 2021-03-26 西安电子科技大学 一种支持用户身份隐私保护的在线认证系统及方法
CN108632089B (zh) * 2018-05-07 2022-09-20 平安普惠企业管理有限公司 测试终端的管理方法、装置、设备和计算机存储介质
US10467398B1 (en) * 2019-03-14 2019-11-05 Alibaba Group Holding Limited Authentication by transmitting information through a human body
CN113112665A (zh) * 2021-03-22 2021-07-13 深兰盛视科技(苏州)有限公司 出入管理方法、装置、电子设备及存储介质
CN113408678B (zh) * 2021-06-15 2023-08-15 广州极飞科技股份有限公司 关联方法、装置、电子设备及存储介质
CN116953510A (zh) * 2023-07-12 2023-10-27 瑞声开泰声学科技(上海)有限公司 一种马达个体参数确定方法、装置、设备及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090249475A1 (en) * 2008-03-31 2009-10-01 Fujitsu Limited Authentication system, electronic apparatus, electronic apparatus authentication method, and computer-readable recording medium having authentication program recorded thereon
CN102027487A (zh) * 2009-04-24 2011-04-20 三美电机株式会社 个人认证装置
US20150089593A1 (en) * 2013-09-24 2015-03-26 International Business Machines Corporation Method and system for using a vibration signature as an authentication key
CN104935431A (zh) * 2014-03-17 2015-09-23 株式会社理光 认证装置、认证系统、认证方法

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWM527570U (zh) * 2016-04-29 2016-08-21 華美電子股份有限公司 具有認證功能之穿戴式裝置及其認證系統

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090249475A1 (en) * 2008-03-31 2009-10-01 Fujitsu Limited Authentication system, electronic apparatus, electronic apparatus authentication method, and computer-readable recording medium having authentication program recorded thereon
CN102027487A (zh) * 2009-04-24 2011-04-20 三美电机株式会社 个人认证装置
US20150089593A1 (en) * 2013-09-24 2015-03-26 International Business Machines Corporation Method and system for using a vibration signature as an authentication key
CN104935431A (zh) * 2014-03-17 2015-09-23 株式会社理光 认证装置、认证系统、认证方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113468007A (zh) * 2021-06-30 2021-10-01 完美世界(北京)软件科技发展有限公司 设备标识信息验证方法、装置、设备和存储介质

Also Published As

Publication number Publication date
CN107786340A (zh) 2018-03-09
TWI670619B (zh) 2019-09-01
TW201812628A (zh) 2018-04-01

Similar Documents

Publication Publication Date Title
TWI670619B (zh) 身份驗證的方法及裝置
US11855981B2 (en) Authenticating a user device via a monitoring device
US11508382B2 (en) System, device and method for enforcing privacy during a communication session with a voice assistant
US11651100B2 (en) System, device and method for enforcing privacy during a communication session with a voice assistant
EP3580911B1 (en) Method and apparatus for authenticating users in internet of things environment
US10467396B2 (en) Using biometric user-specific attributes
EP3446457B1 (en) Two-factor authentication
US11902275B2 (en) Context-based authentication of a user
JP2017515178A (ja) モバイルデバイスによる連続的認証
US9667613B1 (en) Detecting mobile device emulation
JP2018507461A (ja) 連続的および離散的ユーザ認証を提供するモバイルデバイス
WO2019072132A1 (zh) 人脸识别方法及相关产品
KR20170056681A (ko) 디바이스 기초 인증 시스템 및 방법
KR20160124833A (ko) 모바일 디바이스들을 위한 신뢰 브로커 인증 방법
US20160350761A1 (en) Method and Apparatus for Managing Reference Templates for User Authentication Using Behaviometrics
US9721087B1 (en) User authentication
US11695746B2 (en) Multi-layer user authentication with live interaction
CN107786976A (zh) 无屏幕智能设备及其自动连接无线网络的方法和装置
CN106470192B (zh) 身份验证方法、装置及系统
US20250007747A1 (en) Systems, methods, computer-readable media, and devices for authenticating users
US12581296B2 (en) Systems and methods for user authentication using mobile network data
HK1249677A1 (zh) 一种身份验证的方法及装置
US20210209217A1 (en) Method and system for authentication using mobile device id based two factor authentication
CA3018853C (en) System, device and method for enforcing privacy during a communication session with a voice assistant
CN120980499A (zh) 为智能设备进行智能配网的方法、装置及智能设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17845248

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17845248

Country of ref document: EP

Kind code of ref document: A1