WO2018099276A1 - 身份认证方法及装置和计算设备 - Google Patents

身份认证方法及装置和计算设备 Download PDF

Info

Publication number
WO2018099276A1
WO2018099276A1 PCT/CN2017/111506 CN2017111506W WO2018099276A1 WO 2018099276 A1 WO2018099276 A1 WO 2018099276A1 CN 2017111506 W CN2017111506 W CN 2017111506W WO 2018099276 A1 WO2018099276 A1 WO 2018099276A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
user
risk coefficient
type
risk
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2017/111506
Other languages
English (en)
French (fr)
Inventor
于鲲
王炎
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Publication of WO2018099276A1 publication Critical patent/WO2018099276A1/zh
Priority to US16/421,294 priority Critical patent/US20190347425A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/90Details of database functions independent of the retrieved data types
    • G06F16/95Retrieval from the web
    • G06F16/953Querying, e.g. by the use of web search engines
    • G06F16/9535Search customisation based on user profiles and personalisation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/316User authentication by observing the pattern of computer usage, e.g. typical user behaviour
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Definitions

  • the present invention relates to the field of Internet technologies, and in particular, to an identity authentication method and apparatus, and a computing device.
  • Identity authentication also known as “authentication” or “identification” refers to the process of confirming the identity of an operator in a computer and computer network system to determine whether the user has access to and use of a certain resource, thereby enabling the computer And the network system access policy can be executed reliably and effectively, preventing an attacker from impersonating a legitimate user to obtain access to resources, ensuring the security of the system and data, and authorizing the legitimate interests of the visitor.
  • the user identity is usually determined based on the identity authentication conditions, thereby authorizing users who pass all identity authentication conditions.
  • the identity authentication condition is ID card information, and the user can pass the identity authentication according to the input ID card information.
  • the identity authentication condition is the user's face information
  • the user's face information can be used to determine whether the user passes the identity authentication. That is to say, in the related art, whether the identity of the user passes the identity authentication according to each identity authentication condition is independent and has no association. Therefore, the risk of error in the identity authentication decision is large, which affects the user experience.
  • An embodiment of the present invention provides an identity authentication method, apparatus, and computing device, to at least solve the identity authentication decision caused by whether the user identity is independent of each other and has no association according to each identity authentication condition in the related art.
  • the risk of errors is large and the technical problems affecting the user experience.
  • an identity authentication method includes: collecting multiple types of information of an identity authentication user, where multiple types of information are used to authenticate a user identity; a risk coefficient corresponding to each type of information in the plurality of types of information, wherein the risk coefficient is used to indicate the degree to which the user's identity is trusted; and comprehensively evaluating the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient; According to the comprehensive risk coefficient, it is judged whether the user's identity authentication is passed.
  • an identity authentication apparatus includes: an acquisition unit, configured to collect multiple types of information of an identity authentication user, where multiple types of information are used for
  • the first acquisition unit is configured to obtain a risk coefficient corresponding to each type of information in the plurality of types of information, wherein the risk coefficient is used to indicate the degree of trust of the user's identity;
  • the second obtaining unit It is used for comprehensively evaluating the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient; and a judging unit for judging whether the user's identity authentication is passed according to the comprehensive risk coefficient.
  • a computing device which provides a first interface for user interaction, where the first interface includes: a plurality of first controls, which are used to collect multiple users to be authenticated. Types of information, multiple types of information are used to authenticate the identity of the user; the first sending unit is configured to send multiple types of information to the server, and the risk coefficient of the plurality of types of information is evaluated by the server.
  • the second receiving unit is configured to receive the risk coefficient corresponding to the multiple types of information sent by the server and the comprehensive risk coefficient;
  • a plurality of second controls corresponding to one control are used to represent the risk coefficient corresponding to each type of information; and a third control is used to represent the comprehensive risk coefficient of the user to be authenticated.
  • multiple types of information are used to authenticate the user, and multiple types of information are used to authenticate the identity of the user.
  • the comprehensive risk coefficient it is judged whether the user's identity authentication is passed, thereby correlating the risk coefficients corresponding to each type of information, thereby avoiding the risk of error in the identity authentication decision caused by the independent identity and no association between the identity authentication.
  • the purpose of improving the authentication accuracy of the user is achieved, thereby realizing the technical effect of improving the user experience, and further solving the problem that the user identity is independent of each other according to the identity authentication conditions in the related technology.
  • the wind of mistakes in any authentication decision caused by any association Affecting the user experience technical problems.
  • FIG. 1 is a block diagram showing the hardware structure of a computer terminal of an optional identity authentication method according to an embodiment of the present invention
  • FIG. 2 is a flow chart of an identity authentication method according to an embodiment of the present invention.
  • FIG. 3 is a flow chart of an optional identity authentication method according to an embodiment of the present invention.
  • FIG. 4 is a flowchart of an optional identity authentication method according to an embodiment of the present invention.
  • FIG. 5 is a flowchart of an optional identity authentication method according to an embodiment of the present invention.
  • FIG. 6 is a schematic diagram of an optional identity authentication method according to an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of an optional identity authentication method according to an embodiment of the present invention.
  • FIG. 8 is a schematic diagram of an identity authentication apparatus according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of a computing device in accordance with an embodiment of the present invention.
  • FIG. 10 is a block diagram showing the structure of an optional computer terminal in accordance with an embodiment of the present invention.
  • the embodiment of the invention provides an embodiment of an identity authentication method.
  • the identity authentication method can use the identity authentication of the user in the Internet. For example, in a financial related application, after the user registers in the application, the identity of the user needs to be confirmed, and if the user only uploads one picture, it is actually insufficient. I think that the photo is my own photo taken by this user, because the user can completely download the photo from the Internet for impersonation. This risk can be reduced if multiple types of information are collected from the user. When multiple types of information of the user are collected, the risk coefficient corresponding to each type of information is comprehensively evaluated to obtain a comprehensive risk coefficient; according to the comprehensive risk coefficient Determine whether the user's identity authentication is passed.
  • the following solution can be implemented in an application installed in a mobile terminal, that is, the application of the mobile terminal can be used to determine whether the identity authentication of the user passes.
  • the application or software can be used only as an interface for obtaining photos.
  • the user can upload photos through the application or software, and then the application or software transmits the photos to the server for judgment by the server.
  • the computing power of the server is stronger than the application itself, so using it on the server can simultaneously process a large number of photos from different applications or software.
  • the server can be a real hardware server or a service. With the development of cloud computing, this service can also be placed on the cloud service for processing.
  • the recognition results of the following schemes can be used by other applications or services.
  • the identity authentication of a user based on various types of information that authenticates the user's identity can be implemented in a variety of situations, and will not be described one by one.
  • the hardware structure described below is a relatively common hardware structure. As the technology advances, the hardware structure changes. No matter what hardware structure can implement the authentication of the user's identity, as long as the solution in the embodiment of the present application can be implemented. Whether it passed.
  • FIG. 1 shows a hardware block diagram of a computer terminal (or mobile device) for implementing an identity authentication method.
  • computer terminal 10 may include one or more (shown in the figures 102a, 102b, ..., 102n) processor 102 (processor 102 may include, but is not limited to, micro A processing device such as a processor MCU or a programmable logic device FPGA, a memory 104 for storing data, and a transmission module for communication functions.
  • processor 102 may include, but is not limited to, micro A processing device such as a processor MCU or a programmable logic device FPGA, a memory 104 for storing data, and a transmission module for communication functions.
  • FIG. 1 is merely illustrative and does not limit the structure of the above electronic device.
  • computer terminal 10 may also include more or fewer components than those shown in FIG. 1, or have a different configuration than that shown in FIG.
  • processors 102 and/or other data processing circuits may be referred to herein generally as "data processing circuits.”
  • the data processing circuit may be embodied in whole or in part as software, hardware, firmware or any other combination.
  • the data processing circuitry can be a single, separate processing module, or incorporated in whole or in part into any of the other components in computer terminal 10 (or mobile device).
  • the data processing circuit is controlled as a processor (e.g., selection of a variable resistance termination path connected to the interface).
  • the memory 104 can be used to store software programs and modules of the application software, such as the program instructions/data storage devices corresponding to the identity authentication method in the embodiment of the present invention, and the processor 102 executes by executing the software programs and modules stored in the memory 104.
  • Various functional applications and data processing implement the above-described identity authentication method.
  • Memory 104 may include high speed random access memory, and may also include non-volatile memory such as one or more magnetic storage devices, flash memory, or other non-volatile solid state memory.
  • memory 104 may further include memory remotely located relative to processor 102, which may be coupled to computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
  • the transmission device is for receiving or transmitting data via a network.
  • the network specific examples described above may include a wireless network provided by a communication provider of the computer terminal 10.
  • the transmission device 106 includes a Network Interface Controller (NIC) that can be connected to other network devices through a base station to communicate with the Internet.
  • the transmission device can be a Radio Frequency (RF) module for communicating with the Internet wirelessly.
  • NIC Network Interface Controller
  • RF Radio Frequency
  • the display can be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of computer terminal 10 (or mobile device).
  • LCD liquid crystal display
  • the computer device (or mobile device) shown in FIG. 1 above may include hardware components (including circuits), software components (including computers stored on a computer readable medium). Code), or a combination of both hardware and software components.
  • FIG. 1 is only one example of a specific embodiment, and is intended to show the types of components that may be present in the above-described computer device (or mobile device).
  • the application provides the identity authentication method as shown in FIG. 2, and the method specifically includes the following steps:
  • Step S202 Collect multiple types of information of the user to be authenticated, where multiple types of information are used to authenticate the identity of the user.
  • users need to be authenticated on the Internet.
  • various types of information for authenticating the identity of the user are collected.
  • user A (to be authenticated user) needs to establish a real-name account for himself on a certain website, so it needs to perform identity authentication on the Internet. After the identity authentication is passed, a website will authorize user A to open it. Real name account.
  • User A may upload some User A related materials in order to authenticate on the Internet.
  • some user A's phase has been uploaded.
  • the information in the related material uploaded by the user A is collected, and the information includes the information for authenticating the user A.
  • information for authenticating user A is also collected in the Internet. If some user A related materials are not uploaded, information for authenticating user A is collected in the Internet.
  • the type of information of the user includes at least one of the following: certificate information, biometric information, rights information, and behavior information of the user on the Internet.
  • the related materials uploaded include at least one of the following: user A's certificate, user A's biometrics, and information collected by user A's related materials, including the documents in the uploaded document.
  • the user A's rights information in the Internet is collected. For example, it is determined whether the user A is in the Internet blacklist in the Internet. If the user A is in the blacklist, the user A's rights in the Internet may be restricted.
  • the behavior information of the user A on the Internet may be the access trajectory of the user A on the Internet. For example, according to the access trajectory of the user A on the Internet, it may be determined whether the operation of the user A on the Internet is at risk.
  • Step S204 Acquire a risk coefficient corresponding to each type of information in the plurality of types of information, where the risk coefficient is used to indicate the degree to which the identity of the user is trusted.
  • the risk factor can be a coefficient that is evaluated from the forward direction. At this time, the greater the value of the risk coefficient, the higher the degree of trust of the user, and the lower the risk after the user's identity is authenticated.
  • the risk coefficient can also be reversed.
  • the coefficient of evaluation the greater the value of the risk coefficient, the lower the degree of trust of the user, and the higher the risk after the user's identity is authenticated.
  • the type of information of the user may include at least one of the following: certificate information, biometric information, rights information, and behavior information of the user on the Internet.
  • the behavior information of the user on the Internet is a kind of information, and the behavior information of the user can also be used as a reference for evaluating the user, which will be exemplified below.
  • the document information is a more important one.
  • the evaluation of the document information may adopt multiple dimensions.
  • the document information may be determined according to at least one of the following conditions: Risk factor: document clarity, document completeness, and document validity.
  • the document clarity can be used to determine whether the document is a certificate downloaded from the Internet, not a photo taken by the user; the completeness of the document can be used as a comprehensive assessment, such as only the ID card photo and sufficient to indicate the user-uploaded ID card.
  • the photo is his own. If the user uploads an ID card and a driver's license, the risk of the user's fraud is much lower.
  • the validity of the document can be used to verify that the document is still valid, which is also helpful in determining the risk of fraud by the user.
  • the document information is not limited thereto, and the above-mentioned types of document information may be used alone or in combination, as long as the risk coefficient of the user can be evaluated.
  • the risk coefficient may be a coefficient value or a probability.
  • the user A is taken as an example, and the risk coefficient is determined according to the clarity of the uploaded document of the user A. If the probability is used, 100% think that the user ID photo is clear and there is no risk at all.
  • the degree of image clarity can be defined by using some parameters of the photo, such as the pixels of the photo, the size of the photo, and the like. Some existing algorithms for the sharpness of the photo can be applied in this embodiment, and details are not described herein again. If the resolution of the uploaded document is 80%, it is determined that the probability of the uploaded document being qualified is 80%, and the risk factor is determined to be 80% according to the possibility of the certificate being qualified.
  • the clarity of the document can be obtained based on the possibility of successfully identifying the information in the document.
  • the probability of failure of the certificate is used to represent the risk factor.
  • the risk factors listed in the following embodiments can also be defined from the two aspects of positive correlation and negative correlation, and will not be further described below.
  • the risk coefficient may be determined according to the completeness of the uploaded documents of the user A. Specifically, if the completeness of the uploaded documents is 55%, the probability of determining the uploaded documents is 55%. The risk factor is determined to be 55% based on the likelihood of the certificate being qualified. It should be noted that the completeness of the documents can be calculated by uploading the number and type of documents and the number and type of documents required to be uploaded.
  • the risk coefficient may be determined according to the validity of the uploaded certificate of the user A. Specifically, if the validity of the uploaded document is 68%, the probability of determining the uploaded certificate is 68%. The risk factor is determined to be 68% based on the likelihood of the certificate being qualified. It should be noted that the validity of the certificate can be determined according to the information in the identification of the uploaded document to determine whether it meets the preset requirements.
  • Biometric information is also important information. It can also be used for reference when evaluating users. For example, if the type of information is biometric information, the risk coefficient corresponding to the biometric information can be determined according to at least one of the following conditions. : Whether the portrait picture from the user matches the user, whether the voiceprint information from the user matches the user, whether the fingerprint information from the user matches the user, and the like.
  • the risk coefficient is determined according to whether the portrait picture from the user A matches the user. It can be determined according to whether the portrait picture from the user A matches the user A (that is, whether the portrait picture from the user A is the user A or not), and the possibility that the uploaded biometric information is qualified is determined according to the possibility that the biometric information is qualified. Risk factor.
  • the risk coefficient can be determined based on the voiceprint information from the user A. Specifically, it is determined whether the voiceprint information from the user A matches the user A (that is, whether the voiceprint information from the user A is From the user A himself, the possibility of the uploaded biometric information is determined, and the risk coefficient is determined according to the possibility that the biometric information is qualified.
  • the risk coefficient may be determined according to whether the fingerprint information from the user A matches the user. Specifically, according to whether the fingerprint information from the user is consistent with the user A (that is, whether the fingerprint information from the user A is from the user A), it is determined that the uploaded biometric information is qualified, and the possibility of passing the biometric information is qualified. Determine the risk factor.
  • the rights information may include a blacklist or a white list, and the rights information indicates to some extent that the user has been considered to be secure or secure, and therefore may be used in the evaluation. That is, in a case where the type of the information is the authority information, the risk coefficient corresponding to the authority information may be determined according to at least one of the following conditions: whether the user is restricted by the predetermined authority, whether the user is allowed to reserve the authority;
  • the risk coefficient can be determined according to whether the user A is restricted by the predetermined authority. If it is judged that the user A is not restricted to the predetermined authority, the risk coefficient is large; if it is judged that the user A is restricted by the predetermined authority, the risk coefficient is small.
  • the risk factor may be determined based on whether the user A is allowed to reserve power. If it is judged that the user A is not allowed to reserve the power, the risk coefficient is small; if it is judged that the user A is allowed to reserve the power, the risk coefficient is large.
  • the risk coefficient corresponding to the behavior information may be determined according to at least one of the following conditions: website information accessed by the user, network address information of the user, and operation behavior of the user.
  • the risk coefficient can be determined according to the website information accessed by user A. If user A has not visited an illegal website or has visited a website, the risk factor is large; if user A visits an illegal website or has not visited the website, there is a risk, and the risk factor is small.
  • the risk coefficient may also be determined according to the network address information of the user A. If the network address information of user A is not marked as having a risk or the like, the risk coefficient is large; if the network address information of user A is marked as having a risk, etc., the risk coefficient is small.
  • the risk factor may also be determined according to the user's operational behavior. If the user's operating behavior on the Internet is not risky, the risk factor is large; if the user's operational behavior on the Internet is at risk, the risk factor is small.
  • Step S206 comprehensively evaluating the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient.
  • a comprehensive risk assessment can be obtained based on the risk coefficient corresponding to each type of information obtained above. number.
  • the degree to which the identity of the user A is trusted (associating the collected risk coefficients corresponding to the information used by the user A for identity authentication to obtain a comprehensive risk coefficient), and finally determining whether the identity authentication of the user A passes.
  • the technical solution also improves the pass rate of the identity authentication, and the user does not have to repeat the identity authentication, thereby improving the user experience.
  • the user not only uploads a series of photo IDs, but also finds that the user is a real-name authenticated customer on a well-known website.
  • the user is authenticated by the real-name website as one of the user's behavior information on the Internet.
  • the identity photo and the user's behavior information on the Internet can be obtained from the user's comprehensive risk system for judging the user.
  • the first type the certificate information: the resolution of the uploaded document is 80%, the corresponding risk factor is 80% (indicating that the probability of the user being trusted is 80%); the completeness of the uploaded document is 55%, the corresponding risk coefficient It is 55% (indicating that the probability that the user is trusted is 55%).
  • the weight of the resolution of the pre-configured uploading document is 0.9, and the weight of the uploaded document completeness is 0.1.
  • the biological information the user's fingerprint is verified, and the verification is passed, and the corresponding risk coefficient is 100% (indicating that the probability that the user is trusted is 100%).
  • the user's behavior information on the Internet obtaining the user's Internet behavior information and discovering that the user is a real-name authentication user on the A website, and the acceptance degree of the A website information is 70%, the corresponding risk coefficient is 70% (indicating The probability that the user is trusted is 70%).
  • the certificate information, biological information and behavior information on the Internet can be comprehensively evaluated according to the pre-configured weights.
  • the weight of the document information is 0.4
  • the weight of the biological information is 0.4
  • the weight of the behavior information on the Internet is 0.2.
  • the higher the risk factor indicates the higher the degree to which the user is trusted.
  • Step S208 determining whether the identity authentication of the user passes according to the comprehensive risk coefficient.
  • the comprehensive risk coefficient it is judged whether the user's identity authentication is passed, and avoids the risk that the related technology is determined according to each identity authentication condition, whether the identity of the user is authenticated by the identity authentication, and the identity authentication decision is made. A problem that affects the user experience.
  • multiple types of information of the user to be authenticated are collected, wherein multiple types of information are used to authenticate the identity of the user;
  • the risk coefficient corresponding to each type of information in the information wherein the risk coefficient is used to indicate the degree to which the user's identity is trusted;
  • the risk coefficient corresponding to each type of information is comprehensively evaluated to obtain a comprehensive risk coefficient;
  • the purpose of the identity authentication accuracy is to achieve the technical effect of improving the user experience, and thereby solve the identity authentication caused by whether the user identity is independent of each other and no association is determined according to various identity authentication conditions in the related art.
  • the risk of making mistakes in decision-making is large, and the impact is Experience technical problems.
  • FIG. 3 is a flow chart showing a comprehensive evaluation of the risk coefficient corresponding to each type of information in the technical solution disclosed in the above step S206 to obtain a comprehensive risk coefficient. As shown in FIG. 3, the method further includes the following steps:
  • Step S302 the risk coefficient corresponding to each type of information is evaluated by the data model to obtain a comprehensive risk coefficient, wherein the data model is obtained according to the training set, and the training set includes the user and/or the identity authentication passed by the identity authentication.
  • the comprehensive risk coefficient corresponding to the user passed, the comprehensive risk coefficient corresponding to the user passing the identity authentication and/or the user whose identity authentication fails, is obtained according to the risk coefficient corresponding to each type of information of the user.
  • the data model mentioned in the embodiment of the present invention is obtained by training according to a training set, and the training set includes a comprehensive risk coefficient corresponding to the user passing the identity authentication, and the comprehensive risk coefficient corresponding to the user passing the identity authentication is according to each of the users.
  • the type of information corresponds to the risk factor obtained.
  • the training set includes: user B1, user B2, user B3, ... user Bn are users whose identity authentication passes, and at this time, according to the comprehensive risk coefficient of these users, it is determined which users can be authenticated.
  • the training set may further include: the training set includes a comprehensive risk coefficient corresponding to the user whose identity is not authenticated, and the comprehensive risk coefficient corresponding to the user whose identity is not authenticated is according to the The risk factor corresponding to each type of information of the user is obtained.
  • user C1, user C2, The user C3 ... the user Cn is a user whose identity authentication has not passed, and is trained according to the training set to obtain a data model.
  • the risk coefficient corresponding to each type of information is evaluated by the data model to obtain a comprehensive risk coefficient.
  • the risk coefficient corresponding to the user A's certificate information and/or the risk coefficient corresponding to the biometric information and/or the risk coefficient corresponding to the authority information are evaluated by the data model to obtain a comprehensive risk coefficient.
  • the risk coefficient corresponding to each type of information is evaluated by the data model to obtain a comprehensive risk coefficient. That is, the risk coefficient corresponding to each type of information is associated, which avoids the risk of error in the identity authentication decision caused by the independent identity and no association between the identity authentication, and improves the pass rate of the user's identity authentication. And the purpose of accuracy, thus achieving the technical effect of improving the user experience.
  • FIG. 4 is a flow chart showing comprehensive evaluation of the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient in the technical solution disclosed in the above step S206. As shown in FIG. 4, the method specifically includes the following steps:
  • Step S402 performing weighting and weight calculation on the risk coefficient corresponding to all types of information according to the risk coefficient and the weight corresponding to each type of information, to obtain a comprehensive risk coefficient, wherein the weight corresponding to each type of information may represent the species.
  • the weight corresponding to each type of information is pre-configured.
  • each type of information for authenticating a user is pre-set with a corresponding weight, or a training model of various types of information for authenticating a plurality of users is used to obtain a risk coefficient data model.
  • the risk coefficient data model obtains the weights corresponding to each type of information collected, and then weights and calculates the risk coefficients corresponding to all types of information according to the weights corresponding to each type of information obtained, to obtain a comprehensive risk. coefficient.
  • the weight of the certificate information of user A is 0.6
  • the weight of the biometric information is 0.25
  • the weight of the authority information is 0.15.
  • the weight and biometric corresponding to the document information are obtained.
  • the weight corresponding to the information and the weight corresponding to the authority information weight the sum of the risk coefficients corresponding to each type of information to obtain the comprehensive risk coefficient of the user A through identity authentication.
  • FIG. 5 is a flow chart showing the risk coefficient corresponding to each type of information in the plurality of types of information acquired in the technical solution disclosed in the above step S204. As shown in FIG. 5, the method specifically includes the following steps:
  • Step S502 Acquire a risk coefficient corresponding to each type of subtype, where the risk coefficient corresponding to the subtype includes at least one of the following: a risk coefficient corresponding to each subtype, and a wind corresponding to a combination of at least two subtypes Risk factor.
  • the type of information is document information
  • the subtype of the type is the number on the document, the picture, the expiration date, and the like.
  • the risk factor corresponding to the number on the document is 2
  • the risk coefficient corresponding to the picture on the document is 3
  • the risk factor corresponding to the validity period on the document is 1, etc.
  • the risk corresponding to the combination of the number on the document and the picture The coefficient is 3.5
  • the risk factor corresponding to the combination of the number on the document and the validity period is 2.5 and so on.
  • Step S504 Acquire a risk coefficient of the type information according to the risk coefficient corresponding to the subtype.
  • the type of information is document information
  • the subtype of the type is the number on the document, the picture, the expiration date, and the like.
  • the risk coefficient corresponding to the number on the document is 2
  • the risk coefficient corresponding to the picture on the certificate is 3
  • the risk coefficient corresponding to the validity period on the document is 1, the risk coefficient of the type information is obtained according to the risk coefficient corresponding to the subtype. Is 6.
  • the risk coefficient corresponding to each type of information is determined according to the risk coefficient of the subtype of different types of information, and the accuracy of obtaining the risk coefficient corresponding to each type of information is improved. It further balances the risk of users passing identity authentication and enhances the user experience.
  • FIG. 6 is a schematic diagram of an optional identity authentication method according to an embodiment of the present invention.
  • information such as a user uploaded certificate, a biometric feature, a user trajectory on the Internet, and a user access behavior on the Internet are shown.
  • the user is authenticated, and if the user's identity is authenticated, the user is authorized. For example, according to the clarity of the uploaded documents, the completeness of the documents and the complete validity of the documents, etc., it is judged whether the documents are qualified. If the documents are unqualified, the requirements are not met, and the identity authentication of the user fails, that is, the authentication cannot be performed. Further the Internet refuses to grant authorization to the user.
  • FIG. 7 is a schematic diagram of an optional identity authentication method according to an embodiment of the present invention.
  • information such as a user uploaded certificate, a biometric feature, a user trajectory on the Internet, and a user access behavior on the Internet are shown.
  • the user is authenticated, and if the user's identity is authenticated, the user is authorized. For example, based on the clarity of the uploaded document, the completeness of the document and the complete validity of the document, the portrait/voiceprint/other biometric definition in the biometrics of the person, the user has risk information on the Internet, etc.
  • the multi-dimensional feature fusion model determines whether all types of information used to authenticate the user identity are full according to the multi-dimensional feature fusion model
  • the identity authentication pass condition is granted to the user if the identity authentication pass condition is met; if the identity authentication pass condition is not met, the authorization is denied.
  • the dimension of authenticating the user is expanded, thereby improving the normal user identity authentication experience while covering more risks.
  • the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, by hardware, but in many cases, the former is A better implementation.
  • the technical solution of the present invention which is essential or contributes to the prior art, may be embodied in the form of a software product stored in a storage medium (such as ROM/RAM, disk,
  • the optical disc includes a number of instructions for causing a terminal device (which may be a cell phone, a computer, a server, or a network device, etc.) to perform the methods of various embodiments of the present invention.
  • an identity authentication apparatus is further provided. As shown in FIG. 8, the apparatus includes: an acquisition unit 100, a first acquisition unit 102, a second acquisition unit 104, and a determination unit 106.
  • the collecting unit 100 is configured to collect multiple types of information of the user to be authenticated, where multiple types of information are used to authenticate the identity of the user.
  • the collection unit 100 collects multiple types of information for authenticating the identity of the user.
  • user A (to be authenticated user) needs to establish a real-name account for himself on a certain website, so it needs to perform identity authentication on the Internet. After the identity authentication is passed, a website will authorize user A to open it. Real name account.
  • User A may upload some User A related materials in order to authenticate on the Internet.
  • the information in the related materials uploaded by the user A is collected, and the information includes the information for authenticating the user A. .
  • information for authenticating user A is also collected in the Internet. If some user A related materials are not uploaded, information for authenticating user A is collected in the Internet.
  • the type of information of the user includes the following at least One: certificate information, biometric information, permission information, and user behavior information on the Internet.
  • the related materials uploaded include at least one of the following: user A's certificate, user A's biometrics, and information collected by user A's related materials, including the documents in the uploaded document.
  • the user A's rights information in the Internet is collected. For example, it is determined whether the user A is in the Internet blacklist in the Internet. If the user A is in the blacklist, the user A's rights in the Internet may be restricted.
  • the behavior information of the user A on the Internet may be the access trajectory of the user A on the Internet. For example, according to the access trajectory of the user A on the Internet, it may be determined whether the operation of the user A on the Internet is at risk.
  • the first obtaining unit 102 is configured to acquire a risk coefficient corresponding to each type of information of the plurality of types of information, where the risk coefficient is used to indicate a degree of the user's identity being trusted.
  • the first obtaining unit 102 includes at least one of the following: a first determining module 1021, a second determining module 1022, a third determining module 1023, and a fourth determining module 1024. .
  • the first determining module 1021 is configured to determine, according to at least one of the following conditions, a risk coefficient corresponding to the document information: the document clarity, the document completeness, and the document validity, in the case that the type of the information is the document information.
  • the risk coefficient may be a coefficient value or a probability.
  • the first determining module 1021 determines the risk coefficient according to the definition of the uploaded ID of the user A. Specifically, if the resolution of the uploaded document is 80%, it is determined that the probability of the uploaded document being qualified is 80%, and the risk coefficient is determined to be 80% according to the possibility of the certificate being qualified. It should be noted that the clarity of the document can be obtained based on the possibility of successfully identifying the information in the document.
  • the first determining module 1021 determines the risk coefficient according to the completeness of the uploaded ID of the user A. Specifically, if the completeness of the uploaded document is 55%, the probability of determining the uploaded certificate is 55%. The risk factor is determined to be 55% based on the likelihood of the certificate being qualified. It should be noted that the completeness of the documents can be calculated by uploading the number and type of documents and the number and type of documents required to be uploaded.
  • the first determining module 1021 determines the risk coefficient according to the validity of the uploaded certificate of the user A. Specifically, if the validity of the uploaded document is 68%, the probability of determining that the uploaded document is qualified is 68%. The risk factor is determined to be 68% based on the likelihood of the certificate being qualified. It should be noted that the validity of the certificate can be determined according to the information in the identification of the uploaded document to determine whether it meets the preset requirements.
  • the second determining module 1022 is configured to: when the type of the information is biometric information, according to the following conditions At least one of determining the risk coefficient corresponding to the biometric information: whether the portrait image from the user matches the user, whether the voiceprint information from the user matches the user, and whether the fingerprint information from the user matches the user.
  • the second determining module 1022 determines the risk coefficient according to whether the portrait picture from the user A matches the user. Specifically, according to whether it is determined whether the portrait picture from the user A matches the user A (that is, whether the portrait picture from the user A is the user A or not), the possibility that the uploaded biometric information is qualified is determined, and the biometric information is qualified according to the possibility. Sex determines the risk factor.
  • the second determining module 1022 determines the risk factor based on the voiceprint information from the user A. Specifically, according to whether the voiceprint information from the user A is consistent with the user A (that is, whether the voiceprint information from the user A is from the user A), the possibility that the uploaded biometric information is qualified is determined, and the biometric information is qualified. The likelihood of determining the risk factor.
  • the second determining module 1022 determines the risk coefficient according to whether the fingerprint information from the user A matches the user. Specifically, according to whether the fingerprint information from the user is consistent with the user A (that is, whether the fingerprint information from the user A is from the user A), it is determined that the uploaded biometric information is qualified, and the possibility of passing the biometric information is qualified. Determine the risk factor.
  • the third determining module 1023 is configured to determine, according to at least one of the following conditions, a risk coefficient corresponding to the right information, according to at least one of the following conditions: whether the user is restricted by the predetermined power, and whether the user is allowed to reserve the power.
  • the third determining module 1023 determines the risk coefficient according to whether the user A is restricted by the predetermined authority. If it is judged that the user A is restricted by the predetermined authority, the risk coefficient is large; if it is judged that the user A is not restricted by the predetermined authority, the risk coefficient is small.
  • the third determining module 1023 determines the risk factor based on whether the user A is allowed to reserve power. If it is judged that user A is allowed to reserve power, the risk coefficient is small; if it is judged that user A is not allowed to reserve power, the risk coefficient is large.
  • the fourth determining module 1024 is configured to: when the type of the information is the behavior information of the user on the Internet, determine the risk coefficient corresponding to the behavior information according to at least one of the following conditions: website information accessed by the user, network address information of the user, User's operational behavior.
  • the fourth determining module 1024 determines the risk coefficient according to the website information accessed by the user A. If user A visits an illegal website or has visited a website, the risk factor is large; if user A has not visited an illegal website or has not visited the website, there is a risk factor, and the risk factor is small.
  • the fourth determining module 1024 determines the risk coefficient according to the network address information of the user A. If user A The network address information is marked as having a risk, etc., and the risk coefficient is large; if the user A's network address information is not marked as having a risk, etc., the risk coefficient is small.
  • the fourth determining module 1024 determines the risk coefficient according to the user's operating behavior. If the user's operating behavior on the Internet is at risk, the risk factor is large; if the user's operating behavior on the Internet is not risky, the risk factor is small.
  • the second obtaining unit 104 is configured to comprehensively evaluate the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient.
  • the second obtaining unit 104 performs comprehensive evaluation according to the risk coefficient corresponding to each type of information obtained above to obtain a comprehensive risk coefficient.
  • the determining unit 106 is configured to determine, according to the comprehensive risk coefficient, whether the identity authentication of the user passes.
  • the judging unit 106 judges whether the identity authentication of the user passes through the comprehensive risk coefficient, and avoids the risk of error in the identity authentication decision caused by whether the user identity is independent of each other and has no association according to each identity authentication condition in the related technology. Larger, affecting the user experience.
  • the identity card authentication may not necessarily fail when the user A is authenticated on the Internet, and the user A is authenticated by using the account book, the passport, and the like to perform a comprehensive evaluation.
  • the degree to which the identity of the user A is trusted (associating the collected risk coefficients corresponding to the information used by the user A for identity authentication to obtain a comprehensive risk coefficient), and finally determining whether the identity authentication of the user A passes.
  • the technical solution also improves the pass rate of the identity authentication, and the user does not have to repeat the identity authentication, thereby improving the user experience.
  • the collecting unit 100 can collect various types of information of the user to be authenticated, among which multiple The type of information is used to authenticate the identity of the user; the first obtaining unit 102 acquires a risk coefficient corresponding to each type of information of the plurality of types of information, wherein the risk coefficient is used to indicate the degree to which the identity of the user is trusted; The second obtaining unit 104 comprehensively evaluates the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient; the determining unit 106 determines, according to the comprehensive risk coefficient, whether the user's identity authentication passes, thereby each type The risk coefficient corresponding to the information is correlated, which avoids the risk of error in the identity authentication decision caused by the independent and unrelated relationship between the identity authentication, and achieves the purpose of improving the accuracy of the user's identity authentication, thereby improving the user.
  • the technical effect of the experience further solves the problem that the risk of error
  • the foregoing collecting unit 100, the first obtaining unit 102, the second obtaining unit 104, and the determining unit 106 correspond to steps S202 to S208 in Embodiment 1, and the four units are implemented by corresponding steps.
  • the example and the application scenario are the same, but are not limited to the content disclosed in the first embodiment.
  • the above module can be operated as part of the device in the computer terminal 10 provided in the first embodiment.
  • the second obtaining unit 104 is further configured to: use the data model to evaluate the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient, where the data model is based on The training set is obtained by training, and the training set includes a comprehensive risk coefficient corresponding to the user passing the identity authentication and/or the user whose identity authentication fails, and the comprehensive risk coefficient corresponding to the user who passes the identity authentication and/or the user whose identity authentication fails is Obtained according to the risk coefficient corresponding to each type of information of the user.
  • the data model mentioned in the embodiment of the present invention is obtained by training according to a training set, where the training set includes a comprehensive risk coefficient corresponding to the user passing the identity authentication and/or the user whose identity authentication fails, and the user and/or the identity authentication pass.
  • the comprehensive risk coefficient corresponding to the user whose identity authentication fails is obtained according to the risk coefficient corresponding to each type of information of the user.
  • the training set includes: user B1, user B2, user B3, ... user Bn is a user whose identity authentication passes, user C1, user C2, user C3, ... user Cn is a user whose identity authentication fails, and is trained according to the training set.
  • Get the data model The risk coefficient corresponding to each type of information is evaluated by the data model to obtain a comprehensive risk coefficient.
  • the risk coefficient corresponding to the user A's certificate information and/or the risk coefficient corresponding to the biometric information and/or the risk coefficient corresponding to the authority information are evaluated by the data model to obtain a comprehensive risk coefficient.
  • the risk coefficient corresponding to each type of information is evaluated by the data model to obtain a comprehensive risk coefficient. That is, the risk coefficient corresponding to each type of information is associated, which avoids the risk of error in the identity authentication decision caused by the independent identity and no association between the identity authentication, and improves the pass rate of the user's identity authentication. And the purpose of accuracy, thus achieving the technical effect of improving the user experience.
  • the above-mentioned code second obtaining unit 104 corresponds to the step S206 in the first embodiment, and the three modules are the same as the example and the application scenario implemented by the corresponding steps, but are not limited to the one disclosed in the first embodiment. content. It should be noted that the above module can be operated as a part of the device in the computer terminal provided in the first embodiment. 10 in.
  • the second obtaining unit 104 is further configured to perform weighting and calculation on the risk coefficient corresponding to all types of information according to the risk coefficient and the weight corresponding to each type of information. , get a comprehensive risk factor.
  • each type of information for authenticating the user is preset with a corresponding weight, or the second obtaining unit 104 performs training for learning according to various types of information for performing identity authentication on multiple users.
  • the coefficient data model obtains the weights corresponding to each type of information collected by the risk coefficient data model, and then weights the risk coefficients corresponding to all types of information according to the weights corresponding to each type of information obtained. Calculate and get the comprehensive risk factor.
  • the weight of the certificate information of user A is 0.6
  • the weight of the biometric information is 0.25
  • the weight of the authority information is 0.15.
  • the weight and biometric corresponding to the document information are obtained.
  • the weight corresponding to the information and the weight corresponding to the authority information weight the sum of the risk coefficients corresponding to each type of information to obtain the comprehensive risk coefficient of the user A through identity authentication.
  • the first obtaining unit 102 further includes: a first acquiring module, configured to acquire a risk coefficient corresponding to each type of subtype, where the risk corresponding to the subtype The coefficient includes at least one of the following: a risk coefficient corresponding to each subtype, and a risk coefficient corresponding to a combination of at least two subtypes; and a second obtaining module, configured to obtain a risk coefficient of the type information according to the risk coefficient corresponding to the subtype.
  • the risk coefficient corresponding to each type of information is determined according to the risk coefficient of the subtype of different types of information, and the accuracy of obtaining the risk coefficient corresponding to each type of information is improved. It further balances the risk of users passing identity authentication and enhances the user experience.
  • the above unit can be operated in the computer terminal 10 provided in the first embodiment as a part of the device.
  • FIG. 9 is a schematic diagram of a computing device according to an embodiment of the present invention. As shown in FIG. 9, the computing device 100 provides a first interface 110.
  • the first interface 110 includes: a plurality of first controls 111, configured to collect multiple types of information of the user to be authenticated, and multiple types of information are used to authenticate the identity of the user; the first sending unit is configured to Various types The information is sent to the server, and the risk coefficient of the plurality of types of information is evaluated by the server to obtain a comprehensive risk coefficient, wherein the risk coefficient is used to indicate the degree of trust of the user's identity; and the second receiving unit is configured to receive the information sent by the server.
  • a risk coefficient corresponding to the plurality of types of information and an integrated risk coefficient
  • a plurality of second controls 121 corresponding to the plurality of first controls, configured to represent risk coefficients corresponding to each type of information
  • a third control 122 configured to: Reflects the comprehensive risk factor of the user to be authenticated.
  • the plurality of second controls 121 embody the risk coefficients corresponding to the plurality of types of information such as the document risk coefficient and the fingerprint risk coefficient, and pass through the plurality of third controls 122 .
  • the comprehensive risk factor is reflected, and the user can view the above information to further improve the technical effect of the user experience.
  • multiple types of information are used to authenticate the user, and multiple types of information of the user to be authenticated are collected by the plurality of first controls 111, and multiple types of information are used for the user.
  • the identity is authenticated; the first sending unit sends multiple types of information to the server, and the risk coefficient of the plurality of types of information is evaluated by the server to obtain a comprehensive risk coefficient, wherein the risk coefficient is used to indicate that the identity of the user is trusted.
  • a second receiving unit configured to receive a risk coefficient corresponding to the plurality of types of information sent by the server, and a comprehensive risk coefficient; and the plurality of second controls 121 corresponding to the plurality of first controls correspond to each type of information
  • the risk coefficient; the third control 122 reflects the comprehensive risk coefficient of the user to be authenticated, and associates the risk coefficient corresponding to each type of information, thereby avoiding the risk of error in the identity authentication decision caused by the independent identity and no association between the identity authentication.
  • the third control reflects the comprehensive risk coefficient of the user to be authenticated, so that the user can view the relevant information, further improving the technical effect of the user experience, and thus solving the problem according to the relevant technology.
  • Each identity authentication condition determines whether the identity of the user is independent of each other, and there is no risk of an error in the identity authentication decision caused by the association, which affects the technical problem of the user experience.
  • Embodiments of the present invention may provide a computer terminal, which may be any one of computer terminal groups.
  • the foregoing computer terminal may also be replaced with a terminal device such as a mobile terminal.
  • the computer terminal may be located in at least one network device of the plurality of network devices of the computer network.
  • the computer terminal may execute the program code of the following steps in the identity authentication method of the application: collecting multiple types of information of the user to be authenticated, wherein multiple types of information are used to identify the identity of the user. Authentication; access to the risk factor corresponding to each type of information in multiple types of information, where risk The coefficient is used to indicate the degree to which the user's identity is trusted; the risk coefficient corresponding to each type of information is comprehensively evaluated to obtain a comprehensive risk coefficient; and the user's identity authentication is determined according to the comprehensive risk coefficient.
  • FIG. 10 is a structural block diagram of a computer terminal according to an embodiment of the present invention.
  • the computer terminal 10 can include one or more (only one shown) processor and memory.
  • the memory can be used to store software programs and modules, such as the security vulnerability detection method and the program instruction/module corresponding to the device in the embodiment of the present invention.
  • the processor executes various functions by running a software program and a module stored in the memory.
  • Application and data processing that is, the detection method for implementing the above system vulnerability attack.
  • the memory may include a high speed random access memory, and may also include non-volatile memory such as one or more magnetic storage devices, flash memory, or other non-volatile solid state memory.
  • the memory can further include memory remotely located relative to the processor, which can be connected to the terminal 10 over a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
  • the processor may invoke the information and the application stored by the memory through the transmission device to perform the following steps: collecting multiple types of information of the user to be authenticated, wherein multiple types of information are used to authenticate the identity of the user; a risk coefficient corresponding to each type of information in the plurality of types of information, wherein the risk coefficient is used to indicate the degree to which the user's identity is trusted; and comprehensively evaluating the risk coefficient corresponding to each type of information to obtain a comprehensive risk coefficient; According to the comprehensive risk coefficient, it is judged whether the user's identity authentication is passed.
  • the foregoing processor may further execute the following program code: the risk coefficient corresponding to each type of information is evaluated by using a data model to obtain a comprehensive risk coefficient, wherein the data model is obtained according to the training set, and the training is performed.
  • the set includes a comprehensive risk factor corresponding to the user passing the identity authentication and/or the user whose identity authentication fails, and the comprehensive risk coefficient corresponding to the user who passes the identity authentication and/or the user whose identity authentication fails is according to each type of the user.
  • the risk coefficient corresponding to the information is obtained.
  • the foregoing processor may further execute the following program code: weighting and calculating the risk coefficient corresponding to all types of information according to the risk coefficient and the weight corresponding to each type of information, to obtain a comprehensive risk coefficient.
  • the processor may further execute the following program code: the type of the user information includes at least one of the following: certificate information, biometric information, rights information, and behavior information of the user on the Internet.
  • the foregoing processor may further execute the following program code: when the type of the information is the certificate information, determine the risk coefficient corresponding to the document information according to at least one of the following conditions: the document clarity, the document completeness, The validity of the document; in the case where the type of the information is biometric information, the risk coefficient corresponding to the biometric information is determined according to at least one of the following conditions: whether the portrait image from the user matches the user, and is from the user Whether the voiceprint information is consistent with the user, whether the fingerprint information from the user is consistent with the user; if the type of the information is the rights information, determining the risk coefficient corresponding to the rights information according to at least one of the following conditions: whether the user is restricted in the predetermined power Whether the user is allowed to reserve power; if the type of the information is behavior information of the user on the Internet, the risk coefficient corresponding to the behavior information is determined according to at least one of the following conditions: website information accessed by the user, network address information of the user, User's operational behavior.
  • the foregoing processor may further execute the following program code: obtaining a risk coefficient corresponding to each type of information in the multiple types of information, including: acquiring a risk coefficient corresponding to each type of subtype, where, The risk coefficient corresponding to the type includes at least one of the following: a risk coefficient corresponding to each subtype, and a risk coefficient corresponding to a combination of at least two subtypes; and obtaining a risk coefficient of the type information according to the risk coefficient corresponding to the subtype.
  • An embodiment of the present invention provides a solution for identity authentication. Collecting multiple types of information of the user to be authenticated, wherein multiple types of information are used to authenticate the identity of the user; and acquiring a risk coefficient corresponding to each type of information in the plurality of types of information, wherein the risk The coefficient is used to indicate the degree to which the user's identity is trusted; the risk coefficient corresponding to each type of information is comprehensively evaluated to obtain a comprehensive risk coefficient; and the comprehensive risk coefficient is used to determine whether the user's identity authentication is passed, thereby corresponding to each type of information.
  • the risk factors are related to each other, which avoids the risk of error in the identity authentication decision caused by the independent and unrelated relationship between the identity authentication, and achieves the purpose of improving the accuracy of the user's identity authentication, thereby improving the user experience.
  • the technical effect further solves the technical problem that the risk of error in the identity authentication decision caused by the identification of the user identity according to each identity authentication condition according to each identity authentication condition is independent and without any association, and affects the user experience.
  • FIG. 10 is merely illustrative, and the computer terminal can also be a smart phone (such as an Android mobile phone, an iOS mobile phone, etc.), a tablet computer, an applause computer, and a mobile Internet device (Mobile Internet Devices, MID). ), PAD and other terminal devices.
  • FIG. 10 does not limit the structure of the above electronic device.
  • computer terminal 10 may also include more or fewer components (such as a network interface, display device, etc.) than shown in FIG. 10, or have a different configuration than that shown in FIG.
  • Embodiments of the present invention also provide a storage medium.
  • the foregoing storage medium may be used to save the program code executed by the identity authentication method provided in Embodiment 1 above.
  • the foregoing storage medium may be located in any one of the computer terminal groups in the computer network, or in any one of the mobile terminal groups.
  • the storage medium is configured to store program code for performing the following steps: collecting multiple types of information of the user to be authenticated, wherein multiple types of information are used for the identity of the user Performing authentication; obtaining a risk coefficient corresponding to each type of information in the plurality of types of information, wherein the risk coefficient is used to indicate the degree of trust of the user's identity; and comprehensively evaluating the risk coefficient corresponding to each type of information Comprehensive risk coefficient; judge whether the user's identity authentication passes according to the comprehensive risk coefficient.
  • the storage medium is configured to store program code for performing the following steps: evaluating the risk coefficient corresponding to each type of information by using a data model to obtain a comprehensive risk coefficient, wherein the data model is According to the training set, the training set includes the comprehensive risk coefficient corresponding to the user passing the identity authentication and/or the user whose identity authentication fails, and the comprehensive risk coefficient corresponding to the user passing the identity authentication and/or the user whose identity authentication fails. It is obtained based on the risk coefficient corresponding to each type of information of the user.
  • the storage medium is configured to store program code for performing the following steps: weighting the risk coefficient corresponding to all types of information according to the risk coefficient and the weight corresponding to each type of information Calculate and get the comprehensive risk factor.
  • the storage medium is configured to store program code for performing the following steps: the type of information of the user includes at least one of the following: certificate information, biometric information, rights information, and the user on the Internet. Behavioral information.
  • the storage medium is configured to store program code for performing the following steps: in case the type of the information is the document information, determining the risk coefficient corresponding to the document information according to at least one of the following conditions: : document clarity, document completeness, and document validity; in the case where the type of the information is biometric information, the risk coefficient corresponding to the biometric information is determined according to at least one of the following conditions: whether the portrait image from the user matches the user Whether the voiceprint information from the user is consistent with the user, whether the fingerprint information from the user is consistent with the user; if the type of the information is the rights information, determining the risk coefficient corresponding to the rights information according to at least one of the following conditions: The predetermined power is restricted, the user is allowed to reserve the power; and in the case where the type of the information is the behavior information of the user on the Internet, the risk coefficient corresponding to the behavior information is determined according to at least one of the following conditions: the website information accessed by the user, the user's Network address information, user's operating behavior
  • the storage medium is configured to store program code for performing the following steps: acquiring risk coefficients corresponding to each type of information of the plurality of types of information includes: acquiring each type of sub- The risk coefficient corresponding to the type, wherein the risk coefficient corresponding to the subtype includes at least one of the following: each subtype corresponds to The risk coefficient, the risk coefficient corresponding to the combination of at least two subtypes; and the risk coefficient of the type information according to the risk coefficient corresponding to the subtype.
  • the disclosed technical contents may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • multiple units or components may be combined or may be Integrate into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, unit or module, and may be electrical or otherwise.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention which is essential or contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product stored in a storage medium.
  • a number of instructions are included to cause a computer device (which may be a personal computer, server or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a removable hard disk, a magnetic disk, or an optical disk, and the like. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Databases & Information Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Data Mining & Analysis (AREA)
  • Social Psychology (AREA)
  • Biomedical Technology (AREA)
  • Collating Specific Patterns (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本发明公开了一种身份认证方法及装置和计算设备。其中,该方法包括:采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过。本发明解决了由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。

Description

身份认证方法及装置和计算设备
本申请要求2016年11月30日递交的申请号为201611089354.3、发明名称为“身份认证方法及装置和计算设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及互联网技术领域,具体而言,涉及一种身份认证方法及装置和计算设备。
背景技术
身份认证也称为“身份验证”或“身份鉴别”,是指在计算机及计算机网络系统中确认操作者身份的过程,从而确定该用户是否具有对某种资源的访问和使用权限,进而使计算机和网络系统的访问策略能够可靠、有效地执行,防止攻击者假冒合法用户获得资源的访问权限,保证系统和数据的安全,以及授权访问者的合法利益。对于互联网身份认证,通常是根据身份认证条件认定用户身份,从而对通过所有身份认证条件的用户进行授权。例如,身份认证条件为身份证信息,根据输入的身份证信息即可判定用户是否通过身份认证。再例如,身份认证条件为用户的人脸信息,根据用户的人脸信息即可判定用户是否通过身份认证。也即,相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联,因此身份认证决策时出错的风险较大,影响用户体验。
针对上述的问题,目前尚未提出有效的解决方案。
发明内容
本发明实施例提供了一种身份认证方法及装置和计算设备,以至少解决由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。
根据本发明实施例的一个方面,提供了一种身份认证方法,该方法包括:采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过。
根据本发明实施例的另一方面,还提供了一种身份认证装置,该装置包括:采集单元,用于采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;第一获取单元,用于获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;第二获取单元,用于对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;判断单元,用于根据综合风险系数判断用户的身份认证是否通过。
根据本发明实施例的另一方面,还提供了一种计算设备,提供第一界面,用于用户交互;其中,第一界面包括:多个第一控件,用于采集待身份认证用户的多种类型的信息,多种类型的信息用于对用户的身份进行认证;第一发送单元,用于将多种类型的信息发送至服务器,通过服务器对多种类型的信息的风险系数进行评估,得到综合风险系数,其中,风险系数用于指示用户的身份被信任的程度;第二接收单元,用于接收服务器发送的与多种类型的信息对应的风险系数以及综合风险系数;与多个第一控件对应的多个第二控件,用于体现每种类型的信息对应的风险系数;第三控件,用于体现待身份认证用户的综合风险系数。
在本发明实施例中,采用多种类型的信息对用户进行身份认证的方式,通过采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过,从而将每种类型的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证准确性的目的,从而实现了提升用户体验度的技术效果,进而解决了由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。
附图说明
此处所说明的附图用来提供对本发明的进一步理解,构成本申请的一部分,本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1是根据本发明实施例的一种可选的身份认证方法的计算机终端的硬件结构框图;
图2是根据本发明实施例的一种身份认证方法的流程图;
图3是根据本发明实施例的一种可选的身份认证方法的流程图;
图4是根据本发明实施例的一种可选的身份认证方法的流程图;
图5是根据本发明实施例的一种可选的身份认证方法的流程图;
图6是根据本发明实施例的一种可选的身份认证方法的示意图;
图7是根据本发明实施例的一种可选的身份认证方法的示意图;
图8是根据本发明实施例的一种身份认证装置的示意图;
图9是根据本发明实施例的一种计算设备的示意图;以及
图10是根据本发明实施例的一种可选的计算机终端的结构框图。
具体实施方式
为了使本技术领域的人员更好地理解本发明方案,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分的实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本发明保护的范围。
需要说明的是,本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本发明的实施例能够以除了在这里图示或描述的那些以外的顺序实施。此外,术语“包括”和“具有”以及他们的任何变形,意图在于覆盖不排他的包含,例如,包含了一系列步骤或单元的过程、方法、系统、产品或设备不必限于清楚地列出的那些步骤或单元,而是可包括没有清楚地列出的或对于这些过程、方法、产品或设备固有的其它步骤或单元。
实施例1
本发明实施例提供了一种身份认证方法实施例。该身份认证方法可以使用到在互联网中对用户的身份认证上,例如,在金融相关的应用中,用户注册到该应用当中之后,需要确认用户的身份,如果用户仅仅上传一张图片其实并不足以认为该张照片是这个用户拍摄的自己的照片,这是由于用户完全可以从互联网上下载照片进行冒充。如果采集用户的多种类型的信息,则可以降低这种风险。当采集到用户的多种类型的信息时,则对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数 判断用户的身份认证是否通过。
以下的方案可以实施到安装在移动终端的应用中,即可以通过移动终端的应用来判断用户的身份认证是否通过。
以下的方案也可以实施到服务器上,例如,应用或者软件可以仅仅作为获取照片的一个接口,用户可以通过应用或软件上传照片,然后,应用或者软件将这些照片传送至服务器,由服务器进行判断。服务器的计算能力是要强于应用本身的,因此,在服务器上进行使用可以同时对来自不同应用或软件的大量的照片进行处理。服务器可以是真实的硬件服务器,也可以是一种服务。随着云计算的发展,这种服务也可以安置在云服务上进行处理。
无论是在终端上实施还是在服务器上实施,以下方案的识别结果都可以被其他的应用或者服务所使用。总之,根据对用户的身份进行认证的多种类型的信息来对用户进行身份认证可以实施到多种情况中,在此不再一一介绍。
在下文中首先对实施本申请实施例方案的移动终端、计算机、服务器等硬件结果进行说明。以下所说明的硬件结构是当前比较通用的硬件结构,随着技术的发展,这些硬件结构会发生变化,无论怎样的硬件结构只要能够实施本申请实施例中的方案就可以实现判断用户的身份认证是否通过。
本申请实施例一所提供的身份认证方法实施例可以在移动终端、计算机终端或者类似的运算装置中执行。图1示出了一种用于实现身份认证方法的计算机终端(或移动设备)的硬件结构框图。如图1所示,计算机终端10(或移动设备10)可以包括一个或多个(图中采用102a、102b,……,102n来示出)处理器102(处理器102可以包括但不限于微处理器MCU或可编程逻辑器件FPGA等的处理装置)、用于存储数据的存储器104、以及用于通信功能的传输模块。除此以外,还可以包括:显示器、输入/输出接口(I/O接口)、通用串行总线(USB)端口(可以作为I/O接口的端口中的一个端口被包括)、网络接口、电源和/或相机。本领域普通技术人员可以理解,图1所示的结构仅为示意,其并不对上述电子装置的结构造成限定。例如,计算机终端10还可包括比图1中所示更多或者更少的组件,或者具有与图1所示不同的配置。
应当注意到的是上述一个或多个处理器102和/或其他数据处理电路在本文中通常可以被称为“数据处理电路”。该数据处理电路可以全部或部分的体现为软件、硬件、固件或其他任意组合。此外,数据处理电路可为单个独立的处理模块,或全部或部分的结合到计算机终端10(或移动设备)中的其他元件中的任意一个内。如本申请实施例中所 涉及到的,该数据处理电路作为一种处理器控制(例如与接口连接的可变电阻终端路径的选择)。
存储器104可用于存储应用软件的软件程序以及模块,如本发明实施例中的身份认证方法对应的程序指令/数据存储装置,处理器102通过运行存储在存储器104内的软件程序以及模块,从而执行各种功能应用以及数据处理,即实现上述的身份认证方法。存储器104可包括高速随机存储器,还可包括非易失性存储器,如一个或者多个磁性存储装置、闪存、或者其他非易失性固态存储器。在一些实例中,存储器104可进一步包括相对于处理器102远程设置的存储器,这些远程存储器可以通过网络连接至计算机终端10。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
传输装置用于经由一个网络接收或者发送数据。上述的网络具体实例可包括计算机终端10的通信供应商提供的无线网络。在一个实例中,传输装置106包括一个网络适配器(Network Interface Controller,NIC),其可通过基站与其他网络设备相连从而可与互联网进行通讯。在一个实例中,传输装置可以为射频(Radio Frequency,RF)模块,其用于通过无线方式与互联网进行通讯。
显示器可以例如触摸屏式的液晶显示器(LCD),该液晶显示器可使得用户能够与计算机终端10(或移动设备)的用户界面进行交互。
此处需要说明的是,在一些可选实施例中,上述图1所示的计算机设备(或移动设备)可以包括硬件元件(包括电路)、软件元件(包括存储在计算机可读介质上的计算机代码)、或硬件元件和软件元件两者的结合。应当指出的是,图1仅为特定具体实例的一个实例,并且旨在示出可存在于上述计算机设备(或移动设备)中的部件的类型。
在上述运行环境下,本申请提供了如图2所示的身份认证方法,该方法具体包括如下步骤:
步骤S202,采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证。
在很多场景下需要在互联网上对用户进行身份认证。为了对待身份认证用户进行身份认证,首先采集对该用户的身份进行身份认证的多种类型的信息。
例如,用户A(待身份认证用户)为了在某网站上为自己开设一实名账户,因此需要在互联网上进行身份认证,待身份认证通过之后,某网站才会对用户A进行授权,为其开设实名账户。通常,用户A为了在互联网上进行身份认证,可能会上传一些用户A的相关材料。对于互联网端,为了对用户A的身份进行认证,在上传了一些用户A的相 关材料的情况下,采集用户A上传的相关材料中的信息,该信息中包括对用户A的进行身份认证的信息。同时也在互联网中采集可对用户A的进行身份认证的信息。如果未上传一些用户A的相关材料,则在互联网中采集可对用户A的进行身份认证的信息。
在一种可选的实施例中,用户的信息的类型包括以下至少之一:证件信息、生物特征信息、权限信息、用户在互联网上的行为信息。
再以用户A为例,上传的相关材料中包括以下至少之一:用户A的证件、用户A的生物特征,采集用户A上传的相关材料中的信息,该信息中包括上传的证件中的证件信息,上传的用户A的生物特征中的生物特征信息。
采集用户A在互联网中的权限信息,例如,判断在互联网中用户A是否在互联网黑名单中,如果用户A在黑名单中,那么用户A的在互联网中的权利会被限制。
用户A在互联网上的行为信息可以为用户A在互联网上的访问轨迹,例如,根据用户A在互联网上的访问轨迹可以确定用户A在互联网上的操作是否存在风险。
步骤S204,获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度。风险系数可以是从正向进行评估的系数,此时风险系数数值越大,用户的身份被信任的程度越高,用户的身份被认证通过之后风险越低;风险系数也可以是从反向进行评估的系数,此时风险系数数值越大,用户的身份被信任的程度越低,用户的身份被认证通过之后风险越高。
用户信息的类型可能有很多种,作为一个可选的实施例,用户的信息的类型可以包括以下至少之一:证件信息、生物特征信息、权限信息、用户在互联网上的行为信息。在这几种信息中,用户在互联网上的行为信息是比较优的一种信息,通过用户的行为信息也可以作为对用户进行评估的一种参考,这在下文中将举例说明。
在上述几种信息中,证件信息是比较重要的一个信息,对于证件信息的评估可以采用多个维度,例如,在一个可选的实施方式中,可以根据如下条件的至少之一确定证件信息对应的风险系数:证件清晰度、证件齐全度、证件有效性。证件清晰度可以用来判断该证件是否是从网上下载的证件,而并非是用户拍摄的证件照片;证件的齐全度可以用作综合的评估,比如只有身份证照片并足以说明用户上传的身份证照片就是他自己,如果用户上传了身份证和驾照,那么该用户作假的风险就降低很多了。证件的有效性可以用来验证该证件是否仍然有效,这对于判断该用户作假的风险也有所帮助。当然,证件信息并不限于此,上述的这几种证件信息可以单独使用也可以组合使用,只要能够评估用户的风险系数即可。
需要说明的是,风险系数可以为系数值,也可以为概率。
例如,针对证件清晰度,以用户A为例,根据用户A的上传的证件的清晰度确定风险系数。如果使用概率来表示的话,100%认为是用户证件照是清晰的,完全没有风险。照片清晰程度可以使用照片的一些参数来进行限定,例如照片的像素、照片的大小等等,现有的一些照片清晰度的算法可以应用在本实施例中,在此不再赘述。如过上传的证件的清晰度为80%,则确定上传的证件合格的可能性为80%,根据证件合格的可能性确定风险系数为80%。需要说明的是,证件的清晰度可以根据对证件中的信息进行成功识别的可能性得到。作为另一个可选的实施方式,使用证件不合格的概率来表示风险系数,在本例子中,风险系数也可以认为是100%-80%=20%。如论从正相关的角度还是从负相关的角度来定义风险系统,均可以取得相应的技术效果,在实施时,可以根据实际需要来进行选择。以下实施例中列举的风险系数也可以从正相关和负相关两种角度来进行定义,在下文中不再一一赘述。
又例如,针对证件齐全度,可以根据用户A的上传的证件的齐全度确定风险系数,具体地,如上传的证件的齐全度为55%,则确定上传的证件合格的可能性为55%,根据证件合格的可能性确定风险系数55%。需要说明的是,证件的齐全度可以通过上传证件的数量和类型与要求上传证件的数量和类型进行计算得到。
又例如,针对证件有效性,可以根据用户A的上传的证件的有效性确定风险系数,具体地,如上传的证件的有效性为68%,则确定上传的证件合格的可能性为68%,根据证件合格的可能性确定风险系数为68%。需要说明的是,证件的有效性可以根据识别上传的证件中的信息判断是否符合预设要求得到。
生物信息也是比较重要的信息,在对用户进行评估的时候也可以参考使用,例如,在信息的类型为生物特征信息的情况下,可以根据如下条件的至少之一确定生物特征信息对应的风险系数:来自用户的人像图片是否与用户相符、来自用户的声纹信息是否与用户相符、来自用户的指纹信息是否与用户相符等。
再以用户A为例,根据来自用户A的人像图片是否与用户相符确定风险系数。可以根据判断来自用户A的人像图片是否与用户A相符(也即来自用户A的人像图片是否是用户A本人),确定上传的生物特征信息合格的可能性,根据生物特征信息合格的可能性确定风险系数。
又例如,针对声纹信息,可以根据来自用户A的声纹信息确定风险系数。具体地,根据判断来自用户A的声纹信息是否与用户A相符(也即来自用户A的声纹信息是否 来自用户A本人),确定上传的生物特征信息合格的可能性,根据生物特征信息合格的可能性确定风险系数。
又例如,针对指纹信息,可以根据来自用户A的指纹信息是否与用户相符确定风险系数。具体地,根据判断来自用户的指纹信息是否与用户A相符(也即来自用户A的指纹信息是否来自用户A本人),确定上传的生物特征信息合格的可能性,根据生物特征信息合格的可能性确定风险系数。
权限信息可以包括类似于黑名单或者白名单,权限信息在某种程度上标识该用户已经被认为是安全或者安全的,因此,在评估时也可以使用。即在信息的类型为权限信息的情况下,可以根据如下条件的至少之一确定权限信息对应的风险系数:用户是否被限制预定权力、用户是否被允许预定权力;
再以用户A为例,可以根据用户A是否被限制预定权力确定风险系数。如果判断用户A未被限制预定权力,风险系数较大;如果判断用户A被限制预定权力,风险系数较小。
又例如,可以根据用户A是否被允许预定权力确定风险系数。如果判断用户A未被允许预定权力,风险系数较小;如果判断用户A被允许预定权力,风险系数较大。
随着大数据技术的发展,用户行为的获取成为可能,而用户的行为也可以作为对该用户进行评估的一种参考,例如,在信息的类型为用户在互联网上的行为信息的情况下,可以根据如下条件的至少之一确定行为信息对应风险系数:用户访问的网站信息、用户的网络地址信息、用户的操作行为。
再以用户A为例,可以根据用户A访问的网站信息确定风险系数。如果用户A未访问过非法网站或者访问过的网站存在风险,风险系数较大;如果用户A访问过非法网站或者未访问过的网站存在风险,风险系数较小。
又例如,还可以根据用户A的网络地址信息确定风险系数。如果用户A的网络地址信息未被标注过存在风险等等,风险系数较大;如果用户A的网络地址信息被标注过存在风险等等,风险系数较小。
又例如,还可以根据用户的操作行为确定风险系数。如果用户在互联网上的操作行为不存在风险,风险系数较大;如果用户在互联网上的操作行为存在风险,风险系数较小。
步骤S206,对每种类型的信息对应的风险系数进行综合评估得到综合风险系数。
可以根据上述得到的每种类型的信息对应的风险系数进行综合评估得到综合风险系 数。
再以用户A为例,用户A在互联网中上传了身份证、户口本、护照等等材料,如果身份证中的身份有效期已过期,在互联网中基于身份证对用户A进行身份认证时,导致身份证认证失败,不能通过身份认证。通过本发明中的技术方案,将身份证、户口本、护照等等材料综合进行考虑,根据各个材料中的信息评估用户A的身份被信任的程度,最后进行评估得到综合风险系数。也即,如果身份证中的身份有效期已过期,在互联网中对用户A进行身份认证时,身份证认证不一定失败,通过对户口本、护照等等材料对用户A进行身份认证,进行综合评估用户A的身份被信任的程度(将采集到的用户A的用于进行身份认证的信息对应的风险系数进行关联,得到综合风险系数),最后确定用户A的身份认证是否通过。通过本技术方案也提升了对身份认证的通过率,用户不必重复进行身份认证,从而提升用户体验。
又例如,用户不仅仅上传了一系列的证件照,还发现该用户在某知名网站是实名认证的客户,该用户被实名网站认证是作为该用户在互联网上的行为信息中的一种,通过证件照以及用户在互联网上的行为信息可以得到该用户的综合风险系统,用于对该用户进行判断。
下面结合一个例子进行说明
用户A用于认证的信息有三种:
第一种,证件信息:上传的证件的清晰度为80%,对应的风险系数为80%(表明该用户被信任的概率为80%);上传证件的齐全度为55%,对应的风险系数为55%(表明该用户被信任的概率为55%)。预先配置的上传证件的清晰度的权值为0.9,上传证件齐全度的权值为0.1,此时,证件信息对应的风险系数为0.8*0.9+0.55*0.1=0.72+0.055=0.772。
第二种,生物信息:验证了用户的指纹,并且验证通过,对应的风险系数为100%(表明该用户被信任的概率为100%)。
第三种,用户的互联网上行为信息:获取该用户的互联网行为信息发现该用户在A网站为实名认证用户,A网站信息的被接受程度为70%,则对应的风险系数为70%(表明该用户被信任的概率为70%)。
可以根据预先配置的权值来综合评估证件信息、生物信息和互联网上的行为信息,证件信息的权值为0.4,生物信息的权值为0.4,互联网上的行为信息的权值为0.2,此时综合风险系数为:0.772*0.4+1*0.4+0.7*0.2=0.3088+0.4+0.14=0.8488。
在这个例子中,风险系数越高表明该用户被信任的程度越高。
步骤S208,根据综合风险系数判断用户的身份认证是否通过。
通过综合风险系数判断用户的身份认证是否通过,避免了相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的问题。
基于上述实施例中步骤S202至步骤S208所公开的方案,可以获知采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过,从而将每种类型的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证准确性的目的,从而实现了提升用户体验的技术效果,进而解决了由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。
图3示出了在上述步骤S206所公开的技术方案中,对每种类型的信息对应的风险系数进行综合评估得到综合风险系数的流程图。如图3所示,该方法具体中还包括如下步骤:
步骤S302,将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数,其中,数据模型是根据训练集进行训练得到的,训练集包括身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数,身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
本发明实施例中提及的数据模型是根据训练集进行训练得到的,训练集包括身份认证通过的用户对应的综合风险系数,身份认证通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。例如,训练集中包括,用户B1、用户B2、用户B3……用户Bn为身份认证通过的用户,此时可以根据这些用户的综合风险系数来确定哪些用户是可以被认证通过的。
为了是训练集更加准确,在一个可选的实施方式中,训练集还可以包括训练集包括身份未认证通过的用户对应的综合风险系数,身份未认证通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。例如,用户C1、用户C2、 用户C3……用户Cn为身份认证未通过的用户,根据训练集进行训练得到数据模型。将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数。例如,根据用户A的证件信息对应的风险系数和/或生物特征信息对应的风险系数和/或权限信息对应的风险系数通过数据模型进行评估得到综合风险系数。
通过本方案,将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数。也即,将每种类型的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证的通过率和准确性的目的,从而实现了提升用户体验的技术效果。
图4示出了在上述步骤S206所公开的技术方案中,对每种类型的信息对应的风险系数进行综合评估得到综合风险系数的流程图。如图4所示,该方法具体包括如下步骤:
步骤S402,根据每种类型的信息对应的风险系数以及权值对所有类型的信息对应的风险系数进行加权和计算,得到综合风险系数,其中,每种类型的信息对应的权值可以表示该种类型的信息对综合风险系数的影响,一个可选的实施方式中,每种类型的信息对应的权值为预先配置的。
在本发明实施例中,对用户进行身份认证的每种类型的信息预先设置对应的权值,或者根据对多个用户进行身份认证的各种类型的信息进行训练学习得到风险系数数据模型,通过该风险系数数据模型获取采集到的每种类型的信息对应的权值,然后根据获取到的每种类型的信息对应的权值对所有类型的信息对应的风险系数进行加权和计算,得到综合风险系数。
例如,用户A的证件信息对应的权值为0.6,生物特征信息对应的权值为0.25,权限信息对应的权值为0.15,在获取综合风险系数时,根据证件信息对应的权值、生物特征信息对应的权值、权限信息对应的权值对各类型的信息对应的风险系数进行加权求和得到用户A通过身份认证的综合风险系数。
通过本方案,充分考虑了不同类型的信息对用户身份认证的重要程度和影响程度,通过不同类型的信息对应的权值对各类型的信息对应的风险系数进行加权求和,得到综合风险系数。进一步地平衡了用户通过身份认证的风险和提升了用户的体验。
图5示出了在上述步骤S204所公开的技术方案中,获取多种类型的信息中的每种类型的信息对应的风险系数的流程图。如图5所示,该方法具体包括如下步骤:
步骤S502,获取每种类型的子类型对应的风险系数,其中,子类型对应的风险系数包括以下至少之一:每个子类型分别对应的风险系数、至少两个子类型的组合对应的风 险系数。
例如,信息的类型为证件信息,该类型的子类型为证件上的号码、图片、有效期等等。如,证件上的号码对应的风险系数为2,证件上的图片对应的风险系数为3,证件上的有效期对应的风险系数为1等等,或者,证件上的号码与图片的组合对应的风险系数为3.5,证件上的号码与有效期的组合对应的风险系数为2.5等等。
步骤S504,根据子类型对应的风险系数获取该类型信息的风险系数。
例如,信息的类型为证件信息,该类型的子类型为证件上的号码、图片、有效期等等。如,证件上的号码对应的风险系数为2,证件上的图片对应的风险系数为3,证件上的有效期对应的风险系数为1,则根据子类型对应的风险系数获取该类型信息的风险系数为6。
通过本方案,根据不同类型的信息的子类型的风险系数,确定每种类型的信息对应的风险系数,提升了获取每种类型的信息对应的风险系数的准确性。进一步地平衡了用户通过身份认证的风险和提升了用户的体验。
图6是根据本发明实施例的一种可选的身份认证方法的示意图,如图6所示,通过用户上传的证件、本人生物特征、在互联网上用户轨迹和在互联网上用户访问行为等信息对用户进行身份认证,如果用户的身份认证通过,对用户进行授权。例如,根据上传证件的清晰度、证件的齐全度和证件完整有效性等等信息,判断证件是否合格,如果证件不合格,则不符合要求,用户的身份认证失败,也即不能通过身份验证,进一步地互联网拒绝授权给用户。判断上传的本人生物特征中的人像照和/或声纹和/或其他生物特征清晰度等等是否合格,如果不合格,则不符合要求,用户的身份认证失败,也即不能通过身份验证,进一步地互联网拒绝授权给用户。判断在互联网上用户命中黑名单、注册垃圾账号是否存在风险,如果存在风险,则不符合要求,用户的身份认证失败,也即不能通过身份验证,进一步地互联网拒绝授权给用户等等,最后根据采集到的用户所有类型的信息进行判断用户身份认证是否通过,是否对其进行授权。
图7是根据本发明实施例的一种可选的身份认证方法的示意图,如图7所示,通过用户上传的证件、本人生物特征、在互联网上用户轨迹和在互联网上用户访问行为等信息对用户进行身份认证,如果用户的身份认证通过,对用户进行授权。例如,根据上传证件的清晰度、证件的齐全度和证件完整有效性、本人生物特征中的人像照/声纹/其它生物特征清晰度,在互联网上用户存在风险操作等等信息进行联合,得到多维度特征融合模型,根据多维度特征融合模型判断用于对用户身份进行认证的所有类型的信息是否满 足身份认证通过条件,如果满足身份认证通过条件,授权给用户;如果不满足身份认证通过条件,拒绝授权。
通过以上本方案,扩充了对用户进行身份认证的维度,从而在覆盖更多的风险的同时改善正常用户身份认证体验。
需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本发明并不受所描述的动作顺序的限制,因为依据本发明,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于可选实施例,所涉及的动作和模块并不一定是本发明所必须的。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到根据上述实施例的方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,或者网络设备等)执行本发明各个实施例的方法。
实施例2
根据本发明实施例,还提供了一种用于实施上述身份认证装置,如图8所示,该装置包括:采集单元100、第一获取单元102、第二获取单元104和判断单元106。
采集单元100,用于采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证。
在很多场景下需要在互联网上对用户进行身份认证。为了对待身份认证用户进行身份认证,采集单元100采集对该用户的身份进行身份认证的多种类型的信息。
例如,用户A(待身份认证用户)为了在某网站上为自己开设一实名账户,因此需要在互联网上进行身份认证,待身份认证通过之后,某网站才会对用户A进行授权,为其开设实名账户。通常,用户A为了在互联网上进行身份认证,可能会上传一些用户A的相关材料。对于互联网端,为了对用户A的身份进行认证,在上传了一些用户A的相关材料的情况下,采集用户A上传的相关材料中的信息,该信息中包括对用户A的进行身份认证的信息。同时也在互联网中采集可对用户A的进行身份认证的信息。如果未上传一些用户A的相关材料,则在互联网中采集可对用户A的进行身份认证的信息。
可选地,在本发明实施例提供的身份认证装置中,用户的信息的类型包括以下至少 之一:证件信息、生物特征信息、权限信息、用户在互联网上的行为信息。
再以用户A为例,上传的相关材料中包括以下至少之一:用户A的证件、用户A的生物特征,采集用户A上传的相关材料中的信息,该信息中包括上传的证件中的证件信息,上传的用户A的生物特征中的生物特征信息。
采集用户A在互联网中的权限信息,例如,判断在互联网中用户A是否在互联网黑名单中,如果用户A在黑名单中,那么用户A的在互联网中的权利会被限制。
用户A在互联网上的行为信息可以为用户A在互联网上的访问轨迹,例如,根据用户A在互联网上的访问轨迹可以确定用户A在互联网上的操作是否存在风险。
第一获取单元102,用于获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度。
由于用户的信息的类型包括以下至少之一:证件信息、生物特征信息、权限信息、用户在互联网上的行为信息。
可选地,在本发明实施例提供的身份认证装置中,第一获取单元102包括以下至少之一:第一确定模块1021、第二确定模块1022、第三确定模块1023和第四确定模块1024。
第一确定模块1021,用于在信息的类型为证件信息的情况下,根据如下条件的至少之一确定证件信息对应的风险系数:证件清晰度、证件齐全度、证件有效性。
需要说明的是,风险系数可以为系数值,也可以为概率。以用户A为例,第一确定模块1021根据用户A的上传的证件的清晰度确定风险系数。具体地,如上传的证件的清晰度为80%,则确定上传的证件合格的可能性为80%,根据证件合格的可能性确定风险系数为80%。需要说明的是,证件的清晰度可以根据对证件中的信息进行成功识别的可能性得到。
和/或,第一确定模块1021根据用户A的上传的证件的齐全度确定风险系数,具体地,如上传的证件的齐全度为55%,则确定上传的证件合格的可能性为55%,根据证件合格的可能性确定风险系数55%。需要说明的是,证件的齐全度可以通过上传证件的数量和类型与要求上传证件的数量和类型进行计算得到。
和/或,第一确定模块1021根据用户A的上传的证件的有效性确定风险系数,具体地,如上传的证件的有效性为68%,则确定上传的证件合格的可能性为68%,根据证件合格的可能性确定风险系数68%。需要说明的是,证件的有效性可以根据识别上传的证件中的信息判断是否符合预设要求得到。
第二确定模块1022,用于在信息的类型为生物特征信息的情况下,根据如下条件的 至少之一确定生物特征信息对应的风险系数:来自用户的人像图片是否与用户相符、来自用户的声纹信息是否与用户相符、来自用户的指纹信息是否与用户相符。
再以用户A为例,第二确定模块1022根据来自用户A的人像图片是否与用户相符确定风险系数。具体地,根据判断来自用户A的人像图片是否与用户A相符(也即来自用户A的人像图片是否是用户A本人),确定上传的生物特征信息合格的可能性,根据生物特征信息合格的可能性确定风险系数。
和/或,第二确定模块1022根据来自用户A的声纹信息确定风险系数。具体地,根据判断来自用户A的声纹信息是否与用户A相符(也即来自用户A的声纹信息是否来自用户A本人),确定上传的生物特征信息合格的可能性,根据生物特征信息合格的可能性确定风险系数。
和/或,第二确定模块1022根据来自用户A的指纹信息是否与用户相符确定风险系数。具体地,根据判断来自用户的指纹信息是否与用户A相符(也即来自用户A的指纹信息是否来自用户A本人),确定上传的生物特征信息合格的可能性,根据生物特征信息合格的可能性确定风险系数。
第三确定模块1023,用于在信息的类型为权限信息的情况下,根据如下条件的至少之一确定权限信息对应的风险系数:用户是否被限制预定权力、用户是否被允许预定权力。
再以用户A为例,第三确定模块1023根据用户A是否被限制预定权力确定风险系数。如果判断用户A被限制预定权力,风险系数较大;如果判断用户A未被限制预定权力,风险系数较小。
和/或,第三确定模块1023根据用户A是否被允许预定权力确定风险系数。如果判断用户A被允许预定权力,风险系数较小;如果判断用户A未被允许预定权力,风险系数较大。
第四确定模块1024,用于在信息的类型为用户在互联网上的行为信息的情况下,根据如下条件的至少之一确定行为信息对应风险系数:用户访问的网站信息、用户的网络地址信息、用户的操作行为。
再以用户A为例,第四确定模块1024根据用户A访问的网站信息确定风险系数。如果用户A访问过非法网站或者访问过的网站存在风险,风险系数较大;如果用户A未访问过非法网站或者未访问过的网站存在风险,风险系数较小。
和/或,第四确定模块1024根据用户A的网络地址信息确定风险系数。如果用户A 的网络地址信息被标注过存在风险等等,风险系数较大;如果用户A的网络地址信息未被标注过存在风险等等,风险系数较小。
和/或,第四确定模块1024根据用户的操作行为确定风险系数。如果用户在互联网上的操作行为存在风险,风险系数较大;如果用户在互联网上的操作行为不存在风险,风险系数较小。
第二获取单元104,用于对每种类型的信息对应的风险系数进行综合评估得到综合风险系数。
第二获取单元104根据上述得到的每种类型的信息对应的风险系数进行综合评估得到综合风险系数。
判断单元106,用于根据综合风险系数判断用户的身份认证是否通过。
判断单元106通过综合风险系数判断用户的身份认证是否通过,避免了相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的问题。
再以用户A为例,用户A在互联网中上传了身份证、户口本、护照等等材料,如果身份证中的身份有效期已过期,在互联网中基于身份证对用户A进行身份认证时,导致身份证认证失败,不能通过身份认证。通过本发明实施例中的技术方案,将身份证、户口本、护照等等材料综合进行考虑,根据各个材料中的信息评估用户A的身份被信任的程度,最后进行评估得到综合风险系数,根据综合风险系数判断用户A的身份认证是否通过。也即,如果身份证中的身份有效期已过期,在互联网中对用户A进行身份认证时,身份证认证不一定失败,通过对户口本、护照等等材料对用户A进行身份认证,进行综合评估用户A的身份被信任的程度(将采集到的用户A的用于进行身份认证的信息对应的风险系数进行关联,得到综合风险系数),最后确定用户A的身份认证是否通过。通过本技术方案也提升了对身份认证的通过率,用户不必重复进行身份认证,从而提升用户体验。
基于上述实施例中采集单元100、第一获取单元102、第二获取单元104和判断单元106所公开的方案,可以获知采集单元100采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;第一获取单元102获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;第二获取单元104对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;判断单元106根据综合风险系数判断用户的身份认证是否通过,从而将每种类型 的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证准确性的目的,从而实现了提升用户体验的技术效果,进而解决了由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。
此处需要说明的是,上述采集单元100、第一获取单元102、第二获取单元104和判断单元106对应于实施例1中的步骤S202至步骤S208,四个单元与对应的步骤所实现的实例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端10中。
可选地,在本发明实施例提供的身份认证装置中,第二获取单元104还用于将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数,其中,数据模型是根据训练集进行训练得到的,训练集包括身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数,身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
本发明实施例中提及的数据模型是根据训练集进行训练得到的,训练集包括身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数,身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。例如,训练集中包括,用户B1、用户B2、用户B3……用户Bn为身份认证通过的用户,用户C1、用户C2、用户C3……用户Cn为身份认证未通过的用户,根据训练集进行训练得到数据模型。将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数。例如,根据用户A的证件信息对应的风险系数和/或生物特征信息对应的风险系数和/或权限信息对应的风险系数通过数据模型进行评估得到综合风险系数。
通过本方案,将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数。也即,将每种类型的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证的通过率和准确性的目的,从而实现了提升用户体验的技术效果。
此处需要说明的是,上述代码第二获取单元104对应于实施例1中的步骤S206,三个模块与对应的步骤所实现的实例和应用场景相同,但不限于上述实施例一所公开的内容。需要说明的是,上述模块作为装置的一部分可以运行在实施例一提供的计算机终端 10中。
可选地,在本发明实施例提供的身份认证装置中,第二获取单元104还用于根据每种类型的信息对应的风险系数以及权值对所有类型的信息对应的风险系数进行加权和计算,得到综合风险系数。
在本发明实施例中,对用户进行身份认证的每种类型的信息预先设置对应的权值,或者第二获取单元104根据对多个用户进行身份认证的各种类型的信息进行训练学习得到风险系数数据模型,通过该风险系数数据模型获取采集到的每种类型的信息对应的权值,然后根据获取到的每种类型的信息对应的权值对所有类型的信息对应的风险系数进行加权和计算,得到综合风险系数。
例如,用户A的证件信息对应的权值为0.6,生物特征信息对应的权值为0.25,权限信息对应的权值为0.15,在获取综合风险系数时,根据证件信息对应的权值、生物特征信息对应的权值、权限信息对应的权值对各类型的信息对应的风险系数进行加权求和得到用户A通过身份认证的综合风险系数。
通过本方案,充分考虑了不同类型的信息对用户身份认证的重要程度和影响程度,通过不同类型的信息对应的权值对各类型的信息对应的风险系数进行加权求和,得到综合风险系数。进一步地平衡了用户通过身份认证的风险和提升了用户的体验。
可选地,在本发明实施例提供的身份认证装置中,第一获取单元102还包括:第一获取模块,用于获取每种类型的子类型对应的风险系数,其中,子类型对应的风险系数包括以下至少之一:每个子类型分别对应的风险系数、至少两个子类型的组合对应的风险系数;第二获取模块,用于根据子类型对应的风险系数获取该类型信息的风险系数。
通过本方案,根据不同类型的信息的子类型的风险系数,确定每种类型的信息对应的风险系数,提升了获取每种类型的信息对应的风险系数的准确性。进一步地平衡了用户通过身份认证的风险和提升了用户的体验。
需要说明的是,上述单元作为装置的一部分可以运行在实施例一提供的计算机终端10中。
实施例3
根据本发明实施例,还提供了一种计算设备,图9是根据本发明实施例的一种计算设备的示意图,如图9所示,该计算设备100,提供第一界面110。
该第一界面110包括:多个第一控件111,用于采集待身份认证用户的多种类型的信息,多种类型的信息用于对用户的身份进行认证;第一发送单元,用于将多种类型的 信息发送至服务器,通过服务器对多种类型的信息的风险系数进行评估,得到综合风险系数,其中,风险系数用于指示用户的身份被信任的程度;第二接收单元,用于接收服务器发送的与多种类型的信息对应的风险系数以及综合风险系数;与多个第一控件对应的多个第二控件121,用于体现每种类型的信息对应的风险系数;第三控件122,用于体现待身份认证用户的综合风险系数。
在本方案公开的内容中,如图9所示,通过多个第二控件121将证件风险系数、指纹风险系数等等多种类型的信息对应的风险系数进行体现,通过多个第三控件122将综合风险系数进行体现,用户可以查看到以上信息,进一步地提升用户体验度的技术效果。
在本发明实施例中,采用多种类型的信息对用户进行身份认证的方式,通过多个第一控件111采集待身份认证用户的多种类型的信息,多种类型的信息用于对用户的身份进行认证;第一发送单元将多种类型的信息发送至服务器,通过服务器对多种类型的信息的风险系数进行评估,得到综合风险系数,其中,风险系数用于指示用户的身份被信任的程度;第二接收单元,用于接收服务器发送的与多种类型的信息对应的风险系数以及综合风险系数;与多个第一控件对应的多个第二控件121体现每种类型的信息对应的风险系数;第三控件122体现待身份认证用户的综合风险系数,将每种类型的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证准确性的目的,还通过第二控件体现每种类型的信息对应的风险系数,第三控件体现待身份认证用户的综合风险系数,从而用户可以查看到相关信息,进一步提升了用户体验度的技术效果,进而解决了由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。
实施例4
本发明的实施例可以提供一种计算机终端,该计算机终端可以是计算机终端群中的任意一个计算机终端设备。可选地,在本实施例中,上述计算机终端也可以替换为移动终端等终端设备。
可选地,在本实施例中,上述计算机终端可以位于计算机网络的多个网络设备中的至少一个网络设备。
在本实施例中,上述计算机终端可以执行应用程序的身份认证方法中以下步骤的程序代码:采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险 系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过。
可选地,图10是根据本发明实施例的一种计算机终端的结构框图。如图10所示,该计算机终端10可以包括:一个或多个(图中仅示出一个)处理器和存储器。
其中,存储器可用于存储软件程序以及模块,如本发明实施例中的安全漏洞检测方法和装置对应的程序指令/模块,处理器通过运行存储在存储器内的软件程序以及模块,从而执行各种功能应用以及数据处理,即实现上述的系统漏洞攻击的检测方法。存储器可包括高速随机存储器,还可以包括非易失性存储器,如一个或者多个磁性存储装置、闪存、或者其他非易失性固态存储器。在一些实例中,存储器可进一步包括相对于处理器远程设置的存储器,这些远程存储器可以通过网络连接至终端10。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
处理器可以通过传输装置调用存储器存储的信息及应用程序,以执行下述步骤:采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过。
可选的,上述处理器还可以执行如下步骤的程序代码:将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数,其中,数据模型是根据训练集进行训练得到的,训练集包括身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数,身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
可选的,上述处理器还可以执行如下步骤的程序代码:根据每种类型的信息对应的风险系数以及权值对所有类型的信息对应的风险系数进行加权和计算,得到综合风险系数。
可选的,上述处理器还可以执行如下步骤的程序代码:用户的信息的类型包括以下至少之一:证件信息、生物特征信息、权限信息、用户在互联网上的行为信息。
可选的,上述处理器还可以执行如下步骤的程序代码:在信息的类型为证件信息的情况下,根据如下条件的至少之一确定证件信息对应的风险系数:证件清晰度、证件齐全度、证件有效性;在信息的类型为生物特征信息的情况下,根据如下条件的至少之一确定生物特征信息对应的风险系数:来自用户的人像图片是否与用户相符、来自用户的 声纹信息是否与用户相符、来自用户的指纹信息是否与用户相符;在信息的类型为权限信息的情况下,根据如下条件的至少之一确定权限信息对应的风险系数:用户是否被限制预定权力、用户是否被允许预定权力;在信息的类型为用户在互联网上的行为信息的情况下,根据如下条件的至少之一确定行为信息对应风险系数:用户访问的网站信息、用户的网络地址信息、用户的操作行为。
可选的,上述处理器还可以执行如下步骤的程序代码:获取多种类型的信息中的每种类型的信息对应的风险系数包括:获取每种类型的子类型对应的风险系数,其中,子类型对应的风险系数包括以下至少之一:每个子类型分别对应的风险系数、至少两个子类型的组合对应的风险系数;根据子类型对应的风险系数获取该类型信息的风险系数。
采用本发明实施例,提供了一种身份认证的方案。通过采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过,从而将每种类型的信息对应的风险系数进行关联,避免了身份认证之间独立、无任何关联造成的身份认证决策时出错的风险较大,达到了提升对用户的身份认证准确性的目的,从而实现了提升用户体验度的技术效果,进而解决了由于相关技术中根据各个身份认证条件认定用户身份是否通过身份认证之间是相互独立、无任何关联造成的身份认证决策时出错的风险较大,影响用户体验的技术问题。
本领域普通技术人员可以理解,图10所示的结构仅为示意,计算机终端也可以是智能手机(如Android手机、iOS手机等)、平板电脑、掌声电脑以及移动互联网设备(Mobile Internet Devices,MID)、PAD等终端设备。图10其并不对上述电子装置的结构造成限定。例如,计算机终端10还可包括比图10中所示更多或者更少的组件(如网络接口、显示装置等),或者具有与图10所示不同的配置。
本领域普通技术人员可以理解上述实施例的各种方法中的全部或部分步骤是可以通过程序来指令终端设备相关的硬件来完成,该程序可以存储于一计算机可读存储介质中,存储介质可以包括:闪存盘、只读存储器(Read-Only Memory,ROM)、随机存取器(Random Access Memory,RAM)、磁盘或光盘等。
实施例5
本发明的实施例还提供了一种存储介质。可选地,在本实施例中,上述存储介质可以用于保存上述实施例一所提供的身份认证方法所执行的程序代码。
可选地,在本实施例中,上述存储介质可以位于计算机网络中计算机终端群中的任意一个计算机终端中,或者位于移动终端群中的任意一个移动终端中。
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:采集待身份认证用户的多种类型的信息,其中,多种类型的信息用于对用户的身份进行认证;获取多种类型的信息中的每种类型的信息对应的风险系数,其中,风险系数用于指示用户的身份被信任的程度;对每种类型的信息对应的风险系数进行综合评估得到综合风险系数;根据综合风险系数判断用户的身份认证是否通过。
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:将每种类型的信息对应的风险系数通过数据模型进行评估得到综合风险系数,其中,数据模型是根据训练集进行训练得到的,训练集包括身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数,身份认证通过的用户和/或身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:根据每种类型的信息对应的风险系数以及权值对所有类型的信息对应的风险系数进行加权和计算,得到综合风险系数。
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:用户的信息的类型包括以下至少之一:证件信息、生物特征信息、权限信息、用户在互联网上的行为信息。
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:在信息的类型为证件信息的情况下,根据如下条件的至少之一确定证件信息对应的风险系数:证件清晰度、证件齐全度、证件有效性;在信息的类型为生物特征信息的情况下,根据如下条件的至少之一确定生物特征信息对应的风险系数:来自用户的人像图片是否与用户相符、来自用户的声纹信息是否与用户相符、来自用户的指纹信息是否与用户相符;在信息的类型为权限信息的情况下,根据如下条件的至少之一确定权限信息对应的风险系数:用户是否被限制预定权力、用户是否被允许预定权力;在信息的类型为用户在互联网上的行为信息的情况下,根据如下条件的至少之一确定行为信息对应风险系数:用户访问的网站信息、用户的网络地址信息、用户的操作行为。
可选地,在本实施例中,存储介质被设置为存储用于执行以下步骤的程序代码:获取多种类型的信息中的每种类型的信息对应的风险系数包括:获取每种类型的子类型对应的风险系数,其中,子类型对应的风险系数包括以下至少之一:每个子类型分别对应 的风险系数、至少两个子类型的组合对应的风险系数;根据子类型对应的风险系数获取该类型信息的风险系数。
上述本发明实施例序号仅仅为了描述,不代表实施例的优劣。
在本发明的上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
在本申请所提供的几个实施例中,应该理解到,所揭露的技术内容,可通过其它的方式实现。其中,以上所描述的装置实施例仅仅是示意性的,例如所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,单元或模块的间接耦合或通信连接,可以是电性或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可为个人计算机、服务器或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、移动硬盘、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述仅是本发明的可选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本发明原理的前提下,还可以做出若干改进和润饰,这些改进和润饰也应视为本发明的保护范围。

Claims (16)

  1. 一种身份认证方法,其特征在于,包括:
    采集待身份认证用户的多种类型的信息,其中,所述多种类型的信息用于对所述用户的身份进行认证;
    获取所述多种类型的信息中的每种类型的信息对应的风险系数,其中,所述风险系数用于指示所述用户的身份被信任的程度;
    对所述每种类型的信息对应的风险系数进行综合评估得到综合风险系数;
    根据所述综合风险系数判断所述用户的身份认证是否通过。
  2. 根据权利要求1所述的方法,其特征在于,对所述每种类型的信息对应的风险系数进行综合评估得到所述综合风险系数包括:
    将所述每种类型的信息对应的风险系数通过数据模型进行评估得到所述综合风险系数,其中,所述数据模型是根据训练集进行训练得到的,所述训练集至少包括身份认证通过的用户对应的综合风险系数,所述身份认证通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
  3. 根据权利要求2所述的方法,其特征在于,所述训练集还包括:身份认证未通过的用户对应的综合风险系数,所述身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
  4. 根据权利要求1所述的方法,其特征在于,对所述每种类型的信息对应的风险系数进行综合评估得到所述综合风险系数包括:
    根据所述每种类型的信息对应的风险系数以及权值对所有类型的信息对应的风险系数进行加权和计算,得到所述综合风险系数,其中,所述每种类型的信息对应的权值用于表示该种类型的信息对综合风险系数的影响,所述每种类型的信息对应的权值为预先配置的。
  5. 根据权利要求1至4中任一项所述的方法,其特征在于,所述用户的信息的类型包括以下至少之一:证件信息、生物特征信息、权限信息、所述用户在互联网上的行为信息。
  6. 根据权利要求5所述的方法,其特征在于,获取所述多种类型的信息中的每种类型的信息对应的风险系数包括以下至少之一:
    在所述信息的类型为证件信息的情况下,根据如下条件的至少之一确定所述证件信息对应的风险系数:证件清晰度、证件齐全度、证件有效性;
    在所述信息的类型为生物特征信息的情况下,根据如下条件的至少之一确定所述生物特征信息对应的风险系数:来自所述用户的人像图片是否与所述用户相符、来自所述用户的声纹信息是否与所述用户相符、来自所述用户的指纹信息是否与所述用户相符;
    在所述信息的类型为权限信息的情况下,根据如下条件的至少之一确定所述权限信息对应的风险系数:所述用户是否被限制预定权力、所述用户是否被允许预定权力;
    在所述信息的类型为所述用户在互联网上的行为信息的情况下,根据如下条件的至少之一确定所述行为信息对应风险系数:所述用户访问的网站信息、所述用户的网络地址信息、所述用户的操作行为。
  7. 根据权利要求1至4中任一项所述的方法,其特征在于,获取所述多种类型的信息中的每种类型的信息对应的风险系数包括:
    获取所述每种类型的子类型对应的风险系数,其中,所述子类型对应的风险系数包括以下至少之一:每个子类型分别对应的风险系数、至少两个子类型的组合对应的风险系数;
    根据所述子类型对应的风险系数获取该类型信息的风险系数。
  8. 根据权利要求1至4中任一项所述的方法,其特征在于,
    所述风险系数数值越大,所述用户的身份被信任的程度越高,所述用户的身份被认证通过之后风险越低;或者,
    所述风险系数数值越大,所述用户的身份被信任的程度越低,所述用户的身份被认证通过之后风险越高。
  9. 一种身份认证装置,其特征在于,包括:
    采集单元,用于采集待身份认证用户的多种类型的信息,其中,所述多种类型的信息用于对所述用户的身份进行认证;
    第一获取单元,用于获取所述多种类型的信息中的每种类型的信息对应的风险系数,其中,所述风险系数用于指示所述用户的身份被信任的程度;
    第二获取单元,用于对所述每种类型的信息对应的风险系数进行综合评估得到综合风险系数;
    判断单元,用于根据所述综合风险系数判断所述用户的身份认证是否通过。
  10. 根据权利要求9所述的装置,其特征在于,所述第二获取单元还用于将所述每种类型的信息对应的风险系数通过数据模型进行评估得到所述综合风险系数,其中,所述数据模型是根据训练集进行训练得到的,所述训练集包括身份认证通过的用户对应的 综合风险系数,所述身份认证通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
  11. 根据权利要求10所述的装置,其特征在于,所述训练集还包括:身份认证未通过的用户对应的综合风险系数,所述身份认证未通过的用户对应的综合风险系数是根据该用户的每种类型的信息对应的风险系数得到的。
  12. 根据权利要求9所述的装置,其特征在于,所述第二获取单元还用于根据所述每种类型的信息对应的风险系数以及权值对所有类型的信息对应的风险系数进行加权和计算,得到所述综合风险系数,其中,所述每种类型的信息对应的权值用于表示该种类型的信息对综合风险系数的影响,所述每种类型的信息对应的权值为预先配置的。
  13. 根据权利要求9至12中任一项所述的装置,其特征在于,所述用户的信息的类型包括以下至少之一:证件信息、生物特征信息、权限信息、所述用户在互联网上的行为信息。
  14. 根据权利要求13所述的装置,其特征在于,所述第一获取单元包括以下至少之一:
    第一确定模块,用于在所述信息的类型为证件信息的情况下,根据如下条件的至少之一确定所述证件信息对应的风险系数:证件清晰度、证件齐全度、证件有效性;
    第二确定模块,用于在所述信息的类型为生物特征信息的情况下,根据如下条件的至少之一确定所述生物特征信息对应的风险系数:来自所述用户的人像图片是否与所述用户相符、来自所述用户的声纹信息是否与所述用户相符、来自所述用户的指纹信息是否与所述用户相符;
    第三确定模块,用于在所述信息的类型为权限信息的情况下,根据如下条件的至少之一确定所述权限信息对应的风险系数:所述用户是否被限制预定权力、所述用户是否被允许预定权力;
    第四确定模块,用于在所述信息的类型为所述用户在互联网上的行为信息的情况下,根据如下条件的至少之一确定所述行为信息对应风险系数:所述用户访问的网站信息、所述用户的网络地址信息、所述用户的操作行为。
  15. 根据权利要求9至12中任一项所述的装置,其特征在于,所述第一获取单元包括:
    第一获取模块,用于获取所述每种类型的子类型对应的风险系数,其中,所述子类型对应的风险系数包括以下至少之一:每个子类型分别对应的风险系数、至少两个子类 型的组合对应的风险系数;
    第二获取模块,用于根据所述子类型对应的风险系数获取该类型信息的风险系数。
  16. 一种计算设备,其特征在于,提供第一界面,用于用户交互;
    其中,所述第一界面包括:
    多个第一控件,用于采集待身份认证用户的多种类型的信息,所述多种类型的信息用于对所述用户的身份进行认证;
    第一发送单元,用于将所述多种类型的信息发送至服务器,通过所述服务器对所述多种类型的信息的风险系数进行评估,得到综合风险系数,其中,所述风险系数用于指示所述用户的身份被信任的程度;
    第二接收单元,用于接收服务器发送的与多种类型的信息对应的风险系数以及综合风险系数;
    与所述多个第一控件对应的多个第二控件,用于体现每种类型的信息对应的风险系数;
    第三控件,用于体现待身份认证用户的综合风险系数。
PCT/CN2017/111506 2016-11-30 2017-11-17 身份认证方法及装置和计算设备 Ceased WO2018099276A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US16/421,294 US20190347425A1 (en) 2016-11-30 2019-05-23 Method and apparatus for identity authentication

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201611089354.3A CN108123926A (zh) 2016-11-30 2016-11-30 身份认证方法及装置和计算设备
CN201611089354.3 2016-11-30

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US16/421,294 Continuation-In-Part US20190347425A1 (en) 2016-11-30 2019-05-23 Method and apparatus for identity authentication

Publications (1)

Publication Number Publication Date
WO2018099276A1 true WO2018099276A1 (zh) 2018-06-07

Family

ID=62226492

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/111506 Ceased WO2018099276A1 (zh) 2016-11-30 2017-11-17 身份认证方法及装置和计算设备

Country Status (4)

Country Link
US (1) US20190347425A1 (zh)
CN (1) CN108123926A (zh)
TW (1) TW201822047A (zh)
WO (1) WO2018099276A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109190342A (zh) * 2018-08-20 2019-01-11 济南大学 智慧社区的业主身份验证方法及社区服务器
CN116883472A (zh) * 2023-09-08 2023-10-13 山东德亿鑫信息科技有限公司 一种基于脸部三维图像配准的人脸护理系统

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109450867B (zh) * 2018-10-22 2019-11-15 腾讯科技(深圳)有限公司 一种身份认证方法、装置及存储介质
CN109274683A (zh) * 2018-10-30 2019-01-25 国网安徽省电力有限公司信息通信分公司 一种交叉组合认证系统及其认证方法
CN109492356A (zh) * 2018-12-28 2019-03-19 深圳竹云科技有限公司 一种基于用户行为风险判断的多级认证方法
CN112906741B (zh) * 2019-05-21 2024-11-12 北京嘀嘀无限科技发展有限公司 图像处理方法、装置、电子设备及存储介质
CN112291709B (zh) * 2019-07-09 2023-07-04 中国移动通信集团安徽有限公司 鉴权方法、装置、设备及计算机存储介质
CN110266738A (zh) * 2019-07-31 2019-09-20 中国工商银行股份有限公司 基于多生物特征的识别认证方法及装置
CN111541656B (zh) * 2020-04-09 2022-09-16 中央电视台 基于融合媒体云平台的身份认证方法及系统
CN112232443B (zh) * 2020-11-20 2023-11-24 中国联合网络通信集团有限公司 身份认证方法、装置、设备及存储介质
US11967307B2 (en) * 2021-02-12 2024-04-23 Oracle International Corporation Voice communication analysis system
CN113114660A (zh) * 2021-04-08 2021-07-13 北京顶象技术有限公司 语音验证码实现方法及装置
CN113129019A (zh) * 2021-05-18 2021-07-16 中国银行股份有限公司 风险防御方法及装置
CN114398667A (zh) * 2021-12-14 2022-04-26 中国通信建设第三工程局有限公司 一种计算机存储系统的数据安全访问系统及方法
CN119848819B (zh) * 2024-12-27 2026-02-03 建信消费金融有限责任公司 身份验证方法和装置、存储介质及电子设备

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102904885A (zh) * 2012-09-26 2013-01-30 北京工业大学 多身份认证信息特征复合认证方法
CN103440686A (zh) * 2013-07-29 2013-12-11 上海交通大学 基于声纹识别、头像识别及位置服务的移动身份验证系统和方法
CN105426723A (zh) * 2015-11-20 2016-03-23 北京得意音通技术有限责任公司 基于声纹识别、人脸识别以及同步活体检测的身份认证方法及系统
CN105556552A (zh) * 2013-03-13 2016-05-04 加迪安分析有限公司 欺诈探测和分析
CN105989263A (zh) * 2015-01-30 2016-10-05 阿里巴巴集团控股有限公司 身份认证方法、开户方法、装置及系统

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6202151B1 (en) * 1997-05-09 2001-03-13 Gte Service Corporation System and method for authenticating electronic transactions using biometric certificates
US8539550B1 (en) * 2008-05-29 2013-09-17 Intuit Inc. Multi-pattern authentication gestures
US9118669B2 (en) * 2010-09-30 2015-08-25 Alcatel Lucent Method and apparatus for voice signature authentication
US8863260B2 (en) * 2012-06-07 2014-10-14 International Business Machines Corporation Enhancing password protection
US9589399B2 (en) * 2012-07-02 2017-03-07 Synaptics Incorporated Credential quality assessment engine systems and methods
US20140020089A1 (en) * 2012-07-13 2014-01-16 II Remo Peter Perini Access Control System using Stimulus Evoked Cognitive Response
US8584219B1 (en) * 2012-11-07 2013-11-12 Fmr Llc Risk adjusted, multifactor authentication
US10235508B2 (en) * 2013-05-08 2019-03-19 Jpmorgan Chase Bank, N.A. Systems and methods for high fidelity multi-modal out-of-band biometric authentication with human cross-checking
US10095850B2 (en) * 2014-05-19 2018-10-09 Kadenze, Inc. User identity authentication techniques for on-line content or access
US10601800B2 (en) * 2017-02-24 2020-03-24 Fmr Llc Systems and methods for user authentication using pattern-based risk assessment and adjustment

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102904885A (zh) * 2012-09-26 2013-01-30 北京工业大学 多身份认证信息特征复合认证方法
CN105556552A (zh) * 2013-03-13 2016-05-04 加迪安分析有限公司 欺诈探测和分析
CN103440686A (zh) * 2013-07-29 2013-12-11 上海交通大学 基于声纹识别、头像识别及位置服务的移动身份验证系统和方法
CN105989263A (zh) * 2015-01-30 2016-10-05 阿里巴巴集团控股有限公司 身份认证方法、开户方法、装置及系统
CN105426723A (zh) * 2015-11-20 2016-03-23 北京得意音通技术有限责任公司 基于声纹识别、人脸识别以及同步活体检测的身份认证方法及系统

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109190342A (zh) * 2018-08-20 2019-01-11 济南大学 智慧社区的业主身份验证方法及社区服务器
CN116883472A (zh) * 2023-09-08 2023-10-13 山东德亿鑫信息科技有限公司 一种基于脸部三维图像配准的人脸护理系统
CN116883472B (zh) * 2023-09-08 2023-11-14 山东德亿鑫信息科技有限公司 一种基于脸部三维图像配准的人脸护理系统

Also Published As

Publication number Publication date
CN108123926A (zh) 2018-06-05
TW201822047A (zh) 2018-06-16
US20190347425A1 (en) 2019-11-14

Similar Documents

Publication Publication Date Title
WO2018099276A1 (zh) 身份认证方法及装置和计算设备
US9673981B1 (en) Verification of authenticity and responsiveness of biometric evidence and/or other evidence
US11539526B2 (en) Method and apparatus for managing user authentication in a blockchain network
US9832023B2 (en) Verification of authenticity and responsiveness of biometric evidence and/or other evidence
CA2798071C (en) Methods and systems for increasing the security of network-based transactions
US9589399B2 (en) Credential quality assessment engine systems and methods
EP3138265B1 (en) Enhanced security for registration of authentication devices
JP6538821B2 (ja) データ分析手法を用いた認証を実行するためのシステム及び方法
US8990572B2 (en) Methods and systems for conducting smart card transactions
JP6574168B2 (ja) 端末識別方法、ならびにマシン識別コードを登録する方法、システム及び装置
CN109951436B (zh) 一种可信终端验证方法、装置
KR101624575B1 (ko) 모바일 상거래에서의 사용자 아이덴티티 증명
CA2819767C (en) Methods and systems for improving the accuracy performance of authentication systems
CN106233663A (zh) 用于在不同信道上携载强验证事件的系统和方法
WO2014105994A2 (en) Query system and method to determine authentication capabilities
CN106295290A (zh) 基于指纹信息生成认证信息的方法、装置及系统
CN118433710A (zh) 一种校验登录方法、装置、电子设备及计算机程序产品
Moepi et al. Five-Factor Authentication System with a Track and Trace Capability for Online Banking Platforms
HK1224450A1 (zh) 一种可信终端验证方法、装置
WO2013066928A2 (en) Verification of authenticity and responsiveness of biometric evidence and/or other evidence

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17877120

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17877120

Country of ref document: EP

Kind code of ref document: A1