WO2019047880A1 - 实人认证方法及装置 - Google Patents
实人认证方法及装置 Download PDFInfo
- Publication number
- WO2019047880A1 WO2019047880A1 PCT/CN2018/104273 CN2018104273W WO2019047880A1 WO 2019047880 A1 WO2019047880 A1 WO 2019047880A1 CN 2018104273 W CN2018104273 W CN 2018104273W WO 2019047880 A1 WO2019047880 A1 WO 2019047880A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- account
- information
- user
- real person
- real
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
Definitions
- the embodiments disclosed in the present specification relate to the field of Internet technologies, and in particular, to a method and apparatus for constructing an account map for real-time authentication, and a real-person authentication method and apparatus.
- the authentication information in the real-name authentication process mainly includes the user's item information and the user's biometric information.
- the user's item information includes the user's ID card, mobile phone and mailbox, as well as the user's pre-set password and security issues.
- the biometric information of the user includes fingerprint information, face information, iris information, and sound information.
- the user's item information is leaky, and the user's biometrics are at risk of copying and misappropriation during the collection process, it is necessary to provide a more reliable scheme for authenticating the user's identity.
- This specification describes a method and apparatus for constructing an account map for real person authentication, and a real person authentication method and apparatus.
- constructing an account map and using a account map to authenticate the user the user identity is improved. Credibility of certification.
- a method of constructing an account map for real-person authentication includes:
- the real person information including the certificate information and/or the biometric identification information
- the account information is an intermediate layer
- the behavior data is an outer layer
- the first association and the second association are used as an inter-layer association
- an account map is constructed for real-person authentication.
- a method of authenticating a person includes:
- the account map When detecting an operation request for performing an account operation on the first account by the user, searching for an account map corresponding to the real person information according to the real person information included in the registration information of the first account; the account map includes Information of the second account associated with the real person information, and behavior data associated with the second account;
- an apparatus for constructing an account map for real-time authentication includes:
- a first acquiring unit configured to acquire real user information of the user, where the real person information includes the certificate information and/or the biometric identification information;
- a second obtaining unit configured to acquire account information of the user, where the account information includes an account
- a third obtaining unit configured to acquire behavior data of the user operating the account
- An association unit configured to establish a first association between the real person information and the account information, and establish a second association between the account information and the behavior data
- a building unit configured to use the real person information as a core layer, the account information is an intermediate layer, the behavior data is an outer layer, and the first association and the second association are used as an inter-layer association to construct an account map. Really certified.
- a real authentication device in a fourth aspect, includes:
- a search unit configured to search for an account map corresponding to the real person information according to the real person information included in the registration information of the first account when detecting an operation request of the user to perform an account operation on the first account;
- the account map includes information of a second account associated with the real person information, and behavior data associated with the second account;
- a processing unit configured to provide a verification content of the real person authentication to the user according to the behavior data
- the determining unit receives the verification operation result of the verification content by the user, and determines whether the user passes the real person authentication according to the verification operation result.
- the present invention provides a method and a device for constructing an account map for real-time authentication, by using relevant information about the user (eg, certificate information, biometric identification information, an account issuing authority, an account number, and an account behavior data). Etc.) to collect, and create the association of these information, build an account map including the core layer, the middle layer and the outer layer, and update the account of the middle layer by real authentication, and associate the middle layer account with the created information. The value is updated and the account map can be used for real-life authentication.
- relevant information about the user eg, certificate information, biometric identification information, an account issuing authority, an account number, and an account behavior data.
- Etc. to collect, and create the association of these information, build an account map including the core layer, the middle layer and the outer layer, and update the account of the middle layer by real authentication, and associate the middle layer account with the created information.
- the value is updated and the account map can be used for real-life authentication.
- the manual authentication method and device provided by the manual obtains the account information and the behavior data by searching the account map corresponding to the real person information in the account registration information, and according to the real person information and the account information in the account map. And the behavior data generates the verification content, and the real account authentication is performed on the first account being operated by the user, thereby improving the credibility of authenticating the user identity.
- FIG. 1 is a schematic diagram of an application scenario of a real person authentication method according to an embodiment of the present disclosure
- FIG. 2 is a structural diagram of an account map provided by an embodiment of the present disclosure
- FIG. 3 is a flowchart of a method for constructing an account map for real person authentication according to an embodiment of the present disclosure
- FIG. 5 is a flowchart of a real person authentication method provided by an embodiment of the present disclosure.
- FIG. 6 is a schematic diagram of real authentication content provided by an embodiment of the present disclosure.
- FIG. 7 is a flowchart of a real person authentication method provided by another embodiment disclosed in the present specification.
- FIG. 8 is a schematic diagram of real authentication content provided by another embodiment disclosed in the present specification.
- FIG. 9 is a flowchart of an account adding method in an account map provided by an embodiment of the present disclosure.
- FIG. 10 is a schematic diagram of an apparatus for constructing an account map for real-life authentication according to an embodiment of the disclosure.
- FIG. 11 is a schematic structural diagram of a real person authentication apparatus according to an embodiment of the present disclosure.
- FIG. 1 is a schematic diagram of an application scenario of a real person authentication method according to an embodiment of the present disclosure.
- the server for example, the server can be the server of the Alipay application
- the terminal for example, the terminal can be a mobile phone, a tablet, a wearable smart device, etc.
- the first account eg, the first account can
- an account operation is performed for an Alipay account (for example, the account operation may be for registering the first account or using the funds in the first account)
- the real person authentication provided by the multiple embodiments disclosed in the present specification may be used.
- the method performs real-person authentication on the first account to check whether the user who performs the operation request of the account operation on the first account and the real person information in the registration information of the first account (for example, the real person information may be a name and an ID card) No.) matches.
- the real person authentication methods provided by the various embodiments disclosed in the present specification are all executed based on the constructed account map.
- the following is an introduction to the method of constructing an account map for real-life authentication.
- FIG. 2 is a structural diagram of an account map provided by an embodiment of the present disclosure. As shown in FIG. 2, the account map includes a core layer, an intermediate layer, and an outer layer from the inside to the outside.
- FIG. 3 is a flowchart of a method for constructing an account map for real person authentication according to an embodiment of the present disclosure.
- the execution body of the method may be a device with processing capability: a server or a system or device, and the method includes:
- Step S310 acquiring real user information of the user, the real person information including the certificate information and/or the biometric identification information.
- the real person information of the user is obtained, and the real person information can uniquely identify an entity in the real world.
- the entity may be a natural person or an organization
- the real person information may include a natural person's ID (eg, the ID may be an ID card, a driver's license, a real estate license) information, and biometrics (eg, biometrics may be faces, fingerprints, irises) Identification information, etc.
- the real person information may include the unified social credit code of the organization, the name of the organization, the registration number of the institution, and the like.
- Step S320 obtaining account information of the user, where the account information includes an account.
- the account information of the user is obtained, and the account information may include an account.
- Each account is generated and issued by the issuing authority of the account according to the user's real person information, and each account is unique within the issuing authority of the account.
- the account number issued by different issuing organizations may be the same. Therefore, for the account number in the account map, the expression can be: authority + account number, for example, account number 12345678 issued by Alipay, its expression in the account map The form is: Alipay 12345678. Therefore, the expression of each account in the account information is unique.
- Step S330 Obtain behavior data of the user operating the account.
- the behavior data of the user operating on the account is obtained, and the data is generated by the account.
- the behavior data may include: establishing an friend relationship with another account, changing the account password, and performing fund transaction behavior of the account. For example, a user purchased a shirt through a Taobao account.
- Step S340 establishing a first association between the real person information and the account information, and establishing a second association between the account information and the behavior data.
- An association includes a direct association or an indirect association.
- the plurality of accounts of the middle layer include a direct account directly associated with the real person information, and an indirect account that is indirectly associated with the real person information through the direct account.
- the customer number generated and issued by Alipay based on the user's real person information is 12345678
- the user number associated with the customer number eg, the user name may include the user name and password
- the user can register the Alipay user account with two mobile phone numbers.
- Each user number can be associated with multiple fund accounts (for example, the fund account can be the balance account, the ant fund account, and the health insurance account).
- the customer number is directly related to the real person information, and the user number is indirectly related to the real person information through the customer number, and the fund account is indirectly associated with the real person information through the user number and the customer number. Only the case where the intermediate account is divided into two layers is shown in FIG. 2, which is not limited thereto.
- step S350 the real person information is used as the core layer, the account information is used as the middle layer, the behavior data is used as the outer layer, and the first association and the second association are used as the interlayer association, and the account map is constructed for real person authentication.
- the account information in step S320 may further include the value of the account, and the value of the account includes the real relationship and the business value.
- the actual relevance of the account may be determined according to the issuing authority of the account. The more authoritative the authority is, the higher the relevance of the account. For example, for an account of a government agency (government department, such as China Railway Customer Service Center, Social Insurance Agency, National Bank), the actual relevance of the account can be rated as 5. For companies with an authority of the world's top 500 (companies, such as Facebook), the real relevance of the account can be rated as 4.
- the business value of the account can be evaluated based on the behavior data of the account. Behavioral data can include establishing friendships, fund transactions, and the like. For example, for a plurality of bank card accounts bound in Alipay, the business value can be determined according to the transaction type, the number of transactions, and the transaction amount. For example, an Alipay personal account is bound to a number of bank cards on January 1, including China Merchants Bank, China Construction Bank and Industrial and Commercial Bank. The transaction status of these bank card accounts in January is as shown in Table 1. Correspondingly, Determine the business value of these bank accounts based on the transaction.
- the association structure between accounts may also change, and the behavior data of the account usually increases. Therefore, the value of the account needs to be updated.
- FIG. 4 is a flow chart of updating the value of an account provided by an embodiment disclosed in the present specification.
- the method periodically updates the value of the account in an iterative manner.
- the new behavior data in the outer layer of the map and the change of the account association structure in the middle layer drive the iteration of the account value.
- the method includes the following steps:
- Step S410 Starting from the outermost account in the account of the middle layer, calculating the value of the outermost account.
- the account of the middle layer includes a total of N-level accounts, and N ⁇ 1.
- the first layer account is an account directly associated with the real person information, and the Nth layer account is the outermost account.
- step S420 it is determined whether the current account is the innermost account. If it is not the innermost account, step S430 is performed, and if it is the innermost account, the iterative update is completed.
- N it is determined whether N is equal to 1. If N is equal to 1, it indicates that the current account is the innermost account, and the iteration update is completed, and the process can be ended. If N is not equal to 1, it indicates that the current account is not the innermost account, and step S430 is performed.
- step S430 a layer is pushed inward.
- the server can determine the value of the account based on the behavior data of the outer layer of an account and the value of other accounts associated with it. For example, when the account of the middle layer includes multiple accounts, and the plurality of accounts includes a direct account directly associated with the real person information, and an indirect account that is indirectly associated with the real person information through the direct account, the value of the direct account includes the direct The sum of the values of the indirect accounts whose second account is indirectly associated with the real person information.
- the method for updating the value of the account starts from the outermost account, performs value calculation and update, and advances to the inner layer in turn, according to the outer behavior data of the account and the account.
- the value of the other account of the affiliate determines the value of the account and updates the account value.
- This specification provides a method for constructing an account map for real-time authentication, by using relevant information about the user (eg, certificate information, biometric identification information, account issuing authority, account number of the account, behavior data of the account, etc.) Collecting and creating associations of these information, constructing an account map including the core layer, the middle layer, and the outer layer, and updating the value of the middle layer account by the association of the created information, and the account map can be used for real people. Certification.
- relevant information about the user eg, certificate information, biometric identification information, account issuing authority, account number of the account, behavior data of the account, etc.
- the real person authentication methods provided by the various embodiments disclosed in the present specification are all executed based on the constructed account map.
- the basis for authenticating an account is: if the user who performs the operation request of the account operation for the account that needs to perform the real person authentication is the same user as the user corresponding to the real person information in the account registration information, the user should know Relevant information of all accounts in the account map corresponding to the real person information, for example, the account name that the user has registered to use and recent behavior data. Otherwise, the user who performs the operation request of the account operation on the account that needs to perform the real person authentication is using the real person information in the account registration information.
- the real person authentication method obtained by the multiple embodiments disclosed in the present specification obtains account information and behavior data by searching for an account map corresponding to the real person information in the account registration information, and generates verification according to the account information and the behavior data.
- the content is authenticated to the first account being operated by the user, thereby improving the credibility of authenticating the user identity.
- FIG. 5 is a flowchart of a real person authentication method provided by an embodiment of the present disclosure.
- the execution subject of the method may be a device having processing capabilities: a server or a system or device, such as the server in FIG. As shown in FIG. 5, the method specifically includes:
- Step S510 when detecting an operation request for performing an account operation on the first account by the user, searching for an account map corresponding to the real person information according to the real person information included in the registration information of the first account.
- the account map includes a core layer, an intermediate layer and an outer layer
- the core layer includes real person information
- the middle layer includes information of a second account associated with the real person information
- the outer layer includes behavior data associated with the second account.
- the first account may be an account in the account map.
- the user may perform the fund transaction through the first account in the account map; or the first account may not be the account in the account map, for example, the user registers the first account for the first time.
- the registration body of the first account may be a natural person or an organization.
- the first account may be a user account in Alipay, including a personal account and a business account.
- the execution entity of this step takes the server of the Alipay application as an example.
- the first account is not the account number in the account map, and the Alipay personal account is taken as an example, and the user can register the Alipay personal account.
- the server when registering an Alipay account, the user first needs to fill in the real person information.
- the server detects an operation request for registering the Alipay account, the server searches for the account map corresponding to the information according to the real person information.
- the server searches for the account map corresponding to the information according to the real person information, and may include: verifying whether the real person information is legal, and if the real person information is legal, searching for an account map corresponding to the real person information.
- the user opens the Alipay application on the phone and enters the phone number.
- the phone number will be used as the personal account that the user uses to log in to the Alipay application.
- enter the phone verification code to pass the verification of the phone number.
- the user enters the real person information, which may include the real name, the document type, and the ID number.
- the name entered by the user is “Zhang San”, the ID of the ID is “ID Card”, and the ID number is “123456200011071234”.
- the server verifies the real person information input by the user, and the verification result is that the real person information is legal information.
- the server searches for the account map corresponding to the real person information.
- Step S520 providing the user with the verification content of the real person authentication according to the behavior data in the account map.
- the number of the second account in the middle layer of the account map may be one or multiple.
- the server may provide the user with the verification content of the real person authentication according to the behavior data of the second account.
- the server may randomly provide the verification content of the real person authentication according to the behavior data of the at least one second account in the second account.
- the middle layer of the account map includes a Taobao account
- the server provides the user with the verification content of the real person authentication according to the transaction data of the Taobao account, such as the last month, as shown in FIG. The item purchased by the user in the last month using the Taobao account.
- Step S530 receiving a verification operation result of the verification content by the user, and determining, according to the operation result, whether the user passes the real person authentication.
- the user performs a verification operation result on the verification content, and compares the operation result with the behavior data, and determines whether the user passes the real person authentication according to the preset real person authentication determination condition.
- the verification content is as shown in FIG. 6, and the result of the operation received by the server is that the user clicks on "shirt”, “milk” and “watch”.
- the actual behavior data includes: the user bought “shirts”, “milk” and “watches” on Taobao in the last month.
- the server presupposes the real person authentication condition: if the user correctly selects all the purchased products, the user passes the real person authentication, and if the user misselects or misses the purchased product, the user does not pass the real person authentication. It can be seen from this that the judgment result of the server is that the user passes the real person authentication.
- the verification content is as shown in FIG. 6, and the result of the operation received by the server is that the user clicks on "hairy crab", "shirt” and “soda”.
- the actual behavior data includes: the user bought “shirts”, “milk” and “watches” on Taobao in the last month.
- the server presupposes the real person authentication condition: if the user correctly selects all the purchased products, the user passes the real person authentication, and if the user misselects or misses the purchased product, the user does not pass the real person authentication. It can be seen from this that the judgment result of the server is that the user has not passed the real person authentication.
- the method may further include: presenting prompt information if the user does not pass the real person authentication, and the prompt information is used to prompt the user to continue or re-establish the real person authentication.
- the prompt information is presented, and the information of the first account is added to the account map.
- the prompt information is presented, and the content of the prompt information may be that the user has passed the real person authentication.
- the user registers the first account, and when the server detects that the user performs the registration operation on the first account, initiates a real person authentication for the user. If the user passes the real person authentication, the user is prompted to have passed the real person authentication. And the first account is successfully registered.
- the information of the first account is added to the account map associated with the real person information in the registration information of the first account. Moreover, the association relationship between the first account and the other second account can be established, and the behavior data associated with the first account is recorded.
- the real person authentication method when detecting an operation request for performing an account operation on the first account by the user, searching and realizing the information according to the real person information included in the registration information in the first account.
- the corresponding account map according to the behavior data in the account map, provides the user with the verification content of the real person authentication, so as to authenticate the user, thereby improving the credibility of authenticating the user identity.
- FIG. 7 is a flowchart of a real person authentication method provided by another embodiment disclosed in the present specification.
- the execution subject of the method may be a device having processing capabilities: a server or a system or device, such as the server in FIG.
- the second account is a plurality of second accounts. As shown in FIG. 7, the method specifically includes:
- Step S710 When detecting an operation request for performing an account operation on the first account by the user, searching for an account map corresponding to the real person information according to the real person information included in the registration information of the first account.
- the execution entity of this step takes the server of the Alipay application as an example.
- the first account is an account in the account map, and the Alipay personal account is taken as an example, and the user can conduct the fund transaction through the Alipay personal account.
- the user logs in to the Alipay application using the registered personal account, and performs a fund transaction.
- the server detects an operation request for performing a fund transaction operation on the Alipay account
- the user searches for an account map corresponding to the information according to the real person information.
- the server searches for the account map corresponding to the information according to the real person information, and the method may include: the server performs real person information authentication on the user according to the real person information in the registration information, and if the user passes the real person information authentication, the real person is The information finds an account map corresponding to the information.
- the user logs in to the Alipay application using the personal account number 13811111111, and initiates an operation of transferring all the funds in the Alipay balance to 10,000 yuan to an unfamiliar account (the unfamiliar account can be a non-friend account).
- the server detects a large transaction operation on the account, and determines that the operation has a high risk.
- the user is authenticated according to the real person information in the account registration information.
- the real person information authentication may include: requiring the user to input the user's name and ID number, or the system sends the transaction verification code to the mobile phone number in the personal account, and the user is required to input the verification code. If the user authenticates through the real person information, the account map corresponding to the information is searched according to the real person information.
- Step S720 the server selects at least two second accounts from the plurality of second accounts.
- the server may randomly select at least two second accounts from the plurality of second accounts.
- the middle layer of the account map includes a plurality of second accounts, such as an intermediate layer including an Alipay account, a Taobao account, a China Railway Customer Service Center account, a flying pig travel account, and a bank card account.
- the server can randomly select the Taobao account and the Qunar network account from the second account.
- the server may select at least two second accounts according to the value of the plurality of second accounts, the value including the business value and the real relevance.
- the first account is an Alipay account
- the Alipay account is a high value account
- the server may select two accounts with lower values according to the value of each of the plurality of second accounts.
- Table 1 the business value of the China Merchants Bank account number, the construction bank and the ICBC account number are 2, 10 and 4, respectively, and the three have the same real relevance. It is possible to select the China Merchants Bank account number and the ICBC account number for presentation to the user.
- Step S730 presenting information of the selected at least two second accounts to the user, and receiving the second account selected by the user.
- the server presents the information of the selected at least two second accounts to the user, and the information of the second account may include the information of the issuing authority of the second account, the account name, and the like, and determines the second account selected by the user.
- At least two second accounts selected by the server include a flying pig travel account: 11111@qq.com and a Taobao account number: 22222@126.com, and the server presents the icon of the flying pig travel and the icon of the Taobao network to the user, such as As shown in FIG. 8, the second account selected by the user is received as a Taobao account.
- the server presents the information of the selected at least two second accounts to the user, where the server may: the server desensitizes the information of the selected at least two accounts, and presents the user with desensitization processing. Information of at least two second accounts.
- the desensitization process refers to the deformation of some sensitive information through desensitization rules to achieve reliable protection of sensitive private data, for example, hiding certain bits of the account.
- the terminal desensitizes the information of the selected China Merchants Bank account number: 1234567890987654321 and ICBC account number: 987653210123456789, hides some of the China Merchants Bank account number and the ICBC account number, and desensitizes the China Merchants Bank account number and business
- the bank account number can be:**********4321,***************6789.
- Step S740 searching for the behavior data associated with the account in the account map according to the second account selected by the user, and providing the user with the verification content of the real person authentication according to the behavior data.
- the server searches for the behavior data associated with the account in the account map according to the second account selected by the user, and generates verification content of the real person authentication according to the behavior data, and the verification content of the real person authentication may include whether the user uses the second account. Make certain behaviors, such as establishing a friend relationship, conducting a transaction, etc., collecting certain data information, and so on.
- the server receives the second account selected by the user as an ICBC account, and the first account is an Alipay account that has been registered for use.
- the verification content generated by the server for real-life authentication includes: making a payment to the ICBC account number, the amount of the payment can be 0.01-0.99, and letting the user input the specific amount of the payment on the authentication page of the Alipay application.
- Step S750 receiving a verification operation result of the verification content by the user, and determining whether the user passes the real person authentication according to the operation result.
- the user performs a verification operation result on the verification content, and compares the operation result with the behavior data, and determines whether the user passes the real person authentication according to the preset real person authentication determination condition.
- the preset real-person authentication criterion is: if the user inputs the correct amount of the payment on the Alipay authentication page of the Alipay, the user passes the real person authentication. Otherwise, the user does not pass the real person certification. For example, if the correct amount of payment in a verification process is 0.07 yuan, and the server receives the amount of the user input, the amount of the payment is 0.07 yuan, the server determines that the user passes the real person authentication. For another example, if the correct amount of the payment is 0.06 yuan in a verification process, and the server receives the amount of the payment input by the user as 0.02 yuan, the server determines that the user has not passed the real person authentication.
- the method may further include: if the user passes the real person authentication, presenting the prompt information, prompting the user to pass the real person authentication, and continuing to perform the original operation. For example, the user initiates a large transaction to transfer to an unfamiliar account by using the Alipay account, and the server detects the operation of the user on the Alipay account, and the operation is a high-risk operation, and initiates a real person authentication for the user, if the user passes the real If the person is authenticated, the transfer operation continues.
- the real person authentication method when detecting an operation request for performing an account operation on the first account by the user, searching and realizing the information according to the real person information included in the registration information in the first account.
- Corresponding account map when the account map includes multiple second accounts, randomly select or select at least two second accounts according to the value of the second account, for further selection by the user, and according to the account map and the user selection
- the behavior data associated with the second account generates a verification content of the real person authentication to authenticate the user, thereby improving the credibility of authenticating the user identity.
- FIG. 9 is a flowchart of an account adding method in an account map provided by an embodiment of the present disclosure.
- the execution subject of the method may be a device having processing capabilities: a server or a system or device, such as the server in FIG.
- the server performs the operation of adding the first account to the account map, usually under the premise that the account has passed the pre-authentication or the system authorizes the account.
- the pre-authentication includes verifying the legality of the real information in the registration information of the account, and the system authorizing the account includes allowing the system to join the account map or delete from the account map.
- the method specifically includes:
- Step S910 determining whether the operation of the first account is a system operation or a user operation. If it is a system operation, step S920 is performed. If it is a user operation, step S930 is performed.
- the system detects that the newly issued first account has not been added to the account map, and initiates an operation of adding the account to the account map. Or, when a user registers an account, the usage platform of the account requires the user to perform real person authentication.
- step S920 the system authority is verified.
- the authority of the system for performing the operation request of the account operation on the first account is verified. If the authority of the system is high enough, for example, the system is a government system, the first account can be directly added to the account map by directly responding to the operation of the first account. If the authority of the system is not high enough, for example, the system is a system of a company with a lower credit rating, the first account fails to be associated with the account map.
- the user opens a bank account to the bank
- the identity authentication method used by the bank can determine that the real information provided by the user is consistent with the identity of the user himself.
- the banking system can initiate the operation of adding the bank account to the account map.
- the server verifies the authority of the banking system, determines that it has sufficient authority, and adds the bank account to The account map associated with the user's real person information.
- Step S930 determining the challenge range of the real person authentication according to the data in the account map.
- the account map associated with the real person information is searched. Based on the data in the account map, determine the scope of the challenge for real-life authentication.
- the challenge scope may include real-life information of the core layer in the account map, such as address information, and a second account of the middle layer, such as information of a Taobao account.
- Step S940 determining a challenge range selected by the user.
- the user can further select the challenge range from the range of challenges determined by the server. For example, the user chooses to verify the Taobao account example****@taobao.com.
- step S950 the challenge task of the real person authentication is determined according to the challenge range selected by the user.
- a challenge task is generated from the behavior data based on the account, for example, the challenge task is to select the latest shopping record.
- Step S960 receiving an operation result of the user on the challenge task, and determining whether the user passes the challenge.
- the server judges the operation result of the challenge task. If the server determines that the user has passed the challenge, the first account is associated with the account map.
- step S970 is performed.
- step S970 it is determined whether to continue the challenge.
- step S930 is performed to proceed to the next cycle. If the server determines that the user is not allowed to continue the challenge or the user abandons the challenge, step S980 is performed.
- step S980 it is determined whether the association is forced.
- the association between the first account and the account map fails. If the first account can be forced to associate the account map, the first account is successfully associated with the account map, and the first account is marked.
- some services may not rely on the actual authentication results of the account.
- the account can still enter the account map, the account is added to the account map, and fraud or other markup is set.
- These tags can be used in certain scenarios.
- the server determines the challenge range based on the tags with the tags in step S830, and alerts the business users of the account that there is a risk of fraud.
- the account with the mark is converted according to the original calculated value according to a certain ratio.
- step S930 the method further includes: determining, according to the value of the first account, that the user needs to perform multiple rounds of challenges.
- the server determines, according to the value of the first account, that the user needs to perform multiple rounds of challenges, and the challenge range in the multiple rounds of challenges may be selected according to the value of the second account. For example, select a second account with a higher value, or select a second account with a lower value, or a second account with a higher value and a value.
- the server may freeze the low-value second account according to the result of the user completing the challenge task.
- the server detects that a high value account is performing a high risk operation. If the server detects that the Alipay account is transferring the entire balance to an unfamiliar account, the server initiates a real person authentication for the account. Real-life certification includes multiple rounds of challenges, such as three rounds of challenges based on the same high-value account, and one round of challenges based on low-value accounts. If the user successfully passes the 3 rounds of challenges based on the same high value account, but does not pass the challenge based on the low value account, at this time, it can be judged that the low value account may be fraudulent, so the low value account can be frozen.
- step S960 the method may further include: if the user passes the current challenge, proceeding to step S930 until the user successfully passes all the challenges, adding the account to the account map.
- the method for adding an account in the account map provided by one embodiment disclosed in the present specification can directly add the first account to the account according to the high authority of the system when the subject of the operation request for performing the account operation on the first account is determined. Map.
- the subject is a user
- the real person authentication may be initiated, and according to the result of the real person authentication, whether the first account is added to the account map is added, thereby increasing the reliability of the account information in the account map and ensuring the security of the user information.
- the embodiments disclosed in the present specification further provide a device for constructing an account map for real person authentication.
- the device includes:
- the first obtaining unit 1010 is configured to acquire real person information of the user, and the real person information includes the certificate information and/or the biometric identification information;
- the second obtaining unit 1020 is configured to acquire account information of the user, where the account information includes an account.
- the third obtaining unit 1030 is configured to obtain behavior data that the user operates on the account.
- the associating unit 1040 is configured to establish a first association between the real person information and the account information, and establish a second association between the account information and the behavior data.
- the building unit 1050 is configured to use the real person information as the core layer, the account information as the middle layer, the behavior data as the outer layer, and the first association and the second association as the inter-layer association, and the account map is constructed for real person authentication.
- the account information acquired by the second obtaining unit 1020 further includes the value of the account, the value includes the business value and the real person relevance, the business value is determined by the behavior data of the account, and the real relevance is determined by the issuing authority of the account. determine.
- the account acquired by the second obtaining unit 1020 includes a plurality of accounts, and the plurality of accounts include a direct account directly associated with the real person information, and an indirect account directly associated with the real person information through the direct account, directly
- the value of the account number includes the sum of the values of the indirect accounts that are indirectly associated with the real person information through the direct second account.
- the building unit 1050 is further configured to: when detecting an account operation request for adding an account to the account map, perform real-client authentication on the account, and when the account passes the real-person authentication, the account is Join the account map.
- the embodiments disclosed in the present specification further provide a real person authentication device.
- the device includes:
- the searching unit 1110 is configured to: when detecting an operation request for performing an account operation on the first account by the user, searching for an account map corresponding to the real person information according to the real person information included in the registration information of the first account; the account map includes Information of the second account associated with the real person information, and behavior data associated with the second account;
- the processing unit 1120 is configured to provide the user with the verification content of the real person authentication according to the behavior data
- the determining unit 1130 receives the verification operation result of the verification content by the user, and determines whether the user passes the real person authentication according to the verification operation result.
- the second account that is found by the searching unit 1110 is a plurality of second accounts
- the processing unit 1120 specifically includes:
- the selecting subunit 1121 is configured to select at least two second account accounts from the plurality of second account accounts;
- a presentation subunit 1122 configured to present information of at least two second accounts to a user, and receive a second account selected by the user;
- the generating subunit 1123 is configured to search for behavior data associated with the second account selected by the user, and generate verification content of the real person authentication according to the behavior data.
- the selection subunit 1121 included in the processing unit 1120 is specifically configured to:
- the value of the plurality of second accounts at least two second accounts are selected, the value includes the business value and the real person relevance, the business value is determined by the behavior data of the account, and the real relevance is determined by the issuing authority of the account.
- the plurality of second accounts found by the searching unit 1110 include a direct second account directly associated with the real person information, and an indirect second account indirectly associated with the real person information through the direct second account.
- the value of the direct second account includes the sum of the values of the indirect second accounts indirectly associated with the real person information through the direct second account.
- the presentation sub-unit 1122 is further configured to desensitize the information of the at least two second accounts, and present the information of the at least two second accounts after the desensitization process to the user.
- the lookup unit 1110 includes:
- the verification subunit 1111 is configured to verify whether the real person information included in the registration information of the first account is legal;
- the searching subunit 1110 is configured to search for an account map corresponding to the real person information if the real person information is legal.
- the account operation detected by the searching unit 1110 is an operation of adding a first account
- the device further includes:
- the adding unit 1140 is configured to add the information of the first account to the account map if the user passes the real person authentication.
- the real person information found by the searching unit 1110 includes the certificate information and the biometric identification information; the information of the second account includes the issuing authority and the user number of the second account; and the behavior data includes the friend of the second account. Relationship and consumption data.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Power Engineering (AREA)
- Health & Medical Sciences (AREA)
- Biomedical Technology (AREA)
- General Health & Medical Sciences (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
本说明书披露的实施例提供的一种实人认证方法中当服务器检测到用户对第一账号进行账号操作的操作请求时,根据所述第一账号的注册信息中所包含的实人信息,查找与所述实人信息对应的账号图谱,并根据账号图谱中的行为数据,向用户提供实人认证的验证内容。服务器接收用户对验证内容的操作结果,并根据操作结果判断该用户是否通过实人认证。
Description
本说明书披露的多个实施例涉及互联网技术领域,尤其涉及一种构建账号图谱用于实人认证的方法及装置,以及一种实人认证方法及装置。
随着互联网技术的不断发展,用户身份信息被别人冒用的情况在不断增多。如果不法分子利用冒用的身份信息进行洗钱等不法行为,不仅无法抓捕不法分子,还会对被冒用身份的正常用户造成较大影响。
对此,为了避免出现上述情况,大部分网络平台和应用程序已经采取了对账户进行实名认证的方法。实名认证过程中的认证信息主要包括用户的物品信息和用户的生物特征信息。其中,用户的物品信息包括用户的身份证、手机和邮箱,以及用户预先设置的密码和安保问题等。用户的生物特征信息包括指纹信息、人脸信息、虹膜信息和声音信息等。但是,由于用户的物品信息存在泄漏的情况,而用户的生物特征在采集的过程中存在复制和盗用的风险,因此,需要提供更可靠的对用户身份进行认证的方案。
发明内容
本说明书描述了一种构建账号图谱用于实人认证的方法及装置,以及实人认证方法及装置,通过构建账号图谱,并利用账号图谱对用户进行实人认证,从而提高了对用户身份进行认证的可信度。
第一方面,提供了一种构建账号图谱用于实人认证的方法。该方法包括:
获取用户的实人信息,所述实人信息包括证件信息和/或生物特征识别信息;
获取所述用户的账号信息,所述账号信息包括账号;
获取所述用户对所述账号进行操作的行为数据;
在所述实人信息与所述账号信息之间建立第一关联,在所述账号信息和 所述行为数据之间建立第二关联;
以所述实人信息为核心层,所述账号信息为中间层,所述行为数据为外层,以所述第一关联和第二关联作为层间关联,构建账号图谱用于实人认证。
第二方面,提供了一种实人认证方法。该方法包括:
当检测到用户对第一账号进行账号操作的操作请求时,根据所述第一账号的注册信息中所包含的实人信息,查找与所述实人信息对应的账号图谱;所述账号图谱包括与所述实人信息关联的第二账号的信息,以及与所述第二账号关联的行为数据;
根据所述行为数据,向用户提供实人认证的验证内容;
接收所述用户对所述验证内容的验证操作结果,并根据所述验证操作结果判断所述用户是否通过所述实人认证。
第三方面,提供了一种构建账号图谱用于实人认证的装置。该装置包括:
第一获取单元,用于获取用户的实人信息,所述实人信息包括证件信息和/或生物特征识别信息;
第二获取单元,用于获取所述用户的账号信息,所述账号信息包括账号;
第三获取单元,用于获取所述用户对所述账号进行操作的行为数据;
关联单元,用于在所述实人信息与所述账号信息之间建立第一关联,在所述账号信息和所述行为数据之间建立第二关联;
构建单元,用于以所述实人信息为核心层,所述账号信息为中间层,所述行为数据为外层,以所述第一关联和第二关联作为层间关联,构建账号图谱用于实人认证。
第四方面,提供了一种实人认证装置。该装置包括:
查找单元,用于当检测到用户对第一账号进行账号操作的操作请求时,根据所述第一账号的注册信息中所包含的实人信息,查找与所述实人信息对应的账号图谱;所述账号图谱包括与所述实人信息关联的第二账号的信息,以及与所述第二账号关联的行为数据;
处理单元,用于根据所述行为数据,向用户提供实人认证的验证内容;
判断单元,接收所述用户对所述验证内容的验证操作结果,并根据所述验证操作结果判断所述用户是否通过所述实人认证。
本说明书提供的一种构建账号图谱用于实人认证的方法及装置,通过对用户的相关信息(如,证件信息,生物特征识别信息、账号的颁发机构、账号的用户编号、账号的行为数据等)进行采集,以及创建这些信息的关联,构建包括核心层、中间层和外层的账号图谱,并可以通过实人认证对中间层的账号进行更新,通过创建的信息的关联对中间层账号的价值进行更新,且该账号图谱可以用于实人认证。
本说明书提供的一种实人认证方法及装置,通过查找与账号注册信息中的实人信息对应的账号图谱,获取其中的账号信息和行为数据,并根据账号图谱中的实人信息、账号信息和行为数据生成验证内容,对正在被用户操作的第一账号进行实人认证,从而提高了对用户身份进行认证的可信度。
为了更清楚地说明本说明书披露的多个实施例的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本说明书披露的多个实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其它的附图。
图1为本说明书披露的一个实施例提供的实人认证方法的应用场景示意图;
图2为本说明书披露的一个实施例提供的账号图谱的结构图;
图3为本说明书披露的一个实施例提供的构建账号图谱用于实人认证的方法流程图;
图4为本说明书披露的一个实施例提供的账号的价值更新流程图;
图5为本说明书披露的一个实施例提供的实人认证方法流程图;
图6为本说明书披露的一个实施例提供的实人认证内容示意图;
图7为本说明书披露的另一个实施例提供的实人认证方法流程图;
图8为本说明书披露的另一个实施例提供的实人认证内容示意图;
图9为本说明书披露的一个实施例提供的账号图谱中账号添加方法流程图;
图10为本说明书披露的一个实施例提供的构建账号图谱用于实人认证的装置示意图;
图11为本说明书披露的一个实施例提供的实人认证装置结构示意图。
下面结合附图,对本说明书披露的多个实施例进行描述。
图1为本说明书披露的一个实施例提供的实人认证方法的应用场景示意图。图1中,当服务器(如,服务器可以为支付宝应用的服务器)检测到用户通过终端(如,终端可以为手机、平板电脑、可穿戴智能设备等)对第一账号(如,第一账号可以为支付宝账号)进行账号操作(如,账号操作可以为注册第一账号,或者使用第一账号中的资金进行消费)的操作请求时,可以采用本说明书披露的多个实施例提供的实人认证方法,对第一账号进行实人认证,以检验对第一账号进行账号操作的操作请求的用户是否与第一账号的注册信息中的实人信息(如,实人信息可以为姓名和身份证号)相匹配。
本说明书披露的多个实施例提供的实人认证方法,均基于构建的账号图谱执行。下面对构建账号图谱用于实人认证的方法进行介绍。
图2为本说明书披露的一个实施例提供的账号图谱的结构图。如图2所示,账号图谱由内向外包括核心层、中间层和外层。
图3为本说明书披露的一个实施例提供的构建账号图谱用于实人认证的方法流程图。所述方法的执行主体可以为具有处理能力的设备:服务器或者系统或者装置,所述方法包括:
步骤S310,获取用户的实人信息,该实人信息包括证件信息和/或生物特征识别信息。
具体的,获取用户的实人信息,实人信息可以唯一确认现实世界中的一 个实体。其中,实体可以为自然人或组织机构,实人信息可以包括自然人的证件(如,证件可以为身份证、驾驶证、房产证)信息,生物特征(例如,生物特征可以为人脸、指纹、虹膜)识别信息等。或者,实人信息可以包括组织机构的统一社会信用代码,组织机构名称、机构登记证号等。
步骤S320,获取用户的账号信息,该账号信息包括账号。
具体的,获取用户的账号信息,该账号信息可以包括账号。其中的每个账号由该账号的颁发机构根据用户的实人信息生成并颁发,且每个账号在该账号的颁发机构内是唯一的。但因不同颁发机构颁发的账号可能出现相同的情况,所以,对于账号图谱中的账号,其表达形式可以为:颁发机构+账号,例如,由支付宝颁发的账号12345678,其在账号图谱中的表达形式为:支付宝12345678。因此,账号信息中每个账号的表达形式都是唯一的。
步骤S330,获取所述用户对所述账号进行操作的行为数据。
具体的,获取所述用户对账号进行操作的行为数据,该数据是由账号产生的。行为数据可以包括:一个账号与另一个账号建立好友关系、账号密码的更改、账号的资金交易行为等。例如,某用户通过淘宝网的账号购买了一件衬衫。
步骤S340,在实人信息与账号信息之间建立第一关联,在账号信息与行为数据之间建立第二关联。
具体的,建立账号之间的关联,并根据中间层中账号之间的关联,对账号进行分层,然后在分层后的账号与核心层中的实人信息之间建立第一关联,第一关联包括直接关联或间接关联。此时,中间层的多个账号包括与实人信息直接关联的直接账号,以及通过直接账号与实人信息间接关联的间接账号。以及,根据账号的行为数据与账号信息,建立账号信息中的账号与获取的行为数据之间的第二关联。
例如,支付宝根据用户的实人信息生成并颁发的客户号为12345678,与该客户号相关联的用户号(如,用户名可以包括用户名和密码)可以为多个,比如,某用户有两个手机号,该用户可以使用两个手机号注册支付宝用户账 号。每个用户号可以关联有多个资金账号(如,资金账号可以为余额宝账号、蚂蚁金服账号、健康保险账号)。其中,客户号与实人信息直接关联,用户号通过客户号与实人信息间接关联,资金账号通过用户号和客户号与实人信息间接关联。图2中仅示出了对中间账号分两层的情况,对此不作限定。
步骤S350,以实人信息作为核心层,账号信息作为中间层,行为数据作为外层,以第一关联和第二关联作为层间关联,构建账号图谱用于实人认证。
需要说明的是,本说明披露的一个实施例中,步骤S320中的账号信息还可以包括账号的价值,账号的价值包括实人关联度和业务价值。
其中,账号的实人关联度可以根据该账号的颁发机构确定。颁发机构越权威,则该账号的实人关联度越高。例如,对于颁发机构为政府部门(政府部门,如中国铁路客服服务中心,社会保险经办机构、国家银行)的账号,该账号的实人关联度可以评定为5。对于颁发机构为世界500强的企业(企业,如阿里巴巴),该账号的实人关联度可以评定为4。
账号的业务价值可以根据该账号的行为数据进行评估。行为数据可以包括建立好友关系,资金交易等。例如,对于支付宝中绑定的多个银行卡账号,其业务价值可以根据其交易类型、交易次数和交易金额确定。比如,某个支付宝的个人账号在1月1日绑定了多张银行卡,包括招商银行、建设银行和工商银行,1月份这些银行卡账号的交易情况如表1所示,相应的,可以根据交易情况确定这些银行账号的业务价值。
表1
| 银行卡账号 | 交易类型 | 交易次数 | 交易金额 | 业务价值 |
| 招商银行 | 转入账户余额 | 1次 | 2000元/次 | 2 |
| 建设银行 | 购买基金 | 2次 | 5000元/次 | 10 |
| 工商银行 | 转入余额宝 | 4次 | 1000元/次 | 4 |
同时,因账号图谱中的账号的数量可能会增加或者减少,账号之间的关联结构也可能发生改变,账号的行为数据通常会不断增加。所以,需要对账 号的价值进行更新。
图4为本说明书披露的一个实施例提供的账号的价值更新流程图。该方法中定期采用迭代的方式对账号的价值进行更新。图谱外层新增的行为数据和中间层中账号关联结构的变更,驱动账号价值的迭代。如图4所示,该方法包括以下步骤:
步骤S410,从中间层的账号中的最外层账号开始,计算最外层账号的价值。
具体的,中间层的账号中一共包括N层账号,且N≥1。其中,第一层账号为与实人信息直接关联的账号,第N层账号为最外层账号。首先,计算第N层账号的价值。
步骤S420,判断当前账号是否为最内层账号。如果不是最内层账号,则执行步骤S430,如果是最内层账号,则此次迭代更新完成。
具体的,判断N是否等于1。如果N等于1,则说明当前账号是最内层账号,则此次迭代更新完成,并可以结束流程。如果N不等于1,则说明当前账号不是最内层账号,且执行步骤S430。
步骤S430,向内推进一层。
具体的,将N的数值减1,即N=N-1,然后继续执行步骤S410,直到N=1,即此次迭代更新完成。
需要说明的是,服务器可以根据某个账号外层的行为数据,以及与其关联的其他账号的价值,确定该账号的价值。如,当中间层的账号包括多个账号,且多个账号包括与实人信息直接关联的直接账号,以及通过直接账号与实人信息间接关联的间接账号时,直接账号的价值包括通过该直接第二账号与实人信息间接关联的间接账号的价值的和。
此外,在确定账号的价值时,还可以考虑账号的实人可信度。例如,当用户选择某个账号的账号信息和行为数据进行实人认证(如,图7或图9所示的实施例)时,多次无法通过实人认证,但是,当该用于选择该账号所在账号图谱中的其他账号进行实人认证时,可以顺利通过实人认证。此时,该 账号存在被非法用户冒用的风险,实人可信度低。即使根据该账号的行为数据计算得到的业务价值很高,但因该账号的实人可信度低,故可以在计算得到的该账号原价值的基础上,按照一定的比例进行折算,并将折算后的价值作为该账号的价值。
本说明书披露的一个实施例提供的账号的价值更新方法,通过从最外层的账号开始,进行价值的计算和更新,并依次向内层推进,根据账号的外层行为数据以及与该账号相关联的其他账号的价值确定该账号的价值,实现了账号价值的更新。
本说明书提供的一种构建账号图谱用于实人认证的方法,通过对用户的相关信息(如,证件信息,生物特征识别信息、账号的颁发机构、账号的用户编号、账号的行为数据等)进行采集,以及创建这些信息的关联,构建包括核心层、中间层和外层的账号图谱,并可以通过创建的信息的关联对中间层账号的价值进行更新,且该账号图谱可以用于实人认证。
本说明书披露的多个实施例提供的实人认证方法,均基于构建的账号图谱执行。对账号进行实人认证的依据是:如果对需要进行实人认证的账号进行账号操作的操作请求的用户,与该账号注册信息中的实人信息对应的用户为同一用户,则该用户应该知道与实人信息对应的账号图谱中所有账号的相关信息,例如,该用户已经注册使用的账号名称以及近期的行为数据等。否则,对需要进行实人认证的账号进行账号操作的操作请求的用户,正在冒用该账号注册信息中的实人信息。
采用本说明书披露的多个实施例提供的实人认证方法,通过查找与账号注册信息中的实人信息对应的账号图谱,获取其中的账号信息和行为数据,并根据账号信息和行为数据生成验证内容,对正在被用户操作的第一账号进行实人认证,从而提高了对用户身份进行认证的可信度。
图5为本说明书披露的一个实施例提供的实人认证方法流程图。所述方法的执行主体可以为具有处理能力的设备:服务器或者系统或者装置,例如,图1中的服务器。如图5所示,所述方法具体包括:
步骤S510,当检测到用户对第一账号进行账号操作的操作请求时,根据第一账号的注册信息中所包含的实人信息,查找与实人信息对应的账号图谱。
需要说明的是,账号图谱包括核心层、中间层和外层,核心层包括实人信息,中间层包括与实人信息关联的第二账号的信息,外层包括与第二账号关联的行为数据。
第一账号可以是账号图谱中的账号,如,用户可以通过账号图谱中的第一账号进行资金交易;或者,第一账号可以不是账号图谱中的账号,例如,用户首次对第一账号进行注册,此前,并不存在第一账号。同时,第一账号的注册主体可以为自然人,也可以为组织机构,例如,第一账号可以为支付宝中的用户账号,包括个人账号和企业账号。
本步骤的执行主体以支付宝应用的服务器为例。在执行本步骤之前,第一账号不是账号图谱中的账号,且以支付宝的个人账号为例,用户可以通过注册支付宝的个人账号。
具体的,用户在注册支付宝账号时,首先需要填写实人信息。服务器检测到对支付宝账号进行注册操作的操作请求,则根据实人信息查找与该信息对应的账号图谱。
其中,服务器根据实人信息查找与该信息对应的账号图谱,可以包括:验证实人信息是否合法,如果该实人信息合法,则查找与实人信息对应的账号图谱。
在一个例子中,用户打开手机上的支付宝应用,输入手机号,在注册成功后,手机号将作为用户用于登录支付宝应用的个人账户。然后,输入手机检验码以通过对于手机号的验证。之后,用户输入实人信息,可以包括真实姓名、证件类型和证件号码。如:用户输入的姓名为“张三”、证件类型为“身份证”,证件号码为“123456200011071234”。服务器对用户输入的实人信息进行验证,验证结果为该实人信息为合法信息。服务器根据该实人信息查找与之对应的账号图谱。
步骤S520,根据账号图谱中的行为数据,向用户提供实人认证的验证内 容。
具体的,账号图谱的中间层中第二账号的数量可以为一个,也可以为多个。当第二账号的数量为一个时,服务器可以根据该第二账号的行为数据,向用户提供实人认证的验证内容。当第二账号的数量为多个时,服务器可以随机根据第二账号中的至少一个第二账号的行为数据,向用户提供实人认证的验证内容。
在一个例子中,账号图谱的中间层中包括淘宝账号,服务器根据淘宝账号的,如最近一个月内的交易数据,向用户提供实人认证的验证内容,如图6所示,验证内容为选出用户最近一个月内使用该淘宝账号购买的商品。
步骤S530,接收用户对验证内容的验证操作结果,并根据该操作结果判断用户是否通过实人认证。
具体的,接收用户对验证内容的验证操作结果,并将该操作结果与行为数据进行比对,根据预设的实人认证判别条件,判断用户是否通过实人认证。
在一个例子中,验证内容如图6所示,服务器接收的操作结果为:用户点击了其中的“衬衫”、“牛奶”和“手表”。而实际的行为数据包括:用户最近一个月内在淘宝网上购买了“衬衫”、“牛奶”和“手表”。服务器预设的实人认证判别条件为:如果用户正确选择了购买的所有商品,则该用户通过实人认证,如果用户错选或漏选了购买的商品,则该用户没有通过实人认证。由此可知,服务器的判断结果为:该用户通过实人认证。
在另一个例子中,验证内容如图6所示,服务器接收的操作结果为:用户点击了其中的“大闸蟹”、“衬衫”和“汽水”。而实际的行为数据包括:用户最近一个月内在淘宝网上购买了“衬衫”、“牛奶”和“手表”。服务器预设的实人认证判别条件为:如果用户正确选择了购买的所有商品,则该用户通过实人认证,如果用户错选或漏选了购买的商品,则该用户没有通过实人认证。由此可知,服务器的判断结果为:该用户没有通过实人认证。
在上述实施例中,在执行步骤S530时,还可以包括:如果用户没有通过实人认证,则呈现提示信息,提示信息用于提示用户需要继续或者重新进行 实人认证。
或者,如果用户通过实人认证,且对第一账号进行的账号操作为新增第一账号的操作,则呈现提示信息,并将第一账号的信息添加到账号图谱中。
具体的,如果用户通过实人认证,则呈现提示信息,提示信息的内容可以为用户已经通过实人认证。例如,用户对第一账号进行注册,当服务器检测到用户在对第一账号进行注册操作时,发起对该用户的实人认证,如果该用户通过实人认证,则提示用户已经通过实人认证,且第一账号注册成功。
同时,将第一账号的信息添加到,与第一账号的注册信息中的实人信息相关联的账号图谱中。并且,可以建立第一账号与其他第二账号的关联关系,以及记录与第一账号相关联的行为数据。
本说明书披露的一个实施例提供的实人认证方法,当检测到用户对第一账号进行账号操作的操作请求时,根据第一账号中的注册信息中包含的实人信息,查找与实人信息对应的账号图谱,根据账号图谱中的行为数据,向用户提供实人认证的验证内容,以对用户进行实人认证,从而提高了对用户身份进行认证的可信度。
图7为本说明书披露的另一个实施例提供的实人认证方法流程图。所述方法的执行主体可以为具有处理能力的设备:服务器或者系统或者装置,例如,图1中的服务器。所述第二账号为多个第二账号,如图7所示,所述方法具体包括:
步骤S710,当检测到用户对第一账号进行账号操作的操作请求时,根据第一账号的注册信息中所包含的实人信息,查找与实人信息对应的账号图谱。
本步骤的执行主体以支付宝应用的服务器为例,第一账号是账号图谱中的账号,且以支付宝的个人账号为例,用户可以通过支付宝的个人账号进行资金交易。
具体的,用户使用已注册的个人账号登录支付宝应用,并进行资金交易,服务器检测到对对支付宝账号进行资金交易操作的操作请求,则根据实人信息查找与该信息对应的账号图谱。其中,服务器根据实人信息查找与该信息 对应的账号图谱,可以包括:服务器根据注册信息中的实人信息,对用户进行实人信息认证,如果该用户通过实人信息认证,则根据实人信息查找与该信息对应的账号图谱。
例如,用户使用个人账号13811111111登录支付宝应用,发起将支付宝余额中的全部资金10,000元转账到一个陌生账号(陌生账号可以为非好友账号)的操作。服务器检测到对该账号的大额交易操作,并判断此操作具有较高风险,首先根据该账号注册信息中的实人信息,对用户进行实人信息认证。实人信息认证可以包括:要求用户输入用户的姓名和身份证号,或者系统发送交易验证码至个人账号中的手机号,要求用户输入该验证码。如果用户通过实人信息认证,则根据实人信息查找与该信息对应的账号图谱。
步骤S720,服务器从多个第二账号中选出至少两个第二账号。
具体的,服务器可以从多个第二账号中随机选出至少两个第二账号。
在一个例子中,账号图谱的中间层中包括多个第二账号,如中间层包括支付宝账号、淘宝账号、中国铁路客服中心账号、飞猪旅行账号、银行卡账号等。服务器可以从第二账号中随机选择淘宝账号和去哪儿网账号。
或者,服务器可以根据多个第二账号的价值,选出至少两个第二账号,所述价值包括业务价值和实人关联度。
在一个例子中,第一账号为支付宝账号,该支付宝账号为高价值账号,服务器可以根据多个第二账号中每个第二账号的价值,选择两个价值较低的账号。如表1中所示,招商银行账号、建设银行和工商银行账号的业务价值分别为2、10和4,且三者具有相同的实人关联度。可以从中选出招商银行账号和工商银行账号,以呈现给用户进行选择。
步骤S730,向用户呈现选出的至少两个第二账号的信息,并接收用户选择的第二账号。
具体的,服务器向用户呈现选出的至少两个第二账号的信息,第二账号的信息可以包括第二账号的颁布机构的信息,账号名称等,并确定用户选择 的第二账号。
例如,服务器选出的至少两个第二账号包括飞猪旅行账号:11111@qq.com和淘宝网账号:22222@126.com,服务器向用户呈现飞猪旅行的图标和淘宝网的图标,如图8所示,并接收用户选择的第二账号为淘宝网账号。
在一个例子中,服务器向用户呈现选出的至少两个第二账号的信息,可以包括:服务器对选出的至少两个账号的信息进行脱敏处理,并向用户呈现进行脱敏处理后的至少两个第二账号的信息。
其中,脱敏处理是指对某些敏感信息通过脱敏规则进行数据的变形,以实现敏感隐私数据的可靠保护,比如,对账号的某几位进行隐藏处理。
例如,终端对选出的招商银行账号:1234567890987654321和工商银行账号:9876543210123456789的信息进行脱敏处理,将招商银行账号和工商银行账号中的某几位隐藏,脱敏处理后的招商银行账号和工商银行账号分别可以为:***************4321,***************6789。然后,将脱敏处理后的支付宝账号和淘宝账号呈现给用户,并接收用户选择的第二账号,第二账号为工商银行账号。
步骤S740,根据用户选择的第二账号查找账号图谱中与该账号关联的行为数据,并根据该行为数据向用户提供实人认证的验证内容。
具体的,服务器根据用户选择的第二账号查找账号图谱中与该账号关联的行为数据,并根据该行为数据生成实人认证的验证内容,实人认证的验证内容可以包括用户是否使用第二账号做出某些行为,如建立好友关系,进行某项交易等,收藏某些数据信息等。
在一个例子中,服务器接收用户选择的第二账号为工商银行账号,第一账号为已注册使用的支付宝账号。服务器生成的实人认证的验证内容包括:向该工商银行的账号打款,打款数额可以为0.01-0.99,并让用户在支付宝应用的认证页面输入具体的打款数额。
步骤S750,接收用户对验证内容的验证操作结果,并根据该操作结果判 断用户是否通过实人认证。
具体的,接收用户对验证内容的验证操作结果,并将该操作结果与行为数据进行比对,根据预设的实人认证判别条件,判断用户是否通过实人认证。
在一个例子中,预设的实人认证判别条件为:如果用户在支付宝的实人认证页面,输入正确的打款金额,则用户通过实人认证。否则,用户没有通过实人认证。例如,某次验证过程中正确的打款金额为0.07元,且服务器接收用户输入的打款金额为0.07元,则服务器判断该用户通过实人认证。又例如,某次验证过程中正确的打款金额为0.06元,且服务器接收用户输入的打款金额为0.02元,则服务器判断该用户没有通过实人认证。
在上述实施例中,在执行步骤S550时,还可以包括:如果用户通过实人认证,则呈现提示信息,提示用户实人认证通过,并继续执行原有操作。例如,用户在使用支付宝账号发起向陌生账号转账的大额交易,服务器检测到用户对支付宝账号的操作,且该操作为高风险操作,则发起对该用户的实人认证,如果该用户通过实人认证,则继续执行该转账操作。
本说明书披露的一个实施例提供的实人认证方法,当检测到用户对第一账号进行账号操作的操作请求时,根据第一账号中的注册信息中包含的实人信息,查找与实人信息对应的账号图谱,当账号图谱中包括多个第二账号时,随机选出或者根据第二账号的价值选出至少两个第二账号,以供用户进一步选择,并根据账号图谱中与用户选择的第二账号相关联的行为数据,生成实人认证的验证内容,以对用户进行实人认证,从而提高了对用户身份进行认证的可信度。
本说明书披露的多个实施例提供的实人认证方法,可以应用于账号图谱中第二账号的添加。图9为本说明书披露的一个实施例提供的账号图谱中账号添加方法流程图。所述方法的执行主体可以为具有处理能力的设备:服务器或者系统或者装置,例如,图1中的服务器。
服务器执行将第一账号加入账号图谱中的操作,通常是在该账号已经通过前置认证或者系统对该账号进行授权的前提下进行的。其中,前置认证包 括验证该账号的注册信息中实人信息的合法性,系统对该账号进行授权包括系统允许其加入账号图谱或从账号图谱中删除。如图9所示,所述方法具体包括:
步骤S910,判断对第一账号的操作是系统操作还是用户操作。如果是系统操作,则执行步骤S920。如果是用户操作则执行步骤S930。
具体的,系统检测到其新颁布的第一账号尚未添加到账号图谱,发起将该账号添加到账号图谱中的操作。或者,某个用户在注册账号时,该账号的使用平台要求用户进行实人认证。
步骤S920,校验系统权限。
具体的,校验对第一账号进行账号操作的操作请求的系统的权限。如果系统的权限足够高,比如该系统为政府系统,则可以直接响应对第一账号的操作,将第一账号加入账号图谱中。如果系统的权限不够高,比如该系统为一个信用等级较低的公司的系统,则第一账号与账号图谱关联失败。
在一个例子中,用户去银行开设银行账号,银行采用的身份认证方法可以极高的准确率确定该用户提供的实人信息与该用户本人的身份一致。用户在银行成功开设银行账号后,银行系统可以发起将该银行账号添加至账号图谱的操作,服务器对银行系统的权限进行校验,确定其具有足够高的权限,并将该银行账号添加至与该用户的实人信息关联的账号图谱。
步骤S930,根据账号图谱中的数据,确定实人认证的挑战范围。
具体的,根据第一账号的注册信息中实人信息,查找与实人信息相关联的账号图谱。根据账号图谱中的数据,确定实人认证的挑战范围。该挑战范围可以包括账号图谱中核心层的实人信息,如,住址信息,以及中间层的第二账号,如,淘宝账号的信息。
步骤S940,确定用户选择的挑战范围。
具体的,用户可以从服务器确定的挑战范围中,进一步选择挑战范围。例如,用户选择验证淘宝账号example****@taobao.com。
步骤S950,根据用户选择的挑战范围,确定实人认证的挑战任务。
具体的,根据用户选择的淘宝账号example****@taobao.com,从基于该账号的行为数据中生成挑战任务,如,挑战任务为选出最近的购物记录。
步骤S960,接收用户对挑战任务的操作结果,判断用户是否通过该挑战。
具体的,用户在完成挑战任务后,比如确认最近购物记录,输入家庭地址,支付宝打款认证等,服务器对挑战任务的操作结果进行判断。如果服务器判断出用户通过该挑战,则将第一账号关联到账号图谱。
如果服务器判断用户没有通过该挑战,如任务部分成功或失败、任务超时,发生任务相关的风险事件(如,风险事件可以为第一账号发生冻结),则执行步骤S970。
步骤S970,判断是否继续进行挑战。
具体的,如果服务器判断出允许用户继续进行挑战,则执行步骤S930,以进入下一个循环。如果服务器判断出不允许用户继续进行挑战或者用户放弃挑战,则执行步骤S980。
步骤S980,判断是否强制关联。
具体的,如果第一账号不能强制关联账号图谱,则第一账号与账号图谱关联失败。如果第一账号可以强制关联账号图谱,则第一账号与账号图谱关联成功,并对该第一账号进行标记。
在一个例子中,某些业务可能并不依赖账号的实人认证结果。对于这些需求,该账号仍旧可以进入账号图谱,即将该账号加入账号图谱,同时设置冒用或其他标记。这些标记可以使用在某些场景中,例如,服务器在步骤S830中根据这些标记,不使用带有这些标记的账号确定挑战范围,以及提醒该账号的业务使用方,该账号存在冒用风险。又例如,在图4中对账号的价值进行更新时,对于带有这些标记的账号,在原计算得到的价值的基础上,按照一定的比例进行折算。
需要说明的是,在步骤S930中,还可以包括:根据第一账号的价值,确定用户需要进行多轮挑战。
具体的,服务器根据第一账号的价值,确定用户需要进行多轮挑战,多 轮挑战中的挑战范围可以根据第二账号的价值进行选取。如,选取价值较高的第二账号,或者选取价值较低的第二账号,或者搭配选取价值较高和价值交底的第二账号。并且,服务器可以根据用户完成挑战任务的结果,对低价值的第二账号进行冻结操作。
在一个例子中,服务器检测到高价值账号正在进行高风险操作,如服务器检测到支付宝账号正在将全部余额转入陌生账号,则服务器发起对该账号的实人认证。实人认证包括多轮挑战,如3轮基于同样高价值账号的挑战,以及1轮基于低价值账号的挑战。如果用户顺利通过3轮基于同样高价值账号的挑战,但没有通过基于低价值账号的挑战,此时,可以判断出该低价值账号有可能是冒用的,因此可以对低价值账号进行冻结。
在步骤S960中,还可以包括:如果用户通过当前挑战,则继续执行步骤S930,直到用户成功通过所有挑战,则将该账号添加至账号图谱中。
本说明书披露的一个实施例提供的账号图谱中账号添加方法,通过判断对第一账号进行账号操作的操作请求的主体,当主体为系统时,可以根据系统的高权限直接将第一账号加入账号图谱。当主体为用户时,可以发起实人认证,并根据实人认证的结果判断是否将第一账号添加至账号图谱中,从而增加了账号图谱中账号信息的可靠度,保障了用户信息的安全。
与上述构建账号图谱用于实人认证的方法对应地,本说明书披露的多个实施例还提供一种构建账号图谱用于实人认证的装置,如图10所示,该装置包括:
第一获取单元1010,用于获取用户的实人信息,实人信息包括证件信息和/或生物特征识别信息;
第二获取单元1020,用于获取用户的账号信息,账号信息包括账号;
第三获取单元1030,用于获取用户对账号进行操作的行为数据;
关联单元1040,用于在实人信息与账号信息之间建立第一关联,在账号信息和行为数据之间建立第二关联;
构建单元1050,用于以实人信息为核心层,账号信息为中间层,行为数 据为外层,以第一关联和第二关联作为层间关联,构建账号图谱用于实人认证。
在一个可能的设计中,第二获取单元1020获取的账号信息还包括账号的价值,价值包括业务价值和实人关联度,业务价值由账号的行为数据确定,实人关联度由账号的颁布机构确定。
在一个可能的设计中,第二获取单元1020获取的账号包括多个账号,多个账号中包括与实人信息直接关联的直接账号,以及通过直接账号与实人信息间接关联的间接账号,直接账号的价值包括通过该直接第二账号与实人信息间接关联的间接账号的价值的和。
在一个可能的设计中,构建单元1050还用于,当检测到将某一账号加入账号图谱的账号操作请求时,对该账号进行实人认证,当该账号通过实人认证时,将该账号加入账号图谱中。
与上述实人认证方法对应地,本说明书披露的多个实施例还提供一种实人认证装置,如图11所示,该装置包括:
查找单元1110,用于当检测到用户对第一账号进行账号操作的操作请求时,根据第一账号的注册信息中所包含的实人信息,查找与实人信息对应的账号图谱;账号图谱包括与实人信息关联的第二账号的信息,以及与第二账号关联的行为数据;
处理单元1120,用于根据行为数据,向用户提供实人认证的验证内容;
判断单元1130,接收用户对验证内容的验证操作结果,并根据验证操作结果判断用户是否通过实人认证。
在一种可能的设计中,查找单元1110查找到的第二账号为多个第二账号,处理单元1120具体包括:
选择子单元1121,用于从多个第二账号中选出至少两个第二账号;
呈现子单元1122,用于向用户呈现至少两个第二账号的信息,并接收用户选择的第二账号;
生成子单元1123,用于查找与用户选择的第二账号关联的行为数据,并 根据该行为数据生成实人认证的验证内容
在一种可能的设计中,处理单元1120包括的选择子单元1121具体用于:
根据多个第二账号的价值,选出至少两个第二账号,价值包括业务价值和实人关联度,业务价值由账号的行为数据确定,实人关联度由账号的颁布机构确定。
在一种可能的设计中,查找单元1110查找到的多个第二账号中包括与实人信息直接关联的直接第二账号,以及通过直接第二账号与实人信息间接关联的间接第二账号,直接第二账号的价值包括通过该直接第二账号与实人信息间接关联的间接第二账号的价值的和。
在一种可能的设计中,呈现子单元1122还用于,对至少两个第二账号的信息进行脱敏处理,向用户呈现进行脱敏处理后的至少两个第二账号的信息。
在一种可能的设计中,查找单元1110包括:
验证子单元1111,用于验证第一账号的注册信息中所包含的实人信息是否合法;
查找子单元1110,用于如果实人信息合法,则查找与实人信息对应的账号图谱。
在一种可能的设计中,查找单元1110检测到的账号操作为新增第一账号的操作,装置还包括:
添加单元1140,用于如果用户通过实人认证,则将第一账号的信息添加到账号图谱中。
在一种可能的设计中,查找单元1110查找到的实人信息包括证件信息和生物特征识别信息;第二账号的信息包括第二账号的颁布机构和用户编号;行为数据包括第二账号的好友关系和消费数据。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本说明书披露的多个实施例所描述的功能可以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些功能存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。
以上所述的具体实施方式,对本说明书披露的多个实施例的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上所述仅为本说明书披露的多个实施例的具体实施方式而已,并不用于限定本说明书披露的多个实施例的保护范围,凡在本说明书披露的多个实施例的技术方案的基础之上,所做的任何修改、等同替换、改进等,均应包括在本说明书披露的多个实施例的保护范围之内。
Claims (24)
- 一种构建账号图谱用于实人认证的方法,其特征在于,包括:获取用户的实人信息,所述实人信息包括证件信息和/或生物特征识别信息;获取所述用户的账号信息,所述账号信息包括账号;获取所述用户对所述账号进行操作的行为数据;在所述实人信息与所述账号信息之间建立第一关联,在所述账号信息和所述行为数据之间建立第二关联;以所述实人信息为核心层,所述账号信息为中间层,所述行为数据为外层,以所述第一关联和第二关联作为层间关联,构建账号图谱用于实人认证。
- 根据权利要求1所述的方法,其特征在于,所述账号信息还包括所述账号的价值,所述价值包括业务价值和实人关联度,所述业务价值由所述账号的行为数据确定,所述实人关联度由所述账号的颁布机构确定。
- 根据权利要求2所述的方法,其特征在于,所述账号包括多个账号,所述多个账号中包括与所述实人信息直接关联的直接账号,以及通过所述直接账号与所述实人信息间接关联的间接账号,所述直接账号的价值包括通过该直接第二账号与所述实人信息间接关联的间接账号的价值的和。
- 根据所述权利要求1-3中任一项所述的方法,其特征在于,还包括:当检测到将某一账号加入账号图谱的账号操作请求时,对该账号进行实人认证,当该账号通过实人认证时,将该账号加入所述账号图谱中。
- 一种实人认证方法,其特征在于,包括:当检测到用户对第一账号进行账号操作的操作请求时,根据所述第一账号的注册信息中所包含的实人信息,查找与所述实人信息对应的账号图谱;所述账号图谱包括与所述实人信息关联的第二账号的信息,以及与所述第二账号关联的行为数据;根据所述行为数据,向用户提供实人认证的验证内容;接收所述用户对所述验证内容的验证操作结果,并根据所述验证操作结果判断所述用户是否通过所述实人认证。
- 根据权利要求5所述的方法,其特征在于,所述第二账号为多个第二账号,所述向用户提供实人认证的验证内容,包括:从所述多个第二账号中选出至少两个第二账号;向所述用户呈现所述至少两个第二账号的信息,并接收所述用户选择的第二账号;查找与所述用户选择的第二账号关联的行为数据,并根据该行为数据生成实人认证的验证内容。
- 根据权利要求6所述的方法,其特征在于,从所述多个第二账号中选出至少两个第二账号,包括:根据所述多个第二账号的价值,选出所述至少两个第二账号,所述价值包括业务价值和实人关联度,所述业务价值由所述账号的行为数据确定,所述实人关联度由所述账号的颁布机构确定。
- 根据权利要求7所述的方法,其特征在于,所述多个第二账号包括与所述实人信息直接关联的直接第二账号,以及通过所述直接第二账号与所述实人信息间接关联的间接第二账号,所述直接第二账号的价值包括通过该直接第二账号与所述实人信息间接关联的间接第二账号的价值的和。
- 根据权利要求6所述的方法,其特征在于,向所述用户呈现所述至少两个第二账号的信息,包括:对所述至少两个第二账号的信息进行脱敏处理,向所述用户呈现进行脱敏处理后的所述至少两个第二账号的信息。
- 根据权利要求5所述的方法,其特征在于,所述根据所述第一账号的注册信息中所包含的实人信息,查找与所述实人信息对应的账号图谱,包括:验证所述第一账号的注册信息中所包含的实人信息是否合法;如果所述实人信息合法,则查找与所述实人信息对应的账号图谱。
- 根据权利要求5所述的方法,其特征在于,其中所述账号操作为新增所述第一账号的操作,所述方法还包括:如果所述用户通过所述实人认证,则将所述第一账号的信息添加到所述账号图谱中。
- 根据权利要求5-11任一项所述的方法,其特征在于,所述实人信息包括证件信息和生物特征识别信息;所述第二账号的信息包括所述第二账号的颁布机构和用户编号;所述行为数据包括所述第二账号的好友关系和消费数据。
- 一种构建账号图谱用于实人认证的装置,其特征在于,包括:第一获取单元,用于获取用户的实人信息,所述实人信息包括证件信息和/或生物特征识别信息;第二获取单元,用于获取所述用户的账号信息,所述账号信息包括账号;第三获取单元,用于获取所述用户对所述账号进行操作的行为数据;关联单元,用于在所述实人信息与所述账号信息之间建立第一关联,在所述账号信息和所述行为数据之间建立第二关联;构建单元,用于以所述实人信息为核心层,所述账号信息为中间层,所述行为数据为外层,以所述第一关联和第二关联作为层间关联,构建账号图谱用于实人认证。
- 根据权利要求13所述的装置,其特征在于,所述第二获取单元获取的所述账号信息还包括所述账号的价值,所述价值包括业务价值和实人关联度,所述业务价值由所述账号的行为数据确定,所述实人关联度由所述账号的颁布机构确定。
- 根据权利要求14所述的装置,其特征在于,所述第二获取单元获取的所述账号包括多个账号,所述多个账号中包括与所述实人信息直接关联的直接账号,以及通过所述直接账号与所述实人信息间接关联的间接账号,所 述直接账号的价值包括通过该直接第二账号与所述实人信息间接关联的间接账号的价值的和。
- 根据所述权利要求13-15中任一项所述的装置,其特征在于,所述构建单元还用于,当检测到将某一账号加入账号图谱的账号操作请求时,对该账号进行实人认证,当该账号通过实人认证时,将该账号加入所述账号图谱中。
- 一种实人认证装置,其特征在于,包括:查找单元,用于当检测到用户对第一账号进行账号操作的操作请求时,根据所述第一账号的注册信息中所包含的实人信息,查找与所述实人信息对应的账号图谱;所述账号图谱包括与所述实人信息关联的第二账号的信息,以及与所述第二账号关联的行为数据;处理单元,用于根据所述行为数据,向用户提供实人认证的验证内容;判断单元,接收所述用户对所述验证内容的验证操作结果,并根据所述验证操作结果判断所述用户是否通过所述实人认证。
- 根据权利要求17所述的装置,其特征在于,所述查找单元查找到的所述第二账号为多个第二账号,所述处理单元具体包括:选择子单元,用于从所述多个第二账号中选出至少两个第二账号;呈现子单元,用于向所述用户呈现所述至少两个第二账号的信息,并接收所述用户选择的第二账号;生成子单元,用于查找与所述用户选择的第二账号关联的行为数据,并根据该行为数据生成实人认证的验证内容。
- 根据权利要求18所述的装置,其特征在于,所述处理单元包括的选择子单元具体用于:根据所述多个第二账号的价值,选出所述至少两个第二账号,所述价值包括业务价值和实人关联度,所述业务价值由所述账号的行为数据确定,所述实人关联度由所述账号的颁布机构确定。
- 根据权利要求19所述的装置,其特征在于,所述查找单元查找到的多个第二账号中包括与所述实人信息直接关联的直接第二账号,以及通过所述直接第二账号与所述实人信息间接关联的间接第二账号,所述直接第二账号的价值包括通过该直接第二账号与所述实人信息间接关联的间接第二账号的价值的和。
- 根据权利要求18所述的装置,其特征在于,所述呈现子单元还用于,对所述至少两个第二账号的信息进行脱敏处理,向所述用户呈现进行脱敏处理后的所述至少两个第二账号的信息。
- 根据权利要求17所述的装置,其特征在于,所述所述查找单元包括:验证子单元,用于验证所述第一账号的注册信息中所包含的实人信息是否合法;查找子单元,用于如果所述实人信息合法,则查找与所述实人信息对应的账号图谱。
- 根据权利要求17所述的装置,其特征在于,所述查找单元检测到的所述账号操作为新增所述第一账号的操作,所述装置还包括:添加单元,用于如果所述用户通过所述实人认证,则将所述第一账号的信息添加到所述账号图谱中。
- 根据权利要求17-23任一项所述的装置,其特征在于,所述查找单元查找到的所述实人信息包括证件信息和生物特征识别信息;所述第二账号的信息包括所述第二账号的颁布机构和用户编号;所述行为数据包括所述第二账号的好友关系和消费数据
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201710814013.6A CN107846393B (zh) | 2017-09-11 | 2017-09-11 | 实人认证方法及装置 |
| CN201710814013.6 | 2017-09-11 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2019047880A1 true WO2019047880A1 (zh) | 2019-03-14 |
Family
ID=61682999
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/104273 Ceased WO2019047880A1 (zh) | 2017-09-11 | 2018-09-06 | 实人认证方法及装置 |
Country Status (3)
| Country | Link |
|---|---|
| CN (1) | CN107846393B (zh) |
| TW (1) | TWI695288B (zh) |
| WO (1) | WO2019047880A1 (zh) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107846393B (zh) * | 2017-09-11 | 2020-01-14 | 阿里巴巴集团控股有限公司 | 实人认证方法及装置 |
| CN109347787B (zh) | 2018-08-15 | 2020-08-04 | 阿里巴巴集团控股有限公司 | 一种身份信息的识别方法及装置 |
| CN113412608B (zh) * | 2019-06-24 | 2022-11-15 | 深圳市欢太科技有限公司 | 内容推送方法、装置、服务端及存储介质 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103944722A (zh) * | 2014-04-17 | 2014-07-23 | 华北科技学院 | 一种互联网环境下用户可信行为的识别方法 |
| CN104159225A (zh) * | 2014-09-02 | 2014-11-19 | 解芳 | 一种基于无线网络的实名制管理方法及系统 |
| CN105100029A (zh) * | 2014-05-22 | 2015-11-25 | 阿里巴巴集团控股有限公司 | 对用户进行身份验证的方法和装置 |
| CN106453209A (zh) * | 2015-08-07 | 2017-02-22 | 阿里巴巴集团控股有限公司 | 一种身份验证方法和装置 |
| CN106549902A (zh) * | 2015-09-16 | 2017-03-29 | 阿里巴巴集团控股有限公司 | 一种可疑用户的识别方法及设备 |
| CN107846393A (zh) * | 2017-09-11 | 2018-03-27 | 阿里巴巴集团控股有限公司 | 实人认证方法及装置 |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060074798A1 (en) * | 2004-09-27 | 2006-04-06 | Din Khaja M | Financial instrument, system, and method for electronic commerce transactions |
| US20150089007A1 (en) * | 2008-12-12 | 2015-03-26 | At&T Intellectual Property I, L.P. | E-mail handling based on a behavioral history |
| CN102647430A (zh) * | 2012-05-09 | 2012-08-22 | 司文 | 一种隐藏身份信息的实名制认证系统和方法 |
| CN105099675B (zh) * | 2014-04-17 | 2019-06-07 | 阿里巴巴集团控股有限公司 | 生成用于身份验证的验证数据和身份验证的方法和装置 |
| TWI539323B (zh) * | 2014-10-06 | 2016-06-21 | Chunghwa Telecom Co Ltd | Personal data inventory system and method |
| CN106850624A (zh) * | 2017-02-07 | 2017-06-13 | 四川研宝科技有限公司 | 一种基于用户账户余额的社交方法及服务器 |
-
2017
- 2017-09-11 CN CN201710814013.6A patent/CN107846393B/zh active Active
-
2018
- 2018-05-28 TW TW107118128A patent/TWI695288B/zh not_active IP Right Cessation
- 2018-09-06 WO PCT/CN2018/104273 patent/WO2019047880A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103944722A (zh) * | 2014-04-17 | 2014-07-23 | 华北科技学院 | 一种互联网环境下用户可信行为的识别方法 |
| CN105100029A (zh) * | 2014-05-22 | 2015-11-25 | 阿里巴巴集团控股有限公司 | 对用户进行身份验证的方法和装置 |
| CN104159225A (zh) * | 2014-09-02 | 2014-11-19 | 解芳 | 一种基于无线网络的实名制管理方法及系统 |
| CN106453209A (zh) * | 2015-08-07 | 2017-02-22 | 阿里巴巴集团控股有限公司 | 一种身份验证方法和装置 |
| CN106549902A (zh) * | 2015-09-16 | 2017-03-29 | 阿里巴巴集团控股有限公司 | 一种可疑用户的识别方法及设备 |
| CN107846393A (zh) * | 2017-09-11 | 2018-03-27 | 阿里巴巴集团控股有限公司 | 实人认证方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN107846393B (zh) | 2020-01-14 |
| TWI695288B (zh) | 2020-06-01 |
| CN107846393A (zh) | 2018-03-27 |
| TW201913433A (zh) | 2019-04-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US12406263B2 (en) | Fraud detection system, method, and device | |
| CA2945703C (en) | Systems, apparatus and methods for improved authentication | |
| CN111819555B (zh) | 利用在线认证的安全远程令牌发布 | |
| US9235695B2 (en) | Alias-based social media identity verification | |
| US20210287225A1 (en) | Method, device and system for information verification | |
| US8914645B2 (en) | Systems and methods for identifying biometric information as trusted and authenticating persons using trusted biometric information | |
| US20180060868A1 (en) | Systems and methods for remote verification of users | |
| US20120150748A1 (en) | System and method for authenticating transactions through a mobile device | |
| US8572398B1 (en) | Systems and methods for identifying biometric information as trusted and authenticating persons using trusted biometric information | |
| WO2015062236A1 (en) | Method, device and system for information verification | |
| US10489565B2 (en) | Compromise alert and reissuance | |
| US20150006399A1 (en) | Social Media Based Identity Verification | |
| JP6707607B2 (ja) | 個人クラウドプラットフォームを用いてオンラインユーザ認証を強化するシステム及び方法 | |
| US20150206147A1 (en) | Dynamic Security Code | |
| WO2019047880A1 (zh) | 实人认证方法及装置 | |
| JP5688127B2 (ja) | 行動パターン認証による振込処理システムおよび方法 | |
| WO2015138976A2 (en) | Dynamic security code | |
| HK1249811B (zh) | 实人认证方法及装置 | |
| CN116976891B (zh) | 一种金融数据安全管理系统、装置及其方法 | |
| HK1249811A1 (zh) | 实人认证方法及装置 | |
| HK1240374B (zh) | 一种认证交易的方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18855016 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 18855016 Country of ref document: EP Kind code of ref document: A1 |