WO2021135170A1 - 一种数据处理方法、装置与系统 - Google Patents

一种数据处理方法、装置与系统 Download PDF

Info

Publication number
WO2021135170A1
WO2021135170A1 PCT/CN2020/103112 CN2020103112W WO2021135170A1 WO 2021135170 A1 WO2021135170 A1 WO 2021135170A1 CN 2020103112 W CN2020103112 W CN 2020103112W WO 2021135170 A1 WO2021135170 A1 WO 2021135170A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
biometric information
target
registered
biometric
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/103112
Other languages
English (en)
French (fr)
Inventor
陈煜�
周继恩
吕伊蒙
何磊
高原
傅宜生
胡修峰
李龙超
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Priority to US17/624,983 priority Critical patent/US11599882B2/en
Priority to SG11202112580YA priority patent/SG11202112580YA/en
Publication of WO2021135170A1 publication Critical patent/WO2021135170A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/10Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
    • G06Q20/102Bill distribution or payments
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/20Point-of-sale [POS] network systems
    • G06Q20/202Interconnection or interaction of plural electronic cash registers [ECR] or to host computer, e.g. network details, transfer of information from host to ECR or from ECR to ECR
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/30Payment architectures, schemes or protocols characterised by the use of specific devices or networks
    • G06Q20/34Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
    • G06Q20/341Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3821Electronic credentials
    • G06Q20/38215Use of certificates or encrypted proofs of transaction rights
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3823Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3825Use of electronic signatures
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/382Payment protocols; Details thereof insuring higher security of transaction
    • G06Q20/3827Use of message hashing
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/385Payment protocols; Details thereof using an alias or single-use codes
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4012Verifying personal identification numbers [PIN]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/38Payment protocols; Details thereof
    • G06Q20/40Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
    • G06Q20/401Transaction verification
    • G06Q20/4014Identity check for transactions
    • G06Q20/40145Biometric identity checks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0807Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan

Definitions

  • the present invention relates to the field of data processing technology, in particular to a data processing method, device and system.
  • the method of 1:1 comparison is generally used for biometric identification.
  • the accepting terminal can collect the user’s face information and mobile phone number, and find the user’s face information entered during registration through the mobile phone number.
  • the collected face information of the user and the face information entered during the user registration are compared and verified to determine whether it is the same person's face. If the verification is passed, the payment can be made through the bank card bound to the user.
  • This application provides a data processing method, device, and system to improve the security and accuracy in the data processing process.
  • the present invention provides a data processing method, which includes:
  • the identifying the registered biometric information matching the target biometric information from the registered biometric information of a plurality of objects includes:
  • partition biometric information from the registered biometric information of a plurality of objects; wherein the partition biometric information is the registered biometric information stored in association with the verification password information;
  • the auxiliary recognition algorithm is used to verify the recognition result of the main recognition algorithm.
  • the identifying registered biometric information matching the target biometric information from the partition biometric information includes:
  • an algorithm is used to select sub-division biometric information from the sub-division biometric information, and identify the target biometric information from the sub-division biometric information. Matching registered biometric information.
  • the method further includes:
  • step of recognizing the registered biometric information matching the target biometric information fails to execute, send a recognition failure response to the terminal through the acquirer server, so that the terminal displays a prompt for inputting identification auxiliary information;
  • auxiliary identification information forwarded by the acquirer server, where the auxiliary identification information is sent by the terminal to the acquirer server in response to a user's operation;
  • the method before sending the data processing request to the card issuer server corresponding to the target account information, the method further includes:
  • the method before the receiving target biometric information and verification password information of the target object, the method further includes:
  • routing index information is generated by calculating the verification password information using an irreversible algorithm
  • the encrypted routing index information, the registered biometric information and the registered account information are stored in association.
  • the associating and storing the encrypted routing index information, the registered biometric information, and the registered account information includes:
  • the determining the target account information of the target object includes:
  • the method further includes:
  • the biometric information includes one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information, palmprint information, finger vein information, palm vein information.
  • the present invention provides a data processing device, which includes:
  • the transceiver unit is used to receive the target biometric information and verification password information of the target object sent by the acquiring institution server;
  • An identification unit configured to identify the registered biometric information matching the target biometric information from the registered biometric information of multiple objects, and the registered biometric information of the same object is stored in association with the account information;
  • the determining unit determines the target account information of the target object according to the recognized registered biometric information
  • the transceiver unit is further configured to send a data processing request to the card issuer server corresponding to the target account information, and the data processing request includes the target account information and the verification password information, so that the card issuer server
  • the verification password information is used for verification, and data processing is performed according to the target account information after the verification is passed.
  • the identification unit is specifically configured to:
  • partition biometric information from the registered biometric information of a plurality of objects; wherein the partition biometric information is the registered biometric information stored in association with the verification password information;
  • the auxiliary recognition algorithm is used to verify the recognition result of the main recognition algorithm.
  • the identification unit is specifically configured to:
  • an algorithm is used to select sub-division biometric information from the sub-division biometric information, and identify the target biometric information from the sub-division biometric information. Matching registered biometric information.
  • the transceiving unit is further configured to: if the step of identifying registered biometric information matching the target biometric information fails, send the identification to the terminal through the acquirer server Failure response, so that the terminal displays a prompt for inputting identification auxiliary information; receiving identification auxiliary information forwarded by the acquirer server, the identification auxiliary information is the terminal responding to the user's operation to the acquirer server Sent
  • the identification unit is further configured to use the identification auxiliary information to determine the registered biometric information corresponding to the identification auxiliary information from the sub-division biometric information; from the identification auxiliary information corresponding to the The registered biometric information that matches the target biometric information is identified in the registered biometric information.
  • the transceiver unit is further configured to:
  • a registration unit is further included for:
  • routing index information is generated by calculating the verification password information using an irreversible algorithm
  • the encrypted routing index information, the registered biometric information and the registered account information are stored in association.
  • the registration unit is specifically configured to mark the registered account information to obtain Tokend information; combine the encrypted routing index information, the registered biometric information and the Tokend information Associative storage
  • the determining unit is further configured to determine Tokent information corresponding to the target biometric information; convert the Tokend information into Tokent information;
  • the transceiver unit is further configured to send the token information to the terminal.
  • the biometric information includes one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information, palmprint information, finger vein information, palm vein information.
  • the present invention also provides an electronic device, including:
  • At least one processor and,
  • a memory communicatively connected with the at least one processor; wherein,
  • the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the foregoing method.
  • the present invention also provides a non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium storing computer instructions, and the computer instructions are used to make the computer execute the above method.
  • the present invention also provides a data processing system, including an acquirer server, a biometric identification server, and a card issuer server;
  • the acquiring institution server is configured to receive the target biometric information and verification password information of the target object sent by the terminal; send the target biometric information and the verification password information to the biometric identification server;
  • the biometric identification server is configured to receive the target biometric information and the verification password information sent by the acquirer server; from the registered biometric information of multiple objects, identify the target biometric information.
  • Information matching registered biometric information the registered biometric information of the same object is stored in association with the account information; the target account information of the target object is determined according to the recognized registered biometric information; the card is issued to the corresponding target account information
  • the organization server sends a data processing request, the data processing request includes the target account information and the verification password information;
  • the card issuer server is configured to receive the data processing request; use the verification password information for verification and perform data processing according to the target account information after the verification is passed.
  • the acquiring institution server forwards the target biometric information and verification password information to the biometric identification server.
  • the biometric identification server recognizes the registered biometric information matching the target biometric information from the stored registered biometric information of the multiple objects, and determines the target account information of the target object based on the recognized registered biometric information.
  • the biometric identification server then sends a data processing request to the card issuer server corresponding to the target account information, where the data processing request includes the target account information and verification password information.
  • the card issuer server uses the verification password information for verification, and performs data processing based on the target account information after the verification is passed.
  • the target biometric information is used to match the registered biometric information of the target object from the registered biometric information of multiple objects, and further determine the target account information of the target object.
  • the target biometric information is actually As a routing identifier, it can serve as a routing index for account information.
  • this solution actually includes a process of verifying the target biometric information.
  • this method not only uses target biometric information to verify the target object, but also uses verification password information to verify the target object. By combining password verification with biometric identification, it can broaden the scope of application and help increase The accuracy and security of the data.
  • this method can also build an interconnected data processing security system, which helps to achieve algorithm interoperability and break the isolation of biometric identification between different institutions.
  • FIG. 1 is an architecture diagram of a data processing system provided by an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a data processing method provided by an embodiment of the present invention.
  • FIG. 3 is a schematic diagram of a multi-algorithm platform provided by an embodiment of the present invention.
  • FIG. 4 is a schematic diagram of a process for determining target account information according to an embodiment of the present invention.
  • Figure 5 is a schematic diagram of a data flow provided by an embodiment of the present invention.
  • Figure 6 is a schematic diagram of a registration process provided by an embodiment of the present invention.
  • FIG. 7 is a schematic diagram of the registration process in the first embodiment of the present invention.
  • FIG. 8 is a schematic diagram of the payment process in the second embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of a data processing device provided by an embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention.
  • the data processing system includes an acceptance terminal 101, an acquiring system 102, a clearing system (ie, a forwarding clearing system) 103, and Card issuing system (ie, issuing bank business system) 104.
  • the acceptance terminal 101 is installed by the acquiring system 102 for a special merchant, and may be a POS (point of sale, point of sale) machine, a card reader and other equipment.
  • the clearing system 103 includes a biometric identification module, which may be integrated in the clearing system server or a separate server.
  • the acquiring system 102, and/or the clearing system 103, and/or the card issuing system 104 may be network devices such as computers.
  • the acquiring system 102, and/or the clearing system 103, and/or the card issuing system 104 may be an independent device or a server cluster formed by multiple servers.
  • the acquiring system 102, and/or the clearing system 103, and/or the card issuing system 104 may use cloud computing technology for information processing.
  • the acceptance terminal 101 and the acquiring system 102, and/or between the acquiring system 102 and the clearing system 103, and/or between the clearing system 103 and the card issuing system 104, are connected through a wired or wireless network.
  • the aforementioned wireless network or wired network uses standard communication technologies and/or protocols.
  • the network is usually the Internet, but it can also be any network, including but not limited to Local Area Network (LAN), Metropolitan Area Network (MAN), Wide Area Network (WAN), mobile, wired or wireless Network, private network or any combination of virtual private network).
  • technologies and/or formats including HyperText Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged over the network.
  • SSL Secure Socket Layer
  • TLS Transport Layer Security
  • VPN Virtual Private Network
  • IPsec Internet Protocol Security
  • customized and/or dedicated data communication technologies can also be used to replace or supplement the aforementioned data communication technologies.
  • the system that uses biometrics to make transaction payments is generally a three-party model, that is, including the merchant's acceptance terminal, the acquiring system, and the issuing bank business system.
  • the acquiring system forwards the biometric information collected by the accepting terminal to the card issuing bank business system, and the card issuing bank business system compares the received biometric information with the stored biometric information. If the two match, the transaction payment is considered to be initiated
  • the user and the registrant are the same user and can be processed.
  • the biometric information is similar to the traditional verification password, which is used as a verification identifier for 1:1 identification.
  • the payment application based on biometric technology supported by it is closed, and different banks cannot be connected to the Internet for general use.
  • biometric information only using biometric information as a verification identifier will result in low verification security and accuracy, and the security and accuracy need to be further improved.
  • an embodiment of the present invention provides a data processing method.
  • the data processing method provided by the embodiment of the present invention includes the following steps:
  • Step 201 The acquiring institution server receives the target biometric information and verification password information of the target object sent by the terminal.
  • the terminal here is generally the acceptance terminal deployed in the merchant, such as POS machines, card readers and other equipment.
  • the acceptance terminal is installed with a client supported by the acquirer and can establish a security with the acquirer server. Communication link.
  • the acceptance terminal is also integrated with a biometric collection module, such as a camera, a fingerprint collector, etc., to collect the user's biometric information.
  • the verification password information may be a payment password entered by the user when paying, and the payment password may be numbers, letters, or character data that is a mixture of numbers and letters, or other types of data.
  • the acceptance terminal may display reminder information to the user, prompting the user to input biometric information and verification password information.
  • Step 202 The acquiring institution server sends the target biometric information and the verification password information to the biometric identification server.
  • Step 203 The biometric identification server recognizes the registered biometric information that matches the target biometric information from the registered biometric information of the multiple objects. Among them, the registered biometric information of the same object is stored in association with the account information.
  • the registered biometric information is stored in a biometric database.
  • the biometric database can be integrated in the biometric identification server, or it can be a separate device, and the biometric identification server can establish a link with it to obtain data from it.
  • the registered biometric information pre-stored in the biometric database may be the biometric information entered by the user when registering with the card issuer through an APP supported by the card issuer.
  • the card issuer server is connected to the biometric database, and the registration information is synchronized to the biometric database.
  • the user can also register through an APP supported by the clearing institution, so that the biometric identification server can directly obtain the user's registration information, and the registration information contains the user's biometric information.
  • the clearing institution server synchronizes the registration information to the card issuer server.
  • the biometric database may be connected to the servers of multiple card issuers, that is, the biometric database stores registered biometric information of multiple card issuers, and each registered biometric information corresponds to a user.
  • the biometric identification server may compare the received target biometric information with multiple registered biometric information stored in the database according to the algorithm model, and if a registered biometric matching the target biometric information is identified
  • the characteristic information indicates that the target biological characteristic information and the recognized registered biological characteristic information are the biological characteristic information of the same user. Therefore, the target biometric information in the embodiment of the present invention can not only play the role of route identification, but also play the role of verifying the user's identity.
  • Step 204 The biometric identification server determines the target account information of the target object according to the recognized registered biometric information.
  • the user's registered biometric information can be stored in the biometric database, and the two are stored in association.
  • the account information here includes the user's bank card Token (token) information, mobile phone identification information, bank card identification information, and so on.
  • the account information of the same user is stored in association with the biometric information.
  • the biometric identification server After the biometric identification server recognizes the registered biometric information that matches the target biometric information, it can determine the user's account information, that is, the target account information, based on the association.
  • Step 205 The biometric identification server sends a data processing request to the card issuer server corresponding to the target account information, where the data processing request includes the target account information and the verification password information.
  • the biometric server after the biometric server obtains the target account information, it can determine the card issuer server corresponding to the target account information, and send a data processing request to the card issuer server.
  • the data processing request can be generated and generated by the biometric server.
  • the sending may also be that the biometric identification server receives the acceptance terminal and sends it through the acquirer server. At this time, the data processing request is generated by the acceptance terminal according to the target account information fed back by the biometric identification server.
  • Step 206 The card issuer server uses the verification password information for verification and performs data processing according to the target account information after the verification is passed.
  • the card issuer server verifies the user's identity according to the received verification password information, and performs data processing after the verification is passed. Since the card issuer server does not need to identify the user’s biometric information, the card issuer server does not need to install a module based on biometric technology, but directly verifies the verification password information.
  • the biometric identification process is performed by the biometric server Just execute it, so that the requirement for the card issuer server connected to the system is lower, that is, when the card issuer server requires to join the system, it does not need to be equipped with a biometric identification related module.
  • all card issuer servers that support different biometric identification technologies can also be connected to the data processing system in the embodiment of the present invention. This method breaks the isolation between different algorithms and can achieve the universal purpose of networking.
  • the target biometric information is used to match the registered biometric information of the target object from the registered biometric information of multiple objects, and further determine the target account information of the target object.
  • the target biometrics The information can actually be used as a routing identifier, playing the role of an account information routing index.
  • this method also includes a process of verifying the target biometric information.
  • this method not only uses the target biometric information to verify the target object, but also uses the verification password information to verify the target object. By combining password verification with biometric identification, it can broaden the scope of application and help increase The accuracy and security of the data.
  • the data processing security system in the embodiment of the present invention is interconnected, can realize algorithm interoperability, and break the biometric identification isolation between different institutions.
  • the biometric database can be connected to multiple card issuer servers, the biometric database can store user information of multiple card issuers at the same time.
  • the registered biometric information stored in the biometric database The number is huge. Therefore, if the registered biometric information matching the target biometric information is directly identified in the massive data, on the one hand, the amount of calculation will be huge, and on the other hand, the accuracy of the recognition result may be low.
  • the verification password information can be used to narrow the identification range of the target biometric information. That is, in the above step 202, identifying registered biometric information matching the target biometric information from the registered biometric information of multiple objects may specifically include the following steps:
  • partition biometric information from the registered biometric information of a plurality of objects; wherein the partition biometric information is the registered biometric information stored in association with the verification password information;
  • the auxiliary recognition algorithm is used to verify the recognition result of the main recognition algorithm.
  • the partitioned biometric information does not mean that the registered biometric information must be completely partitioned, but it indicates that the registered biometric information is stored in association with the verification password information, that is, the registered biometric information can be partitioned Storage can also be stored without partition.
  • the registered biometric information is not stored in a partition on the hard disk, but after being read into the redis, it is stored in the redis in a partitioned manner.
  • the specific partitioning method may be partitioning according to the corresponding verification password information. Due to the large number of registered biometric information, for simpler verification password information, there may be multiple registered biometric information corresponding to the same verification password information. For example, a general bank card payment password is set to 6 digits.
  • the payment password 123456 corresponds to M biological characteristics information.
  • the verification password information can be used for indexing, and the N registered biometric information can be divided into multiple subsets. Each subset contains multiple registered biometric information.
  • the centralized registered biometric information corresponds to a verification password information.
  • the biometric identification server receives the user's payment password as 123456, and then determines the M partition biometric information corresponding to the payment password 123456 from the N registered biometric information in the biometric database, and then The biometric information of the M partitions is compared with the target biometric information, and the registered biometric information matching the target biometric information is identified.
  • the registered biometric information compared with the target biometric information is reduced from N to M, the amount of recognition calculation can be greatly reduced, and the success rate and accuracy of recognition can be increased.
  • the above embodiment uses algorithms to perform biometric identification, but there is no restriction on which algorithm is used.
  • a set of multi-algorithm platform can be provided, and a unified identification interface can be provided for the upper layer to call.
  • the multi-algorithm platform is configured with a variety of different identification algorithms. For the partition biometric information corresponding to different verification password information, different identification algorithms can be selected for identification calculation. For the partition biological information corresponding to the same verification password information, a main recognition algorithm and an auxiliary recognition algorithm can be selected to provide more accurate recognition results.
  • the main recognition algorithm and auxiliary recognition algorithm of the corresponding partition biometric information configuration When obtaining a verification password information, first determine the main recognition algorithm and auxiliary recognition algorithm of the corresponding partition biometric information configuration, and then use the main recognition algorithm to perform 1:M recognition calculations on the partition biometric information, and then use the partition biometric information Identify the registered biometric information that matches the target biometric information. After the recognition result is obtained, the auxiliary recognition algorithm is used to identify and verify the obtained recognition result and the target biometric information to determine the accuracy of the result. If the two conclusions are inconsistent, the registered biometric information recognized by the main recognition algorithm can still be used as the final recognition result, but a response with inconsistent results needs to be recorded and fed back to the receiving terminal.
  • the recognition error rate of the main recognition algorithm can be analyzed based on the inconsistency of the results recorded in the historical time period, so that an algorithm with a smaller error rate and better effect can be subsequently selected as the main recognition algorithm.
  • Fig. 3 shows a schematic diagram of a multi-algorithm platform provided by an embodiment of the present invention.
  • the biometric database includes partition 1, partition 2, partition 3, partition K, partition R, and partition T, where any partition contains multiple registered biometric data.
  • Algorithm A, Algorithm B, Algorithm C...Algorithm N and other recognition algorithms are integrated in the multi-algorithm platform.
  • the algorithm configuration is that partition 1 and partition 2 use algorithm A as the primary algorithm, and algorithm B as the secondary algorithm; partition 3 uses algorithm C as the primary algorithm and algorithm D as the secondary algorithm; partition K, partition R, and partition T use algorithm N as the primary algorithm.
  • Algorithm, algorithm M as a sub-algorithm.
  • the biometric server receives the verification password information 5678 and determines that the corresponding partition is K, then the main algorithm N is used to perform feature recognition calculations on the target biometric information and the registered biometric information in the partition K, and after obtaining the recognition result, use The sub-algorithm M performs identification verification on the identification result.
  • an algorithm is used to select sub-division biometric information from the sub-division biometric information, and identify the target biometric information from the sub-division biometric information. Matching registered biometric information.
  • the number of partition biometric information After determining the partition biometric information corresponding to the verification password information from all registered biometric information, it is also necessary to determine the number of partition biometric information, and compare the number of partition biometric information with the quantity threshold. For example, if there are P partition biometric information and the number threshold is 500, then P will be compared with 500. If P is less than 500, then P partition biometric information will be directly compared with the target biometric information to find the target The registered biometric information that matches the biometric information; if P is greater than or equal to 500, it indicates that the number of partition biometric information is still large, and the recognition range needs to be further reduced.
  • the LRU (Least Recently Used) algorithm can be used to select a part of the biometric information of the sub-region as the biometric information of the sub-region. For example, Q selected from P partition biometric information as the sub-region biometric information, where Q ⁇ P. Then compare the biometric information of the P sub-regions with the target biometric information, and identify the registered biometric information that matches the target biometric information.
  • the correspondence between the verification password information and the registered biometric information is used to determine the registered biometric information matching the target biometric information, which can narrow the range of biometric identification, greatly reduce the amount of identification calculation, and increase the identification success rate.
  • the process of identifying the registered biometric information that matches the target biometric information may still fail.
  • the step of recognizing the registered biometric information matching the target biometric information fails to execute (that is, it does not occur in the registered biometric information matching the target biometric information)
  • the single-institution server sends an identification failure response to the terminal, so that the terminal displays a prompt for inputting identification auxiliary information.
  • auxiliary identification information forwarded by the acquirer server, where the auxiliary identification information is sent by the terminal to the acquirer server in response to a user's operation;
  • the identification auxiliary information may be the last four digits of the user's mobile phone number, the first six digits of the ID number, and so on.
  • the identification auxiliary information corresponds to multiple registered biometric information. If an algorithm is used to select the biometric information of the sub-region from the biometric information of the sub-region, and the number of biometric information of the sub-region obtained is still large, the registered biometric information that matches the target biometric information still cannot be identified .
  • the identification auxiliary information can be further used to find the registered biometric information corresponding to the identification auxiliary information from the sub-division biometric information corresponding to the verification password information, so as to narrow down the identification by using the verification password information and algorithms.
  • the recognition auxiliary information is used to further narrow the recognition range, thereby increasing the success rate of recognition.
  • the biometric recognition server sends a feedback of the recognition failure to the accepting terminal through the acquirer server, and the accepting terminal prompts the user to enter the last 4 digits of the mobile phone number as identification auxiliary information, thereby further narrowing the scope of identification.
  • FIG 4 shows the process in which the biometric server determines the target account information.
  • the face image received by the biometric service is a live photo of user P
  • the payment password is 217384
  • the target biometric information is the live photo
  • the payment password is calculated by an irreversible algorithm and converted to the security code 2ac59075b9 .
  • the face routing library stores N face images
  • the P face image corresponding to the security code 2ac59075b9 is determined from the N face images. Compare P with the number preset 500, if P ⁇ 500, then directly perform face recognition on the received live photo and P stored face images, and identify the face image of user A from the face image of P , And then obtain user A's bank card Token.
  • the LRU algorithm is used to select Q face images to form a subset library. Compare the face image of Q with the received live photos. If the recognition is successful, the face image of user A is obtained, and then the bank card Token of user A is obtained. If the recognition fails, the last 4 digits of the user's mobile phone number are obtained to further narrow the recognition range, and the face image of user A is obtained, and then the bank card Token of user A is obtained.
  • the entire transaction can be split into an identification process and a data processing process.
  • the biometric identification server sends a data processing request to the card issuer server corresponding to the target account information, the method further includes:
  • the accepting terminal can send two requests, one is an identification request and the other is a payment request.
  • the accepting terminal in response to the user's operation, the accepting terminal first generates an identification request, and sends the identification request to the biometric identification server through the acquirer server.
  • the identification request contains the user's target biometric information and verification password information.
  • the acceptance terminal After that, the acceptance terminal generates a payment request after receiving the target account information sent by the biometric identification server, and sends the payment request to the card issuer server through the acquirer server and the biometric identification server.
  • the payment request includes target account information and verification password information.
  • the biometric identification server may be a server in a clearing institution.
  • the clearing institution server is connected to the card issuer server and synchronizes the data in the card issuer server. Therefore, this system structure and the processing method of two requests for one transaction are more changes to the existing system. Small, it can make full use of the existing system resources, and can be arbitrarily superimposed on the existing data processing types, such as transfer, cash withdrawal, pre-authorization and other types of transactions, without modification.
  • Fig. 5 shows a schematic diagram of a data flow provided by an embodiment of the present invention.
  • the accepting terminal after receiving the user's face image and payment password through step 1, the accepting terminal sends the face image and payment password to the face routing gateway in the clearing institution through step 2.
  • the face routing gateway determines the user's bank card number from the face routing database, it sends back the bank card number Token to the accepting terminal through step 3.
  • the accepting terminal passes step 4, forwards it through the acquiring system and the transfer clearing system, and sends a payment request to the card issuing bank business system.
  • the card-issuing banking business system completes the processing, it sends feedback to the transfer clearing system, the acquiring system, and the acceptance terminal through step 5.
  • the receiving terminal sends two requests based on user operations.
  • the user only needs to input his face image and payment password at the beginning, and the user does not need to perceive the middle process. In this way, even if the receiving terminal sends After two requests, the user's operation can be more concise.
  • biometric identification server receives the target biometric information and the verification password information of the target object, it further includes:
  • routing index information is generated by calculating the verification password information using an irreversible algorithm
  • the encrypted routing index information, the registered biometric information, and the registered account information are associated and stored in a partition corresponding to the routing index information.
  • the user can register through the APP of the card issuing institution, or the APP of the clearing institution (such as the card organization), or the third-party APP.
  • the user registers, he obtains the registered account information, the registered biometric information and the verification password information.
  • the card issuer server When a user registers through the card issuer APP, the card issuer server obtains the user's account information, facial image, payment password and other registration information, stores the above-mentioned registration information in association, and synchronizes the above-mentioned registration information with the biometric identification server.
  • the biometric identification server obtains the user's account information, face image, payment password and other registration information, stores the above-mentioned registration information in association, and synchronizes the above-mentioned registration information with the card issuer server.
  • the card issuer server uses an irreversible algorithm to calculate the verification password information to generate routing index information, and then register the account information .
  • the registered biometric information and routing index information are synchronized to the biometric identification server.
  • the biometric identification server adds salt and encryption to the routing index information of each user to ensure information security.
  • Salting encryption is a way of encrypting data.
  • the specific implementation is to associate each piece of data with an n-bit random number called "salt" and then encrypt it together. Whenever the data changes, the random number changes. The random number is stored in the file in an unencrypted manner, and the encrypted result is also stored in the file.
  • the irreversible algorithm can be SM3, SHA-256, etc.
  • Fig. 6 shows a registration process provided by an embodiment of the present invention.
  • the user sets the payment password in the card issuing bank APP.
  • the issuing bank business system uses irreversible calculations to calculate the payment password into a face payment security code, which is then synchronized to the face routing platform.
  • the face routing platform adds a different salt to each face payment security code and stores it encrypted.
  • the "associative storage of the encrypted routing index information, the registered biometric information, and the registered account information" in the above content may specifically include:
  • the encrypted routing index information, the registered biometric information and the Tokend information are stored in association.
  • the determining the target account information of the target object includes:
  • the method further includes:
  • the account information in order to prevent the leakage of the user's account information, can be marked to generate Token information.
  • the card token Token information can be generated using a payment token service (Token Service Provider, TSP).
  • TSP is a basic security service for digital payment, which can provide services to banks, payment institutions, and industries. Agency payments provide security.
  • the payment marking service TSP replaces the traditional bank card number with a specific payment marking Token, which can effectively reduce the risk of card information leakage at the merchant and accepting institution side, and help reduce transaction fraud.
  • the bank card token Token information may include: bank information and information with part of the bank card number.
  • the token information of a bank card is: T Bank, 6666********1234.
  • part of the bank number in the Token information of the bank card is replaced by *.
  • the biometric identification server can use the routing index information as an index (as appropriate, combining the data tag, the last 4 digits of the mobile phone number, etc.) to generate Token information from the account information.
  • the Token information can be divided into Tokend (marked) information and Tokent (temporary mark) information.
  • the Tokend information is stored in a biometric database.
  • the biometric identification server tokenizes the Tokend information to generate Tokent information, and sends the Tokent information to the outside.
  • the Tokent information is only valid for a period of time, such as 3 minutes. In this way, the user's account information can be prevented from being leaked, and the security of the user's property can be improved.
  • the biometric information may include one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information, palmprint information, finger vein information, palm vein information.
  • the accepting device may also perform a living body detection on the user.
  • the living body detection is used to determine whether the collected biometric information comes from a living body.
  • the user may be required to blink his eyes, turn his head, open his mouth, etc. Through living body detection, it can prevent other users from using the user's photo to steal the user's bank card, and improve the security of the user's property.
  • FIG. 7 shows a schematic diagram of the registration process in the first embodiment. As shown in Figure 7, the process includes:
  • the user initiates an application for opening the face recognition offline payment service through the card-issuing bank APP, registers the face information, binds the bank card, and sets the payment password.
  • the card issuing bank business system completes user identity verification and synchronizes face routing information (routing index code, face information, bank card number/Token, last 4 digits of bank card number, last 4 digits of mobile phone number) to the face routing platform.
  • the face routing platform returns the synchronization result of the card issuing bank business system, and the card issuing bank business system returns the user registration opening result.
  • the user can modify the face photo, modify the payment password, and set the default payment card operation.
  • FIG. 8 shows a schematic diagram of the payment process in the second embodiment. As shown in Figure 8, the process includes:
  • the receiving terminal collects facial information and prompts the user to enter a payment password.
  • the receiving terminal transfers the face information and the ciphertext of the payment password to the face routing platform after being encrypted by the acquiring system.
  • the face routing platform After the face routing platform encrypts the ciphertext of the payment password into a routing index code, it recognizes it according to the face information, routing index code, etc., and then tokenizes the payment card number if the recognition is successful, and returns the payment token to the acceptance terminal.
  • the face routing platform returns the need to add auxiliary information, it returns the response code corresponding to the acquiring institution, and the terminal re-collects the last four digits of the mobile phone number and continues to send the identification transaction, and returns to the terminal after the identification is successful.
  • the accepting terminal initiates the transaction using the Token and the ciphertext of the payment password, and transmits the transaction instruction to the issuing bank business system through the acquiring system and the transfer clearing system.
  • the card issuing bank business system confirms the transaction according to the payment password and the biopsy result, and completes the payment transaction.
  • the embodiment of the present invention also provides a data processing device, as shown in FIG. 9, including:
  • the transceiver unit 901 is configured to receive target biometric information and verification password information of the target object sent by the acquiring institution server;
  • the identification unit 902 is configured to identify the registered biometric information matching the target biometric information from the registered biometric information of multiple objects, and the registered biometric information of the same object is stored in association with the account information;
  • the determining unit 903 determines the target account information of the target object according to the recognized registered biometric information
  • the transceiving unit 901 is further configured to send a data processing request to the card issuer server corresponding to the target account information, where the data processing request includes the target account information and the verification password information, so that the card issuer The server uses the verification password information for verification and performs data processing according to the target account information after the verification is passed.
  • the identification unit 902 is specifically configured to:
  • partition biometric information from the registered biometric information of a plurality of objects; wherein the partition biometric information is the registered biometric information stored in association with the verification password information;
  • the auxiliary recognition algorithm is used to verify the recognition result of the main recognition algorithm.
  • the identification unit 902 is specifically configured to:
  • an algorithm is used to select sub-division biometric information from the sub-division biometric information, and identify the target biometric information from the sub-division biometric information. Matching registered biometric information.
  • the transceiving unit 901 is further configured to: if the step of identifying registered biometric information matching the target biometric information fails, then send to the terminal through the acquirer server Recognition failure response, so that the terminal displays a prompt for inputting identification auxiliary information; receiving the identification auxiliary information forwarded by the acquiring institution server, the identification auxiliary information is the terminal responding to the user's operation to the acquiring institution Sent by the server
  • the identification unit 902 is further configured to use the identification auxiliary information to determine the registered biometric information corresponding to the identification auxiliary information from the sub-division biometric information; from the corresponding identification auxiliary information The registered biometric information that matches the target biometric information is identified in the registered biometric information.
  • the transceiver unit 901 is further configured to:
  • a registration unit 904 is further included, configured to:
  • routing index information is generated by calculating the verification password information using an irreversible algorithm
  • the encrypted routing index information, the registered biometric information and the registered account information are stored in association.
  • the registration unit 904 is specifically configured to mark the registered account information to obtain Tokend information; combine the encrypted routing index information, the registered biometric information and the Tokend information. Information related storage;
  • the determining unit 903 is further configured to determine Tokent information corresponding to the target biometric information; convert the Tokend information into Tokent information;
  • the transceiver unit 901 is further configured to send the token information to the terminal.
  • the biometric information includes one or more of the following items:
  • Face information Face information, fingerprint information, voiceprint information, iris information, palmprint information, finger vein information, palm vein information.
  • the present invention also provides an electronic device, as shown in FIG. 10, including:
  • It includes a processor 701, a memory 702, a transceiver 703, and a bus interface 704, wherein the processor 701, the memory 702 and the transceiver 703 are connected through the bus interface 704;
  • the processor 701 is configured to read a program in the memory 702 and execute the following method:
  • the present invention also provides a non-transitory computer-readable storage medium, the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to make a computer execute any one of FIGS. 1 to 8 The method described.
  • These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing equipment to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including the instruction device.
  • the device implements the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
  • These computer program instructions can also be loaded on a computer or other programmable data processing equipment, so that a series of operation steps are executed on the computer or other programmable equipment to produce computer-implemented processing, so as to execute on the computer or other programmable equipment.
  • the instructions provide steps for implementing the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.

Landscapes

  • Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Finance (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computing Systems (AREA)
  • Signal Processing (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Health & Medical Sciences (AREA)
  • Biomedical Technology (AREA)
  • General Health & Medical Sciences (AREA)
  • Economics (AREA)
  • Development Economics (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Collating Specific Patterns (AREA)
  • Measurement Of The Respiration, Hearing Ability, Form, And Blood Characteristics Of Living Organisms (AREA)

Abstract

一种数据处理方法、装置与系统,用以提高数据处理过程中的安全性和准确性。其中方法包括:接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息,从多个对象的注册生物特征信息中识别出与目标生物特征信息匹配的注册生物特征信息,根据识别出的注册生物特征信息,确定目标对象的目标账户信息,向目标账户信息对应的发卡机构服务器发送数据处理请求,数据处理请求中包含目标账户信息和验证密码信息,以使发卡机构服务器利用验证密码信息进行验证并在验证通过后根据目标账户信息进行数据处理。

Description

一种数据处理方法、装置与系统
相关申请的交叉引用
本申请要求在2019年12月31日提交中国专利局、申请号为201911419394.3、申请名称为“一种数据处理方法、装置与系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及数据处理技术领域,尤其涉及一种数据处理方法、装置与系统。
背景技术
近年来,人工智能领域的生物识别技术已经渗透到我们的日常生活。其中,由于人脸识别拥有识别速度快、精度高、设备普及率高等优点,已逐步成为生物特征识别中最为热门的技术。深度学习的应用与发展使得人脸识别通过率显著提升。以1:N(N为500时)的人脸辨识为例,在误识率万分之一的情况下,人脸识别通过率能够达到98.3%以上,该比例的识别通过率已达到金融应用级别。基于此,第三方支付公司以及银行业等,都开始将人脸应用于支付、取款等场景。
目前,一般采用1:1对比的方式进行生物识别,例如,在用户支付时,受理终端可以采集用户的人脸信息和手机号,通过手机号找到用户注册时输入的人脸信息,将本次采集的用户的人脸信息和用户注册时输入的人脸信息进行对比验证,判断是否为同一个人的脸,若验证通过,则可通过用户绑定的银行卡进行支付。
由此可知,现有技术在生物识别过程中,仅利用生物特征进行用户身份验证,其安全性和准确性有待进一步提高。
发明内容
本申请提供一种数据处理方法、装置与系统,用以提高数据处理过程中的安全性和准确性。
第一方面,本发明提供一种数据处理方法,该包括:
接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息;
从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;
根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;
向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息,以使所述发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
一种可选的实施例中,所述从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,包括:
从多个对象的注册生物特征信息中确定出分区生物特征信息;其中,所述分区生物特征信息为与所述验证密码信息关联存储的注册生物特征信息;
确定所述验证密码信息对应的主识别算法以及辅助识别算法;
利用所述主识别算法,从所述验证密码信息对应的所有分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
利用所述辅助识别算法对所述主识别算法的识别结果进行验证。
一种可选的实施例中,所述从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,包括:
将所述分区生物特征信息的信息数量与数量阈值对比;
若所述信息数量小于所述数量阈值,则执行从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤;
若所述信息数量大于或等于所述数量阈值,则利用算法从所述分区生物特征信息中选出子分区生物特征信息,从所述子分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
一种可选的实施例中,所述从多个对象的注册生物特征信息中确定出分区生物特征信息之后,还包括:
若所述识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤执行失败,则通过收单机构服务器向终端发送识别失败响应,以使所述终端显示输入识别辅助信息的提示;
接收所述收单机构服务器转发的识别辅助信息,所述识别辅助信息为所述终端响应于用户的操作向所述收单机构服务器发送的;
利用所述识别辅助信息,从所述子分区生物特征信息中,确定与所述识别辅助信息对应的注册生物特征信息;
从所述与所述识别辅助信息对应的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
一种可选的实施例中,所述向所述目标账户信息对应的发卡机构服务器发送数据处理请求之前,还包括:
通过收单机构服务器向终端发送所述目标账户信息,以使所述终端向所述收单机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
接收所述收单机构服务器转发的所述数据处理请求。
一种可选的实施例中,所述接收目标对象的目标生物特征信息和验证密码信息之前,还包括:
接收所述目标对象的注册账户信息、注册生物特征信息和路由索引信息,其中路由索引信息为利用不可逆算法将所述验证密码信息运算生成的;
将所述路由索引信息加盐加密处理;
将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储。
一种可选的实施例中,所述将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储,包括:
将所述注册账户信息进行标记处理,得到Tokend信息;
将加密后的路由索引信息、所述注册生物特征信息与所述Tokend信息关联存储;
所述确定所述目标对象的目标账户信息,包括:
确定与所述目标生物特征信息对应的Tokent信息;
将所述Tokend信息转换为Tokent信息;
所述确定所述目标对象的目标账户信息之后,还包括:
向所述终端发送所述Tokent信息。
一种可选的实施例中,所述生物特征信息包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息、掌纹信息、指静脉信息、掌静脉信息。
第二方面,本发明提供一种数据处理装置,该装置包括:
收发单元,用于接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息;
识别单元,用于从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;
确定单元,根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;
所述收发单元,还用于向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息,以使所述发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
一种可选的实施例中,所述识别单元,具体用于:
从多个对象的注册生物特征信息中确定出分区生物特征信息;其中,所述分区生物特征信息为与所述验证密码信息关联存储的注册生物特征信息;
确定所述验证密码信息对应的主识别算法以及辅助识别算法;
利用所述主识别算法,从所述验证密码信息对应的所有分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
利用所述辅助识别算法对所述主识别算法的识别结果进行验证。
一种可选的实施例中,所述识别单元,具体用于:
将所述分区生物特征信息的信息数量与数量阈值对比;
若所述信息数量小于所述数量阈值,则执行从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤;
若所述信息数量大于或等于所述数量阈值,则利用算法从所述分区生物特征信息中选出子分区生物特征信息,从所述子分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
一种可选的实施例中,所述收发单元,还用于若所述识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤执行失败,则通过收单机构服务器向终端发送识别失败响应,以使所述终端显示输入识别辅助信息的提示;接收所述收单机构服务器转发的识别辅助信息,所述识别辅助信息为所述终端响应于用户的操作向所述收单机构服务器发送的;
所述识别单元,还用于利用所述识别辅助信息,从所述子分区生物特征信息中,确定与所述识别辅助信息对应的注册生物特征信息;从所述与所述识别辅助信息对应的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
一种可选的实施例中,所述收发单元,还用于:
通过收单机构服务器向终端发送所述目标账户信息,以使所述终端向所述收单机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
接收所述收单机构服务器转发的所述数据处理请求。
一种可选的实施例中,还包括注册单元,用于:
接收所述目标对象的注册账户信息、注册生物特征信息和路由索引信息,其中路由索引信息为利用不可逆算法将所述验证密码信息运算生成的;
将所述路由索引信息加盐加密处理;
将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储。
一种可选的实施例中,所述注册单元,具体用于将所述注册账户信息进行标记处理,得到Tokend信息;将加密后的路由索引信息、所述注册生物特征信息与所述Tokend信息关联存储;
所述确定单元,还用于确定与所述目标生物特征信息对应的Tokent信息;将所述Tokend信息转换为Tokent信息;
所述收发单元,还用于向所述终端发送所述Tokent信息。
一种可选的实施例中,所述生物特征信息包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息、掌纹信息、指静脉信息、掌静脉信息。
第三方面,本发明还提供一种电子设备,包括:
至少一个处理器;以及,
与所述至少一个处理器通信连接的存储器;其中,
所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器能够执行上述方法。
第四方面,本发明还提供一种非暂态计算机可读存储介质,所述非暂态计算机可读存储介质存储计算机指令,所述计算机指令用于使所述计算机执行上述方法。
第五方面,本发明还提供一种数据处理系统,包括收单机构服务器、生物特征识别服务器和发卡机构服务器;
所述收单机构服务器,用于接收终端发送的目标对象的目标生物特征信 息和验证密码信息;将所述目标生物特征信息和所述验证密码信息向所述生物特征识别服务器发送;
所述生物特征识别服务器,用于接收所述收单机构服务器发送的所述目标生物特征信息和所述验证密码信息;从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
所述发卡机构服务器,用于接收所述数据处理请求;利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
本发明中,收单机构服务器接收受理终端发送的目标生物特征信息和验证密码信息后,将目标生物特征信息和验证密码信息转发给生物特征识别服务器。生物特征识别服务器从存储的多个对象的注册生物特征信息中,识别出与目标生物特征信息匹配的注册生物特征信息,并根据识别出的注册生物特征信息,确定目标对象的目标账户信息。之后生物特征识别服务器向目标账户信息对应的发卡机构服务器发送数据处理请求,其中,数据处理请求中包含目标账户信息和验证密码信息。发卡机构服务器利用验证密码信息进行验证,并在验证通过后根据目标账户信息进行数据处理。
在上述设计中,目标生物特征信息用于从多个对象的注册生物特征信息中,匹配出目标对象的注册生物特征信息,进一步确定出目标对象的目标账户信息,如此,目标生物特征信息实际上作为一种路由标识,能够起到账户信息路由索引的作用。且,由于在利用目标生物特征信息查找对应的目标账户信息的过程中,需要与多个注册生物特征信息进行对比,因此,该方案实际上也包含了对目标生物特征信息验证的过程。另一方面,该种方式不仅利用目标生物特征信息对目标对象进行验证,还利用验证密码信息对目标对象进行验证,通过将密码验证与生物特征识别结合起来,能够拓宽适用范围, 有助于增加数据的准确性和安全性。此外,该种方式还能够构建互联互通的数据处理安全体系,有助于实现算法互通,打破不同机构之间生物特征识别的隔离。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简要介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域的普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1为本发明实施例提供的一种数据处理系统架构图;
图2为本发明实施例提供的一种数据处理方法的流程示意图;
图3为本发明实施例提供的一种多算法平台的示意图;
图4为本发明实施例提供的一种确定出目标账户信息的过程示意图;
图5为本发明实施例提供的一种数据流向示意图;
图6为本发明实施例提供的一种注册流程示意图;
图7为本发明具体实施例一中注册流程示意图;
图8为本发明具体实施例二中支付流程示意图;
图9为本发明实施例提供的一种数据处理装置的结构示意图;
图10为本发明实施例提供的电子设备的结构示意图。
具体实施方式
为了使本发明的目的、技术方案和优点更加清楚,下面将结合附图对本发明作进一步地详细描述,显然,所描述的实施例仅仅是本发明一部份实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本发明保护的范围。
请参考图1,其示出了本申请一个实施例提供的数据处理系统的系统架构 图,该数据处理系统中包括受理终端101、收单系统102、清算系统(即转接清算系统)103和发卡系统(即发卡银行业务系统)104。其中,受理终端101是收单系统102为特约商户安装的,可以是POS(point of sale,销售终端)机、刷卡器等设备。清算系统103中包括生物识别模块,该生物识别模块可以是集成在清算系统服务器中,也可以是单独的服务器。
收单系统102,和/或,清算系统103,和/或,发卡系统104,可以是计算机等网络设备。收单系统102,和/或,清算系统103,和/或,发卡系统104,可以是一个独立的设备,也可以是多个服务器所形成的服务器集群。优选地,收单系统102,和/或,清算系统103,和/或,发卡系统104,可以采用云计算技术进行信息处理。
受理终端101与收单系统102之间,和/或,收单系统102与清算系统103之间,和/或,清算系统103与发卡系统104之间,通过有线或无线网络相连。
可选地,上述的无线网络或有线网络使用标准通信技术和/或协议。网络通常为因特网,但也可以是任何网络,包括但不限于局域网(Local Area Network,LAN)、城域网(Metropolitan Area Network,MAN)、广域网(Wide Area Network,WAN)、移动、有线或者无线网络、专用网络或者虚拟专用网络的任何组合)。在一些实施例中,使用包括超文本标记语言(Hyper Text Mark-up Language,HTML)、可扩展标记语言(Extensible Markup Language,XML)等的技术和/或格式来代表通过网络交换的数据。此外还可以使用诸如安全套接字层(Secure Socket Layer,SSL)、传输层安全(Transport Layer Security,TLS)、虚拟专用网络(Virtual Private Network,VPN)、网际协议安全(Internet Protocol Security,IPsec)等常规加密技术来加密所有或者一些链路。在另一些实施例中,还可以使用定制和/或专用数据通信技术取代或者补充上述数据通信技术。
需要注意的是,上文提及的应用场景仅是为了便于理解本申请的精神和原理而示出,本申请实施例在此方面不受任何限制。相反,本申请实施例可以应用于适用的任何场景。
现有技术中,利用生物识别技术进行交易支付的系统一般为三方模式,即包括商户的受理终端、收单系统和发卡银行业务系统。其中,收单系统向发卡银行业务系统转发受理终端采集的生物特征信息,发卡银行业务系统对接收到的生物特征信息和存储的生物特征信息进行对比,若两者匹配,则认为交易支付的发起者与注册者为同一用户,可以进行处理。这种方式下,生物特征信息类似于传统的验证密码,是作为验证标识进行1:1辨识的。针对发卡银行而言,其支持的基于生物识别技术的支付应用是封闭的,不同银行之间无法联网通用。另一方面,仅利用生物特征信息作为验证标识,会导致验证的安全性和准确性不高,安全性和准确性还有待进一步提高。
为了解决上述问题,基于如图1所示的数据处理系统,本发明实施例提供了一种数据处理方法,如图2所示,本发明实施例提供的数据处理方法包括以下步骤:
步骤201、收单机构服务器接收终端发送的目标对象的目标生物特征信息和验证密码信息。
具体实施过程中,这里的终端一般为商户中部署的受理终端,如POS机、刷卡器等设备,该受理终端中安装有收单机构支持的客户端,可以与收单机构服务器之间建立安全的通信链接。受理终端中还集成有生物特征采集模块,如摄像头、指纹采集器等,用于采集用户的生物特征信息。验证密码信息可以为用户支付时输入的支付口令,该支付口令可以为数字、字母,或者数字和字母混合的字符型数据,也可以为其它类型的数据。
示例性地,用户在交易支付时,受理终端可以向用户显示提醒信息,提示用户输入生物特征信息和验证密码信息。
步骤202、收单机构服务器将所述目标生物特征信息和所述验证密码信息向生物特征识别服务器发送。
步骤203、生物特征识别服务器从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息。其中,同一个对象的注册生物特征信息与账户信息关联存储。
具体实施过程中,注册生物特征信息存储在生物特征数据库中,该生物特征数据库可以集成在生物特征识别服务器中,也可以为单独的设备,生物特征识别服务器可以与之建立链接,从中获取数据。生物特征数据库中预存的注册生物特征信息,可以为用户通过发卡机构支持的APP向发卡机构注册时输入的生物特征信息。发卡机构服务器与生物特征数据库相连,将注册信息同步至生物特征数据库中。另一种可能的实施例中,用户也可以通过清算机构支持的APP进行注册,从而,生物特征识别服务器可以直接获取用户的注册信息,该注册信息中包含用户的生物特征信息。之后,清算机构服务器将注册信息同步至发卡机构服务器中。
示例性地,生物特征数据库可以与多个发卡机构的服务器相连,即生物特征数据库中存储了多个发卡机构的注册生物特征信息,每个注册生物特征信息对应一个用户。
本发明实施例中,生物特征识别服务器可以依据算法模型,将接收到的目标生物特征信息与数据库中存储的多个注册生物特征信息进行对比,若识别出与该目标生物特征信息匹配的注册生物特征信息,则表明目标生物特征信息与识别出的注册生物特征信息为同一个用户的生物特征信息。因此,本发明实施例中的目标生物特征信息不仅能够起到路由识别的作用,还能起到对用户身份进行验证的作用。
步骤204、生物特征识别服务器根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息。
具体实施过程中,生物特征数据库中不仅存储有用户的注册生物特征信息,还可以存储有用户的账户信息,两者关联存储。这里的账户信息包括用户的银行卡Token(令牌)信息、手机标识信息、银行卡标识信息等。同一个用户的账户信息与生物特征信息关联存储,生物特征识别服务器识别出与目标生物特征信息匹配的注册生物特征信息后,即可根据该关联确定出该用户的账户信息,即目标账户信息。
步骤205、生物特征识别服务器向所述目标账户信息对应的发卡机构服务 器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息。
具体实施过程中,生物特征识别服务器获取到目标账户信息后,可以确定目标账户信息对应的发卡机构服务器,并向该发卡机构服务器发送数据处理请求,该数据处理请求可以为生物特征识别服务器生成并发送的,也可以为生物特征识别服务器接收受理终端通过收单机构服务器发送的,则此时,数据处理请求为受理终端根据生物特征识别服务器反馈的目标账户信息生成。
步骤206、发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
具体实施过程中,发卡机构服务器根据接收到的验证密码信息对用户身份进行验证,并在验证通过后进行数据处理。由于发卡机构服务器无需对用户的生物特征信息进行辨识,因此,发卡机构服务器中可以无需安装基于生物特征识别技术的模块,而是直接对验证密码信息进行验证,生物特征识别过程由生物特征识别服务器执行即可,从而对连接入系统的发卡机构服务器的要求较低,即发卡机构服务器要求加入系统时,无需设置有生物特征识别相关的模块。另一方面,支持不同生物特征识别技术的发卡机构服务器也都可以连接入本发明实施例中的数据处理系统,这种方式打破了不同算法之间的隔离性,可以实现联网通用的目的。
本发明实施例中,目标生物特征信息用于从多个对象的注册生物特征信息中匹配出目标对象的注册生物特征信息,进一步确定出目标对象的目标账户信息,采用这种方式,目标生物特征信息实际上可以作为路由标识,起到账户信息路由索引的作用。且,由于在利用目标生物特征信息查找对应的目标账户信息的过程中,需要与多个注册生物特征信息进行对比,因此,这种方式也包含了对目标生物特征信息验证的过程。另一方面,这种方式不仅利用目标生物特征信息对目标对象进行验证,还利用验证密码信息对目标对象进行验证,通过将密码验证与生物特征识别结合起来,能够拓宽适用范围,有助于增加数据的准确性和安全性。此外,本发明实施例中的数据处理安全 体系是互联互通的,能够实现算法互通,打破不同机构之间生物特征识别的隔离。
本发明实施例中,由于生物特征数据库可以连接多个发卡机构服务器,因此,生物特征数据库中可以同时存储多个发卡机构的用户信息,这种情况下,生物特征数据库中存储的注册生物特征信息的数量是十分巨大的。因此,若直接在海量数据中识别与目标生物特征信息匹配的注册生物特征信息,则一方面会使得计算量十分巨大,另一方面还可能导致识别结果的准确性较低。为了解决该问题,在一种可选的实施例中,可以利用验证密码信息来缩小目标生物特征信息的识别范围。即,在上述步骤202中,从多个对象的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息,具体可以包括如下步骤:
从多个对象的注册生物特征信息中确定出分区生物特征信息;其中,所述分区生物特征信息为与所述验证密码信息关联存储的注册生物特征信息;
确定所述验证密码信息对应的主识别算法以及辅助识别算法;
利用所述主识别算法,从所述验证密码信息对应的所有分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
利用所述辅助识别算法对所述主识别算法的识别结果进行验证。
具体实施过程中,分区生物特征信息并不代表注册生物特征信息必须是完全分区存储的,而是表明注册生物特征信息是与验证密码信息关联存储的,也就是说,注册生物特征信息可以为分区存储,也可以不分区存储。一种可选的实现方式中,注册生物特征信息在硬盘中并不是分区存储,但是读入到redis中之后,是以分区的方式在redis中存储。具体的分区方式可以为按照对应的验证密码信息进行分区。由于注册生物特征信息的数量较多,因此,对于形式较为简单的验证密码信息,可能会存在多个注册生物特征信息对应于同一个验证密码信息。例如,一般银行卡支付密码设置为6位数字,对于同一种数字排列组合,例如123456,可能有M个用户选择123456作为其注册时输入的支付口令,则该支付口令123456对应有M个生物特征信息。若生物 特征数据库中总共存储有N个注册生物特征信息,则利用验证密码信息进行索引,可以将N个注册生物特征信息划分成多个子集,每个子集中包含多个注册生物特征信息,同一个子集中的注册生物特征信息与一个验证密码信息相对应。
这样,在支付交易时,生物特征识别服务器接收用户的支付口令为123456,则从生物特征数据库的N个注册生物特征信息中确定与该支付口令123456对应的M个分区生物特征信息,并将这M个分区生物特征信息与目标生物特征信息分别对比,识别出与目标生物特征信息匹配的注册生物特征信息。在此过程中,由于与目标生物特征信息相对比的注册生物特征信息由N个降到M个,因此能够大大减少识别计算量,有助于增加识别的成功率和准确性。
上述实施例利用算法进行生物特征识别,而对于具体使用哪种算法则不做限制。具体实施过程中,可以提供一套多算法平台,并提供统一的识别接口供上层调用,其中,多算法平台中配置有多种不同的识别算法。对于不同验证密码信息对应的分区生物特征信息,可以选择不同的识别算法进行识别计算。对于同一个验证密码信息对应的分区生物信息,可以选择一个主识别算法,以及一个辅助识别算法,以提供更精准的识别结果。当获取一个验证密码信息时,首先确定其对应的分区生物特征信息配置的主识别算法和辅助识别算,然后利用主识别算法对分区生物特征信息进行1:M的识别计算,从分区生物特征信息中识别出目标生物特征信息匹配的注册生物特征信息。得到识别结果后,再在利用辅助识别算法,将得到的识别结果与目标生物特征信息进行识别验证,判断结果的准确性。若两者结论不一致,则可以仍将主识别算法识别出的注册生物特征信息作为最终的识别结果,但需记录并向受理终端反馈结果不一致的响应。
可选的,可以依据历史时间段内记录的结果不一致的情况,分析主识别算法的识别失误率,以便于后续选择失误率更小、效果更优的算法作为主识别算法。
图3示出了本发明实施例提供的一种多算法平台的示意图。如图3所示, 生物特征数据库中包含分区1、分区2、分区3、分区K、分区R、分区T,其中,任一分区中包含有多个注册生物特征数据。多算法平台中集成了算法A、算法B、算法C……算法N等识别算法。算法配置为,分区1和分区2将算法A作为主算法,算法B作为次算法;分区3将算法C作为主算法,算法D作为次算法;分区K、分区R和分区T将算法N作为主算法,算法M作为次算法。若生物特征识别服务器接收到验证密码信息5678后,确定对应的分区为K,则利用主算法N对目标生物特征信息与分区K中的注册生物特征信息进行特征识别计算,得到识别结果后,利用次算法M对识别结果进行识别验证。
进一步地,若某验证密码信息对应的子集中,分区生物特征信息的个数仍然很大,则为了进一步减少计算量,降低计算机压力,上述内容中的“从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息”,具体可以包括:
将所述分区生物特征信息的信息数量与数量阈值进行对比;
若所述信息数量小于所述数量阈值,则执行从所述分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤;
若所述信息数量大于或等于所述数量阈值,则利用算法从所述分区生物特征信息中选出子分区生物特征信息,从所述子分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
具体实施过程中,从所有注册生物特征信息中确定出该验证密码信息对应的分区生物特征信息后,还需要确定分区生物特征信息的数量,并将分区生物特征信息的数量与数量阈值相对比。例如,若共有P个分区生物特征信息,数量阈值为500,则将P与500相对比,若P小于500,则直接将P个分区生物特征信息与目标生物特征信息相对比,找出与目标生物特征信息相匹配的注册生物特征信息;若P大于或等于500,则表明分区生物特征信息的数量仍较大,需要进一步缩小识别范围。具体可以利用LRU(Least Recently Used,最近最少使用)算法,再选出一部分分区生物特征信息作为子分区生物特征 信息。例如,从P个分区生物特征信息中选出Q个作为子分区生物特征信息,其中Q≤P。再将P个子分区生物特征信息与目标生物特征信息进行对比,识别出与目标生物特征信息匹配的注册生物特征信息。
本发明实施例中,利用验证密码信息与注册生物特征信息之间的对应关系确定目标生物特征信息匹配的注册生物特征信息,能够缩小生物识别范围,极大地减少识别计算量,增加识别成功率。
但是,若子分区生物特征信息的数量仍较多,则识别出与目标生物特征信息相匹配的注册生物特征信息的过程,仍存在失败的可能。本发明实施例中,若所述识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤执行失败(即不出在与目标生物特征信息匹配的注册生物特征信息),则可以通过收单机构服务器向终端发送识别失败响应,以使所述终端显示输入识别辅助信息的提示。具体实施过程为:
接收所述收单机构服务器转发的识别辅助信息,所述识别辅助信息为所述终端响应于用户的操作向所述收单机构服务器发送的;
利用所述识别辅助信息,从所述子分区生物特征信息中,确定与所述识别辅助信息对应的注册生物特征信息;
从所述与所述识别辅助信息对应的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
其中,识别辅助信息可以为用户的手机号后四位、身份证号前6位等。识别辅助信息与注册生物特征信息之间也存在对应关系,即一个识别辅助信息对应于多个注册生物特征信息。若利用算法从所述分区生物特征信息中选出子分区生物特征信息,得到的子分区生物特征信息的数量仍较多,则仍无法识别出与所述目标生物特征信息匹配的注册生物特征信息。这种情况下,可以进一步利用识别辅助信息,从验证密码信息相对应的子分区生物特征信息中,找出与识别辅助信息相对应的注册生物特征信息,从而在利用验证密码信息和算法缩小识别范围的基础上,利用识别辅助信息进一步缩小识别范围,从而提高识别的成功率。
例如,若识别失败,则生物特征识别服务器通过收单机构服务器向受理终端发送识别失败的反馈,则受理终端提示用户输入手机号后4位,作为识别辅助信息,从而进一步缩小识别范围。
图4示出了生物特征识别服务器确定出目标账户信息的过程。如图4所示,假设生物识别服务接收到的人脸图像为用户P的活体照片,支付口令为217384,则目标生物特征信息为该活体照片,支付口令经不可逆算法计算后转为安全码2ac59075b9。人脸路由库中存储有N个人脸图像,从N个人脸图像中确定出与安全码2ac59075b9对应的P个人脸图像。将P与数量预置500相对比,若P≤500,则直接将接收到的活体照片与P个存储的人脸图像进行人脸辨识,从P个人脸图像中识别出用户A的人脸图像,进而获取用户A的银行卡Token。若P>500,则利用LRU算法,从中选出Q个人脸图像,形成子集库。将Q个人脸图像与接收到的活体照片分别对比,若识别成功,则得出用户A的人脸图像,进而获取用户A的银行卡Token。若识别失败,则获取用户手机号后4位进一步缩小识别范围,得出用户A的人脸图像,进而获取用户A的银行卡Token。
为了最大限度的利用现有的系统资源,本发明实施例中,可以将整个交易拆分成一个识别过程和一个数据处理过程。生物特征识别服务器向所述目标账户信息对应的发卡机构服务器发送数据处理请求之前,还包括:
通过收单机构服务器向终端发送所述目标账户信息,以使所述终端向所述收单机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
接收所述收单机构服务器转发的所述数据处理请求。
具体实施过程中,针对一笔交易,受理终端可以发出两个请求,一个为识别请求,一个为支付请求。具体来说,受理终端响应于用户的操作,首先生成识别请求,并通过收单机构服务器向生物特征识别服务器发送该识别请求。该识别请求中包含用户的目标生物特征信息和验证密码信息。之后,受理终端在接收到生物特征识别服务器发送的目标账户信息后,生成支付请求, 并通过收单机构服务器和生物特征识别服务器向发卡机构服务器发送该支付请求。该支付请求中包含目标账户信息和验证密码信息。其中,生物特征识别服务器可以为清算机构中的服务器。由于现有的交易系统中,清算机构服务器与发卡机构服务器相连,并同步发卡机构服务器中的数据,因此,这种系统结构以及一笔交易两个请求的处理方式,对现有系统的改动较小,可以最大限度的利用现有的系统资源,并能够任意叠加到现有数据处理类型上,如转账、取现、预授权等类型的交易,无需再做修改。
图5示出了本发明实施例提供的一种数据流向示意图。如图5所示,受理终端通过步骤1接收到用户的人脸图像和支付口令后,通过步骤2向清算机构中的人脸路由网关发送人脸图像和支付口令。人脸路由网关从人脸路由数据库中确定出该用户的银行卡号后,通过步骤3将银行卡号Token向受理终端反馈。受理终端再根据接收到的银行卡号Token,通过步骤4,经收单系统和转接清算系统转发,向发卡银行业务系统发送支付请求。发卡银行业务系统在处理完成后通过步骤5向转接清算系统、收单系统和受理终端反馈。由图5可以看出,受理终端根据用户操作发送了两个请求,用户只需在一开始输入其人脸图像和支付口令即可,中间过程用户无需感知,这种方式下,即使受理终端发送了两次请求,用户的操作也能较为简洁。
进一步地,生物特征识别服务器接收目标对象的目标生物特征信息和验证密码信息之前,还包括:
接收所述目标对象的注册账户信息、注册生物特征信息和路由索引信息,其中路由索引信息为利用不可逆算法将所述验证密码信息运算生成的;
将所述路由索引信息加盐加密处理;
将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储在所述路由索引信息对应的分区中。
具体实施过程中,用户可以通过发卡机构APP,或清算机构(比如卡组织)APP,或者第三方APP进行注册,在用户注册时,获得注册账户信息、注册生物特征信息和验证密码信息。
当用户通过发卡机构APP进行注册时,发卡机构服务器获取用户的账户信息、人脸图像和支付口令等注册信息,并将上述注册信息关联存储,向生物特征识别服务器同步上述注册信息。当用户通过清算机构APP进行注册时,生物特征识别服务器获取用户的账户信息、人脸图像和支付口令等注册信息,并将上述注册信息关联存储,向发卡机构服务器同步上述注册信息。
为了保证数据的安全性,尤其是验证密码信息的安全性,本发明实施例中,发卡机构服务器接收到验证密码信息后,利用不可逆算法将验证密码信息运算生成路由索引信息,再将注册账户信息、注册生物特征信息和路由索引信息同步至生物特征识别服务器。生物特征识别服务器对每个用户的路由索引信息加盐加密处理,以保障信息安全。加盐加密是一种对数据的加密方式,具体实现方式是将每一个数据同一个叫做“盐”(salt)的n位随机数相关联,然后一同加密。无论何时只要数据改变,随机数就改变。随机数以未加密的方式存放在文件中,加密后的结果也放在文件中。其中,不可逆算法可以为SM3、SHA-256等。
图6示出了本发明实施例提供的一种注册流程。如图6所示,用户在发卡银行APP中设置支付口令。发卡银行业务系统通过不可逆运算,将支付口令运算为人脸支付安全码,再同步给人脸路由平台。人脸路由平台为每个人脸支付安全码加入不同的salt,并加密存储。
为了进一步保证数据的存储和传输安全,上述内容中的“将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储”,具体可以包括:
将所述注册账户信息进行标记处理,得到卡片标记Tokend信息;
将加密后的路由索引信息、所述注册生物特征信息与所述Tokend信息关联存储。
对应的,所述确定所述目标对象的目标账户信息,包括:
确定与所述目标生物特征信息对应的Tokent信息;
将所述Tokend信息转换为Tokent信息。
进一步地,所述确定所述目标对象的目标账户信息之后,还包括:
向所述终端发送所述Tokent信息。
具体实施过程中,为了防止用户的账户信息泄露,可以对账户信息进行标记处理,生成Token信息。在一种可选的实施例中,卡片标记Token信息可以是利用支付标记服务(Token Service Provider,TSP)生成的,支付标记化服务TSP是数字支付基础安全服务,能为银行、支付机构、行业机构的支付提供安全保障。支付标记服务TSP用特定的支付标记Token替代传统的银行卡号,能够有效降低商户、受理机构侧发生的卡片信息泄露风险,有助于减少交易欺诈。
示例性的,银行卡标记Token信息可以包括:银行信息和带有部分银行卡号的信息。比如,一个银行卡标记Token信息为:T银行,6666********1234。其中,该银行卡标记Token信息中的部分银行号使用*代替。
生物特征识别服务器可以以路由索引信息作为索引(可视情况结合数据标签、手机号后4位等),将账户信息生成Token信息。其中,Token信息可分为Tokend(标记)信息和Tokent(临时标记)信息,Tokend信息存储在生物特征数据库中,生物特征识别服务器将Tokend信息标记化生成Tokent信息,并将Tokent信息向外发送。该Tokent信息仅在一段时间内有效,比如3分钟,如此,能够防止用户的账户信息泄露,提高用户财产的安全性。
本发明实施例中,生物特征信息可以包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息、掌纹信息、指静脉信息、掌静脉信息。
一种可选的实施例中,受理设备在接收到用户的支付指令后,还可以对用户进行活体检测。其中,活体检测用于判断采集到的生物特征信息是否来源于活体。在活体检测时,可以要求用户眨眼睛、转头、张嘴等等。通过活体检测,能够防止其他用户利用用户的照片盗刷用户的银行卡,提高用户财产的安全性。
为了更清楚地理解本发明,以具体实施例对上述流程进行详细描述。图7示出了具体实施例一中注册流程示意图。如图7所示,流程包括:
用户通过发卡银行APP发起开通人脸识别线下支付业务的申请,注册人脸信息,绑定银行卡,设置支付口令。
发卡银行业务系统完成用户身份验证,将人脸路由信息(路由索引码、人脸信息、银行卡卡号/Token、银行卡卡号后4位、手机号后4位)同步至人脸路由平台。
人脸路由平台返回发卡银行业务系统同步结果,发卡银行业务系统返回用户注册开通结果。用户可进行修改人脸照片、修改支付口令,设置默认支付卡的操作。
图8示出了具体实施例二中支付流程示意图。如图8所示,流程包括:
受理终端采集人脸信息,提示用户输入支付口令。
受理终端将人脸信息和支付口令密文经收单系统转加密后,传输至人脸路由平台。
人脸路由平台在将支付口令密文转加密为路由索引码后,根据人脸信息、路由索引码等进行识别,识别成功则将支付卡号进行标记化处理,返回支付Token至受理终端。
如果人脸路由平台返回需增加辅助信息,返回收单机构对应的应答码,终端重新采集手机号后四位后继续上送识别交易,识别成功后返回终端。
受理终端使用Token和支付口令密文发起交易,将交易指令经收单系统、转接清算系统传输至发卡银行业务系统。
发卡银行业务系统根据支付口令、活检结果进行交易确认,完成支付交易。
本发明实施例还提供了一种数据处理装置,如图9所示,包括:
收发单元901,用于接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息;
识别单元902,用于从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;
确定单元903,根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;
所述收发单元901,还用于向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息,以使所述发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
一种可选的实施例中,所述识别单元902,具体用于:
从多个对象的注册生物特征信息中确定出分区生物特征信息;其中,所述分区生物特征信息为与所述验证密码信息关联存储的注册生物特征信息;
确定所述验证密码信息对应的主识别算法以及辅助识别算法;
利用所述主识别算法,从所述验证密码信息对应的所有分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
利用所述辅助识别算法对所述主识别算法的识别结果进行验证。
一种可选的实施例中,所述识别单元902,具体用于:
将所述分区生物特征信息的信息数量与数量阈值对比;
若所述信息数量小于所述数量阈值,则执行从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤;
若所述信息数量大于或等于所述数量阈值,则利用算法从所述分区生物特征信息中选出子分区生物特征信息,从所述子分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
一种可选的实施例中,所述收发单元901,还用于若所述识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤执行失败,则通过收单机构服务器向终端发送识别失败响应,以使所述终端显示输入识别辅助信息的提示;接收所述收单机构服务器转发的识别辅助信息,所述识别辅助信息为所 述终端响应于用户的操作向所述收单机构服务器发送的;
所述识别单元902,还用于利用所述识别辅助信息,从所述子分区生物特征信息中,确定与所述识别辅助信息对应的注册生物特征信息;从所述与所述识别辅助信息对应的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
一种可选的实施例中,所述收发单元901,还用于:
通过收单机构服务器向终端发送所述目标账户信息,以使所述终端向所述收单机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
接收所述收单机构服务器转发的所述数据处理请求。
一种可选的实施例中,还包括注册单元904,用于:
接收所述目标对象的注册账户信息、注册生物特征信息和路由索引信息,其中路由索引信息为利用不可逆算法将所述验证密码信息运算生成的;
将所述路由索引信息加盐加密处理;
将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储。
一种可选的实施例中,所述注册单元904,具体用于将所述注册账户信息进行标记处理,得到Tokend信息;将加密后的路由索引信息、所述注册生物特征信息与所述Tokend信息关联存储;
所述确定单元903,还用于确定与所述目标生物特征信息对应的Tokent信息;将所述Tokend信息转换为Tokent信息;
所述收发单元901,还用于向所述终端发送所述Tokent信息。
一种可选的实施例中,所述生物特征信息包括以下所列项中的一种或多种:
人脸信息、指纹信息、声纹信息、虹膜信息、掌纹信息、指静脉信息、掌静脉信息。
基于相同的原理,本发明还提供一种电子设备,如图10所示,包括:
包括处理器701、存储器702、收发机703、总线接口704,其中处理器701、存储器702与收发机703之间通过总线接口704连接;
所述处理器701,用于读取所述存储器702中的程序,执行下列方法:
接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息;
从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;
向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息,以使所述发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
基于相同的原理,本发明还提供一种非暂态计算机可读存储介质,该非暂态计算机可读存储介质存储计算机指令,该计算机指令用于使计算机执行图1至图8中任一项所述的方法。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本发明的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本发明范围的所有变更和修改。
显然,本领域的技术人员可以对本发明进行各种改动和变型而不脱离本发明的精神和范围。这样,倘若本发明的这些修改和变型属于本发明权利要求及其等同技术的范围之内,则本发明也意图包括这些改动和变型在内。

Claims (19)

  1. 一种数据处理方法,其特征在于,包括:
    接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息;
    从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;
    根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;
    向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息,以使所述发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
  2. 如权利要求1所述的方法,其特征在于,所述从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,包括:
    从多个对象的注册生物特征信息中确定出分区生物特征信息;其中,所述分区生物特征信息为与所述验证密码信息关联存储的注册生物特征信息;
    确定所述验证密码信息对应的主识别算法以及辅助识别算法;
    利用所述主识别算法,从所述验证密码信息对应的所有分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
    利用所述辅助识别算法对所述主识别算法的识别结果进行验证。
  3. 如权利要求2所述的方法,其特征在于,所述从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,包括:
    将所述分区生物特征信息的信息数量与数量阈值对比;
    若所述信息数量小于所述数量阈值,则执行从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤;
    若所述信息数量大于或等于所述数量阈值,则利用算法从所述分区生物特征信息中选出子分区生物特征信息,从所述子分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
  4. 如权利要求2所述的方法,其特征在于,所述从多个对象的注册生物特征信息中确定出分区生物特征信息之后,还包括:
    若所述识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤执行失败,则通过收单机构服务器向终端发送识别失败响应,以使所述终端显示输入识别辅助信息的提示;
    接收所述收单机构服务器转发的识别辅助信息,所述识别辅助信息为所述终端响应于用户的操作向所述收单机构服务器发送的;
    利用所述识别辅助信息,从所述子分区生物特征信息中,确定与所述识别辅助信息对应的注册生物特征信息;
    从所述与所述识别辅助信息对应的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
  5. 如权利要求1所述的方法,其特征在于,所述向所述目标账户信息对应的发卡机构服务器发送数据处理请求之前,还包括:
    通过收单机构服务器向终端发送所述目标账户信息,以使所述终端向所述收单机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
    接收所述收单机构服务器转发的所述数据处理请求。
  6. 如权利要求1所述的方法,其特征在于,所述接收目标对象的目标生物特征信息和验证密码信息之前,还包括:
    接收所述目标对象的注册账户信息、注册生物特征信息和路由索引信息,其中路由索引信息为利用不可逆算法将所述验证密码信息运算生成的;
    将所述路由索引信息加盐加密处理;
    将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储。
  7. 如权利要求6所述的方法,其特征在于,所述将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储,包括:
    将所述注册账户信息进行标记处理,得到Tokend信息;
    将加密后的路由索引信息、所述注册生物特征信息与所述Tokend信息关联存储;
    所述确定所述目标对象的目标账户信息,包括:
    确定与所述目标生物特征信息对应的Tokent信息;
    将所述Tokend信息转换为Tokent信息;
    所述确定所述目标对象的目标账户信息之后,还包括:
    向所述终端发送所述Tokent信息。
  8. 如权利要求1至7任一项所述的方法,其特征在于,所述生物特征信息包括以下所列项中的一种或多种:
    人脸信息、指纹信息、声纹信息、虹膜信息、掌纹信息、指静脉信息、掌静脉信息。
  9. 一种数据处理装置,其特征在于,包括:
    收发单元,用于接收收单机构服务器发送的目标对象的目标生物特征信息和验证密码信息;
    识别单元,用于从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;
    确定单元,根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;
    所述收发单元,还用于向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息,以使所述发卡机构服务器利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
  10. 如权利要求9所述的装置,其特征在于,所述识别单元,具体用于:
    从多个对象的注册生物特征信息中确定出分区生物特征信息;其中,所述分区生物特征信息为与所述验证密码信息关联存储的注册生物特征信息;
    确定所述验证密码信息对应的主识别算法以及辅助识别算法;
    利用所述主识别算法,从所述验证密码信息对应的所有分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息;
    利用所述辅助识别算法对所述主识别算法的识别结果进行验证。
  11. 如权利要求10所述的装置,其特征在于,所述识别单元,具体用于:
    将所述分区生物特征信息的信息数量与数量阈值对比;
    若所述信息数量小于所述数量阈值,则执行从所述分区生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤;
    若所述信息数量大于或等于所述数量阈值,则利用算法从所述分区生物特征信息中选出子分区生物特征信息,从所述子分区生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
  12. 如权利要求10所述的装置,其特征在于,
    所述收发单元,还用于若所述识别出与所述目标生物特征信息匹配的注册生物特征信息的步骤执行失败,则通过收单机构服务器向终端发送识别失败响应,以使所述终端显示输入识别辅助信息的提示;接收所述收单机构服务器转发的识别辅助信息,所述识别辅助信息为所述终端响应于用户的操作向所述收单机构服务器发送的;
    所述识别单元,还用于利用所述识别辅助信息,从所述子分区生物特征信息中,确定与所述识别辅助信息对应的注册生物特征信息;从所述与所述识别辅助信息对应的注册生物特征信息中识别出与所述目标生物特征信息匹配的注册生物特征信息。
  13. 如权利要求9所述的装置,其特征在于,所述收发单元,还用于:
    通过收单机构服务器向终端发送所述目标账户信息,以使所述终端向所述收单机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
    接收所述收单机构服务器转发的所述数据处理请求。
  14. 如权利要求9所述的装置,其特征在于,还包括注册单元,用于:
    接收所述目标对象的注册账户信息、注册生物特征信息和路由索引信息,其中路由索引信息为利用不可逆算法将所述验证密码信息运算生成的;
    将所述路由索引信息加盐加密处理;
    将加密后的路由索引信息、所述注册生物特征信息以及所述注册账户信息关联存储。
  15. 如权利要求14所述的装置,其特征在于,
    所述注册单元,具体用于将所述注册账户信息进行标记处理,得到Tokend信息;将加密后的路由索引信息、所述注册生物特征信息与所述Tokend信息关联存储;
    所述确定单元,还用于确定与所述目标生物特征信息对应的Tokent信息;将所述Tokend信息转换为Tokent信息;
    所述收发单元,还用于向所述终端发送所述Tokent信息。
  16. 如权利要求9至15任一项所述的装置,其特征在于,所述生物特征信息包括以下所列项中的一种或多种:
    人脸信息、指纹信息、声纹信息、虹膜信息、掌纹信息、指静脉信息、掌静脉信息。
  17. 一种电子设备,其特征在于,包括:
    至少一个处理器;以及,
    与所述至少一个处理器通信连接的存储器;其中,
    所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器能够执行权利要求1-8任一所述的方法。
  18. 一种非暂态计算机可读存储介质,其特征在于,所述非暂态计算机可读存储介质存储计算机指令,所述计算机指令用于使所述计算机执行权利要求1~8任一所述方法。
  19. 一种数据处理系统,其特征在于,包括收单机构服务器、生物特征识别服务器和发卡机构服务器;
    所述收单机构服务器,用于接收终端发送的目标对象的目标生物特征信息和验证密码信息;将所述目标生物特征信息和所述验证密码信息向所述生物特征识别服务器发送;
    所述生物特征识别服务器,用于接收所述收单机构服务器发送的所述目标生物特征信息和所述验证密码信息;从多个对象的注册生物特征信息中,识别出与所述目标生物特征信息匹配的注册生物特征信息,同一个对象的注册生物特征信息与账户信息关联存储;根据识别出的注册生物特征信息,确定所述目标对象的目标账户信息;向所述目标账户信息对应的发卡机构服务器发送数据处理请求,所述数据处理请求中包含所述目标账户信息和所述验证密码信息;
    所述发卡机构服务器,用于接收所述数据处理请求;利用所述验证密码信息进行验证并在验证通过后根据所述目标账户信息进行数据处理。
PCT/CN2020/103112 2019-12-31 2020-07-20 一种数据处理方法、装置与系统 Ceased WO2021135170A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US17/624,983 US11599882B2 (en) 2019-12-31 2020-07-20 Data processing method, apparatus, and system
SG11202112580YA SG11202112580YA (en) 2019-12-31 2020-07-20 Data processing method, apparatus, and system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201911419394.3 2019-12-31
CN201911419394.3A CN111144895B (zh) 2019-12-31 2019-12-31 一种数据处理方法、装置与系统

Publications (1)

Publication Number Publication Date
WO2021135170A1 true WO2021135170A1 (zh) 2021-07-08

Family

ID=70522872

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/103112 Ceased WO2021135170A1 (zh) 2019-12-31 2020-07-20 一种数据处理方法、装置与系统

Country Status (5)

Country Link
US (1) US11599882B2 (zh)
CN (1) CN111144895B (zh)
SG (1) SG11202112580YA (zh)
TW (1) TWI793479B (zh)
WO (1) WO2021135170A1 (zh)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111144895B (zh) 2019-12-31 2023-10-31 中国银联股份有限公司 一种数据处理方法、装置与系统
US12273338B2 (en) * 2020-10-20 2025-04-08 Bank Of America Corporation Identity verification through a centralized biometric database
CN113516167B (zh) * 2021-05-17 2025-05-09 中国工商银行股份有限公司 生物特征识别方法及装置
CN116232632B (zh) * 2022-11-18 2025-09-23 南方电网数字平台科技(广东)有限公司 移动端sslvpn安全隧道应用方法及系统
TWI860076B (zh) * 2023-09-01 2024-10-21 合作金庫商業銀行股份有限公司 編碼式信用卡資訊保密與驗證系統及其方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170017957A1 (en) * 2015-07-17 2017-01-19 Mastercard International Incorporated Authentication system and method for server-based payments
CN109711133A (zh) * 2018-12-26 2019-05-03 广州市巽腾信息科技有限公司 身份信息的认证方法、装置及服务器
CN110189136A (zh) * 2019-05-20 2019-08-30 中国银联股份有限公司 交易处理方法、装置、设备、介质及系统
CN111144895A (zh) * 2019-12-31 2020-05-12 中国银联股份有限公司 一种数据处理方法、装置与系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20160044307A (ko) * 2014-10-15 2016-04-25 삼성전자주식회사 정보 보안 제공 방법 및 그 전자 장치
CN110166246B (zh) * 2016-03-30 2022-07-08 创新先进技术有限公司 基于生物特征的身份注册、认证的方法和装置
TWM574284U (zh) * 2018-11-19 2019-02-11 玉山商業銀行股份有限公司 利用活體及人臉辨識執行無卡交易的交易系統及自動櫃員機

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20170017957A1 (en) * 2015-07-17 2017-01-19 Mastercard International Incorporated Authentication system and method for server-based payments
CN109711133A (zh) * 2018-12-26 2019-05-03 广州市巽腾信息科技有限公司 身份信息的认证方法、装置及服务器
CN110189136A (zh) * 2019-05-20 2019-08-30 中国银联股份有限公司 交易处理方法、装置、设备、介质及系统
CN111144895A (zh) * 2019-12-31 2020-05-12 中国银联股份有限公司 一种数据处理方法、装置与系统

Also Published As

Publication number Publication date
TW202127341A (zh) 2021-07-16
CN111144895B (zh) 2023-10-31
SG11202112580YA (en) 2021-12-30
CN111144895A (zh) 2020-05-12
US20220292514A1 (en) 2022-09-15
TWI793479B (zh) 2023-02-21
US11599882B2 (en) 2023-03-07

Similar Documents

Publication Publication Date Title
US10902425B2 (en) System and method for biometric credit based on blockchain
US11030621B2 (en) System to enable contactless access to a transaction terminal using a process data network
US10484178B2 (en) Systems and methods for providing a universal decentralized solution for verification of users with cross-verification features
CN111144895B (zh) 一种数据处理方法、装置与系统
US20220052852A1 (en) Secure biometric authentication using electronic identity
US10341123B2 (en) User identification management system and method
US10515357B2 (en) Systems and methods for authenticating electronic transactions
US20180343120A1 (en) Systems and methods for providing a universal decentralized solution for verification of users with cross-verification features
US20230084897A1 (en) Registration and payment method, device, and system using face information
US20150227937A1 (en) Random biometric authentication method and apparatus
US20150287017A1 (en) Systems and Methods for Transacting at an ATM Using a Mobile Device
WO2020073491A1 (zh) 基于区块链的供应链支付方法、收款方法、装置、设备及介质
CN108171486B (zh) 一种具有电子印章功能的终端
US11810110B2 (en) Method of processing a transaction sent from a proof entity
CN109426963B (zh) 认证生物统计请求的生物统计系统
KR102447899B1 (ko) 비대면 본인인증 시스템 및 그 방법
US12597029B2 (en) System, method, and computer program product for authenticating a transaction
US20250094988A1 (en) Distributed ledger technology utilizing cardless payments
CN117981274A (zh) 远程身份交互
WO2019209291A1 (en) Systems and methods for providing a universal decentralized solution for verification of users with cross-verification features
CN119809814B (zh) 依赖方风险调整指示符系统和方法
US20160342996A1 (en) Two-factor authentication method
WO2020237871A1 (zh) 无卡交易方法、装置及服务器
KR20180011610A (ko) 셀프 뱅킹 장치 및 이를 이용한 금융 거래 방법
HK40020330B (zh) 一种数据处理方法、装置与系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20910400

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20910400

Country of ref document: EP

Kind code of ref document: A1