[go: up one dir, main page]

CN116347406A - User authentication method and device, equipment, storage medium - Google Patents

User authentication method and device, equipment, storage medium Download PDF

Info

Publication number
CN116347406A
CN116347406A CN202111593048.4A CN202111593048A CN116347406A CN 116347406 A CN116347406 A CN 116347406A CN 202111593048 A CN202111593048 A CN 202111593048A CN 116347406 A CN116347406 A CN 116347406A
Authority
CN
China
Prior art keywords
card
identifiable
authentication
information
identifiable card
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202111593048.4A
Other languages
Chinese (zh)
Inventor
葛欣
肖坤
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Original Assignee
China Mobile Communications Group Co Ltd
Research Institute of China Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Mobile Communications Group Co Ltd, Research Institute of China Mobile Communication Co Ltd filed Critical China Mobile Communications Group Co Ltd
Priority to CN202111593048.4A priority Critical patent/CN116347406A/en
Publication of CN116347406A publication Critical patent/CN116347406A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04BTRANSMISSION
    • H04B5/00Near-field transmission systems, e.g. inductive or capacitive transmission systems
    • H04B5/70Near-field transmission systems, e.g. inductive or capacitive transmission systems specially adapted for specific purposes
    • H04B5/77Near-field transmission systems, e.g. inductive or capacitive transmission systems specially adapted for specific purposes for interrogation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/14Direct-mode setup

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Telephonic Communication Services (AREA)

Abstract

The application provides a user authentication method and device, equipment and a storage medium; wherein the method comprises the following steps: establishing a communication connection with the identifiable card; acquiring application information currently bound with the identifiable card; and authenticating the identity of the user currently using the identifiable card at least according to the currently bound application information and the application information bound with the identifiable card history, so as to determine whether to execute card swiping operation on the identifiable card. Therefore, authentication of the user can be completed, authentication safety is improved, and user experience is improved.

Description

用户认证方法及装置、设备、存储介质User authentication method and device, equipment, storage medium

技术领域technical field

本申请涉及通信技术,涉及但不限于一种用户认证方法及装置、设备、存储介质。The present application relates to communication technology, involving but not limited to a user authentication method, device, equipment, and storage medium.

背景技术Background technique

相关技术中,当不同的用户使用同一终端在地铁闸机、公交、企业一卡通等非接触读卡器上进行刷卡操作时,只要使用的终端为合法终端,则对于不同的用户而言,其均能够被认证成功,认证安全性较差。In related technologies, when different users use the same terminal to swipe their cards on non-contact card readers such as subway gates, buses, and corporate cards, as long as the terminals used are legitimate terminals, for different users, the Can be authenticated successfully, and the authentication security is poor.

发明内容Contents of the invention

有鉴于此,本申请提供的用户认证方法及装置、设备、存储介质,能够实现对用户身份的刻画,完成对用户本人的认证,从而提升认证的安全性,且提高用户体验。In view of this, the user authentication method, device, equipment, and storage medium provided by the present application can realize the description of the user's identity and complete the authentication of the user himself, thereby improving the security of authentication and improving user experience.

根据本申请实施例的一个方面,提供一种用户认证方法,包括:与可识别卡片建立通信连接;获取与所述可识别卡片当前绑定的应用信息;至少根据所述当前绑定的应用信息以及与所述可识别卡片历史绑定的应用信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。According to an aspect of an embodiment of the present application, there is provided a user authentication method, including: establishing a communication connection with an identifiable card; obtaining application information currently bound to the identifiable card; at least according to the currently bound application information As well as the application information bound with the history of the identifiable card, the identity authentication of the user currently using the identifiable card is performed to determine whether to perform a card swiping operation on the identifiable card.

在本申请实施例中,在对当前使用可识别卡片的用户进行身份认证时,至少是根据可识别卡片当前绑定的应用信息(可识别卡片当前处于激活状态的应用信息,也即用户在当前时刻使用的应用)和预存的可识别卡片历史绑定的应用信息(即用户在历史时刻使用的可识别卡片上处于激活状态的应用信息)来认证的。这样,一方面,在用户无感的状态下即完成了身份认证,使用便利,提升了用户体验;另一方面,在对用户进行身份认证时考虑到了用户的使用习惯,能够实现对用户本人的认证,而避免出现其他用户使用同一可识别卡片时也能认证通过的情况发生,从而提升了认证的安全性。In this embodiment of the application, when performing identity authentication on a user currently using an identifiable card, at least according to the application information currently bound to the identifiable card (the application information that the identifiable card is currently activated, that is, the user is currently The application used at all times) and the pre-stored application information bound to the identifiable card history (that is, the application information that is activated on the identifiable card used by the user at historical moments) to authenticate. In this way, on the one hand, the identity authentication is completed in a state where the user has no sense, which is convenient to use and improves the user experience; Authentication, and avoid the situation that other users can also pass the authentication when using the same identifiable card, thereby improving the security of authentication.

根据本申请实施例的一个方面,提供一种用户认证装置,包括:通信单元,用于与可识别卡片建立通信连接;获取单元,用于获取与所述可识别卡片当前绑定的应用信息;认证单元,用于至少根据所述当前绑定的应用信息以及与所述可识别卡片历史绑定的应用信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。According to an aspect of an embodiment of the present application, a user authentication device is provided, including: a communication unit, configured to establish a communication connection with an identifiable card; an acquisition unit, configured to acquire application information currently bound to the identifiable card; An authentication unit, configured to authenticate the user currently using the identifiable card according to at least the currently bound application information and the historically bound application information of the identifiable card, so as to determine whether to authenticate the identifiable card Recognize the card and perform the card swiping operation.

根据本申请实施例的一个方面,提供一种电子设备,包括存储器和处理器,所述存储器存储有可在处理器上运行的计算机程序,所述处理器执行所述程序时实现本申请实施例所述的方法。According to one aspect of the embodiments of the present application, an electronic device is provided, including a memory and a processor, the memory stores a computer program that can run on the processor, and the processor implements the embodiment of the present application when executing the program the method described.

根据本申请实施例的一个方面,提供一种计算机可读存储介质,其上存储有计算机程序,该计算机程序被处理器执行时实现本申请实施例提供的所述的方法。According to an aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the method provided in the embodiments of the present application is implemented.

应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本申请。It is to be understood that both the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the application.

附图说明Description of drawings

此处的附图被并入说明书中并构成本说明书的一部分,这些附图示出了符合本申请的实施例,并与说明书一起用于说明本申请的技术方案。显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。The accompanying drawings here are incorporated into the specification and constitute a part of the specification. These drawings show embodiments consistent with the application, and are used together with the description to describe the technical solution of the application. Apparently, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative efforts.

附图中所示的流程图仅是示例性说明,不是必须包括所有的内容和操作/步骤,也不是必须按所描述的顺序执行。例如,有的操作/步骤还可以分解,而有的操作/步骤可以合并或部分合并,因此实际执行的顺序有可能根据实际情况改变。The flow charts shown in the drawings are only exemplary illustrations, and do not necessarily include all contents and operations/steps, nor must they be performed in the order described. For example, some operations/steps can be decomposed, and some operations/steps can be combined or partly combined, so the actual order of execution may be changed according to the actual situation.

图1为本申请实施例提供的一种用户认证方法的实现流程示意图;FIG. 1 is a schematic diagram of an implementation flow of a user authentication method provided in an embodiment of the present application;

图2为本申请实施例提供的一种用户认证方法的实现流程示意图;FIG. 2 is a schematic diagram of an implementation flow of a user authentication method provided in an embodiment of the present application;

图3为本申请实施例提供的一种离线用户认证方法的实现流程示意图;FIG. 3 is a schematic diagram of an implementation flow of an offline user authentication method provided in an embodiment of the present application;

图4为本申请实施例提供的一种在线用户认证方法的实现流程示意图;FIG. 4 is a schematic diagram of an implementation flow of an online user authentication method provided in an embodiment of the present application;

图5为相关技术中的一键登录认证方式示意图;FIG. 5 is a schematic diagram of a one-key login authentication method in the related art;

图6为本申请实施例提供的认证系统的示意图;FIG. 6 is a schematic diagram of an authentication system provided by an embodiment of the present application;

图7为本申请实施例提供的离线认证的实现流程示意图;FIG. 7 is a schematic diagram of an implementation flow of offline authentication provided by an embodiment of the present application;

图8为本申请实施例提供的在线认证的实现流程示意图;FIG. 8 is a schematic diagram of an implementation flow of online authentication provided by an embodiment of the present application;

图9为本申请实施例提供的用户认证装置的结构示意图;FIG. 9 is a schematic structural diagram of a user authentication device provided by an embodiment of the present application;

图10为本申请实施例提供的电子设备的结构示意图。FIG. 10 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.

具体实施方式Detailed ways

为使本申请实施例的目的、技术方案和优点更加清楚,下面将结合本申请实施例中的附图,对本申请的具体技术方案做进一步详细描述。以下实施例用于说明本申请,但不用来限制本申请的范围。In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the specific technical solutions of the present application will be further described in detail below in conjunction with the drawings in the embodiments of the present application. The following examples are used to illustrate the present application, but not to limit the scope of the present application.

除非另有定义,本文所使用的所有的技术和科学术语与属于本申请的技术领域的技术人员通常理解的含义相同。本文中所使用的术语只是为了描述本申请实施例的目的,不是旨在限制本申请。Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application, and are not intended to limit the present application.

在以下的描述中,涉及到“一些实施例”,其描述了所有可能实施例的子集,但是可以理解,“一些实施例”可以是所有可能实施例的相同子集或不同子集,并且可以在不冲突的情况下相互结合。In the following description, references to "some embodiments" describe a subset of all possible embodiments, but it is understood that "some embodiments" may be the same subset or a different subset of all possible embodiments, and Can be combined with each other without conflict.

图1为本申请实施例提供的用户认证方法的实现流程示意图,所述方法应用于非接触读卡器,如图1所示,该方法可以包括以下步骤101至步骤103:Figure 1 is a schematic diagram of the implementation flow of the user authentication method provided by the embodiment of the present application. The method is applied to a contactless card reader. As shown in Figure 1, the method may include the following steps 101 to 103:

步骤101,非接触读卡器与可识别卡片建立通信连接。In step 101, a contactless card reader establishes a communication connection with an identifiable card.

在一些实施例中,非接触读卡器与可识别卡片建立近场通信(Near FieldCommunication,NFC)连接。In some embodiments, the contactless card reader establishes a near field communication (Near Field Communication, NFC) connection with the identifiable card.

在本申请实施例中,对于可识别卡片的类型不做限定。例如,在一些实施例中,可识别卡片可以为任何支持NFC通信技术的卡片,如支持NFC通信技术的公交卡、银行卡、门禁卡等。在另一些实施例中,可识别卡片也可以为内嵌在电子设备中的卡片或者为外接电子设备的卡片,以使电子设备能够支持NFC通信技术,例如所述电子设备可以包括手机、平板电脑、笔记本电脑、个人数字助理(PDA)、平板电脑(PAD)或导航装置等。In this embodiment of the application, there is no limitation on the types of identifiable cards. For example, in some embodiments, the identifiable card may be any card supporting NFC communication technology, such as a bus card, bank card, access control card, etc. supporting NFC communication technology. In other embodiments, the identifiable card can also be a card embedded in an electronic device or a card connected to an external electronic device, so that the electronic device can support NFC communication technology, for example, the electronic device can include a mobile phone, a tablet computer , laptop, personal digital assistant (PDA), tablet computer (PAD) or navigation device, etc.

在本申请实施例中,非接触读卡器可以为任何支持NFC通信技术的读卡器,如销售终端(Point of sales terminal,POS)机、地铁闸机、门禁读卡器等。In the embodiment of the present application, the contactless card reader may be any card reader supporting NFC communication technology, such as a point of sales terminal (POS) machine, a subway gate, an access control card reader, and the like.

步骤102,非接触读卡器获取与可识别卡片当前绑定的应用信息。In step 102, the contactless card reader obtains the application information currently bound to the identifiable card.

需要说明的是,与可识别卡片当前绑定的应用信息,为用户当前正在使用的应用的信息,也即可识别卡片当前激活的应用的信息。在一些实施例中,可以通过获取可识别卡片的路由表信息,再从路由表信息中进一步获取可识别卡片当前激活的应用信息。其中,如表1所示,路由器信息中至少包括不同应用的应用标识(Application Identification,AID),以及各个应用所属类别、所处的位置和当前状态。It should be noted that the application information currently bound to the identifiable card is the information of the application currently being used by the user, that is, the information of the application currently activated by the identification card. In some embodiments, the currently activated application information of the identifiable card can be further obtained from the routing table information by acquiring the routing table information of the identifiable card. Wherein, as shown in Table 1, the router information includes at least application identifications (Application Identification, AID) of different applications, as well as the category, location and current status of each application.

表1Table 1

应用AIDApplication AID 类别category 位置Location 状态state AID1AID1 银行类Bank NFC-SIMNFC-SIM forceforce AID2AID2 银行类Bank eSEeSE activeactive AID3AID3 交通类Transportation eSEeSE activeactive AID4AID4 交通类Transportation HCEHCE deactivedeactive -- -- NFC-SIMNFC-SIM defaultdefault

可以理解地,不同用户在使用可识别卡片时的使用习惯是不同的。相应地,不同用户在使用同一可识别卡片时,可识别卡片上当前激活的应用信息也是不同的。例如,用户A偏向于使用交通类应用,用户B偏向于使用银行卡类应用,那么当用户A使用可识别卡片时,可识别卡片上当前激活的应用为交通类应用;当用户B使用该可识别卡片时,可识别卡片上当前激活的应用为银行卡类应用。Understandably, different users have different usage habits when using an identifiable card. Correspondingly, when different users use the same identifiable card, the currently activated application information on the identifiable card is also different. For example, if user A prefers to use transportation applications, and user B prefers to use bank card applications, then when user A uses an identifiable card, the currently activated application on the card can be identified as a transportation application; When identifying the card, it can be identified that the currently activated application on the card is a bank card application.

其中,对于同一个可识别卡片上的同一类应用,用户在使用该类应用时,是将该类应用中的某一个设置为激活状态,而其他的同类应用设置为待激活状态的。这样,由于用户的使用习惯不同,那么即便是不同的用户均使用银行卡类应用,其在对可识别卡片进行设置时,设置处于激活状态的应用也不同。例如,用户A偏向于使用A银行卡应用进行支付,则其可以将A银行卡应用设置为激活状态,其他的银行卡应用设置为待激活状态;而用户B偏向于使用B银行卡应用进行支付,则其可以将B银行卡应用设置为激活状态,其他的银行卡应用设置为待激活状态。Wherein, for the same type of application on the same identifiable card, when the user uses this type of application, one of the type of applications is set as an activated state, while other similar applications are set as a waiting state. In this way, due to the different usage habits of users, even if different users use bank card applications, when setting the recognizable cards, the applications that are set to be active are also different. For example, if user A prefers to use bank card application A for payment, he can set bank card application A to be activated and other bank card applications to be activated; user B prefers to use bank card application B for payment , then it can set the B bank card application to the activated state, and set the other bank card applications to the pending activation state.

步骤103,至少根据当前绑定的应用信息以及与可识别卡片历史绑定的应用信息,对当前使用可识别卡片的用户进行身份认证,以确定是否对可识别卡片执行刷卡操作。Step 103, at least according to the currently bound application information and the application information bound with the history of the identifiable card, perform identity authentication on the user currently using the identifiable card to determine whether to swipe the identifiable card.

例如,以可识别卡片为手机内嵌的卡片,非接触读卡器为地铁闸机为例来进行说明,当用户需要乘坐地铁进站时,可以通过手机界面选择地铁刷卡的应用,与地铁闸机建立通信连接,以使地铁闸机获取手机当前使用的应用信息,并至少根据当前使用的应用信息和手机在历史时刻进行地铁刷卡时使用的应用信息,离线对当前使用手机的用户进行身份认证,以确定用户是否为本人以及是否对手机执行刷卡操作;或者,地铁闸机在获取手机当前使用的应用信息后,将其上传至业务平台,以使业务平台在线对当前使用手机的用户进行身份认证。For example, take the identifiable card as the card embedded in the mobile phone, and the non-contact card reader as the subway gate. The mobile phone establishes a communication connection, so that the subway gate machine can obtain the application information currently used by the mobile phone, and at least according to the currently used application information and the application information used by the mobile phone to swipe the subway card at historical moments, offline authentication of the user currently using the mobile phone , to determine whether the user is himself and whether to perform card swiping operations on the mobile phone; or, after obtaining the application information currently used by the mobile phone, the subway gate uploads it to the business platform, so that the business platform can identify the current user using the mobile phone online certified.

在一些实施例中,在对用户进行认证时,并不能够完成对用户本人的身份认证,即不能够确定当前使用可识别卡片的用户的真实身份,因此可能会出现不同的用户使用同一张合法的可识别卡片,均能够被认证成功的情况,这种认证方式安全性较低。In some embodiments, when authenticating a user, the identity authentication of the user cannot be completed, that is, the real identity of the user who is currently using an identifiable card cannot be determined, so different users may use the same legal card. If all identifiable cards can be authenticated successfully, the security of this authentication method is low.

基于此,在本申请实施例中,在对当前使用可识别卡片的用户进行身份认证时,至少是根据可识别卡片当前绑定的应用信息(可识别卡片当前处于激活状态的应用信息,也即用户在当前时刻使用的应用)和预存的可识别卡片历史绑定的应用信息(即用户在历史时刻使用的可识别卡片上处于激活状态的应用信息)来认证的。这样,一方面,在用户无感的状态下即完成了身份认证,使用便利,提升了用户体验;另一方面,在对用户进行身份认证时考虑到了用户的使用习惯,能够实现对用户本人的认证,而避免出现其他用户使用同一可识别卡片时也能认证通过的情况发生,从而提升了认证的安全性。Based on this, in this embodiment of the application, when performing identity authentication on a user currently using an identifiable card, at least according to the application information currently bound to the identifiable card (the application information that the identifiable card is currently activated, that is, The application used by the user at the current moment) and the pre-stored application information bound to the identifiable card history (that is, the application information that is activated on the identifiable card used by the user at the historical moment) to authenticate. In this way, on the one hand, the identity authentication is completed in a state where the user has no sense, which is convenient to use and improves the user experience; Authentication, and avoid the situation that other users can also pass the authentication when using the same identifiable card, thereby improving the security of authentication.

图2为本申请实施例提供的用户认证方法的实现流程示意图,所述方法应用于非接触读卡器,如图2所示,该方法可以包括以下步骤201至步骤206:Figure 2 is a schematic diagram of the implementation flow of the user authentication method provided by the embodiment of the present application. The method is applied to a contactless card reader. As shown in Figure 2, the method may include the following steps 201 to 206:

步骤201,非接触读卡器与可识别卡片建立通信连接;Step 201, the contactless card reader establishes a communication connection with the identifiable card;

步骤202,非接触读卡器获取与可识别卡片当前绑定的应用信息;Step 202, the contactless card reader obtains the application information currently bound to the identifiable card;

步骤203,非接触读卡器获取可识别卡片支持的射频信息。Step 203, the contactless card reader acquires the radio frequency information supported by the identifiable card.

在一些实施例中,可识别卡片支持的射频信息至少包括以下至少之一:物理射频信息、射频协议信息、安全元件SE信息。In some embodiments, the radio frequency information supported by the identifiable card includes at least one of the following: physical radio frequency information, radio frequency protocol information, and secure element SE information.

在一些实施例中,物理射频信息包括以下至少一种:NFC设备的天线尺寸、负载调制深度、射频电路阻抗、谐振频率;射频协议信息包括以下至少一种:对A型卡请求的应答(ATQA,AnswerTo Request TypeA)、唯一标识符(UID,Unique Identification)、选择确认(SAK,SelectAcknowledge)、选择应答(ATS,Answer To Select)、帧等待时间(Frame Waitinteger,FWI)、启动帧保护时间整数(Start-up Frame Guard time Integer,SFGI)等符合国际标准化组织/国际电工委员会14443标准的A/B类型(Type A/B)参数;安全元件SE信息包括以下至少一种:嵌入式安全元件(Embedded SE,eSE)、NFC用户身份识别卡(NFC-Subscriber Identity Module,NFC-SIM)信息。In some embodiments, the physical radio frequency information includes at least one of the following: antenna size, load modulation depth, radio frequency circuit impedance, and resonance frequency of the NFC device; the radio frequency protocol information includes at least one of the following: a response to a Type A card request (ATQA , AnswerTo Request TypeA), unique identifier (UID, Unique Identification), selection confirmation (SAK, SelectAcknowledge), selection response (ATS, Answer To Select), frame waiting time (Frame Waitinteger, FWI), start frame protection time integer ( Start-up Frame Guard time Integer, SFGI) and other A/B type (Type A/B) parameters that comply with the ISO/IEC 14443 standard; the secure element SE information includes at least one of the following: Embedded secure element (Embedded SE, eSE), NFC Subscriber Identity Module (NFC-Subscriber Identity Module, NFC-SIM) information.

其中,物理射频信息和SE信息是固定不变的,射频协议信息中的FWI和SFGI是变化的,其与可识别卡片当前处于激活状态的应用有关,即,激活的应用不同,FWI和SFGI也会有变化。Among them, the physical radio frequency information and SE information are fixed, and the FWI and SFGI in the radio frequency protocol information are changeable, which are related to the currently activated application of the identifiable card, that is, the activated application is different, and the FWI and SFGI are also subject to change.

步骤204,将可识别卡片支持的射频信息和预先存储的至少一个历史射频信息进行匹配,得到第一匹配结果。Step 204, matching the radio frequency information supported by the identifiable card with at least one piece of pre-stored historical radio frequency information to obtain a first matching result.

这里,至少一个历史射频信息可以作为一个整体存储在数据库中,也可以单独存储,对此不做限定。Here, at least one piece of historical radio frequency information may be stored in the database as a whole, or may be stored separately, which is not limited.

非接触读卡器在获取到可识别卡片当前支持的射频信息后,可以将其与预先存储的历史射频信息进行匹配,以确定是否存在历史射频信息与当前支持的射频信息相同;也可以将可识别卡片当前支持的射频信息上传至业务平台,以使业务平台确定是否存在历史射频信息与当前支持的射频信息相同。如果存在相同的射频信息,则说明该可识别卡片为合法卡片;如果不存在相同的射频信息,则说明该可识别卡片为非法卡片。After obtaining the radio frequency information currently supported by the identifiable card, the contactless card reader can match it with the pre-stored historical radio frequency information to determine whether there is any historical radio frequency information that is the same as the currently supported radio frequency information; The radio frequency information currently supported by the identification card is uploaded to the service platform, so that the service platform can determine whether the historical radio frequency information is the same as the currently supported radio frequency information. If there is the same radio frequency information, it means that the identifiable card is a legal card; if there is no same radio frequency information, it means that the identifiable card is an illegal card.

在本申请实施例中,对于可识别卡片支持的射频信息和历史射频信息进行匹配方式并不做限定。例如,可以直接将获取到的射频信息和预存的历史射频信息进行匹配;也可以先对射频信息进行特征提取,得到射频信息中的特定字段,与预先存储的历史射频信息中提取好的特定字段进行匹配;还可以进一步将射频信息中的特定字段生成特征码,与预先存储的历史射频信息中生成的历史特征码进行匹配。In the embodiment of the present application, there is no limitation on the matching method between the radio frequency information supported by the identifiable card and the historical radio frequency information. For example, it is possible to directly match the obtained radio frequency information with the pre-stored historical radio frequency information; it is also possible to perform feature extraction on the radio frequency information first, to obtain specific fields in the radio frequency information, and to extract specific fields from the pre-stored historical radio frequency information Matching; it is also possible to further match the characteristic code generated by a specific field in the radio frequency information with the historical characteristic code generated in the pre-stored historical radio frequency information.

步骤205,将当前绑定的应用信息和与可识别卡片历史绑定的应用信息进行匹配,得到第二匹配结果。Step 205, matching the currently bound application information with the historically bound application information of the identifiable card to obtain a second matching result.

需要说明的是,同一可识别卡片历史绑定的应用信息和该可识别卡片对应的历史射频信息关联存储。It should be noted that the historically bound application information of the same identifiable card is stored in association with the historical radio frequency information corresponding to the identifiable card.

非接触读卡器在获取到可识别卡片当前绑定的应用信息后,可以将其与预先存储的历史绑定的应用信息进行匹配,以确定是否存在历史绑定的应用信息与当前绑定的应用信息相同;也可以将可识别卡片当前绑定的应用信息上传至业务平台,以使业务平台确定是否存在历史绑定的应用信息与当前绑定的应用信息相同。如果存在相同的应用信息,则说明当前使用该可识别卡片的用户与历史使用该可识别卡片的用户为同一用户;如果不存在相同的应用信息,则说明当前使用该可识别卡片的用户与历史使用该可识别卡片的用户为不同用户。After the contactless card reader obtains the current binding application information of the identifiable card, it can match it with the pre-stored historical binding application information to determine whether there is any historical binding application information and current binding application information. The application information is the same; the application information currently bound to the identifiable card can also be uploaded to the service platform, so that the service platform can determine whether the historically bound application information is the same as the currently bound application information. If there is the same application information, it means that the user currently using the identifiable card is the same user as the user who used the identifiable card in history; Users using the identifiable card are different users.

这里,对于当前绑定的应用信息和历史绑定的应用信息进行匹配的方式也不做限定。例如,可以直接将获取到的当前绑定的应用信息和预存的历史绑定的应用信息进行匹配;也可以先对当前绑定的应用信息进行特征提取,得到当前绑定的应用信息中的特定字段,与预先存储的历史绑定的应用信息中提取好的特定字段进行匹配;还可以进一步将当前绑定的应用信息中的特定字段生成特征码,与预先存储的历史绑定的应用信息中生成的历史特征码进行匹配。Here, the manner of matching the currently bound application information with the historically bound application information is also not limited. For example, the obtained currently bound application information can be directly matched with the pre-stored historically bound application information; Fields are matched with the specific fields extracted from the pre-stored historically bound application information; it is also possible to further generate a feature code for a specific field in the currently bound application information and match it with the pre-stored historically bound application information The generated historical signatures are matched.

这里,对于步骤204和步骤205的先后顺序不做限定。例如,在一些实施例中,可以先执行步骤204,再执行步骤205,即先对射频信息进行匹配,再对绑定的应用信息进行匹配。这样,当射频信息不匹配时,说明可识别卡片为非法卡片,不能对其执行刷卡操作,那么也可以不再执行步骤205,从而节省功耗。在另一些实施例中,也可以先执行步骤205,再执行步骤204,即先对绑定的应用信息进行匹配,再对射频信息进行匹配。这样,当应用信息不匹配时,说明当前使用该可识别卡片的用户为非法用户,那么也可以不再执行步骤204,从而节省功耗;当然,还可以同时执行步骤204和步骤205。Here, the order of steps 204 and 205 is not limited. For example, in some embodiments, step 204 may be performed first, and then step 205 is performed, that is, the radio frequency information is first matched, and then the bound application information is matched. In this way, when the radio frequency information does not match, it means that the identifiable card is an illegal card, and the card swiping operation cannot be performed on it, so step 205 may not be performed, thereby saving power consumption. In some other embodiments, step 205 may also be performed first, and then step 204 is performed, that is, the bound application information is first matched, and then the radio frequency information is matched. In this way, when the application information does not match, it means that the user currently using the identifiable card is an illegal user, and then step 204 may not be executed to save power consumption; of course, step 204 and step 205 may also be executed simultaneously.

步骤206,在第一匹配结果和第二匹配结果为匹配成功的情况下,确定对当前使用可识别卡片的用户的身份认证成功,并对可识别卡片执行刷卡操作。Step 206 , if the first matching result and the second matching result are successful matching, determine that the identity authentication of the user currently using the identifiable card is successful, and perform a card swiping operation on the identifiable card.

当第一匹配结果和第二匹配结果均匹配成功时,说明可识别卡片为合法卡片,且使用该可识别卡片的用户为用户本人,据此确定对当前使用可识别卡片的用户的身份认证成功,并对可识别卡片执行刷卡操作。这种双重认证的方式,更为安全可靠。When both the first matching result and the second matching result are successfully matched, it means that the identifiable card is a legal card, and the user who uses the identifiable card is the user himself, so it is determined that the identity authentication of the user currently using the identifiable card is successful , and perform a swipe action on a recognized card. This two-factor authentication method is more secure and reliable.

图3为本申请实施例提供的一种离线用户认证方法的实现流程示意图,如图3所示,该方法可以包括以下步骤301至步骤305:FIG. 3 is a schematic diagram of an implementation flow of an offline user authentication method provided in an embodiment of the present application. As shown in FIG. 3 , the method may include the following steps 301 to 305:

步骤301,非接触读卡器与可识别卡片建立通信连接;Step 301, the contactless card reader establishes a communication connection with the identifiable card;

步骤302,非接触读卡器向可识别卡片发送离线认证指令。Step 302, the non-contact card reader sends an offline authentication instruction to the recognizable card.

这里,非接触读卡器侧选择离线认证还是在线认证,是由操作员或者管理员设定的。举例来说,如果非接触读卡器所处位置网络信号较差,那么操作员可以选择将认证方式设置为离线认证,以方便用户操作;如果非接触读卡器所处位置网络信号较好,那么操作员可以选择将认证方式设置为在线认证,以提高认证的安全性。当然,无论是离线认证还是在线认证,用户均是无感知的。Here, whether the offline authentication or the online authentication is selected on the side of the non-contact card reader is set by the operator or the administrator. For example, if the network signal at the location of the contactless card reader is poor, the operator can choose to set the authentication method to offline authentication to facilitate user operation; if the network signal at the location of the contactless card reader is good, Then the operator can choose to set the authentication method as online authentication to improve the security of authentication. Of course, no matter whether it is offline authentication or online authentication, the user is unaware.

步骤303,可识别卡片根据接收到的离线认证指令,获取与可识别卡片当前绑定的应用信息和可识别卡片支持的射频信息;Step 303, the identifiable card obtains the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card according to the received offline authentication instruction;

步骤304,可识别卡片将与可识别卡片当前绑定的应用信息和可识别卡片支持的射频信息发送给非接触读卡器;Step 304, the identifiable card sends the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card to the contactless card reader;

步骤305,非接触读卡器根据接收到的当前绑定的应用信息、与可识别卡片历史绑定的应用信息和可识别卡片支持的射频信息,对当前使用可识别卡片的用户进行身份认证,以确定是否对可识别卡片执行刷卡操作。In step 305, the contactless card reader authenticates the user currently using the identifiable card according to the received application information bound currently, the application information previously bound to the identifiable card, and the radio frequency information supported by the identifiable card, to determine whether to swipe a recognized card.

在本申请实施例中,非接触读卡器对当前使用可识别卡片的用户进行身份认证的认证方法与上述实施例中的步骤204至步骤206中的方法相同,在此不再赘述。In the embodiment of the present application, the authentication method for the contactless card reader to authenticate the user currently using the identifiable card is the same as the method in steps 204 to 206 in the above embodiment, and will not be repeated here.

图4为本申请实施例提供的一种在线用户认证方法的实现流程示意图,如图4所示,该方法可以包括以下步骤401至步骤409:FIG. 4 is a schematic diagram of an implementation flow of an online user authentication method provided in an embodiment of the present application. As shown in FIG. 4, the method may include the following steps 401 to 409:

步骤401,非接触读卡器与可识别卡片建立通信连接;Step 401, the contactless card reader establishes a communication connection with the identifiable card;

步骤402,非接触读卡器向业务平台发起在线认证请求。Step 402, the contactless card reader initiates an online authentication request to the service platform.

当非接触读卡器侧确定认证方式为在线认证时,则向业务平台发起在线认证请求,以使业务平台在线完成对当前使用可识别卡片的用户的身份认证。When the non-contact card reader side determines that the authentication mode is online authentication, it initiates an online authentication request to the service platform, so that the service platform completes the online authentication of the user currently using the identifiable card.

步骤403,非接触读卡器接收业务平台基于在线认证请求返回的在线认证指令;Step 403, the contactless card reader receives the online authentication instruction returned by the service platform based on the online authentication request;

步骤404,非接触读卡器向可识别卡片发送在线认证指令;Step 404, the non-contact card reader sends an online authentication instruction to the recognizable card;

步骤405,可识别卡片根据接收到的在线认证指令获取与可识别卡片当前绑定的应用信息和可识别卡片支持的射频信息;Step 405, the identifiable card obtains the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card according to the received online authentication instruction;

步骤406,非接触读卡器接收可识别卡片发送的与所述可识别卡片当前绑定的应用信息和可识别卡片支持的射频信息;Step 406, the contactless card reader receives the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card sent by the identifiable card;

步骤407,非接触读卡器将当前绑定的应用信息和可识别卡片支持的射频信息上传至业务平台;Step 407, the contactless card reader uploads the currently bound application information and the radio frequency information supported by the identifiable card to the service platform;

步骤408,业务平台根据当前绑定的应用信息、预先存储的与可识别卡片历史绑定的应用信息和射频信息,对当前使用可识别卡片的用户进行身份认证,得到认证结果。Step 408: The service platform performs identity authentication on the user currently using the identifiable card according to the currently bound application information, the pre-stored application information and radio frequency information bound to the identifiable card history, and obtains the authentication result.

需要说明的是,业务平台对当前使用可识别卡片的用户进行身份认证的认证方法与上述实施例中的步骤204至步骤206中的方法相同,在此不再赘述,区别在于,在本申请实施例中,是使用业务平台在线对用户进行身份认证的。It should be noted that the authentication method of the service platform for the user who currently uses an identifiable card is the same as the method in steps 204 to 206 in the above embodiment, and will not be repeated here. The difference is that in this application In the example, the user is authenticated online using the business platform.

步骤409,业务平台向非接触读卡器下发认证结果,并进行显示。Step 409, the service platform sends the authentication result to the contactless card reader and displays it.

在一些实施例,在对用户进行认证时,较多采用用户名+密码或短信验证码等方式。但对于用户而言,用户名+密码的认证方式,难以记住密码,且操作繁琐;短信验证码的方式不能保证验证短信的可达性,操作不便。在另一些实施例中,如图5所示,推出的一键登录功能,从一定程度上降低了用户使用门槛,但是该功能仅是对手机号码而非用户本人的验证,即任何人使用该号码均能完成认证,缺乏对用户本人的有效验证。In some embodiments, when authenticating a user, methods such as user name + password or SMS verification code are often used. But for users, the authentication method of user name + password is difficult to remember the password, and the operation is cumbersome; the method of SMS verification code cannot guarantee the accessibility of verification SMS, and the operation is inconvenient. In some other embodiments, as shown in Figure 5, the one-click login function launched has lowered the threshold for users to use to a certain extent, but this function is only for the verification of the mobile phone number rather than the user himself, that is, anyone who uses this The number can be authenticated, and there is no effective verification of the user himself.

基于此,下面将说明本申请实施例在一个实际的应用场景中的示例性应用。Based on this, an exemplary application of the embodiment of the present application in an actual application scenario will be described below.

在本申请实施例中,通过在终端操作系统中增加刷卡行为模块,在读卡器设备中增加终端认证模块,在平台侧增加终端识别、用户认证模块等,提出一种基于NFC终端的用户认证方法和系统,根据用户终端上使用NFC刷卡的相关信息,实现对用户真实身份的刻画,完成对用户本人的认证,在使用便利的同时,提升认证的安全性。In the embodiment of this application, a user authentication method based on NFC terminals is proposed by adding a card swiping behavior module in the terminal operating system, adding a terminal authentication module in the card reader device, and adding terminal identification and user authentication modules on the platform side. And the system, according to the relevant information of using NFC on the user terminal to swipe the card, realizes the description of the user's real identity, completes the authentication of the user himself, and improves the security of authentication while being convenient to use.

在本申请实施例中,如图6所示,可以通过以下技术手段实现基于NFC终端的用户认证方法和系统:In the embodiment of the present application, as shown in Figure 6, the user authentication method and system based on the NFC terminal can be realized through the following technical means:

(1)在终端的操作系统中增加刷卡行为模块,记录终端侧NFC刷卡相关数据,包括终端NFC射频参数、非接触参数、SE信息及刷卡路由设置等,在用户进行非接触刷卡时,与读卡器进行通信,用户使用APP时,与平台进行通信;(1) Add a card swiping behavior module in the operating system of the terminal to record the data related to NFC card swiping on the terminal side, including terminal NFC radio frequency parameters, contactless parameters, SE information, and card swiping routing settings. The card device communicates, and when the user uses the APP, it communicates with the platform;

(2)在非接触读卡器端增加终端认证模块,在用户刷卡时与终端进行非接触通信,获取用户刷卡行为信息,根据认证算法对用户完成在线或离线认证;(2) Add a terminal authentication module on the contactless card reader side, conduct contactless communication with the terminal when the user swipes the card, obtain the user's card swiping behavior information, and complete online or offline authentication for the user according to the authentication algorithm;

(3)在平台侧增加终端识别、用户认证模块,终端识别模块负责记录用户刷卡行为及用户终端信息,用户认证模块根据用户刷卡时读卡器返回的信息或终端APP上传的信息,对用户完成在线认证。(3) Add terminal identification and user authentication modules on the platform side. The terminal identification module is responsible for recording the user's card swiping behavior and user terminal information. The user authentication module completes the verification for the user based on the information returned by the card reader or the information uploaded by the terminal APP when the user swipes the card. Online certification.

其中,如图7所示,提供一种使用非接触读卡器进行离线用户认证的主要流程图,包括以下步骤701至步骤711:Wherein, as shown in FIG. 7 , a main flowchart for offline user authentication using a contactless card reader is provided, including the following steps 701 to 711:

步骤701,非接触读卡器发起寻卡请求;Step 701, the non-contact card reader initiates a card search request;

步骤702,终端(即可识别卡片的一种示例)返回,并与非接触读卡器建立非接触通信连接;Step 702, the terminal (i.e., an example of identifying the card) returns, and establishes a contactless communication connection with the contactless card reader;

步骤703,非接触读卡器侧的非接触通信模块向终端认证模块返回连接建立结果,以及卡类型、卡支持的通信协议;Step 703, the non-contact communication module on the non-contact card reader side returns the connection establishment result, card type, and communication protocol supported by the card to the terminal authentication module;

步骤704,非接触读卡器侧选择离线用户认证方式;Step 704, the non-contact card reader side selects an offline user authentication method;

步骤705,非接触读卡器发起非接触认证请求;Step 705, the non-contact card reader initiates a non-contact authentication request;

步骤706,非接触读卡器侧的非接触通信模块发出离线认证指令;Step 706, the non-contact communication module on the side of the non-contact card reader sends an offline authentication instruction;

步骤707,终端侧的NFC芯片接收认证指令,并传给刷卡行为模块;Step 707, the NFC chip on the terminal side receives the authentication instruction and transmits it to the card swiping behavior module;

步骤708,终端刷卡行为模块获取终端非接触射频参数信息(即可识别卡片支持的射频信息),包括天线尺寸S,工作场强H,负载调制深度U,谐振频率M等,非接触协议参数(即可识别卡片支持的射频信息),包括ATQA、UID、SAK、FWI、SFGI等,终端SE信息(即可识别卡片支持的射频信息),包括eSE、NFC-SIM信息,终端NFC路由表信息(即可识别卡片当前绑定的应用信息),如上表1所示,反馈给NFC芯片;Step 708, the terminal card swiping behavior module obtains terminal non-contact radio frequency parameter information (that is, the radio frequency information supported by the card), including antenna size S, working field strength H, load modulation depth U, resonance frequency M, etc., non-contact protocol parameters ( The radio frequency information supported by the card can be identified), including ATQA, UID, SAK, FWI, SFGI, etc., the terminal SE information (the radio frequency information supported by the card can be identified), including eSE, NFC-SIM information, terminal NFC routing table information ( The application information currently bound to the card can be identified), as shown in Table 1 above, and fed back to the NFC chip;

步骤709,终端侧的NFC芯片向非接触读卡器侧的非接触通信模块返回终端刷卡信息;Step 709, the NFC chip on the terminal side returns terminal card swiping information to the contactless communication module on the contactless card reader side;

步骤710,非接触读卡器侧的非接触通信模块向终端认证模块返回终端刷卡信息;Step 710, the contactless communication module on the contactless card reader side returns terminal card swiping information to the terminal authentication module;

步骤711,非接触读卡器进行认证处理,主要包括用户识别训练和认证两个阶段。在训练阶段,非接触读卡器获取用户终端侧的非接触射频参数信息、非接触协议参数、终端SE信息(即历史射频信息)、终端NFC路由表信息(即与可识别卡片历史绑定的应用信息)进行特征训练,进行特征选择,提取其中的特定字段,使用朴素贝叶斯等机器学习算法生成用户识别库;在认证阶段,非接触读卡器获取用户终端侧的非接触射频参数信息、非接触协议参数、终端SE信息、终端NFC路由表信息中的特定字段,根据机器学习算法生成用户特征码,与用户识别库中的信息进行匹配,判断该用户是否通过认证,生成用户认证结果。Step 711, the non-contact card reader performs authentication processing, which mainly includes two stages of user identification training and authentication. In the training phase, the contactless card reader obtains the contactless radio frequency parameter information, contactless protocol parameters, terminal SE information (that is, historical radio frequency information) and terminal NFC routing table Application information) for feature training, feature selection, extracting specific fields, and using machine learning algorithms such as naive Bayesian to generate a user identification library; in the authentication phase, the contactless card reader obtains the contactless radio frequency parameter information on the user terminal side , non-contact protocol parameters, terminal SE information, specific fields in terminal NFC routing table information, generate user signatures according to machine learning algorithms, match with information in the user identification database, determine whether the user is authenticated, and generate user authentication results .

如图8所示,提供一种使用业务平台进行在线用户认证的主要流程图。包括以下步骤801至步骤815:As shown in FIG. 8 , a main flow chart of online user authentication using a service platform is provided. Including the following steps 801 to 815:

步骤801,非接触读卡器发起寻卡请求;Step 801, the non-contact card reader initiates a card search request;

步骤802,终端返回,并与非接触读卡器建立非接触通信连接;Step 802, the terminal returns, and establishes a contactless communication connection with the contactless card reader;

步骤803,非接触读卡器侧的非接触通信模块向终端认证模块返回连接建立结果,以及卡类型、卡支持的通信协议;Step 803, the non-contact communication module on the non-contact card reader side returns the connection establishment result, card type, and communication protocol supported by the card to the terminal authentication module;

步骤804,非接触读卡器侧选择在线用户认证方式;Step 804, the non-contact card reader side selects an online user authentication method;

步骤805,非接触读卡器向业务平台发起在线认证申请;Step 805, the non-contact card reader initiates an online authentication application to the business platform;

步骤806,业务平台发起认证请求;Step 806, the service platform initiates an authentication request;

步骤807,非接触读卡器内部传送认证请求;Step 807, the contactless card reader internally transmits the authentication request;

步骤808,非接触读卡器侧的非接触通信模块发出认证指令;Step 808, the non-contact communication module on the side of the non-contact card reader sends an authentication instruction;

步骤809,终端侧的NFC芯片接收认证指令,并传给刷卡行为模块;Step 809, the NFC chip on the terminal side receives the authentication instruction and transmits it to the card swiping behavior module;

步骤810,终端侧的刷卡行为模块获取终端的非接触射频参数信息,包括天线尺寸S,工作场强H,负载调制深度U,谐振频率M等,非接触协议参数,包括ATQA、UID、SAK、FWI、SFGI等,终端SE信息,包括eSE、NFC-SIM信息,终端NFC路由表信息,如上表1所示,反馈给NFC芯片;Step 810, the card swiping behavior module on the terminal side obtains the terminal's non-contact radio frequency parameter information, including antenna size S, working field strength H, load modulation depth U, resonance frequency M, etc., non-contact protocol parameters, including ATQA, UID, SAK, FWI, SFGI, etc., terminal SE information, including eSE, NFC-SIM information, terminal NFC routing table information, as shown in Table 1 above, is fed back to the NFC chip;

步骤811,终端侧的NFC芯片向非接触读卡器侧的非接触通信模块返回终端刷卡信息;Step 811, the NFC chip on the terminal side returns terminal card swiping information to the contactless communication module on the contactless card reader side;

步骤812,非接触读卡器内部传送终端刷卡信息;Step 812, the contactless card reader internally transmits the terminal card swiping information;

步骤813,非接触读卡器向业务平台发送终端刷卡信息;Step 813, the non-contact card reader sends terminal card swiping information to the business platform;

步骤814,业务平台进行认证处理,主要包括用户识别训练和认证两个阶段。在训练阶段,业务平台侧获取用户终端的非接触射频参数信息、非接触协议参数、终端SE信息、终端NFC路由表信息进行特征训练,进行特征选择,提取其中的特定字段,使用朴素贝叶斯等机器学习算法生成用户识别库;在认证阶段,业务平台侧获取用户终端的非接触射频参数信息、非接触协议参数、终端SE信息、终端NFC路由表信息中的特定字段,根据机器学习算法生成用户特征码,与用户识别库中的信息进行匹配,判断该用户是否通过认证,生成用户认证结果;Step 814, the service platform performs authentication processing, which mainly includes two stages of user identification training and authentication. In the training phase, the service platform side obtains the user terminal’s non-contact radio frequency parameter information, non-contact protocol parameters, terminal SE information, and terminal NFC routing table information for feature training, selects features, extracts specific fields, and uses Naive Bayesian and other machine learning algorithms to generate a user identification library; in the authentication phase, the service platform side obtains the user terminal's non-contact radio frequency parameter information, non-contact protocol parameters, terminal SE information, and specific fields in the terminal NFC routing table information, and generates a database based on the machine learning algorithm. The user signature code is matched with the information in the user identification database to determine whether the user has passed the authentication and generate a user authentication result;

步骤815,业务平台向读卡器下发用户认证结果,进行显示。Step 815, the service platform sends the user authentication result to the card reader for display.

在本申请实施例中,根据用户在终端上使用NFC刷卡的相关信息,实现对用户真实身份的刻画,完成对用户本人的认证,提升认证安全性;用户在非接触的刷卡或打开应用(application,APP)时无感知完成认证,业务上使用便捷。In this embodiment of the application, according to the relevant information of the user using NFC card swiping on the terminal, the description of the user's real identity is realized, the user's own authentication is completed, and the authentication security is improved; the user swipes the card or opens the application without contact , APP) completes the authentication without perception, and is convenient for business use.

应当注意,尽管在附图中以特定顺序描述了本申请中方法的各个步骤,但是,这并非要求或者暗示必须按照该特定顺序来执行这些步骤,或是必须执行全部所示的步骤才能实现期望的结果。附加的或备选的,可以省略某些步骤,将多个步骤合并为一个步骤执行,以及/或者将一个步骤分解为多个步骤执行等;或者,将不同实施例中步骤组合为新的技术方案。It should be noted that although the steps of the method in the present application are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all shown steps must be performed to achieve the desired the result of. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and/or one step may be decomposed into multiple steps for execution, etc.; or, the steps in different embodiments may be combined into a new technology plan.

基于前述的实施例,本申请实施例提供一种用户认证装置,该装置包括所包括的各模块、以及各模块所包括的各单元,可以通过处理器来实现;当然也可通过具体的逻辑电路实现;在实施的过程中,处理器可以为中央处理器(CPU)、微处理器(MPU)、数字信号处理器(DSP)或现场可编程门阵列(FPGA)等。Based on the aforementioned embodiments, this embodiment of the present application provides a user authentication device, which includes each module included, and each unit included in each module, which can be realized by a processor; of course, it can also be implemented by a specific logic circuit Implementation; in the process of implementation, the processor may be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP) or a field programmable gate array (FPGA).

图9为本申请实施例提供的用户认证装置的结构示意图,如图9所示,所述装置900包括通信单元901、获取单元902和认证单元903,其中:FIG. 9 is a schematic structural diagram of a user authentication device provided in an embodiment of the present application. As shown in FIG. 9, the device 900 includes a communication unit 901, an acquisition unit 902, and an authentication unit 903, wherein:

通信单元901,用于与可识别卡片建立通信连接;获取单元902,用于获取与所述可识别卡片当前绑定的应用信息;认证单元903,用于至少根据所述当前绑定的应用信息以及与所述可识别卡片历史绑定的应用信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。The communication unit 901 is configured to establish a communication connection with the identifiable card; the obtaining unit 902 is configured to obtain the application information currently bound to the identifiable card; the authentication unit 903 is configured to at least according to the currently bound application information As well as the application information bound with the history of the identifiable card, the identity authentication of the user currently using the identifiable card is performed to determine whether to perform a card swiping operation on the identifiable card.

在一些实施例中,获取单元902,用于获取所述可识别卡片支持的射频信息;认证单元903,用于根据所述当前绑定的应用信息、所述与所述可识别卡片历史绑定的应用信息和所述射频信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。In some embodiments, the obtaining unit 902 is configured to obtain the radio frequency information supported by the identifiable card; the authentication unit 903 is configured to use the currently bound application information, the history binding with the identifiable card The application information and the radio frequency information are used to authenticate the user currently using the identifiable card, so as to determine whether to swipe the identifiable card.

在一些实施例中,所述装置还包括匹配单元和确定单元,所述匹配单元,用于将所述可识别卡片支持的射频信息和预先存储的至少一个历史射频信息进行匹配,得到第一匹配结果;将所述当前绑定的应用信息和所述与所述可识别卡片历史绑定的应用信息进行匹配,得到第二匹配结果;所述确定单元,用于在所述第一匹配结果和所述第二匹配结果为匹配成功的情况下,确定对当前使用所述可识别卡片的用户的身份认证成功,并对所述可识别卡片执行刷卡操作。In some embodiments, the device further includes a matching unit and a determining unit, the matching unit is configured to match the radio frequency information supported by the identifiable card with at least one pre-stored historical radio frequency information to obtain the first matching Result; match the currently bound application information with the historically bound application information of the identifiable card to obtain a second matching result; the determining unit is configured to combine the first matching result and the If the second matching result is successful matching, it is determined that the identity authentication of the user currently using the identifiable card is successful, and a card swiping operation is performed on the identifiable card.

在一些实施例中,所述装置还包括发送单元和接收单元,所述发送单元,用于向所述可识别卡片发送离线认证指令,以便所述可识别卡片根据所述离线认证指令获取所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息;所述接收单元,用于接收所述可识别卡片发送的所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息。In some embodiments, the device further includes a sending unit and a receiving unit, the sending unit is configured to send an offline authentication instruction to the identifiable card, so that the identifiable card can obtain the The application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card; the receiving unit is configured to receive the information currently bound to the identifiable card sent by the identifiable card Application information and radio frequency information supported by the identifiable card.

在一些实施例中,所述发送单元,用于向业务平台发起在线认证请求;所述接收单元,用于接收所述业务平台基于所述在线认证请求返回的在线认证指令;所述发送单元,还用于向所述可识别卡片发送所述在线认证指令,以便所述可识别卡片根据所述在线认证指令获取所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息;所述接收单元,还用于接收所述可识别卡片发送的所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息。In some embodiments, the sending unit is configured to initiate an online authentication request to the service platform; the receiving unit is configured to receive an online authentication instruction returned by the service platform based on the online authentication request; the sending unit, It is also used to send the online authentication instruction to the identifiable card, so that the identifiable card obtains the application information currently bound to the identifiable card and the identifiable card support information according to the online authentication instruction. the radio frequency information; the receiving unit is further configured to receive the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card sent by the identifiable card.

在一些实施例中,所述发送单元,用于将所述当前绑定的应用信息和所述射频信息上传至所述业务平台,以便所述业务平台根据所述当前绑定的应用信息、预先存储的与所述可识别卡片历史绑定的应用信息和所述射频信息,对当前使用所述可识别卡片的用户进行身份认证,得到认证结果;所述接收单元,用于接收所述业务平台发送的所述认证结果。In some embodiments, the sending unit is configured to upload the currently bound application information and the radio frequency information to the service platform, so that the service platform, according to the currently bound application information, The stored application information and the radio frequency information that are bound with the history of the identifiable card are used to authenticate the user currently using the identifiable card and obtain an authentication result; the receiving unit is configured to receive the service platform The authentication result sent.

以上装置实施例的描述,与上述方法实施例的描述是类似的,具有同方法实施例相似的有益效果。对于本申请装置实施例中未披露的技术细节,请参照本申请方法实施例的描述而理解。The description of the above device embodiment is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

需要说明的是,本申请实施例中图9所示的用户认证装置对模块的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。也可以采用软件和硬件结合的形式实现。It should be noted that the division of modules by the user authentication device shown in FIG. 9 in the embodiment of the present application is schematic, and is only a logical function division. In actual implementation, there may be other division methods. In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or physically exist separately, or two or more units may be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units. It can also be implemented in the form of a combination of software and hardware.

需要说明的是,本申请实施例中,如果以软件功能模块的形式实现上述的方法,并作为独立的产品销售或使用时,也可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请实施例的技术方案本质上或者说对相关技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得电子设备执行本申请各个实施例所述方法的全部或部分。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read Only Memory,ROM)、磁碟或者光盘等各种可以存储程序代码的介质。这样,本申请实施例不限制于任何特定的硬件和软件结合。It should be noted that, in the embodiment of the present application, if the above method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the essence of the technical solutions of the embodiments of the present application or the part that contributes to related technologies can be embodied in the form of software products. The computer software products are stored in a storage medium and include several instructions to make The electronic device executes all or part of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media capable of storing program codes such as a U disk, a mobile hard disk, a read only memory (Read Only Memory, ROM), a magnetic disk, or an optical disk. Thus, embodiments of the present application are not limited to any specific combination of hardware and software.

本申请实施例提供一种用户认证系统,所述用户认证系统包括可识别卡片和非接触读卡器;其中,所述可识别卡片,用于获取与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息,并发送给所述非接触读卡器;所述非接触读卡器,用于基于所述可识别卡片发送的与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息,对当前使用所述可识别卡片的用户进行离线身份认证,以确定是否对所述可识别卡片执行刷卡操作。An embodiment of the present application provides a user authentication system, the user authentication system includes an identifiable card and a contactless card reader; wherein the identifiable card is used to obtain application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card, and send it to the non-contact card reader; Using the information and the radio frequency information supported by the identifiable card, offline identity authentication is performed on the user currently using the identifiable card, so as to determine whether to perform a card swiping operation on the identifiable card.

本申请实施例提供一种用户认证系统,所述用户认证系统至少包括可识别卡片、非接触读卡器和业务平台;其中,所述可识别卡片,用于获取与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息,并发送给所述非接触读卡器;所述非接触读卡器,用于将接收到的与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息上传至所述业务平台;所述业务平台,用于基于所述非接触读卡器发送的与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息,对当前使用所述可识别卡片的用户进行在线身份认证,以确定是否对所述可识别卡片执行刷卡操作。An embodiment of the present application provides a user authentication system, the user authentication system includes at least an identifiable card, a contactless card reader, and a service platform; wherein the identifiable card is used to obtain the The specified application information and the radio frequency information supported by the identifiable card are sent to the contactless card reader; The application information and the radio frequency information supported by the identifiable card are uploaded to the service platform; The radio frequency information supported by the identifiable card is used to perform online identity authentication on the user currently using the identifiable card, so as to determine whether to swipe the identifiable card.

本申请实施例提供一种电子设备,图10为本申请实施例的电子设备的硬件实体示意图,如图10所示,所述电子设备100包括存储器101和处理器102,所述存储器101存储有可在处理器102上运行的计算机程序,所述处理器102执行所述程序时实现上述实施例中提供的方法中的步骤。An embodiment of the present application provides an electronic device. FIG. 10 is a schematic diagram of a hardware entity of the electronic device according to the embodiment of the present application. As shown in FIG. 10 , the electronic device 100 includes a memory 101 and a processor 102, and the memory 101 stores A computer program that can run on the processor 102, and the processor 102 implements the steps in the methods provided in the above-mentioned embodiments when executing the program.

需要说明的是,存储器101配置为存储由处理器102可执行的指令和应用,还可以缓存在处理器102以及电子设备100中各模块待处理或已经处理的数据(例如,图像数据、音频数据、语音通信数据和视频通信数据),可以通过闪存(FLASH)或随机访问存储器(RandomAccess Memory,RAM)实现。It should be noted that the memory 101 is configured to store instructions and applications executable by the processor 102, and may also cache data to be processed or processed by each module in the processor 102 and the electronic device 100 (for example, image data, audio data, etc. , voice communication data and video communication data), can be implemented by flash memory (FLASH) or random access memory (Random Access Memory, RAM).

本申请实施例提供一种计算机可读存储介质,其上存储有计算机程序,该计算机程序被处理器执行时实现上述实施例中提供的方法中的步骤。An embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the methods provided in the foregoing embodiments are implemented.

本申请实施例提供了一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机执行上述方法实施例提供的方法中的步骤。The embodiment of the present application provides a computer program product containing instructions, which when run on a computer, causes the computer to execute the steps in the method provided by the above method embodiment.

这里需要指出的是:以上存储介质和设备实施例的描述,与上述方法实施例的描述是类似的,具有同方法实施例相似的有益效果。对于本申请存储介质、存储介质和设备实施例中未披露的技术细节,请参照本申请方法实施例的描述而理解。It should be pointed out here that: the descriptions of the above storage medium and device embodiments are similar to the descriptions of the above method embodiments, and have similar beneficial effects to those of the method embodiments. For technical details not disclosed in the storage medium, storage medium, and device embodiments of the present application, please refer to the description of the method embodiment of the present application for understanding.

应理解,说明书通篇中提到的“一个实施例”或“一实施例”或“一些实施例”意味着与实施例有关的特定特征、结构或特性包括在本申请的至少一个实施例中。因此,在整个说明书各处出现的“在一个实施例中”或“在一实施例中”或“在一些实施例中”未必一定指相同的实施例。此外,这些特定的特征、结构或特性可以任意适合的方式结合在一个或多个实施例中。应理解,在本申请的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。上述本申请实施例序号仅仅为了描述,不代表实施例的优劣。上文对各个实施例的描述倾向于强调各个实施例之间的不同之处,其相同或相似之处可以互相参考,为了简洁,本文不再赘述。It should be understood that reference throughout this specification to "one embodiment" or "an embodiment" or "some embodiments" means that a particular feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the present application . Thus, appearances of "in one embodiment" or "in an embodiment" or "in some embodiments" in various places throughout the specification are not necessarily referring to the same embodiments. Furthermore, the particular features, structures or characteristics may be combined in any suitable manner in one or more embodiments. It should be understood that, in various embodiments of the present application, the sequence numbers of the above-mentioned processes do not mean the order of execution, and the execution order of the processes should be determined by their functions and internal logic, and should not be used in the embodiments of the present application. The implementation process constitutes any limitation. The serial numbers of the above embodiments of the present application are for description only, and do not represent the advantages and disadvantages of the embodiments. The above descriptions of the various embodiments tend to emphasize the differences between the various embodiments, and the same or similar points can be referred to each other, and for the sake of brevity, details are not repeated herein.

本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如对象A和/或对象B,可以表示:单独存在对象A,同时存在对象A和对象B,单独存在对象B这三种情况。The term "and/or" in this article is just an association relationship describing associated objects, which means that there can be three relationships, such as object A and/or object B, which can mean: object A exists alone, and object A and object exist at the same time B, there are three situations of object B alone.

需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者设备中还存在另外的相同要素。It should be noted that, in this document, the term "comprising", "comprising" or any other variation thereof is intended to cover a non-exclusive inclusion such that a process, method, article or apparatus comprising a set of elements includes not only those elements, It also includes other elements not expressly listed, or elements inherent in the process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article or apparatus comprising that element.

在本申请所提供的几个实施例中,应该理解到,所揭露的设备和方法,可以通过其它的方式实现。以上所描述的实施例仅仅是示意性的,例如,所述模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,如:多个模块或组件可以结合,或可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的各组成部分相互之间的耦合、或直接耦合、或通信连接可以是通过一些接口,设备或模块的间接耦合或通信连接,可以是电性的、机械的或其它形式的。In the several embodiments provided in this application, it should be understood that the disclosed devices and methods may be implemented in other ways. The above-described embodiments are only illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods, such as: multiple modules or components can be combined, or can be Integrate into another system, or some features may be ignored, or not implemented. In addition, the mutual coupling, or direct coupling, or communication connection between the various components shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or modules may be in electrical, mechanical or other forms of.

上述作为分离部件说明的模块可以是、或也可以不是物理上分开的,作为模块显示的部件可以是、或也可以不是物理模块;既可以位于一个地方,也可以分布到多个网络单元上;可以根据实际的需要选择其中的部分或全部模块来实现本实施例方案的目的。The modules described above as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules; they may be located in one place or distributed to multiple network units; Part or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

另外,在本申请各实施例中的各功能模块可以全部集成在一个处理单元中,也可以是各模块分别单独作为一个单元,也可以两个或两个以上模块集成在一个单元中;上述集成的模块既可以采用硬件的形式实现,也可以采用硬件加软件功能单元的形式实现。In addition, each functional module in each embodiment of the present application can be integrated into one processing unit, or each module can be used as a single unit, or two or more modules can be integrated into one unit; the above-mentioned integration The modules can be implemented in the form of hardware, or in the form of hardware plus software functional units.

本领域普通技术人员可以理解:实现上述方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成,前述的程序可以存储于计算机可读取存储介质中,该程序在执行时,执行包括上述方法实施例的步骤;而前述的存储介质包括:移动存储设备、只读存储器(Read Only Memory,ROM)、磁碟或者光盘等各种可以存储程序代码的介质。Those of ordinary skill in the art can understand that all or part of the steps to realize the above method embodiments can be completed by hardware related to program instructions, and the aforementioned programs can be stored in computer-readable storage media. When the program is executed, the execution includes: The steps of the above-mentioned method embodiments; and the aforementioned storage medium includes: various media capable of storing program codes such as removable storage devices, read only memory (ROM), magnetic disks or optical disks.

或者,本申请上述集成的单元如果以软件功能模块的形式实现并作为独立的产品销售或使用时,也可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请实施例的技术方案本质上或者说对相关技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得电子设备执行本申请各个实施例所述方法的全部或部分。而前述的存储介质包括:移动存储设备、ROM、磁碟或者光盘等各种可以存储程序代码的介质。Alternatively, if the above-mentioned integrated units of the present application are realized in the form of software function modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the essence of the technical solutions of the embodiments of the present application or the part that contributes to the related technologies can be embodied in the form of software products. The computer software products are stored in a storage medium and include several instructions to make The electronic device executes all or part of the methods described in the various embodiments of the present application. The aforementioned storage medium includes various media capable of storing program codes such as removable storage devices, ROMs, magnetic disks or optical disks.

本申请所提供的几个方法实施例中所揭露的方法,在不冲突的情况下可以任意组合,得到新的方法实施例。The methods disclosed in several method embodiments provided in this application can be combined arbitrarily to obtain new method embodiments under the condition of no conflict.

本申请所提供的几个产品实施例中所揭露的特征,在不冲突的情况下可以任意组合,得到新的产品实施例。The features disclosed in several product embodiments provided in this application can be combined arbitrarily without conflict to obtain new product embodiments.

本申请所提供的几个方法或设备实施例中所揭露的特征,在不冲突的情况下可以任意组合,得到新的方法实施例或设备实施例。The features disclosed in several method or device embodiments provided in this application can be combined arbitrarily without conflict to obtain new method embodiments or device embodiments.

以上所述,仅为本申请的实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。The above is only the embodiment of the present application, but the scope of protection of the present application is not limited thereto. Anyone familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, and should covered within the scope of protection of this application. Therefore, the protection scope of the present application should be determined by the protection scope of the claims.

Claims (11)

1.一种用户认证方法,其特征在于,所述方法包括:1. A user authentication method, characterized in that the method comprises: 与可识别卡片建立通信连接;Establish a communication connection with the identifiable card; 获取与所述可识别卡片当前绑定的应用信息;Acquiring application information currently bound to the identifiable card; 至少根据所述当前绑定的应用信息以及与所述可识别卡片历史绑定的应用信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。At least according to the currently bound application information and the application information bound with the history of the identifiable card, perform identity authentication on the user currently using the identifiable card to determine whether to perform a card swiping operation on the identifiable card . 2.根据权利要求1所述的方法,其特征在于,所述至少根据所述当前绑定的应用信息以及与所述可识别卡片历史绑定的应用信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作,包括:2. The method according to claim 1, wherein at least based on the currently bound application information and the historically bound application information of the identifiable card, the currently using the identifiable card The user performs identity authentication to determine whether to perform a card swiping operation on the identifiable card, including: 获取所述可识别卡片支持的射频信息;Obtain radio frequency information supported by the identifiable card; 根据所述当前绑定的应用信息、所述与所述可识别卡片历史绑定的应用信息和所述射频信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。According to the currently bound application information, the historically bound application information with the identifiable card, and the radio frequency information, perform identity authentication on the user currently using the identifiable card to determine whether to authenticate the Cards can be recognized to perform card swiping operations. 3.根据权利要求2所述的方法,其特征在于,所述根据所述当前绑定的应用信息、所述与所述可识别卡片历史绑定的应用信息和所述射频信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作,包括:3. The method according to claim 2, wherein, according to the currently bound application information, the historically bound application information and the radio frequency information of the identifiable card, the currently used The user of the identifiable card performs identity authentication to determine whether to perform a card swiping operation on the identifiable card, including: 将所述可识别卡片支持的射频信息和预先存储的至少一个历史射频信息进行匹配,得到第一匹配结果;matching the radio frequency information supported by the identifiable card with at least one piece of pre-stored historical radio frequency information to obtain a first matching result; 将所述当前绑定的应用信息和所述与所述可识别卡片历史绑定的应用信息进行匹配,得到第二匹配结果;matching the currently bound application information with the historically bound application information of the identifiable card to obtain a second matching result; 在所述第一匹配结果和所述第二匹配结果为匹配成功的情况下,确定对当前使用所述可识别卡片的用户的身份认证成功,并对所述可识别卡片执行刷卡操作。If the first matching result and the second matching result are successful matching, it is determined that the identity authentication of the user currently using the identifiable card is successful, and a card swiping operation is performed on the identifiable card. 4.根据权利要求2所述的方法,其特征在于,在所述用户认证方式为离线认证的情况下,所述获取与所述可识别卡片当前绑定的应用信息和获取所述可识别卡片支持的射频信息,包括:4. The method according to claim 2, wherein when the user authentication method is offline authentication, the acquiring the application information currently bound to the identifiable card and acquiring the identifiable card Supported RF information, including: 向所述可识别卡片发送离线认证指令,以便所述可识别卡片根据所述离线认证指令获取所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息;Sending an offline authentication instruction to the identifiable card, so that the identifiable card obtains the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card according to the offline authentication instruction; 接收所述可识别卡片发送的所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息。receiving the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card sent by the identifiable card. 5.根据权利要求2所述的方法,其特征在于,在所述用户认证方式为在线认证的情况下,所述获取与所述可识别卡片当前绑定的应用信息和获取所述可识别卡片支持的射频信息,包括:5. The method according to claim 2, wherein when the user authentication method is online authentication, the acquiring the application information currently bound to the identifiable card and acquiring the identifiable card Supported RF information, including: 向业务平台发起在线认证请求;Initiate an online authentication request to the business platform; 接收所述业务平台基于所述在线认证请求返回的在线认证指令;receiving an online authentication instruction returned by the service platform based on the online authentication request; 向所述可识别卡片发送所述在线认证指令,以便所述可识别卡片根据所述在线认证指令获取所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息;sending the online authentication instruction to the identifiable card, so that the identifiable card obtains the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card according to the online authentication instruction ; 接收所述可识别卡片发送的所述与所述可识别卡片当前绑定的应用信息和所述可识别卡片支持的射频信息。receiving the application information currently bound to the identifiable card and the radio frequency information supported by the identifiable card sent by the identifiable card. 6.根据权利要求5所述的方法,其特征在于,所述根据所述当前绑定的应用信息、所述与所述可识别卡片历史绑定的应用信息和所述射频信息,对当前使用所述可识别卡片的用户进行身份认证,包括:6. The method according to claim 5, wherein, according to the currently bound application information, the application information bound with the identifiable card history, and the radio frequency information, the currently used The identity authentication of the user of the identifiable card includes: 将所述当前绑定的应用信息和所述射频信息上传至所述业务平台,以便所述业务平台根据所述当前绑定的应用信息、预先存储的与所述可识别卡片历史绑定的应用信息和所述射频信息,对当前使用所述可识别卡片的用户进行身份认证,得到认证结果;uploading the currently bound application information and the radio frequency information to the service platform, so that the service platform, according to the currently bound application information, pre-stored historically bound applications with the identifiable card information and the radio frequency information, and perform identity authentication on the user currently using the identifiable card, and obtain an authentication result; 接收所述业务平台发送的所述认证结果。Receive the authentication result sent by the service platform. 7.根据权利要求2或3任一项所述的方法,其特征在于,所述可识别卡片支持的射频信息至少包括以下至少之一:物理射频信息、射频协议信息、安全元件SE信息。7. The method according to any one of claims 2 or 3, wherein the radio frequency information supported by the identifiable card includes at least one of the following: physical radio frequency information, radio frequency protocol information, and secure element SE information. 8.根据权利要求1所述的方法,其特征在于,所述与可识别卡片建立通信连接包括:与所述可识别卡片建立近场通信NFC连接。8. The method according to claim 1, wherein said establishing a communication connection with the identifiable card comprises: establishing a near field communication (NFC) connection with the identifiable card. 9.一种用户认证装置,其特征在于,包括:9. A user authentication device, characterized in that it comprises: 通信单元,用于与可识别卡片建立通信连接;a communication unit, configured to establish a communication connection with the identifiable card; 获取单元,用于获取与所述可识别卡片当前绑定的应用信息;an acquiring unit, configured to acquire application information currently bound to the identifiable card; 认证单元,用于至少根据所述当前绑定的应用信息以及与所述可识别卡片历史绑定的应用信息,对当前使用所述可识别卡片的用户进行身份认证,以确定是否对所述可识别卡片执行刷卡操作。An authentication unit, configured to authenticate the user currently using the identifiable card according to at least the currently bound application information and the historically bound application information of the identifiable card, so as to determine whether to authenticate the identifiable card Recognize the card and perform the card swiping operation. 10.一种电子设备,包括存储器和处理器,所述存储器存储有可在处理器上运行的计算机程序,其特征在于,所述处理器执行所述程序时实现权利要求1至8任一项所述的方法。10. An electronic device comprising a memory and a processor, the memory stores a computer program that can run on the processor, wherein any one of claims 1 to 8 is implemented when the processor executes the program the method described. 11.一种计算机可读存储介质,其上存储有计算机程序,其特征在于,该计算机程序被处理器执行时实现如权利要求1至8任一项所述的方法。11. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
CN202111593048.4A 2021-12-23 2021-12-23 User authentication method and device, equipment, storage medium Pending CN116347406A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202111593048.4A CN116347406A (en) 2021-12-23 2021-12-23 User authentication method and device, equipment, storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202111593048.4A CN116347406A (en) 2021-12-23 2021-12-23 User authentication method and device, equipment, storage medium

Publications (1)

Publication Number Publication Date
CN116347406A true CN116347406A (en) 2023-06-27

Family

ID=86890111

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202111593048.4A Pending CN116347406A (en) 2021-12-23 2021-12-23 User authentication method and device, equipment, storage medium

Country Status (1)

Country Link
CN (1) CN116347406A (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2026001649A1 (en) * 2024-06-29 2026-01-02 华为技术有限公司 Card management method and related apparatus

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102005056274A1 (en) * 2005-11-14 2007-06-14 Automaten-Seitz Vertrieb & Kundendienst Gesellschaft mit beschränkter Haftung Chip card e.g. mifare-DESFire card, system operating method for e.g. cash box, involves replacing application area key by updating key, when chip card enters activation area of writing-/reading unit, and when keys are not coincided
US20120313754A1 (en) * 2011-06-13 2012-12-13 X-Card Holdings, Llc Biometric smart card reader
US20140229371A1 (en) * 2011-09-30 2014-08-14 Rakuten, Inc. Payment system and payment terminal
WO2019041357A1 (en) * 2017-09-04 2019-03-07 深圳传音通讯有限公司 Application display method, apparatus, and computer readable storage medium
US20200396325A1 (en) * 2018-02-08 2020-12-17 Huawei Technologies Co., Ltd. Application switching method and terminal
CN112492518A (en) * 2020-12-09 2021-03-12 深圳市欢太科技有限公司 Card determination method and device, electronic equipment and storage medium
CN113422624A (en) * 2021-08-25 2021-09-21 北京紫光青藤微系统有限公司 Card application routing method and device

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE102005056274A1 (en) * 2005-11-14 2007-06-14 Automaten-Seitz Vertrieb & Kundendienst Gesellschaft mit beschränkter Haftung Chip card e.g. mifare-DESFire card, system operating method for e.g. cash box, involves replacing application area key by updating key, when chip card enters activation area of writing-/reading unit, and when keys are not coincided
US20120313754A1 (en) * 2011-06-13 2012-12-13 X-Card Holdings, Llc Biometric smart card reader
US20140229371A1 (en) * 2011-09-30 2014-08-14 Rakuten, Inc. Payment system and payment terminal
WO2019041357A1 (en) * 2017-09-04 2019-03-07 深圳传音通讯有限公司 Application display method, apparatus, and computer readable storage medium
US20200396325A1 (en) * 2018-02-08 2020-12-17 Huawei Technologies Co., Ltd. Application switching method and terminal
CN112492518A (en) * 2020-12-09 2021-03-12 深圳市欢太科技有限公司 Card determination method and device, electronic equipment and storage medium
CN113422624A (en) * 2021-08-25 2021-09-21 北京紫光青藤微系统有限公司 Card application routing method and device

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2026001649A1 (en) * 2024-06-29 2026-01-02 华为技术有限公司 Card management method and related apparatus

Similar Documents

Publication Publication Date Title
US12112310B2 (en) Authentication for third party digital wallet provisioning
JP7792466B2 (en) First factor contactless card authentication system and method
JP6629952B2 (en) Method and apparatus for securing mobile applications
US9438575B2 (en) Smart phone login using QR code
US10872337B2 (en) Payment device and system
US11055720B2 (en) Payment verification method and apparatus
US20130166456A1 (en) System and Method for Remote Payment Based on Mobile Terminal
US8751404B2 (en) Method and mobile terminal for realizing network payment
WO2012155620A1 (en) Method and mobile communication terminal for protecting near field communication security
EP2518670A1 (en) System and method for remote payment based on mobile terminal
US20170202040A1 (en) Dongle device for automatic pairing to a local device
CN105898418A (en) Intelligent terminal, remote controller, and intelligent terminal payment method
WO2023288037A1 (en) Device and systems for remotely provisioning sim profile with strong identity and strong authentication
JP7223753B2 (en) payment processing
CN107005575A (en) A kind of smart card and its method of work with dynamic token OTP functions
CN116347406A (en) User authentication method and device, equipment, storage medium
CN110582771B (en) Method and device for performing authentication based on biometric information
CN101303755A (en) Electronic mobile device and electronic transaction method
CN105405010B (en) Trading device, trading system and trading method using the same
CN108665267A (en) Safety certification device and system
Wang et al. Method of internet service easy login application based on RFSIM
CN106941615B (en) A payment method, set-top box and system
KR101808087B1 (en) Payment method and payment system using wlan fingerprint
HK40094708A (en) Establishing authentication persistence
CN114756838A (en) Identity authentication method, device, equipment and storage medium

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination