IP Library Granted Patent US 10,412,585
Granted Patent B2
US 10,412,585 · App. 15/745,347 · Granted Sep 10, 2019

User identity authentication method and device

Inventors: Yuanqing Zeng (Dongguan, CN); Hai Tang (Dongguan, CN)
Assignee: GUANGDONG OPPO MOBILE TELECOMMUNICAIONS CORP., LTD.
H04W12/06H04L9/32H04L9/3231H04L9/3247H04L9/3263H04L63/0823H04W8/183H04W12/08H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,412,585
App. No.
15/745,347
Granted
Sep 10, 2019
Kind
B2
Abstract

A user identity authentication method is provided, which includes that: a Service Provider (SP) device receives a user request sent by a terminal, the user request including an identity credential of a user; the SP device determines an Identifier (ID) of the user and a priority of the identity credential according to the user request; and the SP device enables corresponding service for the terminal according to the priority. In the embodiment, the SP device provides the corresponding service according to the identity credential of the user. Therefore, a Unified security identity authentication manner may be implemented, usability is improved, and optimal utilization of resources may be implemented.

Claims (89)

1. A user identity authentication method, comprising:

acquiring, by an identity authentication server, a user request from a Service Provider (SP) device, the user request comprising an identity credential of a user;

determining, by the identity authentication server, an Identifier (ID) of the user and a priority of the identity credential according to the user request; and

sending, by the identity authentication server, the ID of the user and the priority of the identity credential to the SP device for enabling a corresponding service for the user;

wherein the identity credential comprises a primary credential and a secondary credential,

wherein the primary credential comprises at least one of: a DeoxyriboNucleic Acid (DNA), a fingerprint, an iris and a voiceprint,

wherein the secondary credential comprises at least one of: a digital certificate, a digital signature, a user card and a password, and

wherein a priority of the primary credential is higher than a priority of the secondary credential.

2. The method according to claim 1 , wherein the identity credential is generated at a terminal by processing with a generation method, and

wherein the determining an ID of the user and a priority of the identity credential according to the user request comprises:

processing the identity credential by adopting a verification method; and

acquiring the ID and the priority corresponding to the processed identity credential according to a prestored corresponding relationship.

3. A user identity authentication method, comprising:

receiving, by a terminal, an identity credential input by a user;

determining, by the terminal, an Identity (ID) of the user and a priority of the identity credential according to the identity credential;

acquiring, by the terminal, subscription information of the user according to the ID of the user; and

determining a service corresponding to the priority of the identity credential according to the subscription information;

wherein the identity credential comprises a primary credential and a secondary credential,

wherein the primary credential comprises at least one of: a DeoxyriboNucleic Acid (DNA), a fingerprint, an iris and a voiceprint,

wherein the secondary credential comprises at least one of: a digital certificate, a digital signature, a user card and a password, and

wherein a priority of the primary credential is higher than a priority of the secondary credential.

4. The method according to claim 3 , wherein before the terminal receives the identity credential input by the user, the method further comprises:

receiving, by the terminal, first selection information input by the user, the first selection information indicating a first operator selected by the user;

receiving, by the terminal, a user request input by the user, the user request comprising the identity credential; and

sending, by the terminal, the user request to a first Service Provider (SP) device of the first operator.

5. The method according to claim 4 , further comprising:

after the first SP device indicates that the identity credential of the terminal passes authentication, accessing, by the terminal, a network of the first operator through the first SP device.

6. The method according to claim 4 , further comprising:

acquiring, by the terminal, the subscription information of the user through the first SP device.

7. The method according to claim 4 , further comprising at least one of the following:

receiving, by the terminal, a first corresponding relationship sent by the first SP device, the first corresponding relationship comprising a corresponding relationship among the ID of the user, the identity credential and the priority of the identity credential;

or,

receiving, by the terminal, a second corresponding relationship sent by the first SP device, the second corresponding relationship comprising a corresponding relationship between the priority of the identity credential and the service.

8. The method according to claim 4 , further comprising:

receiving, by the terminal, an instruction of the user, the instruction indicating that the user is to reselect an operator;

receiving, by the terminal, second selection information of the user, the second selection information indicating a second operator selected by the user;

sending, by the terminal, the user request to a second SP device of the second operator; and

after the second SP device indicates that the terminal passes authentication, accessing, by the terminal, a network of the second operator through the second SP device.

9. The method according to claim 4 , further comprising:

receiving, by the terminal, a temporary quitting instruction of the user; and

suspending, by the terminal, user data of the user according to the temporary quitting instruction.

10. The method according to claim 3 , further comprising:

receiving, by the terminal, a service request of the user; and

when a service indicated by the service request is not the service corresponding to the priority of the identity credential, denying, by the terminal, the service request,

wherein the denying, by the terminal, the service request comprises:

presenting, by the terminal, prompting information, the prompting information being configured to indicate the user to input another identity credential corresponding to the service indicated by the service request.

11. The method according to claim 3 , further comprising:

receiving, by the terminal, a user credential input by another user; and

determining, by the terminal, another service corresponding to the identity credential input by the another user to enable the another user to use the another service through the terminal.

12. The method according to claim 3 , further comprising:

receiving, by the terminal, a permanent deactivation instruction of the user; and

deleting, by the terminal, the user data of the user according to the permanent deactivation instruction.

13. A terminal, comprising:

a receiver, configured to receive an identity credential input by a user;

a processor; and

a memory, configured to store codes executed by the processor;

wherein the processor is configured to:

determine an Identity (ID) of the user and a priority of the identity credential according to the identity credential;

acquire subscription information of the user according to the ID of the user; and

determine a service corresponding to the priority of the identity credential according to the subscription information;

wherein the identity credential comprises a primary credential and a secondary credential,

wherein the primary credential comprises at least one of: a DeoxyriboNucleic Acid (DNA), a fingerprint, an iris and a voiceprint,

wherein the secondary credential comprises at least one of: a digital certificate, a digital signature, a user card and a password, and

wherein a priority of the primary credential is higher than a priority of the secondary credential.

14. The terminal according to claim 13 , further comprising a sender, wherein

the receiver is further configured to receive first selection information input by the user, the first selection information indicating a first operator selected by the user;

the receiver is further configured to receive a user request input by the user, the user request comprising the identity credential; and

the sender is configured to send the user request to a first Service Provider (SP) device of the first operator.

15. The terminal according to claim 14 , wherein the receiver is further configured to perform at least one of the following:

acquire the subscription information of the user through the first SP device;

receive a first corresponding relationship sent by the first SP device, the first corresponding relationship comprising a corresponding relationship among the ID of the user, the identity credential and the priority of the identity credential; or

receive a second corresponding relationship sent by the first SP device, the second corresponding relationship comprising a corresponding relationship between the priority of the identity credential and the service.

16. The terminal according to claim 14 , wherein

the receiver is further configured to receive an instruction of the user, the instruction indicating that the user is to reselect an operator;

the receiver is further configured to receive second selection information of the user, the second selection information indicating a second operator selected by the user;

the sender is further configured to send the user request to a second SP device of the second operator; and

the processor is further configured to, in response to an indication from the second SP device that the terminal passes authentication, access a network of the second operator through the second SP device.

17. The terminal according to claim 14 , wherein

the receiver is further configured to receive a temporary quitting instruction of the user; and

the processor is further configured to suspend user data of the user according to the temporary quitting instruction.

18. The terminal according to claim 13 , wherein

the receiver is further configured to receive a service request of the user; and

the processor is configured to, when a service indicated by the service request is not the service corresponding to the priority of the identity credential, deny the service request, including: presenting prompting information, the prompting information being configured to indicate the user to input another identity credential corresponding to the service indicated by the service request.

19. The terminal according to claim 13 , wherein

the receiver is further configured to receive a user credential input by another user; and

the processor is further configured to determine another service corresponding to the identity credential input by the another user to enable the another user to use the other service through the terminal.

20. The method according to claim 4 , wherein the sending the user request to the first SP device comprises:

processing the identity credential by adopting a predefined generation method; and

sending the processed identity credential to the first SP device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2018
From: ZENG, YUANQING; TANG, HAI
To: GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP., LTD.
Reel/Frame 044630/0824 →
Continuity (1)
Related Publication 20180270658A1 · Sep 20, 2018