
人脸核身的可信结论由服务端把关。本文讲清楚服务端在核身流程中承担什么职责、需要对接哪些 API 接口,以及 Python、Java、Go 等多语言 SDK 的调用要点和完整代码示例。
如果核身结论由客户端自行判断,攻击者篡改客户端就能伪造通过结果。所以正确的设计是:
客户端只负责采集和交互,不掌握最终结论。
服务端主要涉及两个 API:
接口 | 调用时机 | 作用 |
|---|---|---|
GetFaceIdToken | 用户触发核身前 | 生成一次核身流程的唯一凭证(SdkToken) |
GetFaceIdResult | 用户完成核身后 | 拉取本次核身的最终结论 |
一次流程对应一个凭证,凭证不能跨流程复用。
服务端 SDK 通常支持 Python、Java、Go、Node.js、.NET、PHP 等主流语言。
以 Python 为例,调用流程如下:
from tencentcloud.common import credential
from tencentcloud.common.profile.client_profile import ClientProfile
from tencentcloud.common.profile.http_profile import HttpProfile
from tencentcloud.faceid.v20180301 import faceid_client, models
# 初始化认证信息
cred = credential.Credential("YourSecretId", "YourSecretKey")
http_profile = HttpProfile()
http_profile.endpoint = "faceid.tencentcloudapi.com"
client_profile = ClientProfile()
client_profile.httpProfile = http_profile
client = faceid_client.FaceidClient(cred, "ap-guangzhou", client_profile)
# 步骤1:获取核身 Token
req = models.GetFaceIdTokenRequest()
resp = client.GetFaceIdToken(req)
print(resp.to_json_string())
# 步骤2:用户完成核身后,获取核身结果
result_req = models.GetFaceIdResultRequest()
result_req.FaceIdToken = "上一步返回的FaceIdToken"
result_resp = client.GetFaceIdResult(result_req)
print(result_resp.to_json_string())Java 使用腾讯云官方 SDK,核心代码如下:
import com.tencentcloudapi.common.Credential;
import com.tencentcloudapi.common.profile.ClientProfile;
import com.tencentcloudapi.common.profile.HttpProfile;
import com.tencentcloudapi.faceid.v20180301.FaceidClient;
import com.tencentcloudapi.faceid.v20180301.models.GetFaceIdTokenRequest;
import com.tencentcloudapi.faceid.v20180301.models.GetFaceIdTokenResponse;
import com.tencentcloudapi.faceid.v20180301.models.GetFaceIdResultRequest;
import com.tencentcloudapi.faceid.v20180301.models.GetFaceIdResultResponse;
public class FaceIdServerDemo {
private static final String SECRET_ID = "YourSecretId";
private static final String SECRET_KEY = "YourSecretKey";
private static final String REGION = "ap-guangzhou";
public static void main(String[] args) throws Exception {
// 初始化认证信息
Credential cred = new Credential(SECRET_ID, SECRET_KEY);
HttpProfile httpProfile = new HttpProfile();
httpProfile.setEndpoint("faceid.tencentcloudapi.com");
ClientProfile clientProfile = new ClientProfile();
clientProfile.setHttpProfile(httpProfile);
FaceidClient client = new FaceidClient(cred, REGION, clientProfile);
// 步骤1:获取核身 Token
GetFaceIdTokenRequest tokenReq = new GetFaceIdTokenRequest();
GetFaceIdTokenResponse tokenResp = client.GetFaceIdToken(tokenReq);
System.out.println(GetFaceIdTokenResponse.toJsonString(tokenResp));
// 步骤2:用户完成核身后,获取核身结果
GetFaceIdResultRequest resultReq = new GetFaceIdResultRequest();
resultReq.setFaceIdToken("上一步返回的FaceIdToken");
GetFaceIdResultResponse resultResp = client.GetFaceIdResult(resultReq);
System.out.println(GetFaceIdResultResponse.toJsonString(resultResp));
}
}Maven 依赖配置:
<dependency>
<groupId>com.tencentcloudapi</groupId>
<artifactId>tencentcloud-sdk-java-faceid</artifactId>
<version>3.1.xxx</version>
</dependency>Go 版本的完整服务端示例如下(基于官方文档):
package main
import (
"encoding/json"
"log"
"net/http"
"github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common"
"github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common/profile"
"github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/faceid/v20180301"
)
var FaceIdClient *faceid.Client
func init() {
// 初始化客户端配置对象,您可以指定超时时间和其他配置项
prof := profile.NewClientProfile()
prof.HttpProfile.ReqTimeout = 60
// TODO 需要替换成您调用账号的 SecretId 和 SecretKey
credential := common.NewCredential("SecretId", "SecretKey")
var err error
// 初始化调用慧眼人脸核身服务的客户端
FaceIdClient, err = faceid.NewClient(credential, "ap-guangzhou", prof)
if nil != err {
log.Fatal("FaceIdClient init error: ", err)
}
}
// GetFaceIdToken 获取人脸核身 Token
func GetFaceIdTokenHandler(w http.ResponseWriter, r *http.Request) {
log.Println("get face id token")
// 步骤1: 解析请求参数
_ = r.ParseForm()
compareLib := r.FormValue("CompareLib")
// 步骤2: 初始化请求对象,并给必要的参数赋值
request := faceid.NewGetFaceIdTokenRequest()
request.CompareLib = &compareLib
// 步骤3: 通过 FaceIdClient 调用人脸核身服务
response, err := FaceIdClient.GetFaceIdToken(request)
if nil != err {
_, _ = w.Write([]byte("error"))
return
}
// 步骤4: 处理腾讯云 API 的响应,并构造返回对象
faceIdToken := response.Response.FaceIdToken
apiResp := struct {
FaceIdToken *string
}{FaceIdToken: faceIdToken}
b, _ := json.Marshal(apiResp)
// 步骤5: 返回服务响应
_, _ = w.Write(b)
}
// GetFaceIdResult 获取人脸核身核验结果
func GetFaceIdResultHandler(w http.ResponseWriter, r *http.Request) {
// 步骤1: 解析请求参数
_ = r.ParseForm()
faceIdToken := r.FormValue("FaceIdToken")
// 步骤2: 初始化请求对象,并给必要的参数赋值
request := faceid.NewGetFaceIdResultRequest()
request.FaceIdToken = &faceIdToken
// 步骤3: 通过 FaceIdClient 调用人脸核身服务
response, err := FaceIdClient.GetFaceIdResult(request)
if nil != err {
_, _ = w.Write([]byte("error"))
return
}
// 步骤4: 处理腾讯云 API 的响应,并构造返回对象
result := response.Response.Result
apiResp := struct {
Result *string
}{Result: result}
b, _ := json.Marshal(apiResp)
// 步骤5: 返回服务响应
_, _ = w.Write(b)
}
func main() {
// 注册 HTTP 接口路径
http.HandleFunc("/api/v1/get-token", GetFaceIdTokenHandler)
http.HandleFunc("/api/v1/get-result", GetFaceIdResultHandler)
// 监听端口
err := http.ListenAndServe(":8080", nil)
if nil != err {
log.Fatal("Server error: ", err)
}
}安装依赖:
go get github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/faceid/v20180301服务端调用需要处理几类异常:
重试时注意幂等性,避免同一笔核身请求被重复计入。
腾讯云慧眼人脸核身提供多语言服务端 SDK,支持在业务服务端完成凭证申请与结果拉取。该系列产品正在限时特惠活动中,低至3.3折:https://cloud.tencent.com/act/pro/happynewyears
原创声明:本文系作者授权腾讯云开发者社区发表,未经许可,不得转载。
如有侵权,请联系 cloudcommunity@tencent.com 删除。