Adaptive dynamic identity authentication method and system based on trust evaluation

The adaptive dynamic identity authentication method using a trust assessment engine solves the problem that authentication strategies cannot be adaptively adjusted in existing technologies, achieving continuous trustworthiness and flexibility of authentication strategies, and supporting mutual recognition and expansion of multiple authentication systems.

CN116248369BActive Publication Date: 2026-02-03NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310102793.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-18
Publication Date
2026-02-03
Estimated Expiration
2043-01-18

AI Technical Summary

Technical Problem

Existing identity authentication technologies struggle to adapt their authentication strategies to the massive scale and diverse forms of user and device identities, leading to issues such as identity theft and the inability to prevent unauthorized actions by internal users. Furthermore, dynamic password mechanisms based on time synchronization have poor security.

Method used

An adaptive dynamic identity authentication method based on trust assessment is adopted. The trust assessment engine continuously evaluates multi-source data and contextual information, calculates a comprehensive trust assessment value, and dynamically adjusts the authentication strategy to support mutual trust and recognition and flexible reconstruction of different authentication systems.

Benefits of technology

It achieves continuous credibility of authentication policies, dynamically adjusts authentication strength, reduces authentication risks, supports the expansion of new authentication methods, and improves the security and flexibility of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248369B_ABST
    Figure CN116248369B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on trust evaluation's adaptive dynamic identity authentication method and system, belong to information security field, including steps: S1, access subject initiates identity authentication service request to adaptive dynamic authentication server;S2, adaptive dynamic authentication server parses and identifies personnel information, and requests trust evaluation value to trust evaluation engine;S3, trust evaluation engine continues trust evaluation, calculates trust evaluation value;S4, trust evaluation engine carries out calculation based on multiple trust evaluation values, and evaluates integrated trust evaluation value;S5, trust evaluation engine returns the integrated trust evaluation value of user to adaptive dynamic authentication server;S6, adaptive dynamic authentication server carries out adaptive dynamic authentication;The application constructs an intelligent, feedback type identity authentication mode, can solve the problem that authentication strategy cannot be self-adaptively adjusted once being set in current authentication system, with wide application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security, and more specifically, to an adaptive dynamic identity authentication method and system based on trust assessment. Background Technology

[0002] As a crucial component of information security, identity authentication technology is a key assessment method for network and information security. It prevents unauthorized access, information leaks, and data corruption, maximizing the protection of information systems and data security, effectively blocking unauthorized users from entering the system, and ensuring the legitimate interests and information security of users. However, in the current stage of rapid internet development, the massive scale and diverse forms of user and device identities are becoming increasingly prominent, leading to challenges such as more complex business operations and the prevalence of attacks. Single identity authentication and verification models still suffer from issues such as identity theft and inability to prevent unauthorized internal user activities, and are no longer sufficient to meet the security requirements of identity authentication in business operations.

[0003] Existing authentication methods can be broadly categorized into general terminal authentication technologies and time-synchronized authentication technologies. Common general terminal authentication technologies include static password-based authentication, dynamic password-based authentication, and biometric authentication. These technologies each have their limitations: they are easily cracked or their verification messages can be transmitted in plaintext; furthermore, they lack the ability to identify and authenticate potentially threatening users. Time-synchronized authentication technologies use time as a variable factor. The authentication server verifies the initiating party using a dynamic password generated based on the current time and user information. However, this dynamic password generation mechanism relies on the next data in an ordered sequence, which lacks randomness, resulting in poor security and vulnerability to malicious attacks. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide an adaptive dynamic identity authentication method and system based on trust assessment. It constructs an intelligent and feedback-based identity authentication mode, which can solve the problem that the authentication strategy cannot be adaptively adjusted once it is set in the current authentication system, and has broad application value.

[0005] The objective of this invention is achieved through the following solution:

[0006] An adaptive dynamic identity authentication method based on trust assessment includes the following steps:

[0007] S1, the authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server;

[0008] S2, after receiving the request data packet sent by the authentication subject, the adaptive dynamic authentication server parses and identifies the personnel information, and then requests the trust assessment value from the trust assessment engine.

[0009] S3, the trust assessment engine, continuously performs trust assessments during operation, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information.

[0010] S4, the trust assessment engine calculates a comprehensive trust assessment value based on multiple trust assessment values;

[0011] S5, after the trust assessment engine evaluates the comprehensive trust assessment value, returns the user's comprehensive trust assessment value to the adaptive dynamic authentication server.

[0012] S6, the adaptive dynamic authentication server performs adaptive dynamic authentication based on the received trust assessment value and the relationship between the authentication policy and the trust assessment value; after authentication is completed, the adaptive dynamic authentication server returns the dynamic authentication result and policy adjustment result based on the trust assessment value to the authentication initiator.

[0013] Furthermore, in step S3, the trust assessment engine continuously performs trust assessments during operation, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information, including the following sub-steps:

[0014] S31, based on the principles of whether the environment is continuously trustworthy, whether the personnel are continuously trustworthy, and whether the minimum authorization is continuously granted, conducts environmental assessment, behavioral assessment, and authorization governance. Combining the risk levels of the certifier's environment, network, and behavior, the trust assessment engine collects user behavior data, attack threat data, threat intelligence data, and management behavior data based on multiple driving sources.

[0015] S32, After receiving multi-source data, the trust assessment driver source preprocesses the multi-source data and sends the trust assessment data source to the trust assessment module for continuous trust assessment in accordance with the specified data format.

[0016] S33, the trust assessment module calculates the trust assessment value from different perspectives based on multi-source data and contextual information.

[0017] Further, in step S6, the adaptive dynamic authentication based on the relationship between the authentication policy and the trust evaluation value includes the following sub-steps:

[0018] S61, Initialization process, completes unified identity authentication adaptation in the adaptive dynamic authentication server architecture, specifies supported authentication methods and authentication strategies, and completes the formulation of the correspondence between dynamic authentication strategies and trust evaluation values;

[0019] S62, the authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, first obtains challenger data from the authentication server, then encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server;

[0020] S63, after receiving an identity authentication request, the dynamic authentication server first parses the authentication information and verifies the validity of the challenge value information;

[0021] S64, after obtaining user authentication information, the adaptive dynamic authentication server calls the trust evaluation engine's trust value acquisition interface to obtain the comprehensive trust evaluation value of the authenticated user.

[0022] S65: Based on the acquired trust assessment value and the authentication method currently used by the user, the dynamic authentication server determines whether the current user can use the current authentication policy for authentication. If the current authentication policy meets the requirements, the adaptive dynamic authentication server encapsulates the identity token information and returns the authentication result to the authentication terminal, enabling the authentication terminal to proceed with subsequent business access. If the current authentication policy does not meet the requirements of the trust assessment value, the authentication server performs dynamic authentication policy adjustment, automatically adjusting the policy according to different trust assessment values. If the user's trust value is lower than the set value, the user's request is directly rejected, and login authentication is refused.

[0023] Furthermore, following step S6, the following steps are also included:

[0024] The authentication methods are dynamically expanded. A unified authentication service adaptation framework is designed through flexible service reconstruction to achieve adaptation and compatibility with different authentication systems. Various authentication methods are service-oriented and mapped through service identifiers to form independent authentication methods, thereby decoupling the coupling between different authentication methods.

[0025] Furthermore, in step S3, the multi-source data and contextual information specifically include the environment / conditions / situation / background in which the event exists or occurs.

[0026] Furthermore, in step S4, the trust evaluation engine performs calculations based on multiple trust evaluation values, specifically including weighted calculations.

[0027] Furthermore, step S6 includes the following sub-steps: for users with low network behavior credibility or unresolved major violations, authentication is rejected according to the authentication policy, or a trust value authentication result is added to the returned basic identity information authentication result, in order to realize a dynamic authentication process based on user behavior analysis and trust assessment.

[0028] Furthermore, the automatic adjustment of the strategy based on different trust assessment values ​​specifically includes requiring users to use stronger authentication methods, perform secondary authentication, or enforce multi-factor authentication.

[0029] Furthermore, after step S6, the following steps are also included: For the new authentication method, the corresponding authentication service system and authentication service device are adapted incrementally. After the adaptation is completed, the system is packaged and the authentication service identifier, calling address, port and related parameter information are provided. The new authentication service information is configured and added to the unified authentication service through the unified authentication service adaptation framework. The authentication service information is obtained through the service identifier to realize the dynamic calling of the new authentication service.

[0030] An adaptive dynamic identity authentication system based on trust assessment includes a computer device, the computer device including a processor and a memory, the memory storing a computer program that, when loaded by the processor, executes the method described in any of the preceding claims.

[0031] The beneficial effects of this invention include:

[0032] (1) The dynamic identity authentication method based on trust assessment proposed in this invention breaks the default "trust". This method completes the authentication behavior of "continuous verification and never trust", and constructs an intelligent and feedback identity authentication mode. It can solve the problem that the authentication strategy cannot be adaptively adjusted once it is set in the current authentication system, and has a wide range of application value.

[0033] (2) This invention continuously assesses the credibility of visitors based on as many data sources as possible, and dynamically adjusts the authentication strategy according to the assessment results. It performs security modeling of the access subjects and objects, conducts credibility analysis on people and terminals, assesses threats to business access behavior and sensitive data access behavior, and dynamically adjusts the authentication strategy based on the detection and analysis results, handling abnormal or malicious accounts and terminals in real time. The authentication method based on dynamic strategies ensures the continuous credibility of authentication, guarantees the authenticity of each authentication, and reduces authentication risks.

[0034] (3) The authentication method proposed in this invention supports the configuration of new access authentication methods, forming a dynamic authentication extension capability mechanism, realizing mutual trust and recognition between different identity identifiers and different authentication systems, and the ability to flexibly reconstruct the authentication system. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 This is a flowchart illustrating the overall workflow of the method according to an embodiment of the present invention;

[0037] Figure 2 This is a flowchart illustrating the dynamic authentication method based on trust assessment in an embodiment of the present invention.

[0038] Figure 3 This is a flowchart illustrating the authentication interaction process of the method in an embodiment of the present invention.

[0039] Figure 4 This is an extended diagram of the authentication method of the embodiment of the present invention; Detailed Implementation

[0040] All features disclosed in all embodiments of this specification, or steps in all methods or processes implied in the disclosure, may be combined and / or extended or replaced in any way, except for mutually exclusive features and / or steps.

[0041] In view of the technical problems in the background, after analysis by the inventors of this invention, the current network security authentication system urgently needs an identity authentication technology solution that can provide user-insensitive behavioral risk perception for applications with different security level requirements, and can automatically link with other security handling systems (such as antivirus, security audit, firewall, situational awareness, etc.) to handle risks. For example, when a risk is detected, it can automatically switch to two-factor authentication, ultimately achieving both security and efficiency.

[0042] Furthermore, after creative thinking, the inventors of this invention believe that a secure and reliable system should not trust any person, device, or application inside or outside the network by default. The trust foundation of access control should be reconstructed based on authentication and authorization, and the trust of visitors should be continuously assessed based on as many data sources as possible. The authentication and access control policies should be dynamically adjusted according to the assessment results.

[0043] Based on the above considerations, the main technical problem addressed by this invention is the adaptive dynamic authentication problem. In the method of this invention, real-time trust analysis of end users is performed. Based on the results of continuous adaptive risk and trust assessment, the corresponding authentication strategy and authentication strength can be dynamically adjusted. Furthermore, the adjustment process can be completed automatically without human intervention or control, solving the problem that authentication strategies cannot be adaptively adjusted once set. This method offers the advantages of security, convenience, and efficiency. Further, this invention specifically yields the following inventive concept:

[0044] 1) A dynamic authentication method based on trust assessment was studied to solve the problem of how to transform the security architecture from network-centric to identity-centric, and how all access behaviors need to be performed with fine-grained adaptive dynamic authentication and access control centered on identity.

[0045] 2) Conduct continuous trust assessments of visitors based on as many data sources as possible, and dynamically adjust authentication strategies according to the assessment results to ensure continuous trustworthiness of authentication. Perform security modeling on access subjects and objects, conduct trust analysis on people and terminals, assess threats to business access behavior and sensitive data access behavior, and dynamically adjust authentication strategies and access permissions based on detection and analysis results, and handle abnormal or malicious accounts and terminals in real time.

[0046] 3) When authentication strategies and methods need to be dynamically expanded, solve the technical problem of how to support the expansion configuration of new access authentication methods, form a dynamic authentication expansion capability mechanism, and realize mutual trust and recognition between different identity identifiers and different authentication systems, as well as the ability to flexibly reconstruct the authentication system.

[0047] In a specific implementation scheme, the present invention further provides an adaptive dynamic identity authentication method based on trust assessment, such as... Figure 1 As shown, it includes the following process:

[0048] Step 1: The authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server.

[0049] Step 2: After receiving the request data packet sent by the authentication subject, the adaptive dynamic authentication server parses and identifies the personnel information, and then requests a trust assessment value from the trust assessment engine.

[0050] Step 3: During operation, the trust assessment engine continuously performs trust assessments, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information (i.e., the environment / conditions / situation / background in which the event exists or occurs).

[0051] Step 4: The trust assessment engine performs a weighted calculation based on multiple trust assessment values ​​to evaluate a comprehensive trust assessment value Ti.

[0052] Step 5: After the trust assessment engine evaluates the overall trust assessment value, it returns the user's overall trust assessment value to the adaptive dynamic authentication server.

[0053] Step 6: The adaptive dynamic authentication server performs adaptive dynamic authentication based on the received trust assessment value and the relationship between the authentication policy and the trust assessment value. After authentication, the dynamic authentication server returns the dynamic authentication result based on the trust assessment value and the policy adjustment result to the authentication initiator. For users with low network behavior credibility or unresolved major violations, the authentication decision is either rejected or a trust value is added to the basic identity information authentication result, according to the authentication policy, thus realizing a dynamic authentication process based on user behavior analysis and trust assessment.

[0054] In a further implementation, the specific process is as follows: Figure 2 As shown, this includes the trust assessment engine process and the adaptive dynamic authentication service authentication process.

[0055] The trust assessment engine process is as follows:

[0056] Step 1: Based on the principles of whether the environment is continuously trustworthy, whether the personnel are continuously trustworthy, and whether the minimum authorization is continuously granted, conduct environmental assessment, behavioral assessment, and authorization governance. Combining the risk levels of the certifier's environment, network, and behavior, the trust assessment engine collects various data such as user behavior data, attack threat data, threat intelligence data, and management behavior data based on multiple driving sources.

[0057] Step 2: After receiving multi-source data, the trust assessment driver source preprocesses the multi-source data and sends the trust assessment data source to the trust assessment module for continuous trust assessment according to the specified data format.

[0058] Step 3: The trust assessment module calculates the trust assessment value from different perspectives based on multi-source data and contextual information (i.e., the environment / conditions / situation / background in which the event exists or occurs).

[0059] Step 4: The trust assessment engine performs a weighted calculation based on multiple trust assessment values ​​to evaluate a comprehensive trust assessment value Ti.

[0060] The adaptive dynamic authentication service process is as follows:

[0061] Step 1: Initialization Process. The unified identity authentication adaptation is completed within the adaptive dynamic authentication server architecture, specifying supported authentication methods, authentication policies, etc., and establishing the correspondence between dynamic authentication policies and trust evaluation values.

[0062] Step 2: The authentication client obtains the pre-enabled local authentication method from the authentication server. The access subject selects the authentication strategy it supports, first obtains challenger data from the authentication server, then encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server.

[0063] Step 3: After receiving the authentication request, the dynamic authentication server first parses the authentication information, then parses and verifies the validity of the challenge value information. The flowchart for obtaining and verifying the challenge value is attached. Figure 3 As shown.

[0064] Step 4: After obtaining the user authentication information, the adaptive dynamic authentication server calls the trust evaluation engine's trust value acquisition interface to obtain the comprehensive trust evaluation value of the authenticated user.

[0065] Step 5: Based on the acquired trust assessment value and the authentication method currently used by the user, the dynamic authentication server determines whether the current user can use the current authentication policy for authentication. If the current authentication policy meets the requirements, the adaptive dynamic authentication server encapsulates the identity token information and returns the authentication result to the authentication terminal, which can then proceed with subsequent business access. If the current authentication policy does not meet the trust assessment value requirements, the authentication server performs dynamic authentication policy adjustment, automatically adjusting the policy according to different trust assessment values. This may include requiring the user to use a stronger authentication method, performing two-factor authentication, or enforcing multi-factor authentication. If the user's trust value is too low, the user's request is directly rejected, and login authentication is denied.

[0066] This invention also includes the following process: a method for dynamically expanding authentication methods. The method for dynamically expanding authentication methods is as follows: Figure 4 As shown, a unified authentication service adaptation framework is designed through service flexibility reconstruction technology to achieve adaptation and compatibility with different authentication systems, service-oriented authentication methods, and mapping through service identifiers to form mutually independent authentication methods, thereby decoupling the coupling between different authentication methods.

[0067] For new authentication methods, the corresponding authentication service system and authentication service devices are adapted incrementally. After the adaptation is completed, the system is packaged and provides authentication service identifier, call address, port and related parameter information. The new authentication service information is added to the unified authentication service through the unified authentication service adaptation framework. The authentication service information is obtained through the service identifier, and the new authentication service can be dynamically invoked.

[0068] In other embodiments of the present invention, further examples are as follows:

[0069] The specific process of the adaptive dynamic identity authentication method based on trust assessment mainly includes the implementation process of the trust assessment engine and the authentication implementation process of the adaptive dynamic authentication server.

[0070] The implementation process for the trust assessment engine is as follows:

[0071] Step 1: Based on the principles of whether the environment is continuously trustworthy, whether the personnel are continuously trustworthy, and whether the minimum authorization is continuously granted, conduct environmental assessment, behavioral assessment, and authorization governance. Combining the risk levels of the certifier's environment, network, and behavior, the trust assessment engine collects various data such as user behavior data, attack threat data, threat intelligence data, and management behavior data based on multiple driving sources.

[0072] Step 2: After receiving multi-source data, the trust assessment driver source preprocesses the multi-source data and sends the trust assessment data source to the trust assessment module for continuous trust assessment according to the specified data format.

[0073] Step 3: The trust assessment module calculates trust assessment values ​​TAi, TBi, and TBi from different perspectives based on multi-source data and contextual information (i.e., the environment / conditions / situation / background in which the event exists or occurs).

[0074] Step 4: The trust assessment engine introduces service weight factors α, β, and γ, and performs weighted calculations based on multiple trust assessment values ​​to evaluate the comprehensive trust assessment value Ti = α*TAi + β*TBi + γTCi.

[0075] The authentication process of the adaptive dynamic authentication server is as follows:

[0076] Step 1: Initialization Process. In the adaptive dynamic authentication server architecture, unified identity authentication adaptation is completed, specifying supported authentication methods and strategies, and defining the correspondence between dynamic authentication strategies and trust evaluation values. Based on requirements, m trust levels are defined, where TA(t)∈[TA...]. i (t),TA i+1 When (t)], the user's trust level is i, i∈[i,m], TA i (t),TA i+1 (t) represents the maximum and minimum values ​​of the i-th trust value interval, respectively. Assume the following rules are established, with the user trust evaluation value interval being [0, 100], and the trust level classification table is shown in Table 1.

[0077] Table 1 Trust Level Classification Table

[0078]

[0079] a) When a user's trust value Ti is in the range [0, 30], refuse the user's authentication in any way;

[0080] b) When the user's trust value Ti is in the range of [30, 60], force the user to perform multi-factor authentication or use a stronger level of secondary authentication;

[0081] c) When a user's trust value Ti is in the range of [60, 80], the user can use biometric authentication methods (fingerprint, face, iris, finger vein and palm print, etc.) or certificate authentication, but cannot use low-strength authentication methods such as username password or verification code;

[0082] d) When a user's trust value Ti is in the range [80, 100], the user can use any authentication method to authenticate, and once the authentication is successful, the user can log in to the system.

[0083] Step 2: The authentication client obtains the pre-enabled local authentication method from the authentication server. The access subject selects the authentication strategy it supports, first obtains challenger data from the authentication server, then encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server. Here, it is assumed that the user has selected the face recognition single-factor authentication method.

[0084] Step 3: After receiving user A's face authentication request, the dynamic authentication server first parses the authentication information and verifies the validity of the challenge value information.

[0085] Step 4: After obtaining user A's face authentication information, the adaptive dynamic authentication server obtains user A's unique identifier IDA, calls the trust evaluation engine to obtain the trust value interface, and uses user A's unique identifier IDA as a request parameter to obtain the comprehensive trust evaluation value Ta of the authenticated user. Here, it is assumed that the trust evaluation value obtained from the trust evaluation engine is 55.

[0086] Step 5: Based on the obtained trust assessment value of 55, combined with the face authentication method currently used by the user, since the user's current trust assessment value is 55, which is within the trust value range [30, 60], the adaptive dynamic authentication server determines, based on dynamic policy rules, that the current user A needs to use multi-factor authentication to successfully authenticate. The authentication server returns the determination result to the authentication terminal and user A, forcing user A to complete multi-factor authentication. At this time, user A selects a multi-factor authentication strategy, such as face + certificate face authentication, to complete the authentication. After the multi-factor verification is successful, the authentication request is successful, and the current user can then proceed with subsequent login and access operations.

[0087] Implementation of the Dynamic Authentication Method Extension Method: This method refactors the authentication architecture using design patterns such as Singleton, Simple Factory, and Factory. This architecture is fully decoupled and compatible with other authentication methods, ensuring each method is completely independent. When an authentication method needs to be changed, only a simple modification to the configuration file is required, without needing to consider other authentication methods. This significantly reduces development difficulty, accelerates the development cycle, and reduces the workload. Based on this dynamic extension method, authentication methods can be quickly added, masking the differences between various authentication methods such as password certificate authentication, biometric authentication, and QR code authentication, and providing a unified authentication service interface.

[0088] The following example illustrates how to add a new palmprint authentication method. First, add the palmprint authentication method type and its corresponding factory class to the configuration file. After configuration, add an independently implemented palmprint factory class to the project path. Once the palmprint factory class is initialized, it will generate a corresponding palmprint authentication implementation class. When an authentication request arrives and is detected as a palmprint authentication type, it requests the palmprint factory to generate the palmprint authentication implementation class, where palmprint authentication is performed. The client authentication proxy, after obtaining the server's authentication upgrade message, automatically pulls the authentication upgrade configuration and upgrade package, coordinating with the backend's synchronous upgrade of the newly added authentication method to achieve client-side upgrade adaptation. This process is completely decoupled from other authentication methods, and its implementation is relatively independent, greatly improving development efficiency. Furthermore, in case of problems, the client can quickly locate its own authentication implementation class.

[0089] It should be noted that, within the scope of protection defined in the claims of this invention, the following embodiments can be combined and / or extended or replaced in any logical manner from the above specific embodiments, such as the disclosed technical principles, disclosed technical features or implicitly disclosed technical features.

[0090] Example 1

[0091] An adaptive dynamic identity authentication method based on trust assessment includes the following steps:

[0092] S1, the authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server;

[0093] S2, after receiving the request data packet sent by the authentication subject, the adaptive dynamic authentication server parses and identifies the personnel information, and then requests the trust assessment value from the trust assessment engine.

[0094] S3, the trust assessment engine, continuously performs trust assessments during operation, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information.

[0095] S4, the trust assessment engine calculates a comprehensive trust assessment value based on multiple trust assessment values;

[0096] S5, after the trust assessment engine evaluates the comprehensive trust assessment value, returns the user's comprehensive trust assessment value to the adaptive dynamic authentication server.

[0097] S6, the adaptive dynamic authentication server performs adaptive dynamic authentication based on the received trust assessment value and the relationship between the authentication policy and the trust assessment value; after authentication is completed, the adaptive dynamic authentication server returns the dynamic authentication result and policy adjustment result based on the trust assessment value to the authentication initiator.

[0098] Example 2

[0099] Based on Example 1, in step S3, the trust assessment engine continuously performs trust assessments during operation, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information, including the following sub-steps:

[0100] S31, based on the principles of whether the environment is continuously trustworthy, whether the personnel are continuously trustworthy, and whether the minimum authorization is continuously granted, conducts environmental assessment, behavioral assessment, and authorization governance. Combining the risk levels of the certifier's environment, network, and behavior, the trust assessment engine collects user behavior data, attack threat data, threat intelligence data, and management behavior data based on multiple driving sources.

[0101] S32, After receiving multi-source data, the trust assessment driver source preprocesses the multi-source data and sends the trust assessment data source to the trust assessment module for continuous trust assessment in accordance with the specified data format.

[0102] S33, the trust assessment module calculates the trust assessment value from different perspectives based on multi-source data and contextual information.

[0103] Example 3

[0104] Based on Example 1, step S6, which involves adaptive dynamic authentication based on the relationship between authentication strategy and trust evaluation value, includes the following sub-steps:

[0105] S61, Initialization process, completes unified identity authentication adaptation in the adaptive dynamic authentication server architecture, specifies supported authentication methods and authentication strategies, and completes the formulation of the correspondence between dynamic authentication strategies and trust evaluation values;

[0106] S62, the authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, first obtains challenger data from the authentication server, then encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server;

[0107] S63, after receiving an identity authentication request, the dynamic authentication server first parses the authentication information and verifies the validity of the challenge value information;

[0108] S64, after obtaining user authentication information, the adaptive dynamic authentication server calls the trust evaluation engine's trust value acquisition interface to obtain the comprehensive trust evaluation value of the authenticated user.

[0109] S65: Based on the acquired trust assessment value and the authentication method currently used by the user, the dynamic authentication server determines whether the current user can use the current authentication policy for authentication. If the current authentication policy meets the requirements, the adaptive dynamic authentication server encapsulates the identity token information and returns the authentication result to the authentication terminal, enabling the authentication terminal to proceed with subsequent business access. If the current authentication policy does not meet the requirements of the trust assessment value, the authentication server performs dynamic authentication policy adjustment, automatically adjusting the policy according to different trust assessment values. If the user's trust value is lower than the set value, the user's request is directly rejected, and login authentication is refused.

[0110] Example 4

[0111] Based on Example 1, after step S6, the following steps are also included:

[0112] The authentication methods are dynamically expanded; a unified authentication service adaptation framework is designed through flexible service reconstruction to achieve adaptation and compatibility with different authentication systems, service-oriented authentication methods, and mapping through service identifiers to form mutually independent authentication methods, thereby decoupling the coupling between different authentication methods.

[0113] Example 5

[0114] Based on Example 1, in step S3, the multi-source data and context information specifically include the environment / conditions / situation / background in which the event exists or occurs.

[0115] Example 6

[0116] Based on Example 1, in step S4, the trust evaluation engine performs calculations based on multiple trust evaluation values, specifically including weighted calculations.

[0117] Example 7

[0118] Based on Example 1, step S6 includes the following sub-step: for users with low network behavior credibility or unresolved major violations, authentication is rejected according to the authentication policy, or a trust value authentication result is added to the returned basic identity information authentication result, in order to realize a dynamic authentication process based on user behavior analysis and trust assessment.

[0119] Example 8

[0120] Based on Example 3, the automatic adjustment of the strategy according to different trust assessment values ​​specifically includes requiring users to use stronger authentication methods, perform secondary authentication, or enforce multi-factor authentication.

[0121] Example 9

[0122] Based on Example 4, after step S6, the following steps are also included: For the new authentication method, the corresponding authentication service system and authentication service device are adapted incrementally. After the adaptation is completed, the system is packaged and the authentication service identifier, calling address, port and related parameter information are provided. The new authentication service information is configured to be added to the unified authentication service through the unified authentication service adaptation framework. The authentication service information is obtained through the service identifier to realize the dynamic calling of the new authentication service.

[0123] Example 10

[0124] An adaptive dynamic identity authentication system based on trust assessment includes a computer device, the computer device including a processor and a memory, the memory storing a computer program, which, when loaded by the processor, executes the method described in any one of Embodiments 1 to 9.

[0125] The units described in the embodiments of the present invention can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.

[0126] According to one aspect of the present invention, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and executes the computer instructions, causing the computer device to perform the methods provided in the various optional implementations described above.

[0127] In another aspect, embodiments of the present invention also provide a computer-readable medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the methods described in the above embodiments.

[0128] All parts not covered in this invention are the same as or can be implemented using existing technologies.

[0129] The above technical solution is only one embodiment of the present invention. For those skilled in the art, based on the application methods and principles disclosed in the present invention, it is easy to make various types of improvements or modifications, and not limited to the methods described in the above specific embodiments of the present invention. Therefore, the methods described above are only preferred and are not restrictive.

[0130] In addition to the examples above, other embodiments may be obtained by those skilled in the art based on the above disclosure or by making modifications using knowledge or technology in related fields. The features of each embodiment may be interchanged or replaced. Modifications and changes made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.

Claims

1. An adaptive dynamic identity authentication method based on trust assessment, characterized in that, Includes the following steps: S1, the authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server; S2, after receiving the request data packet sent by the authentication subject, the adaptive dynamic authentication server parses and identifies the personnel information, and then requests the trust assessment value from the trust assessment engine. S3, the trust assessment engine, continuously performs trust assessments during operation, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information. S4, the trust assessment engine calculates a comprehensive trust assessment value based on multiple trust assessment values; S5, after the trust assessment engine evaluates the comprehensive trust assessment value, returns the user's comprehensive trust assessment value to the adaptive dynamic authentication server. S6, the adaptive dynamic authentication server performs adaptive dynamic authentication based on the received trust assessment value and the relationship between the authentication policy and the trust assessment value; After authentication is completed, the adaptive dynamic authentication server will return the dynamic authentication result and policy adjustment result based on the trust assessment value to the authentication initiator. In step S3, the trust assessment engine continuously performs trust assessments during operation, calculating trust assessment values ​​from different perspectives based on multi-source data and contextual information, including the following sub-steps: S31, based on the principles of whether the environment is continuously trustworthy, whether the personnel are continuously trustworthy, and whether the minimum authorization is continuously granted, conducts environmental assessment, behavioral assessment, and authorization governance. Combining the risk levels of the certifier's environment, network, and behavior, the trust assessment engine collects user behavior data, attack threat data, threat intelligence data, and management behavior data based on multiple driving sources. S32, After receiving multi-source data, the trust assessment driver source preprocesses the multi-source data and sends the trust assessment data source to the trust assessment module for continuous trust assessment in accordance with the specified data format. S33, the trust assessment module calculates the trust assessment value from different perspectives based on multi-source data and contextual information; In step S6, the adaptive dynamic authentication based on the relationship between the authentication policy and the trust evaluation value includes the following sub-steps: S61, Initialization process, completes unified identity authentication adaptation in the adaptive dynamic authentication server architecture, specifies supported authentication methods and authentication strategies, and completes the formulation of the correspondence between dynamic authentication strategies and trust evaluation values; S62, the authentication client obtains the pre-enabled local authentication method from the authentication server, the access subject selects the authentication strategy it supports, first obtains challenger data from the authentication server, then encapsulates the request data packet, and sends an identity authentication service request to the adaptive dynamic authentication server; S63, after receiving an identity authentication request, the dynamic authentication server first parses the authentication information and verifies the validity of the challenge value information; S64, after obtaining user authentication information, the adaptive dynamic authentication server calls the trust evaluation engine's trust value acquisition interface to obtain the comprehensive trust evaluation value of the authenticated user. S65, based on the obtained trust assessment value and the authentication method currently used by the user, the dynamic authentication server determines whether the current user can use the current authentication policy for authentication based on the trust assessment value result. If the current authentication policy meets the requirements, the adaptive dynamic authentication server encapsulates the identity token information and returns the authentication result to the authentication terminal, which can then proceed with subsequent business access. If the current authentication policy does not meet the trust assessment value requirements, the authentication server will perform dynamic authentication policy adjustment, automatically adjusting the policy according to different trust assessment values. If the user's trust value is lower than the set value, the user's request will be directly rejected, and login authentication will be refused.

2. The adaptive dynamic identity authentication method based on trust assessment according to claim 1, characterized in that, Following step S6, the following steps are also included: The authentication methods are dynamically expanded; a unified authentication service adaptation framework is designed through flexible service reconstruction to achieve adaptation and compatibility with different authentication systems, service-oriented authentication methods, and mapping through service identifiers to form mutually independent authentication methods, thereby decoupling the coupling between different authentication methods.

3. The adaptive dynamic identity authentication method based on trust assessment according to claim 1, characterized in that, In step S3, the multi-source data and contextual information specifically include the environment / conditions / situation / background in which the event exists or occurs.

4. The adaptive dynamic identity authentication method based on trust assessment according to claim 1, characterized in that, In step S4, the trust evaluation engine performs calculations based on multiple trust evaluation values, specifically including weighted calculations.

5. The adaptive dynamic identity authentication method based on trust assessment according to claim 1, characterized in that, Step S6 includes the following sub-steps: For users with low network behavior credibility or unresolved major violations, the authentication decision is either rejected or a trust value is added to the basic identity information authentication result, based on the authentication policy, to realize a dynamic authentication process based on user behavior analysis and trust assessment.

6. The adaptive dynamic identity authentication method based on trust assessment according to claim 1, characterized in that, The automatic adjustment of the strategy based on different trust assessment values ​​specifically includes requiring users to use stronger authentication methods, perform secondary authentication, or enforce multi-factor authentication.

7. The adaptive dynamic identity authentication method based on trust assessment according to claim 2, characterized in that, After step S6, the following steps are also included: For the new authentication method, the corresponding authentication service system and authentication service device are adapted incrementally. After the adaptation is completed, the system is packaged and provides the authentication service identifier, calling address, port and related parameter information. The new authentication service information is configured and added to the unified authentication service through the unified authentication service adaptation framework. The authentication service information is obtained through the service identifier to realize the dynamic calling of the new authentication service.

8. An adaptive dynamic identity authentication system based on trust assessment, characterized in that, The device includes a computer device comprising a processor and a memory, the memory storing a computer program that, when loaded by the processor, executes the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Security authentication method, system and device and readable storage medium

    CN114826771A

  • A system and method for authenticating a user based on user behaviour and environmental factors

    WO2016048129A2