System and method for authenticating trusted data space for multi-party data sharing

By using a trusted data space identity authentication system that shares data from multiple parties, the system dynamically adjusts the status and proportion of authentication factors, solving the problem of poor security in traditional identity authentication and achieving highly secure and convenient multi-party data sharing authentication.

CN120238340BActive Publication Date: 2026-01-02LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510353954.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2026-01-02
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

Traditional identity authentication relies on a single factor, which has poor security and is difficult to meet the high requirements of multi-party data sharing scenarios. Furthermore, existing multi-factor authentication is not perfect in recognizing and matching under complex networks and diverse access devices, affecting data security sharing and user convenience.

Method used

The trusted data space identity authentication system adopts multi-party data sharing and includes an authentication attribute acquisition module, an authentication factor matching module, a hierarchical authentication module, and an authentication verification module. By identifying user authentication attributes, it dynamically adjusts the matching status and fusion ratio of authentication factors to achieve hierarchical authentication and collaborative verification.

Benefits of technology

It improves the security and reliability of identity authentication, enhances the flexibility and adaptability of authentication, improves authentication efficiency, and meets the high security and convenience requirements of multi-party data sharing scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238340B_ABST
    Figure CN120238340B_ABST
Patent Text Reader

Abstract

The application discloses a trusted data space identity authentication system and method for multi-party data sharing, relates to the technical field of data security, and comprises the following modules: an authentication attribute acquisition module, which is used for connecting a user authentication channel and identifying user authentication attributes; an authentication factor matching module, which is used for matching identity authentication elements according to the user authentication attributes and a multi-factor authentication mechanism, determining the authentication matching positions and factor fusion proportions of various factor authentications; a hierarchical authentication module, which is used for performing hierarchical authentication on user feedback identity data according to the authentication matching positions and factor fusion proportions of various factor authentications, and tracking and recording the authentication process; and an authentication verification module, which is used for performing identity authentication collaborative verification according to the hierarchical authentication results and the authentication tracking records, and allowing users with verification results to access a trusted data space. Thus, the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication, and improving the authentication efficiency are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a trusted data space identity authentication system and method for multi-party data sharing. BACKGROUND

[0002] Traditional identity authentication relies on a single factor such as a username and password, which is easy to crack and has poor security. Multi-factor authentication is still imperfect in attribute recognition, factor matching and process tracking under complex networks and diversified access devices, and cannot meet the high requirements of multi-party data sharing scenarios, affecting data security sharing and user convenience. The existing technology has deficiencies in security, adaptability and efficiency, and it is difficult to balance security and convenience in multi-party data sharing. SUMMARY

[0003] The present application provides a trusted data space identity authentication system and method for multi-party data sharing to solve the technical problems of single factor, poor authentication flexibility and adaptability, and affect identity recognition security in the prior art, and achieve the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication, and improving the efficiency of authentication.

[0004] In a first aspect, the present application provides a trusted data space identity authentication system for multi-party data sharing, wherein the trusted data space identity authentication system for multi-party data sharing comprises:

[0005] An authentication attribute acquisition module is configured to connect a user authentication channel and identify user authentication attributes.

[0006] An authentication factor matching module is configured to match authentication elements based on the user authentication attributes and a multi-factor authentication mechanism, determine the authentication matching status of each factor authentication and the factor fusion ratio.

[0007] A hierarchical authentication module is configured to perform hierarchical authentication on user feedback identity data based on the authentication matching status of each factor authentication and the factor fusion ratio, and track and record the authentication process.

[0008] An authentication verification module is configured to perform identity authentication collaborative verification based on the hierarchical authentication results and the authentication tracking records, and allow users with verification results to access the trusted data space.

[0009] In a feasible implementation manner, the authentication attribute acquisition module comprises:

[0010] A user access information identification unit is configured to identify user access devices and access network paths based on the user authentication channel.

[0011] The access device security and feature analysis unit is configured to analyze a user access device to analyze user access device information in a security state and user features, determine access device security information and device attribute features.

[0012] The network path security and feature analysis unit is configured to analyze a user access network path to obtain network path security information and network attribute features.

[0013] The user authentication attribute and security evaluation unit is configured to identify and match user authentication attributes based on the device attribute features and the network attribute features, obtain user authentication attributes, evaluate access security based on the access device security information and the network path security information, and generate a security label of the user authentication attributes.

[0014] In an implementation, the network path security and feature analysis unit includes:

[0015] The network basic parameter identification subunit is configured to identify network basic parameters, including IP addresses and access network types.

[0016] The network path security and feature acquisition subunit is configured to track a routing path based on the IP addresses and the access network types, evaluate each node risk of the routing path, determine attribute feature consistency, and obtain the network path security information and the network attribute features.

[0017] In an implementation, the user authentication attribute and security evaluation unit further includes:

[0018] The request event acquisition subunit is configured to obtain a request event corresponding to user authentication.

[0019] The request event risk evaluation subunit is configured to evaluate risk based on the request event, and obtain request event risk information.

[0020] The security label generation subunit is configured to use the request event risk information as an incremental identification feature, perform security information comprehensive evaluation on the access device security information and the network path security information, obtain access security evaluation information, and generate a security label of the user authentication attributes.

[0021] In an implementation, the authentication factor matching module includes:

[0022] The core authentication element determination unit is configured to analyze user attribute features based on the user authentication attributes, and determine core authentication elements.

[0023] An authentication matching certainty obtaining unit is configured to perform identity authentication element matching between the core authentication element and the multi-factor authentication mechanism, and obtain an authentication matching certainty, which describes the authentication certainty degree of the matching factor authentication mechanism for the core authentication element.

[0024] A central authentication mechanism configuration unit is configured to perform matching maximization search according to the authentication matching certainty of the multi-factor authentication mechanism, and obtain a central authentication mechanism, which is configured to have an authentication priority.

[0025] An auxiliary authentication mechanism and fusion ratio determining unit is configured to determine a security authentication target according to the security label of the user authentication attribute, perform search in the multi-factor authentication mechanism based on the security authentication target, and obtain an auxiliary authentication mechanism and a factor fusion ratio.

[0026] In a feasible implementation, the authentication matching certainty obtaining unit comprises:

[0027] An authentication experiment data establishing sub-unit is configured to establish authentication experiment data of the core authentication element and the multi-factor authentication mechanism.

[0028] An authentication matching certainty calculating sub-unit is configured to calculate an entropy value of an authentication output result of each factor authentication mechanism for the core authentication element according to the authentication experiment data, and determine the certainty of the corresponding factor authentication mechanism for authenticating the core authentication element based on the entropy value of the output result.

[0029] In a feasible implementation, the hierarchical authentication module comprises:

[0030] An authentication level construction unit is configured to establish a primary authentication level according to the central authentication mechanism, establish a secondary authentication level according to the auxiliary authentication mechanism and the factor fusion ratio, and connect the primary authentication level and the secondary authentication level.

[0031] A core authentication executing unit is configured to perform core authentication element authentication on user feedback identity data through the primary authentication level, and obtain a central authentication result.

[0032] A fusion authentication executing unit is configured to perform factor authentication on the corresponding authentication element of the user feedback identity data through the secondary authentication level, and obtain a secondary authentication result. A fusion authentication result is obtained according to the central authentication result and the secondary authentication result.

[0033] In a feasible implementation, the fusion authentication executing unit further comprises:

[0034] A certainty threshold sub-unit is configured to determine an authentication certainty threshold according to the security label of the user authentication attribute.

[0035] The fusion authentication result determination subunit is configured to perform authentication certainty comprehensive calculation based on the central authentication result and the secondary authentication result, determine whether the authentication certainty threshold is met by using the comprehensive calculation result, and set the fusion authentication result as identity authentication passed when the authentication certainty threshold is met, and record and store all authentication results.

[0036] In an available implementation, the execution steps of the fusion authentication result determination subunit further include:

[0037] Based on the security authentication target, the element authentication proportion weight of the central authentication mechanism and the auxiliary authentication mechanism is configured.

[0038] When the central authentication result is authentication passed, the auxiliary authentication mechanism with authentication passed in the secondary authentication result is obtained.

[0039] The authentication certainty corresponding to the central authentication mechanism and the auxiliary authentication mechanism with authentication passed in the secondary authentication result is weighted calculated with the authentication proportion weight to obtain the comprehensive calculation result.

[0040] In a second aspect, the present application further provides a trusted data space identity authentication method for multi-party data sharing, wherein the trusted data space identity authentication method for multi-party data sharing includes:

[0041] The user authentication channel is connected to identify the user authentication attribute.

[0042] The identity authentication element matching is performed according to the user authentication attribute and the multi-factor authentication mechanism to determine the authentication matching status of each factor authentication and the factor fusion proportion.

[0043] The hierarchical authentication is performed on the user feedback identity data according to the authentication matching status of each factor authentication and the factor fusion proportion, and the authentication process is tracked and recorded.

[0044] The identity authentication is cooperatively verified according to the hierarchical authentication result and the authentication tracking record, and the user meeting the verification result is accessed to the trusted data space.

[0045] The application discloses a multi-party data sharing trusted data space identity authentication system and method, which comprises an authentication attribute acquisition module, a authentication factor matching module, a hierarchical authentication module and an authentication verification module. BRIEF DESCRIPTION OF DRAWINGS

[0046] Figure 1 It is a structural schematic view of the multi-party data sharing trusted data space identity authentication system.

[0047] Figure 2 It is a flow schematic view of the multi-party data sharing trusted data space identity authentication method.

[0048] The reference signs are as follows: the authentication attribute acquisition module 11, the authentication factor matching module 12, the hierarchical authentication module 13 and the authentication verification module 14. DETAILED DESCRIPTION

[0049] The above technical solutions will be described in detail below by combining with the drawings in the specification and specific embodiments, so as to better understand the above technical solutions. Obviously, the described embodiments are only part of the embodiments of the application, not all embodiments of the application, and it should be understood that the application is not limited to the example embodiments for explaining the application. Based on the embodiments of the application, all other embodiments obtained by those skilled in the art without creative labor belong to the scope of protection of the application. In addition, it should be noted that, for convenience of description, only the parts related to the application are shown in the drawings, not all.

[0050] Embodiment one, as Figure 1 It is a structural schematic view of the multi-party data sharing trusted data space identity authentication system, wherein the multi-party data sharing trusted data space identity authentication system comprises:

[0051] The authentication attribute acquisition module 11 is used for connecting a user authentication channel and identifying user authentication attributes.

[0052] Specifically, the connection user authentication channel refers to establishing a communication link between the user and the identity authentication system to ensure that the user can send an authentication request to the system through a specific interface or protocol; identifying user authentication attributes refers to the identity characteristic information of the user obtained by the system through technical means, which may include user knowledge elements (information known by the user, such as username, password or personal identification code), possession elements (articles held by the user, such as USBKey, security token), inherent elements (biological characteristics of the user, such as fingerprint, facial recognition or voice recognition), etc., which are the basic data for the subsequent authentication process, used to judge the identity of the user and the security of the access environment.

[0053] For example, first, a connection channel between the user and the authentication system is established, and then technical means are used to identify user access device and network path information; specifically, the system detects the type of device used by the user (such as a notebook computer, a mobile phone, etc.) and the type of network accessed (such as an enterprise intranet, public Wi-Fi, etc.). In addition, the system also performs preliminary detection on the security state of the device, such as checking whether the device has installed necessary security software, and whether there is an anomaly in the network path, to ensure the security of the user authentication channel, thereby providing basic data support and decision basis for subsequent identity authentication.

[0054] In some embodiments, the authentication attribute acquisition module 11 comprises:

[0055] A user access information identification unit is configured to identify a user access device and an access network path according to the user authentication channel; an access device security and feature analysis unit is configured to analyze a security state and user features of the user access device according to the user access device, to determine access device security information and device attribute features; a network path security and feature analysis unit is configured to analyze the user access network path to obtain network path security information and network attribute features; and a user authentication attribute and security evaluation unit is configured to identify and match user authentication attributes according to the device attribute features and the network attribute features, to obtain the user authentication attributes, to evaluate the access security by using the access device security information and the network path security information, and to generate a security label of the user authentication attributes.

[0056] Specifically, the user access information identification unit is configured to detect the type of device and the network path through which the user accesses the system, such as identifying whether the user accesses through a mobile phone or a computer, and whether the network accessed is an enterprise intranet or public Wi-Fi; and the access device security and feature analysis unit is responsible for analyzing the security state and features of the user device, such as checking whether the device has installed security software, hardware information of the device (whether it supports specific encryption instruction sets or algorithms), etc.

[0057] Specifically, the network path security and feature analysis unit analyzes the security and features of the user accessing the network. For example, the network path security information includes the stability of the network path, whether it is a trusted network, and whether there is a risk of man-in-the-middle attack. The network attribute features include enterprise internal network, allied security network, and unknown or external network, etc. Different network attributes correspond to different security risk levels.

[0058] Specifically, the user authentication attribute and security evaluation unit comprehensively analyzes the features and security information of the device and the network to generate a security label of the user authentication attribute, which is used for decision-making in the subsequent authentication process.

[0059] For example, according to the device attribute features (including device model, operating system, hardware fingerprint, MAC address, application installation status, etc.) and the network attribute features (including IP address, geographic location, access method (Wi-Fi, 4G, VPN), and historical access record), multi-factor authentication (MFA) is used for matching to ensure the authenticity of the user identity. Optionally, the matching method includes rule matching (preset white list / black list, limiting untrusted devices or networks), behavior analysis (comparing with the historical access habits of the user such as commonly used devices and commonly used IP to trigger additional authentication in abnormal cases), and biological feature matching (such as face recognition, fingerprint, and voiceprint verification, etc.).

[0060] For example, based on the device and network security information, the risk level of the access behavior is comprehensively evaluated, including device security detection such as checking whether there is a jailbreak / root operation, whether malicious software or tampered applications are installed, and whether the device meets the enterprise security policy (such as not enabling encrypted storage), etc.; network security detection such as whether it is a public Wi-Fi or an insecure network (such as an open HTTP request), whether it is accessed through a proxy or a Tor anonymous tool, and whether the IP address belongs to a high-risk area or a known attack source.

[0061] Further, according to the authentication matching and security evaluation results, a security label is generated for dynamically adjusting the access permission. For example, if the matching is successful and the device and network are secure, normal access is allowed, which is considered as low risk (green label); if there is a slight abnormality (such as a new device login or IP change), secondary verification (SMS verification code, two-factor authentication) is required, which is considered as medium risk (yellow label); if there is a serious abnormality (such as unknown device, blacklisted IP, and root device), access is denied or requires administrator approval, which is considered as high risk (red label).

[0062] In some implementations, the network path security and feature analysis unit includes:

[0063] a network foundation parameter identification subunit, configured to identify network foundation parameters, including an IP address and an access network type;

[0064] Specifically, the network foundation parameters refer to basic information of a user when accessing a network, such as an IP address and an access network type (such as a wired network, a wireless network, a VPN, etc.). The route path tracking refers to a process of determining each network node through which a data packet passes by analyzing a network path from an initiation point to a target server of a user request, which is helpful to identify risk factors existing in the path, such as an unsafe node.

[0065] For example, a complete route path from a user device to a target server is tracked by using Traceroute or similar technologies, and each network node (such as a router or a gateway) is analyzed. Assuming that a user A (home Wi-Fi) and a user B (VPN access) access the same target server (example.com), the tracking result can be shown as follows:

[0066] Table 1 shows an example of a route path tracking result

[0067]

[0068]

[0069] Specifically, a security analysis is performed on each network node in the route path to determine whether the node is suspicious and whether a security risk (such as a high-risk IP, a proxy server, a Tor network, etc.) exists.

[0070] Specifically, a consistency determination is performed on the attribute characteristics of the network path to ensure that the network path meets a preset security policy, such as comparing a commonly used access path of a user to detect whether there is an abnormal path jump.

[0071] Table 2 shows an example of network path security information and network attribute characteristics

[0072] Evaluation Items User A (Home Wi-Fi) User B (VPN) IP Reputation Low Risk (Home IP) High Risk (VPN Data Center) Network Type Wi-Fi (Trusted) VPN (Further Check Needed) Path Hop Count 4 Hops (Normal) 5 Hops (One More Layer of VPN Proxy) Suspicious Nodes No Yes (Data Center IP) Path Stability High (Frequently Used) Low (New Path) Risk Score 10 / 100 (Low) 80 / 100 (High)

[0073] Through the above process, the system can obtain the security information and the attribute characteristics of the network path, which provides an important basis for subsequent access security evaluation, ensures the security of the network path of the user, and prevents data leakage or identity authentication failure caused by potential risks in the network path.

[0074] In some implementations, the user authentication attribute and security evaluation unit further includes:

[0075] The request event acquisition subunit is configured to obtain a request event corresponding to user authentication; the request event risk evaluation subunit is configured to perform risk evaluation according to the request event and obtain request event risk information; and the security label generation subunit is configured to take the request event risk information as an incremental identification feature, perform security information comprehensive evaluation on the access device security information and the network path security information, and obtain access security evaluation information to generate a security label of the user authentication attribute.

[0076] Specifically, the request event refers to specific operation behaviors or context information when the user initiates an authentication request, which is collected through log analysis, such as resource types accessed by the user, request time, frequency, etc. By evaluating the security risk of the request event, it can be determined whether the user has abnormality or potential threat, such as whether it is an access at an abnormal working time, whether it is an access to a high-sensitivity resource, etc., and request event risk information is generated. Exemplarily, the request event risk information includes abnormal high-frequency access and corresponding access frequency, frequent change of IP address and change situation (change rate), high-frequency access request beyond authority, etc.

[0077] Specifically, the risk information of the request event is taken as an additional security evaluation dimension, i.e., an incremental identification feature, combined with the security information of the device and the network, to more comprehensively evaluate the security of the access environment and generate a security label of the user authentication attribute. The label not only reflects the security of the device and the network, but also considers the risk of user behavior, thereby providing a more comprehensive decision basis for subsequent identity authentication.

[0078] Optionally, a weighted scoring method is adopted to fuse the access device security information, the network path security information and the incremental identification feature, calculate the overall security level, and distribute the security label of the user authentication attribute according to the calculated security level result.

[0079] In the whole scheme, the role of this process is to further refine the access security evaluation, to ensure that the authentication system can dynamically adapt to different user behaviors and access scenarios, and to enhance the flexibility and security of the system.

[0080] The authentication factor matching module 12 is configured to perform identity authentication factor matching according to the user authentication attribute and the multi-factor authentication mechanism, determine the authentication matching status and factor fusion proportion of each factor authentication.

[0081] Specifically, based on the user authentication attributes, the identity characteristics of the user are analyzed, and the appropriate multi-factor authentication mechanism is determined, and the user authentication attributes and the multi-factor authentication mechanism are matched to determine the matching status of each authentication factor. For example, if the security of the user access device is high, the system may assign a higher priority to the authentication factor based on the device fingerprint; if the network path is at risk, the weight of the SMS verification code or secondary verification may be increased.

[0082] Specifically, the authentication matching status refers to the importance or priority of a certain authentication factor relative to other factors in multi-factor authentication; the factor fusion ratio refers to the weight ratio of each authentication factor in the comprehensive authentication process, which is used to determine their contribution degree in the final authentication result; for example, for a high-risk access environment, the system may increase the weight of biometric identification (such as fingerprint or facial recognition) to 70%, and reduce the weight of password verification to 30%.

[0083] By matching the identity authentication elements according to the user authentication attributes and the multi-factor authentication mechanism, the system can dynamically determine the matching status and fusion ratio of each authentication factor. This process significantly enhances the flexibility and adaptability of identity authentication, allowing it to adjust the authentication strategy according to the user's access environment and behavior characteristics.

[0084] In some embodiments, the authentication factor matching module 12 includes:

[0085] The core authentication element determination unit is configured to analyze the user attribute characteristics based on the user authentication attributes, and determine the core authentication element; the authentication matching determination degree acquisition unit is configured to perform identity authentication element matching using the core authentication element and the multi-factor authentication mechanism, and obtain an authentication matching determination degree, which describes the authentication determination degree of the matching factor authentication mechanism for the core authentication element; the central authentication mechanism configuration unit is configured to perform a matching maximization search based on the authentication matching determination degree of the multi-factor authentication mechanism, and obtain a central authentication mechanism, and configure the central authentication mechanism to have a primary authentication position; the auxiliary authentication mechanism and fusion ratio determination unit is configured to determine a security authentication target based on the security label of the user authentication attributes, search in the multi-factor authentication mechanism based on the security authentication target, and obtain an auxiliary authentication mechanism and a factor fusion ratio.

[0086] Specifically, by matching the user authentication attributes with the multi-factor authentication mechanism, the authentication status and fusion ratio of each authentication factor are determined, thereby improving the authentication security and optimizing the authentication experience. The core authentication element refers to the attribute or feature that plays a key role in the user authentication process, such as the user's work number, fingerprint, facial recognition, etc. The authentication matching determination degree refers to the accuracy and reliability of the matching between a certain authentication factor and the core authentication element, which is used to measure the effectiveness of the authentication factor in verifying the core authentication element.

[0087] Specifically, the central authentication mechanism refers to the primary authentication method in multi-factor authentication, such as the main verification method of the core authentication element. The auxiliary authentication mechanism refers to other authentication methods used to enhance the reliability and security of authentication in addition to the central authentication mechanism. The factor fusion ratio refers to the weight ratio of the central authentication mechanism and the auxiliary authentication mechanism in the comprehensive authentication process, which is used to balance the contribution of different authentication factors.

[0088] Specifically, first, the core authentication element determination unit analyzes the user attribute characteristics based on the user authentication attributes, determines the core authentication element, such as the user's work number or biometric characteristics. Next, the authentication matching determination degree acquisition unit matches the core authentication element with the multi-factor authentication mechanism, calculates the matching determination degree of each authentication factor with the core authentication element. For example, by calculating the output result entropy value of each authentication factor through experimental data, the authentication determination degree of the core authentication element is determined. Then, the central authentication mechanism configuration unit performs a matching maximization search based on the authentication matching determination degree, selects the authentication factor with the highest determination degree as the central authentication mechanism, and configures it to have the primary authentication position. Finally, the auxiliary authentication mechanism and fusion ratio determination unit determines the security authentication target based on the security label of the user authentication attributes, and searches for suitable auxiliary authentication mechanisms and their fusion ratios in the multi-factor authentication mechanism. For example, if the security label shows that the user access environment is at risk, the weight of the auxiliary authentication mechanism may be increased.

[0089] For example, based on the user authentication attributes, the user identity characteristics are analyzed, and the core authentication elements are extracted:

[0090] Table 3 shows an example of core authentication elements

[0091] User Type Core Authentication Elements Normal User Device Information, Network Characteristics Corporate User Device Security Policy, VPN Verification High-Risk User Behavioral Patterns, Geographical Location

[0092] For example, the core authentication elements are matched with the multi-factor authentication mechanism, and the matching determination degree (i.e., the adaptability of the authentication factor to the core authentication element) is calculated. The matching determination degree calculation formula is as follows:

[0093] AMC(F i ,A j )=W i ×R(Fi ,A j );

[0094] wherein, F i represents the i-th core authentication element (such as device fingerprint, biometric feature, IP address, etc.); A j represents the j-th multi-factor authentication method (such as password, SMS verification code, fingerprint recognition, etc.); W i represents the authentication element weight, which is set based on system strategy (such as biometric recognition weight is higher than password); R(F i ,A j ) is the factor adaptation degree of the i-th core authentication element and the j-th multi-factor authentication method, which is calculated based on historical authentication data, user behavior, and environmental factors, and takes a value of 0-1.

[0095] Suppose user A accesses a financial service platform, and the system detects the core authentication elements: device fingerprint, IP address, and biometric feature; and the authentication mechanisms: password, SMS verification code, biometric recognition, and device fingerprint. Then the corresponding matching determination degree calculation table is as follows:

[0096] Table 4 Exemplary Matching Determination Degree Calculation Table

[0097]

[0098] From the analysis of the matching determination degree, the device fingerprint authentication (0.855) is the highest, and this method is preferred as the central authentication mechanism; the biometric recognition (0.72) has a relatively high adaptation, and can be used as an auxiliary authentication method; the SMS verification code (0.28) has a relatively low adaptation degree, and is only used for additional security verification.

[0099] The above process dynamically adjusts the authentication strategy by determining the core authentication elements, obtaining the authentication matching determination degree, configuring the central authentication mechanism, and determining the auxiliary authentication mechanism and the fusion ratio, to adapt to different user access environments and security requirements. Among them, the determination of the core authentication elements ensures the reliability and pertinence of the authentication process, and the calculation of the authentication matching determination degree provides a scientific basis for selecting the most suitable authentication mechanism, and the combination of the central authentication mechanism and the auxiliary authentication mechanism, as well as the dynamic adjustment of the factor fusion ratio, further enhances the flexibility and adaptability of the authentication. For example, in a high-risk access environment, the system can increase the weight of the auxiliary authentication mechanism to improve security; and in a low-risk environment, the authentication steps can be simplified to improve user experience.

[0100] The above dynamic adjustment mechanism not only improves the security and reliability of identity authentication, but also optimizes the authentication efficiency, and meets the high requirements of identity authentication in multi-party data sharing scenarios.

[0101] In some implementations, the authentication matching determination degree acquisition unit comprises:

[0102] The authentication experiment data establishing subunit is configured to establish authentication experiment data of the core authentication element and the multi-factor authentication mechanism; the authentication matching determination degree calculation subunit is configured to calculate an entropy value of an authentication output result of each factor authentication mechanism for the core authentication element according to the authentication experiment data, and determine a determination degree of the corresponding factor authentication mechanism for authenticating the core authentication element based on the entropy value of the output result.

[0103] Optionally, in the authentication process, the uncertainty of each authentication factor is evaluated in real time, such as by calculating the entropy value or confidence of the output result of each authentication factor to measure the uncertainty thereof.

[0104] Specifically, the authentication experiment data refers to data collected by experiment or simulation of an authentication scenario, and is used to evaluate the matching effect of the multi-factor authentication mechanism on the core authentication element; the entropy value is used to measure the uncertainty of information, and in identity authentication, the higher the entropy value, the greater the uncertainty of the authentication result, and vice versa; through the calculation of the entropy value, the authentication matching determination degree can be obtained, and the matching accuracy and reliability degree of a certain authentication factor on the core authentication element can be quantitatively represented.

[0105] Specifically, first, the authentication experiment data establishing subunit collects authentication data of the core authentication element and the multi-factor authentication mechanism through experiment or simulation of an authentication scenario. These data include output results of different authentication factors in different environments, such as the matching success rate of biometric recognition, the error rate of password verification, and the like. Then, the authentication matching determination degree calculation subunit calculates the entropy value of the output result of each authentication factor according to the authentication experiment data. For example, for a biometric recognition authentication factor, if the output result is highly consistent (low entropy value) in multiple experiments, it indicates that the matching determination degree of the authentication factor on the core authentication element is high; if the output result varies greatly (high entropy value), the matching determination degree is low. Based on the entropy value of the output result, the system can determine the matching determination degree of each authentication factor on the core authentication element.

[0106] By establishing authentication experiment data, the uncertainty of the output result of each authentication factor is calculated by using information entropy, so as to determine the matching determination degree, thereby providing data support for dynamic adjustment of the authentication mechanism.

[0107] The hierarchical authentication module 13 is configured to perform hierarchical authentication on the user feedback identity data according to the authentication matching status of the factors and the factor fusion ratio, and to track and record the authentication process.

[0108] Specifically, according to the matching position and fusion proportion of each authentication factor, the authentication process is divided into multiple levels, and the identity data fed back by the user is verified respectively, wherein the authentication matching position refers to the priority or importance of a certain authentication factor in the authentication process, and the factor fusion proportion refers to the weight distribution of each authentication factor in the comprehensive authentication result.

[0109] Optionally, the core authentication factor (such as biometric identification or employee number verification) is taken as the primary authentication level, and the auxiliary authentication factor (such as SMS verification code or device fingerprint) is taken as the secondary authentication level. According to the identity data fed back by the user, authentication is performed in the primary authentication level and the secondary authentication level respectively, and the primary authentication level result and the secondary authentication level result are comprehensively calculated according to the factor fusion proportion to obtain the fusion authentication result. Through hierarchical authentication and authentication process tracking record, the system can flexibly adjust the authentication strategy according to the matching position and fusion proportion of each authentication factor, and ensure that the authentication process is both efficient and safe.

[0110] Specifically, each step and result in the authentication process is recorded for subsequent audit and analysis.

[0111] In some embodiments, the hierarchical authentication module 13 comprises:

[0112] An authentication level construction unit is configured to establish a primary authentication level according to a central authentication mechanism, establish a secondary authentication level according to an auxiliary authentication mechanism and a factor fusion proportion, and connect the primary authentication level and the secondary authentication level; a core authentication execution unit is configured to perform core authentication element authentication on the identity data fed back by the user through the primary authentication level to obtain a central authentication result; a fusion authentication execution unit is configured to perform element authentication on the authentication elements corresponding to the identity data fed back by the user through the secondary authentication level to obtain a secondary authentication result; and a fusion authentication result is obtained according to the central authentication result and the secondary authentication result.

[0113] Specifically, the primary authentication level refers to an authentication stage for verifying the core elements of the user's identity based on the core authentication mechanism, which usually has a high priority and weight; and the secondary authentication level refers to an authentication stage for verifying other elements of the user's identity based on the auxiliary authentication mechanism, which is usually used to enhance the reliability and security of authentication.

[0114] Specifically, first, the authentication level construction unit establishes a primary authentication level according to the central authentication mechanism, which focuses on verifying the core authentication elements in the user feedback identity data. For example, if the core authentication element is the user's fingerprint information, the system will verify the fingerprint through biometric technology to obtain the central authentication result. Next, the authentication level construction unit establishes a secondary authentication level according to the auxiliary authentication mechanism and the factor fusion ratio, which verifies other authentication elements in the user feedback identity data. For example, the auxiliary authentication mechanism may be a short message verification code or a device fingerprint, which is verified to obtain a secondary authentication result. Then, the authentication level construction unit connects the results of the primary authentication level and the secondary authentication level, and according to the factor fusion ratio, the central authentication result and the secondary authentication result are comprehensively calculated to obtain the fusion authentication result. Through the above hierarchical authentication and weight distribution, the flexibility and security of the authentication process are ensured, and the reliability and adaptability of the authentication are improved.

[0115] In some implementations, the fusion authentication execution unit further comprises:

[0116] A determination degree threshold subunit is configured to determine an authentication determination degree threshold according to the security label of the user authentication attribute; a fusion authentication result judgment subunit is configured to perform authentication determination degree comprehensive calculation according to the central authentication result and the secondary authentication result, and to determine whether the authentication determination degree threshold is met by using the comprehensive calculation result. When the threshold is met, the fusion authentication result is set as identity authentication passed, and all authentication results are recorded and stored.

[0117] Specifically, the authentication determination degree threshold is a preset threshold for determining whether the user's identity authentication is passed. Each authentication process sets different authentication determination degree thresholds according to different risk levels (security labels of user authentication attributes), and then sets different authentication passing standards. For example, in a low-risk scenario, the determination degree threshold for authentication passing is low; in a high-risk scenario, the determination degree threshold for authentication passing is high.

[0118] Specifically, first, an authentication certainty threshold is determined according to a security label of a user authentication attribute, which reflects the risk level of a user access environment, for example, if there is a high risk in the user access environment (such as access through public Wi-Fi), a higher authentication certainty threshold is set; if the access environment is safe (such as access through an intranet), a lower threshold can be set; then, a comprehensive calculation of authentication certainty is performed according to the central authentication result and the secondary authentication result, for example, the weight of the central authentication mechanism (such as fingerprint recognition) can be 70%, and the weight of the auxiliary authentication mechanism (such as SMS verification code) can be 30%. The system adds the authentication certainty of the two results multiplied by the weight to obtain the comprehensive authentication certainty. Then, it is determined whether the threshold is met by using the comprehensive calculation result. If the comprehensive authentication certainty reaches or exceeds the threshold, the fusion authentication result is set as identity authentication passing; if the threshold is not reached, the authentication fails.

[0119] For example, if the core authentication element (such as biometric identification, digital certificate, etc.) is verified, the authentication result is considered to be more reliable, and a higher authentication certainty is usually obtained. If the core authentication element fails, but the comprehensive calculation of authentication certainty reaches the set threshold, the authentication can still be passed.

[0120] Further, all authentication results, including failed authentication results, are recorded and stored for subsequent audit to confirm compliance.

[0121] The above process sets an authentication certainty threshold and performs a comprehensive calculation to ensure that the system can flexibly determine whether the user identity authentication is passed while considering the risk of the user access environment. This mechanism allows the user identity authentication to be determined as passed even if the core authentication element passes but the auxiliary authentication element fails, as long as the comprehensive authentication certainty reaches the threshold, which improves the flexibility and adaptability of authentication, optimizes the user experience, and avoids the overall failure of authentication due to the failure of a single factor.

[0122] In some implementations, the execution steps of the fusion authentication result determination subunit further include:

[0123] Based on the security authentication target, the element authentication proportion weight of the central authentication mechanism and the auxiliary authentication mechanism is configured; when the central authentication result is authentication passing, the auxiliary authentication mechanism with authentication passing in the secondary authentication result is obtained; the authentication certainty corresponding to the central authentication mechanism and the auxiliary authentication mechanism with authentication passing in the secondary authentication result is weighted calculated with the authentication proportion weight to obtain the comprehensive calculation result.

[0124] Specifically, the authentication proportion weight refers to the weight assigned to each authentication factor (central authentication mechanism and auxiliary authentication mechanism) when calculating the authentication certainty, reflecting its importance in the authentication process.

[0125] Specifically, when the core authentication factor (central authentication) is verified, the fusion authentication result judgment subunit further evaluates whether the auxiliary authentication factor (such as dynamic password, SMS verification code, etc.) passes. For each auxiliary authentication factor, if it passes the verification (for example, the SMS verification code passes the verification), it is marked as passing the authentication. Then, according to the authentication passing factors in the central authentication mechanism and the secondary authentication mechanism, the authentication proportion weight is used for weighted calculation to obtain the final comprehensive authentication certainty.

[0126] For example, assuming that the core authentication (fingerprint authentication) certainty is 0.85 and the weight is 0.7; the secondary authentication (SMS verification code) certainty is 0.75 and the weight is 0.3. Then the comprehensive authentication certainty = (0.85 x 0.7) + (0.75 x 0.3) = 0.595 + 0.225 = 0.82.

[0127] By configuring the authentication proportion weight based on the security authentication target and performing weighted calculation according to the central authentication result and the passing auxiliary authentication result, the system can flexibly adjust the authentication strategy to ensure the reliability and adaptability of the authentication result. For example, when the core authentication factor passes, even if part of the auxiliary authentication factor fails, the system can still make a comprehensive judgment according to the weight and certainty of the passing auxiliary authentication mechanism, thereby avoiding the overall failure of the authentication due to the failure of a single factor.

[0128] The authentication verification module 14 is configured to perform identity authentication and verification in cooperation with the authentication tracking record based on the hierarchical authentication result, so as to meet the user access to the trusted data space.

[0129] Specifically, the tracking record is a detailed authentication record generated during the authentication of each user, including the authentication status of each authentication factor, the uncertainty (such as entropy value, confidence) in the authentication process, the result of weighted calculation, etc.

[0130] Specifically, when the user attempts to access the trusted data space, the system initiates an identity authentication verification request, extracts the previously generated hierarchical authentication result and authentication tracking record for comprehensive evaluation. For example, if the user's identity authentication passes and the tracking record shows no potential risks (such as multiple failed attempts, abnormal authentication time, etc.), the verification process proceeds to the next step, i.e. the user is allowed to access the trusted data space; if the tracking record shows potential risks or the authentication fails, the risk is evaluated according to the security label of the tracking record to decide whether to allow re-verification or deny access.

[0131] Through the cooperative verification of the hierarchical authentication result and the authentication tracking record, the system can comprehensively and carefully verify the authentication process of the user, and ensure that only the legal user can access the trusted data space. This mechanism not only enhances the reliability and security of identity authentication, but also provides an important basis for the security audit of the system.

[0132] In summary, the multi-party data sharing trusted data space identity authentication system provided by the application has the following technical effects:

[0133] The authentication attribute acquisition module is connected to the user authentication channel and identifies the user authentication attribute. The authentication factor matching module matches the identity authentication elements according to the user authentication attribute and the multi-factor authentication mechanism, determines the authentication matching status and factor fusion ratio of each factor authentication, and feeds back the identity data of the user to the hierarchical authentication module according to the authentication matching status and factor fusion ratio of each factor authentication, and records the authentication process. The authentication verification module performs identity authentication cooperative verification according to the hierarchical authentication result and the authentication tracking record, and meets the verification result of the user accessing the trusted data space, thereby realizing the technical effects of improving the security and reliability of identity authentication, enhancing the flexibility and adaptability of authentication, and improving the authentication efficiency.

[0134] Embodiment two, as Figure 2 is a flowchart of the multi-party data sharing trusted data space identity authentication method of the application. For example, Figure 1 The structure of the multi-party data sharing trusted data space identity authentication system of the application can be used to realize the flowchart as Figure 2 indicated.

[0135] Based on the same idea as the multi-party data sharing trusted data space identity authentication system in the embodiments, the application also provides a multi-party data sharing trusted data space identity authentication method, which includes:

[0136] Connect the user authentication channel and identify the user authentication attribute.

[0137] According to the user authentication attribute and the multi-factor authentication mechanism, the identity authentication elements are matched, the authentication matching status and the factor fusion ratio of each factor authentication are determined.

[0138] According to the authentication matching status and the factor fusion ratio of each factor authentication, the identity data of the user is fed back to the hierarchical authentication module for hierarchical authentication, and the authentication process is recorded.

[0139] According to the hierarchical authentication result and the authentication tracking record, the identity authentication cooperative verification is performed, and the user meeting the verification result accesses the trusted data space.

[0140] In some embodiments, the connection of the user authentication channel and the identification of the user authentication attribute includes:

[0141] According to the user authentication channel, a user access device and an access network path are identified.

[0142] According to the user access device, user access device information is analyzed in terms of security state and user characteristics, and access device security information and device attribute characteristics are determined.

[0143] The user access network path is analyzed to obtain network path security information and network attribute characteristics.

[0144] According to the device attribute characteristics and the network attribute characteristics, user authentication attribute identification matching is performed to obtain user authentication attributes, and access security evaluation is performed using the access device security information and the network path security information to generate a security label of the user authentication attributes.

[0145] In some implementations, the user access network path is analyzed to obtain network path security information and network attribute characteristics, including:

[0146] Network basic parameters, including IP addresses and access network types, are identified.

[0147] Based on the IP addresses and access network types, route path tracking is performed, and each node risk assessment and attribute characteristic consistency determination are performed on the route path to obtain the network path security information and the network attribute characteristics.

[0148] In some implementations, the access security evaluation is performed using the access device security information and the network path security information to generate a security label of the user authentication attributes, and further includes:

[0149] A request event corresponding to user authentication is obtained.

[0150] Risk evaluation is performed according to the request event to obtain request event risk information.

[0151] The request event risk information is used as an incremental identification feature, and security information comprehensive evaluation is performed on the access device security information and the network path security information to obtain access security evaluation information to generate the security label of the user authentication attributes.

[0152] In some embodiments, identity authentication element matching is performed according to the user authentication attributes and a multi-factor authentication mechanism to determine authentication matching status and factor fusion proportion of each factor authentication, including:

[0153] User attribute characteristic analysis is performed according to the user authentication attributes to determine core authentication elements.

[0154] The core authentication element is matched with the multi-factor authentication mechanism to obtain an authentication matching certainty, which describes the authentication certainty of the matching factor authentication mechanism to the core authentication element.

[0155] A central authentication mechanism is obtained by performing a matching maximization search according to the authentication matching certainty of the multi-factor authentication mechanism, and the central authentication mechanism is configured to have an authentication priority.

[0156] A security authentication target is determined according to the security label of the user authentication attribute, and an auxiliary authentication mechanism and a factor fusion ratio are obtained by searching in the multi-factor authentication mechanism based on the security authentication target.

[0157] In some implementations, the core authentication element is matched with the multi-factor authentication mechanism to obtain an authentication matching certainty, including:

[0158] The authentication experimental data of the core authentication element and the multi-factor authentication mechanism are established.

[0159] According to the authentication experimental data, the entropy value of the authentication output result of each factor authentication mechanism to the core authentication element is calculated, and the certainty of the corresponding factor authentication mechanism to the authentication of the core authentication element is determined based on the entropy value of the output result.

[0160] In some embodiments, the user feedback identity data is subjected to hierarchical authentication according to the authentication matching position and the factor fusion ratio of each factor authentication, including:

[0161] A primary authentication level is established according to the central authentication mechanism, a secondary authentication level is established according to the auxiliary authentication mechanism and the factor fusion ratio, and the primary authentication level and the secondary authentication level are connected.

[0162] The user feedback identity data is subjected to core authentication element authentication through the primary authentication level to obtain a central authentication result.

[0163] The corresponding authentication element of the user feedback identity data is subjected to element authentication through the secondary authentication level to obtain a secondary authentication result.

[0164] A fusion authentication result is obtained according to the central authentication result and the secondary authentication result.

[0165] In some implementations, the fusion authentication result is obtained, including:

[0166] An authentication certainty threshold is determined according to the security label of the user authentication attribute.

[0167] According to the central authentication result and the secondary authentication result, a comprehensive calculation of authentication certainty is performed, and a result of the comprehensive calculation is used to determine whether a threshold of authentication certainty is met, and when the threshold is met, the fusion authentication result is set as identity authentication passing, and all authentication results are recorded and stored.

[0168] In some implementations, the comprehensive calculation of authentication certainty according to the central authentication result and the secondary authentication result includes:

[0169] Based on the security authentication target, an authentication proportion weight of elements of the central authentication mechanism and the auxiliary authentication mechanism is configured.

[0170] When the central authentication result is authentication passing, an auxiliary authentication mechanism with authentication passing in the secondary authentication result is obtained.

[0171] The authentication certainty corresponding to the central authentication mechanism and the auxiliary authentication mechanism with authentication passing in the secondary authentication result is weighted calculated with the authentication proportion weight, and the comprehensive calculation result is obtained.

[0172] It should be understood that the embodiments mentioned in the specification focus on their differences from other embodiments, and the specific embodiments in the first embodiment are also applicable to the multi-party data sharing trusted data space identity authentication method described in the second embodiment. For the sake of brevity of the specification, no further expansion is made here.

[0173] It should be understood that the embodiments disclosed in the present application and the above description can enable those skilled in the art to implement the present application. At the same time, the present application is not limited to the part of the embodiments mentioned above, and it should be understood that the ordinary skilled in the art can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and all should be included in the protection scope of the present application.

Claims

1. A trusted data space authentication system for multi-party data sharing, characterized in that, include: The authentication attribute acquisition module is used to connect to the user authentication channel and identify user authentication attributes; The authentication factor matching module is used to match identity authentication elements with the user authentication attributes and the multi-factor authentication mechanism, and determine the authentication matching status and factor fusion ratio of each factor authentication. The authentication matching status refers to the importance or priority of a certain authentication factor relative to other factors in multi-factor authentication. Factor integration ratio refers to the weight ratio of each certification factor in the comprehensive certification process; The hierarchical authentication module is used to perform hierarchical authentication on user feedback identity data based on the authentication matching status and factor fusion ratio of each factor, and to track and record the authentication process. The authentication and verification module is used to perform collaborative identity verification based on the hierarchical authentication results and authentication tracking records, so as to satisfy the user access to the trusted data space based on the verification results. The authentication factor matching module includes: The core authentication element determination unit is used to perform user attribute feature analysis based on the user authentication attributes to determine the core authentication elements. The authentication matching certainty acquisition unit is used to match the core authentication elements with the multi-factor authentication mechanism to obtain the authentication matching certainty, wherein the authentication matching certainty describes the degree of certainty of the matching factor authentication mechanism for the core authentication elements; The central authentication mechanism configuration unit is used to perform a matching maximization search based on the authentication matching certainty of the multi-factor authentication mechanism to obtain the central authentication mechanism, and configure the central authentication mechanism to have the primary status of authentication. The auxiliary authentication mechanism and fusion ratio determination unit is used to determine the security authentication target based on the security label of the user authentication attribute, and search in the multi-factor authentication mechanism based on the security authentication target to obtain the auxiliary authentication mechanism and factor fusion ratio; The authentication matching certainty acquisition unit includes: The certification experiment data establishment subunit is used to establish certification experiment data for the core certification elements and the multi-factor certification mechanism; The authentication matching certainty calculation subunit is used to calculate the entropy value of the authentication output result of each factor authentication mechanism for the core authentication element based on the authentication experiment data, and determine the certainty of the corresponding factor authentication mechanism for authenticating the core authentication element based on the entropy value of the output result.

2. The trusted data space identity authentication system for multi-party data sharing of claim 1, wherein, The authentication attribute acquisition module includes: The user access information identification unit is used to identify the user access device and access network path based on the user authentication channel. The access device security and feature parsing unit is used to parse the security status and user features of the user access device information based on the user access device, and to determine the access device security information and device attribute features. The network path security and feature analysis unit is used to analyze the user's access network path to obtain network path security information and network attribute features. The user authentication attribute and security evaluation unit is used to identify and match user authentication attributes based on the device attribute features and the network attribute features to obtain user authentication attributes, evaluate access security using the access device security information and the network path security information, and generate a security label for the user authentication attributes.

3. The trusted data space identity authentication system for multi-party data sharing of claim 2, wherein, The network path security and feature analysis unit includes: The network basic parameter identification subunit is used to identify network basic parameters, including IP address and access network type. The network path security and feature acquisition subunit is used to perform routing path tracing based on the IP address and access network type, conduct risk assessment and attribute feature consistency determination for each node of the routing path, and obtain the network path security information and network attribute features.

4. The trusted data space identity authentication system for multi-party data sharing of claim 2, wherein, The user authentication attribute and security evaluation unit further includes: The request event acquisition sub-unit is used to obtain the request event corresponding to user authentication; The request event risk assessment subunit is used to assess the risk of the request event and obtain the request event risk information. The security tag generation subunit is used to take the request event risk information as an incremental identification feature, and perform a comprehensive security information evaluation with the access device security information and the network path security information to obtain access security evaluation information and generate the security tag of the user authentication attribute.

5. The trusted data space identity authentication system for multi-party data sharing of claim 1, wherein, The tiered authentication module includes: The authentication level construction unit is used to establish a primary authentication level according to the central authentication mechanism, establish a secondary authentication level according to the auxiliary authentication mechanism and the factor fusion ratio, and connect the primary authentication level and the secondary authentication level. The core authentication execution unit is used to authenticate the user's feedback identity data through the primary authentication level and obtain the central authentication result. The fusion authentication execution unit is used to perform element authentication on the authentication elements corresponding to the user feedback identity data through the secondary authentication level to obtain the secondary authentication result; and to obtain the fusion authentication result based on the central authentication result and the secondary authentication result.

6. The trusted data space identity authentication system for multi-party data sharing of claim 5, wherein, The fusion authentication execution unit further includes: The certainty threshold subunit is used to determine the authentication certainty threshold based on the security label of the user authentication attribute; The fusion authentication result determination subunit is used to perform a comprehensive calculation of authentication certainty based on the central authentication result and the secondary authentication result, and use the comprehensive calculation result to determine whether the authentication certainty threshold is met. When the threshold is met, the fusion authentication result is set as successful identity authentication, and all authentication results are recorded and stored.

7. The trusted data space identity authentication system for multi-party data sharing of claim 6, wherein, The execution steps of the fusion authentication result determination subunit also include: Based on the security authentication objective, configure the element authentication weighting of the central authentication mechanism and the auxiliary authentication mechanism; When the central authentication result is successful, the auxiliary authentication mechanism that has been successfully authenticated in the secondary authentication result is obtained; The comprehensive calculation result is obtained by weighting the authentication certainty corresponding to the authentication passed auxiliary authentication mechanism in the central authentication mechanism and the authentication proportion weight in the secondary authentication result.

8. A trusted data space authentication method for multi-party data sharing, characterized in that, The trusted data space identity authentication system for multi-party data sharing, applied to any one of claims 1-7, comprises the following: Connect to the user authentication channel and identify user authentication attributes; The identity authentication elements are matched based on the user authentication attributes and the multi-factor authentication mechanism to determine the authentication matching status and factor fusion ratio of each factor authentication. The user feedback identity data is classified and authenticated according to the authentication matching status and factor fusion ratio of each factor, and the authentication process is tracked and recorded. Based on the hierarchical authentication results and authentication tracking records, identity authentication is collaboratively verified, and users who meet the verification results are granted access to the trusted data space.

Citation Information

Patent Citations

  • Identity information fusion system based on multiple features

    CN111539471A

  • Transaction request processing method, device and equipment

    CN116934340A