Cross-system non-inductive switching authentication method and device for e-commerce

By constructing a user behavior feature vector group and historical abnormal behavior archives, the authentication strategy of the e-commerce system is dynamically adjusted, which solves the problems of poor user experience and security caused by fixed authentication strategies in existing technologies, and realizes accurate assessment of user operation risks and adaptive adjustment of authentication strength.

CN120602224AActive Publication Date: 2025-09-05SHENZHEN HUAQIANG ELECTRONIC TRANSACTIONS NETWORK CO LTD

Patent Information

Application Number
CN202511086499.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-09-05
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

The authentication strategy of existing e-commerce systems is fixed and cannot dynamically perceive changes in user behavior, resulting in poor user experience and security.

Method used

By acquiring user behavior data, constructing a user behavior feature vector group, combining historical abnormal behavior archives to conduct risk assessment, dynamically adjusting authentication strategies, and generating targeted authentication process solutions.

Benefits of technology

It achieves dynamic and accurate assessment of user operation risks, improves the automation and intelligence level of the authentication system, ensures transaction security, and reduces unnecessary interruptions to low-risk operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602224A_ABST
    Figure CN120602224A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer authentication, and discloses a cross-system non-inductive switching authentication method and device for e-commerce, electronic equipment and a storage medium. The method comprises the following steps: acquiring user behavior data, and generating a user behavior data set; extracting user behavior features, and constructing a feature vector group; matching a user behavior mode in combination with a historical abnormal file, and giving an initial score to an abnormal risk; if the score exceeds a threshold value, performing cross validation on the login time distribution and the operation instruction sequence, and determining an abnormal risk level; according to the risk level, matching an authentication strategy, and generating a targeted authentication process scheme; and issuing the scheme to the front end of the equipment for execution, and determining an authentication result. According to the method, through dynamic and accurate risk assessment and adaptive adjustment of the authentication strength, the problem of low user experience and safety caused by a fixed authentication strategy in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer authentication technology, and in particular to a method and device for seamless cross-system switching authentication for e-commerce. Background Art

[0002] On modern e-commerce platforms, user authentication is the first line of defense for ensuring transaction security and user data safety. As e-commerce businesses expand, a single platform often integrates multiple subsystems, including transactions, payments, logistics, and customer service. Users must authenticate themselves when switching between these subsystems.

[0003] Currently, to ensure security, e-commerce systems generally employ static rule-based authentication methods. For example, regardless of whether user behavior is abnormal, a fixed authentication method of "password + SMS verification code" is used. While other methods incorporate risk detection, their assessment dimensions are limited and data is lagging. For example, assessing risk solely by determining whether the login IP address is abnormal makes it difficult to fully and realistically reflect the true risk level of the user's current operation. These existing authentication strategies are relatively fixed and lack the ability to dynamically perceive and adapt to user behavior and environmental changes.

[0004] If an overly strict authentication policy is adopted, user operations will be frequently interrupted, reducing the user experience; if an overly loose policy is adopted, the system will be slow to respond to new or potential fraudulent activities, which may easily lead to security vulnerabilities. Therefore, existing technologies result in poor user experience and security. Summary of the Invention

[0005] The present invention provides a cross-system seamless switching authentication method, device, electronic device and storage medium for e-commerce, so as to solve the problems in the prior art of low user experience and security caused by fixed authentication strategies and inability to dynamically perceive risks.

[0006] In a first aspect, in order to solve the above technical problems, the present invention provides a cross-system seamless switching authentication method for e-commerce, comprising: Obtain user behavior data, process it, and generate a user behavior data set; Extracting user behavior features based on the user behavior dataset and constructing a user behavior feature vector group; Based on the user behavior feature vector group and in combination with the system's historical abnormal behavior archive, the user behavior pattern is matched and an initial abnormal risk score is assigned; If the initial abnormal risk score exceeds a preset first threshold, cross-validating the login time distribution and operation instruction sequence in the user behavior feature vector group to determine a specific abnormal risk level; According to the specific level of abnormal risk, matching authentication strategies from the preset authentication strategy library to generate targeted authentication process solutions; The targeted authentication process plan is sent to the device front end for execution to determine the authentication execution result.

[0007] Preferably, the acquiring of user behavior data and processing thereof to generate a user behavior data set includes: Collect user login time distribution data, device switching frequency data, and geographic location change data in real time, set a unique identifier for each type of data, and obtain the initial user behavior record set; Extracting the user identifier and the operation instruction record of the login time distribution data from the initial user behavior record set, and performing missing value completion and format standardization to generate a cleaned user behavior record set; Automatically mark abnormalities and perform corrections on data in the cleaned user behavior record set where the timestamp corresponding to the user identifier does not match the data source, thereby obtaining a verified user behavior record set; According to the verified user behavior record set, the device switching frequency data and the geographic location change data are standardized and fused to obtain the user behavior data set.

[0008] Preferably, extracting user behavior features based on the user behavior dataset and constructing a user behavior feature vector group includes: Extracting user interaction response speed, common function preferences, and abnormal operation ratio as user behavior features based on the user behavior dataset; The extracted user behavior features are grouped and labeled in layers to obtain quantitative feature indices; the quantitative feature indices are multi-dimensionally mapped to construct the user behavior feature vector group.

[0009] Preferably, the matching of user behavior patterns and assigning an initial abnormal risk score based on the user behavior feature vector group and the system's historical abnormal behavior archives includes: Analyzing the geographic location change data, device switching frequency data, and operation frequency fluctuation data according to the user behavior feature vector group to obtain a current behavior pattern; According to the current behavior pattern, a mapping relationship between behavior patterns and risk scores preset in the historical abnormal behavior archive is matched to assign an initial abnormal risk score.

[0010] Preferably, cross-validating the login time distribution and operation instruction sequence in the user behavior feature vector group to determine the specific level of abnormal risk includes: For the login time distribution, by comparing it with the system's historical login time period pattern, obtaining an abnormality determination result of the login time distribution; Comparing the operation instruction sequence with the historical operation instruction sequence of the system to obtain a consistency determination result of the operation instruction sequence; The abnormality determination result and the consistency determination result are combined to perform cross-validation to determine the specific level of the abnormality risk.

[0011] Preferably, the method of matching authentication policies from a preset authentication policy library according to the specific level of abnormal risk and generating a targeted authentication process solution includes: Filtering a set of authentication methods from the authentication policy library according to the specific level of the abnormal risk; Sorting the authentication methods in the authentication method set based on the differences between the user behavior characteristics and the business scenarios, and determining the order of verification steps; The authentication method set is bound to the verification step sequence to generate the targeted authentication process solution.

[0012] Preferably, the step of sending the targeted authentication process solution to the device front end for execution and determining the authentication execution result includes: According to the targeted authentication process scheme, dynamically adjust the interactive interface prompt content and verification time limit to generate the front-end authentication configuration; Send the front-end authentication configuration to the authentication execution module at the front end of the device to obtain the user authentication link configuration that changes in real time; According to the configuration of the user authentication link, the authentication data returned by the authentication execution module is extracted to determine the authentication execution result.

[0013] In a second aspect, the present invention provides a cross-system seamless switching authentication device for e-commerce, comprising: The data collection module is used to obtain user behavior data, process it, and generate a user behavior data set; A feature construction module, configured to extract user behavior features and construct a user behavior feature vector group based on the user behavior dataset; A risk assessment module is used to match user behavior patterns and assign an initial abnormal risk score based on the user behavior feature vector group and historical abnormal behavior archives; a risk level judgment module, configured to, if the initial abnormal risk score exceeds a preset first threshold, cross-validate the login time distribution and operation instruction sequence in the user behavior feature vector group to determine a specific abnormal risk level; An authentication decision module is used to match authentication policies from a preset authentication policy library according to the specific level of the abnormal risk and generate a targeted authentication process plan; The authentication execution module is used to send the targeted authentication process plan to the device front end for execution and determine the authentication execution result.

[0014] In a third aspect, the present invention also provides an electronic device comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements any one of the above-mentioned cross-system seamless switching authentication methods for e-commerce.

[0015] In a fourth aspect, the present invention also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute any one of the above-mentioned cross-system seamless switching authentication methods for e-commerce.

[0016] Compared with the prior art, the present invention has the following beneficial effects: (1) The present invention collects user behavior data from multiple e-commerce subsystems in real time and uses a distributed framework to clean, correct and integrate it, thus solving the technical problem of data integration difficulties caused by the dispersion and different formats of data sources in the existing technology, and providing a comprehensive and high-quality data foundation for subsequent accurate risk assessment.

[0017] (2) The present invention achieves a dynamic and accurate assessment of user operation risks by constructing a user behavior feature vector group and establishing a two-level assessment mechanism of initial risk screening and in-depth verification. It can effectively identify potential abnormal behaviors and solve the problem of inaccurate risk assessment caused by existing technologies relying on a single and lagging data dimension.

[0018] (3) The present invention matches and generates targeted authentication process solutions from the policy library based on the specific risk level dynamically assessed, and sends them to the front-end for execution in real time, thereby achieving adaptive adjustment of authentication strength. While ensuring the security of high-risk operations, it reduces unnecessary interference with low-risk operations and improves the automation and intelligence level of the authentication system. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 This is a flowchart of a cross-system seamless switching authentication method for e-commerce provided by the first embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a cross-system seamless switching authentication device for e-commerce provided by the second embodiment of the present invention. DETAILED DESCRIPTION

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0021] Reference Figure 1 The first embodiment of the present invention provides a cross-system seamless switching authentication method for e-commerce, comprising the following steps: S11, obtaining user behavior data, processing it, and generating a user behavior data set; S12, extracting user behavior features based on the user behavior dataset and constructing a user behavior feature vector group; S13, matching user behavior patterns and assigning an initial abnormal risk score based on the user behavior feature vector group and the system's historical abnormal behavior archive; S14, if the initial abnormal risk score exceeds a preset first threshold, cross-validating the login time distribution and the operation instruction sequence in the user behavior feature vector group to determine a specific abnormal risk level; S15, matching authentication policies from a preset authentication policy library according to the specific level of the abnormal risk, and generating a targeted authentication process plan; S16, sending the targeted authentication process solution to the device front end for execution, and determining the authentication execution result.

[0022] In step S11, user behavior data is obtained and processed to generate a user behavior data set, including: Collect user login time distribution data, device switching frequency data, and geographic location change data in real time, set a unique identifier for each type of data, and obtain the initial user behavior record set; Extracting the user identifier and the operation instruction record of the login time distribution data from the initial user behavior record set, and performing missing value completion and format standardization to generate a cleaned user behavior record set; Automatically mark abnormalities and perform corrections on data in the cleaned user behavior record set where the timestamp corresponding to the user identifier does not match the data source, thereby obtaining a verified user behavior record set; According to the verified user behavior record set, the device switching frequency data and the geographic location change data are standardized and fused to obtain the user behavior data set.

[0023] It's important to note that when collecting real-time data on user login time distribution, device switching frequency, and geographic location changes, this dispersed data is collected from the subsystems of various e-commerce platforms through multi-system interfaces. This data is then integrated into an initial set of user behavior records and stored in a pre-established database. Each data type, such as login time, device switching frequency, and geographic location change data, is assigned a unique identifier—for example, login time data is identified as LT001. This facilitates subsequent tracing and analysis, effectively improving data integration efficiency and ensuring that data sources are clearly traceable. For example, let's assume an e-commerce platform has 100,000 users logging in daily. Login times are collected every minute through an interface to generate time distribution data. Device switching frequency records the number of times a user switches from their phone to their computer within a 24-hour period, assuming an average of two switches per person per day. Geographic location change data is obtained from the user's IP address or GPS information when they log in, recording the number of daily location changes, assuming an average of three per person per day. This data is aggregated to form an initial set of user behavior records, which are stored in a database. Each data type is assigned a unique identifier, such as LT001 for login time data, to facilitate subsequent tracing and analysis.

[0024] It should be noted that when extracting the operation instruction records of user identification and login time distribution data from the initial user behavior record set, and performing missing value completion and format standardization, incomplete operation instruction records are obtained from the user identification and login period attributes in the initial user behavior record set, and the records are completed and formatted using distributed data processing tools (such as Hadoop) to obtain a preliminary cleaned behavior data set. For example, if an e-commerce platform has 50,000 daily user login records, some of which lack login time information, the platform can correlate historical login data based on the user ID to infer the missing time information. For example, the missing login time can be supplemented with the user's common login time period in the past seven days, such as 8:00 PM to 10:00 PM. At the same time, the format adjustment will unify the time format to a 24-hour system, such as adjusting "8:00 PM" to "8:00 PM" to ensure data consistency. It should be noted that when automatically marking anomalies and performing corrections on data in the cleaned user behavior record set where the timestamp corresponding to the user ID does not match the data source, the initial cleaned behavior data set must be verified for record integrity and timestamp consistency. If the timestamp corresponding to the user ID does not match the data source, it will be marked and corrected to determine the behavior data set after consistency verification.

[0025] After verifying the user behavior record set, the device switching frequency data and the location change data are normalized. When the user behavior data set is obtained after fusion, the location and behavior frequency attributes are normalized. If the behavior frequency exceeds the preset frequency threshold, the location data is correlated and calibrated to determine the standardized behavior data set.

[0026] For example, if a user logs in 10 times per day, exceeding a preset threshold by 5, the system will automatically correlate their geolocation data to identify unusual logins. If a user frequently switches between cities 500 kilometers apart, the system will flag this as an anomaly and perform a calibration. By identifying the user's historical location distribution, the anomalous data will be adjusted to reflect the most common location records. Multi-dimensional fusion processing is then performed on interaction pattern attributes to generate a standardized behavioral dataset. In step S12, user behavior features are extracted based on the user behavior dataset to construct a user behavior feature vector group, including: Extracting user interaction response speed, common function preferences, and abnormal operation ratio as user behavior features based on the user behavior dataset; Grouping and layering the extracted user behavior features to obtain quantitative feature indicators; The quantitative feature indicators are mapped into multiple dimensions to construct the user behavior feature vector group.

[0027] It should be noted that when extracting user interaction response speed, common function preferences and abnormal operation ratio as user behavior characteristics based on the standardized behavior data set, relevant record values ​​are obtained for the user response speed and interaction response time attributes, and the record values ​​are grouped by time interval division to obtain user response speed distribution data. For example, the average response speed of users on an e-commerce platform is 2 seconds between 8:00 PM and 10:00 PM, and 3 seconds between 9:00 AM and 11:00 AM. This distribution data helps identify user active periods. Based on the common function preferences and function usage frequency attributes, user function usage records are categorized and summarized. If the function usage frequency exceeds a preset threshold (e.g., 5 times per day), the common function preferences are prioritized and a set of function preference weights is determined. For example, if the search function has an average daily usage frequency of 8 times, the weight is set to 0.8. Based on the abnormal operation ratio and operation anomaly distribution attributes, user operation records are detected for anomalies. If the frequency of abnormal behavior exceeds a preset threshold (e.g., 2 times per day), the operation anomaly distribution is stratified and labeled to determine the abnormal operation ratio range. For example, if the stratification is labeled "high-frequency anomaly," the ratio range is set to 60%. It is worth noting that when the extracted user behavior features are grouped and layered to obtain quantitative feature indicators, they are divided into multiple levels and each level is assigned a different numerical value to form a quantitative indicator. For common function preferences, weights are calculated based on the frequency of user use of different functions, and frequently used functions are assigned higher weights. For the proportion of abnormal operations, the frequency and severity of abnormal behavior are stratified into "low risk," "medium risk," "high risk," etc., and corresponding numerical values ​​are set for each level.

[0028] It should be noted that when the quantitative feature indicators are multi-dimensionally mapped to construct the user behavior feature vector group, the response speed fluctuations are multi-dimensionally mapped according to the different attributes of user behavior patterns and interaction habits to obtain the user behavior feature vector group. User interaction response speed refers to the time it takes for a user to take the next action after receiving information from the system interface. This feature reflects the user's familiarity with the operational process and their decision-making habits. The interaction response duration for each user action is recorded from the dataset. Common function preference refers to which functional modules (such as search, browsing, favorites, and reviews) a user prefers to use within the e-commerce platform. This feature reflects the user's core needs and usage purposes. The abnormal operation ratio indicates the proportion of user actions that the system initially identifies as abnormal (such as short, high-frequency repeated clicks and unconventional page jumps). This feature is directly associated with potential risky behaviors.

[0029] For example, multi-dimensional mapping involves associating quantitative characteristic indicators (such as user interaction response speed, common function preference, and abnormal operation ratio) with user behavior patterns and interaction habit differences. For example, a user's average response speed in payment scenarios is 4 seconds, while it stabilizes at 2 seconds in browsing scenarios, and 70% of their operations occur at night. The system maps these quantitative characteristic indicators with behavioral patterns such as "nighttime activity" and "hesitation in payment scenarios" to construct a user behavior feature vector group. This vector group is a collection of values ​​across multiple dimensions, each representing a quantitative characteristic indicator, such as [average response speed (payment scenario), average response speed (browsing scenario), nighttime operation ratio, common function preference weight (search), common function preference weight (favorite), abnormal operation ratio]. Through this mapping, the system can infer that the user's nighttime payment behavior may be due to factors such as hesitation or network latency.

[0030] Specifically, when analyzing user response speed distribution data, users with an average daily operation record of more than 100 are prioritized as samples to ensure sufficient representativeness of the data. Furthermore, when determining the function preference weight set, the weights are dynamically adjusted based on the user's 30-day history to enhance the timeliness of the preferences. For anomaly detection, contextual operation records are introduced as auxiliary judgment criteria. For example, combined with login device information, it can be used to determine whether an anomaly is caused by a device switch. When constructing behavioral feature vector groups, the mapping results are updated weekly to capture short-term changes in user habits. In step S13, based on the user behavior feature vector group and combined with the system's historical abnormal behavior archive, the user behavior pattern is matched and an initial abnormal risk score is assigned, including: Analyzing the geographic location change data, device switching frequency data, and operation frequency fluctuation data according to the user behavior feature vector group to obtain a current behavior pattern; According to the current behavior pattern, a mapping relationship between behavior patterns and risk scores preset in the historical abnormal behavior archive is matched to assign an initial abnormal risk score.

[0031] In one implementation, this step specifically includes: In the first step, based on the user behavior feature vector group, the geographic location change data, device switching frequency data, and operation frequency fluctuation data are analyzed to obtain the current behavior pattern.

[0032] It should be noted that this step focuses on extracting dynamic behavior data directly related to account security from the user's feature vector.

[0033] Exemplarily, location change data includes the degree of deviation between the current location and historically preferred locations, as well as the frequency of such deviations. Specifically, the user's login location preferences (e.g., their preferred city and frequently used work / home network IP addresses) are obtained from historical records. The degree of deviation between the current location and historically preferred locations, as well as the frequency of such deviations, are then calculated by time period.

[0034] Device switching frequency data includes whether a user's recent device switching behavior exceeds a preset switching threshold or deviates from their historical device type preferences. Specifically, the user's recent device usage records are extracted and analyzed to determine whether their device switching behavior exceeds a preset switching threshold or deviates from their historical device type preferences.

[0035] Operation frequency fluctuation data includes whether there are sudden increases in the number of operations per unit time, or whether the user is active during unusual time periods. Specifically, we extract the user's operation records and analyze whether there are sudden increases in the number of operations per unit time, or whether the user is active during unusual time periods (such as late at night).

[0036] By integrating these three aspects of data, we can obtain the user's current dynamic behavior pattern.

[0037] For example, user B's feature vector data shows that over the past hour, their location changed from their usual home in Beijing to a foreign city they've never logged into. They also switched from their usual phone to a newer computer, and their frequency of operations (such as placing orders and making payments) increased fivefold compared to their usual daily frequency. By integrating this information, we can form a behavioral pattern: "different location, new device, high-frequency trading."

[0038] In the second step, according to the current behavior pattern, a mapping relationship between the behavior pattern and the risk score preset in the historical abnormal behavior archive is matched, and an initial abnormal risk score is assigned.

[0039] It's important to note that the "Historical Abnormal Behavior Archive" is a pre-established knowledge base containing numerous confirmed cases of fraud, account theft, and other risk events. Each case includes the behavioral pattern at the time of occurrence and the corresponding risk score. This archive is dynamically updated by continuously learning new risk cases. The "current behavior pattern" obtained in the first step is compared and matched with various "pre-set abnormal patterns" in the archive. The higher the similarity of the match, the higher the initial risk score assigned.

[0040] For example, User B's "remote location, new device, high-frequency trading" pattern closely matches (95% similarity) a typical pattern in the historical abnormal behavior archive: "account theft followed by resale of stolen goods remotely." This typical pattern has a preset risk score of 90 (out of 100) in the archive. Therefore, User B's behavior is assigned an initial abnormal risk score of 90. Users with normal behavior patterns, on the other hand, would receive a much lower risk score, such as 5.

[0041] In step S14, the login time distribution and the operation instruction sequence in the user behavior feature vector group are cross-validated to determine the specific level of abnormal risk, including: For the login time distribution, by comparing it with the system's historical login time period pattern, obtaining an abnormality determination result of the login time distribution; Comparing the operation instruction sequence with the historical operation instruction sequence of the system to obtain a consistency determination result of the operation instruction sequence; The abnormality determination result and the consistency determination result are combined to perform cross-validation to determine the specific level of the abnormality risk.

[0042] In one implementation, this step specifically includes: The first step is to compare the login time distribution with the system's historical login time period patterns to obtain an abnormality determination result of the login time distribution.

[0043] It's important to note that each user typically has a relatively fixed online activity schedule. "Historical login time patterns" are individual time profiles generated by the system based on long-term user behavior data. For example, a white-collar user's peak login times on weekdays are 9-11 a.m. and 8-10 p.m., while weekends are concentrated in the afternoon. The current login time is compared with this historical pattern.

[0044] For example, a user's initial anomaly risk score is 75, exceeding the first threshold of 60 points, triggering deep verification. The user's login occurred at 3:00 AM, but their historical login time patterns show they have never logged in during this time period in the past year. Furthermore, their late-night login frequency exceeds the preset "maximum once per week" threshold. Therefore, a "high confidence anomaly" is determined for their login time distribution.

[0045] In the second step, the operation instruction sequence is compared with the historical operation instruction sequence of the system to obtain a consistency determination result of the operation instruction sequence.

[0046] It should be noted that when a user performs a task (such as shopping or searching), the sequence of their steps is usually logical and habitual. The "historical operation sequence" is the typical operation process of the user completing various tasks recorded by the system.

[0047] For example, a user's shopping habit sequence is: login -> search for products -> browse details -> add to cart -> submit order -> pay. A sequence comparison algorithm compares the current user's sequence of operations with their historical habit sequence, calculating their degree of consistency. For example, in the aforementioned case, the system further analyzed the user's operation sequence at 3:00 AM and found that it was: login -> directly access the high-value product page -> immediately place an order and pay, without any searching, browsing, or comparison in between. This sequence's consistency score with their historical shopping habit sequence was only 20% (out of a maximum of 100%), far below the normal threshold of 80%. Therefore, the system determined that the user's operation sequence was "high-confidence inconsistency."

[0048] The third step is to combine the abnormality determination result and the consistency determination result to perform cross-validation to determine the specific level of the abnormality risk.

[0049] It should be noted that this step integrates the verification results of the above multiple dimensions through a preset decision matrix or rule engine to output the final risk level.

[0050] Exemplarily, the decision rules are as follows: If the login time is "high confidence abnormal" and the instruction sequence is "high confidence inconsistent", the risk level is determined to be "high risk".

[0051] If the login time is "high confidence abnormal" or the instruction sequence is "high confidence inconsistent", the risk level is determined to be "medium risk".

[0052] In other cases, the risk level is "low risk".

[0053] In the above embodiment, since two high-confidence abnormal conditions are satisfied at the same time, the system ultimately determines that the specific level of abnormal risk is "high risk".

[0054] In step S15, according to the specific level of the abnormal risk, the authentication policy is matched from the preset authentication policy library to generate a targeted authentication process plan, including: Filtering a set of authentication methods from the authentication policy library according to the specific level of the abnormal risk; Sorting the authentication methods in the authentication method set based on the differences between the user behavior characteristics and the business scenarios, and determining the order of verification steps; The authentication method set is bound to the verification step sequence to generate the targeted authentication process solution.

[0055] In one implementation, this step specifically includes: The first step is to filter out a set of authentication methods from the authentication policy library according to the specific level of the abnormal risk.

[0056] It should be noted that the "Authentication Policy Library" is a pre-configured database that stores multiple authentication methods (such as static passwords, SMS dynamic passwords, email verification, biometrics (fingerprint / face), payment passwords, preset security questions, etc.) and policy templates of different security levels composed of these methods.

[0057] For example, for the "high-risk" level, the system will screen out combinations that include at least two strong authentication methods, such as "fingerprint recognition + SMS dynamic password + payment password"; for the "medium-risk" level, the system will screen out enhanced authentication combinations, such as "static password + SMS dynamic password"; for "low-risk" or no-risk users, the system will match the most convenient authentication method, such as "static password" or "seamless pass" on a trusted device.

[0058] For example, for users who are judged to be at a "high-risk" level, the system selects two alternative authentication method sets from the policy library: {fingerprint recognition, SMS dynamic password} and {face recognition, SMS dynamic password}.

[0059] In the second step, the authentication methods in the authentication method set are sorted based on the differences between the user behavior characteristics and the business scenarios, and the order of the verification steps is determined.

[0060] It should be noted that this step personalizes and contextualizes the authentication process, further enhancing the user experience. It analyzes user behavioral characteristics such as device capabilities, operating habits, and current business scenarios (e.g., small payments, large transfers).

[0061] Specifically, when analyzing user behavior, if the user's device supports biometrics and the user has a history of using it, biometric authentication will be prioritized. When considering business scenarios, if there are high-value scenarios such as large transfers, strong verification steps such as payment passwords will be added and performed earlier, even if the risk level is medium. For non-sensitive operations such as browsing and querying, the steps are simplified.

[0062] For example, in the above case, the system detects that the device currently used by the user supports facial recognition, and the user has historically had a high acceptance and fast response speed for facial recognition.

[0063] Therefore, in the set of {face recognition, SMS dynamic password}, ​​the system determines the order of verification steps as follows: the first step is face recognition, and the second step is SMS dynamic password verification.

[0064] The third step is to bind the authentication method set with the verification step sequence to generate the targeted authentication process solution.

[0065] It should be noted that this step solidifies the results of the first two steps into a complete, executable solution. It logically binds the selected authentication method and the determined verification sequence to form a structured process solution with specific steps, sequence, and required parameters.

[0066] In step S16, the targeted authentication process solution is sent to the device front end for execution, and the authentication execution result is determined, including: According to the targeted authentication process scheme, dynamically adjust the interactive interface prompt content and verification time limit to generate the front-end authentication configuration; Send the front-end authentication configuration to the authentication execution module at the front end of the device to obtain the user authentication link configuration that changes in real time; According to the configuration of the user authentication link, the authentication data returned by the authentication execution module is extracted to determine the authentication execution result.

[0067] It should be noted that when refreshing the prompt content of the cross-system interaction interface in real time according to the generated targeted authentication process plan, adjusting the verification time limit, and generating the front-end authentication configuration, an adapted prompt content template is obtained from the pre-established interaction interface data, and the content is screened according to the characteristics of cross-system interaction to obtain a prompt content set that meets the verification time requirements.

[0068] For example, in identity verification scenarios, the system needs to display prompt information within a short timeframe. The interactive interface data stores various prompt templates, such as brief prompts and detailed instructions. For scenarios where the verification timeframe is limited to 10 seconds, a shorter prompt template, such as "Please enter the verification code," is preferred over the lengthier "Please enter the 6-digit verification code you received below to complete verification." When dynamically adjusting the prompt content set based on the timeframe constraints, the verification time allocation is optimized. For example, if the total timeframe for a verification step is limited to 30 seconds, consisting of both prompt display and user input, the initial allocation is 5 seconds for prompt display and 25 seconds for user input. If users are found to be slow to respond on certain devices, the timeframe is dynamically adjusted to 8 seconds for prompt display and 22 seconds for user input. If the adjusted timeframe exceeds the preset threshold, such as a total timeframe of 35 seconds, the prompt display is rescheduled to 6 seconds to ensure the overall timeframe meets the requirement. It should be noted that when the front-end authentication configuration is sent to the authentication execution module at the front end of the device to obtain the real-time changed user authentication link configuration, the prompt content is bound to the time limit according to the verification time plan and transmitted to the execution module at the front end of the device to obtain the real-time changed authentication link configuration.

[0069] For example, if a user's device receives a prompt stating "Please enter your password" and a 10-second time limit, the execution module will adjust the display method based on the current network status. For example, if network latency is high, it will prioritize text prompts over animations to ensure the display is completed within the time limit. The system will then determine whether the configuration meets the requirements for the updated authentication method, such as whether a voice prompt needs to be temporarily added. It should be noted that when extracting the authentication data returned by the authentication execution module according to the configuration of the user authentication link and determining the authentication execution result, for the authentication link after the configuration change, the relevant data of the authentication execution is extracted from the execution module, and combined with the real-time refreshed interactive interface status, the final authentication result data is obtained.

[0070] For example, in a certain verification, the user completes the password input within 5 seconds, and records information such as the input time and number of errors. Combined with the interactive interface status, such as whether an error prompt is displayed, a comprehensive analysis is performed to obtain the authentication result data.

[0071] To facilitate understanding of the present invention, some preferred embodiments of the present invention are further described below.

[0072] In one implementation, the entire e-commerce cross-system authentication process is considered a closed-loop security verification system. This system is designed to monitor user behavior in real time and dynamically adjust authentication strategies to ensure e-commerce transaction security and user experience.

[0073] The working process is as follows: Step 1: The e-commerce platform subsystem starts the user interaction process, and the data collection module starts working, collecting scattered data such as user login time distribution, device switching frequency, and geographic location changes in real time, and transmits it to the server.

[0074] Step 2: The server receives the initial set of user behavior records and uses a distributed data processing framework to clean and format the data, process incomplete records, and generate a standardized behavior data set.

[0075] Step 3: The server extracts features such as user interaction response speed, common function preferences, and abnormal operation ratio based on the standardized behavior dataset to construct a user behavior feature vector group.

[0076] Step 4: The server uses the user behavior feature vector group and combines it with historical abnormal behavior archives to analyze potential inconsistencies in user operations, such as geographic location changes and device switching frequency, and calculates an initial abnormality risk score.

[0077] Step 5: If the initial abnormal risk score exceeds the preset threshold, the server triggers the deep comparison module to perform multi-dimensional cross-validation on the login time distribution and operation instruction sequence in the user behavior feature vector group to determine the specific level of abnormal risk.

[0078] Step 6: The server calls the preset authentication policy library data based on the specific level of abnormal risk, dynamically matches the authentication method combination and verification step sequence, and generates a targeted authentication process plan.

[0079] Step 7: The server refreshes the prompt content of the cross-system interactive interface in real time based on the generated targeted authentication process plan, adjusts the verification time limit, and sends it to the device front-end authentication execution module to change the verification method of the user authentication link in real time and obtain the authentication execution result.

[0080] Step 8: The server records the authentication status based on the authentication execution result. If the authentication fails, the server further restricts the user's operation or notifies the security management personnel. If the authentication succeeds, the user is allowed to switch seamlessly between systems.

[0081] Through the above steps, e-commerce platforms can promptly detect and respond to abnormal user behavior, ensuring transaction security and user experience.

[0082] In order to issue the authentication process plan and execute the authentication, the following two implementation methods are provided: In one embodiment, the server sends the targeted authentication process plan to the device front-end authentication execution module through a communication module configured on the server, and obtains the authentication execution result. Wherein, the communication module and the device front-end authentication execution module are pre-connected via a wired network.

[0083] In this implementation, a stable wired communication connection is pre-established between the server's communication module and the device's front-end authentication execution module. Once the server generates a targeted authentication process plan, the system immediately sends it to the device's front-end authentication execution module via the wired network, ensuring timely transmission of authentication configurations and reliable return of authentication results.

[0084] In another embodiment, the server sends the targeted authentication process solution to the device front-end authentication execution module through a communication module configured on the server, and obtains the authentication execution result. Wherein, the communication module and the device front-end authentication execution module have established a connection in advance through a wireless network.

[0085] In this implementation, a stable wireless communication connection is pre-established between the server's communication module and the device's front-end authentication execution module. Once the server generates a targeted authentication process plan, the system immediately transmits it to the device's front-end authentication execution module via the wireless network. This ensures flexible transmission of authentication configurations and real-time feedback of authentication execution results, adapting to the needs of mobile e-commerce scenarios.

[0086] In summary, the present invention discloses a cross-system seamless switching authentication method for e-commerce, including: obtaining user behavior data, processing it, and generating a user behavior data set; extracting user behavior features based on the user behavior data set, and constructing a user behavior feature vector group; matching user behavior patterns and assigning an initial abnormal risk score based on the user behavior feature vector group in combination with the system's historical abnormal behavior archives; if the initial abnormal risk score exceeds a preset first threshold, cross-validating the login time distribution and operation instruction sequence in the user behavior feature vector group to determine the specific level of abnormal risk; matching authentication policies from a preset authentication policy library based on the specific level of abnormal risk, and generating a targeted authentication process plan; sending the targeted authentication process plan to the device front end for execution, and determining the authentication execution result. The present invention solves the problems of low user experience and low security in the prior art caused by fixed authentication policies and the inability to dynamically perceive risks, through dynamic and accurate assessment of user operation risks and adaptive adjustment of authentication strength.

[0087] Reference Figure 2The second embodiment of the present invention provides a cross-system seamless switching authentication device for e-commerce, comprising: The data collection module is used to obtain user behavior data, process it, and generate a user behavior data set; A feature construction module, configured to extract user behavior features and construct a user behavior feature vector group based on the user behavior dataset; A risk assessment module is used to match user behavior patterns and assign an initial abnormal risk score based on the user behavior feature vector group and historical abnormal behavior archives; a risk level judgment module, configured to, if the initial abnormal risk score exceeds a preset first threshold, cross-validate the login time distribution and operation instruction sequence in the user behavior feature vector group to determine a specific abnormal risk level; An authentication decision module is used to match authentication policies from a preset authentication policy library according to the specific level of the abnormal risk and generate a targeted authentication process plan; The authentication execution module is used to send the targeted authentication process plan to the device front end for execution and determine the authentication execution result.

[0088] It should be noted that the cross-system seamless switching authentication device for e-commerce provided in an embodiment of the present invention is used to execute all the process steps of the cross-system seamless switching authentication method for e-commerce in the above embodiment. The working principles and beneficial effects of the two correspond one to one, so they will not be repeated here.

[0089] An embodiment of the present invention further provides an electronic device. The electronic device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a cross-system seamless switching authentication program for e-commerce. When the processor executes the computer program, the steps in each of the above-mentioned embodiments of the cross-system seamless switching authentication method for e-commerce are implemented, such as Figure 1 Alternatively, when the processor executes the computer program, the functions of the modules / units in the above-mentioned device embodiments are realized, such as the data acquisition module.

[0090] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to implement the present invention. The one or more modules / units may be a series of computer program instruction segments capable of implementing specific functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.

[0091] The electronic device may be a computing device such as a desktop computer, notebook, PDA, or smart tablet. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will appreciate that the aforementioned components are merely examples of electronic devices and do not constitute a limitation of the electronic device. The electronic device may include more or fewer components than those described above, or a combination of certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, and the like.

[0092] The processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. The processor is the control center of the electronic device and connects various parts of the entire electronic device using various interfaces and lines.

[0093] The memory can be used to store the computer programs and / or modules. The processor implements the various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and accessing the data stored in the memory. The memory may primarily include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function or an image playback function); the data storage area may store data generated based on the use of the mobile phone (such as audio data, a phone book, etc.). Furthermore, the memory may include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.

[0094] If the module / unit integrated into the electronic device is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention can implement all or part of the process steps in the above-mentioned method embodiments by using a computer program to instruct the relevant hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. It should be noted that the content of the computer-readable medium can be appropriately increased or decreased based on the requirements of legislation and patent practice in a jurisdiction. For example, in some jurisdictions, based on legislation and patent practice, computer-readable media does not include electric carrier signals and telecommunication signals.

[0095] It should be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art can understand and implement the present invention without inventive effort.

[0096] The specific embodiments described above further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.

Claims

1. A cross-system seamless switching authentication method for e-commerce, characterized in that: Executed by a computer, including: Obtain user behavior data, process it, and generate a user behavior data set; Extracting user behavior features based on the user behavior dataset and constructing a user behavior feature vector group; Based on the user behavior feature vector group and in combination with the system's historical abnormal behavior archive, the user behavior pattern is matched and an initial abnormal risk score is assigned; If the initial abnormal risk score exceeds a preset first threshold, cross-validating the login time distribution and operation instruction sequence in the user behavior feature vector group to determine a specific abnormal risk level; According to the specific level of abnormal risk, matching authentication strategies from the preset authentication strategy library to generate targeted authentication process solutions; The targeted authentication process plan is sent to the device front end for execution to determine the authentication execution result.

2. The cross-system seamless switching authentication method for e-commerce according to claim 1 is characterized in that: The obtaining of user behavior data and processing thereof to generate a user behavior data set includes: Collect user login time distribution data, device switching frequency data, and geographic location change data in real time, set a unique identifier for each type of data, and obtain the initial user behavior record set; Extracting the user identifier and the operation instruction record of the login time distribution data from the initial user behavior record set, and performing missing value completion and format standardization to generate a cleaned user behavior record set; Automatically mark abnormalities and perform corrections on data in the cleaned user behavior record set where the timestamp corresponding to the user identifier does not match the data source, thereby obtaining a verified user behavior record set; According to the verified user behavior record set, the device switching frequency data and the geographic location change data are standardized and fused to obtain the user behavior data set.

3. The cross-system seamless switching authentication method for e-commerce according to claim 1 is characterized in that: The step of extracting user behavior features and constructing a user behavior feature vector group based on the user behavior dataset includes: Extracting user interaction response speed, common function preferences, and abnormal operation ratio as user behavior features based on the user behavior dataset; Grouping and layering the extracted user behavior features to obtain quantitative feature indicators; The quantitative feature indicators are mapped into multiple dimensions to construct the user behavior feature vector group.

4. The cross-system seamless switching authentication method for e-commerce according to claim 1 is characterized in that: The method of matching user behavior patterns and assigning an initial abnormal risk score based on the user behavior feature vector group and the system's historical abnormal behavior archives includes: Analyzing the geographic location change data, device switching frequency data, and operation frequency fluctuation data in the user behavior feature vector group to obtain a current behavior pattern; According to the current behavior pattern, a mapping relationship between behavior patterns and risk scores preset in the historical abnormal behavior archive is matched to assign an initial abnormal risk score.

5. The cross-system seamless switching authentication method for e-commerce according to claim 1 is characterized in that: The cross-validation of the login time distribution and the operation instruction sequence in the user behavior feature vector group to determine the specific level of abnormal risk includes: For the login time distribution, by comparing it with the system's historical login time period pattern, obtaining an abnormality determination result of the login time distribution; Comparing the operation instruction sequence with the historical operation instruction sequence of the system to obtain a consistency determination result of the operation instruction sequence; The abnormality determination result and the consistency determination result are combined to perform cross-validation to determine the specific level of the abnormality risk.

6. The cross-system seamless switching authentication method for e-commerce according to claim 1 is characterized in that: According to the specific level of the abnormal risk, matching the authentication policy from the preset authentication policy library to generate a targeted authentication process solution includes: Filtering a set of authentication methods from the authentication policy library according to the specific level of the abnormal risk; Sorting the authentication methods in the authentication method set based on the differences between the user behavior characteristics and the business scenarios, and determining the order of verification steps; The authentication method set is bound to the verification step sequence to generate the targeted authentication process solution.

7. The cross-system seamless switching authentication method for e-commerce according to claim 1 is characterized in that: The step of sending the targeted authentication process solution to the device front end for execution and determining the authentication execution result includes: According to the targeted authentication process scheme, dynamically adjust the interactive interface prompt content and verification time limit to generate the front-end authentication configuration; Send the front-end authentication configuration to the authentication execution module at the front end of the device to obtain the user authentication link configuration that changes in real time; According to the configuration of the user authentication link, the authentication data returned by the authentication execution module is extracted to determine the authentication execution result.

8. A cross-system seamless switching authentication device for e-commerce, characterized in that: include: The data collection module is used to obtain user behavior data, process it, and generate a user behavior data set; A feature construction module, configured to extract user behavior features and construct a user behavior feature vector group based on the user behavior dataset; A risk assessment module is used to match user behavior patterns and assign an initial abnormal risk score based on the user behavior feature vector group and historical abnormal behavior archives; a risk level judgment module, configured to cross-validate the login time distribution and operation instruction sequence in the user behavior feature vector group to determine a specific abnormal risk level if the initial abnormal risk score exceeds a preset first threshold; An authentication decision module is used to match authentication policies from a preset authentication policy library according to the specific level of the abnormal risk and generate a targeted authentication process plan; The authentication execution module is used to send the targeted authentication process plan to the device front end for execution and determine the authentication execution result.

9. An electronic device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, it implements the cross-system seamless switching authentication method for e-commerce as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the cross-system seamless switching authentication method for e-commerce according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network security protection method and system

    CN118748611A

  • Account authentication method and system based on risk rule model

    CN118916860A

  • Security authentication method and device, equipment, storage medium and computer program product

    CN119484063A

  • Risk management system and method based on multi-source data perception

    CN119918066A

  • Security System Configured to Assign a Group Security Policy to a User Based on Security Risk Posed by the User

    US20200195693A1

Cited By

  • Information processing method and electronic equipment

    CN121030715A

  • Information processing method and electronic device

    CN121030715B

  • Shared data dynamic security management method, system, equipment and medium

    CN121037124A

  • Identity authentication method and device based on fingerprint identification and identity identification, and medium

    CN121167701A

  • An identity authentication method and device based on fingerprint recognition and identity identification, and a medium

    CN121167701B