Multi-factor dynamic authentication method and device, electronic equipment and storage medium

By collecting multi-dimensional data in real time and evaluating with artificial intelligence models, the multi-factor authentication strategy is dynamically adjusted, which solves the problem of insufficient or excessive authentication strength in existing technologies, achieves balanced authentication under different risk scenarios, and improves user experience and security.

CN120934856APending Publication Date: 2025-11-11BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511170040.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing multi-factor authentication technologies are insufficient in high-risk scenarios, while adding unnecessary authentication steps in low-risk scenarios, thus affecting user experience.

Method used

By collecting user behavior data, device fingerprint data, and real-time threat intelligence in real time, a pre-trained artificial intelligence model is used to evaluate the comprehensive risk score, and the multi-factor authentication strategy is dynamically adjusted based on the score to select the appropriate authentication strength.

Benefits of technology

It enables dynamic adjustment of authentication strength under different risk scenarios, balancing user experience and security, and improving the accuracy and efficiency of the authentication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934856A_ABST
    Figure CN120934856A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-factor dynamic authentication method and device, electronic equipment and a storage medium, and the method can collect user behavior data, equipment fingerprint data, real-time threat intelligence and other multi-dimensional data in real time based on a received authentication request, carries out the evaluation of the multi-dimensional data based on a pre-trained artificial intelligence model, and improves the user experience. The method comprises the steps of obtaining a comprehensive risk score of an authentication request, determining a target multi-factor authentication strategy from a preset multi-factor authentication strategy library according to the comprehensive risk score, authenticating a user according to the target multi-factor authentication strategy, and determining authorized access or denied access to the user according to an authentication result. Due to the fact that the corresponding target multi-factor authentication strategy can be selected in combination with the multi-dimensional data collected in real time, the multi-factor authentication strength can be dynamically adjusted to complete multi-factor authentication, and user experience and safety are balanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a multi-factor dynamic authentication method, apparatus, electronic device, and storage medium. Background Technology

[0002] Multi-Factor Authentication (MFA) technology is now widely used in various online services and systems, significantly improving account security. MFA typically combines multiple authentication factors such as "what you know" (e.g., password), "what you possess" (e.g., mobile phone, hardware token), and "who you are" (e.g., fingerprint, facial recognition). However, most MFA systems employ a pre-defined static policy, requiring the same MFA strength regardless of user behavior, device status, or real-time threats. This results in insufficient authentication strength in high-risk scenarios and unnecessary authentication steps in low-risk scenarios, negatively impacting user experience. Summary of the Invention

[0003] This application provides a multi-factor dynamic authentication method, apparatus, electronic device, and storage medium to solve the technical problem of how to dynamically adjust the multi-factor authentication strength for multi-factor authentication.

[0004] Firstly, this application provides a multi-factor dynamic authentication method, the method comprising:

[0005] Based on the received authentication request, multi-dimensional data is collected in real time; wherein, the multi-dimensional data includes at least user behavior data, device fingerprint data and real-time threat intelligence;

[0006] The multi-dimensional data is evaluated based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request.

[0007] The target multi-factor authentication strategy is determined from the preset multi-factor authentication strategy library based on the comprehensive risk score.

[0008] Obtain the authentication result of the user's authentication of the target multi-factor authentication strategy;

[0009] Based on the authentication result, it is determined whether to authorize or deny access to the user.

[0010] Optionally, after determining whether to authorize or deny access to the user based on the authentication result, the method further includes:

[0011] Feedback data is determined based on the authentication results, the target multi-factor authentication strategy, and the multi-dimensional data.

[0012] The artificial intelligence model is optimized and trained based on the feedback data.

[0013] Optionally, the artificial intelligence model includes a user behavior analysis model, a device fingerprint analysis model, and a threat situation analysis model; based on the pre-trained artificial intelligence model, the multi-dimensional data is evaluated to obtain a comprehensive risk score for the authentication request, including:

[0014] The user behavior data is input into the pre-trained user behavior analysis model to obtain a behavior risk score;

[0015] The device fingerprint data is input into the pre-trained device fingerprint analysis model to obtain a device risk score;

[0016] The real-time threat intelligence is input into the pre-trained threat situation analysis model to obtain a threat risk score;

[0017] The comprehensive risk score of the authentication request is determined based on the behavioral risk score, the device risk score, and the threat risk score.

[0018] Optionally, determining the comprehensive risk score of the authentication request based on the behavioral risk score, the device risk score, and the threat risk score includes:

[0019] Obtain a preset weighting coefficient; determine the comprehensive risk score of the authentication request based on the weighting coefficient, the behavior risk score, the device risk score, and the threat risk score;

[0020] or,

[0021] Obtain a preset fusion model; perform data fusion on the behavior risk score, the device risk score and the threat risk score according to the fusion model to obtain the comprehensive risk score of the authentication request.

[0022] Optionally, a target multi-factor authentication strategy is determined from a preset multi-factor authentication strategy library based on the comprehensive risk score, including:

[0023] Obtain a preset multi-factor authentication strategy library; wherein, the multi-factor authentication strategy library includes a variety of multi-factor authentication strategies, which are used to characterize the authentication strength and authentication type of multi-factor authentication; each of the multi-factor authentication strategies corresponds to a risk score range;

[0024] Determine the target risk score range to which the comprehensive risk score belongs;

[0025] The target multi-factor authentication strategy is determined from the multi-factor authentication strategy library based on the target risk score range.

[0026] Optionally, obtaining the authentication result of the user's authentication of the target multi-factor authentication strategy includes:

[0027] Based on the aforementioned multi-factor authentication strategy, issue a multi-factor authentication challenge to the user;

[0028] Obtain the authentication data input by the user based on the multi-factor authentication challenge;

[0029] The certification result is determined based on the certification data and the reference data of the multi-factor certification challenge.

[0030] Optionally, based on the received authentication request, multi-dimensional data is collected in real time, including:

[0031] Obtain user login or login access requests for accessing protected resources;

[0032] Generate the user's authentication request based on the login access request;

[0033] Based on the authentication request, user behavior data, device fingerprint data, and real-time threat intelligence are collected in real time; wherein, the user behavior data includes at least one of the user's historical login habits, resource access patterns, and personal characteristic data; the device fingerprint data is used to characterize the unique identifier of the login device; and the real-time threat intelligence includes external threat information and internal security events.

[0034] The multi-dimensional data is determined based on the user behavior data, the device fingerprint data, and the real-time threat intelligence.

[0035] Secondly, this application provides a multi-factor dynamic authentication device, the device comprising:

[0036] The data acquisition module is used to collect multi-dimensional data in real time based on the received authentication requests; wherein the multi-dimensional data includes at least user behavior data, device fingerprint data and real-time threat intelligence.

[0037] An evaluation module is used to evaluate the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request.

[0038] The first determining module is used to determine a target multi-factor authentication strategy from a preset multi-factor authentication strategy library based on the comprehensive risk score;

[0039] The authentication result acquisition module is used to acquire the authentication result of the user's authentication of the target multi-factor authentication strategy;

[0040] The second determining module is used to determine whether to authorize or deny access to the user based on the authentication result.

[0041] Thirdly, this application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0042] Memory, used to store computer programs;

[0043] When a processor executes a program stored in memory, it implements the multi-factor dynamic authentication method described in any embodiment of the first aspect.

[0044] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the multi-factor dynamic authentication method as described in any embodiment of the first aspect.

[0045] Compared with the prior art, the technical solution provided in this application has the following advantages: The method provided in this application collects multi-dimensional data in real time based on the received authentication request; wherein, the multi-dimensional data includes at least user behavior data, device fingerprint data, and real-time threat intelligence; the multi-dimensional data is evaluated based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request; a target multi-factor authentication strategy is determined from a preset multi-factor authentication strategy library based on the comprehensive risk score; the authentication result of the user authenticating the target multi-factor authentication strategy is obtained; and access is authorized or denied to the user based on the authentication result. This method can collect multi-dimensional data such as user behavior data, device fingerprint data, and real-time threat intelligence in real time based on the received authentication request, and evaluate the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request. Therefore, a target multi-factor authentication strategy can be determined from a preset multi-factor authentication strategy library based on the comprehensive risk score, and the user can be authenticated based on the target multi-factor authentication strategy. Access is then authorized or denied to the user based on the authentication result. Since the corresponding target multi-factor authentication strategy can be selected by combining the real-time collected multi-dimensional data, the multi-factor authentication strength can be dynamically adjusted to complete the multi-factor authentication, balancing user experience and security. Attached Figure Description

[0046] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0047] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0049] Figure 1 A system architecture diagram of a multi-factor dynamic authentication method provided in one embodiment of this application;

[0050] Figure 2 A flowchart illustrating a multi-factor dynamic authentication method provided in one embodiment of this application;

[0051] Figure 3 A flowchart illustrating a multi-factor dynamic authentication method provided in one embodiment of this application;

[0052] Figure 4 This is a schematic diagram of the structure of a multi-factor dynamic authentication device provided in one embodiment of this application;

[0053] Figure 5 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0055] The following disclosure provides numerous different embodiments or examples for implementing various structures of this application. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of this application. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.

[0056] To address the technical problem of how to dynamically adjust the strength of multi-factor authentication in existing technologies, this application provides a multi-factor dynamic authentication method, device, electronic device, and storage medium. It can select the corresponding target multi-factor authentication strategy by combining real-time collected multi-dimensional data, and can dynamically adjust the strength of multi-factor authentication to complete multi-factor authentication, thus balancing user experience and security.

[0057] The first embodiment of this application provides a multi-factor dynamic authentication method, which can be applied to, for example... Figure 1 The system architecture shown includes at least a data acquisition module 101 and a dynamic authentication module 102, which establish a communication connection. Specifically, the system architecture can be a multi-factor dynamic authentication system (hereinafter referred to as the system). The multi-factor dynamic authentication system can include a data acquisition layer, an AI (artificial intelligence) intelligent decision-making layer, an authentication execution layer, and a strategy management and optimization layer. The data acquisition layer can be deployed in the data acquisition module 101, and the AI ​​intelligent decision-making layer, authentication execution layer, and strategy management and optimization layer can be deployed in the dynamic authentication module 102.

[0058] The data acquisition layer is responsible for collecting and preprocessing raw data, including a user behavior data acquisition module, a device fingerprint acquisition module, a threat intelligence integration module, and a data preprocessing and feature engineering module. All collected data can be aggregated into the data preprocessing and feature engineering module for cleaning, standardization, and feature extraction, preparing it for AI analysis.

[0059] The AI-powered intelligent decision-making layer acts as the "brain" of the multi-factor dynamic authentication system, comprising a user behavior analysis model, a device fingerprint analysis model, a threat situation analysis model, and a dynamic risk assessment engine. Preprocessed data flows to these models, which perform in-depth analysis of the data within their respective domains and input the results (such as behavioral anomaly, device trustworthiness, and threat level) into the dynamic risk assessment engine. The engine then integrates all inputs to calculate a real-time, continuous, comprehensive risk score.

[0060] Authentication Execution Layer: Based on the comprehensive risk score output by the dynamic risk assessment engine, it includes a dynamic MFA policy generation module and a multi-factor authentication module. The dynamic MFA policy generation module will match and generate the most suitable MFA policy, and the multi-factor authentication module is responsible for actually executing the selected MFA challenge. The authentication result determines whether the user is granted access authorization, or whether the authentication is denied and an alarm is issued.

[0061] The strategy management and optimization layer includes an authentication policy database and a model continuous learning and optimization module. The authentication policy database stores MFA combinations corresponding to different risk levels. The model continuous learning and optimization module receives authentication results (success or failure) and security event feedback, continuously training and optimizing AI models (user behavior analysis model, device fingerprint analysis model, threat situation analysis model, and dynamic risk assessment engine) to improve the system's accuracy and adaptability. Users / applications initiate authentication requests, and ultimately, access is granted or denied based on the authentication result.

[0062] Next, based on this system architecture, the multi-factor dynamic authentication method will be described in detail, such as... Figure 2 This multi-factor dynamic authentication method includes:

[0063] Step 201: Based on the received authentication request, collect multi-dimensional data in real time; the multi-dimensional data includes at least user behavior data, device fingerprint data, and real-time threat intelligence.

[0064] Authentication requests can be triggered when a user logs in or accesses protected resources. After receiving an authentication request, the system collects multi-dimensional data in real time.

[0065] In one embodiment, based on the received authentication request, multi-dimensional data is collected in real time, including: obtaining a user login or access request for accessing protected resources; generating a user authentication request based on the login access request; collecting user behavior data, device fingerprint data, and real-time threat intelligence in real time according to the authentication request; wherein, user behavior data includes at least one of the user's historical login habits, resource access patterns, and personal characteristic data; device fingerprint data is used to characterize the unique identifier of the login device; real-time threat intelligence includes external threat information and internal security events; and multi-dimensional data is determined based on user behavior data, device fingerprint data, and real-time threat intelligence.

[0066] In this embodiment, when a user logs in or accesses protected resources, a user authentication request is generated based on the login request. Then, user behavior data, device fingerprint data, and real-time threat intelligence are collected in real time based on the authentication request. User behavior data includes the user's historical login habits, resource access patterns, and personal characteristic data. For example, historical login habits may include login time, login location, login frequency, and login Internet Protocol (IP) address; resource access patterns may include accessed applications, data types, and operation permissions; and personal characteristic data may include operation sequences, typing speed, and mouse movements. Machine learning algorithms such as Recurrent Neural Networks (RNNs), Long Short-Term Memory Networks (LSTMs), or time series analysis models can be used to establish a personalized behavioral baseline for each user to analyze the user behavior data. Device fingerprint data can uniquely identify a logged-in device. This includes collecting hardware characteristics (CPU serial number, hard drive ID), operating system and version, browser fingerprints (User-Agent, Canvas fingerprint, WebGL fingerprint, font list, plugin information), network configuration information (MAC address, routing path, port open status), software installation list, and device health status (whether jailbroken / rooted, presence of known vulnerabilities). Then, using hash algorithms and deduplication techniques, highly robust device fingerprint data is constructed, such as through unsupervised learning or deep learning, and can be used to assess the health status of the logged-in device. Real-time threat intelligence includes external threat information and internal security events. External threat information may include malicious IP blacklists, Command and Control (C2) server lists, phishing website databases, known vulnerability databases, high-risk geographical locations, large-scale credential leaks, and industry-specific attack alerts. Internal security events may include SIEM (Security Information and Event Management) system logs, IDS (Intrusion Detection System) / IPS (Intrusion Prevention System) alerts, sandbox analysis results, and abnormal traffic detection. The user behavior data, device fingerprint data, and real-time threat intelligence mentioned above are used as multi-dimensional data collected in real time.

[0067] In this embodiment, user behavior data such as historical login habits, resource access patterns, and personal characteristics can establish a unique and personalized historical behavior baseline for each user. The system continuously learns the user's login habits, operation sequences, and resource access preferences, and compares the current behavior with the user's personalized baseline during each authentication. This significantly improves the ability to identify account theft, session hijacking, and internal threats. By learning "what a user should be like," the system can accurately capture even the smallest and most subtle abnormal behaviors, which is more insightful than simple remote login detection and provides a more solid foundation for preventing complex attacks.

[0068] In this embodiment, in addition to collecting IP addresses and User-Agents, deeper data collection and analysis are performed on the device's underlying hardware characteristics, advanced browser fingerprints (Canvas, WebGL, etc.), network environment characteristics, and even historical usage behavior. Through AI algorithms, more unique and difficult-to-forge device fingerprint data is constructed, and the device's health can be assessed (e.g., whether it has been rooted / jailbroken, whether there are known vulnerabilities or abnormal processes). This significantly improves the accuracy and anti-forgery capabilities of device identification. This allows the system to effectively identify and block access from unknown, untrusted, or infected devices. Even if attackers forge some surface information, it is difficult to bypass the deep device fingerprint detection.

[0069] In this embodiment, the system not only relies on internal data but also deeply integrates and utilizes external threat intelligence (such as malicious IP blacklists, C2 servers, vulnerability exploitation information, and phishing website databases) and internal security events (such as SIEM alerts and IDS / IPS logs) in real time. Through AI models (such as Natural Language Processing (NLP) and Graph Neural Networks (GNNs), this massive amount of intelligence is analyzed for correlation and semantic understanding, dynamically assessing the current macro-level threat level and the related threats to specific users / resources. This endows the system with proactive risk perception and defense capabilities. When the external threat environment deteriorates, or when a certain IP / resource is associated with a known attack event, the system can immediately increase authentication strength, thereby effectively intercepting attacks before or in their early stages, transforming passive defense into proactive offense.

[0070] Step 202: Evaluate the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request.

[0071] Artificial intelligence models can include user behavior analysis models, device fingerprint analysis models, and threat situation analysis models, among others.

[0072] In one embodiment, a comprehensive risk score for an authentication request is obtained by evaluating multi-dimensional data based on a pre-trained artificial intelligence model, including: inputting user behavior data into a pre-trained user behavior analysis model to obtain a behavior risk score; inputting device fingerprint data into a pre-trained device fingerprint analysis model to obtain a device risk score; inputting real-time threat intelligence into a pre-trained threat situation analysis model to obtain a threat risk score; and determining a comprehensive risk score for the authentication request based on the behavior risk score, device risk score, and threat risk score.

[0073] In this embodiment, user behavior data can be analyzed using a user behavior analysis model to assess the abnormality of the current behavior and obtain a behavior risk score. Device fingerprint data can be analyzed using a device fingerprint analysis model to identify the trustworthiness and health status of the device and obtain a device risk score. Real-time threat intelligence can be analyzed using a threat situation analysis model to assess the threat level of the current environment and obtain a threat risk score. Finally, a comprehensive risk score for the authentication request is determined based on the behavior risk score, device risk score, and threat risk score.

[0074] In this embodiment, massive amounts of dynamic data from three dimensions—user behavior data, device fingerprint data, and real-time threat intelligence—can be analyzed in real time and in depth. These data are then integrated to generate a refined and continuous comprehensive risk score, which greatly improves the accuracy and precision of risk assessment. The system no longer simply judges "whether it is abnormal," but can assess "how high the degree of abnormality" and "how great the risk," thereby avoiding false alarms and false negatives in traditional systems. This allows for more precise adjustment of MFA strategies, effectively intercepting high-risk threats while avoiding unnecessary interference to normal users.

[0075] In one embodiment, determining the comprehensive risk score of an authentication request based on behavioral risk score, device risk score, and threat risk score can include at least the following two methods:

[0076] The first method involves obtaining preset weighting coefficients and determining the overall risk score of the authentication request based on the weighting coefficients, behavioral risk score, device risk score, and threat risk score.

[0077] The preset weighting coefficients can be the first coefficient of the behavioral risk score, the second coefficient of the equipment risk score, and the third coefficient of the threat risk score. The sum of the first, second, and third coefficients is one. The comprehensive risk score is obtained by weighting and summing the behavioral risk score, equipment risk score, and threat risk score with the first, second, and third coefficients.

[0078] The second method is to obtain a preset fusion model; and then perform data fusion on the behavioral risk score, device risk score, and threat risk score based on the fusion model to obtain a comprehensive risk score for the authentication request.

[0079] In this embodiment, the preset fusion model can be a fusion model built based on Bayesian networks or reinforcement learning. Bayesian networks can infer dependencies through probabilistic reasoning and are suitable for scenarios with fixed risk factors and clear probability distributions. Reinforcement learning can dynamically learn the optimal strategy and is suitable for dynamic and complex scenarios.

[0080] Step 203: Determine the target multi-factor authentication strategy from the preset multi-factor authentication strategy library based on the comprehensive risk score.

[0081] In one embodiment, determining a target multi-factor authentication strategy from a preset multi-factor authentication strategy library based on a comprehensive risk score includes: acquiring a preset multi-factor authentication strategy library; wherein the multi-factor authentication strategy library includes a variety of multi-factor authentication strategies, which are used to characterize the authentication strength and authentication type of multi-factor authentication; each multi-factor authentication strategy corresponds to a risk score interval; determining the target risk score interval to which the comprehensive risk score belongs; and determining the target multi-factor authentication strategy from the multi-factor authentication strategy library based on the target risk score interval.

[0082] In this embodiment, the multi-factor authentication strategy library may include a variety of multi-factor authentication strategies. Each multi-factor authentication strategy may be an MFA or a combination of multiple MFAs, without limitation. The MFAs shall at least include the following:

[0083] MFA based on OTP (One-Time Password): includes SMS verification codes (SMS OTP), email verification codes, and dynamic passwords based on time (TOTP) or event (HOTP) (generated via the Authenticator App).

[0084] Biometric authentication (MFA) uses biometric features such as fingerprint recognition, facial recognition, iris recognition, or voiceprint recognition for identity verification.

[0085] Hardware Security Key (MFA): Such as a FIDO U2F / WebAuthn compatible USB key, providing strong authentication against phishing attacks.

[0086] Push notification MFA: Users receive and confirm login requests via the application on their registered device.

[0087] Location-based Validation (MFA): Uses the user's current location information for auxiliary verification.

[0088] In this embodiment, each multi-factor authentication strategy can correspond to a risk score range. For example, the total risk score range can be 0-100, and each multi-factor authentication strategy can correspond to one of these ranges. It should be understood that the risk score ranges do not overlap to avoid situations where the same risk score selects different multi-factor authentication strategies. Based on the target risk score range to which the comprehensive risk score belongs, the target multi-factor authentication strategy can be determined from the multi-factor authentication strategy library. Alternatively, the processing can be simplified by setting a high-risk threshold. If the comprehensive risk score is higher than or equal to the high-risk threshold, a high-strength MFA combination (e.g., biometric identification + FIDO2 security key) is selected; if the comprehensive risk score is lower than the high-risk threshold, a low-strength MFA (e.g., password + push notification, or password only) is selected.

[0089] Step 204: Obtain the authentication result of the user's authentication of the target multi-factor authentication strategy.

[0090] It can issue multi-factor authentication challenges to users based on the target multi-factor authentication strategy, and determine the authentication result based on the user's challenge results.

[0091] In one embodiment, obtaining the authentication result of a user authenticating against a target multi-factor authentication strategy includes: issuing a multi-factor authentication challenge to the user based on the target multi-factor authentication strategy; obtaining authentication data input by the user based on the multi-factor authentication challenge; and determining the authentication result based on the authentication data and reference data of the multi-factor authentication challenge.

[0092] In this embodiment, a multi-factor authentication challenge is issued to the user based on the target multi-factor authentication strategy; the authentication data input by the user based on the multi-factor authentication challenge is obtained; the authentication result is determined according to the authentication data and the reference data of the multi-factor authentication challenge. For example, if the MFA is successful, access is authorized; if the MFA fails, authentication is rejected and a warning is triggered.

[0093] Step 205: Determine whether to authorize or deny access to the user based on the authentication result.

[0094] This method can collect multi-dimensional data such as user behavior data, device fingerprint data, and real-time threat intelligence in real time based on received authentication requests. It then evaluates the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request. Based on the comprehensive risk score, it can determine the target multi-factor authentication strategy from a pre-set multi-factor authentication strategy library, authenticate the user according to the target multi-factor authentication strategy, and determine whether to authorize or deny the user access based on the authentication result. Since it can select the corresponding target multi-factor authentication strategy by combining real-time collected multi-dimensional data, it can dynamically adjust the multi-factor authentication strength to complete the multi-factor authentication, thus balancing user experience and security.

[0095] In one embodiment, after determining whether to authorize or deny access to a user based on the authentication result, the method further includes: determining feedback data based on the authentication result, the target multi-factor authentication strategy, and multi-dimensional data; and optimizing and training the artificial intelligence model based on the feedback data.

[0096] In this embodiment, regardless of whether authentication is successful or not, the system's authentication results, raw data, comprehensive risk score, MFA strategy, user response, etc., will be recorded and used as feedback data. The system can continuously train and optimize the artificial intelligence model based on the feedback data, enabling the system to adapt to new threats and user behavior patterns, improve the accuracy of decision-making, and reduce false positives and false negatives.

[0097] In one specific embodiment, the multi-factor dynamic authentication method is as follows: Figure 3 ,include:

[0098] Step 301: The user / application initiates an authentication request. The user attempts to log in or access protected resources.

[0099] Step 302, Data Acquisition. The system immediately initiates multi-dimensional data acquisition, including current user behavior data (such as IP address, geographic location, access time, and requested resources), device fingerprint data (such as browser characteristics and operating system information), and the latest real-time threat intelligence. The collected data is input in parallel into three independent AI models for analysis. For example, the collected user behavior data is input into the user behavior analysis model, the collected device fingerprint data is input into the device fingerprint analysis model, and the collected real-time threat intelligence is input into the threat situation analysis model.

[0100] Step 303, User Behavior Analysis Model. Based on the user's historical behavior patterns, assess the abnormality of the current behavior and output a behavior risk score.

[0101] Step 304, Device Fingerprint Analysis Model. Identify the trustworthiness and health status of the device, and output a device risk score.

[0102] Step 305, Threat Situation Analysis Model. Based on real-time threat intelligence, assess the threat level of the current external environment and output a threat risk score.

[0103] Step 306, Dynamic Risk Assessment Engine. This engine receives risk scores from three models: a user behavior analysis model, a device fingerprint analysis model, and a threat situation analysis model. It then calculates a comprehensive risk score using a pre-defined weighted algorithm or a more complex AI fusion model (such as Bayesian networks or reinforcement learning). This score is a continuous value representing the overall risk level of the current authentication request.

[0104] Step 307: Dynamic MFA Strategy Generation. Based on the comprehensive risk score, the system queries the built-in MFA strategy library to determine the required MFA strength and type. For example, it can use a risk threshold to compare the comprehensive risk score with a preset risk threshold. If the risk score is higher than or equal to the high-risk threshold, proceed to step 308; otherwise, proceed to step 309.

[0105] Step 308: Select and execute a high-strength MFA (e.g., biometric + FIDO2 security key). Then, proceed to step 310 after execution is complete.

[0106] Step 309: Select and execute a low-strength MFA or no MFA (e.g., password + push notification, or password only). Then execute step 311 after execution is complete.

[0107] Step 310: Wait for the user to complete the MFA challenge. The system sends the selected MFA challenge to the user and waits for the user to complete the verification. If the MFA is successful, proceed to step 312; if the MFA fails, proceed to step 313.

[0108] Step 311: Wait for the user to complete the MFA challenge. If the MFA is successful, proceed to step 312; if the MFA fails, proceed to step 313.

[0109] Step 312, Access Authorization.

[0110] Step 313: Authentication denied and an alarm triggered.

[0111] Step 314: Record the authentication results and provide feedback to the AI ​​model: Regardless of whether the authentication is successful or not, the system's authentication results (including raw data, risk score, MFA strategy, user response, etc.) will be recorded and used as feedback data.

[0112] Step 315: Continuous AI Model Optimization. Feedback data is used to continuously train and optimize various AI models, including the user behavior analysis model, device fingerprint analysis model, threat situation analysis model, and dynamic risk assessment engine. This enables the system to adapt to new threats and user behavior patterns, improve decision-making accuracy, and reduce false positives and false negatives.

[0113] In this embodiment, the MFA selection is not only based on risk scores, but also incorporates reinforcement learning or other online learning mechanisms. The system treats MFA decision-making as a dynamic process, receiving rewards or penalties based on the actual results of each authentication (success / failure, false positives, and subsequent security incidents), continuously iterating and optimizing its risk assessment model and MFA policy mapping. This achieves the self-evolution and adaptive capabilities of the authentication system, enabling it to continuously learn and improve from actual operation, increasing the accuracy of risk judgment and finding the optimal balance between security and user experience. Furthermore, false positives will decrease, the user flow will become smoother, and security protection capabilities will continuously strengthen over time.

[0114] Through this embodiment and the above embodiments, at least the following technical effects are achieved:

[0115] 1. Enhance product safety and reputation

[0116] Integrating systems using this multi-factor dynamic authentication method into all products and services requiring user authentication, whether enterprise applications, consumer platforms, SaaS solutions, or IoT device management platforms, can replace or enhance existing static MFA mechanisms. Faced with increasingly complex and covert cyberattacks (such as phishing, credential stuffing, and session hijacking), this system provides more advanced and intelligent defense capabilities. Through AI-powered real-time risk awareness and adaptive MFA, even against zero-day vulnerabilities or advanced persistent threats (APTs), the system can quickly adjust authentication strength, significantly reducing the risk of account theft and data breaches.

[0117] 2. Optimize user experience and improve user satisfaction

[0118] The authentication process is dynamically adjusted based on the user's risk level, strengthening verification in high-risk situations and simplifying or skipping unnecessary steps in low-risk situations. Most of the time, legitimate users will enjoy a smoother, less cumbersome login and access experience. The system can identify users in secure contexts, reduce unnecessary MFA prompts, significantly improve user satisfaction and productivity, and reduce user churn caused by cumbersome MFA processes.

[0119] 3. Reduce operating costs and compliance risks

[0120] Automated risk assessment and MFA (Mission Assistance) policy adjustments can reduce reliance on manual security reviews and interventions. Automated and intelligent certification processes can reduce the manpower costs of security teams and decrease the number of false alarms and user support requests related to MFA issues. Through continuous learning and optimization, the system can reduce invalid security alerts, allowing security teams to focus more on genuine threats. Furthermore, it can meet stringent compliance requirements.

[0121] 4. Enhance product competitiveness and market differentiation

[0122] Provide dynamic, advanced protection solutions to enhance product competitiveness.

[0123] Based on the same technical concept, the second embodiment of this application provides a multi-factor dynamic authentication device, such as... Figure 4 The device includes:

[0124] The data acquisition module 401 is used to collect multi-dimensional data in real time based on the received authentication request; wherein the multi-dimensional data includes at least user behavior data, device fingerprint data and real-time threat intelligence.

[0125] Evaluation module 402 is used to evaluate the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request;

[0126] The first determining module 403 is used to determine a target multi-factor authentication strategy from a preset multi-factor authentication strategy library based on the comprehensive risk score.

[0127] The authentication result acquisition module 404 is used to acquire the authentication result of the user's authentication of the target multi-factor authentication strategy;

[0128] The second determining module 405 is used to determine whether to authorize or deny access to the user based on the authentication result.

[0129] This device can collect multi-dimensional data such as user behavior data, device fingerprint data, and real-time threat intelligence in real time based on received authentication requests. It evaluates the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request. Based on the comprehensive risk score, it can determine the target multi-factor authentication strategy from a preset multi-factor authentication strategy library, and then authenticate the user according to the target multi-factor authentication strategy. Based on the authentication result, it determines whether to authorize or deny the user access. Because it can select the corresponding target multi-factor authentication strategy by combining real-time collected multi-dimensional data, it can dynamically adjust the multi-factor authentication strength to complete multi-factor authentication, thus balancing user experience and security.

[0130] like Figure 5 As shown in the figure, this application provides an electronic device, including a processor 111, a communication interface 112, a memory 113, and a communication bus 114, wherein the processor 111, the communication interface 112, and the memory 113 communicate with each other through the communication bus 114.

[0131] Memory 113 is used to store computer programs;

[0132] In one embodiment of this application, the processor 111, when executing the program stored in the memory 113, implements the multi-factor dynamic authentication method provided in any of the foregoing method embodiments.

[0133] The communication bus mentioned above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0134] The communication interface is used for communication between the aforementioned terminal and other devices.

[0135] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0136] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0137] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the multi-factor dynamic authentication method as provided in any of the foregoing method embodiments.

[0138] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0139] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented using software plus a general-purpose hardware platform, or of course, using hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0140] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also include the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that additional or alternative steps may be used.

[0141] It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. In the description, suffixes such as "module," "part," or "unit" used to denote elements are used solely for illustrative purposes and have no specific meaning in themselves. Therefore, "module," "part," or "unit" may be used interchangeably.

[0142] The above description is merely a specific embodiment of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A multi-factor dynamic authentication method, characterized in that, The method includes: Based on the received authentication request, multi-dimensional data is collected in real time; wherein, the multi-dimensional data includes at least user behavior data, device fingerprint data, and real-time threat intelligence; The multi-dimensional data is evaluated based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request. The target multi-factor authentication strategy is determined from the preset multi-factor authentication strategy library based on the comprehensive risk score. Obtain the authentication result of the user's authentication of the target multi-factor authentication strategy; Based on the authentication result, it is determined whether to authorize or deny access to the user.

2. The method according to claim 1, characterized in that, After determining whether to authorize or deny access to the user based on the authentication result, the method further includes: Feedback data is determined based on the authentication results, the target multi-factor authentication strategy, and the multi-dimensional data. The artificial intelligence model is optimized and trained based on the feedback data.

3. The method according to claim 1, characterized in that, The artificial intelligence model includes a user behavior analysis model, a device fingerprint analysis model, and a threat situation analysis model; The multi-dimensional data is evaluated based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request, including: The user behavior data is input into the pre-trained user behavior analysis model to obtain a behavior risk score; The device fingerprint data is input into the pre-trained device fingerprint analysis model to obtain a device risk score; The real-time threat intelligence is input into the pre-trained threat situation analysis model to obtain a threat risk score; The comprehensive risk score of the authentication request is determined based on the behavioral risk score, the device risk score, and the threat risk score.

4. The method according to claim 3, characterized in that, The comprehensive risk score for the authentication request is determined based on the behavioral risk score, the device risk score, and the threat risk score, including: Obtain a preset weighting coefficient; determine the comprehensive risk score of the authentication request based on the weighting coefficient, the behavior risk score, the device risk score, and the threat risk score; or, Obtain a preset fusion model; perform data fusion on the behavior risk score, the device risk score and the threat risk score according to the fusion model to obtain the comprehensive risk score of the authentication request.

5. The method according to claim 1, characterized in that, Based on the comprehensive risk score, a target multi-factor authentication strategy is determined from a pre-set multi-factor authentication strategy library, including: Obtain a preset multi-factor authentication strategy library; wherein, the multi-factor authentication strategy library includes a variety of multi-factor authentication strategies, which are used to characterize the authentication strength and authentication type of multi-factor authentication; each of the multi-factor authentication strategies corresponds to a risk score range; Determine the target risk score range to which the comprehensive risk score belongs; The target multi-factor authentication strategy is determined from the multi-factor authentication strategy library based on the target risk score range.

6. The method according to claim 1, characterized in that, Obtain the authentication result of the user's authentication of the target multi-factor authentication strategy, including: Based on the aforementioned multi-factor authentication strategy, issue a multi-factor authentication challenge to the user; Obtain the authentication data input by the user based on the multi-factor authentication challenge; The certification result is determined based on the certification data and the reference data of the multi-factor certification challenge.

7. The method according to claim 1, characterized in that, Based on the received authentication request, multi-dimensional data is collected in real time, including: Obtain user login or login access requests for accessing protected resources; Generate the user's authentication request based on the login access request; Based on the authentication request, user behavior data, device fingerprint data, and real-time threat intelligence are collected in real time; wherein, the user behavior data includes at least one of the user's historical login habits, resource access patterns, and personal characteristic data; the device fingerprint data is used to characterize the unique identifier of the login device; and the real-time threat intelligence includes external threat information and internal security events. The multi-dimensional data is determined based on the user behavior data, the device fingerprint data, and the real-time threat intelligence.

8. A multi-factor dynamic authentication device, characterized in that, The device includes: The data acquisition module is used to collect multi-dimensional data in real time based on the received authentication requests; wherein the multi-dimensional data includes at least user behavior data, device fingerprint data and real-time threat intelligence. An evaluation module is used to evaluate the multi-dimensional data based on a pre-trained artificial intelligence model to obtain a comprehensive risk score for the authentication request. The first determining module is used to determine a target multi-factor authentication strategy from a preset multi-factor authentication strategy library based on the comprehensive risk score; The authentication result acquisition module is used to acquire the authentication result of the user's authentication of the target multi-factor authentication strategy; The second determining module is used to determine whether to authorize or deny access to the user based on the authentication result.

9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the multi-factor dynamic authentication method according to any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the multi-factor dynamic authentication method as described in any one of claims 1-7.

Citation Information

Cited By

  • Security authentication method and device and storage medium

    CN121508970A