Front-end implicit authentication method and system based on multi-dimensional operation behavior characteristics
By using a front-end implicit authentication method based on multi-dimensional operational behavior characteristics, user operation characteristics are collected and analyzed in real time to build a user behavior benchmark library. Real-time consistency verification is performed by combining Gaussian mixture model and LSTM model, which solves the problems of easy cracking, non-persistence and hardware dependence of existing authentication technologies, and achieves high-precision and low-latency security authentication, thereby improving security and user experience.
Patent Information
- Application Number
- CN202511246295.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-02
- Publication Date
- 2025-11-18
AI Technical Summary
Existing account security authentication technologies suffer from vulnerabilities such as easy spoofing, non-persistent verification, limitations in the widespread adoption of hardware-dependent biometric authentication, and the one-dimensional limitations of behavioral analysis authentication. These issues result in high security risks, poor user experience, and insufficient privacy compliance.
A front-end implicit authentication method based on multi-dimensional operational behavior features is adopted. By collecting keyboard input, touch operation and device interaction features in real time, a user-specific behavior benchmark library is built. Gaussian mixture model and LSTM model are combined for real-time consistency verification and the authentication strategy is dynamically adjusted to achieve high-precision identity verification.
It achieves an attack interception rate of ≥95% and a false positive rate of <4%, is compatible with common devices, has an authentication latency of <150ms, meets GDPR/CCPA privacy compliance, and improves security, universality, and user experience.
Smart Images

Figure CN120979766A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of biometric recognition and front-end security authentication, and particularly to a front-end implicit authentication method and system based on multi-dimensional operational behavior characteristics. It is applicable to continuous identity security protection scenarios for web applications, mobile devices, and desktop applications. Background Technology
[0002] In the digital age, web applications, mobile devices, and desktop clients serve as the core carriers for users to access network services, and their account security authentication technologies are crucial barriers to protecting user data privacy and asset security. However, with the iterative upgrading of network attack methods (such as brute-force attacks, phishing attacks, and session hijacking), current mainstream account security authentication technologies are gradually revealing multi-dimensional limitations, making it difficult to meet the "continuous, universal, and accurate" identity verification requirements in complex scenarios. Specific problems are as follows:
[0003] I. Inherent defects of static authentication technology
[0004] Static authentication schemes, represented by passwords and SMS verification codes, are currently the most widely used basic authentication methods, but they have two major shortcomings:
[0005] Ease of cracking: Static credentials (such as simple passwords, reusable verification codes, and phone numbers) are easily stolen by attackers through dictionary attacks, credential stuffing, phishing links, etc. - According to the 2023 cybersecurity report, more than 60% of account leaks are caused by the cracking of static passwords; even if a strong password strategy is adopted, users may still choose predictable combinations such as "characters + birthday" for ease of memorization, further lowering the security threshold.
[0006] Non-persistent authentication: Static authentication is only triggered at specific points such as "login" and "payment," and cannot verify the user's identity in real time during subsequent operations. For example, after an attacker steals the password and logs into the account, they can freely perform sensitive operations such as transferring money, changing the linked mobile phone number, and deleting critical data during the session's validity period. Traditional solutions cannot detect the anomaly of "the logged-in user not matching the real user," creating a significant security vulnerability.
[0007] II. Bottlenecks in the Popularization of Hardware-Dependent Biometric Authentication
[0008] While biometric authentication technologies such as fingerprint recognition, facial recognition, and iris scanning are superior to static authentication in terms of security, they are limited by hardware conditions and cannot achieve full-scenario coverage.
[0009] Dedicated hardware barriers: Such solutions require devices to be equipped with dedicated sensors (such as fingerprint modules, 3D structured light cameras, and iris scanners), while many ordinary devices (such as old feature phones, entry-level tablets, and desktop monitors without touch functionality) cannot support this type of certification due to hardware costs or design limitations; even in the field of smart devices, about 20% of low-end models are still not equipped with fingerprint recognition modules, which limits the scope of technology adoption.
[0010] Poor scenario adaptability: Hardware-dependent solutions are easily affected by environmental factors. For example, the success rate of fingerprint recognition drops significantly when the user's fingers are wet or damaged, and facial recognition is prone to failure in low light or obstructed (such as with a mask) scenarios, further reducing user experience and authentication reliability.
[0011] III. The Limitations of the One-Dimensional Approach to Behavioral Analysis Authentication
[0012] In recent years, authentication technologies based on user behavior (such as mouse trajectory analysis and keystroke interval recognition) have begun to be applied. However, existing solutions generally suffer from the problem of "one-dimensional modeling," resulting in insufficient recognition accuracy and anti-interference ability.
[0013] Single feature dimension: Most solutions focus only on a single behavioral feature (such as only analyzing the speed and curvature of the mouse movement trajectory, or only counting the time interval of keyboard key presses), ignoring the "multi-behavior coordination" characteristics during user operation. For example, when a user enters a password, there are often related behaviors such as changes in screen touch pressure and adjustments in device grip angle. A single feature is difficult to fully depict the user's unique behavioral patterns.
[0014] Lack of multimodal fusion capability: Due to the absence of a fusion modeling mechanism for multi-dimensional behavioral features, existing solutions are weakly resistant to "interference from similar behaviors." For example, different users may have similar keystroke intervals, and relying solely on this feature can easily lead to "misjudging the user as abnormal" or "misjudging the attacker as the user." At the same time, when the collection of a single feature is interfered with (such as mouse malfunction causing abnormal trajectory), the entire authentication system may fail directly, resulting in insufficient stability.
[0015] The aforementioned existing technologies address the following typical pain points:
[0016] The aforementioned technical limitations directly lead to security risks in practical applications. For example, after attackers steal users' bank account passwords through phishing emails, they can bypass traditional SMS two-factor authentication (such as using fake base stations to intercept verification codes) and log in to perform transfer operations. In this process, traditional solutions cannot identify "the login user is not the real person" through static credentials, and due to a lack of multi-dimensional behavioral analysis capabilities, they cannot capture in real time the attacker's "abnormal keystroke intervals" and "device holding angles inconsistent with real users," ultimately leading to user asset losses. Such security incidents caused by authentication technology defects result in economic losses exceeding tens of billions of yuan annually for individuals and businesses, highlighting the urgent need to upgrade existing authentication systems. Summary of the Invention
[0017] To address the aforementioned issues, the present invention aims to provide a front-end implicit authentication method and system based on multi-dimensional operational behavior characteristics. This method and system can achieve an attack interception rate of ≥95% and a false positive rate of <4%. It is compatible with ordinary devices, has an authentication latency of <150ms that is imperceptible to users, and meets GDPR / CCPA privacy compliance requirements through local de-identification processing and AES-256 encrypted transmission. This comprehensively improves security, universality, user experience, and privacy compliance.
[0018] The above-mentioned objective of this invention is achieved through the following technical solutions:
[0019] An implicit authentication method for front-end systems based on multi-dimensional operational behavior features includes the following steps:
[0020] S1: Conduct multi-dimensional behavioral feature collection and modeling, including real-time collection of various behavioral features during user operations through standard interfaces that can be called by the front end; preprocessing the collected raw feature data to eliminate data interference and unify the data format; assigning weights to each feature based on feature discrimination to enhance the impact of high-discrimination features on authentication results; and using a probabilistic model to train the processed feature data to build a user-specific behavioral benchmark library to provide a reference for subsequent identity verification.
[0021] S2: Perform real-time behavior consistency verification, including collecting real-time user operation data at a preset frequency and converting it into feature vectors, analyzing the behavior patterns of the feature vectors through a time series model, calculating the similarity between the real-time feature sequence and the reference sequence in the behavior benchmark library using a sequence alignment algorithm, generating a quantitative similarity score, setting anomaly judgment conditions, and triggering a secondary verification mechanism if the real-time similarity meets the anomaly conditions.
[0022] S3: Implement authentication decision-making and dynamic response mechanisms, including tiered authentication decisions based on similarity scores, matching processing strategies for different risk levels, dynamically adjusting authentication parameters and calculation modes based on user scenarios to balance authentication security and applicability, adopting data privacy protection measures throughout the process, and continuously optimizing authentication accuracy through sample feedback and model iteration mechanisms.
[0023] Furthermore, in step S1, multiple behavioral characteristics of the user during the operation process are collected in real time through standard interfaces that can be called by the front end, specifically:
[0024] The various behavioral characteristics include three categories: keyboard input characteristics, touch operation characteristics, and device interaction characteristics; the front-end can call the standard interface Web API.
[0025] Keyboard input feature acquisition: Real-time acquisition of key interval (KeyInterval), key duration (Key Duration), and input frequency (Typing Speed) through keydown / keyup event listening.
[0026] Touch operation feature acquisition: Real-time acquisition of touch pressure, swipe trajectory, and long press duration through touchstart / touchend / touchmove events;
[0027] Device interaction feature acquisition: Real-time acquisition of screen rotation angle (Rotation), grip acceleration (Acceleration), and device tilt angle (Tilt) using DeviceOrientation / DeviceMotion sensors.
[0028] Furthermore, in step S1, the collected raw feature data is preprocessed to eliminate data interference and unify the data format, specifically as follows:
[0029] Timing window splitting:
[0030] Continuous behavioral data is divided into fixed-duration windows to ensure that the features within each time window are temporally correlated.
[0031] Feature standardization:
[0032] Normalization is performed on behavioral features of different dimensions to avoid large numerical features dominating the model. The standardized formula for normalization is as follows:
[0033]
[0034] Where, x normHere, x represents the standardized feature, min(x) represents the minimum value of the feature within the historical data collection period, and max(x) represents the maximum value of the feature within the historical data collection period.
[0035] Furthermore, in step S1, weights are assigned to each feature based on its discriminative power to enhance the impact of highly distinctive features on the authentication results, specifically as follows:
[0036] Information entropy calculation:
[0037] Assign higher weights to highly discriminative behavioral features to ensure the model focuses on users' unique behavioral patterns. To ensure high weights for highly discriminative features, the weights should be proportional to information entropy. The lower the information entropy, the more concentrated the distribution, and the more difficult it is to distinguish different users. The specific information entropy value can be statistically obtained through the following formula:
[0038]
[0039] Where f is the behavioral feature to be calculated, and x i Let p(x) be the i-th discrete value of this behavioral feature. i ) is the feature x i The probability is given by b, where b is the logarithm base, H(f) is the information entropy value, and m is the number of equally spaced intervals after discrete processing.
[0040] Weighting:
[0041] The formula for calculating weight allocation is:
[0042]
[0043] Where w i Representing behavioral characteristics f i The weights, H(f) i ) represents behavioral characteristics f i Information entropy, high-discrimination features will be assigned higher weights, where n is the total number of behavioral features.
[0044] Furthermore, in step S1, a probabilistic model is used to train the processed feature data to construct a user-specific behavior benchmark library, providing a reference for subsequent identity verification. Specifically:
[0045] Gaussian Mixture Model (GMM) is selected as the probability model. The GMM is used to capture the multimodal distribution of user operation behavior in the form of a probability model. The multimodal distribution includes multiple behavior patterns where a single user behavior feature exists.
[0046] Gaussian Mixture Model (GMM) is trained on the multi-dimensional user operation behavior feature data after preprocessing and weight allocation. The multimodal distribution law of user behavior is fitted through the training process, thereby generating a unique behavior probability density function for each user, which is the user's behavior fingerprint.
[0047] The behavioral fingerprints of all users are aggregated and stored to form a behavioral fingerprint database for behavioral consistency verification in the subsequent S2 step. Each user's behavioral fingerprint in the behavioral fingerprint database corresponds one-to-one with the user identifier, ensuring that the historical behavioral benchmark of the target user can be accurately matched during behavioral consistency verification.
[0048] Further, in step S2, real-time user operation data is collected at a preset frequency and converted into feature vectors. The behavioral patterns of the feature vectors are analyzed using a time-series model. A sequence alignment algorithm is used to calculate the similarity between the real-time feature sequence and reference sequences in the behavioral benchmark library, generating a quantified similarity score. Anomaly detection conditions are set. If the real-time similarity meets the anomaly conditions, a secondary verification mechanism is triggered, specifically:
[0049] User operation data is sampled at a preset frequency. After collection, the time window segmentation, feature standardization, and weight allocation are completed sequentially according to the steps in step S1. The data is then transformed into a feature vector of fixed dimension, with the feature vector dimension being consistent with the total number of features collected.
[0050] Temporal model analysis was conducted using a pre-trained three-layer LSTM model to analyze the temporal patterns of feature vectors. The model structure is as follows: input layer matching the dimension of the feature vector → first layer LSTM with 128 units → Dropout layer → second layer LSTM with 128 units → third layer LSTM with 128 units → output layer with ReLU as the activation function, which outputs the temporal feature encoding. This model is pre-trained based on a large user behavior dataset, and the training objective is to minimize the temporal feature encoding reconstruction error to ensure accurate extraction of user behavior temporal patterns.
[0051] Sequence alignment and similarity score calculation were performed using the Dynamic Time Warping (DTW) algorithm. Let the current real-time feature sequence be X = (x1, x2, ..., x...). m ), where m is the real-time sequence length, and the corresponding user reference sequence in the behavioral benchmark library is Y = (y1, y2, ..., y). n ), where n is the length of the reference sequence, taken from the mean sequence of the user's historical feature sequences;
[0052] Calculate the DTW distance by finding the optimal regular path through dynamic programming to minimize the alignment error between sequences X and Y. The distance formula is:
[0053]
[0054] Where K is the length of the regular path, x k This refers to the k-th element in the current real-time feature sequence, y k This refers to the k-th element of the fingerprint database reference sequence, φ = ||x i -y j ||2 represents the maximum Euclidean distance in the feature dimension, x i Let y be the i-th element in X. j Let S be the j-th element in Y. This distance represents the difference between the two sequences. The smaller the difference, the higher the score. The specific score S is obtained using the inverse mapping.
[0055]
[0056] The DTW distance is converted into a similarity score in the range of 0-1. The closer the score is to 1, the higher the consistency between real-time behavior and user's historical behavior.
[0057] Anomaly detection and secondary verification are triggered. A dynamic threshold for anomaly detection is set. If the real-time similarity score S is continuously lower than the preset threshold for several consecutive sampling periods, the identity is determined to be abnormal, and a multi-factor secondary verification process is immediately triggered.
[0058] Furthermore, in step S3, a tiered authentication decision is executed based on the similarity score, matching processing strategies for different risk levels, specifically as follows:
[0059] Based on the similarity score output in step S2, a multi-level authentication decision is executed, setting a first risk threshold and a second risk threshold, with the first risk threshold being greater than the second risk threshold.
[0060] When the similarity score is greater than or equal to the first risk threshold, it is determined to be a normal operation by the user, the current behavior is allowed to be executed, and the feature vector is stored in the behavior baseline library through the incremental learning algorithm. The GMM model weights are updated after a fixed number of executions.
[0061] When the similarity score is greater than or equal to the second risk threshold but less than the first risk threshold, the multi-factor authentication interface is triggered. Depending on the scenario, SMS verification code or biometric verification is invoked. After the second-level verification is successful, the current operation is marked as a trusted anomaly, and the first risk threshold is dynamically adjusted to τ using a sliding window algorithm. high =μ(t)-1.28σ(t) where μ is the mean of recent scores, σ is the variance, and t refers to the amount of recent behavioral data;
[0062] When the similarity score is less than the second risk threshold, the sensitive operation is immediately interrupted and a security log containing the abnormal feature D is generated. dtw The system simultaneously pushes alarms to user terminals based on IP address and device fingerprint.
[0063] Furthermore, in step S3, the authentication parameters and calculation mode are dynamically adjusted based on user scenarios to balance authentication security and applicability. Data privacy protection measures are adopted throughout the process, and authentication accuracy is continuously optimized through sample feedback and model iteration mechanisms. Specifically:
[0064] In terms of environmental adaptation, the first risk threshold is automatically and appropriately lowered in new device / remote login scenarios, and the first risk threshold is automatically and appropriately raised in common device scenarios. Lightweight mode is triggered when low-end devices or high CPU usage occur, the LSTM module is turned off, and the dual-feature DTW comparison is retained.
[0065] The entire process employs local de-identification computation, encrypted transmission of AES-256 feature vectors, and intercepted samples are reviewed and fed back into the training set through federated learning. The model parameters are iterated every quarter to optimize the anomaly detection rate.
[0066] A front-end implicit authentication system based on multi-dimensional operational behavior features for executing the aforementioned front-end implicit authentication method based on multi-dimensional operational behavior features includes:
[0067] The multi-dimensional behavioral feature modeling module is used for multi-dimensional behavioral feature collection and modeling. This includes real-time collection of various behavioral features during user operations through standard interfaces that can be called from the front end; preprocessing the collected raw feature data to eliminate data interference and unify the data format; assigning weights to each feature based on feature discriminability to enhance the impact of high-discrimination features on authentication results; and using a probabilistic model to train the processed feature data to build a user-specific behavioral benchmark library to provide a reference for subsequent identity verification.
[0068] The real-time behavior consistency verification module is used to perform real-time behavior consistency verification. This includes collecting real-time user operation data at a preset frequency and converting it into feature vectors, analyzing the behavior patterns of the feature vectors through a time series model, calculating the similarity between the real-time feature sequence and the reference sequence in the behavior benchmark library using a sequence alignment algorithm, generating a quantitative similarity score, setting anomaly judgment conditions, and triggering a secondary verification mechanism if the real-time similarity meets the anomaly conditions.
[0069] The authentication decision and dynamic response module is used for authentication decision and dynamic response mechanisms, including executing hierarchical authentication decisions based on similarity scores, matching processing strategies for different risk levels, dynamically adjusting authentication parameters and calculation modes in combination with user scenarios, balancing authentication security and applicability, adopting data privacy protection measures throughout the process, and continuously optimizing authentication accuracy through sample feedback and model iteration mechanisms.
[0070] A computer-readable storage medium storing computer code that, when executed, performs the method described above.
[0071] Compared with the prior art, the present invention has at least one of the following beneficial effects:
[0072] (1) Significantly improved security: Based on multi-dimensional behavioral feature collection and modeling and real-time consistency verification mechanism, the attack interception rate is ≥95% in simulated attack tests (the test dataset covers 1000 simulated attacks, including common attack types such as brute force and phishing). By constructing a unique user behavior fingerprint through Gaussian mixture model, combined with LSTM model and DTW algorithm, abnormal behavior is accurately identified with a false alarm rate of <4%, effectively resisting the risk of attackers bypassing verification and performing sensitive operations after stealing credentials, and greatly reducing the possibility of data leakage and asset loss due to account theft.
[0073] (2) Wide applicability: It has flexible device adaptation capabilities. For devices without dedicated hardware such as pressure sensors, it can automatically downgrade to the keyboard + trajectory dual feature mode (such as old mobile phones and ordinary office computers). It does not need to rely on dedicated sensors, breaks through hardware limitations, covers more types of terminals, and allows users with different device configurations to enjoy effective authentication services, thus expanding the scope of technology application.
[0074] (3) User experience optimization and upgrade: The authentication process has been optimized by Web Worker, and the authentication latency has been controlled to <150ms. This latency is within the range that users cannot perceive and will not interrupt the operation process. The entire process, from behavioral feature collection to authentication decision, runs efficiently, which not only ensures account security, but also makes users feel no obvious obstacles in the authentication process when logging in and operating sensitive functions, thereby improving the smoothness of use and user satisfaction.
[0075] (4) Strict Privacy Compliance Guarantee: Raw behavioral data (such as key press intervals, touch trajectories, etc.) is processed 100% locally (including preprocessing, feature extraction, etc.), and only AES-256 encrypted feature vectors are uploaded to avoid leakage of raw privacy data. This mechanism complies with mainstream international privacy protection standards such as GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act), ensuring that user data is properly protected during the authentication process and enhancing user trust in the technology and related services.
[0076] (5) Continuous Model Iteration and Optimization: By using federated learning to intercept samples and feed them back into the training set, the model parameters are iterated every quarter. With the accumulation of samples and model updates, the system can continuously adapt to new attack methods and changes in user behavior, continuously improving the anomaly detection rate and ensuring that the authentication system always maintains good security and adaptability, providing long-term and dynamic protection for account security.
[0077] (6) Flexible and intelligent scenario adaptation: The authentication threshold is automatically adjusted for different scenarios such as new devices / login from different locations and frequently used devices. Lightweight mode is triggered when low-end devices or high CPU usage occur. It can intelligently balance security and performance according to the actual usage scenario, making it more convenient to log in to new devices and more stringent to authenticate frequently used devices while ensuring security. At the same time, it avoids affecting user operation due to insufficient device performance, thus improving the practicality of the technology in complex scenarios. Attached Figure Description
[0078] Figure 1 This is a flowchart illustrating the overall process of the front-end implicit authentication method based on multi-dimensional operational behavior characteristics of the present invention.
[0079] Figure 2 This is a diagram showing the overall structure of the front-end implicit authentication system based on multi-dimensional operational behavior characteristics according to the present invention. Detailed Implementation
[0080] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0081] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this specification means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0082] First Embodiment
[0083] like Figure 1 As shown, this embodiment provides a front-end implicit authentication method based on multi-dimensional operation behavior features, characterized by the following steps:
[0084] S1: Conduct multi-dimensional behavioral feature collection and modeling, including real-time collection of various behavioral features during user operations through standard interfaces that can be called by the front end; preprocessing the collected raw feature data to eliminate data interference and unify the data format; assigning weights to each feature based on feature discrimination to enhance the impact of high-discrimination features on authentication results; and using a probabilistic model to train the processed feature data to build a user-specific behavioral benchmark library to provide a reference for subsequent identity verification.
[0085] (1) Collect multiple behavioral characteristics of users during operation in real time through standard interfaces that can be called by the front end, specifically:
[0086] The various behavioral characteristics include three categories: keyboard input characteristics, touch operation characteristics, and device interaction characteristics; the front-end can call the standard interface Web API.
[0087] Keyboard input feature acquisition: Real-time acquisition of key interval (KeyInterval), key duration (Key Duration), and input frequency (Typing Speed) through keydown / keyup event listening.
[0088] Touch operation feature acquisition: Real-time acquisition of touch pressure, swipe trajectory, and long press duration through touchstart / touchend / touchmove events;
[0089] Device interaction feature acquisition: Real-time acquisition of screen rotation angle (Rotation), grip acceleration (Acceleration), and device tilt angle (Tilt) using DeviceOrientation / DeviceMotion sensors.
[0090] For example, when a user inputs "hello", the collected keyboard key press intervals are: h→e (0.1 seconds), e→l (0.08 seconds), l→l (0.05 seconds), l→o (0.12 seconds), forming a temporal feature sequence.
[0091] In the front-end environment, this invention cleverly leverages the Web API natively supported by browsers to build a non-intrusive user operation behavior feature collection mechanism. Specifically, for core scenarios of user interaction with the front-end interface, it precisely focuses on three behavioral dimensions for feature collection: For keyboard interaction scenarios, it uses keydown / keyup event listeners to capture key intervals (reflecting the timing rhythm of the user's fingers pressing keys), key duration (reflecting the continuous characteristics of finger pressure when pressing keys), and typing speed (characterizing the user's typing speed preference). These subtle differences in keyboard operation features together constitute a unique "keyboard behavior fingerprint." Different users have vastly different key timing patterns, which are the foundation and key basis for identifying user identity. In touchscreen interaction scenarios, it relies on touchstart / touchend / touchmove events to collect touch pressure (Touch Pressure, which can be accurately obtained by some pressure-sensing devices), swipe trajectory (recording the sequence of coordinate changes of the touch point on the screen), and long press duration (Long Press). Duration (reflecting the user's intent and timing of a long press) effectively supplements behavioral difference data between mobile and touchscreen devices, adapting to mainstream usage scenarios such as mobile office and touchscreen operation. At the device physical interaction level, it utilizes DeviceOrientation / DeviceMotion sensors to acquire screen rotation (related to the user's habitual grip posture), grip acceleration (representing changes in hand strength when gripping the device), and device tilt (reflecting the device's physical posture characteristics). This uncovers difficult-to-imitate physical behavior patterns during device handling, further strengthening the uniqueness of identity authentication. Taking the user's input of "hello" as an example, event listening accurately records the time interval between each keystroke, such as 0.1 seconds for h→e and 0.08 seconds for e→l. This transforms seemingly discrete keystrokes into a continuous temporal feature sequence, providing fine-grained and highly discriminative data support for subsequent identity authentication modeling based on multi-dimensional behavioral features. These millisecond-level time differences, combined, become the user's unique input "rhythm password," a crucial clue for distinguishing between the user and an attacker.
[0092] (2) Preprocess the collected raw feature data to eliminate data interference and unify the data format, transforming the raw data into structured features that can be used for model training, and solving the problems of inconsistent dimensions and noise. Specifically:
[0093] Timing window splitting:
[0094] Continuous behavioral data is divided into fixed-duration windows (e.g., 3 seconds / window) to ensure that the features within each time window are temporally correlated (e.g., divide 10 seconds of key press data into 3 windows, each containing 3-4 key presses).
[0095] Feature standardization:
[0096] Normalization is performed on behavioral features of different dimensions (e.g., mapping key press intervals (seconds) and touch pressure (0-1) to the [0,1] interval) to avoid large numerical features dominating the model. The normalization formula is as follows:
[0097]
[0098] Where, x norm Here, x represents the standardized feature, min(x) represents the minimum value of the feature within the historical data collection period, and max(x) represents the maximum value of the feature within the historical data collection period.
[0099] After real-time collection of multi-dimensional user behavior features, this solution employs a targeted preprocessing workflow to eliminate interference and standardize the data format in the raw data, ensuring it meets the structured feature requirements of subsequent model training. The core solution addresses the common issues of inconsistent dimensions and noise in the raw data. Specifically, the temporal window segmentation process divides continuously generated behavioral data (such as continuous keyboard input and touch swipe data) into independent temporal windows of fixed duration (default 3 seconds). This ensures that the feature data within each window has a strong temporal correlation—for example, 10 seconds of keyboard keystroke data is split into three valid windows: the first two windows each contain three keystrokes, and the third window contains four keystrokes. This segmentation method avoids weakening of temporal correlation due to excessively long data spans and provides a unified data dimension for subsequent feature extraction and model input through a fixed window length. The feature standardization process focuses on resolving the issue of dimensional differences between different types of features, such as keyboard input... The button interval in the input features is in seconds (the value is usually in the range of 0.01-1 seconds), and the touch pressure in the touch operation features is presented as a unitless relative value (the range is fixed at 0-1). If directly used for model training, large numerical features tend to dominate the model learning direction. Therefore, the min-max normalization formula is adopted to uniformly map all features to the [0,1] interval, so that features of different dimensions have equal model contribution weights. At the same time, by calculating the extreme values based on historical data, the interference of single abnormal data collection on the overall feature distribution is further reduced, providing high-quality, standardized structured feature data support for subsequent behavior modeling and similarity calculation based on Gaussian mixture model (GMM).
[0100] (3) Assign weights to each feature based on feature discriminativeness to enhance the impact of highly discriminative features on the authentication results, specifically:
[0101] Information entropy calculation:
[0102] Assign higher weights to highly discriminative behavioral features (the higher the information entropy, the more dispersed the data) to ensure the model focuses on the user's unique behavioral patterns. To give high weights to highly discriminative features, the weights should be proportional to the information entropy. The lower the information entropy, the more concentrated the distribution, and the more difficult it is to distinguish different users. The specific information entropy value can be obtained statistically using the following formula:
[0103]
[0104] Where f is the behavioral feature to be calculated, such as touch pressure, and x i Let p(x) be the i-th discrete value of this behavioral feature. i ) is the feature x i The probability is given by b, which is the logarithm base and is usually represented by 2. H(f) is the information entropy value and m is the number of equally spaced intervals after discrete processing.
[0105] Weighting:
[0106] The formula for calculating weight allocation is:
[0107]
[0108] Where w i Representing behavioral characteristics f i The weights, H(f) i ) represents behavioral characteristics f i Information entropy, high-discrimination features will be assigned higher weights, where n is the total number of behavioral features.
[0109] After feature preprocessing, to ensure that subsequent model training prioritizes behavioral features with higher user identity differentiation, this solution employs a two-step logic of "information entropy calculation - weight allocation" to assign differentiated weights to behavioral features of different dimensions, thereby strengthening the impact of high-discrimination features on the final authentication result. The information entropy calculation step serves as the core basis for weight allocation. Its core logic is to evaluate the feature's discriminative ability by quantifying the dispersion of feature data—the higher the information entropy value, the more dispersed the value distribution of the feature, and the more significant the behavioral differences among different users on that feature. For example, if the touch pressure feature exhibits a wide distribution from 0.2 to 0.8 among different users (rather than being concentrated around a fixed value), its information entropy value will be significantly higher than features with concentrated distributions (e.g., for some devices, the screen rotation angle may only be used by most users at 0° or 90°, resulting in a concentrated distribution and lower information entropy). Specifically, the continuous values of the target behavioral feature (such as touch pressure, button spacing) need to be divided into m equally spaced discrete intervals, and the values of each interval (i.e., the i-th discrete value x) are statistically analyzed. i The probability p(x) of appearing in historical data i The model first calculates the discriminative power of a feature using the information entropy formula. Then, the weight allocation stage distributes weights proportionally based on the information entropy values of each feature. The weight calculation formula increases the weight of features with high information entropy (high discriminative power). For example, if the information entropy of touch pressure is 1.8, the information entropy of button spacing is 1.2, and the total information entropy of other features is 2.0, then the weight of touch pressure is 1.8 / (1.8+1.2+2.0) = 0.36, significantly higher than some low-discriminative features. This allocation method guides the model to focus more on features that reflect unique user behavior patterns (such as personal touch pressure habits and button rhythm) during learning and validation, thereby improving the accuracy of identity authentication and reducing the risk of misjudgment caused by interference from low-discriminative features.
[0110] (4) A probabilistic model is used to train the processed feature data to build a user-specific behavior benchmark library, providing a reference for subsequent identity verification, specifically:
[0111] Gaussian Mixture Model (GMM) is selected as the probability model. The GMM is used to capture the multimodal distribution of user operation behavior in the form of a probability model (for example, the user's key press interval may simultaneously conform to both "fast press" and "slow press" modes). The multimodal distribution includes multiple behavior patterns where a single user behavior feature exists.
[0112] Gaussian Mixture Model (GMM) is trained on the multi-dimensional user operation behavior feature data after preprocessing and weight allocation. The multimodal distribution law of user behavior is fitted through the training process, thereby generating a unique behavior probability density function for each user, which is the user's behavior fingerprint.
[0113] The behavioral fingerprints of all users are aggregated and stored to form a behavioral fingerprint database for behavioral consistency verification in the subsequent S2 step. Each user's behavioral fingerprint in the behavioral fingerprint database corresponds one-to-one with the user identifier, ensuring that the historical behavioral benchmark of the target user can be accurately matched during behavioral consistency verification.
[0114] S2: Perform real-time behavior consistency verification, including collecting real-time user operation data at a preset frequency and converting it into feature vectors, analyzing the behavior patterns of the feature vectors through a time series model, calculating the similarity between the real-time feature sequence and the reference sequence in the behavior benchmark library using a sequence alignment algorithm, generating a quantitative similarity score, setting anomaly judgment conditions, and triggering a secondary verification mechanism if the real-time similarity meets the anomaly conditions.
[0115] In this embodiment, step S2 specifically includes:
[0116] User operation data is sampled at a preset frequency. After collection, the time window segmentation, feature standardization, and weight allocation are completed sequentially according to the steps in step S1. The data is then transformed into a feature vector of fixed dimension, with the feature vector dimension being consistent with the total number of features collected.
[0117] Temporal model analysis was conducted using a pre-trained (based on a dataset of 100+ user behaviors) three-layer LSTM model to analyze the temporal patterns of feature vectors. The model structure is as follows: input layer with dimension matching feature vector dimension → first LSTM layer with 128 units → Dropout layer → second LSTM layer with 128 units → third LSTM layer with 128 units → output layer with ReLU activation function, outputting temporal feature encoding. This model was pre-trained on a large user behavior dataset, and the training objective was to minimize the temporal feature encoding reconstruction error to ensure accurate extraction of user behavior temporal patterns.
[0118] Sequence alignment and similarity score calculation were performed using the Dynamic Time Warping (DTW) algorithm. Let the current real-time feature sequence be X = (x1, x2, ..., x...). m ), where m is the real-time sequence length, and the corresponding user reference sequence in the behavioral benchmark library is Y = (y1, y2, ..., y). n ), where n is the length of the reference sequence, taken from the mean sequence of the user's historical feature sequences;
[0119] Calculate the DTW distance by finding the optimal regular path through dynamic programming to minimize the alignment error between sequences X and Y. The distance formula is:
[0120]
[0121] Where K is the length of the regular path, x k This refers to the k-th element in the current real-time feature sequence, y k This refers to the k-th element of the fingerprint database reference sequence, φ = ||x i -y j ||2 represents the maximum Euclidean distance in the feature dimension, x i Let y be the i-th element in X. j Let S be the j-th element in Y. This distance represents the difference between the two sequences. The smaller the difference, the higher the score. The specific score S is obtained using the inverse mapping.
[0122]
[0123] The DTW distance is converted into a similarity score in the range of 0-1. The closer the score is to 1, the higher the consistency between real-time behavior and user's historical behavior. For example, when DTW(X,Y) is 0.05, the score is 0.952, and the higher the similarity, the closer it is to 1.
[0124] Anomaly detection and secondary verification are triggered by setting a dynamic threshold for anomaly detection. If the real-time similarity score S is consistently lower than the preset threshold for several consecutive sampling periods, the identity is determined to be abnormal, and a multi-factor secondary verification process is immediately triggered. For example, if the behavioral similarity score S is consistently lower than the dynamic threshold of 0.72 optimized by the ROC curve for three consecutive sampling periods (i.e., within 0.3 seconds), corresponding to an F1-score of 0.89 (with a true positive rate TPR of 96.5% and a false positive rate FPR of 3.1%), the system will immediately trigger the multi-factor secondary verification process.
[0125] In the real-time behavior consistency verification stage (S2), this solution achieves accurate comparison between the user's current operation and historical behavior benchmarks through a full-process design of "data acquisition and transformation - temporal pattern analysis - similarity calculation - anomaly judgment". The core lies in ensuring the real-time performance and accuracy of the verification through high-frequency acquisition, deep modeling, and dynamic thresholds. Specifically, firstly, real-time user operation data is collected at a preset frequency of 10Hz (i.e., once every 0.1 seconds). After collection, the preprocessing standard verified in step S1 is strictly followed - firstly, a temporal window segmentation of 3 seconds / window is performed to preserve the temporal correlation of behavior, then feature standardization is completed through min-max normalization, and finally, feature weights are assigned based on the information entropy calculation results. Finally, the data is transformed into a fixed-dimensional feature vector with the same number of features, ensuring the consistency between the real-time data format and the historical data in the behavior benchmark library, laying the foundation for subsequent comparisons. Next, a three-layer LSTM model pre-trained on a dataset of 100+ user behaviors was used for temporal pattern analysis. This model, through its structure of "input layer - three-layer 128-unit LSTM - Dropout - ReLU activation output layer," effectively captures long-term temporal dependencies in behavioral data (such as the rhythmic patterns of continuous keystrokes) using multiple LSTM units, while avoiding overfitting through the Dropout layer (with a dropout probability of 0.2). The training process aims to minimize the temporal feature encoding reconstruction error, ensuring the model accurately extracts unique user-specific temporal patterns and transforms feature vectors into temporal feature codes suitable for comparison. In the similarity calculation stage, the Dynamic Time Warping (DTW) algorithm was used to address potential length differences between real-time and reference sequences. Dynamic programming was used to find the optimal warping path, and the difference between the two sequences was calculated using a distance formula. Then, the DTW distance was converted into a similarity score in the 0-1 interval using a reciprocal mapping formula—for example, when the DTW distance is 0.05, the score reaches 0.952, intuitively reflecting the high consistency between real-time and historical behaviors. Finally, the anomaly detection process uses a dynamic threshold of 0.72 (corresponding to F1-score = 0.89, TPR = 96.5%, FPR = 3.1%), which has been trained and optimized from 1000+ attack samples. If the similarity score is lower than this threshold for three consecutive sampling periods (within 0.3 seconds), it indicates that there is a significant deviation between the current operation and the user's historical behavior. The system immediately triggers multi-factor secondary verification (such as SMS verification code and biometric verification), which avoids misjudgment caused by single accidental deviations and can quickly intercept abnormal operations such as account theft, thus achieving a security closed loop of "real-time verification - accurate identification - timely interception".
[0126] S3: Implement authentication decision-making and dynamic response mechanisms, including tiered authentication decisions based on similarity scores, matching processing strategies for different risk levels, dynamically adjusting authentication parameters and calculation modes based on user scenarios to balance authentication security and applicability, adopting data privacy protection measures throughout the process, and continuously optimizing authentication accuracy through sample feedback and model iteration mechanisms.
[0127] In this embodiment, step S3 specifically includes:
[0128] Based on the similarity score output in step S2, a multi-level authentication decision is performed, setting a first risk threshold and a second risk threshold, with the first risk threshold being greater than the second risk threshold; for example, setting the first risk threshold to 0.72 and the second risk threshold to 0.5.
[0129] When the similarity score is greater than or equal to the first risk threshold (e.g., S≥0.72 (high trust threshold, optimized by ROC curve)), it is determined to be a normal operation by the user, the current behavior is allowed to be executed, and the feature vector is stored in the behavior baseline library through the incremental learning algorithm. The operation updates the GMM model weights after a fixed number of executions (e.g., 50 times).
[0130] When the similarity score is greater than or equal to the second risk threshold but less than the first risk threshold (0.5 ≤ S < 0.72 (medium risk range)), the multi-factor authentication interface is triggered. Depending on the scenario, SMS verification code or biometric verification is invoked. After the second-level verification is passed, the current operation is marked as a trustworthy anomaly, and the first risk threshold is dynamically adjusted to τ using a sliding window algorithm (window = 100 operations). high =μ(t)-1.28σ(t) where μ is the mean of recent scores, σ is the variance, and t refers to the amount of recent behavioral data;
[0131] When the similarity score is less than the second risk threshold (S < 0.5 (high risk threshold)), the sensitive operation is immediately interrupted and a security log containing the abnormal feature D is generated. dtw The system simultaneously pushes alarms to user terminals based on IP address and device fingerprint.
[0132] In terms of environmental adaptation, the first risk threshold is automatically and appropriately lowered in new device / remote login scenarios, and the first risk threshold is automatically and appropriately raised in common device scenarios (e.g., the threshold is automatically relaxed to 0.68 in new device / remote login scenarios and raised to 0.78 in common device scenarios). Lightweight mode is triggered when low-end devices or high CPU usage occur, the LSTM module is turned off, and the dual-feature DTW comparison is retained.
[0133] The entire process employs local desensitization calculation (original data coordinate offset processing), encrypted transmission of AES-256 feature vectors, and intercepted samples are reviewed and federated back to the training set. The model parameters are iterated every quarter to optimize the anomaly detection rate.
[0134] Second Embodiment
[0135] like Figure 2 As shown, this embodiment provides a front-end implicit authentication system based on multi-dimensional operation behavior features for executing the front-end implicit authentication method based on multi-dimensional operation behavior features as described in the first embodiment, comprising:
[0136] The multi-dimensional behavioral feature modeling module 1 is used for multi-dimensional behavioral feature collection and modeling. This includes real-time collection of multiple behavioral features during user operations through standard interfaces that can be called from the front end; preprocessing the collected raw feature data to eliminate data interference and unify the data format; assigning weights to each feature based on feature discriminability to enhance the impact of high-discrimination features on authentication results; and using a probabilistic model to train the processed feature data to build a user-specific behavioral benchmark library to provide a reference for subsequent identity verification.
[0137] The real-time behavior consistency verification module 2 is used to perform real-time behavior consistency verification, including collecting real-time user operation data at a preset frequency and converting it into feature vectors, analyzing the behavior patterns of the feature vectors through a time series model, calculating the similarity between the real-time feature sequence and the reference sequence in the behavior benchmark library using a sequence alignment algorithm, generating a quantitative similarity score, setting anomaly judgment conditions, and triggering a secondary verification mechanism if the real-time similarity meets the anomaly conditions.
[0138] The authentication decision and dynamic response module 3 is used for authentication decision and dynamic response mechanisms, including executing hierarchical authentication decisions based on similarity scores, matching processing strategies for different risk levels, dynamically adjusting authentication parameters and calculation modes in combination with user scenarios, balancing authentication security and applicability, adopting data privacy protection measures throughout the process, and continuously optimizing authentication accuracy through sample feedback and model iteration mechanisms.
[0139] A computer-readable storage medium stores computer code that, when executed, performs the methods described above. Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. This program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0140] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.
[0141] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0142] It should be noted that the above embodiments can be freely combined as needed. The above description is only a preferred embodiment of the present invention. It should be pointed out that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A front-end implicit authentication method based on multi-dimensional operational behavior features, characterized in that, Includes the following steps: S1: Conduct multi-dimensional behavioral feature collection and modeling, including real-time collection of various behavioral features during user operations through standard interfaces that can be called by the front end; preprocessing the collected raw feature data to eliminate data interference and unify the data format; assigning weights to each feature based on feature discrimination to enhance the impact of high-discrimination features on authentication results; and using a probabilistic model to train the processed feature data to build a user-specific behavioral benchmark library to provide a reference for subsequent identity verification. S2: Perform real-time behavior consistency verification, including collecting real-time user operation data at a preset frequency and converting it into feature vectors, analyzing the behavior patterns of the feature vectors through a time series model, calculating the similarity between the real-time feature sequence and the reference sequence in the behavior benchmark library using a sequence alignment algorithm, generating a quantitative similarity score, setting anomaly judgment conditions, and triggering a secondary verification mechanism if the real-time similarity meets the anomaly conditions. S3: Implement authentication decision-making and dynamic response mechanisms, including tiered authentication decisions based on similarity scores, matching processing strategies for different risk levels, dynamically adjusting authentication parameters and calculation modes based on user scenarios to balance authentication security and applicability, adopting data privacy protection measures throughout the process, and continuously optimizing authentication accuracy through sample feedback and model iteration mechanisms.
2. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S1, multiple behavioral characteristics of the user during the operation process are collected in real time through standard interfaces that can be called by the front end, specifically: The various behavioral characteristics include three categories: keyboard input characteristics, touch operation characteristics, and device interaction characteristics; the front-end can call the standard interface Web API. Keyboard input feature acquisition: Real-time acquisition of key interval, key duration, and input frequency (Typing Speed) through keydown / keyup event listening. Touch operation feature acquisition: Real-time acquisition of touch pressure, swipe trajectory, and long press duration through touchstart / touchend / touchmove events; Device interaction feature acquisition: Real-time acquisition of screen rotation angle (Rotation), grip acceleration (Acceleration), and device tilt angle (Tilt) using DeviceOrientation / DeviceMotion sensors.
3. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S1, the collected raw feature data is preprocessed to eliminate data interference and unify the data format, specifically as follows: Timing window splitting: Continuous behavioral data is divided into fixed-duration windows to ensure that the features within each time window are temporally correlated. Feature standardization: Normalization is performed on behavioral features of different dimensions to avoid large numerical features dominating the model. The standardized formula for normalization is as follows: Where, x norm Here, x represents the standardized feature, min(x) represents the minimum value of the feature within the historical data collection period, and max(x) represents the maximum value of the feature within the historical data collection period.
4. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S1, weights are assigned to each feature based on its discriminative power to enhance the impact of highly discriminative features on the authentication results. Specifically: Information entropy calculation: Assign higher weights to highly discriminative behavioral features to ensure the model focuses on users' unique behavioral patterns. To ensure high weights for highly discriminative features, the weights should be proportional to information entropy. The lower the information entropy, the more concentrated the distribution, and the more difficult it is to distinguish different users. The specific information entropy value can be statistically obtained through the following formula: Where f is the behavioral feature to be calculated, and x i Let p(x) be the i-th discrete value of this behavioral feature. i ) is the feature x i The probability is given by b, where b is the logarithm base, H(f) is the information entropy value, and m is the number of equally spaced intervals after discrete processing. Weighting: The formula for calculating weight allocation is: Where w i Representing behavioral characteristics f i The weights, H(f) i ) represents behavioral characteristics f i Information entropy, high-discrimination features will be assigned higher weights, where n is the total number of behavioral features.
5. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S1, a probabilistic model is used to train the processed feature data to construct a user-specific behavior benchmark library, providing a reference for subsequent identity verification. Specifically: Gaussian Mixture Model (GMM) is selected as the probability model. The GMM is used to capture the multimodal distribution of user operation behavior in the form of a probability model. The multimodal distribution includes multiple behavior patterns where a single user behavior feature exists. Gaussian Mixture Model (GMM) is trained on the multi-dimensional user operation behavior feature data after preprocessing and weight allocation. The multimodal distribution law of user behavior is fitted through the training process, thereby generating a unique behavior probability density function for each user, which is the user's behavior fingerprint. The behavioral fingerprints of all users are aggregated and stored to form a behavioral fingerprint database for behavioral consistency verification in the subsequent S2 step. Each user's behavioral fingerprint in the behavioral fingerprint database corresponds one-to-one with the user identifier, ensuring that the historical behavioral benchmark of the target user can be accurately matched during behavioral consistency verification.
6. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S2, real-time user operation data is collected at a preset frequency and converted into feature vectors. The behavioral patterns of the feature vectors are analyzed using a time-series model. A sequence alignment algorithm is used to calculate the similarity between the real-time feature sequence and reference sequences in the behavioral benchmark library, generating a quantified similarity score. Anomaly detection conditions are set. If the real-time similarity meets the anomaly conditions, a secondary verification mechanism is triggered, specifically: User operation data is sampled at a preset frequency. After collection, the time window segmentation, feature standardization, and weight allocation are completed sequentially according to the steps in step S1. The data is then transformed into a feature vector of fixed dimension, with the feature vector dimension being consistent with the total number of features collected. Temporal model analysis was conducted using a pre-trained three-layer LSTM model to analyze the temporal patterns of feature vectors. The model structure is as follows: input layer matching the dimension of the feature vector → first layer LSTM with 128 units → Dropout layer → second layer LSTM with 128 units → third layer LSTM with 128 units → output layer with ReLU as the activation function, which outputs the temporal feature encoding. This model is pre-trained based on a large user behavior dataset, and the training objective is to minimize the temporal feature encoding reconstruction error to ensure accurate extraction of user behavior temporal patterns. Sequence alignment and similarity score calculation were performed using the Dynamic Time Warping (DTW) algorithm. Let the current real-time feature sequence be X = (x1, x2, ..., x...). m ), where m is the real-time sequence length, and the corresponding user reference sequence in the behavioral benchmark library is Y = (y1, y2, ..., y). n ), where n is the length of the reference sequence, taken from the mean sequence of the user's historical feature sequences; Calculate the DTW distance by finding the optimal regular path through dynamic programming to minimize the alignment error between sequences X and Y. The distance formula is: Where K is the length of the regular path, x k This refers to the k-th element in the current real-time feature sequence, y k This refers to the k-th element of the fingerprint database reference sequence, φ = ||x i -y j ||2 represents the maximum Euclidean distance in the feature dimension, x i Let y be the i-th element in X. j Let S be the j-th element in Y. This distance represents the difference between the two sequences. The smaller the difference, the higher the score. The specific score S is obtained using the inverse mapping. The DTW distance is converted into a similarity score in the range of 0-1. The closer the score is to 1, the higher the consistency between real-time behavior and user's historical behavior. Anomaly detection and secondary verification are triggered. A dynamic threshold for anomaly detection is set. If the real-time similarity score S is continuously lower than the preset threshold for several consecutive sampling periods, the identity is determined to be abnormal, and a multi-factor secondary verification process is immediately triggered.
7. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S3, a tiered authentication decision is executed based on the similarity score, matching processing strategies for different risk levels, specifically as follows: Based on the similarity score output in step S2, a multi-level authentication decision is executed, setting a first risk threshold and a second risk threshold, with the first risk threshold being greater than the second risk threshold. When the similarity score is greater than or equal to the first risk threshold, it is determined to be a normal operation by the user, the current behavior is allowed to be executed, and the feature vector is stored in the behavior baseline library through the incremental learning algorithm. The GMM model weights are updated after a fixed number of executions. When the similarity score is greater than or equal to the second risk threshold but less than the first risk threshold, the multi-factor authentication interface is triggered. Depending on the scenario, SMS verification code or biometric verification is invoked. After the second-level verification is successful, the current operation is marked as a trusted anomaly, and the first risk threshold is dynamically adjusted to τ using a sliding window algorithm. high =μ(t)-1.28σ(t) where μ is the mean of recent scores, σ is the variance, and t refers to the amount of recent behavioral data; When the similarity score is less than the second risk threshold, the sensitive operation is immediately interrupted and a security log containing the abnormal feature D is generated. dtw The system simultaneously pushes alarms to user terminals based on IP address and device fingerprint.
8. The front-end implicit authentication method based on multi-dimensional operational behavior features according to claim 1, characterized in that, In step S3, authentication parameters and calculation modes are dynamically adjusted based on user scenarios to balance authentication security and applicability. Data privacy protection measures are implemented throughout the process, and authentication accuracy is continuously optimized through sample feedback and model iteration mechanisms. Specifically: In terms of environmental adaptation, the first risk threshold is automatically and appropriately lowered in new device / remote login scenarios, and the first risk threshold is automatically and appropriately raised in common device scenarios. Lightweight mode is triggered when low-end devices or high CPU usage occur, the LSTM module is turned off, and the dual-feature DTW comparison is retained. The entire process employs local de-identification computation, encrypted transmission of AES-256 feature vectors, and intercepted samples are reviewed and fed back into the training set through federated learning. The model parameters are iterated every quarter to optimize the anomaly detection rate.
9. A front-end implicit authentication system based on multi-dimensional operational behavior features for executing the front-end implicit authentication method based on multi-dimensional operational behavior features as described in any one of claims 1-8, characterized in that, include: The multi-dimensional behavioral feature modeling module is used for multi-dimensional behavioral feature collection and modeling. This includes real-time collection of various behavioral features during user operations through standard interfaces that can be called from the front end; preprocessing the collected raw feature data to eliminate data interference and unify the data format; assigning weights to each feature based on feature discriminability to enhance the impact of high-discrimination features on authentication results; and using a probabilistic model to train the processed feature data to build a user-specific behavioral benchmark library to provide a reference for subsequent identity verification. The real-time behavior consistency verification module is used to perform real-time behavior consistency verification. This includes collecting real-time user operation data at a preset frequency and converting it into feature vectors, analyzing the behavior patterns of the feature vectors through a time series model, calculating the similarity between the real-time feature sequence and the reference sequence in the behavior benchmark library using a sequence alignment algorithm, generating a quantitative similarity score, setting anomaly judgment conditions, and triggering a secondary verification mechanism if the real-time similarity meets the anomaly conditions. The authentication decision and dynamic response module is used for authentication decision and dynamic response mechanisms, including executing hierarchical authentication decisions based on similarity scores, matching processing strategies for different risk levels, dynamically adjusting authentication parameters and calculation modes in combination with user scenarios, balancing authentication security and applicability, adopting data privacy protection measures throughout the process, and continuously optimizing authentication accuracy through sample feedback and model iteration mechanisms.
10. A computer-readable storage medium storing computer code, wherein when the computer code is executed, the method of any one of claims 1 to 8 is performed.