Terminal ai confidence progressive identity authentication and dynamic permission management method
By leveraging multimodal sensor data acquisition and deep learning through AI cognitive models, a dynamic permission management system is constructed. This solves the problems of discreteness and static nature in mobile terminal identity authentication, enabling seamless continuous authentication and personalized permission management, thereby improving the security and convenience of mobile terminals.
Patent Information
- Application Number
- CN202610395033.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-29
- Publication Date
- 2026-06-23
Smart Images

Figure CN122268635A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of mobile terminal identity authentication and access control technology, specifically involving a continuous identity verification and dynamic permission management method based on an AI cognitive model, applicable to smartphones, wearable devices, portable smart terminals, home robots, and IoT terminal devices.
[0002] In particular, this invention relates to a hierarchical identity verification mechanism that "cultivates" a comprehensive understanding of the user through an AI deep learning model. Unlike traditional biometric technologies that rely on a fixed template-based "signal-feature-comparison" authentication logic, this invention employs a "data feeding-AI learning-habit formation-cognitive judgment" approach. It utilizes multi-dimensional data continuously collected by various sensors, including grip pressure, touch habits, gait characteristics, vital signs (heart rate, skin conductance, body temperature), and environmental context. This data is not used as an instant "password" for comparison, but rather as "training material" for the AI model. Through continuous interaction, the system grows alongside the user, allowing the system's weight matrix to become "familiar" with the user's behavioral rhythms, physiological baseline, and vital state, forming a dynamically evolving user-friendly architecture. The system employs a user characteristic probability distribution model and a cognitive model. Based on this cognitive model, it makes a comprehensive judgment on real-time input signals regarding "recognition," "familiarity," and "normality." It constructs a dynamic identity confidence assessment system with an N-level (N is a positive integer greater than or equal to 2, such as 100 levels) confidence score spectrum as its core. This achieves a paradigm shift from traditional "discrete absolute authentication (either 0 or 1)" to "intelligent hierarchical authentication (progressive opening)." The system dynamically adjusts the device function opening level according to the degree of identity confidence, ultimately forming a human-machine symbiotic security protection system where "devices grant permissions level by level according to confidence scores, and security decisions are made locally autonomously." Background Technology
[0003] As the value of personal privacy and assets carried by mobile devices increases, identity authentication and access control technologies have become core to the security of smartphones, wearable devices, and other terminals. Current mainstream technologies are evolving along the following paths: (1) Static Biometric Single-Time Authentication Technology Existing mobile terminals widely adopt biometric authentication methods such as passwords, fingerprints, and facial recognition. This type of technology is based on a "single-point trigger" mechanism, which performs identity verification only once before unlocking the device or performing specific sensitive operations. Once the verification is successful, all or most functional permissions are granted. However, this type of solution has fundamental defects: First, the authentication is discrete, and it is impossible to continuously monitor changes in the holder after unlocking, which makes the device vulnerable to unauthorized use when it is unattended or seized; Second, biometrics are easily coerced (such as being forced to perform facial recognition or fingerprint pressing), and existing systems lack the ability to perceive the user's physiological state (awake / unconscious / coerced), and cannot automatically restrict permissions in abnormal states; Third, highly sensitive operations (such as payment and data deletion) require frequent secondary verification, which affects the user experience; Fourth, if the phone is lost, it is easy for professionals to unlock it, resulting in a huge risk of loss.
[0004] (2) Simple recognition technology based on behavioral biometrics In recent years, the industry has proposed using behavioral data such as grip posture, touch dynamics (touch screen pressure, swipe trajectory), and motion sensors (accelerometer, gyroscope) for user identification. Although such technologies can achieve "unobtrusive" recognition, existing solutions mostly rely on sensor modalities (such as only through grip pressure or only through gesture trajectory), resulting in a high false recognition rate (FAR) and false rejection rate (FRR), making it difficult to meet financial-grade security standards. More importantly, existing behavioral recognition focuses on the comparison of short-term behavioral patterns (such as single touch features), lacking deep learning and modeling of users' long-term living habits and circadian rhythms (day and night usage patterns, grip stability baseline), and cannot form a "behavioral fingerprint" that evolves over time, nor can it identify the essential difference between "habit drift" and "abnormal state".
[0005] (3) Context-Aware Dynamic Access Control Technology Some enterprise-level systems or web applications have introduced dynamic access control mechanisms based on roles, geolocation, and network environment (such as dynamic authorization under a zero-trust architecture). However, such technologies mainly rely on external context policies (such as IP address and device ID) rather than a deep understanding of the device holder's internal physiological state (heart rate, skin conductance, body temperature) and emotional state (anxiety, focus, fatigue). Existing solutions cannot identify coercive scenarios where "the person is controlled but the password is correct," nor can they automatically restrict high-risk operations when the user's consciousness is impaired (intoxicated, unconscious, extremely fatigued). In addition, existing dynamic access control mostly adopts a coarse-grained "all or nothing" control, lacking a layered opening mechanism that refines according to trust levels.
[0006] (4) Fundamental limitations of security architecture The above technologies share the following systemic defects: First, the human-machine relationship remains at the level of "tool-user" internal isolation. As a passive response tool, the device does not have the inherent ability to make multiple real-time judgments and take active protection. Second, there is a lack of active identification of the device owner. Existing technologies mainly rely on fixed template comparison or external context strategies, which cannot establish a strong binding relationship between the device and the owner. This may result in the device becoming a carrier of "information exposure" after it is separated from its owner (lost or stolen). Third, the permission management is static and solidified, and a progressive trust mechanism of "the more familiar, the more open; the more unfamiliar, the more restricted" has not been formed, making it difficult to balance security and convenience. Fourth, there is a lack of coercion protection mechanism. Existing technologies can hardly identify the coercion state directly through multimodal physiological signals (heart rate variability, skin conductance response, microtremor), and cannot trigger the defense strategy of "pretending to be open but actually protecting".
[0007] Therefore, there is an urgent need for a new security mechanism based on a human-machine symbiotic architecture, which can upgrade mobile terminals from "passive tools" to "intelligent entities with "life perception" and "autonomous protection" capabilities. Summary of the Invention
[0008] 1. Purpose of the invention To address the shortcomings of existing technologies such as discrete identity authentication, static access control, and tool-based human-machine relationship management, this invention aims to construct an AI-based cognitive model-driven owner trust scoring system, enabling smart devices to evolve from "unfamiliar hardware" to "intelligent owners-connected entities." Through deep learning and internalization of long-term owner behavior data by AI, a comprehensive "familiarity" is formed between the device and the owner, rather than simple feature template comparison. This establishes a progressive trust relationship where "the more familiar, the more open; the more unfamiliar, the more restricted."
[0009] The specific technical objectives are as follows: (1) Establish an online incremental learning mechanism for AI endogenous confidence scoring By continuously collecting data from multimodal sensors as training material for AI models, the system learns through long-term interactive interaction. The weight matrix becomes "familiar" with the user's behavioral rhythms, physiological baseline, operating habits, and life status, forming a dynamically evolving user characteristic probability distribution model cognitive model, which replaces the traditional fixed biometric template.
[0010] (2) Implement progressive access control based on confidence score levels Construct a multi-level spectral permission system (such as an N-level confidence score spectrum, N≥2) that differs from the traditional binary (unlock / lock) authentication. The degree of permission openness is linked in real time to the device's "confidence score" of the owner, realizing a seamless and gradual opening from "strangers can only see time and weather" to "acquaintances can perform daily operations" to "deep trust can pay for privacy".
[0011] (3) Construct a mechanism for seamless continuous authentication and state awareness fusion Without requiring explicit user action (entering a password / pressing a fingerprint), AI continuously assesses "whether the user is the owner" and "the owner's current state (awake / fatigued / unconscious / coerced)" through comprehensive cognitive judgment of real-time input signals, achieving lifelong continuous identity verification rather than single discrete verification.
[0012] (4) Establish an intelligent protection mechanism to prevent coercion and fraud. When AI detects that the user is under duress (abnormal physiological indicators + sudden change in behavior patterns) or facing major risk decisions (transfer of huge assets, deletion of core data), it triggers protective restrictions or repeated verification mechanisms (such as random historical process reconciliation, specific gesture confirmation). If it determines that the user is in an abnormal state, it implements a defense strategy of "pretending to be open but actually protecting" or "mandatory confirmation of key operations".
[0013] (5) Construct a local autonomous security decision-making system All AI cognitive models, behavioral data, and confidence scores are completed locally on the device, without needing to be uploaded to the cloud or rely on third-party verification. This achieves absolute privacy protection that is usable offline, ensuring the independence and security of the "external electronic body."
[0014] (6) Establish a habit drift adaptation and anomaly recognition mechanism AI can distinguish between the essential differences between the owner's normal habit evolution (such as changes in grip after injury or seasonal adjustments to daily routines) and abnormal intrusions (imitation by others or use after theft). By continuously learning and updating its cognitive model, AI can avoid extreme situations such as "being locked out when habits change" or "being identified as the owner even after theft".
[0015] 2. Technical Solution 2.1 System Overall Architecture This invention constructs a bidirectional nested human-machine symbiotic cognitive system, whose architecture establishes a closed-loop cognitive ecosystem of "experience feeding - cognitive development - confidence scoring and judgment - interactive verification - co-growth".
[0016] The specific process is divided into core levels: (1) Sensory Experience Layer – Experience Acquisition System Not just a simple signal collector, but the "source of sensory experience" as an AI cognitive subject. Through multi-modal sensors (touch, pressure, acceleration, heart rate, galvanic skin response, ambient light, etc.), it continuously collects the owner's behavior trajectories, physiological rhythms, and environmental interaction patterns, forming the original "life experience data stream". These data are not used as password credentials for immediate comparison, but as "memory materials" to feed the AI cognitive model, and through long-term accumulation, form the digital life trajectory of the owner.
[0017] (2)Cognitive Familiarity Layer - AI Confidence Score Cultivation Engine The core intelligent agent of the system, built based on an edge AI large model or a deep neural network, with "cognitive subjectivity": • Habit Internalization Module: Through long-term interactive learning, internalize the behavior patterns, physiological baselines, and operation preferences input from the perception layer into the owner's cognitive profile (Owner Cognitive Profile, OCP), rather than storing them as fixed feature templates; • Event Memory Module: Record the key historical events shared with the owner, including important locations, high-frequency operation sequences, and special time markers, forming a shared memory bank as the basis for "reconciliation" during high-confidence verification; • State Understanding Module: Based on the deviation analysis between the current input and historical cognition, judge whether the owner is "normal", such as awake / tired / abnormal, rather than simply "matching"; • Adversarial Defense Module: Configured with an adversarial sample detection mechanism, by analyzing the signal timing consistency and physiological logic rationality (such as the physiological coupling relationship between heart rate and step frequency), identify and reject the injection of forged sensor data.
[0018] (3)Progressive Trust Layer - Hierarchical Permission Open System Perform permission adjudication based on the confidence score index (Familiarity Index, FI) output by the cognitive layer: • Spectral Permission Mapping: Map the abstract cognitive confidence score to an N-level permission spectrum (N≥2, such as 100 levels in the embodiment), set thresholds T1, T2, T3 (T1<T2<T3<N), and divide different trust intervals; • Dynamic Threshold Adjustment: Adjust the confidence score threshold in real time according to the scene risk (environmental safety, operation sensitivity), and implement a flexible security policy of "different permissions for the same person in different scenarios"; • Protective downgrade mechanism: When an abnormal state of the account holder is detected (coerced, confused) or when facing high-risk operations (large transfers, data deletion), the "memory verification" (reconciliation of historical events) or "interactive verification" (confirmation of specific operation sequences) is actively triggered to achieve "disguised openness but actual protection".
[0019] (4) Interaction Layer (Mutual Embedding Layer) – Two-way cognitive verification interface The technological vehicle for achieving "interaction as verification": • Behavioral feedback verification: The way the user operates the device (changes in grip strength, swiping rhythm, click preferences) is itself part of the identity verification. The system verifies this in real time through "operation style recognition". • Virtual Permission Interface: Under duress, a simulated normal operating interface (such as a fake payment success page) is presented through sandbox isolation technology. The backend actually intercepts sensitive API calls and triggers silent alarms to ensure the security of the account holder and the preservation of evidence.
[0020] (5) Co-evolution Layer – Continuous Learning and Update System Ensuring the technological realization of "mutual growth": • Online incremental learning: The AI model supports continuous training on the device side, and its understanding of the user is continuously refined as the interaction deepens, achieving "the more you use it, the better it understands you"; it is equipped with a confidence gating mechanism, and the model is only updated when the input data matches the existing cognitive model with a higher than preset threshold (such as matching more than 50% of the strongly correlated feature set); abnormal data triggers alarms rather than learning, to prevent malicious data pollution; • Habit drift adaptation: Distinguish between "normal habit evolution" (such as changes in grip after injury) and "abnormal intrusion attempts", and adaptively update the cognitive model through time window analysis to avoid "unchanging" or "frequent changes"; • Memory solidification mechanism: Solidify key verification events (such as the historical moment of successful reconciliation) into "anchor memory" for rapid identity verification in future high-security scenarios; • Cross-device migration: The strongly associated feature set supports encrypted export and migration. After the owner is authenticated on a new device, the historical strongly associated feature set can be imported as the initial cognitive basis, shortening the new device learning period.
[0021] System data flow characteristics: Unlike the instantaneous "input-comparison-output" data flow of traditional biometric systems, this system forms a cyclical data ecosystem of "continuous feeding-gradual cognition-hierarchical feedback-bidirectional calibration". Through long-term interaction, the device and the owner form a "mutually nested cognitive loop": the more familiar the device is with the owner, the more permissions it grants; through the machine's continuous learning of human habits, a symbiotic and secure state of "human-machine integration" is ultimately achieved.
[0022] 2.2 Collection of Multimodal Experience Data and Local Cognitive Feeding (1) Perception and acquisition of experience data: The intelligent device continuously perceives the interaction process between the host and the device through its built-in sensor array, the sensor array including: • Touch and grip sensing unit: Collects contact area, pressure distribution, sliding trajectory and grip posture when the main operation touch screen is used; • Motion sensing unit: Collects acceleration, angular velocity, and spatial attitude changes of the device during random main movement; • Physiological sensing unit: Collects physiological signals from the body surface (such as heart rate and skin conductance) when the user comes into contact with the device. • Environmental sensing unit: Collects information on the lighting, sound, location, and network environment characteristics of the environment in which the device is located.
[0023] The data acquisition process is a continuous, low-power acquisition method. In standby mode, the device monitors the environment at a first frequency (e.g., several times per minute) to familiarize itself with the user's static habits. When user control or operation is detected, the device switches to a second frequency (e.g., several times per second) for detailed behavioral data acquisition. For periodic movements, such as walking, running, and cycling, the first frequency is used to collect and monitor the user's habits during periodic changes, and the device can be woken up to switch to the second frequency when the periodicity changes.
[0024] (2) Local Accumulation and Privacy Protection of Experience Data: The raw perception data collected is preprocessed locally and then stored in encrypted form in the device's secure partition. The preprocessing includes: • Remove noisy data that is irrelevant to identity recognition; • Align multi-source heterogeneous data according to timestamps to form empirical data units; • Desensitize sensitive physiological data; • Duplicate data is consolidated into core data.
[0025] Key feature: All experience data is used only for training local AI models and is not uploaded to cloud servers, ensuring the local privacy of the device owner.
[0026] (3) Structured Recording of Association Habits: The system identifies and records the multimodal association habits of the host by analyzing the temporal associations in the empirical data units, including: • Performance-physiological association: Physiological response patterns (heart rate changes) that accompany specific performance (such as answering the phone). • Scenario-behavior correlation: Differences in operating habits under specific environments (such as noisy environments or mobile states); • Time-event association: Behavioral response patterns to specific time events (such as alarm clocks or incoming calls); • Social context association: Changes in usage habits when the presence of others is detected (via front-facing camera or audio analysis).
[0027] The associated habits are stored in the cognitive module in the form of structured data, serving as the basis for subsequent confidence scoring.
[0028] 2.3 Construction of AI Confidence Scoring Cognitive Model and Hierarchical Permission Decision-Making Method 2.3.1 Multi-level signal abstraction and correlation feature extraction mechanism The cognitive module is configured to perform hierarchical abstraction processing on the multimodal signals input from the perception layer to construct a cognitive model relating the host's behavior, physiology, and environment, rather than directly comparing the original sensor values. Level 1 signal (surface signal layer): Directly acquired raw sensor values, including but not limited to discrete time-series data such as touch pressure values, acceleration vectors, heart rate readings, and ambient light intensity; Secondary signal (association feature layer): The cognitive module extracts cross-modal signal association features through temporal alignment and association mining algorithms, including: • Timing co-occurrence correlation: Synchronous response patterns of multi-sensor signals when a specific operational event (such as unlocking action) occurs (e.g., the time-lag correlation between grip pressure and heart rate changes). • Scene-behavior coupling: The association pattern between specific environmental contexts (such as movement state, noisy environment) and operating habits (such as one-handed / two-handed grip, swiping speed); • Physiological-operational mapping: The correspondence between physiological states (such as heart rate zones) and operational intensity (such as click frequency and pressure); Level 3 Signal (Rate of Change Feature Layer): To improve cognitive efficiency and reduce computational power consumption, the cognitive module further extracts dynamic change features of the signal, including: • First-order rate of change: The first derivative (rate of change) of each sensor signal over time, used to identify sudden behavioral changes; • Second-order rate of change (acceleration of change): The rate of change of the signal rate of change, used to identify emergency transitions in the host's state (such as a sudden physiological change from calm to stress). The cognitive module preferentially makes confidence score judgments based on secondary association features and tertiary change rate features, and only reverts to the primary raw signals when the association features are ambiguous, so as to achieve high-performance cognitive computing.
[0029] 2.3.2 Lifelong Dynamic Confidence Score Online Incremental Learning Mechanism The cognitive module is configured in a continuous lifelong learning mode, forming a symbiotic relationship of dynamic following with the device owner: Initial Cultivation Stage: In the initial stage of device activation, the traditional password verification mechanism is continued as the security baseline; at the same time, data collection is started in the background to accumulate multi-level signal features of the device owner, but it does not participate in permission decisions; Progressive Transition Stage: When the set of strongly associated features extracted by the cognitive module reaches the preset quantity M (M is a positive integer, such as 100), and the confidence level is stable, the system gradually reduces the password verification frequency and transitions to a touchless authentication mode mainly based on AI confidence score recognition; Lifelong Following Stage: The cognitive module continuously receives new behavioral data, updates the cognitive profile of the device owner through online incremental learning, so that the confidence score assessment accompanies the device throughout its life, dynamically adapting to the behavioral evolution of the device owner (such as age growth, habit change), rather than relying on a fixed template.
[0030] Management of the Set of Strongly Associated Features: The cognitive module dynamically screens and maintains M core associated features (M is a preset positive integer, such as 100) from a large number of repeated events, as the main basis for confidence score assessment; the set of strongly associated features is dynamically adjusted according to usage habits (old features are forgotten, new features are added), ensuring the timeliness and accuracy of the cognitive model.
[0031] 2.3.3 N-level Confidence Score Spectrum and Four-Situation Permission Model The decision-making module is configured to quantify the confidence score into an N-level confidence score spectrum (N is a positive integer greater than or equal to 2, such as 100 levels in the embodiment), and set thresholds T1, T2, T3 (T1 < T2 < T3 < N), to construct a four-situation permission model: Confidence Score Grading (0 - N levels): • 0 - T1 level: Preliminary Cognition (corresponding to others using, such as 0 - 20 levels); • T1 - T2 level: General Familiarity (corresponding to acquaintances, abnormal states of the device owner, such as 21 - 60 levels); • T2 - T3 level: Deep Familiarity (corresponding to the normal state of the device owner, such as 61 - 90 levels); • T3 - N level: Core Symbiosis (long-term stable matching, such as 90 - 100 levels); The four-situation permission model: The decision-making module divides the permission subject into internal and external dimensions (user's own / others) and status dimensions (normal / abnormal), forming four decision scenarios: Context Access Control Policy Confidence rating mapping illustrate Internal - Normal (Owner is conscious and autonomous) High-level access T2-N level Most functions are available; only high-risk operations such as large payments and data deletion require secondary confirmation. Internal abnormality (abnormal status of the host / being under duress / being unconscious / losing control) Restricting access + reconciliation verification Forced suppression to T1-T2 level or below Triggering historical event reconciliation verification will reduce permissions to basic functions, and a virtual permission interface will be displayed when necessary (pretending to be open but actually protecting). External - Normal (Used normally by others) Classification restrictions T1-T2 level or below Based on the level of intimacy with the user (close relationship / family / friend / acquaintance / stranger), users are mapped to different sub-regions, and limited functions are unlocked tier by tier. External - Abnormalities (coercion / threat from others) Hidden alarm + access lock 0-T1 level or virtual interface Triggering a silent alarm mechanism and displaying a fake interface, core functions are physically isolated. Critical State Veto Power: The cognitive module is set to monitor key physiological indicators (such as facial recognition consistency and heart rate variability). When a specific veto signal is detected (such as abnormal heart rate + facial micro-expression coercion features), regardless of how high the current confidence score index is, permission downgrade or virtual permission mode will be triggered immediately to ensure the safety of the owner in a state of loss of control.
[0032] 2.3.4 Rate of Change Sensing and Emergency Permission Adjustment The decision-making module is configured to make security decisions not only based on the current confidence score level, but also on the rate of change of the confidence score. Gradual adaptation mechanism: When individual sensors or associated features drift slowly (such as when the user's hand is injured and the grip changes), as long as the current level remains above the threshold (such as T2 level), the system allows for gradual model updates and does not immediately adjust permissions to avoid accidental locking. Sudden Change Protection Mechanism: When the confidence score level is detected to be decreasing too rapidly (e.g., from T3 or above to below T1), or when an abnormal second-order rate of change signal is received (signal change acceleration exceeds the safety threshold), the decision module immediately triggers emergency permission contraction, regardless of the current absolute level, and quickly downgrades to a safe lockout state to cope with sudden coercion or equipment seizure scenarios.
[0033] The permission adjustment is implemented through multimodal feedback intensity adjustment, corresponding to an N-level confidence score. • External performance permissions (screen brightness, volume, vibration intensity) decrease as the level decreases (e.g., the screen dims and the microphone picks up weaker when the level decreases). • Internal operation permissions (photo viewing, application launch, data access, payment function) are disabled level by level according to the preset mapping table.
[0034] 2.3.5 Anomaly Detection and Reconciliation Verification Mechanism Anomaly Triggering Conditions: The reconciliation verification is triggered when the system detects the following veto-level anomalies: • Multiple consecutive critical verification failures (such as incorrect payment password or facial recognition mismatch); • The matching degree of a strongly correlated feature set suddenly drops (e.g., the number of matches in M core features is less than the threshold). • Abnormalities in key physiological signals (sudden increase in heart rate, intense skin conductance response) conflict with behavioral patterns; Historical reconciliation verification: The cognitive module randomly selects several recent historical events (such as combinations of specific times and locations, or special operation sequences) from the shared memory bank and requires the owner to verify them; if the verification fails or the owner cannot provide a reasonable explanation, it is determined to be an abnormal owner state, and protective reduction of privileges or virtual privilege mode is initiated.
[0035] 2.3.6 AI Learning and Dynamic Configuration of Personalized Permission Opening Policies The cognitive module not only identifies "whether the user is the owner", but also learns the owner's privacy preferences, personality and social openness habits. Based on historical authorization behavior, it learns to evolve access control from "unified security policy" to personalized protection "a thousand faces for a thousand people".
[0036] (1) AI modeling of the owner's privacy preferences The cognitive module constructs a privacy openness profile of the device owner through long-term observation, which serves as a personalized coefficient for permission decisions. • Behavioral observation layer: Records the owner's history of proactive authorization behavior, such as the frequency with which the owner proactively hands over the phone to others to view content (high frequency = open type, low frequency = conservative type), whether the owner frequently intervenes when others are viewing the content, and the differences in the duration and scope of authorization granted by the owner to different social distance objects (family / friends / colleagues). • Post-event feedback layer: When the permissions granted by AI do not match the user's expectations, the user provides negative feedback through natural language interaction (such as "This should not be shown to him") or immediate intervention (such as quickly taking back the phone or switching interfaces). The cognitive module marks this event as a mistakenly granted permission sample, strengthening the permission restrictions in this scenario. Conversely, if the user does not intervene in others browsing specific content, it is marked as a positive sample, and the permission threshold in this scenario is appropriately relaxed. • Active Declaration Layer: The user can directly inform the system of special rules through explicit instructions, such as "photo permissions cannot be granted to Zhang San" or "work documents are only visible to me". The cognitive module will embed such instructions as hard rules into the permission decision tree, taking precedence over AI inference.
[0037] Based on the above learning, the system generates a unique permission access baseline for each machine owner.
[0038] (2) Prerequisites for owner presence perception and access authorization The system sets "user owner present" as a necessary but not sufficient condition for granting permissions: • When the system recognizes that the owner is currently holding the device (high confidence score index, such as >T3 level) and detects that another person is in the near field (identified by the front camera or audio), the decision module enters the "owner display mode"; • In this mode, the system automatically determines the scope of content that can be shown to others present based on the aforementioned privacy openness profile, without requiring the device owner to manually set "guest mode"; • Owner Retrieval Detection: If the owner hands the device over to another person (abnormal grip characteristics + disappearance of the owner's biological signal), the system will automatically revoke the access privileges and revert to the other person's inherent level (the corresponding level in the external-normal situation), and will prevent the default inheritance of the owner's high privileges.
[0039] (3) Cross-grading of content sensitivity and operational depth The system implements operational dimension segmentation for the same type of data (such as photos), rather than a simple "allow / prohibit" binary control: • Display-level permissions: Only allow viewing of a single image or a few specific images currently displayed by the device owner; scrolling is prohibited. • Browse-level permissions: Allows limited scrolling within the current album (such as the first 10 photos or content from the last 3 days), but prohibits searching, deleting, and sharing; • Deep-level permissions: Allows viewing of private photo albums, historical cache, and metadata information (shooting location, time), limited to the device owner only (within normal circumstances and requiring secondary confirmation); AI Learning Example: The system observes that the owner usually only allows others to view the current single photo (and quickly puts the phone away after displaying it), so the AI learns that the owner's default policy for "photo viewing" is display level; if the owner has explicitly stated "allow Mom to view all travel photos", then for the specific object "Mom", the AI learns browsing level permission, but is still restricted to the travel album tab.
[0040] (4) Automatic mapping between social relationship graph and permissions The cognitive module constructs a social relationship graph of the host, mapping interpersonal relationships in the physical world to digital permission levels: • Relationship identification: By using the owner's address book tags, call frequency, and historical sharing records, combined with the owner's active naming (such as "This is Li Si, my brother"), relationship intimacy tags (close / family / friend / acquaintance / stranger) are established. • Personalized access control: The same content can be presented with different access permissions to different stakeholders; • Exception rules: The owner can set negative rules for specific individuals. The system will bind the rule to the relationship graph and automatically trigger permission lockout or hide specific content.
[0041] (5) Security isolation of cryptographic operations The system sets hard boundaries: the system has a pre-set sensitive operation tag library, including payment API calls, password modification instructions, data deletion commands, etc.; when such instructions are detected, operations involving asset transfer, identity change, and core privacy settings will be required to require the owner to actively perform explicit authentication (password / specific biometrics / historical reconciliation) regardless of how high the AI's confidence score index is, and will prohibit unobtrusive access based on AI confidence scores.
[0042] Such operations are not included in the scope of AI openness learning, ensuring that even if the owner is extremely open in daily life, the core security bottom line is still protected by physical level; in internal abnormal situations (coercion), such operations, in addition to requiring explicit authentication, will trigger reconciliation verification and delayed execution mechanisms (such as large transfers being delayed by 10 minutes to give the owner a window to react). Attached Figure Description Figure 1 This is a diagram of a closed-loop cognitive ecosystem architecture based on experience-based feeding, cognitive development, familiarity assessment, interactive verification, and co-growth. Figure 2 This is a schematic diagram of the overall architecture of a smart terminal security system based on a human-machine symbiotic architecture. Figure 3 A flowchart illustrating the multi-level signal abstraction and development process for AI familiarity and cognitive models. Figure 4 This is a schematic diagram illustrating the mapping relationship between the N-level familiarity spectrum and the four-part contextual permission model. Figure 5 This is a flowchart of the method for dynamically adjusting permissions in a specific embodiment. Figure 6 This is a schematic diagram of the virtual permission interface and protection mechanism under duress. Detailed Implementation
[0043] The following embodiments are used to illustrate the specific implementation of the AI confidence scoring-based smart terminal security method described in this invention in practical applications, but should not be construed as limiting the scope of protection of this invention. All embodiments are based on the aforementioned N-level confidence scoring spectrum (taking N=100 as an example), M strongly correlated feature sets (M=100 as an example), a four-part contextual permission model, and a lifetime follow-up mechanism.
[0044] Example 1: Initial setup and gradual transition of new devices (from password to contactless authentication) Scenario: User A is using a smartphone with this system for the first time.
[0045] Incubation period (days 1-7): • The system is in its initial development phase, requiring user A to enter a password or perform fingerprint verification each time they unlock the device, as a security baseline; • The background cognitive module continuously collects multimodal data from user A: grip pressure distribution, touch swipe trajectory characteristics, and heart rate change patterns before answering a call; • Through association mining, the system identifies strong correlation features: When user A is in a home Wi-Fi environment (environmental signal) between 7:00 and 8:00 in the morning, holding the phone with one hand and with light grip pressure (behavioral signal), and at the same time, the heart rate is at the morning baseline (physiological signal), the four factors form the first strong correlation feature and are stored in the feature set.
[0046] Transition period (days 8-30): • When the strongly correlated feature set accumulates to 60 items (i.e. 60% of M) and the confidence level is stable (matching error <5% for 7 consecutive days), the system begins to gradually reduce the password verification frequency. • When User A picks up his phone in his home environment in the morning, the system matches the current sensor data with a strongly correlated feature set and generates a current confidence score index of 78 (in the example system with N=100, it is in the T2-T3 range). • The decision module determines that it is an internal-normal situation and automatically opens the high-privilege mode (access to the desktop is possible without a password, but payment still requires secondary confirmation). • If user A hands over their phone to someone else (family member) for use in a home environment, the system detects a change in the grip pressure distribution and a mismatch in the heart rate baseline. The confidence score index drops sharply to level 12 (external-normal situation), and the system automatically restricts access to family members (they can only view the weather and time, but cannot open WeChat).
[0047] Follow for life: • Starting from day 31, the system enters the lifelong follow-up phase. User A's behavioral evolution is continuously learned. The 100th strongly correlated feature is updated to "specific pressure distribution when holding the device while lying on your side before sleep + screen tilt angle". Old, less frequently used features are gradually forgotten, ensuring that the cognitive model dynamically follows the user's changes.
[0048] Example 2: Spectrum-based access control for everyday use (N levels correspond to N different experiences) Scenario: User B is using a mobile phone that they are already very "familiar" with (current confidence score level 85, N=100 system).
[0049] Gradual opening of permissions: • Upon waking up in the morning (confidence score 85): User B picks up the phone, and the screen immediately displays at 100% brightness (corresponding to a high level of external performance permissions). • Subway commuting (noisy environment + moving state): The system detects acceleration signals (movement) and audio signals (noisy), matching the strong correlation characteristics of "commuting scenario", maintaining a confidence score of 82, but automatically reducing the screen brightness to 70%; • Handing over photos to a colleague in the office (external-normal scenario): User B hands his phone to colleague C. The system detects that the face is not the owner's through the front camera. At the same time, the pressure distribution of the hand holding the phone changes abruptly, and the confidence score index drops to level 5 instantly (which belongs to the familiar sub-interval of the 0-T1 level in the N=100 system). • Automatic permission reduction: The screen immediately dims to 40%, the volume decreases, and the WeChat and bank app icons become grayed out and unclickable (internal operation permissions are turned off), but the photo album is opened in read-only mode, realizing fine-grained control of N-level permission corresponding to N-level adjustment strategies.
[0050] Example 3: Smart protection under duress (veto power and virtual interface) Scenario: User D is coerced into transferring money.
[0051] Coercion identification: • User D was coerced into picking up the phone and was forced to undergo facial recognition (which was successful). • However, the system's critical status monitoring module detected a rejection-level anomaly: o Second-order rate of change abnormality: Heart rate suddenly increases from 65 bpm at rest to 110 bpm within 5 seconds (acceleration exceeds the safe threshold). o Behavioral-physiological conflict: Facial recognition passes, but grip pressure exhibits an abnormally rigid pattern; o Sudden drop in strong correlation features: Only 23 out of M core features match (a sudden drop exceeding the threshold).
[0052] Veto power triggered: • Even though facial recognition passes, the system’s key physiological indicators take effect, classifying it as an internal-abnormal situation, and the confidence score index is forcibly suppressed to level 35 (in the N=100 system, it is reduced to the T1-T2 level range). • Virtual Permission Interface: The screen displays a fake normal transfer interface (implemented through sandbox isolation technology, with the front end displaying a simulated page and the back end intercepting APIs), but all payment requests are actually intercepted, and a silent alarm is triggered in the background; • Reconciliation verification triggered: The system pops up a historical event query: "Did you go to Xishuangbanna last December?" (extracting key events from the shared memory). User D knows the answer but deliberately answers incorrectly. The system confirms the coercion state and completely locks the payment function.
[0053] Example 4: Protection against strangers after device loss (the cliff from familiar to unfamiliar) Scenario: User E's phone is stolen, and the thief tries to use it.
[0054] Stranger identification: • After picking up the phone, the thief turned on the screen and attempted to swipe. • The system detected that the grip pressure distribution, sliding trajectory speed, and touch force curve all had zero match with user E's M strongly correlated features; • The environmental signal indicates a new location (GPS change) and there is no user E's usual Wi-Fi, so the confidence score remains at level 0 (stranger).
[0055] Permissions locked: • External-Normal Situation (Thief not under duress, but a stranger): The system grants L0 level permissions (only displays time, weather, and emergency calls), all application icons are visible but clicking them has no effect; • Second derivative monitoring: If a thief attempts to force a breakthrough (rapidly and continuously clicking the screen), the system detects an abnormal acceleration in the change of operation frequency (exceeding the limit of the second-order rate of change), and immediately triggers an emergency privilege reduction. Even if individual features are matched by chance later, the system remains locked. • Data protection: Core privacy data is physically isolated (requiring a T3-N level confidence score plus specific historical reconciliation to unlock), and thieves cannot bypass it through regular firmware flashing.
[0056] Example 5: Adaptive learning for habit drift (refamiliarization after injury) Scenario: User F injured their right hand and switched to using their left hand to operate the phone.
[0057] Gradual adaptation: • Day 1: User F holds the phone with their left hand. The system detects that the matching degree between the grip pressure distribution and the historical strong correlation features has dropped to level 55 (in the N=100 system, it is lower than the T2=60 threshold). • Slow-change protection mechanism: Since the confidence score decreases slowly (from 85 to 55 every day, rather than a cliff), and other related features (such as heart rate baseline and touch rhythm) still match, the system judges it as normal habit drift rather than intrusion. • Gradual update: The system allows temporary downgrade to L2 permissions (for daily use), while simultaneously initiating a left-handed habit learning period. Within 3 days, new strong left-handed phone-holding characteristics are collected and replaced with the original right-handed related characteristics (marked as "temporarily invalid" rather than permanently deleted). • Recovery and Integration: After recovering from his injury, User F resumed using his right hand. The system reconstructed cross-handed habit cognition within a week through bimodal recognition (features of both left and right hands coexisting), and the confidence score recovered to above 80.
[0058] Example 6: Hierarchical Permissions for Multiple Users (Intimacy Spectrum) Scenario: User G's family sharing scenario.
[0059] Automatic rating: • Spouse usage: The system identifies specific holding patterns of the spouse through long-term observation, assigns a 20-level confidence score (in the N=100 system, it is in the intimate relationship sub-interval of the 0-T1 level range), and grants higher-level permissions; • Use by children: If the device is identified as being held by a minor, a confidence score of 15 will be assigned, and limited permissions will be granted (only for educational apps; for game apps, a mild restriction of black and white with delayed response will be applied). • Guest borrowing: The first contact with the device is given a level 2 confidence score, only basic permissions (emergency call + calculator) are granted, and the screen continuously dims to indicate that the device is not owned by the user.
[0060] 2.5 Beneficial Effects Compared with the shortcomings of existing technologies such as discrete identity authentication, static access control, and tool-based human-computer interaction, this invention achieves a fundamental paradigm shift from "discrete absolute authentication" to "intelligent hierarchical authentication," from "static access control lists" to "dynamic open access control," and from "passive tool response" to "proactive symbiotic protection" by constructing a confidence scoring system based on an AI cognitive model. The specific beneficial effects are as follows: (1) It achieves truly seamless continuous authentication and eliminates security gaps. Existing technologies employ single-time, discrete authentication methods such as passwords, fingerprints, and facial recognition. Once verified, access is permanently granted, resulting in significant security vulnerabilities. This invention utilizes AI to continuously learn the user's behavioral rhythms and vital signs, forming a lifelong confidence score. This transforms authentication from a "0 / 1 judgment at a specific moment" to a "continuous spectral assessment at every moment." Even when the device is unlocked, the system continuously assesses whether the current user is still a familiar owner. If a sharp drop in confidence score is detected, access is immediately restricted, fundamentally eliminating the security vulnerabilities of traditional authentication.
[0061] (2) A gradual permission opening mechanism has been established to balance security and convenience. Existing technologies employ a binary permission model of "lock or unlock," making it difficult to achieve both security and convenience. This invention, based on an N-level (N≥2) confidence scoring spectrum and a four-part contextual permission model, constructs a progressive trust-building mechanism where "the more familiar the user, the more open they are; the more unfamiliar the user, the more restricted they are." For the device owner, high-privilege access is granted without any explicit operation during daily use; for family, friends, and other acquaintances, the system automatically grants appropriate permissions; for strangers, even if the device is found, they can only view basic information such as time and weather. This spectrum-based permission management significantly improves the smoothness of use in social scenarios while ensuring core security.
[0062] (3) Possesses the ability to identify abnormal states and actively defend against threats, thereby achieving protection against coercion. Existing technologies cannot identify extreme scenarios where the password is correct but the user is being coerced. This invention constructs a critical state veto and coercion identification mechanism through correlation analysis of multimodal physiological signals and behavioral patterns (including second-order rates of change). When the user is detected to be in a coerced state, the system presents a virtual access interface (pretending to be open but actually protecting), while a silent alarm is triggered in the background; when abnormal consciousness of the user is detected, high-risk operations such as payments are automatically restricted. This proactive protection based on vital signs fills the gap in the protection of existing security systems in scenarios of physical coercion.
[0063] (4) It realizes the device's lifelong following of the owner and habit drift adaptation. Existing biometric technologies are based on fixed templates and cannot adapt to the long-term behavioral evolution of the user. This invention utilizes online incremental learning and dynamic updates of strongly correlated feature sets to enable the AI cognitive model to evolve alongside the user throughout their lifespan: on one hand, the system can recognize normal habit drift (such as switching to left-handed holding after injury) and avoid false locking through a gradual adaptation mechanism; on the other hand, it can recognize abnormal intrusion attempts (such as a thief mimicking the holding posture) and immediately lock the device through a sudden change protection mechanism. This dynamic following capability ensures the long-term robustness of the security system.
[0064] (5) A personalized permission policy was developed to enhance the user experience. Existing access control technologies employ a "one-size-fits-all" approach. This invention, however, uses AI to learn the user's privacy profile and social relationship graph, enabling personalized access control policies: for open-minded users, the system defaults to allowing acquaintances to view more content; for conservative users, the system defaults to hiding sensitive information until the user actively authorizes access. This learned personalized configuration transforms the security system from "cold rules" to "understanding your habits."
[0065] (6) Achieved absolute privacy protection and adversarial defense through local autonomy Existing technologies largely rely on cloud-based verification. In this invention, all AI cognitive models, behavioral data, and confidence scores are evaluated locally on the device. Strongly correlated feature sets and shared memory are physically isolated within the device's secure partition, without being uploaded to the cloud or relying on the network. Simultaneously, an adversarial example detection mechanism identifies forged sensor data, and a confidence gating mechanism prevents malicious data from contaminating the model, achieving true security sovereignty belonging to the device owner and inalienable by remote means.
Claims
1. A progressive identity authentication and dynamic permission management method for smart terminals based on an AI cognitive model, characterized in that, Includes the following steps: Continuously collect user-device interaction data through multimodal sensors; The interaction data is learned online incrementally based on the edge AI model to form and continuously update a dynamically evolving user cognitive model. Based on the user cognitive model, the real-time collected data is processed to output a continuous confidence score representing the degree of identity certainty. Based on the confidence score, the device's functional permissions are divided into multiple levels, and a dynamic mapping relationship between the permission opening level and the confidence score is established to achieve progressive permission management that changes with the degree of confidence.
2. The method according to claim 1, characterized in that, The multimodal sensor includes a touch and grip sensing unit, a motion sensing unit, a physiological sensing unit, and an environmental sensing unit. The interactive data includes touch pressure distribution, sliding trajectory, acceleration vector, heart rate, skin conductance response, and environmental context information.
3. The method according to claim 1 or 2, characterized in that, The formation and continuous updating of the dynamically evolving user cognitive model includes: The interactive data is subjected to hierarchical abstraction to extract the first-level signal of the original signal, the second-level correlation features of cross-modal correlation, and the third-level rate of change features that characterize the dynamics of signal changes. A strongly correlated feature set containing M core features is dynamically filtered and maintained from repeated interaction events, which serves as the main basis for the confidence score evaluation, where M is a positive integer; The confidence score evaluation step includes: firstly, calculating based on the secondary correlation features and the tertiary rate of change features; if the confidence score of the calculation result is lower than a preset threshold, then further evaluation is performed in conjunction with the primary signal; Through online incremental learning, the user cognitive model and the strongly correlated feature set are continuously updated based on new interaction data to achieve lifelong tracking of user behavior evolution.
4. The method according to claim 3, characterized in that, The three-level rate of change feature includes the first-order rate of change and the second-order rate of change of the signal. The second-order rate of change is used to identify emergency transitions in the host status. When the second-order rate of change of the familiarity index exceeds the safety threshold, an emergency permission contraction is immediately triggered.
5. The method according to claim 1, characterized in that, The four-situation permission model divides the permission subject into internal and external dimensions and state dimensions, forming four decision scenarios: internal-normal, internal-abnormal, external-normal, and external-abnormal. These correspond to four permission strategies: high-level permission opening, restricted permission and reconciliation verification, hierarchical restriction, and hidden alarm and permission deadlock.
6. The method according to claim 5, characterized in that, The real-time adjustment of device function access levels based on the four-part contextual permission model includes: Configure a high-privilege access policy for the aforementioned internal-normal scenario; Configure access restrictions and trigger verification strategies for the aforementioned internal-abnormal scenarios; Configure a strategy for classifying and restricting access based on the level of intimacy with the device owner for the aforementioned external-normal scenario; Configure a strategy for locking permissions or triggering a virtual permission interface for the aforementioned external-abnormal scenarios.
7. The method according to claim 5 or 6, characterized in that, It also includes a critical status veto mechanism: when a critical physiological indicator is detected to be abnormal or a behavior-physiological conflict is detected, regardless of the current familiarity index range, permission downgrade or virtual permission mode will be triggered immediately to ensure the safety of the owner in a state of loss of control.
8. The method according to claim 5 or 6, characterized in that, The real-time adjustment of device function access levels includes differentiated control of function permissions: Adjust the intensity of the external feedback output of the equipment; Enable or disable tiered access to applications and data; When a change in the entity using the device is detected, the permissions are automatically switched to the level corresponding to the new entity.
9. The method according to claim 1, characterized in that, It also includes AI learning of personalized permission strategies: by observing the user's proactive authorization behavior, post-event feedback and explicit instructions over a long period of time, a privacy openness profile and social relationship graph of the user are constructed to achieve automatic mapping of differentiated permissions for the same content to different people with different relationships.
10. The method according to claim 9, characterized in that, The social relationship graph maps physical interpersonal relationships to digital permission levels. The owner can set negative rules for specific individuals. When the biometric characteristics of that specific individual are detected, the permissions will be automatically locked or specific content will be hidden.
11. The method according to claim 1 or 5, characterized in that, It also includes an anti-coercion protection mechanism: when the owner is detected to be in a coerced state, a simulated normal operation interface is presented through sandbox isolation technology, while the background actually intercepts sensitive API calls and triggers a silent alarm, and at the same time pops up a historical event reconciliation verification request for the owner to confirm.
12. The method according to claim 1 or 3, characterized in that, The strongly associated feature set supports encrypted export and migration. After the owner is authenticated on a new device, the historical strongly associated feature set can be imported as the initial cognitive basis, shortening the new device adoption period.
13. A progressive identity authentication and dynamic access control system for intelligent terminals based on an AI cognitive model, characterized in that, include: The perception layer is configured to continuously collect interaction data between the host and the device through multimodal sensors; The cognitive layer is configured to learn the interaction data over a long period of time based on the edge AI model, endogenously construct the owner's digital twin cognitive model, and form a familiarity index; The decision-making layer is configured to divide the N-level permission spectrum based on the familiarity index, establish a four-situation permission model, and adjust the device function opening level in real time. The system is configured to perform the method according to any one of claims 1 to 12.