An authentication method and device
By monitoring users' operations in target applications, extracting behavioral characteristics and classifying them, the problem of identity verification in the prior art requires users to operate additionally, and an unconscious and efficient authentication method is realized.
Patent Information
- Application Number
- CN202011553085.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-24
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-12-24
AI Technical Summary
In the prior art, the terminal's authentication method requires the user to perform additional operations, resulting in a low user's willingness to use and a lack of unconscious authentication method.
By monitoring the actions performed by the user in the target application, determining the user's behavior sequence, inputting it into the recurrent neural network layer of the pre-trained detection model, extracting behavior characteristics, and then inputting the behavior characteristics to the classifier corresponding to the target application's current login account to determine whether the identity verification is passed or not.
The unaware authentication process is implemented, which improves users' acceptance of authentication methods and improves the efficiency of authentication.
Smart Images

Figure CN112597459B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to an identity authentication method and device. Background Art
[0002] At present, with the development of computer technology, the functions of terminals (such as mobile phones, tablets, etc.) are becoming more and more powerful. Users have the need to use terminals in various scenarios of life and work, making the security of terminals particularly important.
[0003] Common authentication methods for terminals include authenticating users through passwords or biometrics. However, since entering a password or verifying based on biometrics requires additional user input, this can reduce user engagement. Therefore, a user-invisible authentication method is needed. Summary of the Invention
[0004] This specification provides an identity authentication method and device to partially solve the above-mentioned problems existing in the prior art.
[0005] This manual adopts the following technical solutions:
[0006] This document provides an authentication method, including:
[0007] Monitor the actions users perform in the target application;
[0008] When the user initiates a designated service, determining the user's behavior sequence based on the monitored user operations;
[0009] Taking the behavior sequence as input, inputting it into the recurrent neural network layer of a pre-trained detection model, and determining the hidden layer features of the recurrent neural network layer as the behavior features corresponding to the behavior sequence;
[0010] Taking the behavior feature as input, inputting it into the classifier of the detection model corresponding to the current login account of the target application, and determining a classification result of the behavior feature;
[0011] If it is determined according to the classification result that the identity authentication fails, the designated service is not executed, and a prompt message is sent to the server, where the prompt message is used to prompt the server to re-authenticate the user.
[0012] Optionally, determining the user's behavior sequence based on the monitored user operations specifically includes:
[0013] Determining a behavior vector corresponding to the operation based on the monitored operation of the user in the target application and the time when the user performs the operation;
[0014] The user's behavior sequence is determined according to the behavior vector corresponding to the operation.
[0015] Optionally, before taking the behavior sequence as input, the method further includes:
[0016] Encoding the user's behavior sequence according to the monitored user's operations and preset coding rules to determine the user's behavior matrix;
[0017] The behavior matrix is used as input to the recurrent neural network layer of the pre-trained detection model.
[0018] Optionally, the preset encoding rule includes an action dictionary encoding rule and a one-bit effective encoding rule;
[0019] Encoding the user's behavior sequence according to the monitored user's operations and preset coding rules to determine the user's behavior matrix specifically includes:
[0020] Encoding the user's behavior sequence according to the monitored user's operation and the preset action dictionary encoding rule to obtain the user's behavior code;
[0021] The user's behavior matrix is determined according to the behavior code and the preset one-bit effective coding rule.
[0022] Optionally, the user's operation includes the user's operation on each control and the user's browsing operation on each duration of the interface;
[0023] Encoding the user's behavior sequence according to the monitored user operations and the preset action dictionary encoding rules, specifically including:
[0024] The user's behavior sequence is encoded according to the monitored user's operations on each control and the user's browsing operations on the interface for each duration, as well as the preset action dictionary encoding rules.
[0025] Optionally, the user's behavior sequence carries an account identifier;
[0026] The behavioral features are input into the classifier of the detection model corresponding to the current login account of the target application, specifically including:
[0027] Determining a classifier corresponding to a current login account of the target application according to the account identifier carried in the user's behavior sequence;
[0028] The behavioral feature is input into a classifier of the detection model corresponding to the current login account of the target application.
[0029] Optionally, determining that the identity authentication fails according to the classification result specifically includes:
[0030] The classification result is that the user is not the user holding the current login account of the target application, and it is determined that the identity authentication fails.
[0031] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned identity authentication method is implemented.
[0032] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned identity authentication method when executing the program.
[0033] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects:
[0034] In the identity authentication method provided in this specification, by monitoring the operations performed by the user in the target application, when the user initiates a specified business, the user's behavior sequence is determined, the behavior sequence is input into the recurrent convolutional neural network (RNN) layer of the detection model, the behavior characteristics corresponding to the user behavior sequence are determined, the behavior characteristics are input into the classifier of the detection model corresponding to the current login account of the target application, the classification result of the behavior characteristics is determined, and whether the identity authentication is passed is determined based on the classification result.
[0035] As can be seen from the above method, unlike existing methods that rely on password verification and biometric verification, this method determines the operational data that needs to be verified for the user's current designated service execution based on the user's operations in the target application. It further determines the user's behavioral characteristics and, by judging whether these user's behavioral characteristics are normal for the account, determines whether the user is the holder of the account currently logged into the target application. The entire verification process is completed without requiring the user to perform additional operations. The identity verification method described in this specification is imperceptible, which increases user acceptance and further improves authentication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The exemplary embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation of this specification. In the drawings:
[0037] Figure 1 A flowchart of the identity verification method provided in this manual;
[0038] Figure 2 A schematic diagram of encoding the encoded user's behavior sequence provided in this specification;
[0039] Figure 3 A schematic diagram of the identity verification device provided for this instruction manual;
[0040] Figure 4 The corresponding Figure 1 Schematic diagram of electronic equipment. DETAILED DESCRIPTION
[0041] To make the objectives, technical solutions, and advantages of this specification more clear, the following will clearly and completely describe the technical solutions of this specification in conjunction with the specific embodiments of this specification and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this specification.
[0042] The technical solutions provided by the embodiments of this specification are described in detail below with reference to the accompanying drawings.
[0043] Figure 1 The following is a flowchart of the identity verification method provided in this manual, which specifically includes the following steps:
[0044] S100: Monitoring operations performed by a user in a target application.
[0045] Typically, when using a terminal, a user can operate an application running on the terminal to cause the application to perform a corresponding service, or to cause the service provider to perform a corresponding service. In scenarios where services are performed by a service provider, the application is provided by the service provider and, based on the user's operation, can send requests or instructions to the server of the server provider, which then performs the service.
[0046] As used herein, a terminal can monitor the user's actions within a target application installed on the terminal while the user is using the target application, in order to determine the services that require subsequent execution. The target application is an application that implements the verification method described herein and is installed and running on the terminal, provided by a service provider. The target application can be a food delivery application, a payment application, or other similar application. The specific configuration is optional and is not limited by this specification.
[0047] Specifically, when the user opens the target application in the terminal, the target application may send a storage request to the terminal. The terminal may monitor the operations performed by the user in the target application in real time based on the received storage request and store them as user operation data.
[0048] It should be noted that the terminal in this description can be an electronic device that can run applications, such as a mobile phone or a tablet computer.
[0049] S102: When the user initiates a designated service, the user's behavior sequence is determined according to the monitored user operations.
[0050] In one or more embodiments provided herein, when a terminal detects a user initiating a designated service, the terminal can determine the user's behavioral sequence based on the detected user operations. The designated service can be any service within a target application provided by a service provider. Typically, the designated service requires identity verification, such as a payment service or a password change service. The specific content of the designated service can be customized as needed and is not limited in this specification.
[0051] In this specification, when a user is detected to have initiated a specified service, the terminal may send an execution request to the service provider's server, and the execution request carries the account identifier of the current login account of the target application. After receiving the execution request, the service provider's server may obtain the various operations of the user in the target application stored in step S100 based on the execution request and the account identifier carried in the execution request, as the user operation data that needs to be authenticated for the user to execute the specified service this time, and authenticate the obtained user operation data to determine whether to execute the specified service initiated by the user. Alternatively, when a user is detected to have initiated a specified service, the terminal may verify the user operation data that needs to be authenticated for the user to execute the specified service this time based on the account identifier and the pre-stored operations of the user in the target application, and send the verification result to the service provider's server, so that the server can determine whether to execute the specified service. For the convenience of description, this specification takes the terminal executing the identity authentication method as an example.
[0052] Specifically, taking the designated service as a payment service as an example, when the terminal detects that a user has initiated a payment service, it can determine the behavior vector of the user's operation based on the pre-stored operations of the user in the target application from opening the target application to executing the payment service, as well as the time when the user performs the operation. Among them, the monitored user operations may include: operations such as clicking and long pressing on controls, the trajectory of the user sliding the screen, the position where the user taps the screen, and the length of time the user browses the interface can also be regarded as a user operation. Of course, one or more of the above user operations can be selected for monitoring and storage. The terminal can then determine the behavior vector of the user's operation for each monitored user operation based on the time when the user performs the operation, the specific type of operation, and the specific content of the operation. And based on the determined behavior vectors of each operation performed by the user in the target application, the user's behavior sequence can be determined.
[0053] Furthermore, because the determined user behavior sequence includes timestamps, i.e., a description of the time at which the user performed the action, and for electronic devices, even timestamps at adjacent time points represent two completely different sets of data, directly processing the user behavior sequence would be too complex, making subsequent processing difficult. Therefore, to facilitate subsequent processing, the timestamps contained in the behavior sequence can be converted into less complex, easier-to-process time periods. Coding rules can be pre-set to encode the user behavior sequence.
[0054] Specifically, for each operation of the user in the target application, there may be a code in a preset coding rule corresponding to it. Taking the preset action dictionary coding rule as an example, the terminal can encode the determined user's behavior sequence based on the obtained user's operations in the target application and the preset action dictionary coding rule to determine the user's behavior matrix. And when it is necessary to process the user's behavior sequence in the subsequent step S104, the determined user's behavior matrix is used as input for processing. Among them, the preset action dictionary coding rule can be shown in Table 1.
[0055] Behavioral Actions Serial number Click the Comments control 1 Browse page <10s 2 Browse page <30s 3 … … Payment N
[0056] Table 1
[0057] Assuming that the number of all possible operations of the user in the target application is N, the N operations of the user in the target application can be mapped to N sequence number values according to a preset action dictionary encoding rule.
[0058] It should be noted that the various actions in Table 1 are just examples and can also be other operations. For example, browsing operations such as browsing page <5s, 5s < browsing page <10s, etc. correspond to different serial number values. The specific preset action dictionary encoding rules can be set as needed, and this manual does not limit this.
[0059] Furthermore, in the encoded user behavior sequence, there is a size relationship between the encoded serial numbers, and the user's operations in the target application are of equal level. The size relationship between the encoded serial numbers will cause difficulties in model training. Therefore, another encoding rule can be preset to further encode the encoded user behavior sequence. For example, a one-hot encoding rule can be preset, and the encoded user behavior sequence can be processed according to the one-hot encoding rule. Figure 2 shown.
[0060] Figure 2 This is a schematic diagram of encoding the encoded user's behavior sequence provided in this specification. After being encoded by the behavior dictionary in Table 1, the user's behavior sequence is processed into a string of variable-length encoding strings. This variable-length encoding string can be further encoded according to the N operations in Table 1. Figure 2 In the figure, the solid line encloses the encoded user behavior sequence, the dashed line corresponds to the N features in Table 1, and the gray area is the user behavior matrix obtained by single-bit encoding of the encoded behavior sequence. This determined behavior matrix can be used as input for subsequent processing of the user behavior sequence.
[0061] S104: The behavior sequence is input into a recurrent neural network layer of a pre-trained detection model, and hidden layer features of the recurrent neural network layer are determined as behavior features corresponding to the behavior sequence.
[0062] In one or more embodiments provided in this specification, after determining the user's behavior sequence, the terminal can also use the determined behavior sequence of the user as input to the RNN layer of a pre-trained detection model to determine the hidden layer features of the recurrent convolutional neural network layer as the behavior features corresponding to the behavior sequence.
[0063] Specifically, in this specification, the determined behavior sequence of the user can be input into the RNN layer of the detection model in sequence, that is, the behavior vectors determined based on all operations from the user opening the target application in the terminal to initiating the specified service and the time of executing each operation can be input into the RNN layer of the detection model in sequence to obtain the hidden layer features of the RNN layer. The number of cycles of the RNN layer is determined according to the determined behavior sequence of the user. For example, if the determined behavior sequence of the user includes k behavior vectors, the RNN layer needs to be cycled k times. How to train the RNN layer of the detection model will be described in detail later in this specification.
[0064] S106: The behavior feature is input into a classifier of the detection model corresponding to the current login account of the target application to determine a classification result of the behavior feature.
[0065] In one or more embodiments provided in this specification, after determining the behavioral features corresponding to the user's behavior sequence, the determined behavioral features can also be used as input to a classifier of a pre-trained detection model corresponding to the current login account of the target application to determine the classification result of the behavioral features.
[0066] Specifically, when monitoring that a user has initiated a specified service, the terminal may send a classification request to the service provider's server based on the account identifier of the target application's current login account to determine the classifier corresponding to the target application's current login account. After receiving the classification request, the service provider's server may determine the classifier corresponding to the target application's current login account from the classifiers of the detection model based on the account identifier carried in the classification request, and return the determined classifier to the terminal. After receiving the classifier sent by the service provider's server, the terminal may input the behavioral features corresponding to the user's behavioral sequence as input into the classifier to determine the classification result of the behavioral features. The classifier may be a one-class support vector machine (OCSVM) or a support vector machine (SVM). The specific content of the classifier may be set as needed, and this specification does not impose any restrictions on this.
[0067] It should be noted that the classifier corresponds to the target application's currently logged-in account. That is, for each account using the target application, there is a classifier corresponding to that account that has been pre-trained based on a number of operations performed by the account holder in the target application. The classification results of this classifier include: the user is not the user holding the target application's currently logged-in account, that is, the user currently using the account is not the account holder; and the user is the user holding the target application's currently logged-in account, that is, the user currently using the account is the account holder. The classifier can determine whether the user is the holder of the target application's currently logged-in account by determining whether the input user's behavioral characteristics are normal account behavioral characteristics.
[0068] Furthermore, the account logged into the target application on the same terminal is usually fixed. Therefore, after obtaining the classifier corresponding to the account, the terminal can also store the classifier. In subsequent use, when monitoring the user initiating a specified service, the terminal can match the account currently logged into the target application with the account identifier of the classifier. If the match is successful, the user's behavioral characteristics can be directly input into the classifier. If the match fails, the classifier can be re-determined based on the account identifier of the account currently logged into the target application.
[0069] How to train the classifier of the detection model will be described in detail later in this manual.
[0070] S108: If it is determined according to the classification result that the identity authentication fails, the designated service is not executed, and a prompt message is sent to the server, where the prompt message is used to prompt the server to re-authenticate the user.
[0071] In one or more embodiments provided in this specification, after determining the classification result of the behavioral feature, it can also be determined whether the identity authentication is passed based on the classification result. If it is determined that the identity authentication is not passed based on the classification result, the terminal can determine not to execute the specified service initiated by the user and send a prompt message to the server. The prompt message is used to prompt the server to re-authenticate the user.
[0072] Specifically, in this specification, the classification results of the behavioral characteristics determined in step S106 include: the user is not the user holding the current login account of the target application, that is, the user currently using the account is not the account holder himself; and the user is the user holding the current login account of the target application, that is, the user currently using the account is the account holder himself. When the classification result is that the user is the user holding the current login account of the target application, it can be determined that the identity authentication is passed, and the terminal can determine to execute the designated business initiated by the user. When the classification result is that the user is not the user holding the current login account of the target application, it is determined that the identity authentication is not passed, and the terminal can send a prompt message to the server of the service provider to prompt the server to re-verify the user.
[0073] It should be noted that when re-verifying a user, you can use password verification methods, biometric verification methods, and identity verification methods in this manual, etc. The specific method used to re-verify the user can be set as needed, and this manual does not impose any restrictions on this.
[0074] based on Figure 1 The identity authentication method monitors the operations performed by the user in the target application. When the user initiates a specified business, the user's behavior sequence is determined, the behavior sequence is input into the RNN layer of the detection model, the behavior characteristics corresponding to the user's behavior sequence are determined, the behavior characteristics are input into the classifier of the detection model corresponding to the current login account of the target application, the classification result of the behavior characteristics is determined, and whether the identity authentication is passed is determined based on the classification result. Different from the existing methods of password verification and biometric verification, this method determines the operation data that needs to be verified for the user to perform the specified business this time based on each operation of the user in the target application, further determines the user's behavior characteristics, and determines whether the user is the holder of the account currently logged in to the target application by judging whether the user's behavior characteristics are normal behavior characteristics of the account. The entire verification process can be completed without the user performing additional operations. The identity authentication method in this manual improves the user's acceptance of identity authentication without perception and further improves the efficiency of identity authentication.
[0075] In addition, existing technologies also provide a non-perceptual identity verification method. This method collects behavioral characteristics of the current user when using a mobile phone, such as the pressure and duration of screen taps, the area swiped, and the speed of swiping, and compares them with behavioral characteristics of users who have used the terminal in the past. If the similarity reaches a preset threshold, the current user is considered to be the real user. If the similarity is less than the preset threshold, the current user is considered to be not the real user, and other methods are needed to further verify the user's identity.
[0076] However, existing technologies for collecting behavioral characteristics of mobile phone users often rely on the sensors used in those phones. These sensors vary across different brands and models, and the signals output by different sensors for the same user behavior are also not identical. This results in inconsistent collected behavioral characteristics and low accuracy in identity verification methods based on behavioral characteristics. Furthermore, even if the same sensors are used, different sizes and weights of the terminals can still result in inconsistent collected behavioral characteristics, leading to low identity verification accuracy.
[0077] The method used in this specification is different from the existing technology, which is based on the collected behavioral characteristics of the user when using the mobile phone, such as the pressure of clicking the screen, the time of clicking the screen, the area of sliding the screen, the speed of sliding the screen, and other data that are easily affected by sensors and terminal types. Instead, it stores the user's operations on each control on the page and browsing operations of different lengths on the page to determine the user's behavior sequence, avoiding the problem that the collected user behavior characteristics cannot be processed due to different sensors, and improving the efficiency of identity authentication.
[0078] In addition, when using the terminal, the user can authorize an application to open the target application to perform a designated service. For example, the user can authorize a food delivery application to open a payment application to perform a payment service. If the payment application is the target application and the payment service is the designated service, then the amount of user operation data performed by the user in the target application for identity verification is clearly insufficient. Therefore, a first threshold may be set in step S102. When the user operation data required for identity verification for the user's current execution of the designated service is less than the first threshold, the terminal may determine to use password verification, biometric verification, or other methods for auxiliary verification of this service.
[0079] Furthermore, during the use of the target application, when the user initiates a designated service, there is a situation where the pre-stored user operation data that needs to be authenticated for the user's execution of the designated service is too large, resulting in the inability to process the user operation data in a timely manner, thereby reducing the efficiency of identity authentication. Therefore, a second threshold value can also be preset in step S102. When the user initiates a designated service, it can be first determined whether the user operation data of the user is greater than the second threshold value. If the user operation data of the user is not greater than the second threshold value, the subsequent steps of the identity authentication method are continued. If the user operation data of the user is greater than the second threshold value, the user operation data can be cut and processed according to the second threshold value. For example, the user operation data of the first 100 operations initiated by the user for the designated service are selected as the user operation data that needs to be authenticated for the user's execution of the designated service. The cut user operation data is used as input and input into the pre-trained detection model to execute the subsequent steps of the identity authentication method.
[0080] In addition, the storage request in step S100 may also include storage rules. The terminal may then store the monitored user operations as user operation data in the server or user terminal according to the storage rules included in the storage request. The storage rules may include storing the monitored user operations in real time, storing them when a certain number of user operations are reached, or storing them at regular intervals. The specific storage rules may be set as needed and are not limited in this specification.
[0081] Furthermore, the user's actions in the target application may be affected by the user's state (e.g., sitting, lying down, walking). Therefore, in step S102, when encoding the user's behavior sequence using a preset action dictionary encoding rule, encoding rules for the user's state information may also be added to the action dictionary encoding rule, as shown in Table 2. The terminal can then determine the user's current state based on current positioning data, a level, etc., and determine a behavior matrix containing the user's current state when encoding the user's behavior sequence.
[0082]
[0083]
[0084] Table 2
[0085] It should be noted that, similar to Table 1, the various behavioral actions and user states in Table 2 are only examples and may also be other operations. The specific preset action dictionary encoding rules can be set as needed, and this manual does not impose any restrictions on this.
[0086] In addition, in one or more embodiments of this specification, the RNN layer of the detection model can be trained in the following manner.
[0087] Specifically, the hidden features obtained by the RNN layer represent user characteristics, which facilitate the subsequent detection model classifier to determine user identity. The features determined based on user behavior are conducive to the subsequent classifier's accurate classification output, which may be different for different users. Therefore, a detection model can be trained for each user.
[0088] Therefore, the server that trains the model can determine the training samples and sample labels corresponding to each user.
[0089] Specifically, the user data included in the training sample can be the user behavior sequence determined using the method in step S102, or the user behavior matrix encoded using the method in step S102. For each user, the user's behavior sequence can be determined by monitoring the user's operations during several historical uses of the target application, and then determining the user's behavior sequence for each use of the target application.
[0090] Secondly, for each training sample, the next operation in a series of user operations corresponding to the training sample is used as the sample label. The training sample and its corresponding label can be used to train the RNN layer to predict user operations.
[0091] Finally, when training the RNN layer, the training model server inputs the determined training samples into the RNN layer of the detection model to be trained, obtains the predicted operation results, and determines the loss based on the difference between the operation results and the sample labels. The RNN layer is trained with minimizing the loss as the optimization goal. The specific loss function used to determine the loss between different user operations can be set as needed.
[0092] In addition, in this specification, the server for training the model and the server of the service provider that can execute the identity authentication method can be the same server or different. The specific server for training the model can be set as needed, and this specification does not impose any restrictions on this.
[0093] When training the classifier of the detection model, the parameters of the classifier are different for different users, that is, each user has a corresponding classifier, which is used to distinguish whether it is the user. When determining the parameters of the classifier, the server can obtain the output of the RNN layer of the detection model, which contains several behavioral features of the user and other users, as input samples, and use whether the user to whom the behavioral feature belongs is the account holder as the sample label. Each determined sample is input into the classifier of the detection model, and the hyperplane that distinguishes the behavioral features of the user from the behavioral features of other users is used as the optimization goal. The parameters of the classifier are adjusted until a hyperplane is obtained that can distinguish the behavioral features of the user from other users in the sample, and the classifier corresponding to the user is determined.
[0094] Furthermore, if the service provider trains an RNN layer for each user separately, the amount of training for the server may be too large. If a universal RNN layer is trained, the training of the RNN layer will be more difficult because the behavioral characteristics of each user are different, and the accuracy of the trained RNN layer may be lower. Therefore, in this specification, the server of the training model can also pre-group the users, and then for each group of users, determine the user behavior sequence according to the operations of each user in the group when using the target application, so as to determine each training sample and each sample label. And train the RNN layer corresponding to the group based on the training samples. After training the RNN layer corresponding to each group, the server can also store the group identifier corresponding to the user in the user's account information according to the user group, so that in the subsequent step S104, the corresponding group identifier can be determined according to the account identifier, and the determined behavior sequence can be input into the RNN layer corresponding to the group identifier to obtain the hidden layer feature as the behavior feature.
[0095] The server may choose to cluster each user based on their user profile and determine the user group based on the clustering results. Alternatively, users may be grouped based on age, address, and other information in their user profiles, for example, by age groups of 10-20, 20-30, 30-40, and so on. Of course, users may also be grouped based on more than one user profile dimension, for example, by males aged 10-20, females aged 10-20, males aged 20-30, and so on.
[0096] In addition, when determining user data for training, this specification may obtain, for each user, a series of operations performed by the user when using the target application as training samples. Each training sample corresponds to a series of operations performed by the user when using the target application, and the server may determine each training sample based on the user data of different users.
[0097] Furthermore, in order to avoid the monotonicity of the training samples, the trained RNN layer may not be accurate enough. For example, the last operation in a series of operations performed by most users when using the target application is to click on the exit control. As a result, when the model is used, the hidden layer features determined are biased towards the operation of clicking on the exit control, which in turn leads to the RNN layer being inaccurate. Therefore, in order to ensure the accuracy of the trained RNN layer, each training sample can also have diversity. For example, a number of consecutive operations are randomly selected from a series of operations performed by a user when using the target application. Of course, the user operation data corresponding to the randomly selected consecutive operations needs to be no less than a preset first threshold and no more than a preset second threshold, and there must still be operations after the consecutive operations. In this case, the operations after the consecutive operations can be used as sample labels.
[0098] It should be noted that the RNN layer of the detection model and the classifier corresponding to each account can be trained separately or jointly. When the recurrent neural network layer and the classifier are jointly trained, the training samples are several operations of the user and other users in the target application stored in the terminal. Whether the user of the target application is the user is used as the sample label, and the parameters are adjusted until the training samples of the two labels are separated, and the distance between the training samples of the two labels and the hyperplane is greater than the preset third threshold. The detection model corresponding to the user is determined. Among them, the greater the distance between the hyperplane and the user's behavioral characteristics, the more obvious the behavioral characteristics of the user and other users can be distinguished by the detection model. In other words, the higher the accuracy of the detection model.
[0099] In addition, the detection model obtained by jointly training the RNN layer and the classifier is specific to each user. The specific value of the preset third threshold can be set as needed, and this specification does not limit this.
[0100] It should be noted that the users mentioned in this manual are users who have registered accounts with the service provider.
[0101] The above is an identity authentication method provided in one or more embodiments of this specification. Based on the same idea, this specification also provides a corresponding identity authentication device, such as Figure 3 shown.
[0102] Figure 3 The schematic diagram of the identity verification device provided for this manual specifically includes:
[0103] The monitoring module 200 is used to monitor operations performed by users in the target application.
[0104] The encoding module 202 is configured to determine a behavior sequence of the user based on the monitored operations of the user when the user initiates a designated service.
[0105] The first determination module 204 is configured to input the behavior sequence as input to a recurrent neural network layer of a pre-trained detection model, and determine hidden layer features of the recurrent neural network layer as behavior features corresponding to the behavior sequence.
[0106] The second determination module 206 is configured to take the behavior feature as input and input it into a classifier of the detection model corresponding to the current login account of the target application to determine a classification result of the behavior feature.
[0107] The prompt module 208 is configured to not execute the designated service and send a prompt message to the server if it is determined that the identity authentication fails according to the classification result, wherein the prompt message is used to prompt the server to re-authenticate the user.
[0108] Optionally, the encoding module 202 is configured to determine a behavior vector corresponding to the operation based on the monitored operation of the user in the target application and the time when the user performs the operation, and determine the user's behavior sequence based on the behavior vector corresponding to the operation.
[0109] Optionally, the encoding module 202 is also used to encode the user's behavior sequence based on the monitored user operations and preset encoding rules, determine the user's behavior matrix, and use the behavior matrix as input to the recurrent neural network layer of the pre-trained detection model.
[0110] Optionally, the preset coding rules include action dictionary coding rules and one-bit effective coding rules. The coding module 202 is specifically used to encode the user's behavior sequence according to the monitored user's operations and the preset action dictionary coding rules to obtain the user's behavior code, and determine the user's behavior matrix according to the behavior code and the preset one-bit effective coding rules.
[0111] Optionally, the user's operations include the user's operations on each control and the user's browsing operations on the interface for each duration. The encoding module 202 is specifically used to encode the user's behavior sequence based on the monitored user's operations on each control and the user's browsing operations on the interface for each duration, as well as the preset action dictionary encoding rules.
[0112] Optionally, the user's behavior sequence carries an account identifier, and the second determination module 206 is specifically used to determine the classifier corresponding to the current login account of the target application based on the account identifier carried by the user's behavior sequence, and input the behavior characteristics into the classifier corresponding to the current login account of the target application in the detection model.
[0113] Optionally, the prompt module 208 is specifically configured to determine that the identity authentication fails if the classification result indicates that the user is not a user holding a currently logged-in account of the target application.
[0114] This specification also provides a computer-readable storage medium, which stores a computer program that can be used to execute the above Figure 1 The authentication method provided.
[0115] This manual also provides Figure 4 The schematic structure diagram of the electronic device shown in FIG. Figure 4 As mentioned above, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to achieve the above Figure 1 Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0116] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD through their own programming, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly done using "logic compiler" software. This is similar to the software compiler used when developing programs. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that by simply programming the method flow in one of these hardware description languages and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.
[0117] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code format, the controller can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules that implement the method and structures within the hardware component.
[0118] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0119] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0120] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0121] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0122] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0123] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0124] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0125] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0126] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0127] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0128] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0129] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0130] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0131] The foregoing is merely an example of the present invention and is not intended to limit the present invention. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be included within the scope of the claims of the present invention.
Claims
1. An authentication method, characterized in that, the method includes: monitoring the operations performed by the user in the target application; when the user initiates a specified service, determining the behavior sequence of the user according to the operations of the user monitored in the target application from opening the target application to before performing the specified service; the operations of the user include the operations of the user on each control and the browsing operations of the user on the interface for different durations; taking the behavior sequence as an input, inputting it into the recurrent neural network layer of a pre-trained detection model, and determining the hidden layer features of the recurrent neural network layer as the behavior features corresponding to the behavior sequence; taking the behavior features as an input, inputting them into the classifier corresponding to the currently logged-in account of the target application in the detection model, and determining the classification result of the behavior features; if it is determined according to the classification result that the authentication fails, then the specified service is not executed, and a prompt message is sent to the server, where the prompt message is used to prompt the server to re-authenticate the user.
2. The method according to claim 1, characterized in that, determining the behavior sequence of the user according to the operations of the user monitored in the target application from opening the target application to before performing the specified service specifically includes: determining the behavior vector corresponding to the operation according to the operations of the user monitored in the target application from opening the target application to before performing the specified service and the time when the user performs the operation; determining the behavior sequence of the user according to the behavior vector corresponding to the operation.
3. The method according to claim 1, characterized in that, before taking the behavior sequence as an input, the method further includes: encoding the behavior sequence of the user according to the monitored operations of the user and a preset encoding rule, and determining the behavior matrix of the user; taking the behavior matrix as an input, and inputting it into the recurrent neural network layer of a pre-trained detection model.
4. The method according to claim 3, characterized in that, the preset encoding rule includes an action dictionary encoding rule and a one-hot encoding rule; encoding the behavior sequence of the user according to the monitored operations of the user and a preset encoding rule, and determining the behavior matrix of the user specifically includes: encoding the behavior sequence of the user according to the monitored operations of the user and the preset action dictionary encoding rule to obtain the behavior encoding of the user; determining the behavior matrix of the user according to the behavior encoding and the preset one-hot encoding rule.
5. The method according to claim 4, characterized in that, encoding the behavior sequence of the user according to the monitored operations of the user and the preset action dictionary encoding rule specifically includes: encoding the behavior sequence of the user according to the operations of the user on each control monitored and the browsing operations of the user on the interface for each duration, and the preset action dictionary encoding rule.
6. The method according to claim 1, characterized in that, the behavior sequence of the user carries an account identifier; Using the behavioral feature as input, and inputting it into the classifier corresponding to the currently logged-in account of the target application in the detection model, specifically includes: Determining the classifier corresponding to the currently logged-in account of the target application according to the account identifier carried in the user's behavior sequence; Inputting the behavioral feature into the classifier corresponding to the currently logged-in account of the target application in the detection model.
7. The method according to claim 1, wherein, Determining that the authentication fails according to the classification result, specifically includes: When the classification result indicates that the user is not the user holding the currently logged-in account of the target application, determining that the authentication fails.
8. An authentication device, wherein, The device includes: A monitoring module, configured to monitor the operations performed by the user in the target application; An encoding module, configured to, when the user initiates a specified service, determine the user's behavior sequence according to the operations of the user in the target application from opening the target application to before performing the specified service; the operations of the user include the operations of the user on each control and the browsing operations of the user on the interface for different durations; A first determination module, configured to use the behavior sequence as input, input it into the recurrent neural network layer of the pre-trained detection model, and determine the hidden layer feature of the recurrent neural network layer as the behavioral feature corresponding to the behavior sequence; A second determination module, configured to use the behavioral feature as input, input it into the classifier corresponding to the currently logged-in account of the target application in the detection model, and determine the classification result of the behavioral feature; A prompt module, configured to, if it is determined that the authentication fails according to the classification result, not execute the specified service, and send a prompt message to the server, where the prompt message is used to prompt the server to re-authenticate the user.
9. A computer-readable storage medium, wherein, The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 7 above.
10. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the program, it implements the method according to any one of claims 1 to 7 above.
Citation Information
Patent Citations
Hidden type authentication device and method
CN106156566A
Identity authentication method and device and computer readable storage medium
CN109977639A