A security authentication method, device, storage medium and server

By receiving device status and attribute information, multiple authentication strategies can be dynamically selected for security authentication, solving the problem of low flexibility in multimodal biometric technology and improving the security of authentication and user experience.

CN113204758BActive Publication Date: 2025-11-28CHINA CONSTRUCTION BANK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110584689.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-27
Publication Date
2025-11-28
Estimated Expiration
2041-05-27

AI Technical Summary

Technical Problem

Existing multimodal biometric technologies have low security authentication methods, resulting in a low success rate of security authentication. Furthermore, single biometric technologies are prone to false identification, leading to insufficient security.

Method used

By receiving the device's current status and attribute information, the risk coefficient of the security authentication request is determined, and the target authentication strategy is dynamically selected based on the risk coefficient. Security authentication is performed by combining multiple authentication types, including face recognition, fingerprint recognition, and voice recognition.

Benefits of technology

It enables dynamic adjustment of authentication strategies based on risk assessment, improving the security level and user experience of security authentication, avoiding occasional risks associated with a single authentication method, and enhancing the accuracy and flexibility of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113204758B_ABST
    Figure CN113204758B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of mobile internet, and discloses a security authentication method and device, a storage medium and a server. The method comprises the following steps: receiving a security authentication request sent by a device and current state information and attribute information of the device; determining a risk coefficient of the security authentication request based on the current state information and the attribute information, and determining a target authentication strategy based on the risk coefficient, wherein the target authentication strategy comprises at least one authentication type; sending the target authentication strategy to the device, so that intelligent strategy selection is realized; receiving authentication information fed back by the device; performing security authentication on each authentication information; and sending an authentication result to the device, so that the transaction security is guaranteed and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the field of mobile Internet technology, and in particular to a security authentication method and device, a storage medium and a server. BACKGROUND

[0002] Biometric technology is currently increasingly mature, but the use of a single biometric technology has certain limitations due to security and customer experience considerations, such as in terms of security: various biometric means all have certain false recognition situations, resulting in certain security risks in security authentication.

[0003] Currently, there are schemes that propose combining multi-modal recognition means to improve authentication security levels and scene compatibility. Multi-modal means multi-modal biometric recognition, which integrates or fuses two or more biometric technologies, utilizes the unique advantages of multiple biometric technologies, and combines data fusion technology to make the authentication and recognition process more accurate and secure.

[0004] However, in existing technologies, multi-modal recognition is basically rigidly bound, such as face plus voiceprint, face plus fingerprint, etc., resulting in low flexibility of security authentication and a decrease in security authentication success rate. SUMMARY

[0005] The present application provides a security authentication method and device, a storage medium and a server to improve the security level and user experience of security authentication by using data analysis and dynamic authentication methods.

[0006] In a first aspect, embodiments of the present application provide a security authentication method, comprising: receiving a security authentication request sent by a device and current state information and attribute information of the device;

[0007] determining a risk coefficient of the security authentication request based on the current state information and the attribute information, and determining a target authentication strategy based on the risk coefficient, wherein the target authentication strategy includes at least one authentication type;

[0008] sending the target authentication strategy to the device, receiving authentication information fed back by the device, performing security authentication on each of the authentication information, and sending an authentication result to the device.

[0009] In a second aspect, embodiments of the present application also provide a security authentication method, comprising:

[0010] a security authentication request sent by a device and current state information and attribute information of the device;

[0011] The security authentication server receives the security authentication request and the current state information and attribute information of the device, determines a risk coefficient of the security authentication request based on the current state information and the attribute information, determines a target authentication strategy based on the risk coefficient, and sends the target authentication strategy to the device, wherein the target authentication strategy comprises at least one authentication type.

[0012] The device prompts each authentication type in the target authentication strategy, collects authentication information corresponding to each authentication type, and sends each authentication information to the security authentication server.

[0013] The security authentication server receives the authentication information fed back by the device, performs security authentication on each authentication information, and sends an authentication result to the device.

[0014] The device receives the authentication result, and performs business processing when the authentication result is authentication success.

[0015] In a third aspect, an embodiment of the present application further provides a security authentication device, comprising:

[0016] An information receiving module, configured to receive a security authentication request and current state information and attribute information of a device sent by the device;

[0017] A strategy determining module, configured to determine a risk coefficient of the security authentication request based on the current state information and the attribute information, and determine a target authentication strategy based on the risk coefficient, wherein the target authentication strategy comprises at least one authentication type;

[0018] An information authentication module, configured to send the target authentication strategy to the device, receive authentication information fed back by the device, perform security authentication on each authentication information, and send an authentication result to the device.

[0019] In a fourth aspect, an embodiment of the present application further provides a security authentication server, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the security authentication method as described in the embodiments of the present application when executing the computer program.

[0020] In a fifth aspect, an embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executable on a processor to implement the security authentication method as described in the embodiments of the present application.

[0021] The technical scheme of the embodiment of the present application receives a security authentication request sent by a device, and current state information and attribute information of the device; determines a risk coefficient of the security authentication request based on the current state information and the attribute information, and determines a target authentication strategy including at least one authentication type based on the risk coefficient; sends the target authentication strategy to the device, receives authentication information fed back by the device, performs security authentication on each of the authentication information, and sends an authentication result to the device, so that dynamic strategy selection is realized through the risk coefficient, and the transaction security is ensured while the user experience is improved. BRIEF DESCRIPTION OF DRAWINGS

[0022] Figure 1 A flowchart of a security authentication method provided for the embodiment one of the present application.

[0023] Figure 2 A flowchart of a security authentication method provided for the embodiment two of the present application.

[0024] Figure 3 A flowchart of a security authentication method provided for the embodiment three of the present application.

[0025] Figure 4 A structural schematic diagram of a security authentication device provided for the embodiment four of the present application.

[0026] Figure 5 A structural schematic diagram of a security authentication server provided for the embodiment five of the present application. DETAILED DESCRIPTION

[0027] The present application will be further described below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the structures.

[0028] Embodiment one

[0029] Figure 1 A flowchart of a security authentication method provided for the embodiment one of the present application, the embodiment can be applicable to the case of realizing multi-modal security authentication according to device information, the method can be executed by the security authentication device provided by the embodiment of the present application, the device can be realized in the form of software and / or hardware, and generally can be integrated in a computer device. For example, a security authentication server. Specifically includes the following steps:

[0030] Step 110, receiving a security authentication request sent by a device, and current state information and attribute information of the device.

[0031] Before a terminal device such as a mobile phone, a tablet, or the like, or a smart device such as an ATM (Automated Teller Machine) accesses a server to perform a service process, a security authentication is required for an operating user to ensure the security of the service process.

[0032] In this embodiment, the security authentication request is an authentication request initiated to ensure the security of a user transaction. Specifically, when a user performs a service process through a device, the device triggers a security authentication request, and the device sends the security authentication request to a security server and also sends current state information and attribute information of the device to the security authentication server. The security server receives the security authentication request sent by the device and the current state information and attribute information of the device. The device includes but is not limited to a mobile phone, a tablet computer, and a bank self-service device. The device can run a multi-modal software development kit (SDK), and the use of the SDK can improve the development efficiency and more simply access a certain function.

[0033] Optionally, the current state information includes device environment information and service scenario information, and the attribute information includes user attribute information and device attribute information.

[0034] Specifically, the device environment information is the environment state information of the current device that can be collected, and can include a current device networking state, geographic location information, an application program used by the device to perform a service process, and whether the device is in a root mode, and the like. The current device networking state can include but is not limited to mobile data, a wireless local area network, a broadband network, and the like. The geographic location information can be acquired in real time or based on a time interval, for example, through a GPS device. Optionally, it can also be determined whether the device moves relative to a previous time stamp, and if not, the geographic location information of the previous time stamp is determined as the geographic location information of a current time stamp. When the device initiates a security authentication request, the device obtains the geographic location information through a preset acquisition manner. The system running mode of the device can be acquired by collecting a device system bottom code, and the highest permission in the bottom code is detected to determine whether the device is in a root mode. If the highest permission is detected, the device is in a root mode, otherwise, the device is not in a root mode.

[0035] The business scenario information can be a specific business type handled by the user. Different application programs can correspond to different business scenario information. For example, the business scenario information can include, but is not limited to, deposit, transfer, loan, and financial management, etc. In the application of other application programs, the business scenario information can include, but is not limited to, transaction, payment, and collection, etc. The user attribute information is information that can be used to identify the uniqueness of the current user's identity, which can prevent others from impersonating. The user attribute information can include one or more of a user's ID number, name, or unique identifier, etc. The device attribute information can include, but is not limited to, device initiation IP, device fingerprint, device model, etc. The device fingerprint refers to a device feature or unique device identifier that can be used to uniquely identify the device. The current state information and attribute information can be collected by a device collection device, which can be a camera, a GPS device, etc. The current state information and attribute information can also be collected by the application program background. For fixed information, it can be pre-stored and directly read. The current state information and attribute information are data and information obtained from multiple information sources. By associating and comprehensively evaluating multiple data and information, a more accurate identity estimation can be obtained, and a comprehensive evaluation of the situation, threat, and its importance can be performed to ensure the security of user transactions.

[0036] Step 120, determining a risk coefficient of the security authentication request based on the current state information and the attribute information, and determining a target authentication strategy based on the risk coefficient, wherein the target authentication strategy includes at least one authentication type.

[0037] In this embodiment, the risk coefficient is used to measure the risk level of the security authentication request and is represented by a numerical value. The larger the risk coefficient, the greater the risk level of the current security authentication request. The smaller the risk coefficient, the smaller the risk level of the current security authentication request. The target authentication strategy is determined according to the risk coefficient of the security authentication request. Existing authentication strategies are usually bound to devices and business scenarios, resulting in fixed and unchanged authentication strategies. For example, when handling a transfer business, the corresponding authentication strategy is pre-set to fingerprint authentication. When the user handles the transfer business, the authentication strategy can only be fingerprint verification and cannot be verified by other means. In this embodiment, the target authentication strategy is determined by the risk coefficient. Different target authentication strategies can be determined according to the size of the risk coefficient, which improves the authentication security of high-risk and reduces the authentication complexity of low-risk.

[0038] The target authentication strategy can be an authentication strategy including multiple authentication types, and the authentication types of the authentication strategy include, but are not limited to, authentication technologies such as face recognition, fingerprint recognition, voice recognition, and iris recognition that can identify identity. The target authentication strategy can be a combination of multiple types, such as face recognition and voice recognition combined for identity authentication. The target authentication strategy can also be a single authentication type, such as identity authentication through fingerprint recognition only. In some optional embodiments, the target authentication strategy is an authentication strategy including at least two authentication types. The authentication strategy of at least two authentication types avoids the occasional risk of a single authentication method, makes the authentication and identification process more accurate and secure, and can meet the needs of users for different authentication types, provide users with more choices, and improve user satisfaction.

[0039] In some optional embodiments, the risk coefficient of the security authentication request is determined based on the current state information and the attribute information, including: generating a scene factor coefficient based on the business scenario information; generating a risk factor coefficient based on at least one of the device environment information, the user attribute information, and the device attribute information; and generating a risk coefficient of the security authentication request based on the scene factor coefficient and the risk factor coefficient.

[0040] The scene factor coefficient is a risk assessment result of the business scenario information. Different business scenario information corresponds to different transaction types, and a corresponding scene factor coefficient is generated based on the security level requirement corresponding to the transaction type. For example, the security level requirement corresponding to a transfer transaction is a medium level, and a corresponding medium level scene factor coefficient is generated. The security level requirement corresponding to a loan business is a high level, and a corresponding high level scene factor coefficient is generated. The risk factor coefficient is a risk assessment result of at least one of the device environment information, the user attribute information, and the device attribute information.

[0041] In some optional embodiments, the risk factor coefficient is generated based on at least one of the device environment information, the user attribute information, and the device attribute information, including: identifying abnormal information in the device environment information, determining a risk factor based on the identified abnormal information; and / or, matching the device attribute information based on a preset risk library, and generating a risk factor according to a matching result; and / or, determining whether the request time and the request type of the security authentication request include abnormal information based on the user attribute information, and generating a risk factor according to the abnormal information of the security authentication request; and generating a risk factor coefficient based on each risk factor.

[0042] The abnormal information of the device environment information can be user networking state abnormality, geographical location abnormality, system running mode abnormality, etc. For example, the user networking state abnormality can be that the device detects network interruption during the user is handling a service, and risk level assessment is performed on this abnormal information, and the risk factor corresponding to the abnormal information is determined according to the risk level assessment result. The geographical location abnormality can be that the geographical location information is an overseas address when the user is handling a domestic service, and risk level assessment is performed on this abnormal information, and the risk factor corresponding to the abnormal information is determined according to the risk level assessment result. The system running mode abnormality can be that the current device system running mode is root mode, and risk level assessment is performed on this abnormal information, and the risk factor corresponding to the abnormal information is determined according to the risk level assessment result.

[0043] The risk library is a library of events that can cause risks and is pre-established for users, and is matched with the device attribute information, and a risk factor can be generated according to the matching result. For example, when it is detected that the device attribute information is a device-initiated IP, the IP is compared with the blacklisted IP in the risk library, if the device-initiated IP is the same as any IP in the blacklist, the corresponding risk factor is generated, and if the device-initiated IP is not the same as the IP in the blacklist, the corresponding risk factor is not generated.

[0044] The abnormal information of the request time and the request type of the security authentication request can be a request time point abnormality, for example, the request time of the security authentication request is 2 a.m., and if the user has not previously made a security authentication request at this time, it will be marked as abnormal information, wherein the abnormal time period of different users can be determined according to different users, and the historical service execution time of each user is determined. The abnormal information of the request type can be that the current device is to initiate fingerprint verification, but the current device does not have a fingerprint collection device and cannot perform security authentication, which will be marked as abnormal information, and a risk factor is generated according to the marked abnormal information.

[0045] A risk factor coefficient is generated according to the risk factor generated from at least one of the device environment information, the user attribute information and the device attribute information. The risk factor is a condition that promotes or causes a risk event to occur, and different risk factors have different risk levels. By identifying multiple risk factors in the device environment information, the user attribute information and the device attribute information, and determining the corresponding risk factor weights of the multiple risk factors, the final risk factor coefficient is obtained by weighting calculation or addition of the multiple risk factor weights.

[0046] In some optional embodiments, the determining of the risk coefficient of the security authentication request based on the current state information and the attribute information comprises: inputting the device environment information, the business scenario information, the user attribute information and the device attribute information into a pre-trained risk identification model, and outputting the risk coefficient of the security authentication request.

[0047] Specifically, the risk identification model can be a model pre-trained according to a machine learning algorithm. The device environment information, the business scenario information, the user attribute information and the device attribute information are input into the risk identification model, and the risk identification model can obtain the risk coefficient of the security authentication request through real-time online calculation. The machine learning algorithm includes but is not limited to a learning model such as a deep neural network, a decision tree, a support vector machine (SVM) or a random forest. The current state information and the attribute information are trained offline to generate the risk identification model, and the corresponding information is input into the risk identification model online to obtain the risk coefficient.

[0048] Step 130: sending the target authentication strategy to the device, receiving authentication information fed back by the device, performing security authentication on each of the authentication information, and sending an authentication result to the device.

[0049] In this embodiment, the security authentication server sends the target authentication strategy to the device, and the device feeds back authentication information corresponding to the target authentication strategy to the security authentication server. The authentication information is generated by an information collection device on the device side. For example, face information collected by a camera, fingerprint information collected by a fingerprint recognizer, or sound information collected by a microphone, and the like, which can authenticate the identity of a user. The security authentication server performs security authentication on the authentication information. The security authentication specifically judges whether the authentication information fed back by the device matches the user's reserved information, and returns the security authentication result to the device.

[0050] Optionally, after the security authentication result is returned to the device, the device further performs a corresponding operation according to the received authentication result. Specifically, if the authentication result received by the device is that the authentication is passed, the device performs business processing. If the authentication result received by the device is that the authentication is not passed, the device initiates a security authentication request again, and returns to step 110 to continue the security authentication. It should be noted that during the business processing of the device, the authentication identifier and the business request are sent to the business server, so that the business server sends a verification request to the authentication server based on the authentication identifier, the authentication server feeds back the authentication result to the business server according to the authentication identifier, and the business server receives the authentication result corresponding to the authentication identifier, and responds to the business request when it is determined that the authentication result is that the authentication is passed, so as to ensure that the authentication information cannot be tampered with.

[0051] In some optional embodiments, the sending of the target authentication strategy to the device, the receiving of the authentication information fed back by the device, the security authentication of each of the authentication information, and the sending of the authentication result to the device comprise: generating an authentication identifier corresponding to the security authentication request, sending the target authentication strategy and the authentication identifier to the device; receiving the authentication information fed back by the device and the corresponding authentication identifier, performing security authentication on each of the authentication information based on the authentication identifier, and sending the authentication result and the authentication identifier to the device.

[0052] In the method, the authentication identifier is a string of characters generated by the security server according to the security authentication request, and the string of characters and the target authentication strategy are sent to the device, and the authentication information fed back by the device carries the corresponding string of characters of the authentication identifier.

[0053] Optionally, the authentication identifier is generated by using Token technology. Token is a kind of token, and when data request is performed, Token is carried, so that it is not necessary to perform verification on a username and a password.

[0054] Specifically, the device initiates a security authentication request, the security server receives the security authentication request sent by the device, receives a variable and saves the variable as Token in a database, sets the Token to a Session, the Session can store attributes and configuration information required by a user, intercepts each feedback of the device, and compares Token transmitted by the device with Token in the Session of the security server, if the Token is the same, the feedback is allowed, and if the Token is different, the feedback is rejected. The security authentication of each of the authentication information by using the authentication identifier can effectively guarantee that a transaction strategy and a transaction result are not tampered with, and guarantee the security of the transaction.

[0055] In some optional embodiments, the security authentication request and the current state information and attribute information of the device are subjected to encryption processing; after receiving the security authentication request and the current state information and attribute information of the device sent by the device, the method further comprises: performing decryption processing on the security authentication request and the current state information and attribute information of the device subjected to the encryption processing; and correspondingly, the sending of the target authentication strategy to the device, the receiving of the authentication information fed back by the device, the security authentication of each of the authentication information, and the sending of the authentication result to the device comprise: sending the target authentication strategy subjected to encryption processing to the device, receiving the encrypted authentication information fed back by the device, performing security authentication on each of the encrypted authentication information after decryption, and sending the authentication result subjected to encryption to the device, so that the device performs business processing after decryption of the received authentication result.

[0056] The encryption processing aims to protect the security authentication request sent by the device and the current state information and attribute information of the device from being stolen and prevent information forgery. The encryption processing and decryption processing can be symmetric encryption such as DES (Data Encryption Standard) algorithm or asymmetric encryption such as RSA (Rivest Shamir Adleman) algorithm, which is not limited in the embodiment.

[0057] The embodiment of the application provides a security authentication method, which receives a security authentication request sent by a device and current state information and attribute information of the device, determines a risk coefficient of the security authentication request based on the current state information and the attribute information, determines a target authentication strategy including at least one authentication type based on the risk coefficient, sends the target authentication strategy to the device, receives authentication information fed back by the device, performs security authentication on each authentication information, and sends an authentication result to the device, so that intelligent strategy selection is realized, the transaction security is ensured, and the user experience is improved.

[0058] Embodiment two

[0059] Figure 2 A flowchart of a security authentication method provided by the embodiment two of the application. The embodiment of the application can be combined with each optional scheme in one or more of the above embodiments. In the embodiment of the application, the target authentication strategy is determined based on the risk coefficient, including: obtaining a security coefficient corresponding to each combination of security authentication types, the combination of security authentication types including at least one authentication type; determining a combination of security authentication types with a security coefficient greater than or equal to the risk coefficient as a candidate authentication strategy, and determining a target authentication strategy based on the candidate authentication strategy.

[0060] As shown in FIG. 2, the method of the embodiment of the application specifically includes: Figure 2

[0061] Step 210: receiving a security authentication request sent by a device and current state information and attribute information of the device.

[0062] Step 220: determining a risk coefficient of the security authentication request based on the current state information and the attribute information, and determining a target authentication strategy based on the risk coefficient, wherein the target authentication strategy includes at least one authentication type.

[0063] Step 230: obtaining a security coefficient corresponding to each combination of security authentication types, the combination of security authentication types including at least one authentication type.

[0064] ​In this embodiment, the security authentication types can include, but are not limited to, face recognition, fingerprint recognition, voice recognition, iris recognition and other technologies that can realize security authentication. The security coefficients corresponding to the combinations of the pre-set security authentication types are coefficients for evaluating the security degrees of the combinations of the security authentication types. For example, face recognition can not be able to distinguish similar faces of twins well, and the security coefficient is 0.6. When face recognition and fingerprint recognition are combined for verification, the probability of being imitated or stolen is greatly reduced, and the security coefficient is marked as 0.8. The iris collected by the iris recognition technology is difficult to imitate, and the security coefficient is 0.9.

[0065] In step 240, the combinations of the security authentication types with the security coefficients greater than or equal to the risk coefficient are determined as candidate authentication strategies, and a target authentication strategy is determined based on the candidate authentication strategies.

[0066] For example, the risk coefficient determined according to the current state information and the attribute information of the device is 0.7. Different information schemes are combined. The security coefficient of the combination of face recognition and fingerprint recognition is 0.8, and the security coefficient of the iris recognition is 0.9, which is greater than the risk coefficient 0.7. Therefore, the above two schemes are determined as the candidate authentication strategies. The security coefficient of the scheme of only face recognition is 0.6, which is less than the risk coefficient 0.7. Therefore, the combination cannot become a candidate authentication strategy.

[0067] The target authentication strategy is determined based on the candidate authentication strategies. The candidate authentication strategies can be sorted according to the security coefficients. The candidate authentication strategy with the maximum security coefficient is determined as the target authentication strategy, so that the transaction security performance is maximized. The candidate authentication strategies can also be sorted according to the number of authentication types included in the combinations. The candidate authentication strategy with the least number of authentication types is determined as the target authentication strategy, so that the user operation is simplified while ensuring the transaction security.

[0068] Optionally, the security coefficient corresponding to any combination of the security authentication types is determined based on the weights of at least one authentication type included in the combination.

[0069] For example, the security coefficient of the combination of face recognition and fingerprint recognition is determined according to the weights of the security coefficients of face recognition and fingerprint recognition.

[0070] Optionally, the combinations of the security authentication types with the security coefficients greater than or equal to the risk coefficient are determined as the candidate authentication strategies, including: determining the executable combinations of the security authentication types according to the device models in the device attribute information, and determining the combinations of the security authentication types with the security coefficients greater than or equal to the risk coefficient in the executable combinations of the security authentication types as the candidate authentication strategies.

[0071] Exemplarily, the device model can be a mobile phone model, when it is detected that the mobile phone model is Samsung S9, the mobile phone supports the iris recognition function and the face recognition function, the two are combined to determine the candidate authentication strategy.

[0072] Optionally, the target authentication strategy is determined based on the candidate authentication strategy, including: generating a habit factor of the user according to the historical authentication record of the user, and determining the target authentication strategy from the multiple candidate authentication strategies based on the habit factor.

[0073] In the embodiment, the habit factor of the user is a user portrait formed by the security server according to historical transaction data of the user, which is mainly formed by combining the user transaction type, the device type, and the preference and success rate of various multi-modal verifications, and the habit factor can be a string, which can include the use frequency and success rate of each authentication type in the historical authentication record, and the candidate authentication strategy with higher use frequency and success rate is determined as the target authentication strategy. In the embodiment, the flexibility of selecting the target authentication strategy is improved through the analysis of the user habit, the authentication means is closer to the user habit under the premise of ensuring safety, and the user experience is improved.

[0074] Step 250: sending the target authentication strategy to the device, receiving the authentication information fed back by the device, performing security authentication on each authentication information, and sending the authentication result to the device.

[0075] The embodiment of the application provides a security authentication method, which receives a security authentication request sent by a device and current state information and attribute information of the device; determines a risk coefficient of the security authentication request based on the current state information and the attribute information, and determines a target authentication strategy including at least one authentication type based on the risk coefficient; sends the target authentication strategy to the device, receives authentication information fed back by the device, performs security authentication on each authentication information, and sends the authentication result to the device, so that intelligent strategy selection is realized, and the transaction security is ensured while the user experience is improved.

[0076] Embodiment three

[0077] Figure 3 A flowchart of a security authentication method provided by the embodiment one of the application, the embodiment of the application can be combined with each optional scheme in one or more of the above embodiments, and in the embodiment of the application, the following steps are specifically included:

[0078] Step 310: the security authentication request sent by the device and the current state information and attribute information of the device.

[0079] Step 320, the security authentication server receives the security authentication request and the current state information and attribute information of the device, determines the risk coefficient of the security authentication request based on the current state information and the attribute information, determines the target authentication strategy based on the risk coefficient, and sends the target authentication strategy to the device, wherein the target authentication strategy comprises at least one authentication type.

[0080] Step 330, the device prompts each authentication type in the target authentication strategy, collects authentication information corresponding to each authentication type, and sends each authentication information to the security authentication server.

[0081] Step 340, the security authentication server receives the authentication information fed back by the device, performs security authentication on each authentication information, and sends the authentication result to the device.

[0082] Step 350, the device receives the authentication result, and performs business processing when the authentication result is authentication success.

[0083] Specifically, the device receives the authentication result sent by the security service, and performs business processing when the authentication result is authentication success, and performs step 310 to re-perform security authentication when the authentication result fails.

[0084] The embodiment of the application provides a security authentication method, which comprises the following steps: a device sends a security authentication request and current state information and attribute information of the device; a security authentication server receives the security authentication request and the current state information and attribute information of the device, determines a risk coefficient of the security authentication request based on the current state information and the attribute information, determines a target authentication strategy based on the risk coefficient, and sends the target authentication strategy to the device, wherein the target authentication strategy comprises at least one authentication type; the device prompts each authentication type in the target authentication strategy, collects authentication information corresponding to each authentication type, and sends each authentication information to the security authentication server; the security authentication server receives the authentication information fed back by the device, performs security authentication on each authentication information, and sends the authentication result to the device; and the device receives the authentication result, and performs business processing when the authentication result is authentication success, so that intelligent strategy selection is realized, and the transaction security is ensured and the user experience is improved.

[0085] Embodiment four

[0086] Figure 4 A structural schematic diagram of a security authentication device provided by the embodiment four of the application is shown in the figure, Figure 4As shown, the device comprises: an information receiving module 410, a policy determining module 420, and an information authentication module 430.

[0087] The information receiving module 410 is configured to receive a security authentication request sent by a device and current state information and attribute information of the device.

[0088] The policy determining module 420 is configured to determine a risk coefficient of the security authentication request based on the current state information and the attribute information, and determine a target authentication policy based on the risk coefficient, wherein the target authentication policy comprises at least one authentication type.

[0089] The information authentication module 430 is configured to send the target authentication policy to the device, receive authentication information fed back by the device, perform security authentication on each of the authentication information, and send an authentication result to the device.

[0090] The embodiment of the application provides a security authentication device, which receives a security authentication request sent by a device and current state information and attribute information of the device, determines a risk coefficient of the security authentication request based on the current state information and the attribute information, determines a target authentication policy comprising at least one authentication type based on the risk coefficient, sends the target authentication policy to the device, receives authentication information fed back by the device, performs security authentication on each of the authentication information, and sends an authentication result to the device, so that intelligent policy selection is realized, and the user experience is improved while the transaction security is ensured.

[0091] In an optional implementation of the embodiment of the application, optionally, the current state information comprises device environment information and business scenario information; and the attribute information comprises user attribute information and device attribute information.

[0092] In an optional implementation of the embodiment of the application, optionally, the policy determining module 420 can comprise:

[0093] A scenario factor coefficient generating unit configured to generate a scenario factor coefficient based on the business scenario information;

[0094] A risk factor coefficient generating unit configured to generate a risk factor coefficient based on at least one of the device environment information, the user attribute information, and the device attribute information;

[0095] A risk coefficient generating unit configured to generate a risk coefficient of the security authentication request based on the scenario factor coefficient and the risk factor coefficient.

[0096] In an optional implementation of the embodiment of the application, optionally, the risk factor coefficient generating unit is configured to:

[0097] identify abnormal information in the device environment information, determine a risk factor based on the identified abnormal information; and / or,

[0098] match the device attribute information based on a preset risk library, and generate a risk factor according to a matching result; and / or,

[0099] determine whether the request time and the request type of the security authentication request include abnormal information based on the user attribute information, and generate a risk factor according to abnormal information of the security authentication request;

[0100] generate a risk factor coefficient based on each risk factor.

[0101] In an optional implementation of an embodiment of the present application, optionally, the policy determination module 420 can be configured to:

[0102] input the device environment information, the business scenario information, the user attribute information, and the device attribute information into a pre-trained risk identification model, and output a risk coefficient of the security authentication request.

[0103] In an optional implementation of an embodiment of the present application, optionally, the policy determination module 420 can include:

[0104] a security coefficient acquisition unit configured to acquire a security coefficient corresponding to each combination of security authentication types, the combination of security authentication types including at least one authentication type;

[0105] a target authentication policy determination unit configured to determine a combination of security authentication types with a security coefficient greater than or equal to the risk coefficient as a candidate authentication policy, and determine a target authentication policy based on the candidate authentication policy.

[0106] In an optional implementation of an embodiment of the present application, optionally, the security coefficient acquisition unit is specifically configured to determine the security coefficient corresponding to any combination of security authentication types based on a weight of at least one authentication type included in the combination.

[0107] In an optional implementation of an embodiment of the present application, optionally, the target authentication policy determination unit can be configured to:

[0108] determine a combination of executable security authentication types according to a device model in the device attribute information, and determine a combination of security authentication types with a security coefficient greater than or equal to the risk coefficient in the combination of executable security authentication types as a candidate authentication policy.

[0109] In an optional implementation of an embodiment of the present application, optionally, the target authentication policy determination unit can be configured to:

[0110] The habit factor of the user is generated according to historical authentication records of the user, and a target authentication strategy is determined from multiple candidate authentication strategies based on the habit factor.

[0111] In an optional implementation of the embodiments of the present application, optionally, the information authentication module 430 can be used for:

[0112] The target authentication strategy is sent to the device, authentication information fed back by the device is received, each piece of authentication information is subjected to security authentication, and an authentication result is sent to the device.

[0113] An authentication identifier corresponding to the security authentication request is generated, the target authentication strategy and the authentication identifier are sent to the device.

[0114] Authentication information fed back by the device and a corresponding authentication identifier are received, each piece of authentication information is subjected to security authentication based on the authentication identifier, and an authentication result and the authentication identifier are sent to the device.

[0115] As to the apparatus in the above-described embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and thus will not be described here in detail.

[0116] The security authentication apparatus can perform the security authentication method provided by any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of performing the security authentication method.

[0117] Embodiment Five

[0118] Figure 5 A structural schematic diagram of a security server provided by the fifth embodiment of the present application is shown. Figure 5 A block diagram of a security server 12 suitable for use in implementing embodiments of the present application is shown. Figure 5 The security server 12 shown is merely one example and should not be construed as limiting the scope of the functionality or use of embodiments of the present application.

[0119] As shown in Figure 5 The security server 12 is shown in the form of a general computing device. The components of the security server 12 can include, but are not limited to, one or more processors 16, storage 28, and a bus 18 connecting the various system components, including the storage 28 and the processor 16.

[0120] Bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration bus, a processor or local bus using any of a variety of bus architectures. By way of example, these architectures include Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0121] Security server 12 typically includes a number of computer system readable media. These media can be any available media that is accessible by security server 12 and includes both volatile and non-volatile media, removable and non-removable media.

[0122] Storage 28 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Security server 12 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 can be provided for reading from and writing to a non-removable, non-volatile magnetic media (not shown and typically called a "hard drive"). Figure 5 Although not shown, a magnetic disk drive can also be utilized in some embodiments to read from and write to a removable, non-volatile magnetic disk (e.g., a "floppy disk"), and an optical disk drive can be utilized in some embodiments to read from and write to a removable, non-volatile optical disk (e.g., a Figure 5 In such instances, each drive can be connected to the bus 18 by one or more data media interfaces. The storage 28 can include at least one program product having a set (e.g., at least one) of program modules that are configured to carry out the functions of embodiments of the application.

[0123] Program 42, having a set (at least one) of program modules 40, can be stored in storage 28, for example, as illustrated, such program modules 40 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, and each or a combination thereof can include implementation of the gateway environment. Program modules 40 generally carry out the functions and / or methodologies of embodiments described herein.

[0124] The security server 12 can also communicate with one or more external devices 14 such as a keyboard, a pointing device, a camera, a display 24, etc. which enable a user to interact with the security server 12 and / or any devices (e.g., a network card, a modem, etc.) that enable the security server 12 to communicate with one or more other computing devices. Such communication can occur via input / output (I / O) interface 22. Still yet, the security server 12 can communicate with one or more gateways (e.g., a Local Area Network (LAN), a Wide Area Network (WAN), and / or the Internet) through gateway adapter 20. As depicted, the gateway adapter 20 communicates with the other modules of the security server 12 through bus 18. It should be appreciated that although not shown, other hardware and / or software modules could be used in conjunction with the security server 12. Such as, but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, Redundant Arrays of Independent Disks (RAID) systems, tape drives, and data archival storage systems, etc.

[0125] The processor 16 performs a variety of functions as will be developed more fully below. These functions are implemented in software, firmware, hardware, or combinations thereof, which can be stored in the memory 28 and executed by the processor 16 as required.

[0126] Embodiment six

[0127] Embodiment six of the present application provides a storage medium, which has stored thereon a computer program, the program being executed by a processor to implement the security authentication method provided by the embodiments of the present application.

[0128] Of course, the computer program stored on the storage medium provided by the embodiments of the present application is not limited to the method operations described above, but can also execute the security authentication method provided by any of the embodiments of the present application.

[0129] The storage medium of the embodiments of the present application can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination thereof. More specific examples (non-exhaustive list) of the computer-readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus or device.

[0130] The computer-readable signal medium can include a computer-readable source code in a baseband or as part of a carrier wave propagating through a transmission medium, in which the computer-readable source code is carried. Such a propagating computer-readable signal medium can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate or transmit the program for use by or in connection with an instruction execution system, apparatus or device.

[0131] The source code contained in the computer-readable medium can be transmitted in any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination thereof.

[0132] The computer source code for performing the operations of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" language or similar programming languages. The source code can be executed entirely on the user computer, partially on the user computer, as a separate software package, partially on the user computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user computer through any kind of gateway, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).

[0133] Note that the above merely describes preferred embodiments of the present application and the principles of the technology applied. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, modifications and substitutions can be made without departing from the scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the claims.

Claims

1. A security authentication method characterized by, The method comprises the following steps: receiving a security authentication request sent by a device, and current state information and attribute information of the device, wherein the current state information comprises device environment information and service scenario information, different service scenario information corresponds to different transaction types, and the attribute information comprises user attribute information and device attribute information; determining a risk coefficient of the security authentication request based on the current state information and the attribute information, and determining a target authentication strategy based on the risk coefficient, wherein the target authentication strategy comprises at least one authentication type; sending the target authentication strategy to the device, receiving authentication information fed back by the device, performing security authentication on each authentication information, and sending an authentication result to the device; wherein the determination of the risk coefficient of the security authentication request based on the current state information and the attribute information comprises: generating a scenario factor coefficient based on the service scenario information; generating a risk factor coefficient based on at least one of the device environment information, the user attribute information and the device attribute information; generating a risk coefficient of the security authentication request based on the scenario factor coefficient and the risk factor coefficient; wherein the determination of the target authentication strategy based on the risk coefficient comprises: obtaining a security coefficient corresponding to each combination of security authentication types, wherein each combination of security authentication types comprises at least one authentication type, and the security coefficient corresponding to any combination of security authentication types is determined based on the weight of at least one authentication type included in the combination; determining a combination of executable security authentication types according to the device model in the device attribute information, and determining a combination of security authentication types with a security coefficient greater than or equal to the risk coefficient in the combination of executable security authentication types as a candidate authentication strategy; generating a habit factor of the user according to the historical authentication record of the user, and determining a target authentication strategy in multiple candidate authentication strategies based on the habit factor, wherein the habit factor of the user is a user portrait formed by the security server based on the user's historical transaction type, device type, preference for various multi-modal verification and success rate.

2. The method of claim 1, wherein, The generation of the risk factor coefficient based on at least one of the device environment information, the user attribute information and the device attribute information comprises: identifying abnormal information in the device environment information, and determining a risk factor based on the identified abnormal information; and / or, matching the device attribute information based on a preset risk library, and generating a risk factor according to the matching result; and / or, determining whether the request time and the request type of the security authentication request include abnormal information based on the user attribute information, and generating a risk factor according to the abnormal information of the security authentication request; generating a risk factor coefficient based on each risk factor.

3. The method of claim 1, wherein, The determination of the risk coefficient of the security authentication request based on the current state information and the attribute information further comprises: inputting the device environment information, the service scenario information, the user attribute information and the device attribute information into a pre-trained risk identification model, and outputting the risk coefficient of the security authentication request.

4. The method of claim 1, wherein, The target authentication strategy is sent to the device, and authentication information fed back by the device is received, each authentication information is securely authenticated, and an authentication result is sent to the device. An authentication identifier corresponding to the secure authentication request is generated, and the target authentication strategy and the authentication identifier are sent to the device. The authentication information fed back by the device and the corresponding authentication identifier are received, each authentication information is securely authenticated based on the authentication identifier, and the authentication result and the authentication identifier are sent to the device.

5. The method of claim 1, wherein, The secure authentication request and the current state information and attribute information of the device are encrypted; After receiving the secure authentication request and the current state information and attribute information of the device sent by the device, the encrypted secure authentication request and the current state information and attribute information of the device are decrypted; Correspondingly, the target authentication strategy is sent to the device, and authentication information fed back by the device is received, each authentication information is securely authenticated, and an authentication result is sent to the device. The target authentication strategy is encrypted and sent to the device, and encrypted authentication information fed back by the device is received, each encrypted authentication information is decrypted and securely authenticated, and an authentication result is encrypted and sent to the device, so that the device decrypts the received authentication result and performs business processing.

6. A security authentication method characterized by, It includes: The secure authentication request and the current state information and attribute information of the device sent by the device, wherein the current state information includes device environment information and business scenario information, and different business scenario information corresponds to different transaction types; the attribute information includes user attribute information and device attribute information; The secure authentication server receives the secure authentication request and the current state information and attribute information of the device, determines the risk coefficient of the secure authentication request based on the current state information and the attribute information, determines the target authentication strategy based on the risk coefficient, and sends the target authentication strategy to the device, wherein the target authentication strategy includes at least one authentication type; The device prompts each authentication type in the target authentication strategy, collects authentication information corresponding to each authentication type, and sends each authentication information to the secure authentication server; The secure authentication server receives the authentication information fed back by the device, securely authenticates each authentication information, and sends an authentication result to the device; The device receives the authentication result, and performs business processing when the authentication result is authentication success; The risk coefficient of the secure authentication request is determined based on the current state information and the attribute information, including: A scene factor coefficient is generated based on the business scenario information; A risk factor coefficient is generated based on at least one of the device environment information, the user attribute information and the device attribute information; A risk coefficient of the secure authentication request is generated based on the scene factor coefficient and the risk factor coefficient; The target authentication strategy is determined based on the risk coefficient, including: obtain a security coefficient corresponding to each combination of security authentication types, the combination of security authentication types including at least one authentication type, the security coefficient corresponding to any combination of security authentication types being determined based on the weight of the at least one authentication type included in the combination; determine a combination of executable security authentication types according to the device model in the device attribute information, and determine a combination of security authentication types with a security coefficient greater than or equal to the risk coefficient in the combination of executable security authentication types as a candidate authentication strategy; generate a habit factor of the user according to the historical authentication record of the user, and determine a target authentication strategy from the multiple candidate authentication strategies based on the habit factor, wherein the habit factor of the user is a user portrait formed by the security server based on the user's historical transaction type, device type, and preference and success rate of each type of multi-modal verification.

7. A security authentication apparatus characterized by comprising: comprise: an information receiving module configured to receive a security authentication request sent by a device and current state information and attribute information of the device, wherein the current state information includes device environment information and business scenario information, different business scenario information corresponding to different transaction types, and the attribute information includes user attribute information and device attribute information; a strategy determining module configured to determine a risk coefficient of the security authentication request based on the current state information and the attribute information, and determine a target authentication strategy based on the risk coefficient, wherein the target authentication strategy includes at least one authentication type; an information authentication module configured to send the target authentication strategy to the device, receive authentication information fed back by the device, perform security authentication on each authentication information, and send an authentication result to the device; wherein the strategy determining module comprises: a scenario factor coefficient generating unit configured to generate a scenario factor coefficient based on the business scenario information; a risk factor coefficient generating unit configured to generate a risk factor coefficient based on at least one of the device environment information, the user attribute information, and the device attribute information; a risk coefficient generating unit configured to generate a risk coefficient of the security authentication request based on the scenario factor coefficient and the risk factor coefficient; a security coefficient obtaining unit configured to obtain a security coefficient corresponding to each combination of security authentication types, the combination of security authentication types including at least one authentication type, the security coefficient corresponding to any combination of security authentication types being determined based on the weight of the at least one authentication type included in the combination; The target authentication strategy determination unit is configured to determine a combination of executable security authentication types according to the device model in the device attribute information, determine a combination of security authentication types with a security coefficient greater than or equal to the risk coefficient in the combination of executable security authentication types as a candidate authentication strategy, generate a habit factor of the user according to the historical authentication record of the user, and determine a target authentication strategy in multiple candidate authentication strategies based on the habit factor, wherein the habit factor of the user is a user portrait formed by the security server according to the historical transaction type of the user, the device type, the preference of various multi-modal verifications, and the success rate.

8. A secure authentication server comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, The processor executes the computer program to implement the security authentication method in any one of claims 1-6.

9. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the security authentication method in any one of claims 1-6.

Citation Information

Patent Citations

  • Security authentication method, equipment, device and storage medium

    CN110232270A

  • Security authentication method, device and system and mobile terminal

    CN110798432A