User Login Request Processing Method, Device and Equipment Based on Device Credibility

By obtaining and comparing the user's device fingerprint, generating a credibility score, and processing user login requests, the problem of user login verification affecting experience and high data call costs in the prior art is solved, and the user's secure and fast login and information data security is achieved.

CN114357403BActive Publication Date: 2025-05-27SHANGHAI QIYUE INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111590648.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-23
Publication Date
2025-05-27
Estimated Expiration
2041-12-23

AI Technical Summary

Technical Problem

The prior art causes poor user experience through facial recognition and other verification methods when users log in, and the data call costs are high, making it difficult to effectively control security risks.

Method used

By obtaining the user's login request, obtaining user information and current device fingerprint, and comparing it with the historical device fingerprint, determining the credibility of the current device, entering the account credibility model to generate a credibility score, and processing the login request based on the score.

Benefits of technology

On the basis of not affecting the user's login experience, users can log in safely and quickly, ensuring the security of user information and system data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114357403B_ABST
    Figure CN114357403B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method, apparatus, electronic device, and computer-readable medium for processing a user login request based on device credibility. The method includes: obtaining a user login request; obtaining the user's user information and the current device fingerprint through the login request; comparing the current device fingerprint with the user's historical device fingerprints to determine the current device credibility of the user; inputting the current device credibility and the user information into an account credibility model to generate a credibility score; and processing the user's login request according to the credibility score. The method, apparatus, electronic device, and computer-readable medium for processing a user login request based on device credibility according to the present disclosure can assist the user in logging in safely and quickly without affecting the user's login experience, and can ensure both user information security and system data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer information processing, and in particular, to a method, apparatus, electronic device, and computer-readable medium for processing a user login request based on device credibility. Background Art

[0002] Risk control is that risk managers adopt various measures and / or methods to eliminate or reduce the possibility of risk events occurring, or risk managers adopt various measures and / or methods to reduce the losses caused when risk events occur. In order to avoid security risks, risk control is often assisted by verification when a user logs in. When a user conducts financial transactions or other fund-related behaviors, it is necessary to confirm that it is the authorized operation of the customer himself. Generally speaking, common technologies can strengthen verification through face recognition. However, in the actual application process, strengthening verification for each user behavior will have a negative impact on user experience and product conversion, and the continuously accumulating data call cost of face verification brings huge pressure to financial service companies.

[0003] Therefore, a new method, apparatus, electronic device, and computer-readable medium for processing a user login request based on device credibility are needed.

[0004] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure, and thus it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] In view of this, the present disclosure provides a method, apparatus, electronic device, and computer-readable medium for processing a user login request based on device credibility, which can assist users to log in safely and quickly without affecting the user login experience, and can ensure both user information security and system data security.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be learned in part through the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, a method for processing a user login request based on device credibility is proposed. The method includes: obtaining a user login request; obtaining user information and a current device fingerprint of the user through the login request; comparing the current device fingerprint with the historical device fingerprint of the user to determine the current device credibility of the user; inputting the current device credibility and the user information into an account credibility model to generate a credibility score; and processing the user login request according to the credibility score.

[0008] Optionally, it further includes: determining the historical device fingerprint of the user and its corresponding credibility.

[0009] Optionally, determine the historical device fingerprint of the user and its corresponding credibility. This includes: obtaining the user's historical login information and historical user information; generating the user's historical device fingerprint based on the historical login information; generating the credibility corresponding to the historical device fingerprint based on the historical user information.

[0010] Optionally, it further includes: obtaining the historical device fingerprint of a historical user; obtaining the historical user information of the historical user, where the historical user information includes historical behavior information; associating the historical device fingerprint with the historical behavior information; training a machine learning model based on the historical device fingerprint and the historical behavior information to generate the account credibility model.

[0011] Optionally, training a machine learning model based on the historical device fingerprint and the historical behavior information to generate the account credibility model includes: generating historical feature information through the historical behavior information; determining a sample label for the historical feature information according to a predetermined behavior in the historical behavior information and the historical device fingerprint; training the machine learning model with the historical feature information with sample labels to generate the account credibility model.

[0012] Optionally, training the machine learning model with the historical feature information with sample labels to generate the account credibility model includes: dividing the historical feature information into multiple fingerprint feature information sets according to the time period corresponding to the historical device fingerprint; training the machine learning model with the multiple fingerprint feature information sets to generate the account credibility model.

[0013] Optionally, when the user logs in to a preset application scenario, read the current device fingerprint at a predetermined location; when the current device fingerprint does not exist at the predetermined location, obtain the device information of the current device and encrypt the device information according to a preset algorithm to generate the device fingerprint of the current device; store the device fingerprint of the current device in the current device.

[0014] Optionally, processing the user's login request according to the credibility score includes: when the credibility score is in the first score interval, invoking the face recognition application and the password recognition application to process the login request; when the credibility score is in the second score interval, invoking the password recognition application to process the login request; when the credibility score is in the third score interval, allowing the user to log in.

[0015] Optionally, it includes: after the user successfully logs in, updating the credibility of the historical device fingerprint corresponding to the user based on the user's behavior information.

[0016] According to one aspect of the present disclosure, there is provided a user login request processing device based on device credibility, the device comprising: a request module for obtaining a user login request; a fingerprint module for obtaining user information and a current device fingerprint of the user through the login request; a credibility module for comparing the current device fingerprint with the user's historical device fingerprints to determine the current device credibility of the user; a scoring module for inputting the current device credibility and the user information into an account credibility model to generate a credibility score; and a login module for processing the user's login request according to the credibility score.

[0017] According to one aspect of the present disclosure, there is provided an electronic device, the electronic device comprising: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above.

[0018] According to one aspect of the present disclosure, there is provided a computer-readable medium having stored thereon a computer program which, when executed by a processor, implements the method as described above.

[0019] According to the user login request processing method, device, electronic device and computer-readable medium based on device credibility of the present disclosure, by obtaining a user login request; obtaining user information and a current device fingerprint of the user through the login request; comparing the current device fingerprint with the user's historical device fingerprints to determine the current device credibility of the user; inputting the current device credibility and the user information into an account credibility model to generate a credibility score; and processing the user's login request according to the credibility score, it is possible to assist the user to log in safely and quickly without affecting the user's login experience, and both ensure the security of user information and the security of system data.

[0020] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] By referring to the accompanying drawings and describing in detail its exemplary embodiments, the above and other objectives, features and advantages of the present disclosure will become more apparent. The following described drawings are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0022] Figure 1 is a system block diagram of a user login request processing method and device based on device credibility shown according to an exemplary embodiment.

[0023] Figure 2It is a flowchart of a method for processing a user login request based on device credibility shown according to an exemplary embodiment.

[0024] Figure 3 It is a flowchart of a method for processing a user login request based on device credibility shown according to another exemplary embodiment.

[0025] Figure 4 It is a flowchart of a method for processing a user login request based on device credibility shown according to another exemplary embodiment.

[0026] Figure 5 It is a block diagram of a device for processing a user login request based on device credibility shown according to an exemplary embodiment.

[0027] Figure 6 It is a block diagram of an electronic device shown according to an exemplary embodiment.

[0028] Figure 7 It is a block diagram of a computer-readable medium shown according to an exemplary embodiment. Detailed implementation manners

[0029] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Identical reference numerals in the figures denote identical or similar parts, and thus their repetitive description will be omitted.

[0030] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will realize that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present disclosure.

[0031] The block diagrams shown in the drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0032] The flowcharts shown in the accompanying drawings are merely illustrative and not necessarily inclusive of all content and operations / steps, nor are they necessarily to be executed in the order described. For example, some operations / steps may be decomposed, while some operations / steps may be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.

[0033] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below may be referred to as the second component without departing from the teachings of the present disclosure concept. As used herein, the term "and / or" includes any one and all combinations of one or more of the associated listed items.

[0034] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing the present disclosure. Therefore, they cannot be used to limit the protection scope of the present disclosure.

[0035] The innovation of the present disclosure lies in how to use the information interaction technology between the server and the client to make the processing of user login applications more automated, efficient, and reduce labor costs. Thus, essentially, the present disclosure can be applied to the processing of various login requests. However, for convenience, the present disclosure is described by taking a financial service institution as an example. Those skilled in the art should understand that the present disclosure can also be used in other fields.

[0036] The method for processing user login requests based on device credibility provided by the embodiments of the present disclosure is applicable to any one of multiple application fields such as investment, banking, insurance, securities, and e-commerce. In each application field, the application scenarios involved may include, but are not limited to, login, registration, pre-loan, in-loan, post-loan, holiday activities, or promotional activities, etc.

[0037] Figure 1 It is a system block diagram of a method and device for processing user login requests based on device credibility shown according to an exemplary embodiment.

[0038] As Figure 1 shown, the system architecture 10 may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0039] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as financial service applications, shopping applications, web browser applications, instant messaging tools, email clients, social platform software, etc.

[0040] Terminal devices 101, 102, and 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop computers, and desktop computers, etc.

[0041] Terminal devices 101, 102, and 103 can, for example, obtain the user's login request; terminal devices 101, 102, and 103 can, for example, obtain the user's user information and the current device fingerprint through the login request; the device fingerprint refers to the device characteristics or unique device identifier that can be used to uniquely identify the device.

[0042] Terminal devices 101, 102, and 103 can, for example, compare the current device fingerprint with the user's historical device fingerprints to determine the current device credibility of the user; terminal devices 101, 102, and 103 can, for example, input the current device credibility and the user information into an account credibility model to generate a credibility score; terminal devices 101, 102, and 103 can, for example, process the user's login request according to the credibility score.

[0043] Server 105 can be a server that provides various services, such as a back-end management server that provides login support for financial service websites browsed by users using terminal devices 101, 102, and 103. The back-end management server can analyze and process the received user login request and feedback the processing result (whether to allow login) to terminal devices 101, 102, and 103.

[0044] Server 105 can, for example, obtain the user's login request; server 105 can, for example, obtain the user's user information and the current device fingerprint through the login request; server 105 can, for example, compare the current device fingerprint with the user's historical device fingerprints to determine the current device credibility of the user; server 105 can, for example, input the current device credibility and the user information into an account credibility model to generate a credibility score; server 105 can, for example, process the user's login request according to the credibility score.

[0045] Server 105 can also, for example, determine the user's historical device fingerprint and its corresponding credibility.

[0046] The server 105 may also, for example, obtain the historical device fingerprints of historical users; obtain the historical user information of the historical users, where the historical user information includes historical behavior information; associate the historical device fingerprints with the historical behavior information; and train a machine learning model based on the historical device fingerprints and the historical behavior information to generate the account credibility model.

[0047] The server 105 may be a physical server or, for example, composed of multiple servers. It should be noted that the method for processing user login requests based on device credibility provided in the embodiments of the present disclosure may be executed by the server 105 and / or the terminal devices 101, 102, 103. Correspondingly, the device for processing user login requests based on device credibility may be disposed in the server 105 and / or the terminal devices 101, 102, 103. The web page for providing users to browse the financial service platform is generally located in the terminal devices 101, 102, 103.

[0048] Figure 2 It is a flowchart of a method for processing user login requests based on device credibility shown according to an exemplary embodiment. The method 20 for processing user login requests based on device credibility includes at least steps S202 to S208.

[0049] As Figure 2 shown, in S202, a login request of a user is obtained. As described above, the login request may be generated when the user performs a resource operation or other operations involving resource security. More specifically, in daily use, the user may log in to a preset application in a quick login manner, and basic operations may be performed on the preset application, such as viewing the hot news of the day and viewing personal information. When the user needs to use the resources in the electronic account or wants to view information related to the resources, a login request may be generated, and the login request is used to re-verify the user to ensure the security of the resource data.

[0050] In the embodiments of the present disclosure, the user may be an individual user or an enterprise user, and the resources may be financial resources or may also be power resources and water resources.

[0051] In S204, user information and the current device fingerprint of the user are obtained through the login request. The device fingerprint can be obtained based on the login request through a hybrid fingerprint acquisition technology. When the user's current device logs in to the application for the first time, that is, when there is no current device fingerprint at a predetermined location, the device information of the current device is obtained, and the device information is encrypted according to a preset algorithm to generate the device fingerprint of the current device; the device fingerprint of the current device is stored in the current device. When the user uses the current device to log in to the preset application scenario again, the current device fingerprint is read at the predetermined location. An expiration period can also be set for the device fingerprint. After the expiration period, the current fingerprint becomes invalid. When the current device logs in to the application again, the device fingerprint needs to be calculated again based on the device information. This method can ensure the security and timeliness of the device fingerprint.

[0052] The hybrid fingerprint acquisition technology generates the device fingerprint of the user through the combination of active acquisition and server-side algorithms. For example, by implanting the SDK and JS, and setting up data collection points in fixed business scenarios, when the business scenario is triggered, the elements are actively collected and interacted with the server. After being encrypted by the algorithm, a unique device fingerprint ID is generated on the server side, and at the same time, the unique ID is written and stored in the app application cache or browser cookie. Within a certain period of time, when the user uses the corresponding business data collection page again, there is no need to upload a large number of collection elements again. Only the change ratio of the elements needs to be compared. Through weighted comparison, the confidence value is calculated, and it is judged whether to regenerate the device fingerprint code through a threshold. In theory, normal users are unaware during use and rarely actively tamper with the unique ID of the device fingerprint.

[0053] The hybrid device fingerprint technology overcomes the inherent disadvantages of the active device fingerprint and passive device fingerprint technologies respectively, and expands the applicable range of the device fingerprint technology while accurately identifying the device. For application scenarios within a Web page or an App, the active device fingerprint technology can be used for rapid device identification; while for device identification and comparison associations between different browsers, between a Web page and an App, the technical advantages of the passive device fingerprint can be utilized to achieve this.

[0054] The collection elements are the hardware itself information and software setting information in the device. Common element examples are as follows:

[0055] IMEI: International Mobile Equipment Identity, the international mobile device identification serial number stored in the mobile phone.

[0056] IDFA: Identifier For Advertising, the advertising identifier unique to iOS.

[0057] UDID: Unique Device Identifier, the unique device identification code.

[0058] MEID number: The Mobile Equipment Identifier is the identification code of a CDMA mobile phone and is also the unique identification code for each CDMA mobile phone or communication tablet.

[0059] In S206, the current device fingerprint of the device is compared with the historical device fingerprints of the user to determine the credibility of the user's current device. A user can log in to an application through multiple devices, and each device that has been used is stored as a historical device of the user. Multiple historical device fingerprints and their corresponding credibility levels can be stored in a device confidence table in advance. The current device fingerprint is compared with the user's historical device fingerprints. When there is a matching result between the current device and the user's historical device fingerprints, it is considered that the current device is one of the historical devices that the user has used before, and the credibility score corresponding to the historical device is used as the credibility of the current device. If there is no matching data in history, it is defaulted that the current device is not credible, and a default credibility score is given or it is left blank.

[0060] In S208, the current device credibility and the user information are input into an account credibility model to generate a credibility score. Based on the current device credibility and user information, a pre-trained account credibility model can be invoked to obtain the credibility score of the user.

[0061] In S210, the login request of the user is processed according to the credibility score. When the credibility score is in the first score range, the face recognition application and the password recognition application are invoked to process the login request; when the credibility score is in the second score range, the password recognition application is invoked to process the login request; when the credibility score is in the third score range, the user is allowed to log in.

[0062] More specifically, the above account credibility score data can be applied to various business scenarios. Considering the particularities of each business and process, the account credibility score threshold can be appropriately and differentially adjusted to divide high, medium, and low-risk accounts, and different management methods can be adopted:

[0063] 1) High-risk accounts: Accounts with a low predicted credibility by the model, with a high possibility of being manipulated by someone other than the user. The user needs to strengthen the verification of the face or face + transaction password on the client side to identify their identity. After the user submits, for abnormal face verification results, manual real-time review is used to assist in judging whether it is the user himself;

[0064] 2) Medium-risk accounts: Accounts with a general predicted credibility by the model. The user can verify the transaction password or dynamic code, and the account risk is eliminated after successful verification;

[0065] 3) Low-risk accounts: Accounts with a high credibility prediction by the model can default to excluding account risks without other auxiliary authentication.

[0066] In one embodiment, it further includes: after the user successfully logs in, updating the credibility of the historical device fingerprint corresponding to the user based on the user's behavior information. After the account can be managed hierarchically, according to the hierarchical management result, if the account risk is excluded, the current behavior is passed; if there is a risk, it is directly rejected.

[0067] In view of the change of user behavior, in order to effectively identify the account credibility subsequently, it is necessary to update all historical device credibility score data of the account in real time. In this process, for the devices of all historical behaviors of the account, the corresponding behavior characteristics, the results of hierarchical management measures, etc., integrate data and characteristics step by step and establish a scoring system, use data mining and analysis tools to recalculate the score or credibility division of all devices currently used by the account, and update the retained data in the background for risk control invocation when the user logs in subsequently.

[0068] According to the method for processing a user login request based on device credibility of the present disclosure, obtain the user's login request; obtain the user's information and the current device fingerprint through the login request; compare the current device fingerprint with the user's historical device fingerprint to determine the current device credibility of the user; input the current device credibility and the user's information into the account credibility model to generate a credibility score; according to the manner of processing the user's login request based on the credibility score, it can assist the user to log in safely and quickly without affecting the user's login experience, and can ensure both user information security and system data security.

[0069] The method for processing a user login request based on device credibility of the present disclosure, which involves a risk management method for a trusted account system, comprehensively considers the user's historical devices and behavior data, uses the method of data mining to score the user behavior credibility, and adopts differential customer authentication strategies for high, medium, and low-risk behaviors to confirm the operation of the customer himself.

[0070] The method for processing a user login request based on device credibility of the present disclosure solves the account security problem, distinguishes the true and false identity of the account user, and avoids the risk of account theft, that is, others operate the customer's account, resulting in potential financial or compliance risks.

[0071] It is clearly understood that the present disclosure describes how to form and use specific examples, but the principles of the present disclosure are not limited to any details of these examples. On the contrary, based on the teachings of the content disclosed in the present disclosure, these principles can be applied to many other embodiments.

[0072] Figure 3It is a flowchart of a method for processing a user login request based on device credibility shown according to another exemplary embodiment. Figure 3 The shown process 30 is a detailed description of "determining the historical device fingerprint of the user and its corresponding credibility".

[0073] As Figure 3 shown, in S302, the historical login information and historical user information of the user are obtained. Among them, the historical login information may include fingerprint information and time information of the login device; the user information of the historical user may be the information publicly available by the user on the application, and may include basic information, such as business account information, terminal device identification information of the user, geographical location information of the user, etc.; the user information may also include behavior information, such as page operation data of the user, business access duration of the user, business access frequency of the user, etc. The specific content of the user information can be determined according to the actual application scenario and is not limited here. More specifically, the user information of the current user can be obtained by using the method of web page embedding points based on user authorization. The remote information may be the user data of the user on other trading platforms or other business departments.

[0074] More specifically, the behavior information of the user on the website can be obtained through the Fiddler tool. The Fiddler tool works in the form of a web proxy server. After the client sends the request data, the Fiddler proxy server will intercept the data packet, and then the proxy server will impersonate the client and send the data to the server; similarly, when the server returns the response data, the proxy server will also intercept the data and then return it to the client. Through Fiddler, the residence time, residence page, click operations, and other related browsing data of the user's network browsing can be obtained.

[0075] In S304, the historical device fingerprint of the user is generated based on the historical login information. More specifically, the historical device fingerprint can be generated based on device information, login time, location, and other information.

[0076] In S306, the credibility corresponding to the historical device fingerprint is generated based on the historical user information. The device fingerprint and the corresponding credibility data of the account historical behavior are retained in the background. The current device fingerprint is cross-compared with the user historical data to obtain the credibility score of this device in history. If there is no matching data in history, it is defaulted that the current device is not credible, and a default credibility score is given or it is empty.

[0077] Figure 4 It is a flowchart of a method for processing a user login request based on device credibility shown according to another exemplary embodiment. Figure 4 The shown process 40 is a detailed description of "generating the account credibility model".

[0078] AsFigure 4 As shown, in S402, obtain the historical device fingerprint of the historical user.

[0079] In S404, obtain the historical user information of the historical user, where the historical user information includes historical behavior information.

[0080] In S406, associate the historical device fingerprint with the historical behavior information.

[0081] In S408, train a machine learning model according to the historical device fingerprint and the historical behavior information to generate the account credibility model. The device credibility results described above can be comprehensively combined with the behavior data of the entire account system, including but not limited to financial transaction and non-financial transaction behavior data and features such as login, credit granting, transaction, password modification, etc., and use data mining and strategy analysis methods to construct an account credibility scoring model with the goal of account theft risk.

[0082] For example, historical feature information can be generated through the historical behavior information; sample labels can be determined for the historical feature information according to the predetermined behavior in the historical behavior information and the historical device fingerprint; the machine learning model can be trained with the historical feature information with sample labels to generate the account credibility model.

[0083] Multiple feature information can be generated based on the user information and feature strategy. The user information can be cleaned and fused to convert the user information into multiple feature data. More specifically, variable missing rate analysis and processing, outlier processing can be performed on the user information; WOE transformation of continuous variable discretized user information, WOE transformation of discrete variables, text variable processing, word2vec processing of text variables, etc. can also be performed.

[0084] In one embodiment, for example, calculate the key degree indicators of at least one basic information and at least one behavior information in the user information; extract partial information from the historical user information based on the key degree indicators to generate multiple historical feature information. Generate the feature strategy based on the relationship between the multiple historical feature information and the historical user information.

[0085] More specifically, calculate the variable parameters, discrimination parameters, information value, and model feature parameters of the multiple historical feature information; extract multiple historical multi-dimensional feature information from the multiple historical feature information based on the variable parameters, the discrimination parameters, the information value, and the model feature parameters.

[0086] Comprehensive consideration can be given to aspects such as variable coverage, single - value coverage, correlation and significance with the target variable, discrimination degree (KS) and information value (IV) for the target variable, and feature importance of tree - based models (such as XGBoost, RF, etc.). Select features with high coverage and obvious discrimination effect on the target variable as the final user features used. And generate the feature strategy based on the relationship between the multiple historical feature information and the historical user information.

[0087] Fuse the historical user information to form a wide - table variable with tens of thousands of dimensions, and further clean and process the data to ensure the stability and accuracy of the later model. The data cleaning steps include but are not limited to variable missing rate analysis and processing, outlier processing, discretization and WOE transformation of continuous variables, WOE transformation of discrete variables, text variable processing, etc. Comprehensive consideration can be given to aspects such as variable coverage, single - value coverage, correlation and significance with the target variable, discrimination degree (KS) and information value (IV) for the target variable, and feature importance of tree - based models (such as XGBoost, RF, etc.). Select features with high coverage and obvious discrimination effect on the target variable as the feature information.

[0088] Among them, training the machine - learning model with the historical feature information with sample labels to generate the account credibility model includes: dividing the historical feature information into multiple fingerprint feature information sets according to the time period corresponding to the historical device fingerprint; training the machine - learning model with the multiple fingerprint feature information sets to generate the account credibility model.

[0089] Specifically, for each fingerprint feature information set, an adjustment model is constructed respectively. Input each user feature in the fingerprint feature information set into the adjustment model to obtain a predicted label. Compare the predicted label with the corresponding true label to determine whether they are consistent. Count the number of predicted labels that are consistent with the true label, and calculate the proportion of the number of predicted labels that are consistent with the true label in the total number of predicted labels. If the proportion is greater than or equal to the preset proportion value, the adjustment model converges, and the trained account credibility model is obtained. If the proportion is less than the preset proportion value, adjust the parameters in the adjustment model, and re - predict the predicted labels of each object through the adjusted adjustment model until the proportion is greater than or equal to the preset proportion value. Among them, the method of adjusting the parameters in the adjustment model can use the stochastic gradient descent algorithm, the gradient descent algorithm or the normal equation.

[0090] If the number of times of adjusting the parameters of the adjustment model exceeds the preset number of times, the model used to construct the adjustment model can be replaced to improve the model training efficiency.

[0091] The disclosed method for processing user login requests based on device credibility aims to refine the management of account security risks. First, it combines the account behavior authentication results to quasi-real-time update the account's trusted device data, which improves the timeliness of online real-time evaluation of device credibility to a certain extent and has a high reliability. Additionally, through hierarchical management of trusted accounts, for different business scenarios, different account risk levels can have differential requirements for supplementary identity information verification, rather than directly rejecting risky transactions. When the account security is controllable, the business efficiency is improved.

[0092] Those skilled in the art can understand that all or part of the steps for implementing the above embodiments are realized as a computer program executed by a CPU. When the computer program is executed by the CPU, it executes the above functions defined by the above method provided by the present disclosure. The program can be stored in a computer-readable storage medium, which can be a read-only memory, a disk, an optical disc, or the like.

[0093] In addition, it should be noted that the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed, for example, synchronously or asynchronously in multiple modules.

[0094] The following is an embodiment of the device of the present disclosure, which can be used to execute the method embodiment of the present disclosure. For the details not disclosed in the embodiment of the device of the present disclosure, please refer to the method embodiment of the present disclosure.

[0095] Figure 5 is a block diagram of a device for processing user login requests based on device credibility shown according to an exemplary embodiment. As Figure 5 shown, the device 50 for processing user login requests based on device credibility includes: a request module 502, a fingerprint module 504, a credibility module 506, a scoring module 508, and a login module 510.

[0096] The request module 502 is used to obtain the user's login request;

[0097] The fingerprint module 504 is used to obtain the user's information and the current device fingerprint through the login request;

[0098] The credibility module 506 is used to compare the current device fingerprint with the user's historical device fingerprints to determine the current device credibility of the user;

[0099] The scoring module 508 is used to input the current device credibility and the user information into an account credibility model to generate a credibility score;

[0100] The login module 510 is used to process the user's login request according to the credibility score.

[0101] According to the user login request processing device based on device credibility of the present disclosure, a user's login request is obtained; user information of the user and a current device fingerprint are obtained through the login request; the current device fingerprint is compared with the user's historical device fingerprints to determine the current device credibility of the user; the current device credibility and the user information are input into an account credibility model to generate a credibility score; and by processing the user's login request according to the credibility score, it is possible to assist the user to log in safely and quickly without affecting the user's login experience, and both user information security and system data security can be ensured.

[0102] Figure 6 It is a block diagram of an electronic device shown according to an exemplary embodiment.

[0103] The following refers to Figure 6 to describe the electronic device 600 according to this embodiment of the present disclosure. The electronic device 600 shown in FIG. 6 is only an example and should not bring any limitation to the functions and usage scopes of the embodiments of the present disclosure.

[0104] As Figure 6 shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.

[0105] Among them, the storage unit stores program codes, and the program codes can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present disclosure in this specification. For example, the processing unit 610 can execute steps such as Figure 2 , Figure 3 , Figure 4 shown.

[0106] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.

[0107] The storage unit 620 may further include a program / utility 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0108] The bus 630 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus structures.

[0109] The electronic device 600 may also communicate with one or more external devices 600' (such as a keyboard, a pointing device, a Bluetooth device, etc.), devices that enable a user to interact with the electronic device 600, and / or any device that enables the electronic device 600 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication may be through the input / output (I / O) interface 650. Also, the electronic device 600 may communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. The network adapter 660 may communicate with other modules of the electronic device 600 through the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0110] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, as Figure 7 shown, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiments of the present disclosure.

[0111] The software product may employ any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. A readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0112] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0113] The program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).

[0114] The above computer-readable medium carries one or more programs, which, when executed by the device, cause the computer-readable medium to implement the following functions: obtaining a user's login request; obtaining the user's user information and the current device fingerprint through the login request; comparing the current device fingerprint with the user's historical device fingerprints to determine the credibility of the user's current device; inputting the current device credibility and the user information into an account credibility model to generate a credibility score; and processing the user's login request according to the credibility score.

[0115] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are different from the embodiments. The modules of the above embodiments can be combined into one module, or further split into multiple sub-modules.

[0116] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0117] The above specifically shows and describes the exemplary embodiments of the present disclosure. It should be understood that the present disclosure is not limited to the detailed structures, setting manners, or implementation methods described herein; on the contrary, the present disclosure is intended to cover various modifications and equivalent settings included in the spirit and scope of the appended claims.

Claims

1. A method for processing user login requests based on device credibility, characterized in that, it includes: Obtain the user's login request; Based on the login request, obtain the user's information and the current device fingerprint through a hybrid fingerprint acquisition technology. The hybrid fingerprint acquisition technology generates the user's device fingerprint through active acquisition and server-side algorithms, including: implanting the SDK and JS, and setting breakpoints in fixed business scenarios; actively collecting elements when the business scenario is triggered, interacting with the server, and after being encrypted by algorithm obfuscation, generating a unique device fingerprint ID on the server, and at the same time writing the unique ID into the app application cache or browser cookie; Store multiple historical device fingerprints and their corresponding credibility scores through a device confidence table; Compare the current device fingerprint with the user's historical device fingerprints. When there is a matching result between the current device and the user's historical device fingerprints, use the credibility score corresponding to the historical device as the credibility of the current device; Input the current device credibility and the user information into an account credibility model to generate a credibility score; When the credibility score is in the first score range, call the face recognition application and password recognition application to process the login request; When the credibility score is in the second score range, call the password recognition application to process the login request; When the credibility score is in the third score range, allow the user to log in.

2. The method according to claim 1, characterized in that, it further includes: Obtain the historical device fingerprints of historical users; Obtain the historical user information of the historical user, and the historical user information includes historical behavior information; Associate the historical device fingerprint with the historical behavior information; Train a machine learning model based on the historical device fingerprint and the historical behavior information to generate the account credibility model.

3. The method according to claim 1, characterized in that, it further includes: Obtain the historical login information and historical user information of the user; Generate the historical device fingerprint of the user based on the historical login information; Generate the credibility corresponding to the historical device fingerprint based on the historical user information.

4. The method according to claim 1, characterized in that, Obtain the user's information and the current device fingerprint based on the login request through a hybrid fingerprint acquisition technology, including: When the user logs in to a preset application scenario, read the current device fingerprint at a predetermined location; When there is no current device fingerprint at the predetermined location, obtain the device information of the current device and encrypt the device information according to a preset algorithm to generate the device fingerprint of the current device; store the device fingerprint of the current device in the current device.

5. The method according to claim 2, characterized in that, Training a machine learning model based on the historical device fingerprint and the historical behavior information to generate the account credibility model, including: Generate historical feature information through the historical behavior information; Determine a sample label for the historical feature information according to a predetermined behavior in the historical behavior information and the historical device fingerprint; Training a machine learning model with the historical feature information with sample labels to generate the account credibility model.

6. The method according to claim 5, wherein, training a machine learning model with the historical feature information with sample labels to generate the account credibility model includes: dividing the historical feature information into multiple fingerprint feature information sets according to the time period corresponding to the historical device fingerprint; training a machine learning model with multiple fingerprint feature information sets to generate the account credibility model.

7. The method according to claim 1, wherein, further comprising: after the user successfully logs in, updating the credibility of the historical device fingerprint corresponding to the user based on the behavior information of the user.

8. A user login request processing device based on device credibility, wherein, comprising: a request module, configured to obtain a login request of a user; a fingerprint module, configured to obtain user information and a current device fingerprint of the user based on the login request by using a hybrid fingerprint acquisition technology, and the hybrid fingerprint acquisition technology jointly generates a device fingerprint of the user through active acquisition and a server-side algorithm, including: implanting an SDK and JS, and embedding points in a fixed service scenario; actively collecting elements when the service scenario is triggered, and interacting with the server, and after being encrypted by algorithm confusion, generating a unique device fingerprint ID at the server side, and simultaneously writing the unique ID into the app application cache or the browser cookie, and the collected elements are hardware itself information and software setting information in the device; a credibility module, configured to store multiple historical device fingerprints and their corresponding credibility through a device confidence table; comparing the current device fingerprint with the user's historical device fingerprints, and when there is a matching result between the current device and the user's historical device fingerprint, using the credibility score corresponding to the historical device as the credibility of the current device; a scoring module, configured to input the current device credibility and the user information into an account credibility model to generate a credibility score; a login module, configured to, when the credibility score is in a first score range, invoke a face recognition application and a password recognition application to process the login request; when the credibility score is in a second score range, invoke a password recognition application to process the login request; and when the credibility score is in a third score range, allow the user to log in.

9. An electronic device, wherein, comprising: one or more processors; a storage device, configured to store one or more programs; when the one or more programs are executed by the one or more processors, enabling the one or more processors to implement the method according to any one of claims 1-7.

10. A computer-readable medium, on which a computer program is stored, wherein, the program, when executed by a processor, implements the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Integrated identity authentication method based on human and object feature fusion

    CN113313029A

  • Account verification method and device, electronic equipment and computer readable medium

    CN113779550A