Method and device for handling encryption modification behavior

By collecting and analyzing the behavior information of the password-changing behavior, determining the user's password-changing characteristics, and providing personalized password-changing services, solving the problems of low service efficiency and poor experience of users who fail to modify the password, and improving the success rate of password-changing and user stickiness.

CN114417279BActive Publication Date: 2025-08-26ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210018447.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-09-26
Publication Date
2025-08-26
Estimated Expiration
2039-09-26

AI Technical Summary

Technical Problem

In the prior art, users who fail to modify passwords cannot complete password recovery through self-service verification, resulting in business blockage and poor user experience, and tight manual service resources and low efficiency.

Method used

Collect information on the confidentiality behavior, including identity verification behavior, device information and application feedback information, analyze the user's confidentiality characteristics such as urgency, risk degree and lack of security, determine personalized confidentiality service methods, and provide targeted confidentiality services.

Benefits of technology

Improve the service efficiency and experience of users who fail to change passwords, increase users' stickiness to applications, and cover more users who fail to change passwords.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114417279B_ABST
    Figure CN114417279B_ABST
Patent Text Reader

Abstract

One or more embodiments of this specification disclose a method and device for processing password modification behavior, which is used to achieve personalized service methods for users when password modification fails and improve service efficiency. The method includes: when password modification for an application fails, collecting the user's password modification behavior information; the password modification behavior information includes identity authentication behavior information during the password modification process, device information performing the password modification behavior, feedback information on the application within a preset time period, and at least one of account information; based on the password modification behavior information, determining the user's password modification feature information; the password modification feature information includes at least one of the password modification urgency, behavior risk level, lack of sense of security, and account value; analyzing the password modification feature information, and determining the password modification service method for the user based on the analysis results; and performing corresponding password modification services on the user according to the password modification service method.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This invention patent application is a divisional application of the Chinese invention patent application with the application date of September 26, 2019, application number 201910914799.8, and name “Method and device for processing encryption behavior”. Technical Field

[0002] This document relates to the field of data processing technology, and in particular to a method and device for processing encryption behavior. Background Art

[0003] When using an app, users often need to change or retrieve their forgotten passwords. Due to the large number of people who need to retrieve their passwords every day, manual service resources are limited and service efficiency is low. Therefore, most people currently use self-service verification methods (such as SMS verification, facial verification, fingerprint verification, etc.) to retrieve their passwords. According to current data statistics, self-service verification methods have a high pass rate and good interaction. However, a large number of users are still unable to complete password changes through self-service verification every day, which hinders their business and financial needs and reduces their stickiness with the app over time. In addition, these users have a much worse user experience than those who successfully retrieve their passwords. Summary of the Invention

[0004] The purpose of one or more embodiments of this specification is to provide a method and device for processing password modification behavior, so as to achieve personalized service mode for users and improve service efficiency when password modification fails.

[0005] To solve the above technical problems, one or more embodiments of this specification are implemented as follows:

[0006] In one aspect, one or more embodiments of this specification provide a method for processing a decryption behavior, including:

[0007] When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information;

[0008] Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value;

[0009] Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result;

[0010] According to the encryption service mode, the corresponding encryption service is performed on the user.

[0011] On the other hand, one or more embodiments of this specification provide a device for processing a decryption behavior, including:

[0012] a collection module for collecting, when a decryption attempt for an application fails, user decryption behavior information; the decryption behavior information includes at least one of identity authentication behavior information during the decryption process, device information performing the decryption behavior, feedback information on the application within a preset time period, and account information;

[0013] A first determining module determines, based on the password-changing behavior information, password-changing characteristic information of the user; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value;

[0014] An analysis module, for analyzing the encryption feature information and determining an encryption service mode for the user according to the analysis result;

[0015] An execution module performs a corresponding encryption service for the user according to the encryption service mode.

[0016] On the other hand, one or more embodiments of this specification provide a device for processing a decryption action, including:

[0017] processor; and

[0018] a memory arranged to store computer-executable instructions which, when executed, cause the processor to:

[0019] When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information;

[0020] Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value;

[0021] Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result;

[0022] According to the encryption service mode, the corresponding encryption service is performed on the user.

[0023] In another aspect, one or more embodiments of this specification provide a storage medium for storing computer-executable instructions, wherein the computer-executable instructions implement the following process when executed:

[0024] When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information;

[0025] Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value;

[0026] Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result;

[0027] According to the encryption service mode, the corresponding encryption service is performed on the user.

[0028] By adopting the technical solution of an embodiment of the present specification, when the password change fails, the password change service method for the user can be determined in a targeted manner according to the user's password change feature information (such as the urgency of password change, the degree of behavioral risk, the degree of lack of security, the account value, etc.), and then the corresponding password change service is performed on the user according to the determined password change service method, so that the post-service for the user who failed to change the password is more personalized, flexible and efficient, and can cover more users who failed to change the password, thereby improving the security service experience of the users who failed to change the password and increasing the user's stickiness to the application. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate one or more embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in one or more embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0030] Figure 1 is a schematic flow chart of a method for processing a password modification behavior according to an embodiment of this specification;

[0031] Figure 2 is a schematic flow chart of a method for processing a decryption behavior according to a specific embodiment of this specification;

[0032] Figure 3 is a schematic block diagram of a device for processing a decryption behavior according to an embodiment of this specification;

[0033] Figure 4 This is a schematic block diagram of a processing device for a decryption behavior according to an embodiment of this specification. DETAILED DESCRIPTION

[0034] One or more embodiments of this specification provide a method and apparatus for processing a password modification behavior, so as to achieve personalized service for users and improve service efficiency when password modification fails.

[0035] In order to enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below in conjunction with the drawings in one or more embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this document.

[0036] Figure 1 This is a schematic flow chart of a method for processing a password modification behavior according to an embodiment of this specification. Figure 1 As shown, the method includes:

[0037] S102, when the password change for the application fails, collect the user's password change behavior information; the password change behavior information includes at least one of the identity authentication behavior information during the password change process, the device information performing the password change behavior, the feedback information on the application within a preset time period, and the account information.

[0038] S104, determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value.

[0039] S106, analyzing the encryption feature information, and determining the encryption service mode for the user according to the analysis result.

[0040] S108: Execute corresponding encryption service for the user according to the encryption service mode.

[0041] In this embodiment, different user password-changing behavior information corresponds to different password-changing feature information. For example, if the password-changing behavior information includes identity verification behavior information, the password-changing feature information may include the user's sense of security; if the password-changing behavior information includes account information, the password-changing feature information may include the user's account value; if the password-changing behavior information includes device information, the password-changing feature information may include the user's behavioral risk level; if the password-changing behavior information includes user feedback on applications within a preset time period, the password-changing feature information may include the user's password-changing urgency; and so on. Different password-changing service methods are provided for different password-changing feature information, thereby realizing zoned services (i.e., personalized services) for password-changing users.

[0042] One or more embodiments of this specification provide a method for processing password-changing behavior, which can be applied to subsequent service scenarios for users who fail to change their passwords. For example, after a user changes the password of an application and fails to change the password (such as due to authentication failure or forgetting the old password), the password-changing behavior information of the user is collected and the password-changing feature information of the user is determined, and then the password-changing service corresponding to the password-changing feature information is performed on the user. It can be seen that this technical solution fills the gap in the post-service of the full-link service of the current password-changing scenario.

[0043] Therefore, by adopting the technical solution of an embodiment of the present specification, when the password change fails, the password change service method for the user can be determined in a targeted manner according to the user's password change feature information (such as the urgency of password change, the degree of behavioral risk, the degree of lack of security, the account value, etc.), and then the corresponding password change service is performed on the user according to the determined password change service method, so that the post-service for the user who failed to change the password is more personalized, flexible and efficient, and can cover more users who failed to change the password, thereby improving the security service experience of the users who failed to change the password and increasing the user's stickiness to the application.

[0044] In one embodiment, the password-changing behavior information includes identity authentication behavior information and / or device information; the password-changing characteristic information includes the degree of behavior risk. Based on this, the user's password-changing characteristic information can be determined by any one or more of the following methods:

[0045] 1. Determine the user's behavioral risk level based on the user's identity verification behavior information during the password change process.

[0046] First, obtain the behavioral characteristics of high-risk accounts collected in advance; second, compare the user's identity authentication behavior information during the password change process with the behavioral characteristics of the high-risk account to determine the matching degree between the user's identity authentication behavior information during the password change process and the behavioral characteristics of the high-risk account; third, determine the user's behavioral risk level based on the matching degree; the matching degree is positively correlated with the behavioral risk level.

[0047] That is, the higher the matching degree between the user's identity authentication behavior information during the password change process and the behavioral characteristics of high-risk accounts, the higher the user's behavioral risk level, that is, the riskier the current password change behavior is; conversely, the lower the matching degree between the user's identity authentication behavior information during the password change process and the behavioral characteristics of high-risk accounts, the lower the user's behavioral risk level, that is, the safer the current password change behavior is.

[0048] High-risk accounts can be accounts with risky behaviors that have been pre-identified by the risk identification system and stored on the network side. The specific identification method is not limited in this embodiment. For example, if a high-risk account is a stolen account, the account can be determined to be a stolen account by the corresponding tags such as "stolen" or "lost". The behavioral characteristics of the stolen account can include information modifications (such as password changes, identity information modifications, etc.), information binding, information unbinding, account locking, etc. performed by the hacker on the stolen account.

[0049] The degree of match between the user's identity verification behavior during the password change process and the behavioral characteristics of high-risk accounts can be determined by calculating the distance between the feature vector corresponding to the identity verification behavior information and the behavioral feature vector of the high-risk account. The distance between feature vectors can be calculated using any existing method, such as Euclidean distance, Mahalanobis distance, normalized Euclidean distance, cosine distance, etc. Specific vector distance calculation methods are known in the art and will not be further described here.

[0050] 2. Determine the risk level of the user's behavior based on the device information used to perform the password modification behavior.

[0051] First, determine whether the device performing the password modification is a risky device based on device information. Second, determine the risk level of the behavior based on the judgment result. Device information may include the device's Internet Protocol (IP) address, hardware address, geographic location, etc.

[0052] Risky device information (such as IP address, hardware address, and geographic location) can be pre-stored on the network side. By comparing the corresponding information of the current device with that of risky devices, it can be determined whether the device is a risky device. The greater the probability that the device performing the password modification is a risky device, the higher the risk level of the user's behavior.

[0053] In this embodiment, by determining the risk level of the user's behavior, and then performing a password modification service corresponding to the risk level of the user's behavior, the post-service for the user who failed to modify the password can be based on the risk level after the modification, thereby reducing the success rate of password modification in risky situations to a certain extent.

[0054] In one embodiment, the password-changing behavior information includes identity verification behavior information; the password-changing characteristic information includes the password-changing urgency. Based on this, when determining the user's password-changing characteristic information based on the password-changing behavior information, the request event corresponding to the password-changing behavior can be first determined based on the identity verification behavior information; then, based on the preset correspondence between each request event and the password-changing urgency, the password-changing urgency corresponding to the request event can be determined.

[0055] The appeal event includes the reason for changing the password, the purpose of the change, and pending events after the change. Reasons for changing the password include losing the phone, forgetting the password, and changing the password multiple times without a regular pattern. Purposes for changing the password include changing the password of the bank card bound to the phone or resetting a new password. Pending events after the password change include logging into an account, transferring money, and business verification.

[0056] To meet the user's password change needs and combine them with the demands for emergency events in actual application scenarios, the urgency of password change can be set to be higher after the phone is lost, the second highest urgency after the password is forgotten, the lowest urgency for changing the password frequently and irregularly, and so on. Of course, this is just an example of the correspondence between one demand event and the urgency of password change. In addition, the urgency of password change corresponding to each demand event can be arbitrarily set according to needs.

[0057] In this embodiment, the corresponding password modification service is performed on the user according to the user's password modification urgency, so that the password modification service can better meet the user's current demands and urgency, thereby largely meeting the user's current needs and improving the user's password modification experience.

[0058] In one embodiment, the decryption behavior information includes user feedback on the application within a preset time period; the decryption characteristic information includes a sense of insecurity. Based on this, when determining the user's decryption characteristic information based on the decryption behavior information, the user's feedback on the application within the preset time period can be first analyzed to determine the user's experience with the application; then, based on the user's experience with the application, the user's sense of insecurity can be determined. The user's experience with the application is negatively correlated with the sense of insecurity; the feedback information includes voice feedback and / or text feedback.

[0059] That is, the higher the user's experience with the application, the lower his or her lack of security; conversely, the lower the user's experience with the application, the higher his or her lack of security.

[0060] In this embodiment, the user's experience with the application can, to a certain extent, reflect the user's stickiness to the application. The higher the stickiness, the less likely the user is to churn, while the lower the stickiness, the more likely the user is to churn. Therefore, based on the user's experience with the application, it is possible to accurately determine the user's lack of sense of security and thus accurately provide the user with a password-changing service that suits their needs.

[0061] In one embodiment, the password-changing behavior information includes account information; the password-changing characteristic information includes account value. Based on this, when determining the user's password-changing characteristic information based on the password-changing behavior information, the account value can be determined based on the account information. The account information may include account level, account balance, and account transaction amount. There is a positive correlation between account level and account value; there is a positive correlation between account balance and account value; and there is a positive correlation between account transaction amount and account value.

[0062] For example, account levels include Gold Card Account, Silver Card Account, and Ordinary Account. The account level of a Gold Card Account is higher than that of a Silver Card Account, which in turn is higher than that of an Ordinary Account. Therefore, the account value of a Gold Card Account is higher than that of a Silver Card Account, which in turn is higher than that of an Ordinary Account.

[0063] For another example, if the account balance of user A is greater than the account balance of user B, then the account value of user A is higher than the account value of user B.

[0064] For another example, the account transaction amount is the total transaction amount in the most recent month. Assuming that the total transaction amount of user C in the most recent month is greater than the total transaction amount of user D in the most recent month, the account value of user C is higher than that of user D.

[0065] In this embodiment, the corresponding password modification service is performed on the user according to the user's account value, so that the password modification service can be more in line with the level of the user's account value. Since users with higher account values ​​are more important to application merchants, while improving the user's password modification experience, it can also ensure the high value of application users.

[0066] The above details how to determine the user's password-changing feature information based on the user's password-changing behavior information. The following details how to determine the password-changing method for the user by analyzing the password-changing feature information.

[0067] In one embodiment, the password modification service mode for a user may be determined according to the following steps:

[0068] Step A1: Determine whether the user's behavior risk level is higher than a first preset threshold.

[0069] Step A2: If the user's behavior risk level is higher than the first preset threshold, the password-changing service mode for the user is determined to be the first type of service mode; if the user's behavior risk level is lower than or equal to the first preset threshold, it is further determined whether the user's password-changing urgency is higher than the second preset threshold.

[0070] Step A3: If the user's urgency for changing the password is lower than or equal to the second preset threshold, the password change service mode for the user is determined to be the second type of service mode; if the user's urgency for changing the password is higher than the second preset threshold, it is further determined whether the user's lack of sense of security is higher than the third preset threshold.

[0071] Step A4: If the user's lack of security is higher than the third preset threshold, the password-changing service method for the user is determined to be the third type of service method; if the user's lack of security is lower than or equal to the third preset threshold, the password-changing service method is further determined based on the corresponding relationship between the user's account value and the password-changing service method.

[0072] When executing step A4, each account value may correspond to a different score. If the score corresponding to the account value is lower than the first preset score, the password-changing service mode may be determined to be the second type of service mode; if the score corresponding to the account value is higher than the second preset score, the password-changing service mode may be determined to be the third type of service mode; if the score corresponding to the account value is between the first preset score and the second preset score, the password-changing service mode may be determined to be the fourth type of service mode; wherein the second preset score is higher than the first preset score.

[0073] In this embodiment, the service level of the third type of service mode is higher than the service level of the second type of service mode; the service level of the second type of service mode is higher than the service level of the first type of service mode; the service level of the fourth type of service mode is higher than the service level of the second type of service mode, and lower than the service level of the third type of service mode.

[0074] The higher the service level, the more complex the service method, and the more manual intervention required from the service provider. Conversely, the lower the service level, the simpler the service method, and the lower the manual intervention required from the service provider, and even services that require no manual intervention or no intervention at all. For example, as can be seen from the above, the first type of service method has the lowest service level, which can be a completely non-intervention service method; the second type of service method has a higher service level than the first type of service method, and can be a text message reminder service method, such as a text message reminding the user to use other password change methods or guiding the user step by step to complete the password change through text messages; the fourth type of service method has a higher service level than the second type of service method, and can be a verification information push service method, such as pushing user information for verification so that the user can complete the password change with one-click confirmation; the third type of service method has the highest service level, and can be an active phone call method. The active phone call method refers to a method of contacting the user through a manual customer service phone to provide one-on-one service.

[0075] In this embodiment, different encryption service methods are adopted for users who failed to change their password and users with different encryption feature information, so that the post-service for users who failed to change their password is more personalized, flexible and efficient, and can cover more users who failed to change their password, thereby improving the security service experience of users who failed to change their password and increasing user stickiness to the application.

[0076] Figure 2 This is a schematic flow chart of a method for processing a password change behavior according to a specific embodiment of this specification. In this specific embodiment, the user changes the password of application A. When the password change fails, the corresponding post-password change service is executed for the user. Figure 2 As shown, the method includes:

[0077] S201, collecting the user's password-changing behavior information.

[0078] The password change behavior information includes identity authentication behavior information during the password change process, device information for performing the password change behavior, feedback information on application A within a preset time period, and account information.

[0079] Authentication behavior information may include authentication methods (such as biometric identification, personal information verification, verification code input, etc.), identity information used for verification (such as fingerprints, irises, and other biometric features; or ID number, etc.). Device information may include the device's IP address, hardware address, geographic location information, etc. Feedback on Application A within a preset time period may include text feedback and / or voice feedback. For example, if a user uses Application A to execute an event and then comments on Application A regarding the execution results of that event, the comment may serve as user feedback on Application A. Account information may include account level, account balance, account transaction amount, etc.

[0080] S202, determining the user's password-changing characteristic information based on the user's password-changing behavior information, wherein the password-changing characteristic information includes the urgency of password-changing, the degree of behavior risk, the degree of lack of security, and the account value.

[0081] How to determine the user's password-changing feature information based on the user's password-changing behavior information has been described in detail in the above embodiments and will not be repeated here.

[0082] S203, determine whether the user's behavior risk level is higher than a first preset threshold; if not, execute S204; if so, execute S207.

[0083] S204, determining whether the user's password change urgency is higher than a second preset threshold; if so, executing S205; if not, executing S208.

[0084] S205: Determine whether the user's lack of sense of security is higher than a third preset threshold. If not, execute S206; if so, execute S209.

[0085] S206: Determine the password-changing service mode for the user based on the corresponding relationship between the user's account value and the password-changing service mode.

[0086] Specifically, assuming that the user's account value is divided into three levels: high, medium, and low, different account values ​​correspond to different password change service methods. If the account value is high, the password change service method is determined to be the password change service method in S209; if the account value is medium, the password change service method is determined to be the password change service method in S210; if the account value is low, the password change service method is determined to be the password change service method in S208.

[0087] S207: Output the password change service mode for the user as no intervention at all.

[0088] In this embodiment, when the risk level of the user's behavior is higher than the first preset threshold, it indicates that the current password modification behavior is high-risk, and a completely non-interventional service method is adopted to avoid increasing the success rate of such high-risk password modification behavior.

[0089] S208, outputting a password change service mode to the user as a text message reminder.

[0090] Specifically, the user may be reminded via SMS to use other password-changing methods. For example, when the user fails to change the password through the security card verification method, the user may be reminded via SMS to change the password through mobile phone verification or dynamic password, thereby guiding the user to use a password-changing method that is more likely to succeed, thereby increasing the user's password-changing success rate; or, the user may be guided through SMS to complete the password change step by step, thereby increasing the user's password-changing success rate and the user's experience with the post-password change service.

[0091] S209: Outputting the password change service mode for the user as active phone call back.

[0092] The active telephone callback method refers to the method of contacting users through an artificial customer service phone to provide one-to-one service, thereby increasing the user's password change success rate and experience of the post-password change service through one-to-one manual service.

[0093] S210: Outputting the password change service mode to the user is pushing verification information.

[0094] For example, after a user fails to change their password, user information for verification (such as mobile phone number, the last four digits of their ID number, etc.) is pushed. If the pushed user information is correct, the user can complete the password change with one-click confirmation, thereby simplifying the user's password change method and helping the user to successfully change the password through post-services, thereby increasing the user's password change success rate.

[0095] It can be seen from the above embodiments that when a user fails to change his password, the password change service method for the user can be determined in a targeted manner based on the user's password change feature information (such as the urgency of password change, the degree of behavioral risk, the degree of lack of security, the account value, etc.), and then the corresponding password change service is performed on the user according to the determined password change service method, so that the post-service for the user who failed to change the password is more personalized, flexible and efficient, and can cover more users who failed to change the password, thereby improving the security service experience of users who failed to change the password and increasing user stickiness to the application.

[0096] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0097] The above is a method for processing the encryption behavior provided in one or more embodiments of this specification. Based on the same idea, one or more embodiments of this specification also provide a device for processing the encryption behavior.

[0098] Figure 3 This is a schematic block diagram of a device for processing a decryption behavior according to an embodiment of this specification. Figure 3 As shown, the processing device 300 for the encryption behavior includes:

[0099] The collection module 310 collects the user's password change behavior information when the password change for the application fails; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information;

[0100] The first determination module 320 determines the user's password change feature information based on the password change behavior information; the password change feature information includes at least one of the following: the urgency of password change, the risk level of the behavior, the lack of sense of security, and the account value;

[0101] Analysis module 330, analyzes the encryption feature information and determines the encryption service mode for the user based on the analysis result;

[0102] The execution module 340 performs the corresponding encryption service for the user according to the encryption service mode.

[0103] In one embodiment, the decryption behavior information includes identity authentication behavior information and / or device information; the decryption feature information includes the degree of behavior risk;

[0104] The first determining module 320 includes:

[0105] The first determination unit obtains pre-collected behavioral characteristics of high-risk accounts; compares the identity authentication behavior information with the behavioral characteristics of the high-risk accounts to determine a match between the identity authentication behavior information and the behavioral characteristics of the high-risk accounts; and determines a behavioral risk level based on the match; the match level is positively correlated with the behavioral risk level;

[0106] and / or,

[0107] The second determination unit determines whether the device performing the password modification behavior is a risky device based on the device information; determines the risk level of the behavior based on the judgment result; the device information includes at least one of the device's Internet Protocol address, hardware address, and geographic location information.

[0108] In one embodiment, the encryption behavior information includes identity authentication behavior information; the encryption feature information includes the encryption urgency;

[0109] The first determining module 320 includes:

[0110] A third determining unit determines, based on the identity verification behavior information, a request event corresponding to the decryption behavior; the request event includes at least one of the reason for decryption, the purpose of decryption, and an event to be executed after decryption;

[0111] The fourth determining unit determines the urgency of the code change corresponding to the appeal event according to the preset correspondence between each appeal event and the urgency of the code change.

[0112] In one embodiment, the encryption behavior information includes feedback information on the application within a preset time period; the encryption characteristic information includes the degree of loss of sense of security;

[0113] The first determining module 320 includes:

[0114] A fifth determining unit analyzes the feedback information to determine the user's experience of using the application; the feedback information includes voice feedback information and / or text feedback information;

[0115] The sixth determining unit determines the user's lack of sense of security based on the usage experience; the usage experience and the lack of sense of security are negatively correlated.

[0116] In one embodiment, the encryption behavior information includes account information; the encryption feature information includes account value;

[0117] The first determining module 320 includes:

[0118] a seventh determining unit, which determines the account value based on the account information; the account information includes at least one of the account level, the account balance, and the account transaction amount;

[0119] Among them, there is a positive correlation between account level and account value; a positive correlation between account balance and account value; and a positive correlation between account transaction amount and account value.

[0120] In one embodiment, the analysis module 330 includes:

[0121] a judgment unit, for judging whether the risk level of the behavior is higher than a first preset threshold;

[0122] an eighth determining unit, if the behavior risk level is higher than a first preset threshold, determining the password change service mode as a first type of service mode; if the behavior risk level is lower than or equal to the first preset threshold, further determining whether the password change urgency is higher than a second preset threshold;

[0123] a ninth determining unit, which determines that the password change service mode is the second type of service mode if the password change urgency is lower than or equal to the second preset threshold; and further determines whether the sense of insecurity is higher than a third preset threshold if the password change urgency is higher than the second preset threshold;

[0124] The tenth determination unit determines that the password-changing service mode is the third type of service mode if the degree of lack of security is higher than the third preset threshold; if the degree of lack of security is lower than or equal to the third preset threshold, further determines the password-changing service mode based on the corresponding relationship between the account value and the password-changing service mode.

[0125] In one embodiment, each account value corresponds to a different score;

[0126] a tenth determining unit, if the score corresponding to the account value is lower than the first preset score, determining the password change service mode as the second type of service mode; if the score corresponding to the account value is higher than the second preset score, determining the password change service mode as the third type of service mode; if the score corresponding to the account value is between the first preset score and the second preset score, determining the password change service mode as the fourth type of service mode;

[0127] The second preset score is higher than the first preset score.

[0128] In one embodiment, the service level of the third type of service mode is higher than the service level of the second type of service mode; the service level of the second type of service mode is higher than the service level of the first type of service mode; the service level of the fourth type of service mode is higher than the service level of the second type of service mode and lower than the service level of the third type of service mode.

[0129] A device using an embodiment of the present specification can, when password change fails, determine a password change service method for the user based on the user's password change feature information (such as the urgency of password change, the degree of behavioral risk, the degree of lack of security, the account value, etc.), and then perform the corresponding password change service on the user according to the determined password change service method, so that the post-service for the user who failed to change the password is more personalized, flexible and efficient, and can cover more users who failed to change the password, thereby improving the security service experience of the users who failed to change the password and increasing the user's stickiness to the application.

[0130] Those skilled in the art should understand that the above-mentioned processing device for the encryption modification behavior can be used to implement the processing method for the encryption modification behavior described above, and the detailed description should be similar to the description of the method part above. To avoid tediousness, it will not be repeated here.

[0131] Based on the same idea, one or more embodiments of this specification also provide a device for processing encryption behavior, such as Figure 4 As shown. The processing device for the decryption behavior may have relatively large differences due to different configurations or performances, and may include one or more processors 401 and memory 402, and the memory 402 may store one or more storage applications or data. Among them, the memory 402 may be a temporary storage or a permanent storage. The application stored in the memory 402 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the processing device for the decryption behavior. Furthermore, the processor 401 may be configured to communicate with the memory 402 to execute a series of computer executable instructions in the memory 402 on the processing device for the decryption behavior. The processing device for the decryption behavior may also include one or more power supplies 403, one or more wired or wireless network interfaces 404, one or more input and output interfaces 405, and one or more keyboards 406.

[0132] Specifically, in this embodiment, the decryption processing device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the decryption processing device, and the one or more programs are configured to be executed by one or more processors, including computer-executable instructions for performing the following:

[0133] When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information;

[0134] Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value;

[0135] Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result;

[0136] According to the encryption service mode, the corresponding encryption service is performed on the user.

[0137] Optionally, the encryption behavior information includes the identity authentication behavior information and / or the device information; the encryption feature information includes the behavior risk level;

[0138] The computer-executable instructions, when executed, may further cause the processor to:

[0139] Obtaining pre-collected behavioral characteristics of high-risk accounts; comparing the identity verification behavior information with the behavioral characteristics of the high-risk accounts to determine a degree of match between the identity verification behavior information and the behavioral characteristics of the high-risk accounts; determining a degree of behavioral risk based on the degree of match; and a positive correlation between the degree of match and the degree of behavioral risk;

[0140] and / or,

[0141] Based on the device information, determine whether the device that performs the password modification behavior is a risky device; determine the risk level of the behavior based on the judgment result; the device information includes at least one of the Internet Protocol address, hardware address, and geographic location information of the device.

[0142] Optionally, the encryption behavior information includes the identity verification behavior information; the encryption feature information includes the encryption urgency;

[0143] The computer-executable instructions, when executed, may further cause the processor to:

[0144] Determining, based on the identity verification behavior information, a request event corresponding to the decryption behavior; the request event includes at least one of the reason for decryption, the purpose of decryption, and an event to be executed after decryption;

[0145] The urgency of decryption corresponding to the appeal event is determined according to the preset correspondence between each appeal event and the urgency of decryption.

[0146] Optionally, the encryption behavior information includes the feedback information on the application within a preset time period; the encryption feature information includes the degree of loss of sense of security;

[0147] The computer-executable instructions, when executed, may further cause the processor to:

[0148] Analyzing the feedback information to determine the user's experience of using the application; the feedback information includes voice feedback information and / or text feedback information;

[0149] The user's lack of sense of security is determined based on the usage experience; the usage experience is negatively correlated with the lack of sense of security.

[0150] Optionally, the encryption behavior information includes the account information; the encryption feature information includes the account value;

[0151] The computer-executable instructions, when executed, may further cause the processor to:

[0152] Determining the account value based on the account information, wherein the account information includes at least one of an account level, an account balance, and an account transaction amount;

[0153] Among them, the account level is positively correlated with the account value; the account balance is positively correlated with the account value; and the account transaction amount is positively correlated with the account value.

[0154] Optionally, when the computer executable instructions are executed, they may further cause the processor to:

[0155] Determining whether the risk level of the behavior is higher than a first preset threshold;

[0156] If the risk level of the behavior is higher than the first preset threshold, the password-changing service mode is determined to be a first-class service mode; if the risk level of the behavior is lower than or equal to the first preset threshold, it is further determined whether the urgency of the password-changing is higher than a second preset threshold;

[0157] If the urgency of the password change is lower than or equal to the second preset threshold, the password change service mode is determined to be the second type of service mode; if the urgency of the password change is higher than the second preset threshold, it is further determined whether the sense of security loss is higher than a third preset threshold;

[0158] If the degree of lack of security is higher than the third preset threshold, the encryption service mode is determined to be the third type of service mode; if the degree of lack of security is lower than or equal to the third preset threshold, the encryption service mode is further determined based on the correspondence between the account value and the encryption service mode.

[0159] Optionally, each of the account values ​​corresponds to a different score;

[0160] The computer-executable instructions, when executed, may further cause the processor to:

[0161] If the score corresponding to the account value is lower than the first preset score, determining the password change service mode as the second type of service mode;

[0162] If the score corresponding to the account value is higher than the second preset score, the password modification service mode is determined to be the third type of service mode;

[0163] If the score corresponding to the account value is between the first preset score and the second preset score, the password modification service mode is determined to be the fourth type of service mode;

[0164] The second preset score is higher than the first preset score.

[0165] Optionally, the service level of the third type of service mode is higher than the service level of the second type of service mode; the service level of the second type of service mode is higher than the service level of the first type of service mode; the service level of the fourth type of service mode is higher than the service level of the second type of service mode and lower than the service level of the third type of service mode.

[0166] One or more embodiments of this specification further provide a computer-readable storage medium storing one or more programs, wherein the one or more programs include instructions that, when executed by an electronic device including multiple application programs, enable the electronic device to perform the above-mentioned encryption processing method, and are specifically used to perform:

[0167] When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information;

[0168] Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value;

[0169] Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result;

[0170] According to the encryption service mode, the corresponding encryption service is performed on the user.

[0171] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0172] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0173] It will be understood by those skilled in the art that one or more embodiments of this specification may be provided as a method, system, or computer program product. Thus, one or more embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0174] One or more embodiments of this specification are described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0175] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0176] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0177] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0178] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0179] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transit media), such as modulated data signals and carrier waves.

[0180] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0181] One or more embodiments of this specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0182] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.

[0183] The foregoing description is merely one or more embodiments of this specification and is not intended to limit this specification. It will be apparent to those skilled in the art that various modifications and variations may be made to one or more embodiments of this specification. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of one or more embodiments of this specification shall be included within the scope of the claims of one or more embodiments of this specification.

Claims

1. A method for handling a change of encryption, comprising: When the password change for the application fails, collect the user's password change behavior information; The password change behavior information includes at least one of identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information; Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value; Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result; Execute the corresponding encryption service for the user according to the encryption service mode; Among them, the encryption service mode includes: a first type of service mode determined according to the risk level of the behavior, or a second type of service mode determined according to the risk level of the behavior and the urgency of encryption, or a third type of service mode determined according to the risk level of the behavior, the urgency of encryption and the lack of security.

2. The method according to claim 1, wherein the decryption behavior information includes the identity verification behavior information and / or the device information; and the decryption feature information includes the risk level of the behavior; The step of determining the user's encryption feature information based on the encryption behavior information includes: Obtaining pre-collected behavioral characteristics of high-risk accounts; comparing the identity verification behavior information with the behavioral characteristics of the high-risk accounts to determine a degree of match between the identity verification behavior information and the behavioral characteristics of the high-risk accounts; determining a degree of behavioral risk based on the degree of match; and a positive correlation between the degree of match and the degree of behavioral risk; and / or, Based on the device information, determine whether the device that performs the password modification behavior is a risky device; determine the risk level of the behavior based on the judgment result; the device information includes at least one of the Internet Protocol address, hardware address, and geographic location information of the device.

3. The method according to claim 1, wherein the encryption behavior information includes the identity verification behavior information; the encryption feature information includes the encryption urgency; The step of determining the user's encryption feature information based on the encryption behavior information includes: Determining, based on the identity verification behavior information, a request event corresponding to the decryption behavior; the request event includes at least one of the reason for decryption, the purpose of decryption, and an event to be executed after decryption; The urgency of decryption corresponding to the appeal event is determined according to the preset correspondence between each appeal event and the urgency of decryption.

4. The method according to claim 1, wherein the decryption behavior information includes the feedback information on the application within a preset time period; the decryption characteristic information includes the degree of loss of sense of security; The step of determining the user's encryption feature information based on the encryption behavior information includes: Analyzing the feedback information to determine the user's experience of using the application; the feedback information includes voice feedback information and / or text feedback information; The user's lack of sense of security is determined based on the usage experience; the usage experience is negatively correlated with the lack of sense of security.

5. The method according to claim 1, wherein the encryption behavior information includes the account information; the encryption feature information includes the account value; The step of determining the user's encryption feature information based on the encryption behavior information includes: Determining the account value based on the account information, wherein the account information includes at least one of an account level, an account balance, and an account transaction amount; Among them, the account level is positively correlated with the account value; the account balance is positively correlated with the account value; and the account transaction amount is positively correlated with the account value.

6. The method according to claim 1, wherein determining a password modification service mode for the user based on the analysis result comprises: According to the analysis result of the decryption feature information, it is determined that the decryption service mode for the user is a first type of service mode, a second type of service mode or a third type of service mode; wherein the first type of service mode, the second type of service mode and the third type of service mode respectively correspond to different degrees of manual intervention.

7. The method according to claim 6, wherein analyzing the encryption feature information and determining the encryption service mode for the user according to the analysis result comprises: Determining whether the risk level of the behavior is higher than a first preset threshold; If the risk level of the behavior is higher than the first preset threshold, the password-changing service mode is determined to be the first type of service mode; if the risk level of the behavior is lower than or equal to the first preset threshold, the password-changing urgency is further determined to be higher than a second preset threshold; If the urgency of the encryption change is lower than or equal to the second preset threshold, determining that the encryption change service mode is the second type of service mode; if the urgency of the encryption change is higher than the second preset threshold, further determining whether the sense of security loss is higher than a third preset threshold; If the degree of lack of security is higher than the third preset threshold, the encryption service mode is determined to be the third type of service mode; if the degree of lack of security is lower than or equal to the third preset threshold, the encryption service mode is further determined based on the correspondence between the account value and the encryption service mode.

8. The method according to claim 7, wherein each of the account values ​​corresponds to a different score; The determining of the encryption service mode according to the correspondence between the account value and the encryption service mode includes: If the score corresponding to the account value is lower than the first preset score, determining the password change service mode as the second type of service mode; If the score corresponding to the account value is higher than the second preset score, the password modification service mode is determined to be the third type of service mode; If the score corresponding to the account value is between the first preset score and the second preset score, the password modification service mode is determined to be the fourth type of service mode; The second preset score is higher than the first preset score.

9. According to the method according to claim 8, the service level of the third type of service mode is higher than the service level of the second type of service mode; the service level of the second type of service mode is higher than the service level of the first type of service mode; the service level of the fourth type of service mode is higher than the service level of the second type of service mode, and lower than the service level of the third type of service mode.

10. A device for processing a decryption action, comprising: The collection module collects the user's password change behavior information when the password change for the application fails; The password change behavior information includes at least one of identity authentication behavior information during the password change process, device information performing the password change behavior, feedback information on the application within a preset time period, and account information; A first determining module determines, based on the password-changing behavior information, password-changing characteristic information of the user; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value; An analysis module, for analyzing the encryption feature information and determining an encryption service mode for the user according to the analysis result; An execution module, performing a corresponding encryption service for the user according to the encryption service mode; Among them, the encryption service mode includes: a first type of service mode determined according to the risk level of the behavior, or a second type of service mode determined according to the risk level of the behavior and the urgency of encryption, or a third type of service mode determined according to the risk level of the behavior, the urgency of encryption and the lack of security.

11. The apparatus according to claim 10, wherein the decryption behavior information includes the identity verification behavior information and / or the device information; the decryption feature information includes the risk level of the behavior; The first determining module includes: A first determining unit is configured to obtain pre-collected behavioral characteristics of a high-risk account; compare the identity authentication behavior information with the behavioral characteristics of the high-risk account to determine a degree of match between the identity authentication behavior information and the behavioral characteristics of the high-risk account; and determine a degree of behavioral risk based on the degree of match; wherein the degree of match is positively correlated with the degree of behavioral risk; and / or, The second determination unit determines whether the device that performs the password modification behavior is a risky device based on the device information; determines the risk level of the behavior based on the judgment result; the device information includes at least one of the Internet Protocol address, hardware address, and geographic location information of the device.

12. The apparatus according to claim 10, wherein the encryption behavior information includes the identity verification behavior information; the encryption feature information includes the encryption urgency; The first determining module includes: A third determining unit determines, based on the identity verification behavior information, a request event corresponding to the password change behavior; The appeal event includes at least one of the reason for the declassification, the purpose of the declassification, and an event to be executed after the declassification; The fourth determining unit determines the urgency of the code change corresponding to the demand event according to a preset correspondence between each demand event and the urgency of the code change.

13. The device according to claim 10, wherein the decryption behavior information includes the feedback information on the application within a preset time period; the decryption characteristic information includes the degree of loss of sense of security; The first determining module includes: a fifth determining unit, configured to analyze the feedback information to determine the user's experience of using the application; the feedback information includes voice feedback information and / or text feedback information; A sixth determining unit determines the user's lack of sense of security based on the usage experience; the usage experience and the lack of sense of security are negatively correlated.

14. The apparatus according to claim 10, wherein the encryption behavior information includes the account information; the encryption feature information includes the account value; The first determining module includes: a seventh determining unit, configured to determine the account value based on the account information; The account information includes at least one of the account level, account balance, and account transaction amount; Among them, the account level is positively correlated with the account value; the account balance is positively correlated with the account value; and the account transaction amount is positively correlated with the account value.

15. The device according to claim 10, wherein the analysis module determines whether the encryption service mode for the user is the first type of service mode, the second type of service mode, or the third type of service mode based on the analysis result of the encryption feature information; The first type of service mode, the second type of service mode and the third type of service mode respectively correspond to different degrees of manual intervention.

16. The apparatus according to claim 15, wherein the analysis module comprises: a judgment unit, configured to judge whether the risk level of the behavior is higher than a first preset threshold; an eighth determining unit, which determines that the password-changing service mode is the first type of service mode if the behavior risk level is higher than the first preset threshold; and further determines whether the password-changing urgency level is higher than a second preset threshold if the behavior risk level is lower than or equal to the first preset threshold; a ninth determining unit, which determines that the encryption service mode is the second type of service mode if the encryption urgency is lower than or equal to the second preset threshold; and further determines whether the sense of security loss is higher than a third preset threshold if the encryption urgency is higher than the second preset threshold; The tenth determination unit determines that the encryption service mode is the third type of service mode if the degree of lack of security is higher than the third preset threshold; if the degree of lack of security is lower than or equal to the third preset threshold, further determines the encryption service mode based on the corresponding relationship between the account value and the encryption service mode.

17. A device for processing a decryption action, comprising: processor; as well as a memory arranged to store computer-executable instructions which, when executed, cause the processor to: When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, information about the device performing the password change behavior, feedback information on the application within a preset time period, and account information; Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value; Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result; Execute the corresponding encryption service for the user according to the encryption service mode; Among them, the encryption service mode includes: a first type of service mode determined according to the risk level of the behavior, or a second type of service mode determined according to the risk level of the behavior and the urgency of encryption, or a third type of service mode determined according to the risk level of the behavior, the urgency of encryption and the lack of security.

18. A storage medium for storing computer-executable instructions, wherein the computer-executable instructions, when executed, implement the following process: When the password change for the application fails, collecting the user's password change behavior information; the password change behavior information includes at least one of the following: identity authentication behavior information during the password change process, information about the device performing the password change behavior, feedback information on the application within a preset time period, and account information; Determining the user's password-changing characteristic information based on the password-changing behavior information; the password-changing characteristic information includes at least one of the following: password-changing urgency, behavior risk level, sense of security loss, and account value; Analyze the encryption feature information and determine the encryption service mode for the user according to the analysis result; Execute the corresponding encryption service for the user according to the encryption service mode; Among them, the encryption service mode includes: a first type of service mode determined according to the risk level of the behavior, or a second type of service mode determined according to the risk level of the behavior and the urgency of encryption, or a third type of service mode determined according to the risk level of the behavior, the urgency of encryption and the lack of security.

Citation Information

Patent Citations

  • Method and device for recommending password change mode

    CN104580118A

  • Method, device, storage medium and apparatus for protecting access behavior security

    CN109284590A

  • Sensitive-operation processing methods and devices, server, terminal and storage medium

    CN109547495A