An authentication method and a terminal based on a data model
Through the data model-based authentication method, using behavioral data and user identification to judge or create an identity mutual trust data model, the security and accuracy of cross-business authentication are solved, and the simplified verification process and highly reliable identity authentication are achieved.
Patent Information
- Application Number
- CN202111657223.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-31
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-12-31
AI Technical Summary
The existing mutual trust mechanism of identity authentication is difficult to solve the problems of cross-service information relevance and business linkage, and the existing identity authentication methods have poor user experience, low security and immediacy in diversified business scenarios, and are susceptible to network fluctuations, and the authentication results are inaccurate.
The data model-based identity authentication method is adopted to determine whether the target identity mutual trust data model exists by receiving behavioral data and user identification. If otherwise, a target identity mutual trust data model is created to achieve identity authentication, and users do not need to submit personal identity information, simplifying the verification process and ensuring security and reliability.
In cross-platform identity authentication, it improves security and reliability, simplifies the verification process, improves user experience, reduces sensitive data transmission, and enhances the accuracy of verification results.
Smart Images

Figure CN114444039B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to an identity authentication method and a terminal based on a data model. Background Art
[0002] The existing identity authentication and mutual trust mechanism mainly performs authentication through the user's token or CA certificate, or is based on third-party provided identity authentication services such as those provided by WeChat, Alipay, etc. It is difficult to solve problems such as cross-service ticket information association and difficult service linkage, and cannot meet the gradually diversified business development needs. Moreover, the existing method of identity authentication and mutual trust through token or CA certificate usually uses basic information such as the user's ID card number and mobile phone number, which does not match the complex and changeable specific business scenarios, reducing the user experience. Third-party authentication depends on third-party network services, is easily affected by network fluctuations, and there is also a risk that data may be intercepted or tampered with during transmission, reducing the immediacy and security of identity authentication and mutual trust, and also reducing the accuracy of the authentication result. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to provide an identity authentication method and a terminal based on a data model to achieve secure and highly feasible identity authentication.
[0004] To solve the above technical problem, a technical solution adopted by the present invention is:
[0005] An identity authentication method based on a data model, comprising the steps of:
[0006] Receiving a login request, where the login request includes behavior data and a user identifier;
[0007] Searching for a corresponding target identity mutual trust data model according to the user identifier. If so, outputting a verification result according to the behavior data and the target identity mutual trust data model;
[0008] Otherwise, creating a target identity mutual trust data model corresponding to the user identifier according to the behavior data.
[0009] To solve the above technical problem, another technical solution adopted by the present invention is:
[0010] An identity authentication terminal based on a data model, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0011] Receiving a login request, where the login request includes behavior data and a user identifier;
[0012] Find whether there is a corresponding target identity mutual trust data model according to the user identifier. If so, output a verification result according to the behavior data and the target identity mutual trust data model;
[0013] Otherwise, create a target identity mutual trust data model corresponding to the user identifier according to the behavior data.
[0014] The beneficial effects of the present invention are as follows: after receiving a login request, determine whether there is a corresponding target identity mutual trust data model for the user identifier in the login request. If so, output a corresponding verification result according to the behavior data and the target identity mutual trust data model. Otherwise, establish a target identity mutual trust data model corresponding to the user identifier, so as to realize the verification of the user identity through the target identity mutual trust data model. When the user crosses vouchers, there is no need to submit personal identity information, which simplifies the verification process and ensures the security of the verification and the reliability of the verification result. If the user does not have a corresponding identity mutual trust data model, an identity mutual trust data model is established for the user according to the current behavior data, and the identity mutual trust authentication model is used to implement identity authentication in subsequent identity authentication, which is safe and highly feasible. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a step flowchart of an identity verification method based on a data model according to an embodiment of the present invention;
[0016] Figure 2 It is a schematic structural diagram of an identity verification terminal based on a data model according to an embodiment of the present invention;
[0017] Figure 3 It is a schematic system diagram of an identity verification method based on a data model according to an embodiment of the present invention;
[0018] Figure 4 It is a step flowchart of another identity verification method based on a data model according to an embodiment of the present invention;
[0019] Label description:
[0020] 1. An identity verification terminal based on a data model; 2. A processor; 3. A memory. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] To describe in detail the technical content, the achieved objectives and the effects of the present invention, the following is described in conjunction with the embodiments and with reference to the drawings.
[0022] Please refer to Figure 1 , an identity verification method based on a data model, including the steps of:
[0023] Receive a login request, where the login request includes behavior data and a user identifier;
[0024] Search for the existence of a corresponding target identity mutual trust data model based on the user identifier. If so, output a verification result based on the behavior data and the target identity mutual trust data model;
[0025] Otherwise, create a target identity mutual trust data model corresponding to the user identifier based on the behavior data.
[0026] As can be seen from the above description, the beneficial effects of the present invention are as follows: After receiving a login request, it is determined whether there is a corresponding target identity mutual trust data model for the user identifier in the login request. If so, a corresponding verification result is output based on the behavior data and the target identity mutual trust data model. Otherwise, a target identity mutual trust data model corresponding to the user identifier is established, realizing the verification of the user's identity through the target identity mutual trust data model. The user does not need to submit personal identity information when crossing vouchers, ensuring the security of verification and the reliability of the verification result while simplifying the verification process. If the user does not have a corresponding identity mutual trust data model, an identity mutual trust data model is established for the user based on the current behavior data, and the identity mutual trust authentication model is used for identity authentication in subsequent identity authentication, which is safe and highly feasible.
[0027] Further, the login request further includes first platform data and second platform data. The first platform data includes a first platform identifier and the login data corresponding to the user identifier on the first platform, and the second platform data includes a second platform identifier;
[0028] The step of searching for the existence of a corresponding target identity mutual trust data model based on the user identifier and, if so, outputting a verification result based on the behavior data and the target identity mutual trust data model includes:
[0029] Search for the existence of a corresponding target identity mutual trust data model based on the user identifier, the first platform identifier, and the second platform identifier. If so, establish a first identity mutual trust data model based on the behavior data and the login data;
[0030] Compare the first identity mutual trust data model and the target identity mutual trust data model and obtain the similarity. If the similarity exceeds the threshold, output a verification result of verification passed.
[0031] As described above, since the habits of each user are different, the behavioral data of users when jumping between platforms will also be different. Based on this behavioral data, a first identity mutual trust data model is established and compared with the found target identity model. The target identity model is obtained based on the historical behavioral data of the user. If the similarity with the historical behavioral data is within a certain threshold, it can be confirmed that the operation is performed by the user himself, and the user has verified the identity information on the first platform, so as to realize identity verification on the second platform while ensuring security, which is more convenient and improves the user experience of using the system.
[0032] Further, the outputting the verification result according to the behavioral data and the target identity mutual trust data model includes:
[0033] Determining the behavioral index features in the target identity mutual trust data model according to the behavioral data;
[0034] Comparing the behavioral data and the behavioral index features to obtain the verification result and outputting the verification result.
[0035] As described above, according to the behavioral data, the behavioral index features in the target identity mutual trust data model are confirmed, and the behavioral data and the behavioral index features are compared. Some thresholds such as the frequency of clicking on the screen can be set for the behavioral index features. If the behavioral data does not correspond to the behavioral index features, it may not be the operation of the user himself. At this time, the identity verification fails or other identity verification methods are switched to ensure the reliability of the verification result.
[0036] Further, the searching for whether there is a corresponding target identity mutual trust data model according to the user identifier, the first platform identifier and the second platform identifier includes:
[0037] Determining the jump relationship according to the first platform identifier and the second platform identifier;
[0038] Searching for whether there is a corresponding target identity mutual trust data model according to the user identifier. If so, determining the model index corresponding to the target identity mutual trust data model according to the jump relationship.
[0039] As described above, the jump relationship is determined according to the first platform identifier and the second platform identifier, and the corresponding model index in the target identity mutual trust data model is obtained according to the determined jump relationship. The operations of jumping between different subsystems are different, and users may have different behaviors. Obtaining the corresponding model index according to the jump relationship refines the granularity of identity verification, thus ensuring the accuracy of the result.
[0040] Further, the creating the target identity mutual trust data model corresponding to the user identifier according to the behavioral data includes:
[0041] Obtain the behavior data, and calculate the model metrics corresponding to the behavior data through the Paxos algorithm;
[0042] Calculate the target identity mutual trust data model corresponding to the user identifier according to the model metrics.
[0043] As can be seen from the above description, determining the model metrics corresponding to the behavior data through the Paxos algorithm ensures that the determined model metrics can best correspond to the user's own behavior characteristics, guaranteeing the accuracy of subsequent identity verification.
[0044] Please refer to Figure 2 , an identity verification terminal based on a data model, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0045] Receive a login request, where the login request includes behavior data and a user identifier;
[0046] According to the user identifier, check whether there is a corresponding target identity mutual trust data model. If so, output a verification result according to the behavior data and the target identity mutual trust data model;
[0047] Otherwise, create a target identity mutual trust data model corresponding to the user identifier according to the behavior data.
[0048] The beneficial effects of the present invention are as follows: After receiving a login request, it is judged whether there is a corresponding target identity mutual trust data model for the user identifier in the login request. If so, a corresponding verification result is output according to the behavior data and the target identity mutual trust data model. Otherwise, a target identity mutual trust data model corresponding to the user identifier is established, realizing the verification of the user's identity through the target identity mutual trust data model. The user does not need to submit personal identity information when crossing vouchers, ensuring the security of verification and the reliability of the verification result while simplifying the verification process. If the user does not have a corresponding identity mutual trust data model, an identity mutual trust data model is established for the user according to the current behavior data, and the identity mutual trust authentication model is used for identity authentication in subsequent identity authentication, which is safe and highly feasible.
[0049] The above-mentioned identity verification method based on a data model of the present invention can be applied to scenarios where identity authentication is required, especially in the scenario of jumping from an authenticated platform to an unauthenticated platform. The following is an explanation through specific embodiments:
[0050] Please refer to Figure 1 and Figure 4 , Embodiment 1 of the present invention is:
[0051] An identity verification method based on a data model specifically includes:
[0052] S1. Receive a login request, where the login request includes behavior data and a user identifier;
[0053] Among them, the login request further includes first platform data and second platform data. The first platform data includes a first platform identifier and login data corresponding to the user identifier on the first platform, and the second platform data includes a second platform identifier;
[0054] S2. According to the user identifier, check whether there is a corresponding target identity mutual trust data model. If so, output a verification result according to the behavior data and the target identity mutual trust data model, including:
[0055] S21. According to the user identifier, the first platform identifier, and the second platform identifier, check whether there is a corresponding target identity mutual trust data model. If so, establish a first identity mutual trust data model according to the behavior data and the login data;
[0056] S22. Compare the first identity mutual trust data model and the target identity mutual trust data model and obtain a similarity. If the similarity exceeds a threshold, output a verification result of verification passed;
[0057] If the user has logged in to the first platform, there are already data such as the user's identity information and behavior information on the first platform in the login data corresponding to the first platform. According to this information, it can be verified whether the user has the permission to log in to the second platform, and there is no need to let the user send a login request again, which is more efficient;
[0058] Among them, the step of checking whether there is a corresponding target identity mutual trust data model according to the user identifier, the first platform identifier, and the second platform identifier includes:
[0059] Determine a jump relationship according to the first platform identifier and the second platform identifier;
[0060] According to the user identifier, check whether there is a corresponding target identity mutual trust data model. If so, determine the model metrics corresponding to the target identity mutual trust data model according to the jump relationship;
[0061] Among them, the target identity mutual trust data model includes basic information, behavior information, permission information, and association information metrics; the basic information includes name, ID number, contact information, etc.; the behavior information includes operation records, access records, etc.; the permission information includes operable permissions, accessible permissions, etc.; the association information includes associated and bound bank cards, accounts, systems, etc.;
[0062] S3. Otherwise, create a target identity mutual trust data model corresponding to the user identifier according to the behavior data, including:
[0063] Obtain the behavior data, and calculate the model metrics corresponding to the behavior data through the Paxos algorithm;
[0064] Calculate the target identity mutual trust data model corresponding to the user identifier according to the model metrics;
[0065] In an alternative embodiment, it further includes a mutual trust value, which is positively correlated with the amount of historical behavior data in the database. After receiving a login request in step S1, first determine whether the mutual trust value exceeds a threshold. If so, execute step S2; otherwise, jump to the normal login process;
[0066] Please refer to Figure 3 , in an alternative embodiment, all data corresponding to the user identifier can also be obtained, and the identity mutual trust data model corresponding to the user identifier is obtained through model training.
[0067] Embodiment 2 of the present invention is as follows:
[0068] An identity authentication method based on a data model, which is different from Embodiment 1 in that:
[0069] The output of the verification result according to the behavior data and the target identity mutual trust data model in S2 includes:
[0070] Determine the behavior index features in the target identity mutual trust data model according to the behavior data;
[0071] Compare the behavior data and the behavior index features to obtain the verification result and output the verification result; specifically, compare the behavior data and the behavior index features. If the behavior data is not within the range of the behavior index features, output verification failure; if the behavior data is within the range of the behavior index features, output verification success;
[0072] If the verification fails, it further includes jumping to the normal login process. If the user logs in successfully, add the behavior data to the historical behavior data, and obtain new behavior index features according to the Paxos algorithm;
[0073] For example, if the behavior data is the verification code sliding time of 2 seconds, and the behavior index features obtained from the target identity mutual trust data model are the verification code sliding time of 4 - 6 seconds, that is, the behavior data exceeds the range of the behavior index features, the verification fails;
[0074] In an alternative embodiment, first directly compare the behavior data with the behavior index features. If there is no behavior index feature corresponding to the behavior data, jump to execute S21.
[0075] Please refer to Figure 2 , Embodiment 3 of the present invention is as follows:
[0076] An authentication terminal 1 based on a data model, comprising a processor 2, a memory 3, and a computer program stored on the memory 3 and executable on the processor 2. When the processor 2 executes the computer program, each step in the first embodiment is implemented.
[0077] In summary, the present invention provides an authentication method and terminal based on a data model. By establishing an identity mutual trust data model corresponding to the user identifier for each user, after receiving a login request, the information in the login request is compared with the identity mutual trust data model to determine whether to pass the login request. Since the user has logged in on other platforms, when jumping, it is determined whether the user has the permission to log in to the platform where the login request is sent based on the known information, without the user having to repeatedly enter login information for verification, improving the user experience, reducing the transmission of sensitive data, enhancing the protection of user information, improving the security of the system. At the same time, the identity mutual trust data model can be continuously updated according to various behaviors and operations of the user on the system, ensuring the accuracy of the verification result, and is particularly suitable for an environment where multiple mini-programs that need to be logged in separately are integrated on a system, such as integrating multiple functions of medical insurance and social security in a government affairs app without repeated logins.
[0078] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in the relevant technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. An authentication method based on a data model, characterized in that, Including the steps: Receiving a login request, where the login request includes behavior data and a user identifier; According to the user identifier, checking whether there is a corresponding target identity mutual trust data model. If so, outputting a verification result according to the behavior data and the target identity mutual trust data model; Otherwise, creating a target identity mutual trust data model corresponding to the user identifier according to the behavior data; The login request further includes first platform data and second platform data. The first platform data includes a first platform identifier and login data corresponding to the user identifier on the first platform, and the second platform data includes a second platform identifier; The step of checking whether there is a corresponding target identity mutual trust data model according to the user identifier. If so, outputting a verification result according to the behavior data and the target identity mutual trust data model includes: Checking whether there is a corresponding target identity mutual trust data model according to the user identifier, the first platform identifier, and the second platform identifier. If so, establishing a first identity mutual trust data model according to the behavior data and the login data; Comparing the first identity mutual trust data model and the target identity mutual trust data model and obtaining a similarity. If the similarity exceeds a threshold, outputting a verification result of verification passed; The step of checking whether there is a corresponding target identity mutual trust data model according to the user identifier, the first platform identifier, and the second platform identifier includes: Determining a jump relationship according to the first platform identifier and the second platform identifier; Checking whether there is a corresponding target identity mutual trust data model according to the user identifier. If so, determining model metrics corresponding to the target identity mutual trust data model according to the jump relationship; 2. The authentication method based on a data model according to claim 1, wherein The step of outputting a verification result according to the behavior data and the target identity mutual trust data model includes: Determining behavior metric features in the target identity mutual trust data model according to the behavior data; Comparing the behavior data and the behavior metric features to obtain a verification result and outputting the verification result; 3. The authentication method based on a data model according to claim 1, wherein The step of creating a target identity mutual trust data model corresponding to the user identifier according to the behavior data includes: Obtaining the behavior data and calculating model metrics corresponding to the behavior data through the Paxos algorithm; Calculating a target identity mutual trust data model corresponding to the user identifier according to the model metrics; 4. An authentication terminal based on a data model, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the following steps are implemented: Receiving a login request, where the login request includes behavior data and a user identifier; According to the user identifier, checking whether there is a corresponding target identity mutual trust data model. If so, outputting a verification result according to the behavior data and the target identity mutual trust data model; Otherwise, creating a target identity mutual trust data model corresponding to the user identifier according to the behavior data; The login request further includes first platform data and second platform data. The first platform data includes a first platform identifier and login data corresponding to the user identifier on the first platform, and the second platform data includes a second platform identifier; Checking whether there is a corresponding target identity mutual trust data model according to the user identifier. If so, outputting a verification result according to the behavior data and the target identity mutual trust data model includes: Checking whether there is a corresponding target identity mutual trust data model according to the user identifier, the first platform identifier, and the second platform identifier. If so, establishing a first identity mutual trust data model according to the behavior data and the login data; Comparing the first identity mutual trust data model and the target identity mutual trust data model and obtaining a similarity. If the similarity exceeds a threshold, outputting a verification result of verification passed; The checking whether there is a corresponding target identity mutual trust data model according to the user identifier, the first platform identifier, and the second platform identifier includes: Determining a jump relationship according to the first platform identifier and the second platform identifier; Checking whether there is a corresponding target identity mutual trust data model according to the user identifier. If so, determining model metrics corresponding to the target identity mutual trust data model according to the jump relationship.
5. The authentication terminal based on a data model according to claim 4, characterized in that The outputting a verification result according to the behavior data and the target identity mutual trust data model includes: Determining behavioral metric features in the target identity mutual trust data model according to the behavior data; Comparing the behavior data and the behavioral metric features to obtain a verification result and outputting the verification result.
6. The authentication terminal based on a data model according to claim 4, wherein The creating a target identity mutual trust data model corresponding to the user identifier according to the behavior data includes: Obtaining the behavior data and calculating model metrics corresponding to the behavior data through the Paxos algorithm; Calculating a target identity mutual trust data model corresponding to the user identifier according to the model metrics.
Citation Information
Patent Citations
Identity verification method, identity verification device, and identity verification system
CN105827406A
Monitoring method and apparatus
CN107092544A
Identity verification method and device
CN112597459A