A method for trusted user identity verification for shared data access
By detecting single-point anomalies and contextual anomalies based on multi-factor behavioral features, and utilizing isolated forest and long short-term memory neural network models, user identities are dynamically identified, solving the problem of insufficient user identity authentication during data sharing and improving the security of data sharing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TSINGHUA UNIVERSITY
- Filing Date
- 2023-05-08
- Publication Date
- 2026-07-17
AI Technical Summary
In the current data sharing process, user authentication is mainly concentrated in the login stage, lacking multi-dimensional dynamic monitoring of user behavior, resulting in insufficient security in the data sharing process.
Single-point anomaly and contextual anomaly detection is performed using multi-factor behavioral features. The trustworthiness of user identity is judged in real time using the isolated forest model and the long short-term memory neural network model, and access is blocked when the user is deemed untrustworthy.
It improves the security of the data sharing process, enables the earlier identification of potential risky behaviors, and enhances the protection capabilities of the data sharing system.
Smart Images

Figure CN116527366B_ABST
Abstract
Description
Technical Field
[0001] This article relates to, but is not limited to, information security technologies, and in particular to a method for trusted identification of users for access to shared data. Background Technology
[0002] In today's information age, data has become a vital social resource. Simultaneously, for the sustainable development of information systems and to promote win-win cooperation among enterprises, data sharing among companies has gradually become an indispensable and crucial matter. Data processing activities should strengthen risk monitoring; when data security defects or vulnerabilities are discovered, remedial measures should be taken immediately; in the event of a data security incident, immediate action should be taken, and users should be notified promptly in accordance with regulations, and the relevant authorities should be notified. With the comprehensive advancement of informatization and the increasing demand for data sharing from all sectors of society, the level of attention paid to data security is constantly increasing, leading to the development of relatively mature data security protection mechanisms.
[0003] In the data sharing process, existing data security protection mechanisms mainly focus on protecting the data itself and the data transmission link, including encryption before data transmission and data link monitoring. However, for a crucial component of the data sharing process—the users sharing the data—security measures are relatively few. Typically, only basic measures such as user login authentication and traffic restrictions during transmission are implemented. Therefore, how to further improve the security of the data sharing process remains an unresolved issue. Summary of the Invention
[0004] The following is an overview of the subject matter described in detail herein. This overview is not intended to limit the scope of the claims.
[0005] This invention provides a method for trusted identification of user identities for accessing shared data, which can improve the security of the data sharing process.
[0006] This invention provides a method for trusted user identity verification for shared data access, comprising: Based on the multi-factor behavioral characteristics of users participating in data sharing, real-time detection of single-point anomalies is performed on users. Context anomaly detection is performed on users based on their multi-factor behavioral characteristics participating in data sharing. Based on the results of real-time detection of single points of failure and contextual failure detection, determine whether the user's identity is trustworthy; If a user's identity is deemed untrustworthy, block the user's access to data. The multi-factor behavioral features include: user access behavior-related feature information recorded by the system storing the data during the data sharing process.
[0007] On the other hand, embodiments of the present invention also provide a computer storage medium storing a computer program, which, when executed by a processor, implements the above-described method for trusted identification of user identity for shared data access.
[0008] Furthermore, embodiments of the present invention also provide a terminal, comprising: a memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute computer programs in memory; When the computer program is executed by the processor, it implements the method described above for trusted identification of user identity for accessing shared data.
[0009] The technical solution of this application includes: real-time detection of single-point anomalies for users based on multi-factor behavioral characteristics of users participating in data sharing; contextual anomaly detection for users based on multi-factor behavioral characteristics of users participating in data sharing; determination of user identity trustworthiness based on the results of real-time detection of single-point anomalies and contextual anomaly detection; and blocking user access to data when the user identity is determined to be untrustworthy. The multi-factor behavioral characteristics include: feature information related to the user's access behavior during the data sharing process recorded by the system storing the data. This embodiment of the invention performs real-time binding and contextual anomaly detection of single-point anomalies based on multi-factor behavioral characteristics, blocking access operations by users determined to have untrustworthy identities, thereby improving the data security of the data sharing system.
[0010] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the description, claims, and drawings. Attached Figure Description
[0011] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of the present invention and do not constitute a limitation on the technical solutions of the present invention.
[0012] Figure 1 This is a flowchart of a method for trusted user identity verification for shared data access according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating a method for trusted user identity verification for shared data access, serving as an application example of the present invention. Figure 3 This is a schematic diagram illustrating the application example of context anomaly detection in this invention. Detailed Implementation
[0013] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.
[0014] The steps illustrated in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases the steps shown or described may be performed in a different order than that presented here.
[0015] Figure 1 This is a flowchart of a method for trusted user identity verification for shared data access according to an embodiment of the present invention, such as... Figure 1 As shown, it includes: Step 101: Based on the multi-factor behavioral characteristics of users participating in data sharing, perform real-time detection of single-point anomalies for users; Step 102: Perform context anomaly detection on users based on their multi-factor behavioral characteristics participating in data sharing; Step 103: Based on the results of real-time detection of single-point anomalies and context anomaly detection, determine whether the user's identity is trustworthy; Step 104: If the user's identity is determined to be untrustworthy, block the user's access to data; Among them, multi-factor behavioral characteristics include: characteristic information related to user access behavior during the data sharing process recorded by the system storing the data.
[0016] This invention provides real-time binding and contextual anomaly detection for single-point anomalies based on multi-factor behavioral characteristics, blocking access operations by users deemed to have untrustworthy identities, thereby improving the data security of the data sharing system.
[0017] In one exemplary instance, steps 101 and 102 are not performed in any particular order.
[0018] In one exemplary instance, the multi-factor behavioral features in this embodiment of the invention include one or any combination of the following: User login time, user authorization level, user's uplink and downlink traffic during the time period between the detection time and the previous detection time, total uplink and downlink traffic since the user logged in, user's login IP, and user's uplink and downlink traffic at each moment; the detection time is a pre-set fixed detection duration.
[0019] In one exemplary instance, embodiments of the present invention perform real-time detection of single-point anomalies in users, including: A pre-trained isolated forest model is used to perform real-time detection of single-point anomalies in users; The input to the isolated forest model includes one or any combination of the following multi-factor behavioral features: user login time, user uplink and downlink traffic during the time between the current detection time and the previous detection time, and the total uplink and downlink traffic since the user logged in; the detection time is a pre-set fixed detection duration.
[0020] In one exemplary instance, when using a pre-trained isolated forest model to perform real-time detection of single-point anomalies in users, the isolated forest model outputs the anomaly score for each user at each detection time. This embodiment of the invention determines whether a user's identity is trustworthy by including: When the outlier score output by the isolated forest model is greater than or equal to a pre-set first outlier score threshold, the user's identity is determined to be abnormal. When the outlier score output by the isolated forest model is less than or equal to a pre-set second outlier score threshold, the user's identity is determined to be normal. In one exemplary instance, embodiments of the present invention perform contextual anomaly detection on users based on multi-factor behavioral characteristics of users participating in data sharing, including: A long short-term memory neural network model is used to detect contextual anomalies in users; The input to the Long Short-Term Memory Neural Network Model includes one or any combination of the following multi-factor behavioral features: user authorization level, user login time, and user uplink and downlink traffic during the time between the current detection time and the previous detection time.
[0021] In one exemplary instance, when using a Long Short-Term Memory (LSTM) neural network model to perform context anomaly detection on a user, the output of the LSM model is the probability value of the user's identity being abnormal at each detection time. This embodiment of the invention determines whether a user's identity is trustworthy, including: When the probability value of the user's identity being abnormal output by the Long Short-Term Memory Neural Network Model is greater than or equal to a pre-set first abnormal probability threshold, the user's identity is determined to be abnormal. When the probability value of user identity abnormality output by the Long Short-Term Memory Neural Network Model is less than or equal to a pre-set second abnormality probability threshold, the user identity is determined to be normal.
[0022] When the outlier score output by the isolated forest model is less than or equal to a pre-set second outlier score threshold, the user's identity is determined to be normal.
[0023] In one exemplary instance, an embodiment of the present invention determines whether a user's identity is trustworthy, including: The anomaly score of the isolated forest model is initialized to 0. The anomaly score of the isolated forest model is obtained according to a preset period. When the obtained anomaly score is greater than or equal to a preset third anomaly score threshold, the scores greater than or equal to the preset third anomaly score threshold are accumulated, and the accumulated result is used as the first anomaly score. The anomaly score of the Long Short-Term Memory Neural Network Model is initialized to 0. The anomaly score of the Long Short-Term Memory Neural Network Model is obtained according to a preset period. When the obtained anomaly score is greater than or equal to the preset fourth anomaly score threshold, the scores greater than or equal to the preset fourth anomaly score threshold are accumulated, and the accumulated result is used as the second anomaly score. If the score of the first anomaly is greater than a preset first-type anomaly threshold, or the score of the second anomaly is greater than a preset second-type anomaly threshold, the user's identity is determined to be abnormal. In an exemplary embodiment, the present invention further includes the following steps before the following: An isolated forest model is obtained by training using a pre-defined first sample dataset; A long short-term memory neural network model is obtained by training a pre-defined second sample dataset; The first sample dataset includes one or more multi-factor behavioral features; the second sample dataset includes one or more multi-factor behavioral features.
[0024] In one exemplary instance, the multi-factor behavioral features of this embodiment of the invention further include: User's traffic access type; The traffic access types include one or any combination of the following: Network Time Protocol (NTP), Internet Control Message Protocol (ICMP), peer-to-peer network behavior, WebSocket (a network technology for full-duplex communication between browsers and servers introduced in HTML5), Remote Connection Tool (SSH), Bitmap Display Windows System (X11), Relational Database Management System (MySQL), Oracle, Secure Sockets Protocol (SSL), Application Layer Protocol Request (HTTP_POST), and File Transfer Protocol (FTP) download.
[0025] This invention also provides a computer storage medium storing a computer program, which, when executed by a processor, implements the aforementioned method for trusted user identity verification for shared data access.
[0026] This invention also provides a terminal, comprising: a memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute computer programs in memory; When a computer program is executed by a processor, it implements the method described above for trusted identification of users for access to shared data.
[0027] The following application examples briefly illustrate the embodiments of the present invention. These application examples are only used to describe the embodiments of the present invention and are not intended to limit the scope of protection of the present invention.
[0028] Application Examples Unlike related technologies that employ static user identification and management mechanisms, this application example constructs a multi-dimensional dynamic user identification algorithm based on the multi-factor behavioral characteristics of users sharing data over a long period of time, thereby improving the security of the data sharing process.
[0029] The application example method of this invention includes: real-time detection of single-point anomalies among users participating in data sharing; that is, real-time detection of whether the behavior of all users participating in data sharing is abnormal. In one exemplary instance, the application example of this invention can use an isolated forest model for real-time detection of single-point anomalies; in another exemplary instance, the application example of this invention can use other types of single-point anomaly detection algorithms in related technologies to achieve real-time detection of single-point anomalies; a single-point anomaly (Global Outliers), also known as global anomalies, is a point that is different from most points globally, and this point constitutes a single-point anomaly. The application example method of this invention includes: performing context anomaly detection on the behavior of users participating in data sharing since login; that is, determining whether the user's behavior since login has anomalies in the time dimension; in one exemplary instance, the application example of this invention can use a long short-term memory neural network model for context anomaly detection; in another exemplary instance, the application example of this invention can use other types of context anomaly detection algorithms in related technologies to implement context anomaly detection; context anomaly, also known as situational anomaly, refers to the behavior of an object that differs significantly from that of most objects in a certain situation, and this data object is an anomaly in this context or situation.
[0030] Real-time detection of single-point anomalies and contextual anomalies can obtain a corresponding anomaly score. When the anomaly score reaches the pre-set anomaly score threshold for each detection, the user's identity is considered untrustworthy. Pre-set blocking measures are then implemented for the user's data access behavior. The workflow of this invention is as follows: Figure 2 As shown.
[0031] The application examples of this invention demonstrate models for real-time detection of single-point anomalies and contextual anomalies. Their development requires first collecting multi-factor behavioral characteristics of all authorized users over a certain period for learning, thereby obtaining relevant parameters. These multi-factor behavioral characteristics are various types of data obtained through the computer system when a user accesses the system storing data during data sharing. They mainly include: user login time, user authorization level, uplink and downlink traffic between the current and previous detection times, total uplink and downlink traffic since login, user login IP, and uplink and downlink traffic at each moment. These multi-factor behavioral characteristics are also the relevant data to be detected in the subsequent real-time detection process. Inputted into the model, the model outputs corresponding anomaly scores based on the above process, used for reliable user identification.
[0032] In one exemplary instance, this application example uses the Isolation Forest model for real-time detection of single-point anomalies. The input to the Isolation Forest model consists of multi-factor behavioral features of all users at a fixed time (a fixed period for detecting whether user behavior is abnormal). Based on the fundamental characteristics of the data sharing process, and considering factors such as identification efficiency and accuracy, features such as: user login time, user uplink and downlink traffic during the time interval between the current detection time and the previous detection time, and the total uplink and downlink traffic since the user logged in are selected as input to the model. The output of the Isolation Forest model is the anomaly score for each user at the fixed time, with a score between 0 and 1. If the anomaly score is greater than a preset first anomaly score threshold, for example, close to 1, then the corresponding user is considered to have abnormal behavior at the current time (user identity is untrustworthy); if the anomaly score is less than or equal to a second anomaly score threshold, then the user is considered not to have anomalies (user identity is trustworthy).
[0033] In one exemplary instance, when using a Long Short-Term Memory (LSTM) neural network model for context anomaly detection, the users for context anomaly detection are different for different users. That is, each user has corresponding detection model parameters. The input to the model is the user's multi-factor behavioral characteristics at the current detection time, which includes latent variables containing behavioral characteristics since the user logged in. Taking into account factors such as identification efficiency and accuracy, multi-factor behavioral characteristics such as user authorization level, user login time, and uplink / downlink traffic during the time interval between the current and previous detection times are selected as the model input. The output of the LSM model is the probability value of the corresponding user's identity being abnormal at a fixed time, ranging from 0 to 1. If the probability value is greater than a preset anomaly probability threshold (e.g., close to 1), the user's behavior is considered abnormal at the current time; if the probability value is less than or equal to the anomaly probability threshold (e.g., close to 0), the user is considered not abnormal.
[0034] When each user logs in, initialize the two types of exception values. All are 0. At each time step, the outlier results output by the two types of models mentioned above are respectively ,when Exceeding the set threshold hour, ,when Exceeding the set threshold hour, If after the update, Exceeding a Class I anomaly threshold or Exceeding the Type II anomaly threshold The system determines that a user's identity is abnormal, meaning the current user's identity is considered untrustworthy. In one exemplary instance, if a user's identity is determined to be abnormal, corresponding blocking measures are taken. This invention's application example considers the security of the data sharing process from the perspective of both parties using the data. It uses multi-factor behavioral characteristics of data users as a basis to dynamically identify the trustworthiness of user identities, thus enhancing the security of the data sharing process. In one exemplary instance, this application example uses isolated forests and long short-term memory networks to perform anomaly analysis on the temporal characteristics of user groups and individual users, respectively. Compared to methods based solely on traffic threshold detection, this can detect more potentially risky behaviors.
[0035] In one exemplary instance, the method for establishing an isolated forest model for real-time detection of single-point anomalies in this application example is as follows: Input the first sample dataset (a normal dataset). ;in, This data represents the access behavior of all users over a period of time. The number of samples in the dataset. The dimension of the multifactor behavioral features; First, construct an isolated tree, including: Step 1: From the first sample dataset Random selection Each sample point constitutes a subset. , as the root node; Step 2, from Randomly select one dimension from the dimensions. And randomly generate a split point. satisfy ; Step 3: Randomly select Among the sample points, the following conditions are met: The sample points are placed in the left child node; otherwise, random sampling will be used. Among the sample points, the following conditions are met: The sample point is placed in the right child node; Recursively execute steps 2 and 3 above until all leaf nodes have only one sample point, or the isolated tree reaches the specified height. ; Repeat the above process until a complete isolated forest is generated; For each sample point Let it traverse every isolated tree and calculate its average height in the forest. The average height of all sample points is normalized, and outlier values are calculated using equations (1) to (3). : (1) (2) (3) In the stage of using the model for identity trust identification, the average height of the behavioral feature data to be verified is recorded at each tree to obtain the anomaly score for each user.
[0036] The application example demonstrates the method for establishing a context-based abnormal user detection model using a Long Short-Term Memory (LSTM) network, as follows: Input the second sample dataset (normal dataset) ,in: For a certain user Access behavior data over a period of time, The number of samples in the dataset. Let be the dimension of the behavioral features, and its labels. The record is 0. Considering that abnormal data is extremely rare in real data sharing environments, especially under highly sensitive conditions, we construct abnormal data such as periodic peak traffic and abnormal user logins based on the main characteristics of anomalies in the data sharing process, and then label them. The record is 1; Construct a long short-term memory neural network model with the following number of hidden layers: , No. The number of neurons in the hidden layer is The network input dimension is The output dimension is 1, and the activation function is... To ensure that the output of the last layer takes values within the range [0,1], the following is adopted: function ; Establish loss function ;in, The results are the ground truth labels and the network output, respectively. Gradient descent is then used to analyze these results. Perform gradient descent to update the neural network parameters until the upper limit of the number of iterations is reached. The process terminates at a certain time, and the model is obtained. In the stage of using the model for identity trust identification, the model is used when the user logs in, and then the corresponding multi-factor behavioral feature data is input at each detection time to obtain the user's abnormal score value.
[0037] In one exemplary instance, the application example of this invention typically sets the upper limit of the number of iterations randomly based on experience. During training, the upper limit is determined based on data convergence, specifically the ratio of the difference in the loss function between two adjacent training processes to the total loss function. ,when Less than a very small amount (usually 1) e-3 When the condition is met (e.g., K), the model can be considered converged, and training can be terminated. If the condition is not met when K is reached, the value of K is further increased, and training continues until convergence. When convergence is not possible (which is extremely unlikely), it is usually necessary to reconstruct the network structure (by increasing the number of layers, etc.) or increase the number of neurons, etc., to improve the model.
[0038] If we consider security detection methods that include traffic threshold limits, taking a context-based abnormal user detection model based on long short-term memory networks as an example, its detection flowchart is as follows: Figure 3 As shown.
[0039] The application example of this invention is based on isolated forest and long short-term memory neural networks. It designs a method for reliable identification of user identity based on multi-factor behavioral characteristics of data sharing personnel during the data sharing process, thereby improving the security of the data sharing process.
[0040] This case study uses access log data from the Civil Aviation Administration of China's database, containing 5308 valid data items. Among these, the uplink and downlink traffic data generated during each user's login and logout process is primarily concentrated in the portion where both uplink and downlink traffic is less than 1 gigabit (GB), comprising 4934 data items, accounting for 93.0% of the total data. Considering abnormal behavior identification based on the isolated forest model, in this example, normal uplink and downlink traffic is 1GB, and the traffic threshold is set to 5GB.
[0041] An isolated forest model is built based on uplink and downlink traffic data. Through learning, the model can identify anomalies at various points. In an application example, the isolated forest can identify abnormal data even when access data does not reach a threshold limit. Accordingly, the cumulative anomaly score of the corresponding user will increase. When a set threshold is reached, the system can implement blocking measures. However, detection based solely on threshold limits will never detect behaviors with long-term anomalies (such as frequent high-traffic flows or information theft) that do not exceed the access traffic threshold for each session.
[0042] In one exemplary instance, the application example of this invention additionally considers user traffic access type characteristics. Based on the dataset information and according to the frequency of occurrence, excluding data without labeled access types, the traffic access types in the dataset are, in order: NTP, ICMP protocol, peer-to-peer network behavior, WebSocket, SSH, X11, MySQL, Oracle, SSL, HTTP_POST, and FTP download. By discretizing and vectorizing these access type values as features for learning, the application example of this invention allows the model to output anomalies that additionally consider access type characteristics, enabling more accurate identification of abnormal behavior as an auxiliary judgment criterion.
[0043] It will be understood by those skilled in the art that all or some of the steps, systems, or apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
Claims
1. A method for trusted user identification for accessing shared data, comprising: Based on the multi-factor behavioral characteristics of users participating in data sharing, real-time detection of single-point anomalies is performed on users. Context anomaly detection is performed on users based on their multi-factor behavioral characteristics participating in data sharing. Based on the results of real-time detection of single-point anomalies and contextual anomalies, determine whether the user's identity is trustworthy; If a user's identity is deemed untrustworthy, block the user's access to data. The multi-factor behavioral features include: user characteristics recorded by the system storing the data during the data sharing process, including one or any combination of the following: user login time, user authorization level, total uplink and downlink traffic since login, user's login IP address, and user's uplink and downlink traffic at each moment; the determination of user identity credibility includes: initializing the outlier score of the isolated forest model to 0, acquiring the outlier score of the isolated forest model according to a preset period, and when the acquired outlier score is greater than or equal to a preset third outlier score threshold, accumulating the scores greater than or equal to the preset third outlier score threshold, and using the accumulated result as the first outlier score; initializing the outlier score of the long short-term memory neural network model to 0, and acquiring the outlier scores of the long short-term memory neural network model according to a preset period. When the obtained abnormal score is greater than or equal to the preset fourth abnormal score threshold, the scores greater than or equal to the preset fourth abnormal score threshold are accumulated, and the accumulated result is used as the score of the second abnormal value; when the score of the first abnormal value is greater than the preset first-class abnormal threshold, or the score of the second abnormal value is greater than the preset second-class abnormal threshold, the user's identity is determined to be abnormal; the multi-factor behavioral characteristics also include: the user's traffic access type; the traffic access type includes one or any combination of the following: Network Time Protocol (NTP), Internet Control Message Protocol (ICMP), peer-to-peer network behavior, WebSocket, SSH remote connection tool, X11 bitmap display window system, MySQL relational database management system, Oracle, SSL secure socket protocol, HTTP_POST application layer protocol request and FTP file transfer protocol download.
2. The method according to claim 1, characterized in that, The real-time detection of single-point anomalies for users includes: A pre-trained isolated forest model is used to perform real-time detection of the single-point anomaly for the user.
3. The method according to claim 2, characterized in that, The determination of whether a user's identity is trustworthy includes: When the score of the outlier output by the isolated forest model is greater than or equal to a pre-set first outlier score threshold, the user's identity is determined to be abnormal. When the score of the outlier output by the isolated forest model is less than or equal to a pre-set second outlier score threshold, the user's identity is determined to be normal.
4. The method according to claim 2, characterized in that, The determination of whether a user's identity is trustworthy includes: When the probability value of the user's identity being abnormal output by the long short-term memory neural network model is greater than or equal to a preset first abnormal probability threshold, the user's identity is determined to be abnormal. When the probability value of the user's identity being abnormal output by the long short-term memory neural network model is less than or equal to a pre-set second abnormal probability threshold, the user's identity is determined to be normal.
5. The method according to claim 2 or 3, characterized in that, Before performing real-time detection of single-point anomalies for users, the method further includes: The isolated forest model is obtained by training using a pre-defined first sample dataset; The long short-term memory neural network model is obtained by training using a pre-defined second sample dataset; The first sample dataset includes one or more of the aforementioned multi-factor behavioral features; the second sample dataset includes one or more of the aforementioned multi-factor behavioral features.
6. A computer storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the method for trusted identification of user identity for shared data access as described in any one of claims 1-5.
7. A terminal, comprising: A memory and a processor, wherein the memory stores a computer program; wherein, The processor is configured to execute computer programs in memory; When the computer program is executed by the processor, it implements the method for trusted identification of user identity for shared data access as described in any one of claims 1-5.