A login security control method, device, equipment and medium

By receiving and comparing the actual user's mobile phone number with the registered mobile phone number, and using a multi-factor communication data model platform for risk detection, the problem of impersonation login on mobile apps has been solved, enabling security control of mobile apps, protecting users' property security, and improving user experience.

CN118432931BActive Publication Date: 2025-12-26CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410679095.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-29
Publication Date
2025-12-26
Estimated Expiration
2044-05-29

AI Technical Summary

Technical Problem

Existing financial anti-fraud models still have security issues in mobile app impersonation login scenarios, especially when illegal logins are made by stealing mobile verification codes or account passwords, making it difficult to effectively identify and defend against.

Method used

By receiving the actual user's mobile phone number sent by the mobile app and comparing it with the registered mobile phone number, a risk detection request is sent to the operator's number retrieval platform if they do not match. The risk detection is performed using a multi-factor communication data model platform, and security controls are implemented on the mobile app based on the detection results, including app exit operations.

Benefits of technology

It enables the detection of impersonation login risks on mobile apps, protecting users' property security, improving user experience, and reducing potential losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118432931B_ABST
    Figure CN118432931B_ABST
Patent Text Reader

Abstract

The application provides a login security control method, device, equipment and medium, which comprises the following steps: receiving a mobile phone number of an actual loginer sent by a mobile terminal application APP; querying a registered mobile phone number of the mobile terminal APP account, and comparing the registered mobile phone number with the mobile phone number of the actual loginer; if the registered mobile phone number is the same as the mobile phone number of the actual loginer, it is judged as normal login; if the registered mobile phone number is different from the mobile phone number of the actual loginer, it is judged that there is a login security risk, a risk detection request is sent to a carrier number taking platform, and the risk detection request carries the registered mobile phone number and the mobile phone number of the actual loginer; receiving a risk detection result obtained after risk detection by a multi-factor communication data model platform, and performing security control on the mobile terminal APP according to the risk detection result. According to the scheme, the mobile phone number for logging in the mobile terminal APP can be detected for risk, and the mobile terminal APP can be controlled for security according to the risk detection result, so that the property safety of the user is protected.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the fields of mobile communication technology and computer, in particular to a security control method, device and equipment for login and medium. BACKGROUND

[0002] Mobile financial APP (including mobile bank, third-party payment wallet, etc.) refers to a channel mode that customers can use financial services on the terminal through the APP of banks or third-party payment companies with smart phones as the carrier. With the progress of communication and Internet technology, the business functions of mobile finance are constantly updated and improved. Through mobile financial APP, customers can handle many businesses such as transfer, remittance, payment, payment, inquiry, credit card, finance, etc., to realize convenient financial services anytime, anywhere and on the body. While mobile financial APP brings convenience to users, it also brings certain security risks such as fraud.

[0003] At present, in order to reduce financial security risks, institutions and organizations use data analysis, model establishment, real-time monitoring, behavior analysis, identity verification and other means to identify potential fraud behaviors to protect their own and customers' interests.

[0004] The security technology of financial anti-fraud mainly includes behavior analysis, machine learning and artificial intelligence, identity verification and authorization, risk assessment and scoring, transaction monitoring and reporting, blockchain technology, biometric technology, etc. These technologies can be used alone or in combination to provide a multi-level, multi-angle anti-fraud defense system.

[0005] The existing financial anti-fraud model is usually based on artificial intelligence, machine learning, data analysis and behavior science, mainly including several types: rule-based model, statistical model, machine learning model, behavior analysis model, prediction model, integrated model, etc.

[0006] However, the data sources of the existing financial anti-fraud model mainly include: transaction data, customer information, social network data, external data, machine-generated event logs and sanctions compliance data, etc. Based on the above data, most of the problems of telecom security risks can be identified and solved, but for the impersonation login of mobile APP, that is, through means such as stealing mobile phone verification code or account password, illegal login to the impersonated mobile financial APP, there are still security problems in this scenario. SUMMARY

[0007] The present application provides a security control method, device and equipment for login to solve the problem of impersonation login by fraudsters through mobile APP.

[0008] In one aspect, the application provides a security control method for login, comprising:

[0009] receiving a mobile phone number of an actual loginer sent by a mobile APP;

[0010] querying a registered mobile phone number of the mobile APP account and comparing the registered mobile phone number with the actual loginer mobile phone number;

[0011] if the registered mobile phone number is the same as the actual loginer mobile phone number, it is determined as normal login; if the registered mobile phone number is different from the actual loginer mobile phone number, it is determined that there is a login security risk, a risk detection request is sent to the operator number taking platform, and the risk detection request carries the registered mobile phone number and the actual loginer mobile phone number;

[0012] receiving a risk detection result obtained after the risk detection by a multi-factor communication data model platform, and performing security control on the mobile APP according to the risk detection result.

[0013] Further, the security control on the mobile APP according to the risk detection result comprises:

[0014] if a risk value represented by the detection result is less than a threshold value, the mobile APP is controlled to perform a normal operation process; if the risk value is greater than or equal to the threshold value, the mobile APP is controlled to exit.

[0015] Optionally, the application also provides a security control method for login, comprising:

[0016] receiving a risk detection request sent by a mobile application APP management platform, the request carrying a registered mobile phone number and an actual loginer mobile phone number of the mobile APP; the actual loginer mobile phone number is a mobile phone number used by a user actually performing a login action, and the registered mobile phone number is a mobile phone number filled in when registering an APP account;

[0017] according to the risk detection request, inputting the actual loginer mobile phone number and the registered mobile phone number to a multi-factor communication data model for risk detection, and checking whether the actual loginer mobile phone number is in a risk database;

[0018] if the actual loginer mobile phone number is in the risk database, it is determined that the risk detection result is a highest risk level;

[0019] if the actual loginer mobile phone number is not in the risk database, actual risk values of each factor except the risk database are calculated respectively, and a risk detection result is obtained after comprehensive processing; wherein the calculation steps of the actual risk value comprise:

[0020] a default risk value is preset for each factor;

[0021] According to the association information between the actual login mobile phone number and the registered mobile phone number, the association value of each factor is calculated in sequence.

[0022] The actual risk value of each factor is obtained by operating the default risk value of each factor and the association value of the corresponding factor, and the operation mode is to subtract the association value from the default risk value.

[0023] Further, the factors in the multi-factor communication data model include:

[0024] Risk database, location information, call and SMS record, identity information, recharge record, and mobile phone unique identification code IMEI.

[0025] Further, the multi-factor communication data model further includes one or more different sub-models, and the sub-models are used to adopt different rules and algorithms according to different factors.

[0026] In a third aspect, the application provides a security control device for login, comprising:

[0027] The receiving module is configured to receive an actual login mobile phone number sent by a mobile terminal APP.

[0028] The comparison module is configured to query a registered mobile phone number of the mobile terminal APP account, and compare the registered mobile phone number with the actual login mobile phone number.

[0029] The sending module is configured to determine that the login is normal if the registered mobile phone number is the same as the actual login mobile phone number, and determine that there is a login security risk if the registered mobile phone number is different from the actual login mobile phone number, send a risk detection request to the operator number taking platform, and the risk detection request carries the registered mobile phone number and the actual login mobile phone number.

[0030] The control module is configured to receive a risk detection result obtained by a multi-factor communication data model platform after risk detection, and perform security control on the mobile terminal APP according to the risk detection result.

[0031] In a fourth aspect, the application provides an electronic device, comprising a memory and a processor.

[0032] The memory is configured to store computer instructions.

[0033] The processor is configured to execute the computer instructions to implement the method according to any one of claims 1-5.

[0034] In a fifth aspect, the present application provides a computer storage medium, wherein the computer storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the method according to any one of claims 1 to 5.

[0035] The application provides a login security control method, device, equipment and medium. The method comprises the following steps: receiving a mobile phone number of an actual login user sent by a mobile terminal application APP; querying a registered mobile phone number of the mobile terminal APP account, and comparing the registered mobile phone number with the mobile phone number of the actual login user; if the registered mobile phone number is the same as the mobile phone number of the actual login user, it is determined that the login is normal; if the registered mobile phone number is different from the mobile phone number of the actual login user, it is determined that there is a login security risk, a risk detection request is sent to an operator number taking platform, and the risk detection request carries the registered mobile phone number and the mobile phone number of the actual login user; receiving a risk detection result obtained by a multi-factor communication data model platform after risk detection, and performing security control on the mobile terminal APP according to the risk detection result. The mobile phone number for logging in the mobile terminal APP can be subjected to risk detection, and the mobile terminal APP can be subjected to security control according to the risk detection result, thereby protecting the property safety of the user. BRIEF DESCRIPTION OF DRAWINGS

[0036] The accompanying drawings, which are incorporated into and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the application.

[0037] Figure 1 A login security control system architecture schematic diagram is provided in the present application.

[0038] Figure 2 A login security control method flowchart is provided in the present application.

[0039] Figure 3 A login security control system interaction principle schematic diagram is provided in the present application.

[0040] Figure 4 A login security control method flowchart is provided in the present application.

[0041] Figure 5 A position information ordered list schematic diagram is provided in the present application.

[0042] Figure 6 A mobile phone call total duration ordered list schematic diagram is provided in the present application.

[0043] Figure 7 A login security control device schematic diagram is provided in the present application.

[0044] Figure 8 A structure schematic diagram of an electronic device is provided in the present application.

[0045] The specific embodiments of the application have been shown and described in the above drawings and text. These drawings and text are not meant to limit the scope of the inventive concept in any way but are merely meant to illustrate the inventive concept to one of ordinary skill in the art by reference to a particular embodiment. DETAILED DESCRIPTION

[0046] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The description of the exemplary embodiments is intended to apply to all alternative embodiments, as would be understood by one skilled in the art. The following exemplary embodiments are described herein with reference to specific side views and cross-section illustrations that are for purposes of illustration only. The exemplary embodiments described herein are not intended to be limiting. Constructions similar to the ones illustrated can be constructed and used in other embodiments, and the scope of the exemplary embodiments described herein is limited only by the claims.

[0047] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards, and provide corresponding operation portal for user to choose authorization or refusal.

[0048] The application scenario of the present application is mainly applied to the login of mobile terminal APP, and is specifically applied to the login of mobile terminal financial APP in the financial service industry.

[0049] With the progress of communication and Internet technology, the business functions of mobile finance are constantly updated and improved. Through mobile terminal financial APP, customers can handle a number of businesses, and realize convenient financial services anytime, anywhere and on the go. While mobile terminal financial APP brings convenience to users, it also brings certain fraud risks.

[0050] The existing financial anti-fraud model data sources mainly include: transaction data, customer information, social network data, external data, machine-generated event logs, sanctions compliance data, etc. Based on the above data, most of the problems of telecommunication security risks can be identified and solved, but for the impersonation login of mobile terminal APP, that is, through means such as stealing mobile phone verification code or account password, illegal login of impersonated mobile terminal financial APP, there are still security problems in this scenario.

[0051] In view of this, the embodiment provides a login security control method, device, equipment and medium, comprising: receiving a mobile phone number of an actual loginer sent by a mobile terminal application APP; querying a registered mobile phone number of the mobile terminal APP account, and comparing the registered mobile phone number with the actual loginer mobile phone number; if the registered mobile phone number is the same as the actual loginer mobile phone number, it is judged as normal login; if the registered mobile phone number is different from the actual loginer mobile phone number, it is judged that there is a login security risk, a risk detection request is sent to an operator number taking platform, the risk detection request carries the registered mobile phone number and the actual loginer mobile phone number; receiving a risk detection result obtained after the risk detection by a multi-factor communication data model platform, and performing security control on the mobile terminal APP according to the risk detection result. The scheme of the application performs risk detection on the mobile phone number of the login mobile terminal APP, and performs security control on the mobile terminal APP according to the risk detection result, which plays a role in protecting the safety of user property.

[0052] The technical scheme of the application and how the technical scheme of the application solves the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments. The embodiments of the application will be described below with reference to the drawings.

[0053] Figure 1 A login security control system architecture schematic diagram provided by the embodiment of the application, the system comprises:

[0054] S101: the mobile terminal APP is used for sending the mobile phone number of the loginer to the mobile terminal APP management platform.

[0055] The mobile terminal APP here mainly refers to a mobile terminal financial APP, including but not limited to a mobile bank APP and a third-party payment wallet APP.

[0056] S102: the mobile operator number taking platform is used for obtaining the mobile phone number of the actual loginer of the mobile terminal APP and interacting with the multi-factor communication data model platform to obtain a risk detection result.

[0057] The mobile operator number taking platform can obtain the mobile phone number of the loginer of the mobile terminal APP based on the network capability of the operator, and after receiving the risk detection request of the APP management platform, accesses the mobile operator multi-factor communication data model platform to obtain the risk detection result.

[0058] S103: the mobile operator multi-factor communication data model platform is used for performing risk detection on the mobile phone number of the actual loginer of the mobile terminal APP, and generating a detection result.

[0059] S104: a mobile terminal APP management platform, configured to interact with the mobile terminal APP and the operator number taking platform.

[0060] Figure 2 A login security control method flow diagram is provided for the embodiments of the present application, applied to a mobile terminal application APP management platform, and the method comprises the following steps:

[0061] S201: receiving a mobile terminal application APP sent actual login mobile phone number.

[0062] The mobile terminal APP here mainly refers to mobile terminal financial APP, including but not limited to mobile banking APP and third-party payment wallet APP. Since the current mobile banking and third-party payment wallet support SMS verification code or account password mode, there is a risk of impersonation login fraud. That is, the fraudster (actual login) obtains the mobile login verification code or account password of the account legal owner, and successfully logs in the APP account of the account legal owner.

[0063] When the user logs in the mobile terminal APP, the mobile terminal APP can access the operator number taking platform to request the login mobile phone number. The operator number taking platform can obtain the login mobile phone number based on the network capability of the operator, and transmit the obtained login mobile phone number to the mobile terminal APP. After the mobile terminal APP management platform receives the mobile phone number sent by the mobile terminal APP, it can process the mobile phone number.

[0064] S202: querying the registered mobile phone number of the mobile terminal APP account, and comparing the registered mobile phone number with the actual login mobile phone number.

[0065] The registered mobile phone number of the APP account legal user is stored in the mobile terminal APP management platform. When the actual login mobile phone number sent by the mobile terminal APP is received, the registered mobile phone number of the APP account is first queried from the database of the mobile terminal APP management platform. After the registered mobile phone number is queried, the actual login mobile phone number sent by the APP is compared with the registered mobile phone number, and it is judged whether the two mobile phone numbers are the same. According to the judgment result, subsequent operation is performed.

[0066] S203: if the registered mobile phone number is the same as the actual login mobile phone number, it is judged as normal login; if the registered mobile phone number is different from the actual login mobile phone number, it is judged that there is a login security risk, and a risk detection request is sent to the operator number taking platform, and the risk detection request carries the registered mobile phone number and the actual login mobile phone number.

[0067] When the two mobile phone numbers are the same, it means that the actual login user of the mobile terminal APP is the legal registered user of the APP. At this time, it can be judged that the login of the user is normal and there is no risk. The user can continue to use the APP for business operation.

[0068] When the two mobile phone numbers are found to be different, it indicates that the actual loginer of the APP may not be the legal registered user of the account, and there may be a risk of impersonation login. At this time, risk detection is needed, and a series of specific methods are used to judge whether the loginer has a fraud risk.

[0069] Since the mobile terminal APP management platform itself cannot perform corresponding risk detection, the APP management platform needs to send the two mobile phone numbers to the operator number taking platform at the same time, and send a risk detection request to the multi-factor communication data model platform through the operator number taking platform. As the provider and manager of mobile phone numbers, the operator has more comprehensive user data and more powerful technical capabilities to perform risk detection. The operator can analyze the user's call records, SMS records and other data to determine whether the mobile phone number has abnormal behavior or risk.

[0070] S204, receiving the risk detection result obtained after the multi-factor communication data model platform performs risk detection, and performing security control on the mobile terminal APP according to the risk detection result.

[0071] The multi-factor communication data model platform can perform risk detection on the mobile phone number according to the established data model and output the risk detection result. After receiving the risk detection result returned by the multi-factor communication data model platform, the APP management platform can take different measures to protect the property of the account owner according to the detection result.

[0072] In this embodiment, the mobile terminal APP management platform receives the mobile terminal application APP sent actual loginer mobile phone number; query the registered mobile phone number of the mobile terminal APP account, compare the registered mobile phone number with the actual loginer mobile phone number; if the registered mobile phone number and the actual loginer mobile phone number are the same, it is judged as normal login; if the registered mobile phone number and the actual loginer mobile phone number are different, it is judged that there is a login security risk, and a risk detection request is sent to the operator number taking platform, and the risk detection request carries the registered mobile phone number and the actual loginer mobile phone number; receiving the risk detection result obtained after the multi-factor communication data model platform performs risk detection, and performing security control on the mobile terminal APP according to the risk detection result. By comparing the actual loginer mobile phone number of the APP with the registered mobile phone number, sending a risk detection request to the operator number taking platform when the two numbers are different, and performing security control on the APP according to the risk detection result, the effect of protecting the safety of user property is achieved, and the security of the mobile application and the privacy of the user data are guaranteed.

[0073] Optionally, the security control on the mobile terminal APP according to the risk detection result comprises:

[0074] If the risk value represented by the detection result is less than the threshold value, the mobile terminal APP is controlled to execute a normal operation process; if the risk value is greater than or equal to the threshold value, the mobile terminal APP is controlled to exit.

[0075] After the two mobile phone numbers are detected for risk by the multi-factor communication data model platform, an actual risk detection result value is given, and the detection result is returned to the operator number taking platform. After receiving the risk detection result of the multi-factor communication data model platform, the mobile terminal APP management platform can determine, according to a pre-set risk value threshold value, that the mobile terminal APP is forced to exit when the risk detection result value is greater than or equal to the threshold value, so as to protect the property of the user from being damaged. When the risk value is less than the pre-set threshold value, the APP can continue to execute a subsequent process.

[0076] The embodiment determines the execution state of the APP according to the size of the risk value. When the risk value is high, the APP is forced to exit, which can prevent potential malicious behavior or fraudulent activities from continuing to be executed, thereby protecting the safety of the property of the user. When the risk value is low, the APP can normally execute, and the user can smoothly perform various operations and enjoy the services provided by the APP. This can improve the user experience and reduce potential losses of the user.

[0077] Figure 3 A login security control system interaction principle schematic diagram provided by the embodiment of the application is shown in the following figure,

[0078] The general principle is as follows:

[0079] S301: The APP calls an SDK method.

[0080] SDK (Software Development Kit, software development kit) generally refers to a collection of development tools used by software engineers to develop application software for a specific software package, software framework, hardware platform, operating system, etc. It is usually used to help developers more easily access and use the functions of a specific platform or service.

[0081] The APP calling the SDK method usually occurs when the user performs certain operations, such as login, registration, or identity verification. Under the premise that the user agrees to authorize the mobile terminal APP to take numbers, after the user successfully logs in to the mobile terminal APP, the mobile terminal APP can take numbers by itself. When the APP needs to obtain the mobile phone number of the login user, it triggers a number taking request through the SDK. By calling the SDK method, the APP can more conveniently access the operator platform.

[0082] S302: The SDK accesses the mobile operator number taking platform and requests the mobile phone number of the login user.

[0083] Mobile operators (such as telecom, mobile, and Unicom) have the real mobile phone number of the user, and can directly provide the current mobile phone number. The SDK can obtain the real mobile phone number of the current login user by accessing the operator number taking platform, thereby ensuring the accuracy of the data.

[0084] S303: The number taking platform returns the mobile phone number to the SDK.

[0085] After the operator number taking platform receives the number taking request of the SDK, it obtains the actual login user's mobile phone number based on the network capability of the operator, and returns the obtained mobile phone number to the SDK. Here, the mobile phone number refers to the real mobile phone number of the login user of the mobile banking or third-party payment wallet account. Currently, it is not possible to determine whether the login user is a fraud.

[0086] S304: The SDK transmits the login user's mobile phone number to the mobile terminal APP.

[0087] S305: The APP sends the login user's mobile phone number to the mobile terminal APP management platform.

[0088] After the SDK obtains the mobile phone number of the login user from the operator number taking platform, it transmits the mobile phone number to the mobile terminal APP through the interface or callback method provided by the SDK. The mobile terminal APP sends the mobile phone number data as part of the request to the mobile terminal APP management platform, and the APP management platform performs subsequent data analysis or other logical processing.

[0089] S306: The mobile terminal APP management platform sends a risk detection request carrying the login user's mobile phone number and the registered mobile phone number to the operator number taking platform.

[0090] When the APP management platform receives the actual login user's mobile phone number, it searches for the registered mobile phone number of the APP account in the APP management platform database. When the two mobile phone numbers are found to be different, the two mobile phone numbers are sent to the operator number taking platform to request the operator number taking platform to perform impersonation risk detection.

[0091] S307: The number taking platform forwards the mobile phone number and the risk detection request to the multi-factor communication data model platform for risk detection.

[0092] The actual risk detection process is completed by the multi-factor communication data model platform. Therefore, after receiving the risk detection request, the operator number taking platform needs to forward the risk detection request to the multi-factor communication data model platform, and the multi-factor communication data model platform outputs the risk detection result after detecting according to the established multi-factor communication data model.

[0093] S308: The operator multi-factor communication data model platform returns the impersonation risk detection result to the number taking platform.

[0094] S309: The number taking platform returns the impersonation risk detection result to the APP management platform.

[0095] The multi-factor communication data model platform returns the risk detection result after risk detection to the operator number taking platform through data interaction with the operator number taking platform, and the operator number taking platform returns the risk detection result to the mobile terminal APP management platform again.

[0096] The operator number taking platform is responsible for managing and controlling access permissions to communication data. Through forwarding by the number taking platform, it can be ensured that only authorized and verified APP management platforms can receive the detection result, preventing unauthorized access and data misuse.

[0097] S310: The APP management platform performs security control on the mobile terminal APP according to the risk detection result.

[0098] This step is the same as step S204 and will not be repeated here.

[0099] Figure 4 Another login security control method is also provided for the present application, applied to a multi-factor communication data model platform, comprising:

[0100] S401, receiving a risk detection request sent by a mobile terminal application APP management platform, the request carrying a mobile terminal APP actual login user mobile phone number and a registered mobile phone number, the actual login user mobile phone number being the mobile phone number used by the user actually performing the login action, and the registered mobile phone number being the mobile phone number filled in when registering the APP account.

[0101] A data model is an abstract representation of the characteristics of real-world data, used to describe and organize the structure and relationship of data. It is the core and foundation of a database system, providing a unified framework for database design, implementation and management, usually consisting of three parts: data structure, data operation and data constraint. A multi-factor communication data model is a data model that combines multiple influencing factors to analyze and predict relevant data in the communication field.

[0102] This risk detection request is triggered when the APP management platform compares the registered mobile phone number with the login user mobile phone number. The request contains two key pieces of information: the actual login user mobile phone number and the registered mobile phone number. The actual login user mobile phone number refers to the mobile phone number used by the user actually performing the login action, and the registered mobile phone number refers to the mobile phone number filled in when registering the APP account. These two mobile phone numbers are important basis for verifying user identity and identifying potential risks.

[0103] S402, according to the risk detection request, input the actual login user mobile phone number and the registered mobile phone number into the multi-factor communication data model for risk detection, and check whether the actual login user mobile phone number is in the risk database.

[0104] According to the risk detection request, the multi-factor communication data model platform will import the actual login mobile phone number and the registered mobile phone number as key input parameters into the multi-factor communication data model that has been constructed for risk detection. This process aims to accurately assess the security of the login request through the analysis of multiple factors. Through the calculation and analysis of the multi-factor communication data model, the platform can obtain a risk detection result, which will serve as the basis for platform decision-making.

[0105] The risk database is a database system specifically used to store information related to risky activities, covering illegal activities such as network fraud and malicious attacks. This factor can be used to check whether the mobile phone number is associated with known malicious behavior. When the multi-factor communication data model platform receives a risk detection request, the first step is to query the actual login mobile phone number provided by the APP management platform to verify whether the mobile phone number has been recorded in the risk database. By comparing the records in the risk database, high-risk mobile phone numbers can be quickly identified, thereby preventing potential security threats.

[0106] S403, if the actual login mobile phone number is in the risk database, determine the risk detection result as the highest risk level.

[0107] If the query finds that the mobile phone number exists in the risk database, it can be preliminarily determined that the login request contains high security risks. At this time, the risk detection result level can be determined as the highest risk level. The implementation of this step helps the platform to identify and respond to potential security threats in a timely manner, ensuring the security and reliability of communication data.

[0108] S404, if the actual login mobile phone number is not in the risk database, calculate the actual risk value for each factor other than the risk database, and obtain the risk detection result after comprehensive processing. The calculation steps of the actual risk value include: pre-setting a default risk value for each factor; calculating the correlation value of each factor according to the correlation information between the actual login mobile phone number and the registered mobile phone number; calculating the actual risk value of each factor by operating the default risk value of each factor with the corresponding correlation value, and the operation mode is to subtract the correlation value from the default risk value.

[0109] If the actual login mobile phone number is not listed in the risk database, but the actual login mobile phone number is inconsistent with the registered mobile phone number, there are two possibilities: one is that the registrant of the mobile terminal APP uses other mobile phones to log in to the account; the other possibility is that the non-registered person attempts to log in. In view of the two possibilities, it is impossible to directly determine the risk level only by the difference between the mobile phone numbers. In order to ensure the accuracy and comprehensiveness of risk assessment, it is necessary to calculate the actual risk value of each related factor according to the multi-factor communication data model, and comprehensively process to obtain the final risk detection result.

[0110] Among them, the actual risk value of each factor is determined by the following steps: first, a default risk value is set for each factor; then, according to the association information of the two mobile phone numbers, the association value of each factor is calculated in turn; finally, the default risk value and the association value of the corresponding factor are operated to obtain the actual risk value of the factor. The specific operation method is: subtract the association value from the default risk value, thereby obtaining the actual risk value.

[0111] In this embodiment, the risk value is defined as an integer type data, which is used to quantitatively represent the high and low of the risk. The default risk value is set to 100, which is used as the reference value of risk assessment. With the subsequent calculation, the value will be adjusted according to the association value of each factor. Finally, the system returns an actual risk value, and the larger the value, the higher the risk. If the two mobile phone numbers have no association, the association value is 0. In this case, the actual risk value will be equal to the default risk value, that is, 100. This indicates that in the absence of association information, the mobile phone login behavior is considered to have a high risk.

[0112] In addition, the default risk value of each factor can be flexibly set according to the actual situation. In this embodiment, the default risk values of different factors may be different, for example, the location information, the call and message record, the user identity information, the mobile phone recharge record and the mobile phone IMEI information, etc. Each of them has a different default risk value. For example: the default risk value of the location information is set to 20, the default risk value of the call and message record is 50, the default risk value of the user identity information is 10, the default risk value of the mobile phone recharge record is 10, and the default risk value of the mobile phone IMEI information is 10. The default risk values of the five factors are 100 in total. Such a setting method can more accurately reflect the different weights of each factor in risk assessment, and improve the accuracy and reliability of risk assessment.

[0113] The comprehensive processing mode in the scheme is to add the actual risk values of each factor to obtain a final risk value as the risk detection result. In actual application, the risk values of various factors can be combined in a certain way (such as weighted average, machine learning model, etc.) to obtain a total risk score or risk level. The total risk score or level will be used as the final risk detection result to guide subsequent decision-making.

[0114] The login security control method provided by the embodiment fully utilizes the powerful analysis capability of the multi-factor communication data model, detects the login risk through the multi-factor data model platform, and first checks whether the actual login user's mobile phone number is in the risk database. If the mobile phone number is in the risk database, it is determined that the risk detection result is the highest risk level. Since the risk database usually contains mobile phone numbers directly related to high-risk activities, this method can accurately and quickly identify potential risks without complex calculations or analysis. If the mobile phone number is not in the risk database, the actual risk value of each factor other than the risk database is calculated, and the risk detection result is obtained after comprehensive processing. The actual risk value calculation can consider more factors and more accurately assess the risk level, thereby obtaining a more comprehensive risk assessment result and providing corresponding risk control measures, thereby effectively improving the security of the mobile APP login process, avoiding user inconvenience or loss due to misjudgment, and providing an effective risk management means for enterprises and customers.

[0115] Optionally, the factors in the multi-factor communication data model can include:

[0116] Risk database, location information, call and message records, identity information, recharge records, and mobile phone unique identification code IMEI.

[0117] The risk database is a database that stores risk-related information, which can include the activity records, tools used, attack patterns, resource characteristics, etc. of illegal actors. By using the risk database, enterprises can monitor and timely perceive attack risks through multiple channels, and conduct targeted defense.

[0118] Location information: Location information can reflect the user's activity range and habits. If the location information of the login request is significantly different from the user's historical location information, it may mean that the account is at risk of being impersonated by others.

[0119] Call and message records: Analyzing the user's call and message records can reveal the user's communication habits and possible associations. For example, abnormal call frequency, communication with high-risk numbers, etc. can all be risk signals.

[0120] Identity Information: Identity information includes sensitive information such as the user's name and ID number. By verifying the authenticity and consistency of identity information, the user's identity can be further confirmed, reducing the risk of being impersonated.

[0121] Recharge Records: Recharge records can reflect the user's account activity and consumption habits. If there is a sudden large amount of recharge or abnormal recharge behavior in the account, it may mean that the account is at risk of being manipulated by others.

[0122] IMEI: IMEI is the unique identification code of a mobile phone, which can be used to track and identify mobile devices. By analyzing IMEI information, it can be determined whether the login request comes from the user's own device, thereby adding an additional layer of security.

[0123] In practical applications, the multi-factor communication data model can selectively consider these factors according to specific needs and data availability. By comprehensively using these factors, the model can more comprehensively assess the risk of login requests and provide more accurate and effective security control.

[0124] Optionally, the multi-factor communication data model also includes one or more different sub-models, which are used to adopt different rules and algorithms according to different factors.

[0125] Data sub-models are models that describe or simulate specific local areas of data features or data structures. They are relative to the overall data model and focus on a certain part or specific aspect of the data. Data sub-models can be used to analyze and understand specific properties, relationships or patterns of data in order to better process, manage and apply these data.

[0126] The multi-factor communication data model in this scheme includes one or more different sub-models. These sub-models are designed to adopt targeted rules and algorithms for risk detection according to different factor characteristics.

[0127] Specifically, the multi-factor communication data model integrates multiple sub-models to achieve fine processing of different communication data factors. Each sub-model is designed for a specific data factor, such as location information, call and message records, user identity information, mobile phone recharge records and mobile phone IMEI information, etc. These algorithms and rules fully consider the characteristics, change patterns and relevance to risk of data factors, so as to more accurately assess the risk contained in each factor.

[0128] By the use of sub-models, the method can realize the comprehensive analysis and trade-off of different communication data factors. Each sub-model calculates the risk value of the corresponding factor according to its own algorithm and rules, and these risk values are then integrated into the overall risk assessment. In this way, the method can comprehensively and accurately detect the risk of mobile phone login behavior and provide effective risk management means for enterprises.

[0129] The different rules and algorithms adopted by each sub-model are described in detail below. For convenience of description, the actual login mobile phone number of the APP and the registered mobile phone number are replaced by A and B respectively.

[0130] First, the rules and algorithms of the location information correlation value of mobile phone A and B are introduced:

[0131] Through base station positioning, the operator can obtain the location information of the user. The location data of each mobile phone within three months is preprocessed to establish a preprocessing database. Each mobile phone passes through several base stations every day, and all LAC (Location Area Code), CID (Cell Identity) and the time spent are recorded. A fixed-length queue (Fixed-Length Queue) with a length of 90 (three months) is established with LAC+CID as the queue name, and the values in the queue are the time spent in that LAC+CID every day. Input the queue in chronological order, then the data in the queue is the effective data of the last three months. Take the average value of all data in the queue, with LAC+CID as the key and the average value as the value, to generate a key-value pair. Then generate a sorted list (Sorted List) with the value in order, i.e. the location information list, which is arranged from large to small according to the average value, and the longest 7 values are taken.

[0132] An ordered list (Ordered List) is a list format used in text or HTML to represent a series of items, where the items are arranged in a certain order (usually numerical or alphabetical). An ordered list helps to organize and present information, making it easier for readers to understand the items and their order in the list.

[0133] When performing location correlation calculation, first obtain the ordered list of location information corresponding to mobile phone A and B respectively, and assign scores from 7 to 1 in order according to the average value from large to small (see Figure 6). Secondly, the same values in the two ordered lists are compared. If the LAC+CID are the same, the corresponding scores are taken, summed and divided by 2 to obtain the association value 1. If the LAC is the same and the CID is different, it means that the two are relatively close, but not very close, so the corresponding scores are taken, summed and divided by 4 to obtain the association value 2. In this way, the association values 1, 2, … are obtained, and then the position information association value is obtained by summing these association values (if the position information association value is greater than 20, it is directly assigned a value of 20). Finally, the position information risk value is obtained by subtracting the position information association value from 20.

[0134] Figure 5 The position information ordered list provided by the embodiments of the present application is shown in the figure. Taking Figure 5 for example, it is found after comparison that Aa in the two lists is the same, and the association value 1=(7+7)÷2=7. The LAC of Bb and Bt in the list is the same and the CID is different, and the association value 2=(6+6)÷4=3. The LAC of Cc and Cs in the list is the same and the CID is different, and the association value 3=(5+1)÷4=1.5. Thus, the position information association value=7+3+1.5=11.5, and the actual position information risk value=20-11.5=8.5 can be determined according to the default risk value 20 set for the position information.

[0135] The rules and algorithms for associating the mobile phone number and the call and message record are as follows. Similar to the association calculation of the position information, only the phone numbers called by the registered mobile phone number and the login mobile phone number in the past three months are considered, and the sum of the call time of each call is taken as the value. The ordered list with a length of 10 is established. The message record is the same. The call record is taken as an example for subsequent description. The default risk values of the call record and the message record are processed according to the weight ratio of 8:2. Since the default risk value of the call and message record is set to 50 in the present scheme, the default risk value of the call record is 40 and the default risk value of the message record is 10 after processing according to the weight ratio.

[0136] When the call and message record association calculation is performed, the ordered lists of the call records corresponding to the mobile phone numbers A and B are obtained first, and the scores from 10 to 1 are assigned in the order of the sum of the call time from large to small (see Figure 6). Secondly, it is inquired whether the opposite party's mobile phone number is in each ordered list. If only one party has it, the corresponding score is taken as the correlation value 1. If both parties have it, the corresponding scores are summed and multiplied by 2 to be the correlation value 1. Then the same values in the two ordered lists are compared, i.e. whether there is a mutual relationship of calling by both parties. If so, the corresponding score is summed and divided by 2 to be the correlation value 2. In this way, the correlation values 1, 2, … are obtained. Then the communication record correlation value is obtained by summing the correlation values (if the communication record correlation value is greater than 40, it is directly assigned as 40). Similarly, the short message record correlation value is obtained. Finally, the communication and short message record risk value is obtained by subtracting the communication and short message record correlation value from 50.

[0137] Figure 6 The ordered list of total call time of mobile phone provided by the embodiment of the present application is shown in the figure. Figure 6 For example, it is known by comparison that the two lists have each other, i.e. A and B often call each other and talk, and the correlation value 1=(10+9)×2=38. The mobile phone F exists in both lists, and the correlation value 2=(6+6)÷2=6. The communication record correlation value=38+6=44>40, which is assigned as 40. Assuming that the short message record correlation value is 6, the communication and short message record risk value=50-40-6=4.

[0138] The rules and methods for mobile phone A and B to perform mobile phone identity information correlation calculation are as follows. The proportion of mobile phone real-name system is very high at present. Through analysis of the identity card information corresponding to the mobile phone A and B, certain correlation information can be obtained. For example, if the addresses are the same, the correlation value 1 is 10. If the first 6 digits of the ID number are the same, the correlation value 2 is 3. If the surnames are the same, the correlation value 3 is 1. According to the above rules, the correlation values 1, 2, … are obtained. Then the identity information correlation value is obtained by summing the correlation values (if the identity information correlation value is greater than 10, it is directly assigned as 10). The identity information risk value is obtained by subtracting the identity information correlation value from 10.

[0139] For example, the addresses corresponding to the mobile phone A and B are different, the first 6 digits of the ID number are the same, and the surnames are the same. Then the identity information correlation value=3+1=4, and the identity information risk value=10-4=6.

[0140] The rules and methods for mobile phone A and B to perform mobile phone recharge record correlation calculation are as follows. The rule is relatively simple. It is inquired whether there is a mutual recharge record of mobile phone fee within 3 months. If there is one record of more than 30 yuan, the correlation value 1 is 3. If there are two records of more than 30 yuan, the correlation value 1 is 7. If the total amount of cumulative recharge is more than 200 yuan, the correlation value 2 is 5. The recharge record risk value is obtained by subtracting the recharge record correlation value from 10.

[0141] For example, if there is a record of a recharge between mobile phone A and B once, and the recharge amount is 300 yuan, then the recharge record correlation value = 5, and the recharge record risk value = 10-5 = 5.

[0142] The rules and methods for mobile phone A and B to perform mobile IMEI information correlation calculation are as follows. Since it is common for family members to use each other's mobile phones, IMEI information can be used to determine that the two mobile phones are associated. However, due to the existence of second-hand mobile phones, the IMEI information correlation needs to be increased by a time limit to reduce the probability of false judgment of second-hand mobile phones. Calculate the IMEI records of mobile phone A and mobile phone B within 3 months, and the start and stop time of each IMEI value. If mobile phone A and B have the same IMEI information and the start time of one of them is less than 2 days from the stop time of the other, the IMEI information correlation value is 8. If mobile phone A and B have the same IMEI information but the start time of one of them is more than 2 days and less than 1 month from the stop time of the other, the IMEI information correlation value is 6. If mobile phone A and B have the same IMEI information but the start time of one of them is more than 1 month from the stop time of the other, the IMEI information correlation value is 4. Subtract the IMEI information correlation value from 10 to get the IMEI information risk value.

[0143] For example, if mobile phone A and B have the same IMEI information within three months but the start time of one of them is 40 days from the stop time of the other, then the IMEI information correlation value = 4, and the IMEI information risk value = 10-4 = 6.

[0144] The location information risk value, call and message record risk value, identity information risk value, mobile phone recharge record risk value, and IMEI information risk value are added up to obtain the risk detection result. Taking the above data as an example, the risk detection result = 8.5 + 4 + 6 + 5 + 6 = 29.5.

[0145] In the above embodiments, the sub-models in the multi-factor communication data model adopt different rules and algorithms according to different factors, which can be optimized for specific factors and flexibly adapt to different needs. Each sub-model performs fine processing on different data factors and obtains its own risk detection result through specific algorithms and rules. The outputs of these sub-models are comprehensively considered, which not only makes full use of the professionalism and advantages of each sub-model, but also makes up for the limitations and deficiencies of a single model. Through the synergistic effect of multiple models, this model can provide more reliable and accurate risk detection results.

[0146] Figure 7 A security control device for login provided by the embodiments of the present application, comprising:

[0147] receive a mobile terminal APP sent actual login mobile phone number.

[0148] Comparison module, for querying the registration mobile phone number of the mobile terminal APP account, and comparing the registration mobile phone number with the actual login mobile phone number.

[0149] Sending module, if the registration mobile phone number is same as the actual login mobile phone number, it is judged as normal login; if the registration mobile phone number is different from the actual login mobile phone number, it is judged as existing login security risk, and a risk detection request is sent to the operator number platform, and the risk detection request carries the registration mobile phone number and the actual login mobile phone number.

[0150] Control module, for receiving the risk detection result obtained after the multi-factor communication data model platform carries out risk detection, and carrying out security control on the mobile terminal APP according to the risk detection result.

[0151] Figure 8 An electronic device schematic diagram provided by the embodiment of the application comprises a memory and a processor.

[0152] The memory is used for storing computer instructions.

[0153] The processor is used for executing computer instructions to realize the method shown in any one of claims 1 to 5.

[0154] The embodiment of the application further provides a computer storage medium, which stores computer instructions, and the computer instructions are executed by the processor to realize the method shown in any one of claims 1 to 5.

[0155] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The specification and examples given are exemplary only and the true scope and spirit of the application are indicated by the following claims. The true scope and spirit of the application are indicated by the following claims.

[0156] It should be understood that the application is not limited to the precise construction that has been described above and shown in the accompanying drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is indicated only by the appended claims.

Claims

1. A security control method of login, characterized by, The application is applied to a mobile terminal application APP management platform, comprising: receiving a mobile terminal APP sent actual login mobile phone number; querying the registered mobile phone number of the mobile terminal APP account, and comparing the registered mobile phone number with the actual login mobile phone number; if the registered mobile phone number is the same as the actual login mobile phone number, it is judged as normal login; if the registered mobile phone number is different from the actual login mobile phone number, it is judged that there is a login security risk, a risk detection request is sent to the operator number taking platform, and the risk detection request is sent to the multi-factor communication data model platform through the operator number taking platform, the risk detection request carries the registered mobile phone number and the actual login mobile phone number; the risk detection is to input the actual login mobile phone number and the registered mobile phone number into the multi-factor communication data model, check whether the actual login mobile phone number is in the risk database, if the actual login mobile phone number is in the risk database, it is determined that the risk detection result is the highest risk level, if the actual login mobile phone number is not in the risk database, the actual risk value of each factor except the risk database is calculated respectively, and the risk detection result is obtained after comprehensive processing, wherein the actual risk value calculation step comprises: a default risk value is set for each factor, the correlation value of each factor is calculated in turn according to the correlation information between the actual login mobile phone number and the registered mobile phone number, the default risk value of each factor is operated with the correlation value of the corresponding factor, and the actual risk value of each factor is obtained, and the operation mode is to subtract the correlation value from the default risk value; receiving the risk detection result obtained after the multi-factor communication data model platform performs risk detection, and performing security control on the mobile terminal APP according to the risk detection result.

2. The method of claim 1, wherein, The security control on the mobile terminal APP according to the risk detection result comprises: if the risk value represented by the detection result is less than a threshold value, the mobile terminal APP is controlled to execute a normal operation process; if the risk value is greater than or equal to the threshold value, the mobile terminal APP is controlled to exit.

3. A security control method of login, characterized by, The application is applied to a multi-factor communication data model platform, comprising: receiving a risk detection request sent by a mobile terminal application APP management platform, the request carrying an actual login mobile phone number and a registered mobile phone number of a mobile terminal APP; the actual login mobile phone number is a mobile phone number used by a user actually performing a login action, and the registered mobile phone number is a mobile phone number filled in when registering an APP account; according to the risk detection request, inputting the actual login mobile phone number and the registered mobile phone number into a multi-factor communication data model for risk detection, and checking whether the actual login mobile phone number is in a risk database; if the actual login mobile phone number is in the risk database, it is determined that the risk detection result is the highest risk level; if the actual login mobile phone number is not in the risk database, the actual risk value of each factor except the risk database is calculated respectively, and the risk detection result is obtained after comprehensive processing; wherein the actual risk value calculation step comprises: a default risk value is set for each factor; According to the association information between the actual login mobile phone number and the registered mobile phone number, the association value of each factor is calculated in turn; The actual risk value of each factor is obtained by operating the default risk value of each factor and the association value of the corresponding factor, and the operation mode is to subtract the association value from the default risk value.

4. The method of claim 3, wherein, The factors of the multi-factor communication data model include: Risk database, location information, call and message record, identity information, recharge record, and IMEI.

5. The method of claim 4, wherein, The multi-factor communication data model includes one or more different sub-models, which are used to adopt different rules and algorithms according to different factors.

6. A security control device for login, characterized by It includes: The receiving module is used to receive the actual login mobile phone number sent by the mobile terminal APP; The comparison module is used to query the registered mobile phone number of the mobile terminal APP account and compare the registered mobile phone number with the actual login mobile phone number; The sending module is used to determine that it is a normal login if the registered mobile phone number is the same as the actual login mobile phone number; If the registered mobile phone number is different from the actual login mobile phone number, it is determined that there is a login security risk, a risk detection request is sent to the operator number taking platform, and the risk detection request is sent to the multi-factor communication data model platform through the operator number taking platform, and the risk detection request carries the registered mobile phone number and the actual login mobile phone number; The risk detection is to input the actual login mobile phone number and the registered mobile phone number into the multi-factor communication data model, check whether the actual login mobile phone number is in the risk database, if the actual login mobile phone number is in the risk database, it is determined that the risk detection result is the highest risk level, if the actual login mobile phone number is not in the risk database, the actual risk value of each factor except the risk database is calculated, and the risk detection result is obtained after comprehensive processing, wherein the calculation steps of the actual risk value include: a default risk value is set for each factor, the association value of each factor is calculated in turn according to the association information between the actual login mobile phone number and the registered mobile phone number, the actual risk value of each factor is obtained by operating the default risk value of each factor and the association value of the corresponding factor, and the operation mode is to subtract the association value from the default risk value; The control module is used to receive the risk detection result obtained after the multi-factor communication data model platform performs risk detection, and to perform security control on the mobile terminal APP according to the risk detection result.

7. An electronic device, comprising: It includes: Memory and processor; The memory is used to store computer instructions; The processor is used to execute the computer instructions to realize the method of any one of claims 1-5.

8. A computer storage medium, characterized in that The computer storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the method of any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data processing method and device, equipment and storage medium

    CN111191925A

  • Risk level login processing method and system, computer equipment and storage medium

    CN114357420A