User authentication method, device, electronic device, and storage medium
Through trust level assessment and authentication methods based on user feature information, the problems of unauthorized access and data leakage in the security protection of shared resources are solved, precise access permission control is achieved, and resource security is improved.
Patent Information
- Application Number
- CN202410486078.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-22
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2044-04-22
AI Technical Summary
In existing technologies, the security protection of shared resources faces threats such as unauthorized user access, data leakage, resource paralysis and data tampering. Identity authentication and encryption technologies have defects and cannot fully guarantee resource security.
By determining the characteristic values of characteristic indicators based on the characteristic information of the target user, obtaining the characteristic value ranges corresponding to multiple trust levels, and determining the comprehensive membership of the trust level based on the characteristic values of the characteristic indicators and the characteristic value ranges of the trust levels, the trust level of the target user is determined, and authentication is performed based on the trust level to accurately control the user's access rights to shared resources.
It enables accurate determination of trust levels and authentication when users access shared resources, improving the security of shared resources and the accuracy of access rights control.
Smart Images

Figure CN118449722B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the fields of terminal technology, IT (Information Technology) application and security technology, and in particular to a user authentication method, device, electronic device and storage medium. Background Art
[0002] With the development of information technology, more and more resources are being shared, stored, and transmitted across networks, and the security of these resources faces increasingly severe challenges. If shared resources are not properly protected, they may face various security threats and risks, resulting in resource failure, data loss, or tampering. Therefore, improving the security of shared resources is an urgent issue that needs to be addressed. Summary of the Invention
[0003] The present disclosure provides a user authentication method, device, electronic device and storage medium.
[0004] In a first aspect, the present disclosure provides a user authentication method, the method comprising: determining a characteristic value of a characteristic indicator based on characteristic information of a target user; obtaining characteristic value ranges corresponding to multiple trust levels; for each trust level, determining a comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, wherein the comprehensive membership represents the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level; determining the trust level to which the target user belongs based on the comprehensive membership of each of the trust levels; and authenticating the target user based on the trust level to which the target user belongs.
[0005] In a second aspect, the present disclosure provides a user authentication device, which includes: a first determination module for determining a characteristic value of a characteristic indicator based on characteristic information of a target user; an acquisition module for acquiring characteristic value ranges corresponding to multiple trust levels; a second determination module for determining, for each trust level, the comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, wherein the comprehensive membership represents the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level; a third determination module for determining the trust level to which the target user belongs based on the comprehensive membership of each trust level; and an authentication module for authenticating the target user based on the trust level to which the target user belongs.
[0006] In a third aspect, the present disclosure provides an electronic device comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the user authentication method disclosed in an embodiment of the present disclosure.
[0007] In a fourth aspect, the present disclosure provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the user authentication method disclosed in the embodiment of the present disclosure.
[0008] In a fifth aspect, the present disclosure provides a computer program product, including a computer program, which, when executed by a processor, implements the user authentication method disclosed in the embodiment of the present disclosure.
[0009] The technical solutions provided by the embodiments of the present disclosure bring at least the following beneficial effects:
[0010] By determining the characteristic values of characteristic indicators based on the characteristic information of the target user, obtaining the characteristic value ranges corresponding to multiple trust levels, and for each trust level, determining the comprehensive membership of the trust level based on the characteristic values of the characteristic indicators and the characteristic value ranges corresponding to the trust level, determining the trust level to which the target user belongs based on the comprehensive membership of each trust level, and authenticating the target user based on the trust level to which the target user belongs, it is possible to accurately determine the trust level of the target user based on the characteristic information of the target user when the target user accesses shared resources, and authenticate the target user, thereby accurately controlling the target user's access rights to shared resources and improving the security of shared resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0012] Figure 1 4 is a flow chart showing a user authentication method according to an exemplary embodiment;
[0013] Figure 2 is a flow chart showing another user authentication method according to an exemplary embodiment;
[0014] Figure 3 is a flow chart showing another user authentication method according to an exemplary embodiment;
[0015] Figure 4 This is a flow chart showing identity authentication based on a SIM card according to an exemplary embodiment;
[0016] Figure 5This is a flow chart showing an identity authentication based on a preset list according to an exemplary embodiment;
[0017] Figure 6 1 is a schematic structural diagram of a user authentication device according to an exemplary embodiment;
[0018] Figure 7 The figure is a structural block diagram of an electronic device according to an exemplary embodiment.
[0019] The above drawings illustrate specific embodiments of the present disclosure, which will be described in more detail below. These drawings and textual descriptions are not intended to limit the scope of the present disclosure in any way, but rather to illustrate the concepts of the present disclosure to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0020] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present disclosure. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present disclosure, as detailed in the appended claims.
[0021] If shared resources are not properly protected, they may face various security threats and risks, such as unauthorized users accessing resources, resulting in data leaks, or unknown vulnerabilities or malicious attacks that can cause resource paralysis, data loss, or tampering. In the process of protecting shared resources, various measures can be taken to improve their security.
[0022] Related technologies can provide security protection for shared resources through identity authentication and encryption based on a super SIM (Subscriber Identity Module) card.
[0023] Authentication is the process of verifying a user's identity to grant access rights. During resource access, authentication can effectively prevent unauthorized users from logging in and accessing resources.
[0024] Encryption ensures the secure transmission of sensitive data (such as passwords and bank card information) during resource access and data transmission. Encryption technology converts data into an encrypted form, preventing unauthorized access. It effectively prevents data theft during resource transmission.
[0025] Therefore, identity authentication and encryption are two common measures for resource access security protection, which ensure that only authenticated users can access resources and prevent unauthorized users from accessing resources.
[0026] However, since authorized accounts may be used by other users to perform malicious activities and flaws in authentication and encryption technologies may be exploited for attacks, authentication and encryption in related technologies cannot fully guarantee the security of shared resources.
[0027] To this end, embodiments of the present disclosure provide a user authentication method, apparatus, electronic device, and storage medium to improve the security of shared resources.
[0028] The following detailed description of the technical solution of the present disclosure and how the technical solution of the present disclosure solves the above-mentioned technical problems is provided with specific embodiments. The following specific embodiments may be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments. The embodiments of the present disclosure will be described below in conjunction with the accompanying drawings.
[0029] First combine Figure 1 , an exemplary description of the user authentication method provided in the embodiment of the present disclosure is given.
[0030] Figure 1 The figure is a flowchart of a user authentication method according to an exemplary embodiment.
[0031] It should be noted that the user authentication method provided in the embodiments of the present disclosure can be performed by a user authentication device, wherein the user authentication device can be implemented by software and / or hardware. The user authentication device can be an electronic device, or can be configured in an electronic device.
[0032] The electronic device may be any device with computing capabilities, such as a server, a mobile phone, a computer, a wearable device, etc.
[0033] like Figure 1 As shown, the user authentication method includes the following steps:
[0034] Step 101: Determine a characteristic value of a characteristic indicator based on characteristic information of a target user.
[0035] The target user is the user who needs to be authenticated.
[0036] Feature information may include various aspects of feature information, such as the user's own attribute information, the user's terminal environment information, network location information, access behavior information, etc. Attribute information may include, for example, age information, gender information, etc. Terminal environment information may include, for example, the operating system type, operating status information, hardware fingerprint, etc. of the terminal used by the user. Network location information may include, for example, the user's IP address (Internet Protocol Address), network connection speed, network connection type such as WiFi (Wireless Fidelity), WiFi name, etc. Access behavior information may include, for example, the URL (Uniform Resource Locator) accessed by the user, the type of file accessed, operation behavior, etc.
[0037] The collection scope of the target user's characteristic information may include the time period between the current moment and a certain historical moment before the current moment, or may include the time period between a certain historical moment and another historical moment, etc., and this disclosure does not impose any restrictions on this.
[0038] Among them, the characteristic indicators are indicators that can reflect a certain aspect of the user's characteristics or behaviors, which can be pre-set as needed and dynamically adjusted as needed. Among them, the characteristic indicators may include characteristic indicators under one dimension or multiple dimensions, such as indicators under the terminal environment dimension, network location dimension, and user access behavior dimension, and the present disclosure does not limit this. Among them, the characteristic indicators under the terminal environment dimension may include, for example, the operating system type switching frequency, the frequency of operating failures, etc. The characteristic indicators under the network location dimension may include, for example, the IP address switching frequency, the network connection speed, the network connection type switching frequency, etc. The characteristic indicators under the user access behavior dimension may include the accessible frequency, the access failure rate, etc.
[0039] In some embodiments, the domain value of the characteristic value of each characteristic indicator can be set in advance, that is, the range of the characteristic value of each characteristic indicator, and based on the characteristic information of the target user, the characteristic value of each characteristic indicator can be determined according to the characteristic value calculation strategy corresponding to each characteristic indicator, and the characteristic value of each characteristic indicator can be converted into the domain value to obtain the final characteristic value of each characteristic indicator.
[0040] The domain values of the characteristic values of each characteristic indicator may be the same.
[0041] Among them, the eigenvalue calculation strategy corresponding to each characteristic indicator can be set as needed, and the eigenvalue calculation strategies corresponding to different characteristic indicators can be different. Therefore, for different characteristic indicators, the corresponding eigenvalues can be determined according to the corresponding eigenvalue calculation strategies to obtain accurate eigenvalue results.
[0042] Step 102: Obtain characteristic value ranges corresponding to multiple trust levels.
[0043] In some embodiments, multiple trust levels can be pre-set, with different trust levels corresponding to different trust levels, and each trust level has a corresponding characteristic value range. The trust level is the degree of trust in the user. The characteristic value range is the range of characteristic values of the characteristic indicator, which may also be referred to as a trust level subset domain or other names, and this disclosure is not limited to this.
[0044] The characteristic value range may include a lower limit and an upper limit of the characteristic value. The lower limit is the minimum value of the characteristic value, and the upper limit is the maximum value of the characteristic value. The upper limit and the lower limit are used to divide the boundaries of the characteristic value range. Furthermore, the characteristic value range may also include a peak point. The peak point is used to describe the distribution of trust within the characteristic value range corresponding to the trust level. For example, taking the peak point in the characteristic value range corresponding to a certain trust level as an example, at this peak point, the trust in the user reaches the peak within the trust level.
[0045] For example, five trust levels can be pre-set: trust level 1, trust level 2, trust level 3, trust level 4, and trust level 5. The trust levels and characteristic value ranges corresponding to each trust level can be shown in Table 1. In each characteristic value range, the left endpoint represents the lower limit, the right endpoint represents the upper limit, and the middle value represents the peak point.
[0046] Table 1 Trust levels and eigenvalue ranges corresponding to each trust level
[0047]
[0048] In some embodiments, the characteristic value range corresponding to each trust level can be set according to the domain value of the characteristic value of each characteristic indicator.
[0049] Step 103 : For each trust level, based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, determine the comprehensive membership of the trust level, wherein the comprehensive membership represents the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level.
[0050] The characteristic indicators in step 103 may include all characteristic indicators or part of characteristic indicators, which is not limited in the present disclosure.
[0051] In some embodiments, for each trust level, the comprehensive membership of the trust level may be determined based on the characteristic values of all characteristic indicators and the characteristic value range corresponding to the trust level.
[0052] Step 104: Determine the trust level to which the target user belongs based on the comprehensive membership of each trust level.
[0053] In some embodiments, the trust level with the largest corresponding comprehensive membership degree may be determined as the trust level to which the target user belongs.
[0054] Understandably, in practical applications, many feature values are ambiguous and difficult to describe with definite numerical values. However, trust level classification can better express this uncertainty and demonstrate the reliability of trust level assessment results. By determining the target user's trust level, we can evaluate their user behavior and historical access records to determine their trust value during resource access.
[0055] Step 105: Authenticate the target user based on the trust level of the target user.
[0056] In some embodiments, different authentication methods corresponding to different trust levels may be preset, so that the target user may be authenticated according to the authentication method corresponding to the trust level to which the target user belongs.
[0057] The user authentication method provided by the embodiment of the present disclosure determines the characteristic value of the characteristic indicator based on the characteristic information of the target user, obtains the characteristic value ranges corresponding to multiple trust levels, determines the comprehensive membership of the trust level for each trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, determines the trust level to which the target user belongs based on the comprehensive membership of each trust level, and authenticates the target user based on the trust level to which the target user belongs. This method can accurately determine the trust level of the target user based on the characteristic information of the target user when the target user accesses shared resources, and authenticate the target user, thereby accurately controlling the target user's access rights to shared resources and improving the security of shared resources.
[0058] Figure 2 The figure is a flow chart of another user authentication method according to an exemplary embodiment.
[0059] like Figure 2 As shown, the user authentication method includes the following steps:
[0060] Step 201: determining a characteristic value of a characteristic indicator based on characteristic information of a target user, wherein the number of characteristic indicators is multiple.
[0061] In some embodiments, the characteristic indicators may include characteristic indicators in at least one of the following dimensions: terminal environment dimension, network location dimension, and user access behavior dimension.
[0062] In some embodiments, a characteristic value calculation strategy corresponding to each characteristic indicator can be pre-set, and the characteristic value of each characteristic indicator can be determined according to the characteristic value calculation strategy corresponding to each characteristic indicator, and the characteristic value of each characteristic indicator can be converted into a domain value to obtain the final characteristic value of each characteristic indicator.
[0063] For example, the user authentication device may include a trust calculation module and a system library management module. In the system library management module, the characteristic indicators can be customized and the characteristic value calculation strategy corresponding to each characteristic indicator can be defined, so that the trust calculation module can automatically adapt to the characteristic value calculation strategy and intelligently output accurate characteristic values.
[0064] An exemplary eigenvalue calculation strategy is described below. In some embodiments, step 201 can be implemented by following the steps 201a-201c:
[0065] Step 201a: Determine a characteristic value corresponding to the characteristic indicator at the current moment based on the characteristic information before the current moment in the characteristic information.
[0066] In some embodiments, the time period between the current moment and a certain historical moment before the current moment can be divided into multiple time windows, and the characteristic value corresponding to the characteristic indicator at the current moment is determined based on the characteristic information in the time window with the current moment as the end moment and the characteristic information in the entire time period. For example, assuming that the current moment is t0 and the historical moment with a time interval T from the current moment is t n , you can use t n The time period between t and t0 is divided into n time windows, where the first time window corresponds to the historical moment t n to t n-1 , the second time window corresponds to the historical moment t n-1 to t n-2 , and so on, the nth time window corresponds to the historical moment t1 to t0. Then based on the feature information in the time window corresponding to t1 to t0 and t n The characteristic information in the time period between t0 and t1 is used to determine the characteristic value corresponding to the characteristic index at the current moment.
[0067] Among them, taking the characteristic index with the characteristic value of rate as an example, such as the access failure rate, the number of failed accesses of the target user to the shared resource in the time window corresponding to t1 to t0 can be compared with the number of failed accesses of the target user to the shared resource in the time window corresponding to t1 to t0. n The ratio of the number of failed accesses to the shared resource in the time period from t1 to t0 is used as the characteristic value of the characteristic indicator at the current moment. Taking the characteristic indicator with a characteristic value of rate value, such as access frequency, as an example, the number of target users’ accesses to the shared resource in the time window from t1 to t0 can be compared with the number of failed accesses to the shared resource in the time window from t1 to t0. nThe ratio of the number of accesses to the shared resource in the time period from t1 to t0 is used as the characteristic value of the characteristic indicator at the current moment. Taking the characteristic indicator whose characteristic value is speed, such as network connection speed, as an example, the average network connection speed of the target user in the time window corresponding to t1 to t0 can be compared with the average network connection speed of the target user in the time window corresponding to t1 to t0. n The ratio of the average network connection speed in the time period from t to t0 is used as the characteristic value corresponding to the characteristic indicator at the current moment.
[0068] Step 201b: Determine the characteristic value corresponding to the characteristic indicator at the historical moment based on the characteristic information before the historical moment in the characteristic information.
[0069] There may be multiple historical moments, and the characteristic values corresponding to the characteristic indicators at the historical moments may include the characteristic values corresponding to the characteristic indicators at each historical moment.
[0070] In some embodiments, for any historical moment, the time period between the arbitrary historical moment and another historical moment before the arbitrary historical moment can be divided into multiple time windows, and based on the characteristic information in the time window with the arbitrary historical moment as the end moment and the characteristic information in the entire time period, the characteristic value corresponding to the characteristic indicator at the arbitrary historical moment can be determined.
[0071] For example, continuing the above example, suppose the current moment is t0, and the historical moment with a time interval T from the current moment is t n , t n The time period between t and t0 is divided into n time windows, where the first time window corresponds to the historical moment t n to t n-1 , the second time window corresponds to the historical moment t n-1 to t n-2 , and so on, the nth time window corresponds to the historical moments t1 to t0.
[0072] For the historical moment t1, we can use the characteristic information in the time window from t2 to t1 and t n The characteristic value of the characteristic index at the historical moment t1 can be determined based on the characteristic information in the time window from t3 to t2 and t n The characteristic information in the time period between t and t2 is used to determine the characteristic value of the characteristic index at the historical moment t2. Similarly, for the historical moment t n-1 , can be based on t n to t n-1 Feature information within the time window, determine the feature index at the historical moment t n-1 The corresponding eigenvalues.
[0073] The method for determining the characteristic value corresponding to the characteristic indicator at any historical moment based on the characteristic information within the time window ending at any historical moment and the characteristic information within the entire time period can refer to the optional implementation method of the above step 201a, which will not be repeated here. For example, taking the characteristic indicator whose characteristic value is a rate value, such as the access failure rate, as an example, the number of failed accesses to the shared resource by the target user in the time window corresponding to t2 to t1 can be compared with the number of failed accesses to the shared resource by the target user in the time window corresponding to t1. n The ratio of the number of failed accesses to shared resources in the time period from t3 to t1 is used as the characteristic value of the characteristic indicator at the historical moment t1. The number of failed accesses to shared resources by the target user in the time window from t3 to t2 can be compared with the number of failed accesses to shared resources in the time window from t3 to t2. n The ratio of the number of failed accesses to the shared resource in the time period from t to t2 is used as the characteristic value corresponding to the characteristic indicator at the historical time t2.
[0074] Step 201c: Smoothing the characteristic values of the characteristic indicator at the current moment and the historical moment to obtain the characteristic value of the characteristic indicator.
[0075] In some embodiments, smoothing may be performed by exponential smoothing, simple moving average, median smoothing, low-pass filter, etc., which is not limited in the present disclosure.
[0076] By smoothing the eigenvalues corresponding to the characteristic indicators at the current moment and the historical moment, the noise, outliers or fluctuations in the data can be eliminated, thereby obtaining more stable and reliable characteristic values of the characteristic indicators, which helps to better reveal the inherent laws and trends of the data and improve the accuracy of subsequent processing results.
[0077] In some embodiments, assuming that there are multiple historical moments, the characteristic values of the characteristic indicator corresponding to the current moment and each historical moment can be obtained. Then, the characteristic values of the characteristic indicator corresponding to the current moment and each historical moment can be smoothed in the following manner to obtain the characteristic values of the characteristic indicator:
[0078] For the earliest historical moment among multiple historical moments, the characteristic value corresponding to the characteristic indicator at the earliest historical moment is used as the smoothed characteristic value corresponding to the earliest historical moment;
[0079] For any historical moment other than the earliest historical moment among the multiple historical moments, the characteristic value corresponding to the characteristic indicator at any historical moment and the smoothed characteristic value corresponding to the previous historical moment are smoothed to obtain the final characteristic value corresponding to the any historical moment, and the final characteristic value corresponding to the characteristic indicator at any historical moment and the smoothed characteristic value corresponding to the previous historical moment are smoothed to obtain the smoothed characteristic value corresponding to the any historical moment;
[0080] The characteristic value of the characteristic indicator at the current moment and the smoothed characteristic value corresponding to the latest historical moment among multiple historical moments are smoothed to obtain the characteristic value of the characteristic indicator.
[0081] In some embodiments, it is assumed that the current moment is t0 and the historical moment with a time interval T from the current moment is t n , t n The time period from t to t0 is divided into n time windows, where the first time window corresponds to time t n to t n-1 , the second time window corresponds to time t n-1 to t n-2 , and so on, the nth time window corresponds to time t1 to t0. Assume {f1, f2, f3, ..., f n Each element in} represents the characteristic index at t n-1 The final eigenvalues corresponding to the n moments in t0, {sm1, sm2, sm3, ..., sm n Each element in} represents the characteristic index at t n-1 To the smooth characteristic values corresponding to n moments in t0, the characteristic index has been obtained at t n-1 In the case of the characteristic values corresponding to each moment in t0, the characteristic values of the characteristic indicators can be obtained by the following formulas (1)-(3):
[0082] sm1=f1 (1)
[0083] sm i =αf i +(1-α)sm i-1 ,i=2,3,4,…,n (2)
[0084] f i =α(X i / Y i )+(1-α)sm i-1 ,i=2,3,4,…,n (3)
[0085] Among them, sm i Indicates that the characteristic index is at t n-1 The smoothed eigenvalue corresponding to the i-th moment in t0; f i Indicates that the characteristic index is at t n-1 The final eigenvalue corresponding to the i-th moment in t0, X i Indicates t n-1 The characteristic information in the time period from the i-1th moment to the i-th moment in t0, Y i Indicates t n The characteristic information in the time period from moment t to moment i, Xi / Y i Indicates that the characteristic index is at t n-1 The eigenvalue corresponding to the i-th moment in t0; α represents the smoothing factor, which is a preset parameter, 0<α<1, for example, it can be a decimal between 0.1 and 0.3.
[0086] It can be understood that for characteristic indicators whose characteristic values are rate values, such as access failure rate, access frequency, etc., or characteristic indicators whose characteristic values are other types, the method shown in the above example can be adopted to obtain accurate characteristic values through smoothing based on the short-term changes and long-term trends of the characteristic indicators, thereby improving the accuracy of subsequent processing results.
[0087] Step 202: Acquire characteristic value ranges corresponding to multiple trust levels.
[0088] In some embodiments, obtaining characteristic value ranges corresponding to multiple trust levels may be achieved by following the steps 202a-202c:
[0089] Step 202a: Obtain the scores corresponding to the characteristic indicators at each trust level; wherein the scores represent the contribution of the characteristic indicators to the improvement of the user's creditworthiness or the impact on the loss of the user's creditworthiness.
[0090] In some embodiments, the characteristic indicators include multiple credit loss indicators and multiple credit contribution indicators. Credit contribution indicators are characteristic indicators that contribute to improving a user's credit, such as access success rate. Credit loss indicators are characteristic indicators that affect a user's credit loss, such as access failure rate and operating system type switching frequency.
[0091] In some embodiments, for each characteristic indicator and each trust level, a score corresponding to the characteristic indicator at the trust level can be pre-set, and when the characteristic information of the target user or the characteristic information of each user under the user type to which the target user belongs includes characteristic information related to the characteristic indicator, the pre-set score corresponding to the characteristic indicator at the trust level is determined as the score corresponding to the characteristic indicator at the trust level. When the characteristic information of the target user or the characteristic information of each user under the user type to which the target user belongs does not include characteristic information related to the characteristic indicator, the score corresponding to the characteristic indicator at the trust level is determined to be zero.
[0092] Step 202b: Determine the user credit value corresponding to each trust level based on the score corresponding to the characteristic indicator at each trust level.
[0093] Among them, the user credit value can measure the user's credit status.
[0094] In some embodiments, when the characteristic indicator includes multiple credit loss indicators and multiple credit contribution indicators, step 202b can be implemented in the following manner:
[0095] Determine the credit contribution value corresponding to each trust level based on the scores and weights corresponding to multiple credit contribution indicators at each trust level; wherein the credit contribution value represents the contribution degree of the multiple credit contribution indicators to the improvement of the user's credit level;
[0096] Determining a credit loss value corresponding to each trust level based on the scores and weights corresponding to multiple credit loss indicators at each trust level; wherein the credit loss value represents the degree of impact of the multiple credit loss indicators on the user's credit loss;
[0097] Based on the credit contribution value and credit loss value corresponding to each trust level, the user credit value corresponding to each trust level is determined.
[0098] In some embodiments, for any trust level, the credit contribution value corresponding to the trust level can be determined by the following formula (4):
[0099]
[0100] Among them, w i’ represents the weight corresponding to the i'th credit contribution indicator under the trust level; c i’ represents the score corresponding to the i'th credit contribution indicator under the trust level; N1 represents the number of credit contribution indicators; C represents the credit contribution value corresponding to the trust level.
[0101] In some embodiments, for any trust level, the credit loss value corresponding to the trust level can be determined by the following formula (5):
[0102]
[0103] Among them, w j’ represents the weight corresponding to the j'th credit loss indicator under the trust level; l j’ represents the score corresponding to the j'th credit loss indicator under the trust level; N2 represents the number of credit loss indicators; L represents the credit loss value corresponding to the trust level.
[0104] In some embodiments, for any trust level, the user credit value corresponding to the trust level can be determined by the following formula (6):
[0105] V'=C / (C+L) (6)
[0106] Where V' represents the user's credit value corresponding to the trust level; C represents the credit contribution value corresponding to the trust level; and L represents the credit loss value corresponding to the trust level. According to formula (6), the user's credit value can range from [0, 1]. The user's credit value can be obtained based on the scores and weights of the user's credit-related characteristic indicators.
[0107] Step 202c: using the user credit value corresponding to each trust level as the boundary value of the corresponding characteristic value range, and combining the domain value of the characteristic value of the characteristic indicator to determine the characteristic value range corresponding to each trust level.
[0108] In some embodiments, assuming that the user credit value corresponding to trust level 1 is 0.9, the user credit value corresponding to trust level 2 is 0.75, the user credit value corresponding to trust level 3 is 0.5, the user credit value corresponding to trust level 4 is 0.2, and the user credit value corresponding to trust level 5 is 0, and the domain value of the characteristic value of the characteristic indicator is [0,1], then the user credit value corresponding to each trust level can be used as the lower limit value of the corresponding characteristic value range, the difference between the user trust value corresponding to the previous trust level and the preset value, such as 0.01, can be used as the upper limit value of the characteristic value range corresponding to the next trust level, and the maximum value of the domain value of the characteristic value can be used as the upper limit value of the characteristic value range corresponding to trust level 1, thereby obtaining the characteristic value range corresponding to each trust level shown in Table 1.
[0109] When the characteristic value range corresponding to each trust level includes a peak point, the peak point in the characteristic value range corresponding to each trust level can be determined according to the distribution of the trust degree along with the characteristic value in the characteristic value range corresponding to each trust level.
[0110] Step 203, for each trust level, based on the characteristic value of any characteristic indicator among the multiple characteristic indicators and the characteristic value range corresponding to the trust level, determine the characteristic membership of any characteristic indicator to the trust level, wherein the characteristic membership represents the degree to which the characteristic value of any characteristic indicator belongs to the characteristic value range corresponding to the trust level.
[0111] The higher the characteristic membership of any characteristic indicator to the trust level, the more the characteristic value of the characteristic indicator belongs to the trust level.
[0112] In some embodiments, the characteristic value range corresponding to each trust level may include an upper limit, a lower limit, and a peak point. Accordingly, step 203 may be implemented as shown in the following formula (7):
[0113] μ(Tr j ,f)=max{0,min{[(f-a_j) / (b_j-a_j)],[(c_j-f) / (c_j-b_j)]}} (7)
[0114] Among them, Tr j =(a, b, c) represents the eigenvalue range corresponding to the jth trust level, μ(Tr j ,f) represents the characteristic membership of the eigenvalue f to the jth trust level, max represents the maximum value, min represents the minimum value, a_j, b_j, c_j represent Tr j The lower limit, peak point and upper limit of the .
[0115] Assuming that the number of characteristic indicators is N, the characteristic membership of all characteristic indicators to the same trust level can be obtained by the method shown in formula (7), which is expressed as μ = {μ1, μ2, μ3, ..., μ N}, where μ N Indicates the characteristic membership of the Nth characteristic indicator to the trust level.
[0116] Step 204: Obtain weights corresponding to the plurality of characteristic indicators.
[0117] Since the importance and contribution of each characteristic indicator are different, it is necessary to determine their weights so that the comprehensive membership of the trust level can be obtained by comprehensively utilizing the characteristic membership of each characteristic indicator to the trust level based on the weight corresponding to each characteristic indicator.
[0118] Among them, step 203 and step 204 can be executed simultaneously, or executed in sequence, and this disclosure does not limit this.
[0119] In some embodiments, the number of characteristic indicators is N, where N is an integer greater than 1; step 204 is implemented by the following steps 204a-204d:
[0120] Step 204a, determine the initial weight relationship matrix corresponding to multiple feature indicators; wherein the value of the element in the sth row and qth column of the initial weight relationship matrix represents the importance of the sth feature indicator relative to the qth feature indicator, the order of the initial weight relationship matrix is N, and s and q are integers from 1 to N.
[0121] Among them, the initial weight relationship matrix can be expressed as:
[0122] In some embodiments, the value of each element in the initial weight relationship matrix can be determined by comparing the importance of each pair of feature indicators, thereby dynamically comparing and giving the most appropriate importance of the feature indicators.
[0123] In some embodiments, the element value corresponding to the comparison result of the importance between two feature indicators can be set as needed. For example, a number between 1 and 9 can be used to represent the comparison result of the importance between two feature indicators. Among them, 1 means that the importance between the two feature indicators is equal, 3 means that one feature indicator is slightly more important than the other feature indicator, 5 means that one feature indicator is significantly more important than the other feature indicator, 7 means that one feature indicator is very important than the other feature indicator, and 9 means that one feature indicator is extremely important than the other feature indicator.
[0124] Correspondingly, the weight relationship table can be expressed as shown in Table 2:
[0125] Table 2 Weight relationship table
[0126] 1 The importance between the two feature indices is equal 3 One feature metric is slightly more important than another feature metric 5 One feature is significantly more important than another 7 One feature is more important than another 9 One characteristic metric is significantly more important than another characteristic metric 2、4、6、8 The importance between two adjacent comparison results
[0127] By comparing the importance of each characteristic indicator, a weight relationship matrix is finally obtained, which can effectively reflect the weight relationship of each characteristic indicator, reduce the probability of misjudgment of the final trust level, and reduce the risk of wrong decision-making.
[0128] Step 204b: determine the weight vector of the initial weight relationship matrix; wherein the kth element in the weight vector represents the weight corresponding to the kth characteristic index, and k is an integer from 1 to N.
[0129] In some embodiments, step 204b may be implemented as shown in the following formula (8):
[0130]
[0131] in, represents the weight vector; A s,q Represents the element in the sth row and qth column of the weight relationship matrix.
[0132] From the above formula, we can know that for the initial weight relationship matrix, we can get Calculate the Nth root of the product of each row, that is, calculate the Nth root of the product of all elements in each row, get an N-dimensional column vector, and pass Calculate the Nth root of the product of each row and sum them to get a value, and make a quotient of each element in the N-dimensional column vector and the value to get an N-dimensional weight vector.
[0133] Step 204c: Determine the consistency of the initial weight relationship matrix, and adjust the initial weight relationship matrix based on the consistency.
[0134] Step 204d: Determine the weight of each characteristic indicator based on the weight vector of the adjusted weight relationship matrix.
[0135] In some embodiments, whether the initial weight relationship matrix has satisfactory consistency can be determined by determining whether the consistency ratio of the initial weight relationship matrix meets the set conditions. If not, the initial weight relationship matrix can be adjusted until the consistency ratio of the adjusted weight relationship matrix meets the set conditions. The weights of each feature indicator can then be determined based on the weight vector of the final weight relationship matrix.
[0136] In some embodiments, the consistency ratio CR of the initial weight relationship matrix can be determined by the following formula (9):
[0137] CR=(λmax-N) / (N-1) / RI (9)
[0138] Among them, λmax is the value of the maximum eigenvalue, N is the order of the weight relationship matrix, (λmax-N) / (N-1) represents the relative consistency index, and RI represents the random consistency index.
[0139] The value of RI when N is 1 to 9 may be as shown in Table 3 below.
[0140] Table 3 RI values when N is 1 to 9
[0141] N 1 2 3 4 5 6 7 8 9 RI value 0 0 0.58 0.9 1.12 1.24 1.32 1.41 1.45
[0142] Among them, the smaller the CR value, the higher the consistency of the weight relationship matrix. In the embodiment of the present disclosure, when CR is less than or equal to 0.1, it can be considered that the consistency of the weight relationship matrix is acceptable; when CR is greater than 0.1, it can be considered that there is a problem with the consistency of the weight relationship matrix, and the weight relationship matrix needs to be further adjusted or re-evaluated.
[0143] Through continuous adjustment, the weight of each characteristic indicator can be finally obtained.
[0144] Step 205 : Determine the comprehensive membership of the trust level based on the characteristic memberships of the multiple characteristic indicators and the corresponding weights of the trust levels.
[0145] The comprehensive membership degree indicates the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level. The characteristic indicator here may include all or part of the characteristic indicators.
[0146] In some embodiments, step 205 is achieved by:
[0147] Arrange the multiple feature indicators in order according to the corresponding feature membership, and remove a preset number of feature indicators that are ranked first and last, to obtain the remaining target feature indicators;
[0148] Based on the characteristic membership of the target characteristic indicators to the trust level and the corresponding weights, the comprehensive membership of the trust level is determined.
[0149] The preset number can be set as needed, and the number of feature indicators ranked first and the number of feature indicators ranked last to be eliminated can be the same or different, and the present disclosure does not impose any restrictions on this.
[0150] By arranging multiple feature indicators in sequence according to the size of the corresponding feature membership, and eliminating a preset number of feature indicators that are ranked in front and behind, and then determining the comprehensive membership of the trust level based on the feature membership and corresponding weight of the remaining target feature indicators, the influence of outliers on the determination result of the comprehensive membership can be reduced, and the accuracy of the determination result of the comprehensive membership can be improved.
[0151] In some embodiments, the characteristic membership of all characteristic indicators to the same trust level is expressed as μ = {μ1, μ2, μ3, ..., μ N}, assuming that multiple feature indicators are arranged in order according to the size of the corresponding feature membership, the sequence composed of the feature membership of each feature indicator to the same trust level is expressed as {μ′1, μ′2, μ′3, …, μ′ N}, the sequence composed of the weights of each feature index after sorting is {w1, w2, w3, ..., w N}, where N represents N feature indicators, w N Represents the weight of the Nth feature index.
[0152] The comprehensive membership degree S of the mth trust level can be determined by the following formula (10): m .
[0153]
[0154] Among them, w z represents the weight of the z-th feature index, is the influence coefficient, which is used to consider the balance between the distance and difference between the previous feature index and the next feature index, and then the z-th feature membership μ' z Take the absolute value and add a very small positive number ∈ to ensure that the calculation result is not infinite when there is a zero value in the feature membership sequence. Then take the limit value of removing p% before and after the feature membership sequence to reduce the influence of outliers on the result, where p% is a decimal greater than zero and less than or equal to 0.5. Represents the sum of the weights of all target feature indicators, for the zth feature membership μ' z , take its w zPower, find the product of the weight powers of all feature memberships, and then find the weight and power root to get the comprehensive membership of all feature indicators after adding the weights.
[0155] Step 206: Determine the trust level to which the target user belongs based on the comprehensive membership of each trust level.
[0156] In some embodiments, it is assumed that the sequence of the comprehensive membership of each trust level is {S1, S2, S3, ..., S M}, where M represents M trust levels, S M Denotes the comprehensive membership of the Mth trust level. After obtaining the comprehensive memberships of different trust levels, these comprehensive memberships can be converted into probability distributions through normalization operations to obtain the trust level to which the target user belongs.
[0157] Specifically, assuming that the comprehensive membership of the trust level Gm is S m , then its corresponding probability distribution P(Gm) can be obtained as shown in the following formula (11):
[0158]
[0159] in, It represents the sum of the comprehensive membership of all trust levels.
[0160] The trust level G of the target user can be obtained by the following formula (12):
[0161] G = argmax m∈{1,2,…,M} P(Gm) (12)
[0162] Step 207: Authenticate the target user based on the trust level of the target user.
[0163] The user authentication method provided by the embodiment of the present disclosure determines the characteristic value of the characteristic indicator based on the characteristic information of the target user, wherein there are multiple characteristic indicators, obtains the characteristic value ranges corresponding to multiple trust levels, and for each trust level, determines the characteristic membership of any characteristic indicator to the trust level based on the characteristic value of any characteristic indicator among the multiple characteristic indicators and the characteristic value range corresponding to the trust level, obtains the weights corresponding to the multiple characteristic indicators, determines the comprehensive membership of the trust level based on the characteristic membership of the multiple characteristic indicators to the trust level and the corresponding weights, determines the trust level to which the target user belongs based on the comprehensive membership of each trust level, and authenticates the target user based on the trust level to which the target user belongs. This method can achieve the goal of accurately determining the trust level of the target user based on the characteristic information of the target user when the target user accesses shared resources, and authenticating the target user, thereby accurately controlling the target user's access rights to the shared resources and improving the security of the shared resources.
[0164] Figure 3 The figure is a flowchart of a user authentication method according to an exemplary embodiment.
[0165] like Figure 3 As shown, the user authentication method includes the following steps:
[0166] Step 301: Authenticate the target user based on the Subscriber Identity Module (SIM) card.
[0167] In some embodiments, when a target user accesses a shared resource, a super SIM identity authentication may be performed. By using a SIM quick authentication and entering a password, the legitimacy of the target user's identity may be confirmed through identity verification to prevent illegal users from accessing the shared resource.
[0168] refer to Figure 4 , taking the user authentication device as the identity authentication system as an example, the specific identity authentication can be Figure 4 In the form shown. That is, when the target user accesses the shared resource, it can be determined whether the target user is logging in for the first time and performing identity authentication. If so, the identity authentication system can prompt the target user to enter a password. Otherwise, it can directly confirm that the target user's identity authentication is successful and execute step 302. The identity authentication system can record the number of identity authentication failures and determine whether the current number of identity authentication failures has exceeded. If so, the target user is denied access to the shared resource. Otherwise, the identity authentication system can verify whether the target user's identity recognition is successful based on the password entered by the target user. If the recognition fails, the authentication is re-initiated. If the recognition passes, it is determined that the target user's identity authentication is successful.
[0169] Step 302: If the identity authentication is successful, query the preset list and determine whether the target user belongs to the users in the preset list.
[0170] The preset list may include user identifiers that are authorized to access the shared resources.
[0171] In some embodiments, when it is determined that the target user's identity authentication has passed, a preset list can be obtained to check whether the target user is on the preset list. If so, the target user is considered to have access rights to the shared resources. Otherwise, access is denied or the target user is prompted to apply to join the preset list.
[0172] refer to Figure 5 The user authentication device may include a trust store management module, and step 302 may be Figure 5 That is, if the identity authentication is successful, the trust store management module can determine whether the target user belongs to the preset list. If so, step 303 can be executed. Otherwise, the target user can be prompted to apply to join the preset list. If the target user applies to join the preset list and is added to the preset list, the information is synchronized to the trust store management module for management. If the target user does not belong to the preset list, or the target user does not apply to join the preset list, or the addition of the preset list fails, access is denied.
[0173] By authenticating the target user based on their SIM card, and if the authentication passes, searching a preset list to confirm that the target user is on the list, the target user can be authenticated when accessing shared resources, ensuring the security of the shared resources. To further enhance the security of shared resources, the target user can also be authenticated again using the following steps.
[0174] Step 303: Determine the current characteristic value of the characteristic indicator based on the characteristic information of the target user before the current moment.
[0175] In some embodiments, the characteristic indicators may include characteristic indicators in at least one of the following dimensions: terminal environment dimension, network location dimension, and user access behavior dimension.
[0176] In some embodiments, step 303 can be implemented in the following ways: based on the feature information before the current moment in the feature information, determine the feature value corresponding to the feature indicator at the current moment; based on the feature information before the historical moment in the feature information, determine the feature value corresponding to the feature indicator at the historical moment; smooth the feature values corresponding to the feature indicator at the current moment and the historical moment to obtain the current feature value of the feature indicator.
[0177] The historical moment here refers to the historical moment of the current moment. The number of historical moments can be one or more, and this disclosure does not limit this.
[0178] The specific implementation process and principle of step 303 are similar to the process of determining the characteristic value of the characteristic indicator based on the characteristic information of the user in the aforementioned embodiment, and will not be repeated here.
[0179] Step 304: Acquire characteristic value ranges corresponding to multiple trust levels.
[0180] The specific implementation process and principle of step 304 can be referred to the description of other embodiments and will not be repeated here.
[0181] Step 305 : For each trust level, based on the current characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, determine the current comprehensive membership of the trust level.
[0182] The current comprehensive membership degree indicates the degree to which the current characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level. The characteristic indicator here may include all or part of the characteristic indicators.
[0183] In some embodiments, there are multiple characteristic indicators, and step 305 can be implemented in the following manner: for each trust level, based on the current characteristic value of any characteristic indicator among the multiple characteristic indicators and the characteristic value range corresponding to the trust level, determine the current characteristic membership of any characteristic indicator to the trust level, wherein the current characteristic membership represents the degree to which the characteristic value of any characteristic indicator belongs to the characteristic value range corresponding to the trust level; obtain the weights corresponding to the multiple characteristic indicators respectively; and determine the current comprehensive membership of the trust level based on the current characteristic memberships and corresponding weights of the multiple characteristic indicators to the trust level.
[0184] Among them, the specific implementation process and principles of obtaining the weights corresponding to multiple feature indicators can refer to the description of other embodiments, and the specific implementation process and principles of obtaining the current feature membership can refer to the description of obtaining the feature membership in other embodiments, which will not be repeated here.
[0185] In some embodiments, the current comprehensive membership of the trust level is determined based on the current feature membership and corresponding weight of the trust level of multiple feature indicators, including: arranging the multiple feature indicators in sequence according to the size of the corresponding current feature membership, and eliminating a preset number of feature indicators ranked in front and behind to obtain the remaining target feature indicators; determining the current comprehensive membership of the trust level based on the target feature indicators and the corresponding weight of the trust level.
[0186] Among them, the specific implementation process and principle of determining the current comprehensive membership of the trust level based on the current feature membership and the corresponding weight of the trust level respectively according to the target feature indicator can be referred to the description of determining the comprehensive membership of the trust level based on the feature membership and the corresponding weight of the trust level respectively according to the target feature indicator in other embodiments, which will not be repeated here.
[0187] Step 306 , obtaining a historical comprehensive membership of the trust level, wherein the historical comprehensive membership is determined based on the historical characteristic values of the characteristic indicators and the characteristic value range corresponding to the trust level, and the historical characteristic values are determined based on the characteristic information of the target user before the historical moment.
[0188] The historical moment is any historical moment before the current moment. The number of historical moments can be one or more, and this disclosure does not limit this.
[0189] The historical comprehensive membership degree indicates the degree to which the historical characteristic values of the characteristic indicators belong to the characteristic value range corresponding to the trust level. The characteristic indicators here may include all or part of the characteristic indicators.
[0190] It should be noted that the method for determining the historical comprehensive membership and the current comprehensive membership is the same as the method for determining the comprehensive membership in the above embodiment. The difference between the methods for determining the historical comprehensive membership and the current comprehensive membership is that they are determined using characteristic indicator characteristic values determined based on characteristic information within different time periods. That is, the historical comprehensive membership is determined using characteristic indicator characteristic values determined based on characteristic information before the historical moment, while the current comprehensive membership is determined using characteristic indicator characteristic values determined based on characteristic information before the current moment.
[0191] Step 307: Determine the comprehensive membership of the trust level based on the historical comprehensive membership and the current comprehensive membership.
[0192] The comprehensive membership degree indicates the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level. The characteristic indicator here may include all or part of the characteristic indicators.
[0193] In some embodiments, it is assumed that the current moment is t0 and the historical moment with a time interval T from the current moment is t n , t n The time period between t and t0 is divided into n time windows, based on t n-1 The historical comprehensive membership of the mth trust level determined by the characteristic information before the moment is S m1 , based on t n-2 The historical comprehensive membership of the mth trust level determined by the characteristic information before the moment is S m2 , based on tn-3 The historical comprehensive membership of the mth trust level determined by the characteristic information before the moment is S m3 , and so on, the current comprehensive membership of the mth trust level determined based on the feature information before time t0 is S mn Then step 307 can be implemented as shown in the following formula (13):
[0194]
[0195] Among them, S m represents the comprehensive membership of the mth trust level, t i Indicates the i-th timestamp of the characteristic index, t0 is the timestamp of the current moment, α' and β are preset parameters used to control the distribution of the weight of the comprehensive membership, the exponential part Represents the time decay factor, that is, as time gradually moves away from the current moment, the weight of the comprehensive membership will gradually decrease. The size of the time decay factor is controlled by the parameter β. The larger the value of β, the faster the time decay of the weight. It plays a normalization role and ensures that the sum of all weights is 1. The parameter α′ controls the smoothness of the normalization process. The larger the value of α′, the higher the smoothness.
[0196] In some embodiments, the user authentication device may record the comprehensive membership of the trust level after determining it at a previous moment. This allows the user to use the recorded comprehensive membership at the previous moment as a historical comprehensive membership when determining the comprehensive membership at the current moment, thereby quickly calculating the comprehensive membership at the current moment. Furthermore, the user authentication device may record the comprehensive membership after determining the comprehensive membership of the trust level at the current moment. This allows the user to use the recorded comprehensive membership at the current moment as a historical comprehensive membership when determining the comprehensive membership at the next moment, thereby quickly calculating the comprehensive membership at the next moment.
[0197] It is understandable that historical data is one of the important bases for trust level assessment. Incorporating historical data into trust level assessment can effectively improve data quality, enhance assessment accuracy and reliability, and obtain more accurate trust level assessment results.
[0198] Step 308: Determine the trust level to which the target user belongs based on the comprehensive membership of each trust level.
[0199] Step 309: Determine the corresponding resource access permission based on the trust level of the target user.
[0200] In some embodiments, a mapping relationship between each trust level and resource access rights can be pre-set, so that the resource access rights corresponding to the target user's trust level can be determined based on the mapping relationship. For example, it can be pre-set to allow only access to certain content and / or certain operations when the trust level is low, and to allow access to more content and / or more operations when the trust level is high.
[0201] The resource access permissions corresponding to each trust level can be flexibly customized as needed. For example, the resource access permissions corresponding to each trust level can be set based on the importance of the resource.
[0202] The mapping relationship between each trust level and resource access permission may be shown in Table 4.
[0203] Table 4 Mapping relationship between each trust level and resource access rights
[0204]
[0205] Step 310: When it is determined that the target user needs to be re-authenticated based on the resource access rights, an authentication method corresponding to the trust level of the target user is determined.
[0206] In some embodiments, the resource access rights corresponding to each trust level include the scope of resources that the user can access, and the authentication method when the user cannot access the resources. Therefore, it is possible to determine whether the target user needs to be re-authenticated based on the resource access rights corresponding to the trust level to which the target user belongs, and if it is determined that the target user needs to be re-authenticated, determine the authentication method corresponding to the trust level to which the target user belongs.
[0207] For example, referring to Table 4, when the target user's trust level is trust level 4, according to the resource access rights corresponding to trust level 4, it can be determined that the target user needs to be authenticated again, and the authentication method is determined to be SMS verification code or email verification.
[0208] Step 311: Authenticate the target user based on the authentication method.
[0209] In some embodiments, resource access rights corresponding to each trust level can be set as needed, and the trust library management module in the user authentication device can perform unified entry management. The trust calculation module can automatically map the corresponding resource access rights according to the trust level of the target user, and then determine the authentication method for secondary authentication based on the resource access rights. The target user is authenticated based on the authentication method, and access is restored if the authentication is successful, thereby achieving the effect of dynamic access control.
[0210] Taking the SMS verification code authentication method as an example, the trust calculation module can send a verification code to the target user's SIM card via SMS, and compare the verification code entered by the target user in the interactive interface provided by the user authentication device with the verification code sent to the target user. If the comparison is consistent, it is determined that the authentication of the target user is successful.
[0211] Thus, by authenticating the target user based on the SIM card, and if the authentication passes, querying a preset list and determining that the target user belongs to the preset list, the target user can be authenticated when accessing shared resources. If the target user is determined to belong to the preset list, the target user's trust level is determined, and the corresponding resource access rights and authentication methods are automatically adapted according to the trust level. This allows for secondary authentication of the target user, strengthening multiple protection barriers against suspicious user behavior, achieving the effect of dynamically controlling the user's resource access rights, and providing users with more flexible and secure access protection. Furthermore, by determining the comprehensive membership of the trust level based on historical comprehensive membership and current comprehensive membership, and determining the trust level of the target user based on the comprehensive membership of each trust level, the trust level of the target user can be determined in combination with historical data, thereby improving the accuracy and reliability of the trust level assessment, further reducing the possibility of illegal access based on vulnerabilities, reducing the probability of data leakage and abuse, and improving the reliability and accuracy of network security protection for shared resources. By determining the comprehensive membership of each trust level based on the characteristic values of characteristic indicators in multiple dimensions such as terminal environment dimension, network location dimension and user access behavior dimension, a more accurate trust level can be obtained.
[0212] In addition, compared with the identity authentication and encryption methods in related technologies, the user authentication method provided by the present invention determines the comprehensive membership of each trust level by determining the characteristic values of characteristic indicators in multiple dimensions such as terminal environment dimension, network location dimension and user access behavior dimension. It can more carefully analyze user behavior, relationships, background and other information from multiple dimensions to accurately locate the risks of access behavior; by tracking and analyzing the historical behavior data of target users, it can more accurately assess the risks of users and manage and control them according to the degree of risk; in the process of trust level evaluation, the user authentication device can continuously improve its own evaluation capabilities through learning and optimization, and more accurately identify and evaluate the risks and threats of users in the process of accessing resources.
[0213] Figure 6 The figure is a schematic structural diagram of a user authentication device according to an exemplary embodiment.
[0214] It should be noted that the user authentication device can be implemented by software and / or hardware. The user authentication device can be an electronic device, or configured in an electronic device.
[0215] The electronic device may be any device with computing capabilities, such as a server, a mobile phone, a computer, a wearable device, etc.
[0216] like Figure 6 As shown, the user authentication device 600 includes: a first determination module 610, an acquisition module 620, a second determination module 630, a third determination module 640 and an authentication module 650, wherein:
[0217] A first determining module 610 is configured to determine a characteristic value of a characteristic indicator based on characteristic information of a target user;
[0218] An acquisition module 620 is used to obtain characteristic value ranges corresponding to multiple trust levels;
[0219] A second determination module 630 is configured to determine, for each trust level, a comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, wherein the comprehensive membership indicates the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level;
[0220] The third determination module 640 is configured to determine the trust level to which the target user belongs based on the comprehensive membership of each trust level;
[0221] The authentication module 650 is used to authenticate the target user based on the trust level of the target user.
[0222] In one embodiment of the present disclosure, there are multiple characteristic indicators; the second determining module 630 is configured to:
[0223] For each trust level, based on the characteristic value of any characteristic indicator among the multiple characteristic indicators and the characteristic value range corresponding to the trust level, determining the characteristic membership of any characteristic indicator to the trust level, wherein the characteristic membership represents the degree to which the characteristic value of any characteristic indicator belongs to the characteristic value range corresponding to the trust level;
[0224] Get the weights corresponding to multiple feature indicators;
[0225] Based on the characteristic membership of the trust level and the corresponding weights of the multiple characteristic indicators, the comprehensive membership of the trust level is determined.
[0226] In one embodiment of the present disclosure, the second determining module 630 is configured to:
[0227] Arrange the multiple feature indicators in order according to the corresponding feature membership, and remove a preset number of feature indicators that are ranked first and last, to obtain the remaining target feature indicators;
[0228] Based on the characteristic membership of the target characteristic indicators to the trust level and the corresponding weights, the comprehensive membership of the trust level is determined.
[0229] In one embodiment of the present disclosure, the second determining module 630 is configured to:
[0230] Determine an initial weight relationship matrix corresponding to multiple feature indicators; wherein the value of the element in the sth row and qth column of the initial weight relationship matrix represents the importance of the sth feature indicator relative to the qth feature indicator, the order of the initial weight relationship matrix is N, and s and q are integers from 1 to N;
[0231] Determine the weight vector of the initial weight relationship matrix; wherein the kth element in the weight vector represents the weight corresponding to the kth feature index, and k is an integer from 1 to N;
[0232] Determining the consistency of the initial weight relationship matrix, and adjusting the initial weight relationship matrix based on the consistency;
[0233] Based on the weight vector of the adjusted weight relationship matrix, the weight of each characteristic indicator is determined.
[0234] In one embodiment of the present disclosure, the second determining module 630 is configured to:
[0235] For each trust level, determining a current comprehensive membership of the trust level based on a current characteristic value of the characteristic indicator and a characteristic value range corresponding to the trust level, wherein the current characteristic value is determined based on characteristic information before the current moment in the characteristic information;
[0236] Obtaining a historical comprehensive membership of the trust level, wherein the historical comprehensive membership is determined based on a historical characteristic value of the characteristic indicator and a characteristic value range corresponding to the trust level, and the historical characteristic value is determined based on characteristic information before a historical moment in the characteristic information;
[0237] Based on the historical comprehensive membership and the current comprehensive membership, the comprehensive membership of the trust level is determined.
[0238] In one embodiment of the present disclosure, the first determining module 610 is configured to:
[0239] Determine the characteristic value corresponding to the characteristic indicator at the current moment based on the characteristic information before the current moment in the characteristic information;
[0240] Determine the characteristic value corresponding to the characteristic indicator at the historical moment based on the characteristic information before the historical moment in the characteristic information;
[0241] The characteristic values of the characteristic indicators at the current moment and the historical moments are smoothed to obtain the characteristic values of the characteristic indicators.
[0242] In one embodiment of the present disclosure, there are multiple historical moments, and the first determining module 610 is configured to:
[0243] For the earliest historical moment among multiple historical moments, the characteristic value corresponding to the characteristic indicator at the earliest historical moment is used as the smoothed characteristic value corresponding to the earliest historical moment;
[0244] For any historical moment other than the earliest historical moment among the multiple historical moments, the characteristic value corresponding to the characteristic indicator at any historical moment and the smoothed characteristic value corresponding to the previous historical moment are smoothed to obtain the final characteristic value corresponding to the any historical moment, and the final characteristic value corresponding to the characteristic indicator at any historical moment and the smoothed characteristic value corresponding to the previous historical moment are smoothed to obtain the smoothed characteristic value corresponding to the any historical moment;
[0245] The characteristic value of the characteristic indicator at the current moment and the smoothed characteristic value corresponding to the latest historical moment among multiple historical moments are smoothed to obtain the characteristic value of the characteristic indicator.
[0246] In one embodiment of the present disclosure, the acquisition module 620 is configured to:
[0247] Obtain the scores corresponding to the characteristic indicators at each trust level; the scores represent the degree to which the characteristic indicators contribute to improving the user's creditworthiness or the degree to which they affect the user's creditworthiness;
[0248] Determine the user credit value corresponding to each trust level based on the scores corresponding to the characteristic indicators at each trust level;
[0249] The user credit value corresponding to each trust level is used as the boundary value of the corresponding characteristic value range, and combined with the domain value of the characteristic value of the characteristic indicator, the characteristic value range corresponding to each trust level is determined.
[0250] In one embodiment of the present disclosure, the characteristic indicators include a plurality of credit loss indicators and a plurality of credit contribution indicators;
[0251] The acquisition module 620 is used to:
[0252] Determine the credit contribution value corresponding to each trust level based on the scores and weights corresponding to multiple credit contribution indicators at each trust level; wherein the credit contribution value represents the contribution degree of the multiple credit contribution indicators to the improvement of the user's credit level;
[0253] Determining a credit loss value corresponding to each trust level based on the scores and weights corresponding to multiple credit loss indicators at each trust level; wherein the credit loss value represents the degree of impact of the multiple credit loss indicators on the user's credit loss;
[0254] Based on the credit contribution value and credit loss value corresponding to each trust level, the user credit value corresponding to each trust level is determined.
[0255] In one embodiment of the present disclosure, the user authentication device 600 further includes:
[0256] An authentication module is used to authenticate the target user based on the user identity module SIM card;
[0257] The fourth determination module is used to query the preset list and determine whether the target user belongs to the preset list if the identity authentication is passed;
[0258] The authentication module 650 is used to:
[0259] Determine the corresponding resource access permissions based on the target user's trust level;
[0260] If it is determined that the target user needs to be re-authenticated based on the resource access rights, determine the authentication method corresponding to the trust level of the target user;
[0261] Authenticate the target user based on the authentication method.
[0262] In one embodiment of the present disclosure, the characteristic indicators include characteristic indicators in at least one of the following dimensions: terminal environment dimension, network location dimension, and user access behavior dimension.
[0263] It should be noted that the aforementioned description of the user authentication method embodiment is also applicable to the user authentication device of this embodiment and will not be repeated here.
[0264] The user authentication device provided by the embodiment of the present disclosure determines the characteristic value of the characteristic indicator based on the characteristic information of the target user, obtains the characteristic value ranges corresponding to multiple trust levels, determines the comprehensive membership of the trust level for each trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, determines the trust level to which the target user belongs based on the comprehensive membership of each trust level, and authenticates the target user based on the trust level to which the target user belongs. This can achieve the goal of accurately determining the trust level of the target user based on the characteristic information of the target user when the target user accesses shared resources, and authenticating the target user, thereby accurately controlling the target user's access rights to shared resources and improving the security of shared resources.
[0265] According to an embodiment of the present disclosure, an electronic device is further provided, comprising: a processor; and a memory for storing instructions executable by the processor, wherein the processor is configured to: implement the user authentication method disclosed in the embodiment of the present disclosure.
[0266] In order to implement the above embodiment, the embodiment of the present disclosure further proposes a storage medium.
[0267] When the instructions in the storage medium are executed by the processor, the processor is enabled to execute the user authentication method disclosed in the embodiment of the present disclosure.
[0268] In order to implement the above embodiments, the embodiments of the present disclosure also provide a computer program product.
[0269] When the computer program product is executed by a processor of an electronic device, the electronic device is enabled to execute the user authentication method disclosed in the embodiment of the present disclosure.
[0270] Figure 7 The figure is a structural block diagram of an electronic device according to an exemplary embodiment. Figure 7 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0271] like Figure 7 As shown, the electronic device 1000 includes a processor 111, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 112 or a program loaded from a memory 116 to a random access memory (RAM) 113. Various programs and data required for the operation of the electronic device 1000 are also stored in the RAM 113. The processor 111, the ROM 112, and the RAM 113 are connected to each other via a bus 114. An input / output (I / O) interface 115 is also connected to the bus 114.
[0272] The following components are connected to the I / O interface 115: a memory 116 including a hard disk, etc.; and a communication part 117 including a network interface card such as a local area network (LAN) card, a modem, etc., which performs communication processing via a network such as the Internet; a drive 118 is also connected to the I / O interface 115 as needed.
[0273] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program carried on a computer-readable medium, the computer program including program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 117. When the computer program is executed by the processor 111, the above-mentioned functions defined in the method of the present disclosure are performed.
[0274] In an exemplary embodiment, a storage medium including instructions is further provided, such as a memory including instructions, and the instructions can be executed by the processor 111 of the electronic device 1000 to perform the above method. Alternatively, the storage medium can be a non-transitory computer-readable storage medium, for example, a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0275] In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the foregoing.
[0276] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.
[0277] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A user authentication method, characterized in that: The method comprises: Determine a characteristic value corresponding to the characteristic indicator at the current moment based on characteristic information before the current moment in the characteristic information of the target user; Determining a characteristic value of the characteristic indicator corresponding to the historical moment based on characteristic information before the historical moment in the characteristic information of the target user; Smoothing the characteristic values of the characteristic indicator at the current moment and the historical moment to obtain the characteristic value of the characteristic indicator; Obtaining characteristic value ranges corresponding to multiple trust levels; For each trust level, determining a comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, wherein the comprehensive membership indicates the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level; Determining the trust level to which the target user belongs based on the comprehensive membership of each of the trust levels; authenticating the target user based on the trust level to which the target user belongs; There are multiple historical moments, and smoothing the characteristic values of the characteristic indicator corresponding to the current moment and the historical moments to obtain the characteristic values of the characteristic indicator includes: For the earliest historical moment among the multiple historical moments, taking the characteristic value of the characteristic indicator at the earliest historical moment as the smoothed characteristic value corresponding to the earliest historical moment; For any other historical moment except the earliest historical moment among the plurality of historical moments, smoothing the characteristic value of the characteristic indicator corresponding to the arbitrary historical moment and the smoothed characteristic value corresponding to the previous historical moment to obtain a final characteristic value corresponding to the arbitrary historical moment, and smoothing the final characteristic value of the characteristic indicator corresponding to the arbitrary historical moment and the smoothed characteristic value corresponding to the previous historical moment to obtain a smoothed characteristic value corresponding to the arbitrary historical moment; Smoothing is performed on the characteristic value of the characteristic indicator corresponding to the current moment and the smoothed characteristic value corresponding to the latest historical moment among the multiple historical moments to obtain the characteristic value of the characteristic indicator.
2. The method according to claim 1, wherein There are multiple characteristic indicators; for each trust level, determining the comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level includes: For each trust level, determining, based on a characteristic value of any characteristic indicator among the multiple characteristic indicators and a characteristic value range corresponding to the trust level, a characteristic membership degree of the arbitrary characteristic indicator to the trust level, wherein the characteristic membership degree indicates the degree to which the characteristic value of the arbitrary characteristic indicator belongs to the characteristic value range corresponding to the trust level; Obtaining weights corresponding to the plurality of characteristic indicators; Based on the characteristic memberships of the multiple characteristic indicators to the trust levels and the corresponding weights, a comprehensive membership of the trust levels is determined.
3. The method according to claim 2, wherein The determining of the comprehensive membership of the trust level based on the characteristic memberships of the multiple characteristic indicators to the trust level and the corresponding weights includes: Arrange the plurality of characteristic indicators in order according to the corresponding characteristic membership degrees, and remove a preset number of characteristic indicators that are ranked first or last, to obtain the remaining target characteristic indicators; Based on the characteristic membership of the target characteristic indicators to the trust levels and the corresponding weights, a comprehensive membership of the trust levels is determined.
4. The method according to claim 2, wherein The number of the characteristic indicators is N, where N is an integer greater than 1; and obtaining the weights corresponding to the plurality of characteristic indicators includes: Determine an initial weight relationship matrix corresponding to the multiple feature indicators; wherein the value of the element in the sth row and qth column of the initial weight relationship matrix represents the importance of the sth feature indicator relative to the qth feature indicator, the order of the initial weight relationship matrix is N, and s and q are integers from 1 to N; Determine a weight vector of the initial weight relationship matrix; wherein the kth element in the weight vector represents the weight corresponding to the kth characteristic index, and k is an integer from 1 to N; Determining the consistency of the initial weight relationship matrix, and adjusting the initial weight relationship matrix based on the consistency; The weight of each characteristic indicator is determined based on the weight vector of the adjusted weight relationship matrix.
5. The method according to claim 1, wherein The step of determining, for each trust level, a comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level includes: For each trust level, determining a current comprehensive membership of the trust level based on a current characteristic value of the characteristic indicator and a characteristic value range corresponding to the trust level, wherein the current characteristic value is determined based on characteristic information before the current moment in the characteristic information; Obtaining a historical comprehensive membership of the trust level, wherein the historical comprehensive membership is determined based on a historical characteristic value of the characteristic indicator and a characteristic value range corresponding to the trust level, and the historical characteristic value is determined based on characteristic information before a historical moment in the characteristic information; The comprehensive membership of the trust level is determined based on the historical comprehensive membership and the current comprehensive membership.
6. The method according to claim 1, wherein The obtaining of characteristic value ranges corresponding to multiple trust levels includes: Obtaining a score corresponding to the characteristic indicator at each trust level; wherein the score indicates the degree of contribution of the characteristic indicator to improving the user's creditworthiness or the degree of impact on the loss of the user's creditworthiness; Determining the user credit value corresponding to each trust level based on the score corresponding to the characteristic indicator at each trust level; The user credit value corresponding to each trust level is used as the boundary value of the corresponding characteristic value range, and combined with the domain value of the characteristic value of the characteristic indicator, the characteristic value range corresponding to each trust level is determined.
7. The method according to claim 6, wherein The characteristic indicators include multiple credit loss indicators and multiple credit contribution indicators; The determining of the user credit value corresponding to each trust level based on the score corresponding to the characteristic indicator at each trust level includes: Determining a credit contribution value corresponding to each trust level based on the scores and weights corresponding to the multiple credit contribution indicators at each trust level; wherein the credit contribution value represents the degree of contribution of the multiple credit contribution indicators to improving the user's credit; Determining a credit loss value corresponding to each trust level based on the scores and weights corresponding to the multiple credit loss indicators at each trust level; wherein the credit loss value represents the degree of influence of the multiple credit loss indicators on the user's credit loss; Based on the credit contribution value and the credit loss value corresponding to each trust level, the user credit value corresponding to each trust level is determined.
8. The method according to any one of claims 1 to 7, wherein Before authenticating the target user based on the trust level of the target user, the method further includes: Performing identity authentication on the target user based on a subscriber identity module SIM card; If the identity authentication is successful, query the preset list and determine whether the target user belongs to the users in the preset list; The authenticating the target user based on the trust level of the target user includes: Determining corresponding resource access rights based on the trust level of the target user; If it is determined that the target user needs to be re-authenticated based on the resource access rights, determining an authentication method corresponding to the trust level to which the target user belongs; Based on the authentication method, the target user is authenticated.
9. The method according to any one of claims 1 to 7, wherein The characteristic indicators include characteristic indicators in at least one of the following dimensions: terminal environment dimension, network location dimension and user access behavior dimension.
10. A user authentication device, characterized in that: The device comprises: A first determination module is configured to determine a characteristic value corresponding to a characteristic indicator at a current moment based on characteristic information before the current moment in the characteristic information of the target user; determine a characteristic value corresponding to the characteristic indicator at the historical moment based on characteristic information before the historical moment in the characteristic information of the target user; and smooth the characteristic values corresponding to the characteristic indicator at the current moment and the historical moment to obtain a characteristic value of the characteristic indicator; An acquisition module, used to obtain characteristic value ranges corresponding to multiple trust levels; a second determining module configured to determine, for each trust level, a comprehensive membership of the trust level based on the characteristic value of the characteristic indicator and the characteristic value range corresponding to the trust level, wherein the comprehensive membership indicates the degree to which the characteristic value of the characteristic indicator belongs to the characteristic value range corresponding to the trust level; A third determining module is configured to determine the trust level to which the target user belongs based on the comprehensive membership of each of the trust levels; an authentication module, configured to authenticate the target user based on the trust level to which the target user belongs; There are multiple historical moments, and the first determining module is specifically configured to: For the earliest historical moment among the multiple historical moments, taking the characteristic value of the characteristic indicator at the earliest historical moment as the smoothed characteristic value corresponding to the earliest historical moment; For any other historical moment except the earliest historical moment among the plurality of historical moments, smoothing the characteristic value of the characteristic indicator corresponding to the arbitrary historical moment and the smoothed characteristic value corresponding to the previous historical moment to obtain a final characteristic value corresponding to the arbitrary historical moment, and smoothing the final characteristic value of the characteristic indicator corresponding to the arbitrary historical moment and the smoothed characteristic value corresponding to the previous historical moment to obtain a smoothed characteristic value corresponding to the arbitrary historical moment; Smoothing is performed on the characteristic value of the characteristic indicator corresponding to the current moment and the smoothed characteristic value corresponding to the latest historical moment among the multiple historical moments to obtain the characteristic value of the characteristic indicator.
11. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the method according to any one of claims 1 to 9 when executing the computer program.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.
13. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 9 when the computer program is executed by a processor.
Citation Information
Patent Citations
Method for identifying vulnerable nodes of power distribution network
CN110428191A
Multi-attribute identity authentication method based on continuous trust evaluation
CN115333755A
Layered control method for urban regional integrated energy system
CN117151406A
Access control strategy self-adaption method and system based on attribute trust
CN117371007A