Dynamic Password Generation System for Mobile Devices

By building a multi-factor dynamic password generation system, combining transaction risk assessment, user behavior and emotional characteristic verification, the shortcomings of traditional identity verification mechanisms in telecommunications fraud are solved, and more efficient security protection is achieved.

CN119254492BActive Publication Date: 2025-07-25WUXI ZHIPU IOT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411370330.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2025-07-25
Estimated Expiration
2044-09-29

AI Technical Summary

Technical Problem

Traditional identity verification mechanisms are difficult to effectively distinguish between legal requests and fraud attempts in the face of carefully designed telecom fraud, which leads to threatening user information and funds security.

Method used

The transaction risk assessment module, user data packaging module, dynamic factor verification module and emotion monitoring verification module are adopted, and combined with the blockchain service network, a multi-factor dynamic password generation system is built to provide a multi-level security line through transaction risk assessment, user behavior and emotional characteristic verification.

Benefits of technology

It significantly improves users' anti-fraud capabilities when operating mobile devices, effectively resists telecommunications fraud, especially Ponzi schemes, ensures that payment efficiency is not affected in a low-risk environment, and provides a more solid financial security guarantee.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254492B_ABST
    Figure CN119254492B_ABST
Patent Text Reader

Abstract

The present invention discloses a dynamic password generation system for mobile devices, including a transaction risk assessment module, a user data packaging module, a dynamic factor verification module, an emotion monitoring verification module, and an early warning and blocking service module; wherein, the transaction risk assessment module is applicable to evaluating the risk of the current transaction environment when the device enters the financial transaction period; the user data packaging module is used to collect the associated data of the user using the mobile device and package and upload it to the blockchain service network; the dynamic factor verification module is used to add a dynamic factor verification mechanism based on user behavior after responding to the evaluation result of the transaction risk assessment module; the emotion monitoring verification module is used to add a user emotion factor verification mechanism further based on the dynamic factor verification mechanism of user behavior after responding to the evaluation result of the transaction risk assessment module. The present invention has the characteristics of high intelligence and high security level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and specifically to a dynamic password generation system for mobile devices. Background Art

[0002] In the digital age, mobile devices, as the central hubs of personal information, frequently participate in users' daily financial transactions, social interactions, and online services. However, this convenience also comes with huge security risks. Especially when users encounter sophisticated telecom frauds, especially Ponzi schemes, during the operation of their mobile devices, their financial and personal information security is often seriously threatened.

[0003] Traditional authentication mechanisms, such as static passwords or simple dynamic passwords, are inadequate when faced with such highly disguised and elaborate frauds. They often fail to effectively distinguish legitimate requests from fraud attempts, resulting in users leaking critical information or funds without their knowledge. Therefore, in order to enhance users' anti-fraud capabilities during mobile device operations, a more powerful and intelligent dynamic password generation system for identity authentication and risk identification is urgently needed. Summary of the Invention

[0004] The purpose of the present invention is to provide a dynamic password generation system for mobile devices to solve the problems raised in the above background art.

[0005] To solve the above technical problems, the present invention provides the following technical solution: A dynamic password generation system for mobile devices, including a transaction risk assessment module, a user data packaging module, a dynamic factor verification module, an emotion monitoring verification module, and a warning and blocking service module, with each module connected by signals; among them,

[0006] The transaction risk assessment module is applicable to assessing the risk of the current transaction environment when the device enters a financial transaction period;

[0007] The user data packaging module is used to collect the associated data of the user's use of the mobile device and package and upload it to the blockchain service network;

[0008] The dynamic factor verification module is used to add a dynamic factor verification mechanism based on user behavior after responding to the assessment result of the transaction risk assessment module;

[0009] The emotion monitoring verification module is used to add a user emotion factor verification mechanism on top of the dynamic factor verification mechanism based on user behavior after responding to the assessment result of the transaction risk assessment module;

[0010] The warning and blocking service module is used to warn the financial transaction program and block suspicious transactions according to the verification result of the multi-factor dynamic password mechanism.

[0011] According to the above technical solution, the transaction risk assessment module includes a transaction amount collection module, a transaction frequency collection module, and a transaction object collection module; wherein,

[0012] The transaction amount collection module is used to collect the single transaction amount during the financial transaction;

[0013] The transaction frequency collection module is used to collect and monitor the user's historical financial transaction frequency based on the financial transaction period;

[0014] The transaction object collection module is used to collect the transaction object during the financial transaction.

[0015] According to the above technical solution, the user data packaging module includes a user operation data storage module and a user facial data storage module; wherein,

[0016] The user operation data storage module is used to collect and record the standard operation data of the user operating the mobile device;

[0017] The user facial data storage module is used to collect and record the facial data of the user during the operation of the mobile device.

[0018] According to the above technical solution, the dynamic factor verification module includes a sliding trajectory tracking module, an operation timing module, and a touch sensing module; wherein,

[0019] The sliding trajectory tracking module is used to collect and continuously track the sliding trajectory of the gesture on the operation screen when the user operates the mobile device during the financial transaction;

[0020] The operation timing module is suitable for collecting the operation interval time between the front and back operation actions when the user operates the mobile device during the financial transaction and performing timing;

[0021] The touch sensing module is used to collect the touch pressure distribution area of the gesture on the operation screen when the user operates the mobile device during the financial transaction.

[0022] According to the above technical solution, the emotion monitoring and verification module includes a camera call unit, a brow recognition module, and a contour fitting module. The camera call unit is signal-connected to the brow recognition module, and the brow recognition module is signal-connected to the contour fitting module; wherein,

[0023] The camera call unit is used to call the camera permission of the mobile device during the financial transaction based on the evaluation result of the transaction risk assessment module;

[0024] The brow recognition module is used to monitor the real-time picture according to the camera call unit and track the user's brow information in the monitored picture based on the preset brow features;

[0025] The contour fitting module is used to fit the contour of the user's eyebrows and output the data on the change of the eyebrow contour during the monitoring period.

[0026] According to the above technical solution, the operation method of the dynamic password generation system includes the following steps:

[0027] Step S1: In response to monitoring that the mobile device enters the trading program, start the trading risk assessment module, and collect the current financial transaction amount, the trading frequency within the period monitored by the system, and the current trading object data respectively;

[0028] Step S2: Then, based on the collected data in Step S1, evaluate the risk of the current trading environment, and divide the evaluation results into a low-risk environment, a medium-risk environment, and a high-risk environment;

[0029] Step S3: When the evaluation result is a low-risk environment, the system outputs a dynamic password in the financial transaction link to verify the security of the trading environment;

[0030] Step S4: When the evaluation result is a medium-risk environment, the system first outputs a dynamic password in the financial transaction link to verify the security of the trading environment. If the dynamic password verification is successful, start the dynamic factor verification module to conduct a secondary verification of the current transaction;

[0031] Step S5: When the evaluation result is a high-risk environment, the system first outputs a dynamic password in the financial transaction link to verify the security of the trading environment. If the dynamic password verification is successful, start the dynamic factor verification module to conduct a secondary verification of the current transaction. If the secondary verification is successful, then start the emotion monitoring verification module to conduct a third verification of the current transaction;

[0032] Step S6: Obtain the final verification results of Steps S3 - S5. When the security verification result of any step is "verification failed", it is determined as a "suspicious transaction", and then a warning is issued and the current financial trading program is blocked.

[0033] According to the above technical solution, Step S2 further includes:

[0034] Step S21: When the single financial transaction amount is less than 1000 yuan, the historical trading frequency is less than once a day, and the trading object is not a "new trading object", and all three points are met at the same time, it is evaluated as a "low-risk environment", where the new trading object is the object that the user trades with for the first time within the last three days;

[0035] Step S22: When the trading environment meets only two of the three conditions described in Step S21 and does not simultaneously touch either of the following situations - the single financial transaction amount exceeds 10,000 yuan, or the historical trading frequency is higher than once an hour, then evaluate this trading environment as a "medium-risk environment";

[0036] Step S23: When the trading environment meets one or zero of the three conditions described in Step S21, or when the trading environment meets only two of the three conditions described in Step S21 but simultaneously touches either of the following situations - the single financial transaction amount exceeds 10,000 yuan, or the historical trading frequency is higher than once an hour, then evaluate this trading environment as a "high-risk environment".

[0037] According to the above technical solution, the method for performing secondary verification on the current transaction in Step S4 is as follows:

[0038] Step S41: Collect and continuously track the sliding track length values l1, l2,..., l of the gestures when the user operates the mobile device during the financial transaction on the operation screen; n ; where n is the sampling number of the sliding track length value, which is a positive integer; l n is the nth sliding track length sampling value;

[0039] Step S42: Collect the operation interval time between the previous and subsequent operation actions when the user operates the mobile device during the financial transaction, and perform timing to obtain the operation interval time values t1, t2,..., t m ; where m is the sampling number of the operation interval time, which is a positive integer; t m is the mth operation interval time sampling value;

[0040] Step S43: Collect the touch pressure distribution area of the gesture on the operation screen when the user operates the mobile device during the financial transaction, and mark the p mobile device touch screen corresponding pixel points x1, x2,..., x with the highest touch times during this period p , to obtain the set X = {x1, x2,..., x p};

[0041] Step S44: Calculate the average screen sliding track length value respectively using the formula Average operation interval time value

[0042] Step S45: Find the intersection of the set X = {x1, x2,..., x p} and the set X b = {x b1 , x b2 ,..., x bp}, and obtain the quantity q of this intersection; where X b= {x b1 , x b2 ,..., x bp} are the p mobile device touch screen pixel points x with the highest corresponding number of touches in the collected standard operation data of the user operating the mobile device stored in the user data packaging module b1 , x b2 , …, x bp ;

[0043] Step S46: When , the dynamic factor verification module responds to judge that the secondary verification is successful, otherwise it judges that the secondary verification fails, where l b , t b are respectively the standard sliding trajectory length value and the standard operation interval time value corresponding to the collected standard operation data of the user operating the mobile device stored in the user data packaging module, and α, β, γ are respectively the control parameters of the sliding trajectory length value, the operation interval time value and the touch pressure distribution area ratio value, all of which are constants greater than 0.

[0044] According to the above technical solution, the method for performing three verifications on the current transaction in step S5 is as follows:

[0045] Step S51: In response to the instruction signal of the emotion verification module, start the camera calling unit to call the front camera module of the mobile device to collect the user's facial picture;

[0046] Step S52: Use the brow recognition module to obtain the enlarged brow picture according to the brow features of the face;

[0047] Step S53: Fit the user's brow contour in the enlarged picture, define the brow area, and then calibrate the upper brow edge points and lower brow edge points of both sides of the brow, namely the upper brow edge point A, the upper brow edge point B, the lower brow edge point C, and the lower brow edge point D;

[0048] Step S54: Establish a plane rectangular coordinate system with the tip of the nose as the origin, the nasal midline as the Y axis, and the line obtained by rotating the nasal midline 90° at the tip of the nose as the X axis, and use the distance from the tip of the nose to the vertex of the upper lip on the Y axis as the unit distance 1 to calibrate the corresponding coordinate systems of the different distance facial pictures collected during the current transaction, and then obtain the coordinate positions of the upper brow edge point A, the upper brow edge point B, the lower brow edge point C, and the lower brow edge point D in the current user's facial picture respectively;

[0049] Step S55: Finally, compare and judge the coordinate positions of the upper brow edge point A, the upper brow edge point B, the lower brow edge point C, and the lower brow edge point D with the standard data collected and extracted by the user facial data storage module one by one;

[0050] Step S56: When the system preset error distance is exceeded by more than u sets of data, the emotion monitoring verification module responds and determines that the three verifications are successful; otherwise, it determines that the three verifications are failed.

[0051] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: By combining transaction risk assessment with a multi-factor dynamic password verification mechanism, the present invention significantly improves the anti-fraud ability of users during mobile device operations. At the same time, according to the risk level of the transaction environment, the verification method can be flexibly adjusted, from a single dynamic password verification to a secondary verification combined with user behavior characteristics, and then to a tertiary verification of emotional characteristics, thus constructing an all-round and intelligent security defense line. This not only effectively resists the infringement of telecommunications fraud, especially complex fraud means such as Ponzi schemes, but also ensures that the payment efficiency is not affected in a low-risk environment, providing a more solid guarantee for the security of users' funds. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention, and do not constitute a limitation to the present invention.

[0053] In the drawings:

[0054] Figure 1 is a schematic diagram of the system module composition of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] Please refer to Figure 1 , the present invention provides a technical solution: A dynamic password generation system for mobile devices, including a transaction risk assessment module, a user data packaging module, a dynamic factor verification module, an emotion monitoring verification module, and a warning and blocking service module. Each module is connected by signals; among them,

[0057] The transaction risk assessment module is applicable to evaluating the risk of the current transaction environment when the device enters a financial transaction period;

[0058] The user data packaging module is used to collect the associated data of the user's use of the mobile device and package and upload it to the blockchain service network;

[0059] The dynamic factor verification module is used to add a dynamic factor verification mechanism based on user behavior after responding to the evaluation result of the transaction risk assessment module;

[0060] The emotion monitoring and verification module is used to, after responding to the evaluation result of the transaction risk assessment module, further add a user emotion factor verification mechanism based on the dynamic factor verification mechanism of user behavior.

[0061] The early warning and blocking service module is used to give early warnings to the financial transaction program and block suspicious transactions according to the verification result of the multi-factor dynamic password mechanism; among them, the early warning methods include pop-up reminders, SMS notifications, etc.

[0062] The transaction risk assessment module includes a transaction amount collection module, a transaction frequency collection module, and a transaction object collection module; among them,

[0063] The transaction amount collection module is used to collect the amount of a single transaction during the financial transaction.

[0064] The transaction frequency collection module is used to collect and monitor the historical financial transaction frequency of the user based on the financial transaction period.

[0065] The transaction object collection module is used to collect the transaction object during the financial transaction.

[0066] The user data packaging module includes a user operation data storage module and a user facial data storage module; among them,

[0067] The user operation data storage module is used to collect and record the standard operation data of the user operating the mobile device; its collection method includes but is not limited to, during the first registration of the dynamic password generation system, performing the operation steps according to a set of mobile device operation processes preset by the system. During this period, the system calls the hardware device of the mobile device to complete the recording and storage of the user operation data, and the collected operation data includes the user's sliding trajectory, touch pressure distribution, and average operation interval time.

[0068] The user facial data storage module is used to collect and record the facial data of the user during the operation of the mobile device; its collection method also includes but is not limited to, during the first registration of the dynamic password generation system, performing face entry on the user's facial data according to the system preset.

[0069] The dynamic factor verification module includes a sliding trajectory tracking module, an operation timing module, and a touch sensing module; among them,

[0070] The sliding trajectory tracking module is used to collect and continuously track the sliding trajectory of the gesture on the operation screen when the user operates the mobile device during the financial transaction.

[0071] The operation timing module is applicable to collecting the operation interval time between the front and back operation actions when the user operates the mobile device during the financial transaction and performing timing.

[0072] The touch sensing module is used to collect the touch pressure distribution area of gestures on the operation screen when the user operates the mobile device during a financial transaction; by adding a dynamic factor verification mechanism based on user behavior to the original dynamic password, it can not only rely on time and keys but also on the dynamic characteristics of the user's behavior during a financial transaction, greatly improving the ability to resist man-in-the-middle attacks.

[0073] The emotion monitoring and verification module includes a camera calling unit, a brow recognition module, and a contour fitting module. There is a signal connection between the camera calling unit and the brow recognition module, and a signal connection between the brow recognition module and the contour fitting module; among them,

[0074] The camera calling unit is used to retrieve the camera permission of the mobile device during a financial transaction based on the evaluation result of the transaction risk assessment module;

[0075] The brow recognition module is used to monitor the real-time image according to the camera calling unit and track the user's brow information in the monitored image based on the preset brow features;

[0076] The contour fitting module is used to fit the user's brow contour and output the brow contour change data during the monitoring period; by further adding an emotion monitoring and verification mechanism for the user during a financial transaction, it can analyze and verify the emotional changes of the user's face again on the basis of the dynamic password and the dynamic factor verification of the user's behavior, so as to effectively detect that when the user is deeply involved in a financial fraud, due to the large transaction amount and the fraud being on the surface, but the user is reluctant to give up the previous investment, resulting in the user falling into deep suspicion and struggle, showing the situation of anxiety and fear; and aiming at the common involuntary facial muscle changes such as "frowning", "brows rising", and "brow distortion" when the user shows anxiety and fear, a monitoring and verification mechanism provides all-round and intelligent security protection, effectively resisting the infringement of Ponzi schemes and other telecommunications frauds.

[0077] The operation method of the dynamic password generation system includes the following steps:

[0078] Step S1: In response to monitoring that the mobile device enters the transaction program, start the transaction risk assessment module, and collect the current financial transaction amount, the transaction frequency within the period monitored by the system, and the current transaction object data respectively;

[0079] Step S2: Then, based on the collected data in Step S1, evaluate the risk of the current transaction environment, and divide the evaluation result into a low-risk environment, a medium-risk environment, and a high-risk environment;

[0080] Step S3: When the evaluation result is a low-risk environment, the system outputs a dynamic password during the financial transaction link for the security verification of the transaction environment;

[0081] Step S4: When the evaluation result is a medium-risk environment, the system first outputs a dynamic password in the financial transaction link to conduct a security verification of the transaction environment. If the dynamic password verification is successful, the dynamic factor verification module is activated to conduct a secondary verification of the current transaction;

[0082] Step S5: When the evaluation result is a high-risk environment, the system first outputs a dynamic password in the financial transaction link to conduct a security verification of the transaction environment. If the dynamic password verification is successful, the dynamic factor verification module is activated to conduct a secondary verification of the current transaction. If the secondary verification is successful, the emotion monitoring verification module is then activated to conduct a tertiary verification of the current transaction;

[0083] Step S6: Obtain the final verification results of Steps S3 - S5. When the security verification result of any step is "verification failed", it is determined as a "suspicious transaction", and then a warning is issued and the current financial transaction program is blocked; Through the above steps, the risk of the transaction environment can be evaluated during the transaction, and a multi-mode transaction verification mechanism can be generated correspondingly using the risk assessment results, which not only improves the anti-fraud ability of users when operating mobile devices, but also reduces the impact of the multi-factor dynamic password mechanism on the payment efficiency in a low transaction risk environment.

[0084] Step S2 further includes:

[0085] Step S21: When the single financial transaction amount is less than 1000 yuan, the historical transaction frequency is less than once a day, and the transaction object is not a "new transaction object", and all three of the above conditions are met, it is evaluated as a "low-risk environment", where the new transaction object is the object of the user's first transaction within the past three days;

[0086] Step S22: When the transaction environment only meets two of the three conditions in Step S21 and does not simultaneously touch any of the following situations - the single financial transaction amount exceeds 10000 yuan, or the historical transaction frequency is higher than once an hour, then the transaction environment is evaluated as a "medium-risk environment";

[0087] Step S23: When the trading environment meets one or none of the three conditions in Step S21, or when the trading environment only meets two of the three conditions in Step S21 but simultaneously touches any of the following situations - the single financial transaction amount exceeds 10,000 yuan, or the historical trading frequency is higher than once an hour, then the trading environment is evaluated as a "high-risk environment"; when the user encounters a sophisticated telecom fraud, especially a Ponzi scheme, during the operation of the mobile device, the trading environment is mainly manifested as making multiple transfer and remittance operations to new trading objects within a short period of time, and it will also be accompanied by an increasing transaction amount. The larger the single transaction amount, the more serious the one-time loss the user faces in the scam. Therefore, through the above steps, a comprehensive analysis and evaluation are carried out respectively from the single transaction amount, historical trading frequency, and trading object, and classified into the corresponding risk levels, so as to effectively cut into the characteristics of telecom fraud. This process not only enhances the accuracy of the system's recognition of telecom fraud characteristics but also lays a solid foundation for the subsequent introduction of a multi-factor dynamic password mechanism, ensuring that the security measures can be flexibly adjusted with the dynamic changes of the risk level, providing a more solid guarantee for the user's capital security.

[0088] The method for performing a secondary verification on the current transaction in Step S4 is as follows:

[0089] Step S41: Collect and continuously track the length values l1, l2, …, l of the sliding trajectory of the user's gesture on the operation screen when operating the mobile device during a financial transaction n ; where n is the sampling number of the sliding trajectory length value, and it is a positive integer; l n is the nth sampling value of the sliding trajectory length;

[0090] Step S42: Collect the operation interval time between the previous and subsequent operation actions when the user operates the mobile device during a financial transaction, and perform timing to obtain the operation interval time values t1, t2, …, t m ; where m is the sampling number of the operation interval time, and it is a positive integer; t m is the mth sampling value of the operation interval time;

[0091] Step S43: Collect the touch pressure distribution area of the gesture on the operation screen when the user operates the mobile device during a financial transaction, and mark the p mobile device touch screen corresponding pixel points x1, x2, …, x with the highest touch times during this period p , and obtain the set X = {x1, x2, …, x p};

[0092] Step S44: Calculate the average screen sliding trajectory length value respectively using the formula Average operation interval time value

[0093] Step S45: Find the intersection of set X = {x1, x2, …, x p} and set X b = {x b1 , x b2 , …, x bp}, and obtain the number q of the intersection; where X b = {x b1 , x b2 ,..., x bp} are the p mobile device touch screen pixel points x b1 , x b2 , …, x bp with the highest corresponding touch times in the collected standard operation data of the user operating the mobile device stored in the user data packaging module;

[0094] Step S46: When , the dynamic factor verification module responds to determine that the secondary verification is successful, otherwise it determines that the secondary verification fails, where l b , t b are respectively the standard sliding trajectory length value and the standard operation interval time value corresponding to the collected standard operation data of the user operating the mobile device stored in the user data packaging module, and α, β, γ are respectively the control parameters of the sliding trajectory length value, the operation interval time value, and the touch pressure distribution area ratio value, all of which are constants greater than 0; in the formula, when the smaller the corresponding value of p - q is, the smaller the formula calculation value is, that is, when the sliding trajectory length value of the average screen, the average operation interval time value, and the touch pressure distribution area on the operation screen are closer to the standard operation data collected during the first registration of the dynamic password generation system, the secondary verification mechanism of the final dynamic factor verification module is more likely to succeed; through the above steps, on the basis of the original dynamic password, a dynamic factor verification based on user behavior can be added, and it is necessary to comprehensively meet the verification of multiple operation behavior results to pass the secondary verification mechanism, so as to effectively avoid the financial transaction behaviors of users under the influence of the outside world such as "remote guidance" and "on - site guidance" during the process of being defrauded by telecommunications. Only when the user performs consecutive mobile device operations according to their operation habits can the verification be satisfied, greatly improving the transaction security.

[0095] The method for performing three - factor verification on the current transaction in Step S5 is as follows:

[0096] Step S51: In response to the instruction signal of the emotion verification module, start the camera calling unit to call the front - facing camera module of the mobile device to collect the user's facial image;

[0097] Step S52: Use the brow recognition module to obtain the magnified image of the brow area according to the brow features of the face;

[0098] Step S53: fitting the user's eyebrow contour in the enlarged image, defining the eyebrow area, and respectively marking the upper and lower eyebrow points of the eyebrows on both sides, namely, upper eyebrow point A, upper eyebrow point B, lower eyebrow point C, and lower eyebrow point D;

[0099] Step S54: establish a plane rectangular coordinate system with the nose tip as the origin, the nose midline as the Y axis, and the straight line of the nose midline rotated 90 degrees at the nose tip as the X axis, and take the distance from the nose tip to the upper lip vertex on the Y axis as the unit distance 1, calibrate the corresponding coordinate system of the facial images of different distances collected during the current transaction, and then respectively obtain the coordinate positions of the upper brow point A, the upper brow point B, the lower brow point C, and the lower brow point D in the current user's facial image;

[0100] Step S55: Finally, the coordinate positions of the upper edge point A, the upper edge point B, the lower edge point C, and the lower edge point D of the brow are compared with the standard data collected and extracted by the user's facial data storage module;

[0101] Step S56: When the error distance exceeds the system preset error distance and reaches more than u groups of data, the emotion monitoring verification module responds and judges that the three verifications are successful, otherwise it judges that the three verifications fail; when the transaction environment is evaluated as a "high-risk environment", it means that the user may be involved in a large amount of money, a high transaction frequency, and a low credibility transaction object during the current financial transaction, especially when the user is deeply involved in a Ponzi scheme, the user loses the ability to think independently, and there will be fear and anxiety due to the fear of missing investment opportunities or facing financial losses. In this emotional state, facial features such as frowning, raising eyebrows, and twisting eyebrows generally appear inadvertently. Therefore, for high-risk transaction environments, the system not only performs dual verification of the user's dynamic password and dynamic factors based on user behavior, but also further analyzes and judges the user's emotional characteristics at this moment. If the analysis shows that there are potential tension, anxiety, fear and other emotions, the verification fails, and the current financial transaction program is warned and blocked in time, which ultimately aims to provide users with all-round and intelligent security protection when operating mobile devices, and effectively resist the infringement of telecommunications fraud such as Ponzi schemes.

[0102] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.

[0103] Finally, it should be noted that the above are only preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A dynamic password generation system for mobile devices, characterized in that: The dynamic password generation system includes a transaction risk assessment module, a user data packaging module, a dynamic factor verification module, an emotion monitoring verification module, and an early warning and blocking service module, and the modules are connected by signals; among them, The transaction risk assessment module is applicable to assessing the current transaction environment risk when the device enters the financial transaction period; The user data packaging module is used to collect the associated data of the user using the mobile device and package and upload it to the blockchain service network; The dynamic factor verification module is used to add a dynamic factor verification mechanism based on user behavior after responding to the evaluation result of the transaction risk assessment module; The emotion monitoring verification module is used to add a user emotion factor verification mechanism on the basis of the dynamic factor verification mechanism based on user behavior after responding to the evaluation result of the transaction risk assessment module; The early warning and blocking service module is used to give an early warning to the financial transaction program and block suspicious transactions according to the verification result of the multi-factor dynamic password mechanism; The dynamic factor verification module includes a sliding trajectory tracking module, an operation timing module, and a touch sensing module; among them, The sliding trajectory tracking module is used to collect and continuously track the sliding trajectory of the gesture on the operation screen when the user operates the mobile device during the financial transaction; The operation timing module is applicable to collecting the operation interval time between the front and back operation actions when the user operates the mobile device during the financial transaction and performing timing; The touch sensing module is used to collect the touch pressure distribution area of the gesture on the operation screen when the user operates the mobile device during the financial transaction; by adding a dynamic factor verification mechanism based on user behavior on the basis of the original dynamic password, it is possible to not only rely on time and keys during financial transactions, but also rely on the dynamic behavioral characteristics of the user; The operation method of the dynamic password generation system includes the following steps: Step S1: In response to monitoring that the mobile device enters the transaction program, start the transaction risk assessment module, and collect the current financial transaction amount, the transaction frequency within the period monitored by the system, and the current transaction object data respectively; Step S2: Then, according to the collected data in Step S1, evaluate the current transaction environment risk, and divide the evaluation result into a low-risk environment, a medium-risk environment, and a high-risk environment; Step S3: When the evaluation result is a low-risk environment, the system outputs a dynamic password in the financial transaction link for security verification of the transaction environment; Step S4: When the evaluation result is a medium-risk environment, the system first outputs a dynamic password in the financial transaction link for security verification of the transaction environment. If the dynamic password verification is successful, start the dynamic factor verification module to perform secondary verification on the current transaction; Step S5: When the evaluation result is a high-risk environment, the system first outputs a dynamic password in the financial transaction link for security verification of the transaction environment. If the dynamic password verification is successful, start the dynamic factor verification module to perform secondary verification on the current transaction. If the secondary verification is successful, then start the emotion monitoring verification module to perform tertiary verification on the current transaction; Step S6: Obtain the final verification results of Steps S3 - S5. When the security verification result of any step is "verification failed", it is determined as a "suspicious transaction", and then a warning is issued and the current financial transaction process is blocked; The method for verifying the current transaction three times in Step S5 is as follows: Step S51: In response to the instruction signal of the emotion verification module, start the camera calling unit to call the front camera module of the mobile device to collect the user's facial image; Step S52: Use the brow recognition module to obtain a magnified image of the brow area based on the brow features of the face; Step S53: Fit the user's brow contour in the magnified image. After defining the brow area, mark the upper brow points and lower brow points on both sides of the brow, namely upper brow point A, upper brow point B, lower brow point C, and lower brow point D; Step S54: Establish a plane rectangular coordinate system with the tip of the nose as the origin, the nasal midline as the Y-axis, and the line obtained by rotating the nasal midline 90° at the tip of the nose as the X-axis. Use the distance from the tip of the nose to the vertex of the upper lip, which is on the Y-axis, as the unit distance 1. Calibrate the corresponding coordinate systems of the facial images at different distances collected during the current transaction, and then obtain the coordinate positions of upper brow point A, upper brow point B, lower brow point C, and lower brow point D in the current user's facial image; Step S55: Finally, compare and judge the coordinate positions of upper brow point A, upper brow point B, lower brow point C, and lower brow point D one by one with the standard data collected and extracted by the user facial data storage module; Step S56: When the number of data groups exceeding the system preset error distance reaches u or more, the emotion monitoring verification module responds and determines that the three verifications are successful; otherwise, it determines that the three verifications are failed.

2. The dynamic password generation system for a mobile device according to claim 1, wherein: The transaction risk assessment module includes a transaction amount collection module, a transaction frequency collection module, and a transaction object collection module; among them, The transaction amount collection module is used to collect the single transaction amount during the financial transaction; The transaction frequency collection module is used to collect and monitor the user's historical financial transaction frequency based on the financial transaction period; The transaction object collection module is used to collect the transaction object during the financial transaction.

3. The dynamic password generation system for a mobile device according to claim 1, wherein: The user data packaging module includes a user operation data storage module and a user facial data storage module; among them, The user operation data storage module is used to collect and record the standard operation data of the user operating the mobile device; The user facial data storage module is used to collect and record the facial data of the user during the operation of the mobile device.

4. The dynamic password generation system for a mobile device according to claim 3, characterized in that: The emotion monitoring verification module includes a camera calling unit, a brow recognition module, and a contour fitting module. The camera calling unit is signal-connected to the brow recognition module, and the brow recognition module is signal-connected to the contour fitting module; among them, The camera calling unit is used to call the camera permission of the mobile device during the financial transaction based on the evaluation result of the transaction risk assessment module; The brow recognition module is used to monitor the real-time image based on the camera calling unit and track the user's brow information in the monitored image based on the preset brow features; The contour fitting module is used to fit the contour of the user's eyebrows and output the data on the change of the eyebrow contour during the monitoring period.

5. The dynamic password generation system for a mobile device according to claim 1, wherein: The step S2 further includes: Step S21: When the single financial transaction amount is less than 1000 yuan, the historical transaction frequency is less than once a day, and the transaction object is not a "new transaction object", and all three of the above conditions are met, it is evaluated as a "low-risk environment", where the new transaction object is the object with which the user conducts the first transaction within the last three days; Step S22: When the trading environment only meets two of the three conditions described in step S21 and does not simultaneously touch any of the following situations - the single financial transaction amount exceeds 10,000 yuan, or the historical transaction frequency is higher than once an hour, then the trading environment is evaluated as a "medium-risk environment"; Step S23: When the trading environment meets one or none of the three conditions described in step S21, or when the trading environment only meets two of the three conditions described in step S21 but simultaneously touches any of the following situations - the single financial transaction amount exceeds 10,000 yuan, or the historical transaction frequency is higher than once an hour, then the trading environment is evaluated as a "high-risk environment".

6. The dynamic password generation system for a mobile device according to claim 1, wherein: The method for secondary verification of the current transaction in step S4 is: Step S41: Collect and continuously track the length values l1, l2, …, l of the sliding trajectory of the gesture when the user operates the mobile device during a financial transaction on the operation screen n ; where n is the number of sampling times of the sliding trajectory length value, and n is a positive integer; l n is the nth sliding trajectory length sampling value; Step S42: Collect the operation interval time between the pre-operation and post-operation actions when the user operates the mobile device during a financial transaction, and perform timing to obtain the operation interval time values t1, t2, …, tm; m where m is the number of samples of the operation interval time, which is a positive integer; tm m is the m-th sampled value of the operation interval time; Step S43: Collect the touch pressure distribution area of the gesture on the operation screen when the user operates the mobile device during the financial transaction, and mark the p mobile device touch screen corresponding pixel points x1, x2, …, x p , to obtain the set X = {x1, x2, …, x p}; Step S44: Calculate the sliding track length value of the average screen using formulas respectively Average operation interval time value Step S45: Find the intersection of set X = {x1, x2, …, x p} and set X b = {x b1 , x b2 , …, x bp}, and obtain the number q of the intersection; where X b = {x b1 , x b2 ,..., x bp} are the p mobile device touch screen pixel points x b1 , x b2 , …, x bp with the highest corresponding touch times among the collected standard operation data of the user operating the mobile device stored in the user data packaging module; Step S46: When occurs, the dynamic factor verification module responds to determine that the secondary verification is successful, otherwise it determines that the secondary verification fails, where l b , t b are respectively the corresponding standard sliding trajectory length value and standard operation interval time value in the standard operation data of the user's operation of the mobile device collected and stored in the user data packaging module, and α, β, γ are respectively the control parameters of the sliding trajectory length value, operation interval time value, and touch pressure distribution area ratio value, all of which are constants greater than 0.

Citation Information

Patent Citations

  • Method, apparatus and device for verifying financial business and computer storage medium

    CN108269187A

  • Financial business processing method and device based on face recognition, equipment and medium

    CN113177480A