An electronic ticket generation and verification system based on network trusted identity
By introducing verification analysis module and node analysis module in the electronic ticket generation and verification system, analysis strategies are formulated based on the connection status and status of network nodes, the problem of insufficient network node reliability analysis in the prior art is solved, and the accuracy and management efficiency of monitoring results are improved.
Patent Information
- Application Number
- CN202510093512.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-21
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-21
AI Technical Summary
The prior art has failed to further analyze the reliability of network nodes based on the connection between network nodes in actual working scenarios, resulting in low accuracy of the reliability judgment results of node monitoring.
An electronic ticket generation and verification system based on a network trusted identity is provided, including a verification analysis module, a node analysis module, a first node execution module, a second node execution module and a ticket processing module. The system determines the status of each target verification identity and key analysis nodes in response to authentication update conditions and node status conditions, and formulates targeted analysis strategies based on different node statuses to improve the reliability of monitoring results of network nodes.
By conducting more refined analysis and policy formulation of network nodes, the effectiveness of monitoring results of network authentication nodes is improved, the risk of authentication errors is reduced, and the efficiency of access rights management in the target management park is improved.
Smart Images

Figure CN119561777B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of identity authentication, and in particular to an electronic ticket generation and verification system based on network trusted identity. Background Art
[0002] Currently, the generation and verification operations of electronic tickets are based on the network verification results of the verification target. Real-time monitoring is performed on the network nodes that perform network identity authentication to ensure the reliability of the identity authentication results of the network nodes. This can effectively improve the accuracy of electronic ticket generation and verification results. However, the operation status of the network nodes and the connection relationship between the network nodes are likely to affect the judgment results of the reliability of the network nodes. Therefore, how to determine the targeted node analysis method based on the actual nodes to improve the reliability of the monitoring results of the network nodes is an urgent problem to be solved by technical personnel in this field.
[0003] China Patent Application Publication No. CN115643047A discloses a blockchain identity authentication method based on integrity reward, including: a user client sends an identity authentication processing request to the authentication blockchain network, and the identity authentication blockchain network arranges the three nodes that first grab the processing right to perform identity authentication processing; if the number of suspicious nodes in the three authentication nodes that first grab the processing right is greater than the number of trusted nodes, or the authentication results of the three authentication nodes are inconsistent, then a credibility random algorithm is used to randomly select several nodes from the trusted nodes for a second identity authentication, ensuring that the number of trusted nodes in the authentication nodes is greater than the number of suspicious nodes and the number of votes in the final result accounts for the majority; finally, the authentication blockchain network returns the final result to the client and performs identity authentication processing reward work. China Patent Publication No. CN117974170A discloses a scenic spot data management method and system based on electronic ticket verification, which belongs to the field of encrypted communication technology. In the scenic spot data management method based on electronic ticket verification, the mobile device sends the first ciphertext and the second ciphertext to the scenic spot terminal, and the scenic spot terminal decrypts the first ciphertext and the second ciphertext to verify the access authority of the mobile device. After the ticket verification is completed, the mobile device encrypts the ticket purchase code according to the third encryption parameter to generate a third ciphertext. The resource server generates a third private key based on the master key, decrypts the third ciphertext based on the third private key to obtain the ticket purchase code, and then pushes the multimedia data to the mobile device. The above technical solution has the following problems: it fails to make further analysis on the reliability of the network nodes according to the connection conditions between the network nodes in the actual working scenario, resulting in low accuracy of the reliability judgment result of the node monitoring. Summary of the invention
[0004] To this end, the present invention provides an electronic ticket generation and verification system based on network trusted identity, so as to overcome the problem in the prior art that the reliability of network nodes is not further analyzed according to the connection conditions between network nodes in actual working scenarios, resulting in low accuracy of reliability judgment results of node monitoring.
[0005] To achieve the above-mentioned purpose, the present invention provides an electronic ticket generation and verification system based on a network trusted identity, comprising:
[0006] A verification analysis module, responsive to the authentication update condition, to determine the category of each target verification identity;
[0007] A node analysis module, which is connected to the verification analysis module, and is used to periodically respond to node status conditions to determine the node status of each key analysis node, and respond to the node status of each key analysis node to determine a node analysis strategy, wherein the node analysis strategy is to perform analysis combination settings for key analysis nodes, or to perform associated node analysis for key analysis nodes;
[0008] A first node execution module, which is connected to the node analysis module, is used to respond to the combination division condition to determine the combination division method, and respond to different division conditions to determine the combination analysis method of each node analysis combination, the combination analysis method includes determining the verification reliability coefficient according to the proportion of key monitoring nodes and the reference monitoring coefficient, and determining the verification reliability coefficient according to the reference association duration and the reference density coefficient;
[0009] a second node execution module, connected to the node analysis module, for responding to the traffic verification condition to determine whether to perform abnormal communication analysis on the associated node of the key analysis node, and determining whether the key analysis node can perform network identity authentication according to the reference abnormal communication coefficient;
[0010] A ticket processing module, which is respectively connected to the verification analysis module, the first node execution module and the second node execution module, and the ticket processing module includes a ticket generation unit and a ticket verification unit, wherein the ticket generation unit is used to generate a target electronic ticket and a target identity verification code, and the ticket verification unit determines whether to respond to the permission application based on the permission authentication coefficient of the target verification person.
[0011] Further, the verification analysis module is responsive to the authentication update condition to periodically determine the category of each target verification identity;
[0012] Verify identity against a single target,
[0013] If the authentication update condition responded by the authentication analysis module is that the authority change coefficient is greater than the preset authority change coefficient or the authentication duration coefficient is greater than the preset authentication duration coefficient, the target authentication identity is determined to be an authentication update identity;
[0014] If the authentication update condition responded by the authentication analysis module is that the authority change coefficient is less than or equal to the preset authority change coefficient and the authentication duration coefficient is less than or equal to the preset authentication duration coefficient, the target authentication identity is determined to be a regular authentication identity.
[0015] Further, the node analysis module is responsive to the node status condition to periodically determine the node status of each key analysis node;
[0016] For a single key analysis node,
[0017] If the node status condition responded by the node analysis module is that the verification update ratio is greater than the preset verification update ratio or the node communication parameter is greater than the preset node communication parameter, it is determined that the key analysis node is in the first preset node state;
[0018] If the node status condition responded by the node analysis module is that the verification update ratio is less than or equal to the preset verification update ratio and the node communication parameter is less than or equal to the preset node communication parameter, it is determined that the key analysis node is in the second preset node state;
[0019] The key analysis node is a network authentication node that needs to perform network identity authentication for verifying the updated identity.
[0020] Further, the node analysis module responds to the node status of each key analysis node to periodically determine the node analysis strategy of each key analysis node;
[0021] If the node analysis condition responded by the node analysis module is that the key analysis node is in the first preset node state, it is determined to perform analysis combination setting for the key analysis node;
[0022] The node analysis condition responded by the node analysis module is that the key analysis node is in the second preset node state, and then it is determined to perform association analysis on the key analysis node.
[0023] Furthermore, the first node execution module performs node analysis combination division for the key analysis node and its associated nodes in response to the first node analysis condition;
[0024] The first node execution module responds to the combination partitioning condition to determine the combination partitioning mode;
[0025] If the combination division condition responded by the first node execution module is that the proportion of central nodes is greater than the preset proportion of central nodes, the node analysis combination is determined according to the topological connection coefficient;
[0026] If the combination division condition responded by the first node execution module is that the proportion of central nodes is less than or equal to the preset proportion of central nodes, the node analysis combination is determined according to the node density coefficient;
[0027] The first node analysis condition is that the node analysis module determines to perform analysis combination setting for a key analysis node.
[0028] Further, the first node execution module responds to the first division condition and determines the key monitoring coefficient of each associated central node according to the key communication frequency and the associated difference coefficient to determine the key monitoring node;
[0029] Determine the verification reliability coefficient of key analysis nodes based on the proportion of key monitoring nodes and reference monitoring coefficient;
[0030] The first division condition is that a node analysis combination is determined according to a topological connection coefficient, and a reference topological connection coefficient of the node analysis combination is greater than a preset reference topological connection coefficient.
[0031] Further, the first node execution module determines the verification reliability coefficient of the key analysis node corresponding to the node analysis combination according to the reference association duration and the reference density coefficient in response to the second division condition;
[0032] The verification reliability coefficient is positively correlated with the reference association duration and the reference density coefficient respectively;
[0033] The second division condition is that a node analysis combination is determined according to a node density coefficient, and a reference density coefficient of the node analysis combination is greater than a preset reference density coefficient.
[0034] Further, the second node execution module detects the communication message proportion of each associated node of the key analysis node in response to the second node analysis condition, and determines the abnormal proportion difference coefficient of the key analysis node according to the communication message proportion of each associated node;
[0035] If the traffic verification condition responded by the second node execution module is that the abnormal proportion difference coefficient is greater than the preset abnormal proportion difference coefficient, it is determined to perform abnormal communication analysis on the associated nodes of the key analysis node;
[0036] The second node analysis condition is that the node analysis module determines to perform association analysis on a key analysis node.
[0037] Further, the second node execution module responds to the abnormal analysis condition and determines the abnormal communication coefficient of each associated node of the key analysis node according to the associated connection frequency and the flow difference parameter;
[0038] If the node determination condition responded by the second node execution module is that the reference abnormal communication coefficient is less than the preset reference abnormal communication coefficient, the key analysis node is determined to be a verification node;
[0039] The reference abnormal communication coefficient is an average value of the abnormal communication coefficients of each associated node of the key analysis node;
[0040] The abnormal analysis condition is that the second node execution module determines to perform abnormal communication analysis on a node associated with a key analysis node.
[0041] Further, the ticket generation unit generates a target electronic ticket and a target identity verification code based on the target verification identity in response to the verification completion condition, and sends the target electronic ticket and the target identity verification code together to the target verification person corresponding to the target verification identity;
[0042] The ticket verification unit responds to the authority authentication condition and determines the authority authentication coefficient of the target verification person according to the reference feature similarity and the authority range matching degree;
[0043] The permission response condition responded by the ticket verification unit is that the permission authentication coefficient of a target verification person is greater than the preset permission authentication coefficient, and then it is determined to respond to the permission application of the target verification person;
[0044] The verification completion condition is that a target verification identity is a regular verification identity or a verification update identity completes the verification update process, and the authority authentication condition is that the ticket verification unit obtains an authority application from a target verification person.
[0045] Compared with the prior art, the beneficial effect of the present invention lies in that the node analysis module in the technical solution of the present invention determines the degree of influence of each key analysis node on the overall authentication result and its own influence on other network authentication nodes according to the verification update ratio and the node communication parameters, and determines the corresponding targeted node analysis strategy, so that the analysis process of each key analysis node is more in line with the actual working scenario, and further improves the effectiveness of the monitoring results of the network authentication nodes in the target management park, so as to reduce the risk of authentication errors in the target management park. The present invention improves the management efficiency of the access rights of the target management park.
[0046] Furthermore, the present invention determines the node status of each key analysis node based on the verification update ratio and the node communication parameters, so as to characterize the influence of each key analysis node on the overall management process of the target management park and the degree to which it is susceptible to the influence of other network nodes, so that the subsequent selection of node analysis strategies is more in line with the needs of actual work scenarios, so as to improve the effectiveness of the monitoring results of network authentication nodes.
[0047] Furthermore, in the present invention, for the key analysis nodes in the first preset node state, the division method of the corresponding node analysis combination and the subsequent combined analysis method are determined according to the central node proportion of each key analysis node. Since the key analysis nodes in the first preset node state have a greater impact on the overall management process of the target management park or are more susceptible to the influence of associated nodes, a combined analysis is performed on such key analysis nodes, and targeted analysis methods are determined for different node analysis combinations. This can effectively improve the effectiveness of the monitoring results of the network authentication nodes in the target management park, thereby improving the management efficiency of the access rights of the target management park.
[0048] Furthermore, in the present invention, for the key analysis node in the second preset node state, it is determined whether to perform further abnormal communication analysis according to the difference in the proportion of communication messages of the associated nodes of the key analysis node, and the credibility of the key analysis node is determined according to the acquired abnormal communication coefficient. Since the key analysis node in the second preset node state has a smaller impact on the overall management process of the target management park and is not easily affected by the associated nodes, the reliability of the key analysis node is determined according to the difference in the proportion of communication messages between its different associated nodes, which improves the analysis efficiency while ensuring the validity of the monitoring results of the corresponding network authentication node. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 It is a module connection diagram of the electronic ticket generation and verification system based on network trusted identity of the present invention;
[0050] Figure 2 A flow chart of the node analysis module of the present invention determining the node status of each key analysis node in response to the node status condition;
[0051] Figure 3 A flowchart of a node analysis strategy for determining each key analysis node by a node analysis module of the present invention in response to a node status;
[0052] Figure 4 This is a flow chart of the first node execution module of the present invention responding to the combination partitioning condition to determine the combination partitioning method. DETAILED DESCRIPTION
[0053] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0054] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.
[0055] It should be noted that, in the description of the present invention, terms such as "up", "down", "left", "right", "inside" and "outside" indicating directions or positional relationships are based on the directions or positional relationships shown in the drawings. This is merely for the convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it cannot be understood as a limitation on the present invention.
[0056] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0057] See also Figures 1 to 4 As shown, the present invention provides an electronic ticket generation and verification system based on a network trusted identity, comprising:
[0058] A verification analysis module, responsive to the authentication update condition, to determine the category of each target verification identity;
[0059] A node analysis module, which is connected to the verification analysis module, and is used to periodically respond to node status conditions to determine the node status of each key analysis node, and respond to the node status of each key analysis node to determine a node analysis strategy, wherein the node analysis strategy is to perform analysis combination settings for key analysis nodes, or to perform associated node analysis for key analysis nodes;
[0060] A first node execution module, which is connected to the node analysis module, is used to respond to the combination division condition to determine the combination division method, and respond to different division conditions to determine the combination analysis method of each node analysis combination to determine the verification reliability coefficient of the key analysis node, the combination analysis method includes determining the verification reliability coefficient according to the proportion of key monitoring nodes and the reference monitoring coefficient, and determining the verification reliability coefficient according to the reference association duration and the reference density coefficient;
[0061] a second node execution module, connected to the node analysis module, for responding to the traffic verification condition to determine whether to perform abnormal communication analysis on the associated node of the key analysis node, and determining whether the key analysis node can perform network identity authentication according to the reference abnormal communication coefficient;
[0062] A ticket processing module is connected to the verification analysis module, the first node execution module and the second node execution module. The ticket processing module includes a ticket generation unit and a ticket verification unit, wherein the ticket generation unit is used to generate a target electronic ticket and a target identity verification code, and the ticket verification unit determines whether to respond to the permission application based on the permission authentication coefficient of the target verification person.
[0063] The present invention is used to manage access rights for a park. The electronic ticket can ensure the access management effect in the park while improving the flexibility of the management process. It can be understood that the park described in the present invention needs to verify the identity and access rights of personnel through a corresponding authentication method before entering the park and specific locations in the park. The park that needs to perform communication authority management is recorded as a target management park, and the personnel who need to obtain access rights in the target management park are recorded as target verification personnel. Each target verification personnel has a corresponding target verification identity. The information contained in the target verification identity contains each authentication time and the corresponding access rights of the target verification personnel. The access rights are the areas that can be passed set for the target verification personnel;
[0064] Several communication management records are applied in the present invention, and any access management record records the authority change coefficient, authentication time coefficient, verification update ratio, node communication parameters, central node ratio, reference topology connection coefficient, key monitoring coefficient, verification reliability coefficient of each verification node, reference density coefficient, abnormal ratio difference coefficient, reference abnormal communication coefficient and authority authentication coefficient in the process of communication authority management for a target management park at least once, and each access management record corresponds to a qualified mark, which records whether the management efficiency of the communication authority of the target management park meets user needs.
[0065] Specifically, the verification analysis module is responsive to the authentication update condition to periodically determine the category of each target verification identity;
[0066] Verify identity against a single target,
[0067] If the authentication update condition responded by the authentication analysis module is that the authority change coefficient is greater than the preset authority change coefficient or the authentication duration coefficient is greater than the preset authentication duration coefficient, the target authentication identity is determined to be an authentication update identity;
[0068] If the authentication update condition responded by the authentication analysis module is that the authority change coefficient is less than or equal to the preset authority change coefficient and the authentication duration coefficient is less than or equal to the preset authentication duration coefficient, the target authentication identity is determined to be a regular authentication identity.
[0069] Among them, for a single target verification identity, the authority change coefficient = the area of the changed authority area / the area of the area included in the access authority set for the target verification identity, the changed authority area is the area of the newly added area in the communication authority corresponding to the target verification identity at the end time of the current identity authentication cycle compared to the end time of the previous identity authentication cycle, the authentication duration coefficient = ln (authentication update frequency / authentication interval duration), the authentication update frequency is the number of times the target verification identity completes the authentication update within the preset frequency analysis duration, the value of the preset frequency analysis duration can be determined by the user according to the actual work scenario, for example, the user can set it according to historical analysis records. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the greater the value of the preset frequency analysis time. A value of the preset frequency analysis time is provided. The value of the preset frequency analysis time is 10 times the duration of the current identity authentication cycle. The authentication interval time is the interval between the current time and the most recent authentication update time of the target authentication identity. The authentication update time is when any network authentication node completes the authentication update for the target authentication identity, that is, the network authentication node verifies the information contained in the target authentication identity. How the network authentication node verifies the information contained in the target authentication identity is easily understood by those skilled in the art.
[0070] The values of the preset authority change coefficient and the preset authentication time coefficient can be determined by the user according to the actual work scenario. For example, the user can set them according to the historical analysis records. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the smaller the value of the preset authority change coefficient, and the smaller the value of the preset authentication time coefficient. A method for determining the value of the preset authority change coefficient is provided, and the minimum value of the authority change coefficient for verifying and updating the identity in the historical analysis records that meet the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset authority change coefficient. A method for determining the value of the preset authentication time coefficient is provided, and the minimum value of the authentication time coefficient for verifying and updating the identity in the historical analysis records that meet the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset authentication time coefficient.
[0071] The present invention applies a cyclic identity authentication cycle, and the duration of the identity authentication cycle can be determined by the user. The higher the user's requirement for the management efficiency of the communication authority of the target management park, the shorter the duration of the identity authentication cycle. The duration of an identity authentication cycle is provided, and the identity authentication cycle is 1 hour. The end time of each identity authentication cycle is judged according to the category of each target verification identity.
[0072] Specifically, the node analysis module is responsive to the node status condition to periodically determine the node status of each key analysis node;
[0073] For a single key analysis node,
[0074] If the node status condition responded by the node analysis module is that the verification update ratio is greater than the preset verification update ratio or the node communication parameter is greater than the preset node communication parameter, it is determined that the key analysis node is in the first preset node state;
[0075] If the node status condition responded by the node analysis module is that the verification update ratio is less than or equal to the preset verification update ratio and the node communication parameter is less than or equal to the preset node communication parameter, it is determined that the key analysis node is in the second preset node state;
[0076] The key analysis node is a network authentication node that needs to perform network identity authentication for verifying the updated identity.
[0077] Among them, there are several network authentication nodes in the present invention, which are used to store and verify and update various types of information contained in each target verification identity. For a single key analysis node, the verification update ratio = the number of verification update identities that need to be completed by the key analysis node / the number of target verification identities stored in the key analysis node. The node communication parameters are determined according to the number of associated nodes of the key analysis node and the reference association coverage. The node communication parameters are the sum of the products of the number of associated nodes and the reference association coverage and the corresponding influence coefficients. The associated nodes are network authentication nodes that have communication connections with the key analysis nodes. The reference association coverage is the average value of the number of network authentication nodes that have communication connections with each associated node. The number of associated nodes and the value of the influence coefficient corresponding to the reference association coverage can be determined by the user according to the actual work scenario. The value of the influence coefficient corresponding to the number of associated nodes and the reference association coverage is provided. The value of the influence coefficient corresponding to the number of associated nodes is 0.6, and the value of the influence coefficient corresponding to the reference association coverage is 0.4.
[0078] The preset verification update ratio and the value of the preset node communication parameter can be determined by the user according to the actual work scenario. For example, the user can set them according to the historical analysis records. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the smaller the value of the preset verification update ratio and the smaller the value of the preset node communication parameter. A method for determining the value of the preset verification update ratio is provided, and the minimum value of the verification update ratio of the key analysis nodes in the historical analysis records that meet the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset verification update ratio. A value of the preset verification update ratio is provided, and the value of the preset verification update ratio is 0.4. A method for determining the value of the preset node communication parameter is provided, and the minimum value of the node communication parameter of the key analysis node in the historical analysis records that meet the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset node communication parameter.
[0079] The present invention applies a cyclic node analysis cycle, and the duration of the node analysis cycle can be determined by the user. The higher the user's requirement for the management efficiency of the communication authority of the target management park, the shorter the duration of the node analysis cycle. A node analysis cycle duration is provided, and the node analysis cycle is 5 hours. At the end time of each node analysis cycle, the node status of each key analysis node is detected and the node analysis is performed according to the corresponding node analysis strategy.
[0080] Specifically, the node analysis module responds to the node status of each key analysis node to determine the node analysis strategy of each key analysis node;
[0081] If the node analysis condition responded by the node analysis module is that the key analysis node is in the first preset node state, it is determined to perform analysis combination setting for the key analysis node;
[0082] The node analysis condition responded by the node analysis module is that the key analysis node is in the second preset node state, and then it is determined to perform association analysis on the key analysis node.
[0083] Specifically, the first node execution module responds to the first node analysis condition, and then performs node analysis combination division on the key analysis node and its associated nodes;
[0084] The first node execution module responds to the combination partitioning condition to determine the combination partitioning mode;
[0085] If the combination division condition responded by the first node execution module is that the proportion of central nodes is greater than the preset proportion of central nodes, the node analysis combination is determined according to the topological connection coefficient;
[0086] If the combination division condition responded by the first node execution module is that the proportion of central nodes is less than or equal to the preset proportion of central nodes, the node analysis combination is determined according to the node density coefficient;
[0087] The first node analysis condition is that the node analysis module determines to perform analysis combination setting for a key analysis node.
[0088] Among them, for a single key analysis node in the first preset node state, the central node ratio = the number of central nodes included in the associated nodes of the key analysis node / the number of associated nodes of the key analysis node. The central node is an associated node whose number of network authentication nodes with communication connections is greater than the preset number of nodes. The value of the preset central node ratio can be determined by the user according to the actual work scenario. For example, the user can set it according to historical analysis records. A method for determining the value of the preset central node ratio is provided. The historical analysis records for determining the node analysis combination according to the topological connection coefficient are recorded as combination reference records. The average value of the central node ratio of each key analysis node in the combination reference record that meets the user's management efficiency requirements for the communication authority of the target management park is recorded as the preset central node ratio. A value of the preset central node ratio is provided. The value of the preset central node ratio is 0.4. The obtained node analysis combination is a set of the key analysis node and some associated nodes of the key analysis node.
[0089] Specifically, the first node execution module responds to the first division condition and determines the key monitoring coefficient of each associated central node according to the key communication frequency and the associated difference coefficient;
[0090] If the node monitoring condition responded by the first node execution module is that the key monitoring coefficient of an associated central node is greater than the preset key monitoring coefficient, the associated central node is recorded as the key monitoring node of the key analysis node corresponding to the node analysis combination, and the verification reliability coefficient of the key analysis node is determined according to the proportion of the key monitoring nodes and the reference monitoring coefficient;
[0091] The first division condition is that a node analysis combination is determined according to a topological connection coefficient, and a reference topological connection coefficient of the node analysis combination is greater than a preset reference topological connection coefficient.
[0092] Among them, if a node analysis combination is determined according to the topological connection coefficient, the reference topological connection coefficient of the node analysis combination is the average value of the topological connection coefficients of each associated node and the key analysis node in the node analysis combination. For a single associated node, the topological connection coefficient is the number of associated nodes that are simultaneously the associated node and the key analysis node. The value of the preset reference topological connection coefficient can be determined by the user according to the actual work scenario. For example, the user can set it according to the historical analysis records. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the larger the value of the preset reference topological connection coefficient. A method for setting the value of the preset reference topological connection coefficient is provided, and the minimum value of the reference topological connection coefficient of each node analysis combination in the combined reference record that meets the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset reference topological connection coefficient;
[0093] For a single node analysis combination, the associated central node is an associated node that serves as a central node in the node analysis combination. For a single associated central node, the key monitoring coefficient is the natural logarithm of the product of the key communication frequency and the associated difference coefficient. The associated communication frequency is the sum of the number of times the associated central node completes message reception and transmission with its associated nodes in the current node analysis cycle. The associated difference coefficient is the absolute value of the difference between the maximum and minimum number of times the associated central node completes message reception and transmission with its associated nodes in the current node analysis cycle. The value of the preset key monitoring coefficient can be determined by the user according to the actual working scenario. For example, the user can set it according to the historical analysis records. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the larger the value of the preset key monitoring coefficient. A method for determining the value of the preset key monitoring coefficient is provided to satisfy The average value of the key monitoring coefficients of each key monitoring node in the combination reference record of the user's management efficiency requirements for the communication rights of the target management park is recorded as the preset key monitoring coefficient. The verification reliability coefficient of the key analysis node in the node analysis combination = 1 / (key monitoring node proportion + reference monitoring coefficient), the key monitoring node proportion = the number of key monitoring nodes in the node analysis combination / the number of associated nodes in the node analysis combination, and the reference monitoring coefficient is the average value of the key monitoring coefficients of each associated node in the node analysis combination. If the verification reliability coefficient of the key analysis node is greater than the preset first verification coefficient, it is determined that the key analysis node can be used as a verification node. If the verification reliability coefficient of the key analysis node is less than or equal to the preset first verification coefficient, a warning message is sent to the user, prompting that the verification update result of the key analysis node for the target verification identity is at risk;
[0094] The value of the preset first verification coefficient can be determined by the user according to the actual working scenario. For example, the user can set it according to the historical analysis record. The higher the user's requirement for the management efficiency of the communication authority of the target management park, the larger the value of the preset first verification coefficient. A method for determining the value of the preset first verification coefficient is provided, and the minimum value of the verification reliability coefficient of the verification node in the combined reference record that meets the user's requirement for the management efficiency of the communication authority of the target management park is recorded as the preset first verification coefficient.
[0095] Specifically, the first node execution module responds to the second division condition and determines the verification reliability coefficient of the key analysis node corresponding to the node analysis combination according to the reference association duration and the reference density coefficient;
[0096] The verification reliability coefficient is positively correlated with the reference association duration and the reference density coefficient respectively;
[0097] The second division condition is that a node analysis combination is determined according to a node density coefficient, and a reference density coefficient of the node analysis combination is greater than a preset reference density coefficient.
[0098] Among them, for a single associated node, its node density coefficient with the key analysis node is the natural logarithm of the product of the associated connection frequency and the associated communication ratio, the associated communication ratio = the number of times the associated node and the key analysis node complete message sending and receiving in the current node analysis cycle / the number of times the associated node completes message sending and receiving in the current node analysis cycle, for a single node analysis combination determined according to the node density coefficient, the reference density coefficient is the average value of the node density coefficients of each associated node and the key analysis node in the node analysis combination, the value of the preset reference density coefficient can be determined by the user according to the actual working scenario, for example, the user can set it according to the historical analysis record, the higher the user's requirements for the management efficiency of the communication authority of the target management park, the larger the value of the preset reference density coefficient, and a method for setting the value of the preset reference density coefficient is provided, the historical analysis record of the node analysis combination determined according to the node density coefficient is recorded as a dense reference record, and the minimum value of the reference density coefficient of each node analysis combination in the dense reference record that meets the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset reference density coefficient;
[0099] For a single node analysis combination determined according to the node density coefficient, the verification reliability coefficient of the key analysis node in the node analysis combination is the sum of the products of the reference association duration and the reference density coefficient and the corresponding verification influence coefficient. The reference association duration is the average value of the maximum connection durations between each associated node and the key analysis node in the node combination in the current node analysis cycle. The connection duration is the duration during which the associated node and the key analysis node can continuously complete the message sending and receiving. The values of the verification influence coefficient corresponding to the reference association duration and the reference density coefficient can be determined by the user according to the actual working scenario. A reference association duration and a value of the verification influence coefficient corresponding to the reference density coefficient are provided. The value of the verification influence coefficient corresponding to the reference association duration is 0.6, and the value of the verification influence coefficient corresponding to the reference density coefficient is 0.4. If the verification reliability coefficient of the key analysis node is greater than the preset second verification coefficient, it is determined that the key analysis node can be used as a verification node. If the verification reliability coefficient of the key analysis node is less than or equal to the preset second verification coefficient, a warning message is sent to the user, prompting that the key analysis node has a risk in the verification update result of the target verification identity.
[0100] The value of the preset second verification coefficient can be determined by the user according to the actual working scenario. For example, the user can set it according to the historical analysis record. The higher the user's requirement for the management efficiency of the communication authority of the target management park, the larger the value of the preset second verification coefficient. A method for determining the value of the preset second verification coefficient is provided, and the minimum value of the verification reliability coefficient of the verification node in the dense reference record that meets the user's requirement for the management efficiency of the communication authority of the target management park is recorded as the preset second verification coefficient.
[0101] Specifically, the second node execution module responds to the second node analysis condition, detects the communication message proportion of each associated node of the key analysis node, and determines the abnormal proportion difference coefficient of the key analysis node according to the communication message proportion of each associated node;
[0102] If the traffic verification condition responded by the second node execution module is that the abnormal proportion difference coefficient is greater than the preset abnormal proportion difference coefficient, it is determined to perform abnormal communication analysis on the associated nodes of the key analysis node;
[0103] The second node analysis condition is that the node analysis module determines to perform association analysis on a key analysis node.
[0104] Among them, for any key analysis node that needs to be associated with the key analysis node, the communication message ratio of each associated node of the key analysis node is detected, and the abnormal ratio difference coefficient of the key analysis node = the maximum value of the abnormal ratio difference value of each associated node / the average value of the absolute value of the abnormal ratio difference value of each associated node. For a single associated node, the communication message ratio = the number of times the associated node and the key analysis node complete message sending and receiving / the number of times the key analysis node completes message sending and receiving, the abnormal ratio difference value = the communication message ratio of the associated node - the reference message ratio of the key analysis node, and the reference message ratio is the average value of the communication message ratio of each associated node of the key analysis node. When a network node is attacked from the outside, the communication message ratio between its different associated nodes will be greatly different. The abnormal ratio difference coefficient can effectively characterize whether each key analysis node has the risk of being attacked;
[0105] The value of the preset abnormality proportion difference coefficient can be determined by the user according to the actual work scenario. For example, the user can set it according to the historical analysis records. The higher the user's requirement for the management efficiency of the communication authority of the target management park, the smaller the value of the preset abnormality proportion difference coefficient. A method for determining the value of the preset abnormality proportion difference coefficient is provided, and the minimum value of the abnormality proportion difference coefficient of each key analysis node for abnormal communication analysis of the associated nodes in the historical analysis records that meet the user's requirement for the management efficiency of the communication authority of the target management park is recorded as the preset abnormality proportion difference coefficient.
[0106] Specifically, the second node execution module responds to the abnormal analysis condition and determines the abnormal communication coefficient of each associated node of the key analysis node according to the associated connection frequency and the flow difference parameter;
[0107] If the node determination condition responded by the second node execution module is that the reference abnormal communication coefficient is less than the preset reference abnormal communication coefficient, the key analysis node is determined to be a verification node;
[0108] The reference abnormal communication coefficient is an average value of the abnormal communication coefficients of each associated node of the key analysis node;
[0109] The abnormal analysis condition is that the second node execution module determines to perform abnormal communication analysis on a node associated with a key analysis node.
[0110] Among them, if an associated node of a key analysis node needs to perform abnormal communication analysis, for a single associated node, the abnormal communication coefficient is the natural logarithm of the product of the associated connection frequency and the traffic difference parameter, the associated connection frequency is the number of times a communication connection is established between the associated node and the key analysis node in the current node analysis cycle, the traffic difference parameter is the amount of data received by the associated node in the current node analysis cycle, and the value of the preset reference abnormal communication coefficient can be determined by the user according to the actual working scenario. For example, the user can set it according to the historical analysis record. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the smaller the value of the preset reference abnormal communication coefficient. A method for setting the value of the preset reference abnormal communication coefficient is provided, and the historical analysis record of the verification node determined according to the reference abnormal communication coefficient is recorded as a second reference record, and the maximum value of the reference abnormal communication coefficient of each verification node in the second reference record that meets the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset reference abnormal communication coefficient;
[0111] Among them, the verification nodes determined by different node analysis strategies can perform verification and update on the verification and update identity to determine whether the verification and update identity is a network trusted identity. Only the network trusted identity can obtain the target electronic ticket. How each verification node performs verification and update on the verification and update identity is easy to understand for those skilled in the art and will not be elaborated here.
[0112] Specifically, the ticket generation unit generates a target electronic ticket and a target identity verification code based on the target verification identity in response to the verification completion condition, and sends the target electronic ticket and the target identity verification code together to the target verification person corresponding to the target verification identity;
[0113] The ticket verification unit responds to the authority authentication condition and determines the authority authentication coefficient of the target verification person according to the reference feature similarity and the authority range matching degree;
[0114] The permission response condition responded by the ticket verification unit is that the permission authentication coefficient of a target verification person is greater than the preset permission authentication coefficient, and then it is determined to respond to the permission application of the target verification person;
[0115] The verification completion condition is that a target verification identity is a regular verification identity or a verification update identity completes the verification update process, and the authority authentication condition is that the ticket verification unit obtains an authority application from a target verification person.
[0116] Among them, if a target verification identity is a regular verification identity or a verification update identity that has completed the verification update process, a target electronic ticket is generated based on the information contained in the target verification identity. The information category displayed on the generated target electronic ticket can be set by the user according to the actual work scenario. The information category contained in the target verification identity and that can be displayed on the target electronic ticket includes but is not limited to: verification personnel image, name, gender and position information. The verification personnel image is the facial image of the target verification personnel. When the target electronic ticket is generated, a target identity verification code is generated for authority authentication. The ticket verification unit obtains the corresponding target verification personnel facial image and access authority by scanning the target identity verification code. If a target verification personnel submits an authority application and a target identity verification code, the authority application is for the target verification personnel. For the area that the person needs to pass through, a facial image of the person who has applied for permission is obtained and recorded as the applicant image. Facial features are extracted from the applicant image and the verification person image corresponding to the target identity verification code provided by the applicant, and the feature similarity of each facial feature between the applicant image and the verification person image is detected. The average value of the feature similarity of each facial feature is recorded as the reference feature similarity of the target verification person. If the area corresponding to the permission application submitted by the target verification person is not within the area included in the access permission corresponding to his target identity verification code, the target verification person's permission range matching degree is determined to be 0. If the area corresponding to the permission application submitted by the target verification person is within the area included in the access permission corresponding to his target identity verification code, the target verification person's permission range matching degree is determined to be 1.
[0117] The authority authentication coefficient is the sum of the reference feature similarity and the authority range matching degree. The value of the preset authority authentication coefficient can be determined by the user according to the actual work scenario. For example, the user can set it according to the historical analysis record. The higher the user's requirements for the management efficiency of the communication authority of the target management park, the larger the value of the preset authority authentication coefficient. A method for setting the value of the preset authority authentication coefficient is provided. The average value of the authority authentication coefficient of the target verification personnel corresponding to the authority application answered in the historical analysis record that meets the user's requirements for the management efficiency of the communication authority of the target management park is recorded as the preset authority authentication coefficient. The authority application of a target verification personnel is answered, that is, the target verification personnel is allowed to pass the area corresponding to his authority application. How to generate a target electronic ticket and a target identity verification code according to the information contained in the target verification identity, how to obtain the corresponding target verification personnel's facial image and access authority by identifying the target identity verification code, and how to determine the feature similarity of each facial feature between the applicant personnel image and the verification personnel image are contents that technicians in this field have mastered and will not be repeated here.
[0118] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
[0119] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. An electronic ticket generation and verification system based on network trusted identity, characterized in that: include: A verification analysis module, responsive to the authentication update condition, to determine the category of each target verification identity; A node analysis module, which is connected to the verification analysis module, and is used to periodically respond to node status conditions to determine the node status of each key analysis node, and respond to the node status of each key analysis node to determine a node analysis strategy; A first node execution module, which is connected to the node analysis module, is used to respond to the combination division condition to determine the combination division method, and respond to different division conditions to determine the combination analysis method of each node analysis combination, the combination analysis method includes determining the verification reliability coefficient according to the proportion of key monitoring nodes and the reference monitoring coefficient, and determining the verification reliability coefficient according to the reference association duration and the reference density coefficient; a second node execution module, connected to the node analysis module, for responding to the traffic verification condition to determine whether to perform abnormal communication analysis on the associated node of the key analysis node, and determining whether the key analysis node can perform network identity authentication according to the reference abnormal communication coefficient; a ticket processing module, which is connected to the verification analysis module, the first node execution module and the second node execution module respectively, and the ticket processing module includes a ticket generation unit and a ticket verification unit, wherein the ticket generation unit is used to generate a target electronic ticket and a target identity verification code, and the ticket verification unit determines whether to respond to the permission application according to the permission authentication coefficient of the target verification person; If the node analysis condition responded by the node analysis module is that the key analysis node is in the first preset node state, it is determined to perform analysis combination setting for the key analysis node; The node analysis condition responded by the node analysis module is that the key analysis node is in the second preset node state, and then it is determined to perform association analysis on the key analysis node.
2. The electronic ticket generation and verification system based on network trusted identity according to claim 1 is characterized in that: The verification analysis module is responsive to the authentication update condition to periodically determine the category of each target verification identity; Verify identity against a single target, If the authentication update condition responded by the authentication analysis module is that the authority change coefficient is greater than the preset authority change coefficient or the authentication duration coefficient is greater than the preset authentication duration coefficient, the target authentication identity is determined to be an authentication update identity; If the authentication update condition responded by the authentication analysis module is that the authority change coefficient is less than or equal to the preset authority change coefficient and the authentication duration coefficient is less than or equal to the preset authentication duration coefficient, the target authentication identity is determined to be a regular authentication identity.
3. The electronic ticket generation and verification system based on network trusted identity according to claim 2 is characterized in that: The node analysis module is responsive to the node status condition to periodically determine the node status of each key analysis node; For a single key analysis node, If the node status condition responded by the node analysis module is that the verification update ratio is greater than the preset verification update ratio or the node communication parameter is greater than the preset node communication parameter, it is determined that the key analysis node is in the first preset node state; If the node status condition responded by the node analysis module is that the verification update ratio is less than or equal to the preset verification update ratio and the node communication parameter is less than or equal to the preset node communication parameter, it is determined that the key analysis node is in the second preset node state; The key analysis node is a network authentication node that needs to perform network identity authentication for verifying the updated identity.
4. The electronic ticket generation and verification system based on network trusted identity according to claim 3 is characterized in that: The first node execution module responds to the first node analysis condition and performs node analysis combination division on the key analysis node and its associated nodes; The first node execution module responds to the combination partitioning condition to determine the combination partitioning mode; If the combination division condition responded by the first node execution module is that the proportion of central nodes is greater than the preset proportion of central nodes, the node analysis combination is determined according to the topological connection coefficient; If the combination division condition responded by the first node execution module is that the proportion of central nodes is less than or equal to the preset proportion of central nodes, the node analysis combination is determined according to the node density coefficient; The first node analysis condition is that the node analysis module determines to perform analysis combination setting for a key analysis node.
5. The electronic ticket generation and verification system based on network trusted identity according to claim 4 is characterized in that: The first node execution module responds to the first division condition and determines the key monitoring coefficient of each associated central node according to the key communication frequency and the associated difference coefficient to determine the key monitoring node; Determine the verification reliability coefficient of key analysis nodes based on the proportion of key monitoring nodes and reference monitoring coefficient; The first division condition is that a node analysis combination is determined according to a topological connection coefficient, and a reference topological connection coefficient of the node analysis combination is greater than a preset reference topological connection coefficient.
6. The electronic ticket generation and verification system based on network trusted identity according to claim 5 is characterized in that: The first node execution module responds to the second division condition and determines the verification reliability coefficient of the key analysis node corresponding to the node analysis combination according to the reference association duration and the reference density coefficient; The verification reliability coefficient is positively correlated with the reference association duration and the reference density coefficient respectively; The second division condition is that a node analysis combination is determined according to a node density coefficient, and a reference density coefficient of the node analysis combination is greater than a preset reference density coefficient.
7. The electronic ticket generation and verification system based on network trusted identity according to claim 6 is characterized in that: The second node execution module detects the communication message proportion of each associated node of the key analysis node in response to the second node analysis condition, and determines the abnormal proportion difference coefficient of the key analysis node according to the communication message proportion of each associated node; If the traffic verification condition responded by the second node execution module is that the abnormal proportion difference coefficient is greater than the preset abnormal proportion difference coefficient, it is determined to perform abnormal communication analysis on the associated nodes of the key analysis node; The second node analysis condition is that the node analysis module determines to perform association analysis on a key analysis node.
8. The electronic ticket generation and verification system based on network trusted identity according to claim 7, characterized in that: The second node execution module responds to the abnormal analysis condition and determines the abnormal communication coefficient of each associated node of the key analysis node according to the associated connection frequency and the flow difference parameter; The node determination condition responded by the second node execution module is that the reference abnormal communication coefficient is less than the preset reference abnormal communication coefficient, then the key analysis node is determined to be a verification node; The reference abnormal communication coefficient is an average value of the abnormal communication coefficients of each associated node of the key analysis node; The abnormal analysis condition is that the second node execution module determines to perform abnormal communication analysis on a node associated with a key analysis node.
9. The electronic ticket generation and verification system based on network trusted identity according to claim 8, characterized in that: The ticket generation unit generates a target electronic ticket and a target identity verification code based on the target identity verification in response to the verification completion condition, and sends the target electronic ticket and the target identity verification code together to the target verification person corresponding to the target identity verification; The ticket verification unit responds to the authority authentication condition and determines the authority authentication coefficient of the target verification person according to the reference feature similarity and the authority range matching degree; The permission response condition responded by the ticket verification unit is that the permission authentication coefficient of a target verification person is greater than the preset permission authentication coefficient, and then it is determined to respond to the permission application of the target verification person; The verification completion condition is that a target verification identity is a regular verification identity or a verification update identity completes the verification update process, and the authority authentication condition is that the ticket verification unit obtains an authority application from a target verification person.
Citation Information
Patent Citations
Block chain identity authentication method based on honesty reward
CN115643047A
Scenic spot data management method and system based on electronic ticket verification
CN117974170A
Data processing method and device based on block chain, equipment and medium
CN118897862A