An internet-based multi-party signature electronic payment method and system

By analyzing signature behavior using machine learning and deep learning technologies, a risk assessment model is established, and signature timestamp differences are monitored in real time. Adaptive strategies are adopted to adjust intervention measures, which solves the problems of consistency and timeliness in judging abnormal signatures in multi-party signature electronic payments, thereby improving payment security and user experience.

CN119671561BActive Publication Date: 2026-02-03DONGGUAN UNIONPAY TONGGUAN POS LEASING SERVICE
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411781627.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2026-02-03
Estimated Expiration
2044-12-05

AI Technical Summary

Technical Problem

In multi-signature electronic payment scenarios, it is difficult to unify the criteria for judging abnormal signature behavior, and it is difficult to balance timeliness and accuracy. Data inconsistency increases the complexity of judgment, affecting fund security and user experience.

Method used

By analyzing the statistical characteristics of signature behavior through machine learning algorithms, a quantitative standard for judging signature anomalies is established. Multi-dimensional feature analysis is carried out by combining deep learning technology to construct a signature behavior risk assessment model, monitor signature timestamp differences in real time, and adopt an adaptive signature intervention strategy to adjust the frequency and intensity of intervention.

Benefits of technology

Effectively identify abnormal signature behavior, improve the security and reliability of electronic signatures, reduce the impact on normal payment processes, and provide intelligent and precise risk management methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119671561B_ABST
    Figure CN119671561B_ABST
Patent Text Reader

Abstract

The application provides an Internet-based multi-party signature electronic payment method and system, comprising: obtaining historical signature data, analyzing signature behavior statistical characteristics by using a machine learning algorithm, obtaining signature anomaly judgment quantitative standards, determining abnormal threshold values of signature duration, stroke number, pressure change and timestamp characteristics; according to the signature anomaly judgment quantitative standards, obtaining signature trajectory, speed and timestamp multidimensional characteristics, comprehensively analyzing the multidimensional characteristics by using a deep learning technology, obtaining an abnormal signature recognition accuracy; according to the abnormal signature recognition accuracy, establishing a signature behavior risk assessment model, quantifying the risk degree of signature behavior, obtaining a signature intervention strategy decision basis; if the difference between the signature timestamps exceeds a preset threshold value, triggering a signature delay anomaly warning, and starting a signature intervention measure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology, and in particular to a multi-signature electronic payment method and system based on the Internet. Background Technology

[0002] In multi-signature electronic payment scenarios, signature intervention technology faces numerous technical challenges. First, the criteria for judging abnormal signature behavior are difficult to standardize. Different payment scenarios have different definitions of signature abnormalities, making it difficult to determine the triggering conditions for intervention. For example, in some scenarios, a signature delay might be considered abnormal, while in others it might be considered normal. This variability makes it difficult to establish a unified standard for judging abnormal signatures. Second, the timeliness and accuracy of signature intervention are difficult to balance. To prevent risks in a timely manner, the system needs to monitor and intervene in abnormal signature behavior in real time. However, overly frequent interventions may affect the normal payment process, leading to a decline in user experience. At the same time, if the intervention strategy is too lenient, it may fail to effectively prevent risks, threatening fund security. Furthermore, signature intervention also faces the problem of data inconsistency. In multi-signature scenarios, the signature data of each participant may be inconsistent, such as asynchronous timestamps or inconsistent signature algorithms. This data inconsistency increases the difficulty of judging abnormal signature behavior, further increasing the complexity of signature intervention technology. In summary, in multi-signature electronic payment scenarios, signature intervention technology faces technical challenges such as the difficulty in unifying judgment standards, the challenge of balancing timeliness and accuracy, and data inconsistencies. How to ensure fund security while minimizing the impact on normal payment processes is a key issue that signature intervention technology needs to address. This requires a comprehensive consideration of factors such as the characteristics of the payment scenario, risk prevention needs, and user experience. By optimizing abnormal signature judgment algorithms and dynamically adjusting intervention strategies, the effectiveness and reliability of signature intervention technology can be continuously improved. Summary of the Invention

[0003] This invention provides an internet-based multi-signature electronic payment method, mainly comprising:

[0004] Historical signature data is obtained, and machine learning algorithms are used to analyze the statistical characteristics of signature behavior to obtain quantitative standards for judging signature anomalies and determine the anomaly thresholds for signature duration, number of strokes, pressure changes, and timestamp features.

[0005] Based on the aforementioned signature anomaly judgment quantification standard, multi-dimensional features of signature trajectory, speed, and timestamp are obtained. Deep learning technology is used to comprehensively analyze the multi-dimensional features to obtain the anomaly signature recognition accuracy.

[0006] Based on the accuracy of abnormal signature identification, a signature behavior risk assessment model is established to quantify the degree of risk of signature behavior and obtain the basis for signature intervention strategy decision-making.

[0007] The signature timestamps of each participant are obtained in real time from the Internet. Based on the abnormal thresholds of the signature duration, number of strokes, pressure changes and timestamp characteristics, and the signature behavior risk assessment model, it is determined whether the difference between the signature timestamps exceeds a preset threshold.

[0008] If the difference between the signature timestamps exceeds a preset threshold, a signature delay abnormality warning is triggered, and signature intervention measures are initiated.

[0009] Based on factors such as transaction amount, user credit score, and transaction frequency, the payment risk level is comprehensively assessed, and an adaptive signature intervention strategy is adopted. Through a dynamic weight allocation mechanism, the frequency and intensity of intervention are automatically adjusted according to the importance of different factors.

[0010] This invention provides an internet-based multi-signature electronic payment system, mainly comprising:

[0011] The signature anomaly detection module is used to establish quantitative standards for signature anomalies.

[0012] Anomaly signature recognition module is used to analyze multi-dimensional features to improve recognition accuracy;

[0013] The risk assessment module is used to build models to quantify the degree of risk.

[0014] The real-time monitoring module is used to obtain timestamps to identify anomalies;

[0015] The intervention strategy module is used to take adaptive intervention measures based on the risk level.

[0016] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0017] This invention discloses an internet-based multi-party signature electronic payment method. This method analyzes historical signature data to establish quantitative standards for judging signature anomalies, including anomaly thresholds for signature duration, number of strokes, pressure variations, and timestamp features. Deep learning technology is used to comprehensively analyze multi-dimensional features such as signature trajectory, speed, and timestamps to construct a signature behavior risk assessment model. This invention acquires the signature timestamps of each participant in real time and determines whether their differences exceed a preset threshold. If they do, a signature delay anomaly warning is triggered, and intervention measures are initiated. Simultaneously, considering factors such as transaction amount, user credit score, and transaction frequency, an adaptive signature intervention strategy is adopted, automatically adjusting the intervention frequency and intensity through a dynamic weight allocation mechanism. This invention can effectively identify abnormal signature behavior, improve the security and reliability of electronic signatures, and provide a more intelligent and precise risk management tool for scenarios such as financial transactions. Attached Figure Description

[0018] Figure 1 This is a flowchart of an internet-based multi-signature electronic payment method according to the present invention.

[0019] Figure 2 This is a schematic diagram of a multi-signature electronic payment method and system based on the Internet according to the present invention.

[0020] Figure 3 This is another schematic diagram of a multi-signature electronic payment method and system based on the Internet according to the present invention.

[0021] Figure 4 This is a schematic diagram of the structure of an Internet-based multi-signature electronic payment system according to the present invention. Detailed Implementation

[0022] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0023] like Figure 1-4 This embodiment of a multi-signature electronic payment system based on the Internet may specifically include:

[0024] S101. Obtain historical signature data, use machine learning algorithms to analyze the statistical characteristics of signature behavior, obtain quantitative standards for judging signature anomalies, and determine the anomaly thresholds for signature duration, number of strokes, pressure changes, and timestamp features.

[0025] The system retrieves pre-stored historical user signature data and analyzes its statistical characteristics, including signature duration, number of strokes, pressure variation, and timestamp. A support vector machine (SVM) algorithm is used to establish a signature anomaly detection model. Through training, anomaly thresholds for each statistical characteristic are determined, resulting in a quantitative standard for signature anomaly detection. The system then retrieves the current user's signature data and determines whether the signature duration is less than a preset duration threshold; if so, it is considered an anomaly. It also determines whether the number of strokes in the signature data is less than a preset number of strokes threshold; if so, it is considered an anomaly. Finally, it determines whether the pressure variation in the signature data exceeds a preset normal pressure variation range; if so, it is considered an anomaly. If the interval between the timestamp of the data and the timestamp of the last signature is less than a preset time interval threshold, it is judged as a signature anomaly. The result of the anomaly judgment is input into a decision tree model for classification, and the authenticity of the signature data is determined based on the classification result. A convolutional neural network is used to extract features from the signature image of the signature data to obtain the depth features of the signature image. The depth features of the signature image are concatenated with the statistical features of the signature data to construct a signature authenticity discrimination model. The signature anomaly judgment threshold is dynamically adjusted based on the discrimination result of the signature authenticity discrimination model. A personal signature feature model is established for each user, and a personalized judgment threshold is set based on the user's personal signature habits when judging anomalies.

[0026] Specifically, firstly, pre-stored historical signature data of users is acquired, and statistical characteristics of signature behavior are analyzed. When a user signs using an electronic device, the system records various data during the signing process, such as the start time, end time, stroke coordinate sequence, and pressure changes of the strokes. By analyzing this data, the user's signature characteristics can be extracted. For example, a user's historical signature data shows that their signature duration is usually between 3 and 5 seconds, the average number of strokes is 12, and the pressure variation ranges from 500 to 1000. Simultaneously, the timestamp of each signature can be recorded for subsequent analysis of signature consistency. Next, a signature anomaly detection model is established using the support vector machine algorithm. In this scenario, signature data can be divided into two categories: normal signatures and abnormal signatures. Through training, the anomaly thresholds for each feature can be determined, obtaining a quantitative standard for signature anomaly detection. For example, based on the user's historical signature data, the thresholds for signature duration can be set to 2 seconds and 6 seconds; that is, if the signature duration is less than 2 seconds or greater than 6 seconds, the signature is considered abnormal. Similarly, the threshold for the number of strokes can be set to 8 or 16 strokes, and the threshold for the pressure variation range can be set to 300 to 1200. These thresholds need to be adjusted according to the actual situation to achieve the best judgment effect. After receiving the user's signature data, anomaly judgment is performed. First, it checks whether the signature duration is less than the preset duration threshold; if it is, the signature is judged as abnormal. For example, if the duration threshold is set to 2 seconds, and the user's signature duration is only 1.5 seconds, the signature is considered abnormal. This is because an excessively short signature duration may indicate that the user did not write carefully, suggesting the possibility of forgery. Then, it checks whether the number of strokes is less than the preset number of strokes threshold; if it is, the signature is judged as abnormal. For example, if the number of strokes threshold is set to 8 strokes, and the user's signature has only 5 strokes, the signature is considered abnormal. Too few strokes may indicate that the user did not write their signature completely. Next, it checks whether the pressure variation exceeds the preset normal pressure variation range; if it does, the signature is judged as abnormal. For example, if the pressure variation range is set to 500 to 1000, and the user's pressure variation exceeds this range during the signing process, the signature is considered abnormal. Abnormal pressure variation may indicate unnatural pauses or jitters during the signing process, which could be characteristics of a forged signature. Finally, it is determined whether the interval between the timestamp of the current signature and the timestamp of the previous signature is less than a preset time interval threshold. If it is less, the signature is judged as abnormal. For example, if the time interval threshold is set to 5 minutes, and the user makes two consecutive signatures within 2 minutes, the latter signature is considered abnormal. An excessively short time interval may indicate that the user has made multiple signature attempts in a short period of time, posing a risk of signature forgery. The results of the above anomaly judgments are input into a decision tree model for classification, and the authenticity of the signature is determined based on the classification results. Decision trees are a commonly used classification algorithm that achieves classification by constructing a series of judgment rules.In this scenario, anomaly detection results can be used as input features for the decision tree, such as whether the signature duration or the number of strokes is abnormal, with signature authenticity as the output category. Through training, the decision tree can learn how to determine the authenticity of a signature based on anomaly detection results. If it is determined to be a genuine signature, it is accepted; if it is determined to be a forged signature, it is rejected, and the anomalous feature information of the signature is recorded. For example, if the decision tree model detects anomalies in the duration and number of strokes of a signature, and the final classification result is a forged signature, the system will reject the signature and record the duration and number of strokes for subsequent analysis. To further improve the accuracy of signature authenticity detection, a convolutional neural network is used to extract features from the signature image, obtaining the deep features of the signature image. Convolutional neural networks are a deep learning algorithm that excels at processing image data. By performing convolution and pooling operations on the signature image, feature information in the image can be extracted, such as the shape, thickness, and tilt angle of the strokes. This feature information can reflect the user's signature habits and personalized characteristics. The image depth features are concatenated with the previously obtained statistical features of signature behavior to construct a signature authenticity discrimination model. For example, the feature vector extracted from the signature image through a convolutional neural network can be merged with statistical features such as signature duration and number of strokes to form a more comprehensive feature vector, which is then used to train the signature authenticity discrimination model. The advantage of this approach is that it combines image and behavioral information to more accurately reflect the user's signature characteristics. Based on the discrimination results of the signature authenticity discrimination model, the signature anomaly judgment threshold is dynamically adjusted. For example, after the system has been running for a period of time, if statistics show that a high proportion of genuine signatures are judged as anomalous, such as reaching 10%, this means that the current anomaly threshold is set too strictly, leading to some genuine signatures being misjudged. To improve the system's recall rate, i.e., its ability to identify more genuine signatures, the anomaly judgment threshold can be appropriately relaxed, such as adjusting the lower limit of signature duration from 2 seconds to 1.5 seconds. Conversely, if statistics show that a high proportion of forged signatures are judged as genuine, such as also reaching 10%, this indicates that the current anomaly threshold is set too leniently, causing some forged signatures to fail to be identified. To improve the system's accuracy in identifying forged signatures, the anomaly detection threshold can be tightened, for example, by adjusting the maximum signature duration from 6 seconds to 5.5 seconds. Dynamically adjusting the anomaly detection threshold allows the system to better adapt to changes in user signature habits and improves overall system performance. Furthermore, a personal signature feature model can be built for each user, statistically analyzing the normal distribution range of features such as signature duration, number of strokes, and pressure variations. When detecting anomalies, personalized thresholds can be set based on the user's individual signature habits. For example, for a user whose signature duration is typically between 4 and 5 seconds, setting a uniform threshold might not accurately identify anomalies.Therefore, a personalized signature duration threshold can be set for this user, such as 3.5 seconds or 5.5 seconds. The advantage of doing so is that it allows for more precise capture of subtle changes in the user's signature characteristics, improving the accuracy of signature anomaly detection.

[0027] S102. Based on the signature anomaly judgment quantification standard, obtain multi-dimensional features of signature trajectory, speed and timestamp, and use deep learning technology to comprehensively analyze the multi-dimensional features to obtain the anomaly signature recognition accuracy.

[0028] The process involves: acquiring signature time-series data, which includes at least signature coordinates and timestamps; extracting the signature trajectory and motion velocity from the time-series data; calculating the time interval and displacement between adjacent sampling points to obtain the velocity vector of each sampling point; obtaining the frequency domain features of the signature trajectory using discrete Fourier transform; analyzing the high-frequency and low-frequency components in the frequency domain features to calculate the ratio of high-frequency energy to low-frequency energy, using this as a signature smoothness feature, where a larger smoothness feature value indicates a smoother signature trajectory; calculating the curvature of the signature trajectory using a local polynomial fitting method based on the signature smoothness feature, obtaining curvature values ​​at each position of the signature, forming a curvature change sequence, where drastic curvature changes indicate a high degree of curvature in the signature trajectory; calculating the magnitude of each velocity vector as the velocity magnitude and the direction angle as the velocity direction, resulting in a velocity scalar sequence and a velocity direction sequence, reflecting the velocity changes during the signing process; and using a one-dimensional convolutional neural network to extract the signature trajectory features and velocity velocity. The process involves three steps: First, inputting the coordinate sequence, velocity scalar sequence, and velocity direction sequence into a one-dimensional convolutional layer. Local features are extracted through convolution operations, then compressed using a pooling layer. These features are flattened and concatenated to form a deep feature representation of the signature. This deep feature representation is then concatenated with the corresponding timestamp information to form a fused feature vector sequence. This fused feature vector sequence is input into a Long Short-Term Memory (LSTM) recurrent neural network (RNN), which learns the temporal dependencies of the feature sequences. A fully connected layer and a Softmax layer are then connected to the output of the last time step of the RNN to classify the authenticity of the signature. The RNN is trained using real signature data and various forged signature data, with network parameters continuously adjusted to improve classification performance. During the testing phase, the abnormal probability of the signature to be verified is calculated based on the trained model parameters. If the abnormal probability exceeds a preset threshold, the signature is determined to be abnormal; otherwise, it is determined to be a genuine signature.

[0029] Specifically, when acquiring signature timing data on a touch device, it's crucial to ensure the device possesses high-precision touch sensing capabilities, enabling accurate recording of coordinates and timestamps during the signing process. For instance, assuming a touch device has a sampling frequency of 100Hz, recording coordinate points every 0.01 seconds, sufficient data points can be captured during the signing process for subsequent analysis. Extracting the signature trajectory and motion velocity from the timing data can be achieved by calculating the displacement and time interval between adjacent sampling points. For example, assuming two adjacent sampling points A and B, where A's coordinates are (x1, y1) and timestamp t1, and B's coordinates are (x2, y2) and timestamp t2, the displacement Δs can be calculated using the Euclidean distance formula, and the time interval Δt is t2-t1. The velocity vector v = Δs / Δt, where the magnitude is the velocity and the direction angle is the velocity direction. When using the Discrete Fourier Transform (DFT) to obtain the frequency domain features of the signature, the coordinate sequence of the signature trajectory can be converted into a frequency domain signal. For example, assuming a signature trajectory consists of N coordinate points, N frequency components can be obtained through DFT. High-frequency components reflect the detailed changes in the signature trajectory, while low-frequency components reflect the overall trend. The ratio of high-frequency energy to low-frequency energy can be used as a signature smoothness feature. If the smoothness feature value of a signature is 0.8, it indicates a relatively smooth trajectory; while another signature has a smoothness feature value of 1.5, it indicates a relatively coarse trajectory. When calculating the curvature of the signature trajectory using the local polynomial fitting method, a sub-trajectory containing k sampling points can be selected. This sub-trajectory can be fitted using a polynomial, and its curvature value can be calculated. For example, choosing k=5, a polynomial function can be obtained through fitting, and the curvature of each sampling point can be calculated, forming a curvature change sequence. If the curvature of a certain trajectory changes drastically, it indicates a large degree of curvature in that segment of the signature trajectory, which may reflect the signer's specific writing habits. For movement speed, the magnitude and direction angle of each velocity vector are calculated, forming a velocity scalar sequence and a velocity direction sequence. For example, suppose the velocity scalar sequence during a signature process is [1.2, 1.5, 1.3] and the velocity direction sequence is [30°, 45°, 40°]. These sequences reflect the changes in velocity during the signature process, helping to distinguish between genuine and forged signatures. When using a one-dimensional convolutional neural network (1D-CNN) to extract signature trajectory and velocity features, the coordinate sequence, velocity scalar sequence, and velocity direction sequence can be input into the convolutional layers of the 1D-CNN, respectively. For example, assuming a kernel size of 3, local features are extracted through convolution operations, then compressed through pooling layers, and finally flattened and concatenated to form a deep feature representation of the signature. This deep feature representation of the signature is then concatenated with the corresponding timestamp information to form a fused feature vector sequence.For example, assuming the deep feature representation is [0.2, 0.5, 0.3] and the timestamp information is [0.01, 0.02, 0.03], the two are concatenated to form a fused feature vector sequence [0.2, 0.5, 0.3, 0.01, 0.02, 0.03]. This sequence is input into a Long Short-Term Memory Recurrent Neural Network (LSTM), and the LSTM units learn the temporal dependencies of the feature sequence. For example, assuming the LSTM network has 128 units, with the fused feature vector as the input at each time step, the LSTM units can capture the temporal information in the feature sequence. Finally, a fully connected layer and a Softmax layer are connected to the output of the last time step to classify the authenticity of the signature. During the model training phase, real signature data and various forged signature data are used for training, and the network parameters are continuously adjusted. For example, assuming the training set contains 1000 real signatures and 1000 forged signatures, the model's classification performance gradually improves through multiple iterations of optimization. During the testing phase, the anomaly probability of the signature to be verified is calculated based on the trained model parameters. For example, assuming the probability of an anomaly in a signature to be verified is 0.07, if it exceeds a pre-set threshold of 0.05, it is determined to be an anomaly signature; otherwise, it is a genuine signature. Through the above steps, a deep learning-based signature verification model is constructed by comprehensively utilizing signature trajectory features, speed features, and temporal information. This model can effectively distinguish between genuine and anomaly signatures, improving the accuracy and reliability of signature verification. For example, in practical applications, this model can increase the accuracy of signature verification from 80% to 95%, significantly reducing the risk of forged signatures. In specific implementations, personalized signature feature models can also be established based on users' individual signature habits. For example, by statistically analyzing the normal distribution range of a user's signature duration, number of strokes, pressure variations, and other features, personalized judgment thresholds can be set in conjunction with these personalized features during anomaly detection, further improving the accuracy of signature anomaly detection. For example, if a user's normal signature duration is between 2 and 3 seconds, and a signature lasts only 1 second, it can be immediately determined to be an anomaly signature. By dynamically adjusting the signature anomaly judgment threshold, the flexibility and adaptability of the model can be further improved. For example, by statistically analyzing the proportion of genuine signatures identified as anomalous within a certain timeframe, and if this proportion is high, the anomalous signature threshold can be appropriately relaxed; conversely, by statistically analyzing the proportion of forged signatures identified as genuine signatures, and if this proportion is high, the anomalous signature threshold can be appropriately tightened. This approach can improve the recall rate of signature anomaly detection while maintaining accuracy. In conclusion, by employing multi-layered feature extraction and deep learning models, combined with personalized signature features and dynamic threshold adjustments, an efficient and accurate signature verification system can be constructed, effectively preventing the risk of forged signatures.

[0030] S103. Based on the accuracy of abnormal signature recognition, establish a signature behavior risk assessment model, quantify the degree of risk of signature behavior, and obtain the basis for signature intervention strategy decision-making.

[0031] A pre-established abnormal signature feature library is obtained, containing multiple abnormal signature features; a signature image to be identified is obtained; a pattern matching algorithm is used to match the signature image to be identified with the abnormal signature features in the abnormal signature feature library to obtain an abnormal signature identification result; based on the abnormal signature identification result, a confusion matrix is ​​used to calculate the accuracy, precision, and recall of the abnormal signature identification to obtain an identification accuracy value; using the identification accuracy value as a feature, a support vector machine algorithm is used to construct a signature behavior risk assessment model to obtain signature behavior risk assessment model parameters; based on the signature behavior risk assessment model parameters, a weighted average method is used to calculate the signature behavior... The risk level is determined numerically. Based on this numerical value, a signature intervention strategy decision tree is generated using the CART decision tree algorithm to obtain the basis for intervention strategy decisions. It is then determined whether the risk level of the signature behavior exceeds a preset threshold; if so, a signature intervention strategy is triggered. Based on the intervention strategy decision basis, signature intervention measures are determined. According to the signature intervention measures, the user is guided to adjust their signature behavior through a graphical user interface. The adjusted signature is obtained, and its risk level is calculated. It is then determined whether the risk level of the adjusted signature is lower than a preset risk threshold; if so, the signature intervention process ends; otherwise, the process returns to the signature behavior adjustment step until the risk is reduced to an acceptable level.

[0032] Specifically, based on a pre-established abnormal signature feature library, a pattern matching algorithm is used to identify abnormal signatures in the signature image, obtaining the abnormal signature identification result. For example, suppose the feature library contains common forged signature features, such as disjointed strokes, sudden speed changes, and abnormal pressure distribution. When a user signs on a touch device, the system captures the signature image data in real time and extracts the corresponding features. The pattern matching algorithm compares these features with the abnormal features in the feature library. If the user's signature features are found to highly match a certain type of abnormal feature in the feature library, such as a sudden increase in the speed of a stroke or an abnormally concentrated pressure distribution, the system determines that the signature is abnormal. Based on the abnormal signature identification result, a confusion matrix is ​​used to calculate the accuracy, precision, and recall of the abnormal signature identification, obtaining the identification accuracy value. For example, suppose in a test, the system identifies 100 signature samples, of which 80 are genuine signatures and 20 are forged signatures. The confusion matrix shows that the system correctly identified 75 genuine signatures, correctly identified 15 forged signatures, misidentified 5 genuine signatures as forged signatures, and misidentified 5 forged signatures as genuine signatures. Based on this data, the accuracy can be calculated as (75+15) / 100=0.9, the precision as (15 / (15+5)=0.75), and the recall as (15 / 20=0.75). The final recognition accuracy is 0.9. Using the recognition accuracy as a feature, a support vector machine (SVM) algorithm is used to construct a signature behavior risk assessment model, obtaining the model parameters. For example, assuming that in addition to accuracy, other features such as signature duration and number of strokes are considered, these features are used as input and trained using the SVM algorithm to obtain the model parameters. Assuming the model parameters are a weight vector W and a bias b, these parameters are continuously optimized through training data, enabling the model to better predict the risk of signature behavior. Based on the risk assessment model parameters, a weighted average method is used to calculate the risk level of the signature behavior, obtaining the risk level value. For example, assuming that the feature vector of a certain signature includes an accuracy of 0.9, a duration of 2.5 seconds, and a number of strokes of 15, a weighted average risk value is calculated based on the model parameters. Assuming the weight vector W is [0.6, 0.3, 0.1] and the bias b is -1, the risk level value is 0.6*0.9 + 0.3*2.5 + 0.1*15 - 1 = 0.54 + 0.75 + 1.5 - 1 = 1.79. Based on the risk level value, the CART decision tree algorithm is used to generate a signature intervention strategy decision tree, thus obtaining the basis for intervention strategy decisions. For example, assuming the node splitting of the decision tree is based on the risk level value, with a threshold set to 1.5, if the risk level value is greater than 1.5, it is determined to be high risk, requiring intervention measures; if it is less than 1.5, it is determined to be low risk, requiring no intervention. The decision tree generated by the CART algorithm can clearly define the intervention strategy under different risk levels.If the risk level of a signature exceeds a preset threshold, a signature intervention strategy is triggered, and intervention measures are determined based on the decision criteria. For example, assuming the preset threshold is 1.5, and the risk level of a certain signature is 1.79, exceeding the threshold, the system triggers an intervention strategy. Based on the decision tree, specific intervention measures are determined, such as prompting the user to re-sign or providing a signature example. According to the signature intervention measures, the system guides the user to adjust their signature behavior through a graphical user interface to reduce the risk. For example, the system displays the user's abnormal signature and prompts "Uneven signing speed, please refer to the example for adjustment." Simultaneously, the interface displays a standard signature example for the user to refer to for adjustment. The user re-signs through the interface, and the system evaluates the risk of the adjusted signature in real time until the risk is reduced to an acceptable level. This not only effectively identifies and prevents forged signatures but also improves the authenticity and reliability of signatures by guiding users to adjust their signature behavior. Through multi-level feature extraction and risk assessment, combined with dynamic intervention strategies, the system can flexibly respond to different situations, significantly improving the accuracy of signature verification and the standardization of user signatures.

[0033] S104. Obtain the signature timestamps of each participant from the Internet in real time, and determine whether the difference between the signature timestamps exceeds a preset threshold based on the abnormal thresholds of the signature duration, number of strokes, pressure changes and timestamp characteristics and the signature behavior risk assessment model.

[0034] The process involves acquiring signature data from multiple participants, including signature duration, number of strokes, pressure variation, and timestamp features. The signature data is preprocessed to remove noise and outliers, and key features are extracted. A support vector machine (SVM) algorithm is used to construct a signature behavior risk assessment model, which is then trained and optimized using historical signature data. The preprocessed signature feature data is input into the model to obtain an anomaly score for each feature. The anomaly score for each feature is compared to a preset anomaly threshold; features exceeding the threshold are marked as anomalous. Based on the proportion of anomalous features to the total number of features, the signature behavior risk level is determined to be low, medium, or high. Timestamp information from the signature data is extracted, and the time difference between adjacent signature timestamps is calculated. This time difference is compared to a preset reasonable time threshold; time differences exceeding the threshold are marked as anomalous. Weights are assigned to the signature behavior risk level and the time difference anomaly, and a weighted average is used to obtain a first comprehensive risk score for the signature. Finally, the first comprehensive risk score is compared to a preset risk level threshold.

[0035] Specifically, signature data from all participants is acquired in real time via the internet, including features such as signature duration, number of strokes, pressure changes, and timestamps. For example, when a user uses the electronic signature system, the system records their signature process, capturing a signature duration of 3.2 seconds, 12 strokes, a pressure change range of 0.2 to 0.8 Newtons, and a timestamp of 2023-10-01 14:30:00. This data is transmitted to the backend server in real time for further analysis. The acquired signature data is preprocessed to remove noise and outliers and extract key features. For example, during preprocessing, the system detects abrupt peaks in the pressure change data of a certain signature, which may be caused by equipment failure or external interference. A smoothing filter algorithm is used to remove these outliers, ensuring data accuracy. Key features extracted include average signature speed, pressure distribution uniformity, and stroke continuity. A signature behavior risk assessment model is constructed using the Support Vector Machine (SVM) algorithm and trained and optimized using historical signature data. Suppose the system collects 1000 historical signature samples, of which 500 are genuine signatures and 500 are forged signatures. Through feature extraction, these samples are transformed into multi-dimensional feature vectors, which are then input into an SVM model for training. The SVM effectively distinguishes between genuine and forged signatures by finding the optimal hyperplane, forming a risk assessment model. The preprocessed signature feature data is input into the trained SVM model, and an anomaly score is calculated for each feature. For example, the feature vector of a certain signature might include average speed (0.8 m / s), pressure distribution uniformity (0.7), and stroke continuity (0.9). These features are input into the SVM model, and the model calculates the anomaly score for each feature based on the weights and biases obtained during training, such as a speed anomaly score of 0.2, a pressure distribution anomaly score of 0.1, and a stroke continuity anomaly score of 0.05. The anomaly score for each feature is compared with a preset anomaly threshold; features exceeding the threshold are marked as anomalous features. Assuming a preset anomaly threshold of 0.15, a speed anomaly score of 0.2 would be marked as an anomalous feature, while pressure distribution and stroke continuity scores, not exceeding the threshold, would be considered normal features. The number of anomalous features is counted, and the signature behavior risk level is categorized into low, medium, and high based on the proportion of anomalous features to the total number of features. For example, a signature might have 10 features, with 2 marked as anomalous, representing 20% ​​of the total. According to the preset classification criteria, a 20% anomalous proportion corresponds to a medium risk level. The timestamp information of the signature is extracted, and the time difference between adjacent signature timestamps is calculated. For example, a user might sign twice, at 14:30:00 and 14:35:00, with a time difference of 5 minutes. This time difference is compared to a preset reasonable time threshold; differences exceeding the threshold are marked as anomalous. Assuming a preset reasonable time threshold of 10 minutes, a 5-minute time difference is considered normal, while a difference exceeding 10 minutes is marked as anomalous.Different weights are assigned to the risk level of signature actions and the anomaly of time difference, and a first comprehensive risk score for the signature is calculated using a weighted average. For example, assuming the weight of risk level is 0.7 and the weight of time difference anomaly is 0.3, if a signature has a medium risk level (score 0.5) and a normal time difference (score 0), then the first comprehensive risk score is 0.7*0.5 + 0.3*0 = 0.35. The first comprehensive risk score is compared with a preset risk level threshold to determine the validity and risk level of the signature, serving as the basis for subsequent signature verification and business review. Assuming the preset risk level threshold is 0.4, if the first comprehensive risk score of 0.35 is below the threshold, the system determines that the signature is valid and has a low risk, allowing the business process to continue; if the score is above the threshold, it indicates a high risk, requiring further review or intervention. In this way, the system can monitor and analyze signature actions in real time, promptly detect anomalies, and improve the accuracy of signature verification and business security.

[0036] S105. If the difference between the signature timestamps exceeds a preset threshold, a signature delay abnormality warning is triggered, and signature intervention measures are initiated.

[0037] The system retrieves the current signature timestamp and the previous signature timestamp, calculates the difference between them to obtain a signature timestamp difference value, and determines whether the difference value exceeds a preset threshold. If the difference value exceeds the preset threshold, a signature delay anomaly warning is triggered. According to pre-configured rules, signature intervention measures are initiated, including adjusting the priority of signature requests, increasing resource allocation to the signature server, and batch processing of signature requests. Historical signature data is retrieved, and a support vector machine algorithm is used to train the historical signature data to establish a classification model for signature delay anomalies. The current signature request data is input into the classification model to determine whether the current signature request belongs to a delay anomaly. Based on the classification results, the signature intervention measures are dynamically adjusted to optimize signature efficiency. Historical data on signature delay anomalies is retrieved, and a decision tree algorithm is used to analyze the historical data to obtain the key factors causing signature delay anomalies. Based on the key factors, the signature process is optimized, the deployment architecture of the signature system is adjusted, and the fault tolerance and scalability of the signature system are improved.

[0038] Specifically, obtaining the current signature timestamp and the previous signature timestamp, and calculating the difference between the two timestamps, is a fundamental step in signature behavior monitoring. For example, if a user completes a signature at 14:30:00 and then performs another signature at 14:35:00, the timestamp difference is 5 minutes. The purpose of this step is to capture the time interval of signature actions to determine if there is any abnormal delay. Comparing the signature timestamp difference with a preset threshold is a crucial step in determining signature delay anomalies. Assuming the system's preset reasonable time threshold is 10 minutes, a 5-minute time difference is within the normal range and will not trigger an anomaly warning. However, if the time difference is 15 minutes, exceeding the preset threshold, the system will determine that the current signature has experienced an abnormal delay and automatically trigger a signature delay anomaly warning. When the system triggers a signature delay anomaly warning, it automatically initiates corresponding signature intervention measures according to pre-configured rules. For example, the system can adjust the priority of signature requests, elevating delayed signature requests to high priority to ensure they are processed quickly. In addition, the system can increase the resource allocation of the signature server, such as temporarily increasing CPU and memory resources, to improve the speed of signature processing. For batch signature requests, the system can employ parallel processing to reduce the processing time of individual requests. While implementing signature intervention measures, a Support Vector Machine (SVM) algorithm is used to analyze signature latency anomalies in real time. The SVM algorithm is trained on historical signature data to build a classification model for signature latency anomalies. Assume the system has collected 1000 historical signature samples, of which 500 are normal signatures and 500 are delayed signatures. Through feature extraction, these samples are transformed into multi-dimensional feature vectors, which are then input into the SVM model for training. The SVM finds the optimal hyperplane to effectively distinguish between normal and delayed signatures, forming a classification model. Current signature request data is used as input; after classification by the SVM model, it can determine in real time whether a signature request belongs to a latency anomaly. For example, the feature vector of a signature might include parameters such as request time, server load, and network latency. After being input into the SVM model, the model determines whether the signature request belongs to a latency anomaly based on the weights and biases obtained during training. Based on the classification results, the system can dynamically adjust signature intervention measures, such as further optimizing resource allocation or adjusting the processing order of signature requests. Real-time analysis based on the SVM algorithm automatically adjusts relevant parameters in the signature process, which is an important means of optimizing signature efficiency. For example, the system can dynamically adjust the timeout for signature requests from the default 30 seconds to 20 seconds based on real-time analysis results to speed up signature processing. Simultaneously, the system can also adjust the caching time for signature results, extending it from 5 minutes to 10 minutes to reduce the processing time for duplicate signatures. Furthermore, the system can limit the number of concurrent signature requests to avoid latency caused by server overload.Analyzing historical data on signature delay anomalies using decision tree algorithms is an effective method for uncovering key factors causing these anomalies. Decision tree algorithms recursively segment the dataset to identify the main factors influencing signature delays. For example, the system analysis revealed that poor network conditions are one of the primary causes of signature delays, followed by excessive server load and overly complex signature keys. Based on these key factors, the system can optimize the signature process, such as enabling backup network channels when network conditions are poor or automatically scaling up when server load is high. Adjusting the deployment architecture of the signature system is crucial for improving system fault tolerance and scalability. For example, the system can adopt a distributed architecture, distributing signature requests across multiple servers to avoid delays caused by single points of failure. Simultaneously, the system can introduce load balancing mechanisms to ensure balanced load across servers and improve overall processing efficiency. Through these multi-layered and multi-dimensional analysis and optimization measures, the system can effectively mitigate signature delay anomalies and ensure timely signature completion. Real-time monitoring and dynamic adjustment of signature parameters not only improve signature efficiency but also enhance the system's intelligence and reliability, providing solid data support for business decisions. Fundamentally preventing signature delays and ensuring their reliability and timeliness is crucial for smooth business processes. For example, in practical applications, a financial institution's electronic signature system successfully reduced the signature latency rate from 5% to 1% using the methods described above, significantly improving customer experience and business efficiency. Through real-time analysis and dynamic adjustments, the system can automatically increase server resources during peak periods, ensuring rapid response to signature requests and preventing business interruptions due to delays. As another example, during a promotional event on an e-commerce platform, a surge in signature requests was identified by the system using a decision tree algorithm as the primary cause of latency. The system immediately initiated a capacity expansion mechanism, increasing server resources and adjusting the priority of signature requests to ensure that signature requests for important orders were processed first, effectively preventing signature delays and ensuring the smooth operation of the promotional event.

[0039] S106. Based on factors such as transaction amount, user credit score, and transaction frequency, comprehensively assess the payment risk level, adopt an adaptive signature intervention strategy, and automatically adjust the intervention frequency and intensity according to the importance of different factors through a dynamic weight allocation mechanism.

[0040] The system acquires transaction data, including transaction amount, user credit score, and transaction frequency; calculates a second comprehensive risk score using a weighted average model with preset initial weight values; maps the second comprehensive risk score to corresponding risk levels (low, medium, and high) based on preset risk level thresholds; acquires a pre-configured signature intervention strategy library and selects appropriate intervention strategies from the library according to the risk level; calculates the weight coefficients of each risk factor using a linear regression model, the training data of which includes historical transaction data and their corresponding risk labels; updates the weight values ​​in the weighted average model using the risk factor weight coefficients; and acquires new transaction data in real time, extracting transaction amount, user credit score, and transaction frequency. Frequency, input the updated weighted average model, calculate the second comprehensive risk score of the current transaction; for the second comprehensive risk score of the current transaction, compare it with the adjusted risk level threshold to determine the risk level of the current transaction; determine the signature intervention probability and intervention intensity range based on the risk level of the current transaction, the intervention intensity range determines the signature complexity; if signature intervention is required, generate a random number between 0 and 1, if the random number is less than the signature intervention probability, trigger the signature process; adjust the signature complexity according to the intervention intensity range; continuously collect transaction data over a period of time, and statistically analyze the number of transactions at each risk level and the occurrence rate of risk events; use the rule engine to analyze the statistical data, and dynamically adjust the risk level threshold and signature intervention strategy parameters based on the analysis results.

[0041] Specifically, obtaining transaction amount, user credit score, and transaction frequency data is the first step in risk management. For example, when processing a transaction, an e-commerce platform first extracts the transaction amount as 5,000 yuan, the user's credit score as 85, and the transaction frequency as 10 times in the past month. This data forms the basis for subsequent risk assessment. Using pre-set initial weight values, a second comprehensive risk score is calculated through a weighted average model. Assuming the initial weights are: transaction amount weight 0.4, user credit score weight 0.3, and transaction frequency weight 0.3, then the second comprehensive risk score = 0.4 * 5000 + 0.3 * 85 + 0.3 * 10 = 2000 + 25.5 + 3 = 2028.5. This score reflects the overall risk level of the current transaction. Based on pre-set risk level thresholds, the second comprehensive risk score is mapped to the corresponding risk level. Assuming the risk level thresholds are: low risk (0-1000), medium risk (1001-2000), and high risk (2001 and above). The current transaction's second comprehensive risk score is 2028.5, classifying it as high-risk. The system retrieves a pre-configured signature intervention strategy library and selects the appropriate intervention strategy based on the transaction's risk level. This library contains signature intervention strategies of varying complexity, such as SMS verification codes, fingerprint recognition, and facial recognition. For high-risk transactions, the system selects the most complex signature method—a composite signature combining facial recognition and digital certificates—to ensure transaction security. A linear regression model is used to calculate the weights of risk factors. The training data for this model includes historical transaction data and their corresponding risk labels. Assuming the system has collected 1000 historical transaction records, each including transaction amount, user credit score, transaction frequency, and corresponding risk label (low, medium, high), the system derives new weight coefficients through linear regression model training: transaction amount weight 0.5, user credit score weight 0.2, and transaction frequency weight 0.3. The calculated risk factor weights are then used to update the weights in the weighted average model. The new second comprehensive risk score = 0.5*5000 + 0.2*85 + 0.3*10 = 2500 + 17 + 3 = 2520. The updated risk factor weights make the calculation of the second comprehensive risk score more accurate, reflecting the latest risk trends. New transaction data is acquired in real time, extracting transaction amount, user credit score, and transaction frequency. For example, the system monitors a new transaction in real time with an amount of 3000 yuan, a user credit score of 90, and a transaction frequency of 5 times. These data are input into a weighted average model with updated weights to calculate the second comprehensive risk score for the current transaction: 0.5*3000 + 0.2*90 + 0.3*5 = 1500 + 18 + 1.5 = 1519.5. Based on the second comprehensive risk score of the current transaction, the adjusted risk level threshold is used to determine the risk level of the current transaction.Assuming the adjusted risk level thresholds are: low risk (0-1500), medium risk (1501-2500), and high risk (2501 and above), the current transaction's second comprehensive risk score is 1519.5, falling into the medium risk category. The signature intervention probability and intensity range are determined based on the current risk level. For example, the signature intervention probability for a medium-risk transaction is 30%, and the intervention intensity range is 1-5. The intervention intensity range determines the signature complexity; if the pre-set intensity is 3, a fingerprint recognition plus SMS verification code signature method is used. If signature intervention is required, a random number between 0 and 1 is generated. For example, if the system generates a random number of 0.25, which is less than the signature intervention probability of 30%, the signature process is triggered. The signature complexity is adjusted according to the preset intervention intensity range, and a fingerprint recognition plus SMS verification code signature method is used. Transaction data is continuously collected over a period of time, and the number of transactions at each risk level and the occurrence rate of risk events are statistically analyzed. For example, the system analyzed 10,000 transactions within a month, including 6,000 low-risk transactions, 3,000 medium-risk transactions, and 1,000 high-risk transactions. The risk event occurrence rates were: low risk 1%, medium risk 5%, and high risk 10%. The system uses a rules engine to analyze the statistical data. Based on the analysis results, it dynamically adjusts the risk level thresholds and signature intervention strategy parameters. For instance, if the occurrence rate of high-risk events exceeds a preset threshold of 8%, the risk level thresholds are adjusted so that more transactions are assessed as high-risk. The new risk level thresholds might become: low risk (0-1200), medium risk (1201-2200), and high risk (2201 and above). Through this dynamic adjustment mechanism, the system can more accurately identify high-risk transactions and take timely signature intervention measures, thereby effectively reducing the probability of risk events and ensuring the security and reliability of transactions. This method not only improves the efficiency of risk management but also enhances the system's intelligence and adaptability, providing solid data support for business decisions.

[0042] It will be apparent to those skilled in the art that this application is not limited to the details of the exemplary embodiments described above, and that this application can be implemented in other specific forms without departing from the spirit or essential characteristics of this application. Therefore, the embodiments should be considered illustrative and non-limiting in all respects, and the scope of this application is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within this application. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A multi-signature electronic payment method based on the Internet, characterized in that, The method includes: Historical signature data is obtained, and machine learning algorithms are used to analyze the statistical characteristics of signature behavior to obtain quantitative standards for judging signature anomalies and determine the anomaly thresholds for signature duration, number of strokes, pressure changes, and timestamp features. Based on the aforementioned signature anomaly judgment quantification standard, multi-dimensional features of signature trajectory, speed, and timestamp are obtained. Deep learning technology is used to comprehensively analyze these multi-dimensional features to obtain the anomaly signature recognition accuracy. This also includes: Obtain signature timing data, wherein the timing data includes at least signature coordinates and timestamps; Extract the signature trajectory and motion speed from the time-series data; Calculate the time interval and displacement between adjacent sampling points to obtain the velocity vector of the sampling points; For the signature trajectory, the frequency domain features of the signature are obtained using the Discrete Fourier Transform. By analyzing the high-frequency and low-frequency components in the frequency domain features, the ratio of high-frequency energy to low-frequency energy is calculated and used as the signature smoothness feature. The larger the smoothness feature value, the smoother the signature trajectory. Based on the signature smoothness characteristics, the curvature of the signature trajectory is calculated using a local polynomial fitting method to obtain the curvature values ​​at each position of the signature, forming a curvature change sequence. The dramatic curvature changes indicate that the signature trajectory is highly curved. For the aforementioned motion speed, the magnitude of each velocity vector is calculated as the velocity magnitude, and the direction angle is calculated as the velocity direction, resulting in a velocity scalar sequence and a velocity direction sequence, reflecting the changes in velocity during the signature process; The signature trajectory features and velocity features are extracted using a one-dimensional convolutional neural network, respectively. The coordinate sequence, velocity scalar sequence, and velocity direction sequence are respectively input into a one-dimensional convolutional layer. Local features are extracted through convolution operations, and then the features are compressed through a pooling layer. The features are flattened and concatenated to form a deep feature representation of the signature. The deep feature representation of the signature is concatenated with the corresponding timestamp information to form a fused feature vector sequence; The fused feature vector sequence is input into a long short-term memory recurrent neural network, and the temporal dependencies of the feature sequence are learned through the long short-term memory recurrent neural network. The output of the last time step of the long short-term memory recurrent neural network is connected to a fully connected layer and a softmax layer to classify and judge the authenticity of the signature. The long short-term memory recurrent neural network is trained using real signature data and various forged signature data, and the network parameters are continuously adjusted to improve the classification performance of the model. Calculate the anomaly probability of the signature to be verified based on the model parameters obtained from training. If the anomaly probability exceeds a preset threshold, it is determined to be an abnormal signature; otherwise, it is determined to be a genuine signature. Based on the accuracy of abnormal signature identification, a signature behavior risk assessment model is established to quantify the degree of risk of signature behavior and obtain the basis for signature intervention strategy decision-making. The signature timestamps of each participant are obtained in real time from the Internet. Based on the abnormal thresholds of the signature duration, number of strokes, pressure changes and timestamp characteristics, and the signature behavior risk assessment model, it is determined whether the difference between the signature timestamps exceeds a preset threshold. If the difference between the signature timestamps exceeds a preset threshold, a signature delay abnormality warning is triggered, and signature intervention measures are initiated. Based on factors such as transaction amount, user credit score, and transaction frequency, the payment risk level is comprehensively assessed, and an adaptive signature intervention strategy is adopted. Through a dynamic weight allocation mechanism, the frequency and intensity of intervention are automatically adjusted according to the importance of different factors.

2. The method according to claim 1, characterized in that, The process of acquiring historical signature data, analyzing the statistical characteristics of signature behavior using machine learning algorithms, obtaining quantitative standards for signature anomaly judgment, and determining anomaly thresholds for signature duration, number of strokes, pressure changes, and timestamp features includes: Obtain pre-stored user historical signature data and analyze the statistical characteristics of the signature data, including signature duration, number of strokes, pressure variation, and timestamp; A signature anomaly detection model is established using the support vector machine algorithm. The anomaly thresholds of each statistical feature are determined through training, and a quantitative standard for signature anomaly detection is obtained. Obtain the signature data of the current user, and determine whether the signature duration of the signature data is less than a preset duration threshold. If it is less than the threshold, the signature is considered abnormal. Determine whether the number of strokes in the signature data is less than a preset stroke count threshold; if it is less, the signature is considered abnormal. Determine whether the pressure change of the signature data exceeds the preset normal pressure change range; if it does, it is determined to be a signature abnormality. Determine whether the interval between the timestamp of the signature data and the timestamp of the previous signature is less than a preset time interval threshold; if it is less than, the signature is judged to be abnormal. The result of the anomaly detection is input into a decision tree model for classification, and the authenticity of the signature data is determined based on the classification result. A convolutional neural network is used to extract features from the signature image of the signature data to obtain the depth features of the signature image; The depth features of the signature image are concatenated with the statistical features of the signature data to construct a signature authenticity discrimination model; Based on the discrimination results of the signature authenticity discrimination model, the signature anomaly judgment threshold is dynamically adjusted; A personal signature feature model is established for each user, and personalized judgment thresholds are set based on the user's personal signature habits when judging anomalies.

3. The method according to claim 1, characterized in that, The step involves establishing a signature behavior risk assessment model based on the accuracy of abnormal signature identification, quantifying the degree of signature behavior risk, and obtaining the basis for signature intervention strategy decisions, including: Obtain a pre-established abnormal signature feature library, which contains multiple abnormal signature features; Obtain the signature image to be identified; A pattern matching algorithm is used to match the signature image to be identified with the abnormal signature features in the abnormal signature feature library to obtain the abnormal signature identification result. Based on the abnormal signature recognition results, the accuracy, precision, and recall of abnormal signature recognition are calculated using a confusion matrix to obtain the recognition accuracy value. Using the recognition accuracy value as a feature, a signature behavior risk assessment model is constructed using the support vector machine algorithm, and the parameters of the signature behavior risk assessment model are obtained. Based on the parameters of the signature behavior risk assessment model, the weighted average method is used to calculate the risk level of the signature behavior and obtain the risk level value. Based on the risk level value, the CART decision tree algorithm is used to generate a signature intervention strategy decision tree to obtain the basis for intervention strategy decision; Determine whether the risk level of the signature behavior exceeds a preset threshold; if so, trigger a signature intervention strategy. Based on the aforementioned decision-making criteria for the intervention strategy, determine the signature-based intervention measures; Based on the aforementioned signature intervention measures, users are guided to adjust their signature behavior through a graphical user interface; Obtain the user's adjusted signature and calculate the risk level of the adjusted signature; Determine whether the risk level of the adjusted signature is lower than the preset risk threshold. If so, end the signature intervention process; otherwise, return to the signature behavior adjustment step until the risk is reduced to an acceptable level.

4. The method according to claim 1, characterized in that, The process of obtaining signature timestamps from each participant in real time via the internet, and determining whether the differences between the signature timestamps exceed a preset threshold based on the abnormal thresholds of signature duration, number of strokes, pressure changes, and timestamp characteristics, and the signature behavior risk assessment model, includes: Obtain signature data from multiple participants, including signature duration, number of strokes, pressure variation, and timestamp features; The signature data is preprocessed to remove noise and outliers and extract key features; A signature behavior risk assessment model is constructed using the support vector machine algorithm and trained and optimized using historical signature data; The preprocessed signature feature data is input into the signature behavior risk assessment model to obtain an anomaly score for each feature; The abnormality score of each feature is compared with a preset abnormality threshold, and features that exceed the threshold are marked as abnormal features. Based on the proportion of abnormal features to the total number of features, the risk level of the signature behavior is determined to be one of the three levels: low, medium, and high. Extract the timestamp information from the signature data and calculate the time difference between adjacent signature timestamps; The time difference is compared with a preset reasonable time threshold, and time differences exceeding the threshold are marked as abnormal. The risk level and time difference anomalies of the signature behavior are assigned weights respectively, and the first comprehensive risk score of the signature is obtained by weighted averaging. The first comprehensive risk score is compared with the preset risk level threshold.

5. The method according to claim 1, characterized in that, If the difference between the signature timestamps exceeds a preset threshold, a signature delay anomaly warning is triggered, and signature intervention measures are initiated, including: Obtain the current signature timestamp and the previous signature timestamp, calculate the difference between the current signature timestamp and the previous signature timestamp, and obtain the signature timestamp difference value; Determine whether the difference in the signature timestamp exceeds a preset threshold; If the signature timestamp difference exceeds the preset threshold, a signature delay abnormality warning is triggered; According to pre-configured rules, signature intervention measures are initiated, including adjusting the priority of signature requests, increasing the resource allocation of the signature server, and batch processing of signature requests; Historical signature data is obtained, and a support vector machine algorithm is used to train the historical signature data to establish a classification model for signature delay anomalies. Input the current signature request data into the classification model to determine whether the current signature request belongs to a delay anomaly. Based on the classification results, the signature intervention measures are dynamically adjusted to optimize signature efficiency; Historical data on signature delay anomalies is obtained, and the historical data is analyzed using a decision tree algorithm to identify the key factors causing signature delay anomalies. Based on the aforementioned key factors, optimize the signature process, adjust the deployment architecture of the signature system, and improve the fault tolerance and scalability of the signature system.

6. The method according to claim 1, characterized in that, The system comprehensively assesses payment risk levels based on transaction amount, user credit score, and transaction frequency. It employs an adaptive signature intervention strategy, which automatically adjusts the intervention frequency and intensity according to the importance of different factors through a dynamic weighting mechanism. This includes: Acquire transaction data, including transaction amount, user credit score, and transaction frequency; The second comprehensive risk score is calculated using a weighted average model with preset initial weight values. Based on a preset risk level threshold, the second comprehensive risk score is mapped to a corresponding risk level, which includes low risk, medium risk, and high risk. Obtain a pre-configured signature intervention strategy library, and select the appropriate intervention strategy from the signature intervention strategy library according to the risk level; The weight coefficients of each risk factor are calculated using a linear regression model. The training data for the linear regression model includes historical transaction data and their corresponding risk labels. Update the weight values ​​in the weighted average model using the risk factor weight coefficients; Real-time acquisition of new transaction data, extraction of transaction amount, user credit score and transaction frequency, input into the updated weighted average model, and calculation of the second comprehensive risk score of the current transaction; Based on the second comprehensive risk score of the current transaction, and by comparing it with the adjusted risk level threshold, determine the risk level of the current transaction; The signature intervention probability and intervention intensity range are determined based on the risk level of the current transaction, and the intervention intensity range determines the signature complexity. If signature intervention is required, a random number between 0 and 1 is generated. If the random number is less than the signature intervention probability, the signature process is triggered. Adjust the signature complexity according to the range of the intervention intensity values; Continuously collect transaction data over a period of time, and statistically analyze the number of transactions at each risk level and the occurrence rate of risk events; Utilize a rules engine to analyze statistical data, and dynamically adjust risk level thresholds and signature intervention strategy parameters based on the analysis results.

7. An internet-based multi-signature electronic payment system, used to execute the method described in any one of claims 1-6, characterized in that, The system includes: The signature anomaly detection module is used to establish quantitative standards for signature anomalies. Anomaly signature recognition module is used to analyze multi-dimensional features to improve recognition accuracy; The risk assessment module is used to build models to quantify the degree of risk. The real-time monitoring module is used to obtain timestamps to identify anomalies; The intervention strategy module is used to take adaptive intervention measures based on the risk level.

Citation Information

Patent Citations

  • Method for identifying abnormal signature and system thereof

    CN110826380A

  • Abnormal transaction processing method and device

    CN116192465A

  • Secure payment method and system based on signature recognition

    CN117952621A