A method and system for access identity authentication of financial data

By combining multiple authentication methods and using a fraud coefficient model, the complexity of identity authentication is dynamically adjusted, resolving the security and efficiency contradiction caused by fixed authentication methods, and improving user experience and resource utilization efficiency.

CN119830249BActive Publication Date: 2025-11-04SHENGYIN CONSUMER FINANCE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510286964.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-11-04
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

In existing technologies, fixed authentication methods cannot be adaptively adjusted according to the different fraud probabilities of different users, resulting in a contradiction between security and efficiency, affecting user experience and wasting resources.

Method used

By acquiring multiple authentication methods, the complexity of the combined authentication method is determined, and a fraud coefficient model is used to assess the user's fraud risk, dynamically selecting the appropriate combined authentication method for identity verification.

Benefits of technology

It enables dynamic adjustment of verification complexity based on user fraud risk, improving user experience and verification efficiency, avoiding resource waste, and ensuring the security and compliance of financial data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119830249B_ABST
    Figure CN119830249B_ABST
Patent Text Reader

Abstract

The present disclosure provides a financial data access identity authentication method and system, and relates to the technical field of data processing. The method comprises the following steps: acquiring multiple identity verification modes, and determining multiple combined verification modes based on the identity verification modes; determining the combined complexity of each combined verification mode; acquiring a to-be-verified access identity, inputting the to-be-verified access identity into a pre-trained fraud coefficient model, and determining the fraud coefficient of the to-be-verified access identity; wherein the fraud coefficient is used to indicate the probability of the corresponding access identity being suspected of fraud; based on the fraud coefficient of the to-be-verified access identity and the combined complexity of each combined verification mode, a target combined verification mode is determined from the combined verification modes, and the target combined verification mode is used to verify the identity of the to-be-verified access identity. The present disclosure adopts different identity verification modes for users with different fraud coefficients, improves the verification efficiency, and improves the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and particularly relates to a financial data access identity authentication method and system. BACKGROUND

[0002] Financial data generally refers to various data related to financial markets, economy, enterprises and financial tools, and is usually an important basis for banks and financial institutions to manage customer accounts, financial settlement and implement financial supervision. Therefore, it is particularly important to ensure the security, integrity and compliance of financial data during access.

[0003] In related technologies, the security, integrity and compliance of data are ensured by verifying the identity of a user accessing financial data. However, in the prior art, a fixed combination of verification methods is usually used to verify the identity of a user. That is, the same set of verification methods is used to verify the identity of any user. Since the probabilities of fraud suspicion of different users differ, using a fixed verification combination may lead to a contradiction between security and efficiency. For example, for a user with a low fraud coefficient, using a complex verification method not only wastes a lot of computing resources and time, but also reduces the user's experience and affects the user's operation efficiency; and for a user with a high fraud coefficient, using a simple verification method may not provide sufficient security and increase potential security risks. SUMMARY

[0004] To solve the problem that the probabilities of fraud suspicion of different users differ, using a fixed verification combination may lead to a contradiction between security and efficiency in related technologies, the present application provides a financial data access identity authentication method, and the technical solution adopted is as follows:

[0005] A plurality of identity verification methods are obtained, and a plurality of combined verification methods are determined based on the identity verification methods; wherein the combined verification method includes at least one identity verification method, and the identity verification method is used to authenticate the identity of a user accessing financial data;

[0006] The combined complexity of each combined verification method is determined; wherein the combined complexity is used to indicate the verification accuracy of the corresponding combined verification method;

[0007] An access identity to be verified is obtained, and the access identity to be verified is input into a pre-trained fraud coefficient model to determine the fraud coefficient of the access identity to be verified; wherein the fraud coefficient is used to indicate the probability of fraud suspicion of the corresponding access identity;

[0008] determine a target combination verification mode from the combination verification modes based on the fraud coefficient of the access identity to be verified and the combination complexity of each of the combination verification modes, and perform identity verification on the access identity to be verified based on the target combination verification mode.

[0009] Correspondingly, the application also provides a financial data access identity authentication system, specifically comprising:

[0010] An obtaining unit is configured to obtain a plurality of identity verification modes and determine a plurality of combination verification modes based on the identity verification modes, wherein the combination verification modes comprise at least one of the identity verification modes, and the identity verification modes are used to perform identity authentication on a user accessing financial data;

[0011] A processing unit is configured to determine the combination complexity of each of the combination verification modes, wherein the combination complexity is used to indicate the verification accuracy of the corresponding combination verification mode;

[0012] The obtaining unit is further configured to obtain an access identity to be verified, input the access identity to be verified into a pre-trained fraud coefficient model, and determine the fraud coefficient of the access identity to be verified, wherein the fraud coefficient is used to indicate the probability of the corresponding access identity being suspected of fraud;

[0013] An authentication unit is configured to determine a target combination verification mode from the combination verification modes based on the fraud coefficient of the access identity to be verified and the combination complexity of each of the combination verification modes, and perform identity verification on the access identity to be verified based on the target combination verification mode.

[0014] The application can have the following partial or all beneficial effects:

[0015] In the financial data access identity authentication method provided by the present application, a plurality of identity authentication modes are obtained, and a plurality of combined authentication modes are determined based on the identity authentication modes; wherein the combined authentication modes include at least one identity authentication mode, and the identity authentication mode is used for identity authentication of a user accessing financial data; the combined complexity of each combined authentication mode is determined, which is used to indicate the verification accuracy of the corresponding combined authentication mode; the access identity to be verified is obtained, and the access identity to be verified is input into a pre-trained fraud coefficient model to determine the fraud coefficient of the access identity to be verified, which is used to indicate the probability of the corresponding access identity being suspected of fraud; based on the fraud coefficient of the access identity to be verified and the combined complexity of each combined authentication mode, the target combined authentication mode is determined from the combined authentication modes, and the identity of the access identity to be verified is authenticated based on the target combined authentication mode. The present application combines a plurality of identity authentication modes to obtain corresponding combined authentication modes, and determines the combined complexity of each combined authentication mode. The fraud coefficient of the access identity to be verified is determined through the fraud coefficient model, so that the target combined authentication mode with appropriate combined complexity can be determined based on the fraud coefficient of the access identity to be verified to authenticate the identity of the access identity to be verified. According to different fraud coefficients, the combined authentication mode with appropriate complexity is selected, which solves the contradictory problem between security and efficiency caused by fixed authentication combination in the prior art, avoids unnecessary waste of resources, and improves user experience and verification efficiency.

[0016] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present application or the prior art, the drawings needed in the embodiment or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0018] Figure 1 A flowchart of a financial data access identity authentication method according to an exemplary embodiment of the present disclosure is shown;

[0019] Figure 2 A flowchart of training a fraud coefficient model in a financial data access identity authentication method according to an exemplary embodiment of the present disclosure is shown;

[0020] Figure 3 A schematic diagram of a financial data access identity authentication system according to an exemplary embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0021] To further clarify the technical means and effects taken by the present application to achieve the predetermined inventive purpose, the specific implementation, structure, features and effects of the financial data access identity authentication method according to the present application are described in detail below in combination with the drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0022] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs.

[0023] The specific scheme of the financial data access identity authentication method provided by the present application is described in detail below in combination with the drawings.

[0024] Please refer to Figure 1 , which shows the method flowchart of the financial data access identity authentication method provided by one embodiment of the present application, as Figure 1 shown, the financial data access identity authentication method specifically includes the following steps:

[0025] S110: Obtain multiple identity verification modes, and determine multiple combined verification modes based on the identity verification modes; wherein the combined verification mode includes at least one identity verification mode, and the identity verification mode is used for identity authentication of a user accessing financial data;

[0026] S120: Determine the combination complexity of each combined verification mode; wherein the combination complexity is used to indicate the verification accuracy of the corresponding combined verification mode;

[0027] S130: Obtain the access identity to be verified, input the access identity to be verified into a pre-trained fraud coefficient model, and determine the fraud coefficient of the access identity to be verified; wherein the fraud coefficient is used to indicate the probability of the corresponding access identity being suspected of fraud;

[0028] S140: Based on the fraud coefficient of the access identity to be verified and the combination complexity of each combined verification mode, determine the target combined verification mode from each combined verification mode, and perform identity verification on the access identity to be verified based on the target combined verification mode.

[0029] The present application combines a plurality of identity verification manners to obtain corresponding combined verification manners, determines the combined complexity of each combined verification manner, determines the fraud coefficient of the access identity to be verified through the fraud coefficient model, and thus can determine the target combined verification manner with appropriate combined complexity for the access identity to be verified based on the fraud coefficient of the access identity to be verified to perform identity authentication on the access identity to be verified. According to different fraud coefficients, the combined verification manner with appropriate complexity is selected, the contradiction between security and efficiency caused by the fixed verification combination in the prior art is solved, unnecessary resource waste is avoided, and user experience and verification efficiency are improved.

[0030] Next, each step of the above financial data access identity authentication method is described in detail.

[0031] In step S110, a plurality of identity verification manners are obtained, and a plurality of combined verification manners are determined based on the identity verification manners; wherein the combined verification manner includes at least one identity verification manner, and the identity verification manner is used to perform identity authentication on the user accessing the financial data.

[0032] In the embodiment of the present application, the identity verification manner is a verification method for verifying the user accessing the financial data. Illustratively, the identity verification manner can include password verification, SMS verification code verification, fingerprint recognition or dynamic password, and the like.

[0033] In the embodiment of the present application, the financial data refers to various data generated, recorded and analyzed in the financial field, and is usually related to financial market, economy, enterprise and financial tools, and the like. Illustratively, the financial data can include bank transaction records, stock market data, credit records, investment portfolios, financial statements, risk analysis data, and the like.

[0034] In the embodiments of the present application, the combination authentication mode is an authentication mode combined by the above-mentioned identity authentication modes. The combination authentication mode is composed of at least one identity authentication mode. For example, assuming that the identity authentication modes provided by the embodiments of the present application include password authentication, SMS code authentication and fingerprint identification, the process of determining a plurality of combination authentication modes based on the identity authentication modes can be obtained by arranging and combining the three identity authentication modes. Specifically, the combination authentication modes obtained based on the three identity authentication modes can include the following cases: {password authentication}, {SMS code authentication}, {fingerprint identification}, {password authentication, SMS code authentication}, {password authentication, fingerprint identification}, {SMS code authentication, fingerprint identification}, {password authentication, SMS code authentication, fingerprint identification}. It should be noted that the above-mentioned scenario is only an example, and the protection scope of the embodiments of the present application is not limited thereto. For example, the above-mentioned identity authentication modes can be other authentication modes, and the number thereof can be any integer greater than 0.

[0035] In step S120, the combination complexity of each combination authentication mode is determined; wherein the combination complexity is used to indicate the authentication accuracy of the corresponding combination authentication mode.

[0036] In the embodiments of the present application, the combination complexity is used to indicate the authentication accuracy of the corresponding combination authentication mode, and the higher the combination complexity, the higher the accuracy of identity authentication through the combination authentication mode.

[0037] In the embodiments of the present application, the process of determining the combination complexity of the combination authentication mode can be implemented as follows: obtaining historical access information based on financial data, the historical access information including historical access identities and first identity authentication results corresponding to the historical access identities; determining the single complexity of each identity authentication mode based on the historical access identities and the first identity authentication results; wherein the single complexity is used to indicate the authentication accuracy when the corresponding identity authentication mode is used alone; and determining the combination complexity of each combination authentication mode based on the single complexity of each identity authentication mode.

[0038] In the embodiments of the present application, the historical access information is historical information of accessing financial data, which can include historical access identities and first identity authentication results. The historical access identity is the identity of a user who has accessed the financial data in the past, and the first identity authentication result is an identity authentication result obtained by identity authentication on the historical access identity (i.e., a known identity authentication result obtained in the historical access process).

[0039] In the embodiments of the present application, the historical access information can be obtained based on the transaction records of the financial company. For example, the access identities with known verification results (i.e., the historical access identities) in the historical transaction records of the financial company can be collected, and the verification results of the access identities under different verification manners (i.e., the first identity verification results) can be collected. Specifically, M access identities with known verification results can be collected from the historical transaction records of the financial company, and each access identity includes N characteristics (such as an identity ID, a transaction frequency, an IP address, and the like). After the N identity characteristics of the M access identities are quantified, the historical access information shown in Table 1 can be obtained.

[0040] Table 1

[0041]

[0042] In the embodiments of the present application, the process of determining the single complexity of each identity verification manner based on the historical access identities and the first identity verification results can be implemented as follows: for each historical access identity, identity verification is performed on the historical access identity based on each identity verification manner, and the second identity verification result of the historical access identity under each identity verification manner is determined; and the single complexity of each identity verification manner is determined based on the first identity verification result and the second identity verification result corresponding to each historical access identity.

[0043] In the embodiments of the present application, the second identity verification result is the verification result obtained by using a certain identity verification manner to perform identity verification on the historical access identity, and the single complexity is used to indicate the verification accuracy of using the corresponding identity verification manner. Specifically, different identity verification manners are used to perform identity verification on the M access identities, and the number of the identity verification manners is n. The results of using n identity verification manners to perform identity verification on the M access identities can be shown in Table 2.

[0044] Table 2

[0045]

[0046] For the M access identities, the first identity verification result is known, and is set to label 1 if the verification is passed, or is set to label 0 if the verification is not passed. Then, the n verification manners can be used to perform verification processing on the M access identities, and the second identity verification result is set to label 1 if the verification is passed, or is set to label 0 if the verification is not passed.

[0047] In this embodiment of the application, after determining the second authentication result of each authentication method for the historical access identity, taking authentication method A among the above n authentication methods as an example, the process of determining the single complexity of authentication method A based on the first and second authentication results corresponding to each historical access identity can be implemented as follows:

[0048] Specifically, the complexity coefficient (i.e., the single complexity of authentication method A) can be determined by the verification performance of the aforementioned M historical access identities under authentication method A. For any of the aforementioned M historical access identities... If the historical access identity is verified through authentication method A, the verification result is... (that is, the first) The second authentication result obtained by verifying the historical access identity through authentication method A) and the first Known authentication results of historical access identities (that is, the first) If the results of the first identity verification of the historical access identity match, then for the first... For a given historical access identity, authentication based on authentication method A yields an accurate result, but with a relatively high complexity coefficient. However, since the authentication difficulty varies across different access identities, if a historical access identity obtains a second authentication result significantly different from the known first authentication result under most authentication methods, that is... A larger value indicates greater difficulty in verifying the historical access identity. Therefore, the complexity coefficients of the above M historical access identities under authentication method A can be weighted to obtain the complexity coefficient of authentication method A (i.e., the single complexity of authentication method A). The specific formula for this weighting is as follows:

[0049]

[0050] in, Let M represent the single complexity of authentication method A, M represent the number of historical access identities mentioned above, and n represent the total number of authentication methods. Indicates the first The verification result of the historical access identity under authentication method u. Indicates the first The first authentication result of the historical access identity, Indicates the first The difficulty of verifying historical access identities. Indicates the first The verification result of the historical access identity under authentication method A. representing the conformity of the second authentication result of the historical access identity under the identity authentication manner A with the first authentication result, representing the complexity of the identity authentication manner A under the historical access identity. representing the complexity of the identity authentication manner A under the historical access identity.

[0051] It should be noted that the above scenario is only an example, and the single complexity of other identity authentication manners can also be determined by the above method.

[0052] In the embodiments of the present application, after determining the single complexity of each identity authentication manner, the combined complexity of each combined authentication manner can be further determined based on the single complexity of each identity authentication manner. For example, the process of determining the combined complexity of each combined authentication manner can be implemented as follows: for any two identity authentication manners, the complexity correlation between the two identity authentication manners is determined based on the first authentication result and the second authentication result corresponding to each historical access identity and the single complexity of the two identity authentication manners; and the combined complexity of each combined authentication manner is determined based on the complexity correlation between each pair of identity authentication manners.

[0053] In the embodiments of the present application, the above complexity correlation is used to describe the correlation between different identity authentication manners, because the above identity authentication manners are not necessarily independent of each other, that is, the different identity authentication manners can be correlated. When determining the combined complexity of the combined authentication manner, the correlation needs to be determined first, so as to exclude the influence of the correlation when calculating the combined complexity subsequently. For example, taking the calculation of the complexity correlation between the identity authentication manner A and the identity authentication manner B as an example, the determination of the complexity correlation between any two identity authentication manners can be implemented as follows:

[0054] ​Specifically, the correlation between authentication methods A and B can be determined by using the authentication performance of the aforementioned M historical access identities under authentication methods A and B. For any historical access identity, if the authentication results of authentication methods A and B match, then the authentication correlation between authentication methods A and B is high for that historical access identity. However, since the authentication difficulty varies among different historical access identities, if the second authentication result obtained by a certain historical access identity under most authentication methods differs significantly from the known first authentication result, then it is determined that the authentication difficulty of that historical access identity is high, and the authentication correlation is good. Therefore, the complexity correlation between authentication methods A and B can be obtained by weighting the correlation of the authentication results of the aforementioned M historical access identities under authentication methods A and B. The specific formula for this complexity correlation is as follows:

[0055]

[0056] in, Let f represent the complexity correlation between authentication method A and authentication method B, f represent the normalization function, M represent the total number of M historical access identities, and n represent the total number of authentication methods. Indicates the first The verification result of the historical access identity under authentication method u. Indicates the first The first authentication result of a known historical access identity. Indicates the first The difficulty of verifying historical access identities. Indicates the first The verification result of the historical access identity under authentication method A. Indicates the first The verification result of the historical access identity under authentication method B. Indicates the first The conformity of a historical access identity under authentication method A and authentication method B. Indicates the first The complexity correlation between authentication method A and authentication method B under a given historical access identity. This represents the single complexity of authentication method A. This represents the single complexity of authentication method B.

[0057] It should be noted that the above scenario is only an example, and the complexity correlation between any two other authentication methods can also be determined using the above method.

[0058] In the embodiments of the present application, after the complexity correlation between any two identity verification manners is determined through the above process, the combined complexity of each combined verification manner can be determined based on the complexity correlation between each pair of identity verification manners through the following method: for each combined verification manner, the number of identity verification manners in the combined verification manner is obtained; the combined complexity of the combined verification manner is determined according to the complexity correlation between the identity verification manners in the combined verification manner, the number of identity verification manners, and the single complexity of each identity verification manner.

[0059] For example, taking the combined verification manner i as an example, the process of determining the combined complexity of the combined verification manner can be implemented as follows: for each identity verification manner in the combined verification manner i, the pure verification of the corresponding identity verification manner under the condition of no interference from other identity verification manners is determined based on the complexity correlation between each identity verification manner and other identity verification manners; the single complexity of each identity verification manner in the combined verification manner i is weighted by using the calculated pure verification to determine the combined complexity of the combined verification manner i. Specifically, assuming that the combined verification manner i is composed of identity verification manners i1, i2…ig, the combined complexity of the combined verification manner i can be determined by the following formula:

[0060]

[0061] wherein, Ci represents the combined complexity of the combined verification manner i, g represents that the combined verification manner i is composed of g identity verification manners, represents the complexity correlation between the identity verification manner A and the identity verification manner B in the combined verification manner i, represents the pure verification of the identity verification manner A in the combined verification manner i, represents the single complexity of the identity verification manner A in the combined verification manner i.

[0062] It should be noted that the above scenario is only an example, and the combined complexity of other verification combinations can also be determined by the above method.

[0063] In step S130, the access identity to be verified is obtained, and the access identity to be verified is input into the pre-trained fraud coefficient model to determine the fraud coefficient of the access identity to be verified; wherein the fraud coefficient is used to indicate the probability of the corresponding access identity being suspected of fraud.

[0064] In the embodiments of the present application, the access identity to be verified is the user identity that needs to be authenticated. If the access identity to be verified passes the identity authentication, the corresponding financial data can be accessed.

[0065] In the embodiments of the present application, the fraud coefficient model is used to determine the probability that the user identity input into the model is suspected of fraud. For example, any access identity can be input into the fraud coefficient model, and after model processing, the corresponding fraud coefficient is output, which is used to indicate the probability that the access identity input into the model is suspected of fraud.

[0066] In the embodiments of the present application, the historical access information described above can be used as a training data set to train the fraud coefficient model. For example, the training process of the fraud coefficient model can be implemented as follows: based on the identity feature information of the historical access identities, the identity similarity between each two historical access identities is determined; based on the identity similarity, the fraud coefficient of each historical access identity is determined; and based on the fraud coefficient of the historical access identities, the fraud coefficient model is trained.

[0067] In the embodiments of the present application, the identity similarity is used to describe the similarity between each historical access identity and other historical access identities in the training data set, which can be determined based on the identity feature information of the historical access identities.

[0068] For example, the process of determining the identity similarity between each two historical access identities based on the identity feature information of the historical access identities can be implemented as follows: for each identity feature information, based on the first verification result corresponding to each feature value of the identity feature information, the availability of the identity feature information is determined; wherein the availability is used to indicate the importance of the corresponding identity feature information for identity verification; and based on the availability of each identity feature information, the identity similarity between each two historical access identities is determined.

[0069] The fraud coefficient of each historical access identity based on the identity similarity can be implemented as follows: for each historical access identity, based on the identity similarity between the historical access identity and other historical access identities, and the first identity verification result of each historical access identity, the fraud coefficient of the historical access identity is determined.

[0070] Next, in a specific embodiment, the fraud coefficient model is combined with the identity feature information of the access identity to determine the probability that the access identity is suspected of fraud. Figure 2 The training process of the fraud coefficient model is described in detail as follows: Figure 2 The training process specifically includes the following steps:

[0071] S210: Determine the identity similarity between each historical access identity and other historical access identities in the training data set.

[0072] In the embodiments of the present application, taking the M historical access identities as an example, each historical access identity includes N identity characteristic information, and the identity similarity can be calculated based on each identity characteristic information. However, due to the different availability of different identity characteristic information, for each identity characteristic information of any historical access identity, if the identity characteristic information has a greater influence on the identity verification result, that is, the identity verification result can be roughly judged only by the different characteristic values under this identity characteristic information, then the purity of the verification result of each access value under this identity characteristic information is higher (that is, the difference between the total number of access identities with identity verification result of 1 and the total number of access identities with identity verification result of 0 is large), so it can be judged that the availability of the identity characteristic information is higher. Taking the transaction frequency as an example of the above identity characteristic information, the characteristic value under this identity characteristic information can be the transaction times of each historical access identity in a certain time period, and the characteristic value can be obtained through the process of collecting historical access information in step S120. If the different characteristic values (that is, the transaction times of each historical access identity in a certain time period) under the transaction frequency are used to verify the historical access identity, the difference between the total number of historical access identities with identity verification result of 1 and the total number of historical access identities with identity verification result of 0 is large, which proves that the availability of the transaction frequency identity characteristic information is higher. Taking the Tth identity characteristic information as an example, the availability of the Tth identity characteristic information can be determined by the following formula:

[0073]

[0074] wherein, represents the availability of the Tth identity characteristic information, represents the total number of characteristic values of the Tth identity characteristic information, represents the total number of historical access identities with identity verification result of 1 under the hth characteristic value of the Tth identity characteristic information, represents the total number of historical access identities with identity verification result of 0 under the hth characteristic value of the Tth identity characteristic information, represents the total number of access identities with different identity verification results under the hth characteristic value of the Tth identity characteristic information, represents the total number of historical access identities under the hth characteristic value of the Tth identity characteristic information, represents the relative total number of access identities with different identity verification results under the hth characteristic value of the Tth identity characteristic information.

[0075] In the embodiments of the present application, after determining the availability of each identity characteristic information based on the above method, further, the identity similarity between the historical access identity a and the historical access identity b in the training data set can be determined based on the availability of each identity characteristic information, and the specific formula is as follows:

[0076]

[0077] wherein, represents the identity similarity between the historical access identity a and the historical access identity b in the training data set, and N represents that there are N identity characteristic information in total, represents the availability of the Tth identity characteristic information, and exp represents the exponential function with e as the base, represents the feature value of the historical access identity a under the Tth identity characteristic information (taking the identity ID of the Tth identity characteristic information as an example, here is the identity ID of the historical access identity a), represents the feature value of the historical access identity b under the Tth identity characteristic information, represents the similarity between the historical access identity a and the historical access identity b under the Tth identity characteristic information in the training data set.

[0078] It should be noted that the above scenario is only an example, and the identity similarity between other historical access identities in the training data set can also be determined by the above method.

[0079] S220: Determine the overall fraud coefficient of each historical access identity in the training data set, and construct an initial feature matrix.

[0080] In the embodiment of the present application, when the identity similarity between any two historical access identities is large, their known identity verification results should be consistent, and if the verification results are different, it means that there is a greater possibility of fraud. Taking the historical access identity a as an example, when the identity similarity between other access identities and the historical access identity a is high, if there is a difference in their verification results, it can be considered that the historical access identity a has a fraud suspicion. Exemplarily, the fraud coefficient of the historical access identity a can be determined by the following formula:

[0081]

[0082] wherein, represents the fraud coefficient of the historical access identity a in the training data set, and M represents that there are M historical access identities in the training data set, represents the identity similarity between the historical access identity a and the Mth historical access identity in the training data set, represents the known identity verification result of the historical access identity A in the training data set, represents the known identity verification result of the Mth historical access identity in the training data set.

[0083] ​​Similarly, the fraud coefficients of all historical access identities in the training data set are determined, and an initial feature matrix shown in Table 3 is constructed.

[0084] Table 3:

[0085]

[0086] S230: Construct a fraud coefficient model.

[0087] In the embodiments of the present application, after the initial feature matrix is constructed through the above steps, an initial decision tree for predicting the fraud coefficient is determined based on the initial feature matrix; the gradient of the residual error of the current model is calculated based on the gradient boosting decision tree algorithm (eXtreme Gradient Boosting, XGBoost), and a new decision tree is trained using this gradient; after the training is completed, the new tree is added to the existing model to update the prediction value of the model, and the updated prediction result is obtained by the weighted sum of all decision trees. The process is repeated until a predetermined number of training rounds (i.e., the number of trees) is reached, so that the prediction error of the previous model is corrected through each iteration, and the model gradually becomes more accurate.

[0088] In the embodiments of the present application, the XGBoost fraud coefficient model trained contains all the decision trees generated during the training process. For any new input sample (i.e., the above-mentioned to-be-verified access identity), the identity feature information of the sample is input into the trained fraud model, and the fraud model generates a final prediction value (i.e., the fraud coefficient of the to-be-verified access identity) through the weighted sum of all decision trees.

[0089] In step S140, based on the fraud coefficient of the to-be-verified access identity and the combination complexity of each combined verification mode, a target combined verification mode is determined from each combined verification mode, and the identity of the to-be-verified access identity is verified based on the target combined verification mode.

[0090] In the embodiments of the present application, after the combination complexity of each combined verification mode and the fraud coefficient of the to-be-verified access identity are determined based on the above steps, the process of determining the target combined verification mode from each combined verification mode based on the fraud coefficient of the to-be-verified access identity and the combination complexity of each combined verification mode can be implemented as follows: for each historical access identity, the verification complexity required by the historical access identity is determined based on each combined verification mode; the unit complexity is determined based on the verification complexity required by each historical access identity, and the unit complexity is the verification complexity corresponding to the unit fraud coefficient; the verification complexity required by the to-be-verified access identity is determined based on the fraud coefficient of the to-be-verified access identity and the unit complexity; and the target combined verification mode is determined from each combined verification mode based on the verification complexity required by the to-be-verified access identity and the combination complexity.

[0091] In this embodiment, the verification complexity is used to characterize the complexity required for authentication of the corresponding access identity. Typically, this verification complexity is directly proportional to the fraud coefficient of the access identity; that is, the higher the fraud coefficient of the access identity, the higher the required verification complexity.

[0092] In this embodiment of the application, the verification complexity required for the aforementioned historical access identity can be determined by the following process: The aforementioned combined verification methods are arranged in ascending order of combined complexity. Assuming there are u combined verification methods composed of the aforementioned identity verification methods, a sequence of combined verification methods {1, 2, 3, 4...u} can be obtained through the above sorting. Each of the aforementioned historical access identities is sequentially substituted into each of the combined verification methods in the sequence of combined verification methods for identity verification, and the corresponding identity verification result is obtained until the identity verification result no longer changes. The combined complexity corresponding to the combined verification method at this point is taken as the verification complexity required for the corresponding historical access identity.

[0093] In this embodiment, the aforementioned unit complexity refers to the verification complexity required for a unit fraud coefficient. This complexity can be determined by the average of the minimum complexity required for the unit fraud coefficient of all historical access identities in the training dataset, and can be specifically calculated using the following formula:

[0094]

[0095] in, This represents the verification complexity required per unit of fraud coefficient, where M represents the number of historical access identities in the training set. Indicates the first training set Fraud coefficient corresponding to each historical access identity Indicates the first in the training dataset The verification complexity required for historical access identities, Indicates the first in the training dataset The minimum complexity required to determine the fraud coefficient of a unit based on historical access identity.

[0096] In this embodiment of the application, after determining the unit complexity, since the unit complexity is the verification complexity required for the unit fraud coefficient, the above-mentioned determination of the verification complexity required for the access identity to be verified based on the fraud coefficient and unit complexity of the access identity to be verified can be achieved as follows: multiply the fraud coefficient of the access identity to be verified and the unit complexity to obtain the verification complexity required for the access identity to be verified.

[0097] Further, based on the verification complexity required for the to-be-verified access identity, a combination verification manner with a combination complexity reaching the verification complexity is selected as the target verification manner in each combination verification manner. For example, a combination verification manner with the least number of included identity verification manners and a combination complexity greater than or equal to the verification complexity required for the to-be-verified access identity is selected as the target verification manner, so as to verify the to-be-verified access identity based on the target verification manner.

[0098] The present application obtains a corresponding combination verification manner by combining a plurality of identity verification manners, determines the combination complexity of each combination verification manner, determines the fraud coefficient of the to-be-verified access identity by using the fraud coefficient model, and thus can determine a target combination verification manner with a suitable combination complexity to verify the to-be-verified access identity based on the fraud coefficient of the to-be-verified access identity. According to different fraud coefficients, a combination verification manner with a suitable complexity is selected, which solves the contradictory problem between security and efficiency caused by a fixed verification combination in the prior art, avoids unnecessary waste of resources, and improves user experience and verification efficiency.

[0099] The above mainly describes the scheme provided by the embodiments of the present application from the perspective of a method. To implement the above functions, it includes a hardware structure and / or a software module corresponding to each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in hardware or in the form of computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0100] The embodiments of the present disclosure provide a financial data access identity authentication system. Referring to FIG. 3, the financial data access identity authentication system 300 can include an acquisition unit 310, a processing unit 320, and an authentication unit 330. Figure 3 The acquisition unit 310 is configured to acquire a plurality of identity verification manners and determine a plurality of combination verification manners based on the identity verification manners. The combination verification manners include at least one identity verification manner, and the identity verification manners are used to authenticate the user accessing the financial data.

[0101] The acquisition unit 310 is configured to acquire a plurality of identity verification manners and determine a plurality of combination verification manners based on the identity verification manners. The combination verification manners include at least one identity verification manner, and the identity verification manners are used to authenticate the user accessing the financial data.

[0102] The processing unit 320 is configured to determine the combination complexity of each combination verification manner. The combination complexity is used to indicate the verification accuracy of the corresponding combination verification manner.

[0103] The acquisition unit 310 is further configured to acquire the to-be-verified access identity, input the to-be-verified access identity into the pre-trained fraud coefficient model, and determine a fraud coefficient of the to-be-verified access identity; the fraud coefficient is used to indicate a probability of suspected fraud of the corresponding access identity.

[0104] The authentication unit 330 is configured to determine a target combined verification mode from the combined verification modes based on the fraud coefficient of the to-be-verified access identity and the combined complexity of each combined verification mode, and perform identity verification on the to-be-verified access identity based on the target combined verification mode.

[0105] In the embodiments of the present application, the processing unit is specifically configured to: acquire historical access information based on the financial data, the historical access information including historical access identities and first identity verification results corresponding to the historical access identities; determine the single complexity of each identity verification mode based on the historical access identities and the first identity verification results; the single complexity is used to indicate the verification accuracy when the corresponding identity verification mode is used alone; and determine the combined complexity of each combined verification mode based on the single complexity of each identity verification mode.

[0106] In the embodiments of the present application, the processing unit is specifically configured to: for each historical access identity, perform identity verification on the historical access identity based on each identity verification mode, and determine a second identity verification result of the historical access identity under each identity verification mode; and determine the single complexity of each identity verification mode based on the first identity verification result and the second identity verification result corresponding to each historical access identity.

[0107] In the embodiments of the present application, the processing unit is specifically configured to: for any two identity verification modes, determine the complexity correlation between the any two identity verification modes based on the first identity verification result and the second identity verification result corresponding to each historical access identity, and the single complexity of the any two identity verification modes; and determine the combined complexity of each combined verification mode based on the complexity correlation between each pair of identity verification modes.

[0108] In the embodiments of the present application, the processing unit is specifically configured to: for each combined verification mode, acquire the number of identity verification modes in the combined verification mode; and determine the combined complexity of the combined verification mode based on the complexity correlation between the identity verification modes in the combined verification mode, the number of identity verification modes in the combined verification mode, and the single complexity of each identity verification mode in the combined verification mode.

[0109] In the embodiment of the present application, the historical access information includes identity feature information of the historical access identity; the access identity authentication system of the financial data further includes a model training module, which is specifically configured to: determine identity similarity between each two of the historical access identities based on the identity feature information; determine a fraud coefficient of each historical access identity based on the identity similarity; and train a fraud coefficient model based on the fraud coefficients of the historical access identities.

[0110] In the embodiment of the present application, the model training module is further configured to: for each identity feature information, determine the availability of the identity feature information based on the first verification result corresponding to each feature value of the identity feature information; wherein the availability is used to indicate the importance of the corresponding identity feature information for identity verification; and determine the identity similarity between each two of the historical access identities based on the availability of each identity feature information.

[0111] In the embodiment of the present application, the model training module is further configured to: for each historical access identity, determine the fraud coefficient of the historical access identity based on the identity similarity between the historical access identity and other historical access identities, and the first identity verification result of each historical access identity.

[0112] In the embodiment of the present application, the authentication unit is specifically configured to: for each historical access identity, determine the verification complexity required by the historical access identity based on each combination verification mode; determine a unit complexity based on the verification complexity required by each historical access identity, the unit complexity being a verification complexity corresponding to a unit fraud coefficient; determine the verification complexity required by the to-be-verified access identity based on the fraud coefficient of the to-be-verified access identity and the unit complexity; and determine the target combination verification mode from the combination verification modes based on the verification complexity required by the to-be-verified access identity and the combination complexity.

[0113] The embodiment of the present application can divide the functional modules of the access identity authentication system of the financial data according to the above-mentioned method examples. For example, each functional module can be divided according to each function, or two or more functions can be integrated in one processing module. The integrated module can be realized in the form of hardware or in the form of a software functional module. It should be noted that the division of the modules in the embodiment of the present application is illustrative, and is only a logical functional division. In actual implementation, another division mode can be used.

[0114] In addition, the specific implementation details of the access identity authentication system of the financial data have been described in detail at the corresponding position of the access identity authentication method of the financial data, and thus will not be described here again.

[0115] It is to be noted that the sequential order of the above-described embodiments of the present application only for the purpose of description, but not the advantages and disadvantages of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or can be advantageous.

[0116] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments.

Claims

1. A method of access identity authentication of financial data, characterized by, The method comprises: obtaining a plurality of identity authentication manners, and determining a plurality of combined authentication manners based on the identity authentication manners; wherein the combined authentication manner comprises at least one identity authentication manner, and the identity authentication manner is used for identity authentication of a user accessing financial data; determining the combined complexity of each combined authentication manner, comprising: determining the single complexity of each identity authentication manner based on the historical access identities and the first identity authentication results; wherein the single complexity is used to indicate the authentication accuracy when the corresponding identity authentication manner is used alone; for any two identity authentication manners, determining the complexity correlation between the two identity authentication manners based on the first identity authentication results and the second identity authentication results corresponding to each historical access identity, and the single complexity of the two identity authentication manners; for each combined authentication manner, obtaining the number of identity authentication manners in the combined authentication manner; determining the combined complexity of the combined authentication manner according to the complexity correlation between the identity authentication manners in the combined authentication manner, the number of identity authentication manners in the combined authentication manner, and the single complexity of each identity authentication manner in the combined authentication manner; wherein the combined complexity is used to indicate the authentication accuracy of the corresponding combined authentication manner; obtaining a to-be-verified access identity, inputting the to-be-verified access identity into a pre-trained fraud coefficient model, and determining the fraud coefficient of the to-be-verified access identity; wherein the fraud coefficient is used to indicate the probability of the corresponding access identity being suspected of fraud; determining a target combined authentication manner from the combined authentication manners based on the fraud coefficient of the to-be-verified access identity and the combined complexity of each combined authentication manner, and performing identity authentication on the to-be-verified access identity based on the target combined authentication manner; obtaining historical access information based on the financial data, the historical access information comprising the historical access identities, the first identity authentication results corresponding to each historical access identity, and the identity characteristic information of the historical access identities; the fraud coefficient model is obtained by training in the following manner, comprising: for each identity characteristic information, determining the availability of the identity characteristic information based on the first authentication results corresponding to each feature value of the identity characteristic information; wherein the availability is used to indicate the importance of the corresponding identity characteristic information for identity authentication; determining the identity similarity between the historical access identities based on the availability of each identity characteristic information; for each historical access identity, determining the fraud coefficient of the historical access identity based on the identity similarity between the historical access identity and other historical access identities, and the first identity authentication results of each historical access identity; training the fraud coefficient model based on the fraud coefficients of the historical access identities; wherein the single complexity of each identity authentication manner is determined based on the historical access identities and the first identity authentication results, comprising: for each historical access identity, determining the second identity authentication results of the historical access identity under each identity authentication manner based on the identity authentication of the historical access identity by each identity authentication manner; determining the single complexity of each identity authentication manner based on the first identity authentication results and the second identity authentication results corresponding to each historical access identity; the specific calculation formula is: wherein W A represents the single complexity of the identity authentication mode A, M represents the number of historical access identities, n represents the total number of n identity authentication modes, Y v-u represents the authentication result of the vth historical access identity under the identity authentication mode u, Y v represents the first identity authentication result of the vth historical access identity, represents the authentication difficulty of the vth historical access identity, Y v-A represents the authentication result of the vth historical access identity under the identity authentication mode A, ||Y v-A -Y v represents the consistency of the second identity authentication result and the first identity authentication result of the vth historical access identity under the identity authentication mode A, represents the complexity of the identity authentication mode A under the vth historical access identity.

2. The financial data access authentication method of claim 1, wherein, determine a target combination authentication mode from the combination authentication modes based on a fraud coefficient of the to-be-verified access identity and combination complexities of the combination authentication modes, including: determining, for each historical access identity, authentication complexity required by the historical access identity based on the combination authentication modes; determining a unit complexity based on the authentication complexity required by each historical access identity, the unit complexity being authentication complexity corresponding to a unit fraud coefficient; determining authentication complexity required by the to-be-verified access identity based on the fraud coefficient of the to-be-verified access identity and the unit complexity; determining the target combination authentication mode from the combination authentication modes based on the authentication complexity required by the to-be-verified access identity and the combination complexity.

3. An access identity authentication system for financial data, characterized by, The system comprises: an acquisition unit configured to acquire a plurality of identity authentication modes and determine a plurality of combination authentication modes based on the identity authentication modes; wherein the combination authentication mode comprises at least one identity authentication mode, and the identity authentication mode is used to authenticate a user accessing financial data; a processing unit configured to determine combination complexity of each combination authentication mode, including: determining single complexity of each identity authentication mode based on historical access identities and first identity authentication results; wherein the single complexity is used to indicate authentication accuracy when the corresponding identity authentication mode is used alone; determining complexity correlation between any two identity authentication modes based on first identity authentication results and second identity authentication results corresponding to each historical access identity, and the single complexity of the any two identity authentication modes; acquiring the number of identity authentication modes in the combination authentication mode for each combination authentication mode; and determining the combination complexity of the combination authentication mode according to the complexity correlation between the identity authentication modes in the combination authentication mode, the number of identity authentication modes in the combination authentication mode, and the single complexity of each identity authentication mode in the combination authentication mode; wherein the combination complexity is used to indicate authentication accuracy of the corresponding combination authentication mode; the acquisition unit is further configured to acquire a to-be-verified access identity, input the to-be-verified access identity into a pre-trained fraud coefficient model, and determine a fraud coefficient of the to-be-verified access identity; wherein the fraud coefficient is used to indicate probability of fraud suspicion of the corresponding access identity; an authentication unit configured to determine a target combination authentication mode from the combination authentication modes based on the fraud coefficient of the to-be-verified access identity and the combination complexity of each combination authentication mode, and perform identity authentication on the to-be-verified access identity based on the target combination authentication mode; acquiring historical access information based on the financial data, the historical access information comprising historical access identities, first identity authentication results corresponding to each historical access identity, and identity feature information of the historical access identities; the fraud coefficient model is obtained by training through the following method, including: determining availability of the identity feature information based on first authentication results corresponding to each feature value of the identity feature information for each identity feature information; wherein the availability is used to indicate importance of the corresponding identity feature information for identity authentication; determining identity similarity between the historical access identities two by two based on the availability of each identity feature information; For each historical access identity, based on the identity similarity of the historical access identity and other historical access identities, and the first identity verification result of each historical access identity, a fraud coefficient of the historical access identity is determined; A fraud coefficient model is trained based on the fraud coefficients of the historical access identities; Wherein, the single complexity of each identity verification mode is determined based on the historical access identity and the first identity verification result, including: for each historical access identity, based on the identity verification of each identity verification mode on the historical access identity, the second identity verification result of the historical access identity under each identity verification mode is determined; the single complexity of each identity verification mode is determined based on the first identity verification result and the second identity verification result corresponding to each historical access identity; the specific calculation formula is: wherein W A represents the single complexity of the identity authentication mode A, M represents the number of historical access identities, n represents the total number of n identity authentication modes, Y v-u represents the verification result of the vth historical access identity under the identity authentication mode u, Y v represents the first identity authentication result of the vth historical access identity, represents the verification difficulty of the vth historical access identity, Y v-A represents the verification result of the vth historical access identity under the identity authentication mode A, ||Y v-A -Y v represents the consistency of the second identity authentication result and the first identity authentication result of the vth historical access identity under the identity authentication mode A, represents the complexity of the identity authentication mode A under the vth historical access identity.

Citation Information

Patent Citations

  • System and method for adaptively determining an optimal authentication scheme

    CN113383333A

  • Identity verification method and device, electronic equipment and storage medium

    CN117034228A