User authentication method and system for a communication software
By constructing a matching feature matrix and analyzing historical session data, the accuracy and security of identity verification in communication software are solved, dynamic adaptation and abnormal detection of user behavior are achieved, and the security and user experience of identity verification are improved.
Patent Information
- Application Number
- CN202510393386.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-03-31
AI Technical Summary
During the authentication process of existing communication software, the lack of correlation analysis of the overall structure of the data packets is likely to occur in the case of field layout changes or partial fields forgery, and it is not possible to effectively detect abnormal changes in user behavior patterns, making it difficult to identify deceptive requests and reduce security.
By parsing the authentication request packet, extracting fixed, dynamic and variable fields, calculating data bit offset values, building matching feature matrix, combining historical session data analysis, evaluating session coherence and context consistency, and dynamically adjusting verification strength.
It improves the accuracy and security of identity verification, can dynamically adapt to changes in user behavior, enhances the ability to detect abnormal data, and improves the interactive experience.
Smart Images

Figure CN119903501B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication, and particularly to a user identity authentication method and system for a communication software. Background Art
[0002] The technical field of identity authentication includes methods for confirming and managing user identities. The core content involves encryption and decryption technologies based on cryptography, biometric recognition methods, multi-factor identity authentication mechanisms, and security communication verification means based on network protocols, systematically covering the processes of collecting, storing, comparing, and verifying user identity data. In a computer network environment, identity authentication technologies are widely used in multiple fields such as personal device unlocking, online payment, network service access control, and data secure transmission. Common identity authentication methods include password-based authentication, token-based authentication, biometric authentication, and digital certificate authentication based on public key infrastructure. With the development of information technology, identity authentication technologies are constantly evolving to improve security and user experience.
[0003] Among them, the user identity authentication method for communication software refers to an identity confirmation method for the access rights and data security of network communication software users, mainly covering identity authentication based on user credentials, user identification based on device fingerprints, and secure communication mechanisms based on encryption protocols. Its specific implementation methods usually include using a hash function to encrypt and verify the identity information input by the user, adopting a key exchange protocol to establish a secure communication channel between the client and the server, and verifying user behavior based on a specific identity authentication protocol. In addition, it also involves using biometric information combined with a time synchronization mechanism to improve the reliability of identity authentication, and verifying the user identity step by step through the protocol to ensure security in different communication environments.
[0004] In the existing identity authentication process of communication software, when parsing identity authentication data, it mainly relies on a single field or a limited combination of fields for verification, lacking the correlation analysis of the overall structure of the data packet, resulting in easy misjudgment in the case of field layout changes or forgery of some fields. The determination of the legality of identity authentication requests depends on static rule matching, and the arrangement order and consistency of fields cannot be effectively detected, enabling attackers to interfere with the verification logic by adjusting the field structure and avoiding security checks. The identity authentication method usually only conducts independent authentication based on a single request, lacking the ability to analyze historical sessions and being difficult to identify abnormal changes in user behavior patterns, allowing attackers to use low-frequency and multiple attempts to avoid detection. The context analysis is relatively rough, with insufficient ability to identify changes in the content input by users, and it fails to effectively distinguish normal user behavior from malicious tampering behavior, resulting in some deceptive requests being difficult to accurately intercept and reducing the overall security. Summary of the Invention
[0005] The object of the present invention is to solve the deficiencies existing in the prior art, and a user authentication method for a communication software is proposed.
[0006] To achieve the above object, the present invention adopts the following technical solutions: A user authentication method for a communication software, comprising the following steps:
[0007] S1: Obtain the authentication request data packet in the communication protocol, decode the authentication field information, extract the fixed field, dynamic field and variable field, calculate the data bit offset value, perform structure mapping and obtain the authentication field mapping result;
[0008] S2: According to the authentication field mapping result, calculate the matching feature for the fixed field, perform permutation sequence verification on the data packet format, establish a field matching rule, parse the data range of the dynamic field, calculate the time span value of the time stamp field, determine whether the time stamp field conforms to the time matching reference value, calculate the correlation matching degree between variable fields, and comprehensively establish an authentication field matching feature matrix;
[0009] S3: Based on the authentication field matching feature matrix, perform field permutation order verification on the authentication request data, calculate the field matching consistency metric value, compare the authentication field mapping result, calculate the legitimacy degree of the authentication request, and output the authentication request legitimacy data;
[0010] S4: Read the authentication request legitimacy data, parse the current session data, calculate the correlation degree between the current session and the historical session data, determine whether there is a topic change, and obtain the session authentication continuity analysis result.
[0011] As a further solution of the present invention, the authentication field mapping result includes a field offset value, a field structure relationship, and field decoding information. The authentication field matching feature matrix includes a fixed field matching feature, a dynamic field data range, a variable field correlation matching degree, and a time stamp matching reference. The authentication request legitimacy data includes field permutation order consistency, field matching consistency metric value, storage offset matching situation, and legitimacy evaluation result. The session authentication continuity analysis result includes message content correlation degree, message order matching degree, time feature consistency, and dialogue topic change situation.
[0012] As a further solution of the present invention, the specific steps of S1 are:
[0013] S111: Obtain the authentication request data packet in the communication protocol, decode the authentication field information, extract the fixed field, dynamic field and variable field associated with the authentication, calculate the data bit offset value, and obtain the authentication field position information;
[0014] S112: Based on the authentication field position information, perform authentication field structure mapping, analyze the relative offsets of each field in the data packet and the correlation degree between fields, and use the formula:
[0015] ;
[0016] Calculate the offset error value of each authentication field , and obtain the authentication field mapping error data, where represents the calculated offset of the th field, represents the theoretical offset of the th field, represents the standard offset unit of the th field, represents the importance weight of the th field, represents the total number of authentication fields;
[0017] S113: Based on the authentication field mapping error data, adjust the structural relationship of the authentication fields, match the field mapping rules, and obtain the authentication field mapping result.
[0018] As a further solution of the present invention, the specific steps of S2 are:
[0019] S211: Based on the authentication field mapping result, calculate the matching features for the fixed fields, extract the field values of the fixed fields, and count the matching patterns to determine the fixed field matching rate and obtain the fixed field matching features;
[0020] S212: According to the fixed field matching features, establish field matching rules based on the protocol header information, parse the dynamic field data range, and count the time span value of the timestamp field. Use the formula:
[0021] ;
[0022] Calculate the time matching deviation value , combine the time interval of the normal authentication request to set the time matching reference value, and determine whether the timestamp field meets the time matching reference value to obtain the time matching deviation data, where represents the time value of the th timestamp field, represents the time value of the previous timestamp field, represents the number of timestamp fields, represents the number of time points for calculating the time span;
[0023] S213: Calculate the correlation matching degree between variable fields based on the time matching deviation data, and comprehensively establish an authentication field matching feature matrix by combining the matching features of fixed fields and dynamic fields.
[0024] As a further solution of the present invention, the specific steps of S3 are as follows:
[0025] S311: Based on the authentication field matching feature matrix, perform field arrangement order verification on the authentication request data, analyze the storage order of the fields, and check the offset of the field arrangement to obtain a field order offset record.
[0026] S312: According to the field order offset record, and compare whether the storage offset of the authentication field conforms to the authentication field mapping result, using the formula:
[0027] ;
[0028] Calculate the field matching consistency metric value , and combine the threshold to set the matching standard to obtain the authentication field matching analysis result, where represents the storage position of the th field, represents the standard storage offset position of the th field, represents the storage step of the th field, represents the total number of authentication fields;
[0029] S313: Based on the authentication field matching analysis result, analyze the legitimacy degree of the authentication request and output the authentication request legitimacy data.
[0030] As a further solution of the present invention, the specific steps of S4 are as follows:
[0031] S411: Read the authentication request legitimacy data, parse the current session data, extract the message content, message order and time characteristics, calculate the time interval, transmission delay and data consistency between messages, and obtain the session time characteristic parameters.
[0032] S412: According to the session time characteristic parameters, and judge whether there is a topic change in the conversation content before and after the current authentication request, using the formula:
[0033] ;
[0034] Calculate and output the session topic consistency coefficient , analyze the correlation matching value between the current session and the historical session, and judge whether the topic has changed according to the threshold, where The feature vector representing the b-th current session message, The feature vector representing the b-th historical session message, representing the total number of messages participating in the calculation;
[0035] S413: Based on the session topic consistency coefficient, combined with the session time feature parameter, comprehensively calculate the session authentication continuity of the authentication request, and obtain the session authentication continuity analysis result.
[0036] As a further solution of the present invention, the method further includes S5;
[0037] S5: According to the session authentication continuity analysis result, calculate the context consistency value of the authentication request, judge the deviation degree of the user's keyword usage, calculate the credibility of the verification request, adjust the verification strength of the authentication, and re-perform user authentication.
[0038] As a further solution of the present invention, the specific steps of S5 are:
[0039] S511: Based on the session authentication continuity analysis result, calculate the context consistency value of the authentication request, analyze the keyword distribution, semantic features and context relationship in the current session, extract the context feature parameter, and obtain the context consistency value;
[0040] S512: According to the context consistency value, judge the deviation degree of the user's keyword usage, calculate the semantic change range, and combine the historical session data to analyze the keyword stability, evaluate the context matching degree of the authentication request, and obtain the authentication request credibility;
[0041] S513: Based on the authentication request credibility, adjust the verification strength of the authentication, and perform re-verification of the user identity.
[0042] A user authentication system for a communication software, including:
[0043] The authentication field mapping module is used for S1: obtaining the authentication request data packet in the communication protocol, decoding the authentication field information, extracting the fixed field, dynamic field and variable field, calculating the data bit offset value, performing structure mapping and obtaining the authentication field mapping result;
[0044] The authentication feature matching module is used for S2: according to the authentication field mapping result, calculating the matching feature for the fixed field, performing permutation sequence verification on the data packet format, establishing a field matching rule, parsing the data range of the dynamic field, calculating the time span value of the timestamp field, judging whether the timestamp field meets the time matching reference value, calculating the correlation matching degree between variable fields, and comprehensively establishing an authentication field matching feature matrix;
[0045] The authentication legality analysis module is used for S3: Based on the authentication field matching feature matrix, perform field arrangement order verification on the authentication request data, calculate the field matching consistency metric value, compare whether the storage offset of the authentication field conforms to the authentication field mapping result, calculate the legality degree of the authentication request, and output the authentication request legality data;
[0046] The session continuity detection module is used for S4: Read the authentication request legality data, parse the current session data, calculate the correlation degree between the current session and the historical session data, determine whether there is a topic change, and obtain the session authentication continuity analysis result;
[0047] The authentication credibility evaluation module is used for S5: According to the session authentication continuity analysis result, calculate the context consistency value of the authentication request, judge the deviation degree of the user keyword usage, calculate the context consistency value of the authentication request, adjust the verification intensity of the authentication and re-perform the authentication.
[0048] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0049] In the present invention, through in-depth parsing of the authentication request data packet, the authentication field structure is extracted and mapped, so that the data formatting process accurately matches the preset field features, improving the parsing accuracy. According to the mapping result, a matching feature matrix is constructed, making the verification of data format and content more targeted, enhancing the judgment of field structure consistency, reducing the possibility of abnormal data bypassing verification, combining historical session data, analyzing the message content, order and time features, evaluating the coherence of the session, enhancing the adaptability of authentication to dynamic behaviors, and adjusting the authentication intensity based on context consistency calculation and keyword deviation degree judgment, enabling the authentication to dynamically adapt to user behavior changes, improving the interaction experience and enhancing security. Brief Description of the Drawings
[0050] Figure 1 is the main step flow chart of the present invention;
[0051] Figure 2 is the flow chart of step S1 of the present invention;
[0052] Figure 3 is the flow chart of step S2 of the present invention;
[0053] Figure 4 is the flow chart of step S3 of the present invention;
[0054] Figure 5 is the flow chart of step S4 of the present invention;
[0055] Figure 6This is the flowchart of step S5 of the present invention. Detailed implementation manners
[0056] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0057] In the description of the present invention, it should be understood that the orientation or positional relationships indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationships shown in the drawings. They are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more unless otherwise specifically defined.
[0058] Please refer to Figure 1 , a user authentication method for a communication software, including the following steps:
[0059] S1: Obtain an authentication request data packet in the communication protocol, decode the authentication field information, extract the fixed fields, dynamic fields and variable fields associated with the authentication, calculate the data bit offset value, perform an authentication field structure mapping, and obtain an authentication field mapping result;
[0060] S2: According to the authentication field mapping result, calculate the matching features for the fixed fields, perform an arrangement sequence verification on the data packet format, establish a field matching rule based on the protocol header information, analyze the data range of the dynamic fields, calculate the time span value of the time stamp field, set a time matching reference value according to the time interval of a normal authentication request, and determine whether the time stamp field conforms to the time matching reference value, calculate the associated matching degree between the variable fields, and comprehensively establish an authentication field matching feature matrix;
[0061] S3: Based on the authentication field matching feature matrix, perform a field arrangement order verification on the authentication request data, calculate the matching consistency value of the fields, compare whether the storage offset of the authentication fields conforms to the authentication field mapping result, calculate the legality degree of the authentication request, and output the authentication request legality data;
[0062] S4: Read the legality data of the authentication request, parse the current session data, extract the message content, message sequence, and time characteristics, calculate the data correlation degree between the current session and the historical sessions, determine whether there is a topic change in the conversation content before and after the current authentication request, and obtain the analysis result of session authentication continuity;
[0063] S5: According to the analysis result of session authentication continuity, calculate the context consistency value of the authentication request, determine the deviation degree of user keyword usage, calculate the credibility of the verification request, adjust the verification strength of the authentication, and re-perform user authentication.
[0064] The authentication field mapping result includes the field offset value, field structure relationship, and field decoding information. The authentication field matching feature matrix includes fixed field matching features, dynamic field data range, variable field association matching degree, and timestamp matching benchmark. The legality data of the authentication request includes the consistency of field arrangement order, the measurement value of field matching consistency, the storage offset matching situation, and the legality evaluation result. The analysis result of session authentication continuity includes message content correlation degree, message sequence matching degree, time feature consistency, and conversation topic change situation.
[0065] Please refer to Figure 2 , and the steps of S1 are as follows:
[0066] S111: Obtain the authentication request data packet in the communication protocol, decode the authentication field information, extract the fixed fields, dynamic fields, and variable fields associated with the authentication, calculate the data bit offset value, and obtain the authentication field position information;
[0067] To obtain the authentication request data packet in the communication protocol, it is necessary to parse the overall structure of the data packet, including the protocol header, payload part, and additional fields. Assume that in actual applications, the total length of the authentication request data packet is 1024 bytes, of which the protocol header occupies 64 bytes, and the rest is the data payload. Call the data packet parsing module to decode it to obtain the authentication field information. Assume that after parsing, it is found that the data packet contains three keyword fields: fixed field (F), dynamic field (D), and variable field (V), which are located at different offset addresses in the data packet. For example, the F field is located at offset address 128, the D field is located at offset address 256, and the V field is located at offset address 384. The corresponding field lengths are 16 bytes, 32 bytes, and 48 bytes respectively. Calculate the data bit offset value, that is, the offset of each field relative to the starting address of the data packet, which can be expressed as , , , and further obtain the offset relationship between fields, that is, calculate the interval distance between fields. For example , , these offset values are used for the structural mapping of subsequent authentication fields, and finally the position information of the authentication fields is obtained.
[0068] S112: Based on the position information of the authentication fields, perform structural mapping of the authentication fields, analyze the relative offsets of each field in the data packet and the correlation degree between fields, and use the formula:
[0069] ;
[0070] Calculate the offset error values of each authentication field , and obtain the mapping error data of the authentication fields, where represents the calculated offset of the th field, represents the theoretical offset of the th field, represents the standard offset unit of the th field, represents the importance weight of the th field, represents the total number of authentication fields;
[0071] Based on the position information of the authentication fields, perform structural mapping of the authentication fields. First, determine the relative offsets of each field in the data packet. Taking the F field as the reference, calculate the offsets of the D field and the V field relative to the F field, as calculated above , , and further calculate the correlation degree between each field. By analyzing the numerical change characteristics between fields. For example, set the value of the fixed field F to always be a certain preset identifier (such as 0xA5A5), the value of the dynamic field D is variable and depends on the user's identity information, such as a hash digest , the variable field V is then specifically transformed according to the value of D, such as . Assume that the V field is stored using a specific encryption method, for example (K is the key), calculate the offset error of each field. Assume the theoretical offset value is , , .
[0072] Combined with the formula, substitute the actual values. Let the standard offset unit , the weight , , , the basis for setting the weights lies in the importance weight distribution of the fields. Among them, the F field is a fixed field and plays a fundamental role in the authentication process. It is necessary to ensure its accuracy, so the weight is set to the highest value of 0.4. The D field and the V field both belong to the dynamic part. Compared with the F field, their stability is slightly lower, but they equally affect the overall authentication structure. Therefore, both of them are set with a weight of 0.3. The change of this value is affected by the adjustment of the overall structure of the data packet. If the number of dynamic fields in the data packet increases, the weight of the D field will decrease relatively to maintain the proportional distribution with a sum of 1. If the fixed field F involves other auxiliary fields due to protocol adjustment, its weight may be further increased to 0.5 to ensure that the accuracy of the fixed field takes precedence over the dynamic field. The calculation is as follows:
[0073] ;
[0074] Obtain the offset error value , indicating that the mapping error of the current field structure is zero, that is, all fields conform to the theoretical offset value, as shown in Table 1:
[0075] Table 1 Offset Calculation Table for Authentication Fields
[0076]
[0077] As shown in Table 1, all fields are within the theoretical offset range, and obtain the mapping error data of the authentication fields.
[0078] S113: Based on the mapping error data of the authentication fields, adjust the structural relationship of the authentication fields, match the field mapping rules, and obtain the mapping result of the authentication fields;
[0079] Based on the mapping error of the authentication fields, adjust the structural relationship of the authentication fields. If the mapping error exceeds the acceptable range, adjust the data storage format to make the field offset conform to the theoretical value. For example, if it is detected that the offset value of the D field changes to 272 (the theory is 256), the error is 16 bytes. It is necessary to adjust the data packet storage structure, set the D field to realign to the 256 offset, and at the same time match the final field mapping rules. The specific adjustment methods include recalculating the storage order between fields or adding padding bytes. Assume that the number of added padding bytes satisfies:
[0080] ;
[0081] Since the negative value indicates that the position of the D field is advanced, the offset can be adjusted by inserting 16 bytes of padding data after the F field, as shown in Table 2 below:
[0082] Table 2 Comparison Table of Field Storage Before and After Adjustment
[0083]
[0084] Refer to Table 2. After adjustment, the D field is successfully aligned to the theoretical offset of 256, and at the same time, the V field is moved forward by 16 bytes accordingly, and finally the authentication field mapping result is obtained.
[0085] Please refer to Figure 3 , and the steps of S2 are as follows:
[0086] S211: Based on the authentication field mapping result, calculate the matching features for the fixed fields, extract the field values of the fixed fields, and count the matching patterns to determine the fixed field matching rate and obtain the fixed field matching features.
[0087] Based on the authentication field mapping result, obtain the fixed fields and calculate the matching features. The fixed fields usually include information such as the identifier, version number, source address, and destination address in the protocol header. The number and arrangement of fixed fields for different protocols are different. Therefore, these fields need to be extracted, and the occurrence frequency of these fields in the data packet is counted. By analyzing the distribution law of these fields in the legal authentication request, a matching feature matrix of the fixed fields can be constructed. Assume that the fixed fields of a data packet include (A, B, C), then count their occurrence probabilities in different data packets. For example, data packet 1 contains A, B, C, data packet 2 contains A, B, and data packet 3 only contains C. The counted matching probabilities are as follows:
[0088] Table 3: Matching Probability Table
[0089]
[0090] As shown in Table 3, the matching probability reflects the distribution law of the fixed fields in the data packet. In order to set the fixed field matching threshold, a probability statistical method is used to calculate the minimum probability requirement for data packet matching, and the setting formula is as follows:
[0091] ;
[0092] Set to reduce the impact of low-matching data.
[0093] Calculate the fixed field matching probability for each data packet:
[0094] Data packet 1: ;
[0095] Data packet 2: ;
[0096] Data packet 3: ;
[0097] Substitute into the formula for calculation:
[0098] ;
[0099] ;
[0100] The calculation results show that the matching threshold is set to 0.6167, which means that the matching probability of the fixed fields of the data packet needs to be greater than 61.67% to meet the authentication matching requirements. The setting of this value is based on the stability of the fixed fields of the data packet. Usually, the matching probability fluctuates with the change of the protocol version and the adjustment of the data packet format. When it is lower than 61.67%, it indicates that the fixed field matching is unstable, and there may be abnormal protocol formats or attack behaviors. A matching degree above 61.67% is usually the trusted range of normal protocol matching, and thus the fixed field matching characteristics are obtained.
[0101] S212: According to the fixed field matching characteristics, establish field matching rules based on the protocol header information, parse the data range of the dynamic fields, and count the time span value of the timestamp field. Use the formula:
[0102] ;
[0103] Calculate the time matching deviation value , combine the time interval of the normal authentication request to set the time matching reference value, and judge whether the timestamp field meets the time matching reference value to obtain the time matching deviation data, where represents the represents the time value of the previous timestamp field, represents the number of timestamp fields, represents the number of time points for calculating the time span;
[0104] Invoke the fixed field matching characteristics, establish field matching rules based on the protocol header information, parse the data range of the dynamic fields, and calculate the time span value of the timestamp field. In the authentication protocol, the timestamp field is used to record the sending time and receiving time of the data packet, usually in milliseconds or seconds. To analyze the time span of the timestamp field, set the timestamp sequence of the data packet (unit: second) as follows:
[0105] ;
[0106] Use the formula to calculate the data packet time span value:
[0107] ;
[0108] ;
[0109] ;
[0110] Set a time matching reference value based on the calculation result. For example, if the time interval for a normal authentication request is 3.0 seconds ± 0.5 seconds, then the time matching reference value is , and the currently calculated time matching deviation value is 3.16, which meets the matching reference.
[0111] S213: Calculate the association matching degree between variable fields based on the time matching deviation data, and comprehensively establish an authentication field matching feature matrix by combining the matching characteristics of fixed fields and dynamic fields;
[0112] Calculate the association matching degree between variable fields based on the time matching deviation value. Variable fields refer to the fields in the data packet that change over time or under specific conditions. For example, fields such as the session ID and encryption signature in some authentication requests need to be matched according to dynamic rules. In practical applications, there may be a certain association between the session IDs of different data packets. For example, the change pattern of the session ID can be calculated for its matching degree through sequence analysis. Set the variable field set of a certain data packet as follows:
[0113] ;
[0114] Calculate the change matching degree between each field and its previous field. For example, assume that a certain matching rule calculates the matching degree as follows:
[0115] Table 4: Matching degree data
[0116]
[0117] As shown in Table 4, the matching degree of variable fields between different data packets is above 80%, which can be considered as a relatively high matching degree. This matching degree threshold is derived from the stability measurement of protocol field matching. In a general network environment, a matching degree below 80% indicates a large change in fields, which may be an abnormal data packet or an attack behavior. A matching degree above 80% can be regarded as the feature matching range of a normal authentication request. Combine the matching characteristics of fixed fields and dynamic fields to comprehensively establish an authentication field matching feature matrix.
[0118] Please refer to Figure 4 , and the steps of S3 are as follows:
[0119] S311: Based on the authentication field matching feature matrix, perform field arrangement order verification on the authentication request data, analyze the storage order of the fields, and check the offset of the field arrangement to obtain the field order offset record;
[0120] Based on the authentication field matching feature matrix, in the actual scenario, the field arrangement order of the authentication request data packet needs to be executed according to the protocol specifications. First, extract the field set of the data packet and compare it according to the predetermined storage order. For example, the user authentication request in a certain system contains fields such as username, user ID, timestamp, session key, etc., then read and extract these fields according to the protocol storage order, calculate the storage location of the fields, and extract the actual storage offset of each field through the index value of the storage address. As shown in Table 5, this table lists the field storage addresses and corresponding offsets of different requests, and further calculates the offset degree of each field relative to the protocol standard storage order. The calculation formula is as follows:
[0121] ;
[0122] Among them, represents the offset of the th field, represents the actual storage address of the th field, represents the standard storage address of the th field. As shown in Table 5, assume that the username field of a certain data packet is stored at address 1000, while the standard address is 980, then the offset is . After calculating the offsets of all fields, count the offset situations of each field to obtain the field order offset record.
[0123] Table 5 Field Storage Address and Offset Table
[0124]
[0125] As shown in Table 5, the storage offsets of different fields are different. Excessive storage offset may lead to invalid or abnormal verification requests, and subsequent steps need to be further processed based on this result.
[0126] S312: According to the field order offset record, and compare whether the storage offset of the authentication field conforms to the authentication field mapping result, using the formula:
[0127] ;
[0128] Calculate the field matching consistency metric value , and combine the threshold to set the matching standard to obtain the authentication field matching analysis result. Among them, represents the storage location of the th field, represents the standard storage offset location of the th field, represents the storage step of the th field, Represents the total number of authentication fields;
[0129] Offset the data according to the field order, further calculate the matching consistency value of the fields, and compare whether the storage offset of the authentication fields conforms to the authentication field mapping result. In the authentication system, the storage order of different fields should preferably conform to the protocol specification, otherwise, authentication failure may be caused. Therefore, it is necessary to calculate the matching consistency of each field, analyze the offset of each field in different data packets through multiple data packet samples. As shown in Table 5, substitute into the formula to calculate the matching consistency value.
[0130] Suppose 4 data packets are received. As shown in Table 5, the field storage addresses of each data packet are different. Calculate the sum of the squared errors of the storage positions of each field and perform normalization processing to obtain the matching degree value. For example:
[0131] ;
[0132] The calculated matching degree can be used to determine whether the field order of the data packet conforms to the protocol storage specification. The setting basis of the matching degree threshold of 200 lies in the offset tolerance range of different fields in the protocol. Usually, a certain small floating is allowed for the storage position of the field. For example, an offset within 10% will not affect the parsing of the data packet, while exceeding this range may cause the parsing of the data packet to fail. Therefore, this threshold is determined according to the maximum acceptable error range of the fields in the data storage structure and varies with different data packet types. For example, for key security fields (such as encryption keys, session tokens), the allowed offset range is smaller, and a lower threshold can be set. If the matching degree value is lower than the set threshold (for example, 200), it means that the field arrangement of the data packet is more in line with the standard, and a higher matching degree indicates a larger deviation in the field order.
[0133] Table 6 Field storage addresses of different data packets
[0134]
[0135] As shown in Table 6, the field storage addresses of the data packet have a slight deviation, but generally conform to the protocol standard. The further calculated matching consistency value is used to analyze the degree of deviation of the storage order of the data packet, and finally, the analysis result of the authentication field matching degree is obtained.
[0136] S313: Based on the analysis result of the authentication field matching, analyze the legitimacy degree of the authentication request and output the authentication request legitimacy data;
[0137] Based on the analysis results of the authentication field matching degree, calculate the legitimacy degree of the authentication request and output the authentication request legitimacy data. During the authentication process, it is necessary to set the threshold of the field matching degree. The basis for setting the matching degree threshold of 150 lies in the tolerance range of the system for different request types. For example, for standard authentication requests, the field order deviation usually does not exceed 5%. If the matching degree value exceeds this threshold, it means that the field storage deviation has exceeded the normal range preset by the protocol, which may involve tampering or malicious attacks. Specifically in the calculation, the threshold can be adjusted according to different user levels. For example, for ordinary user requests, the threshold is set to 150, while for administrator-level authentication requests, the matching degree tolerance range is lower, and the threshold can be set to 120. If the calculated matching degree is lower than this threshold, the request can be considered a legitimate authentication request; otherwise, there may be abnormalities. In the actual scenario, the server side will calculate the matching degree for a large number of request data packets and compare the calculation results with the legitimacy threshold. For example:
[0138] ;
[0139] Since the matching degree does not exceed the set threshold, this authentication request is not marked as suspicious. If the calculated , the corresponding authentication request is marked as suspicious, and other security policies need to be combined, such as user behavior analysis, historical request records, etc., to determine whether the request is valid. Finally, the authentication request legitimacy data is output for subsequent security policy processing.
[0140] Please refer to Figure 5 , and the steps of S4 are as follows:
[0141] S411: Read the authentication request legitimacy data, parse the current session data, extract the message content, message order, and time characteristics, calculate the time interval, transmission delay, and data consistency between messages, and obtain the session time characteristic parameters;
[0142] To read the legitimacy data of the authentication request, it is necessary to first obtain the legitimacy detection result in the authentication request data packet. This result is derived from the comprehensive judgment of the matching degree of the authentication field and related information in the previous steps. In actual application scenarios, the authentication requests of different devices at different time nodes can be obtained through a network traffic monitoring system, and the legitimacy tags therein can be extracted. For example, a certain server receives three authentication requests at 10:05, 10:07, and 10:12 respectively. The matching degrees of the first two requests both exceed 90% of the threshold setting, and the matching degree of the third request is as low as 65%. Then, it can be determined that the first two requests have relatively high legitimacy, while the third request may pose a risk of abnormal or illegal requests. Subsequently, when parsing the current session data, it is necessary to extract data from the session where the current authentication request is located. The main extraction contents include the message content, message order, and time characteristics. In actual operation, for a specific application scenario, such as the authentication log in a financial trading system, the operation records of a user's consecutive logins can be extracted. Suppose a user requests to access account information at 10:01, conducts a fund transfer at 10:03, and queries the transaction record at 10:05. Then, the time characteristic of this session can be determined as high-frequency access in a short time. If the user suddenly attempts to modify critical account information at 10:20, this operation may not conform to the aforementioned high-frequency access pattern in a short time, and further analysis of the session relevance is required. Calculating the time interval between messages can be performed by recording the timestamps of each message and calculating the time difference between adjacent messages. For example, if the consecutive three request times of a certain user are 10:01:05, 10:01:10, and 10:01:25 respectively, the time interval between the first two requests is 5 seconds, and the time interval between the second and third requests is 15 seconds. By calculating the average time interval and standard deviation, it can be determined whether the current session maintains a certain interaction rhythm. The transmission delay can be calculated by comparing the timestamps of the server side and the client side. For example, if the client sends a request at 10:01:30 and the server receives and processes it at 10:01:32, the transmission delay of this request is 2 seconds. Data consistency can be measured by verifying the data correlation degree between different messages in the session. For example, in an e-commerce trading platform, if the order amount submitted by the user during the commodity purchase process is consistent with the amount in the payment request, the data consistency is relatively high; otherwise, an abnormal judgment is required. Based on the above analysis, the session time characteristic parameters are obtained.
[0143] S412: According to the session time characteristic parameters, and determine whether there is a topic change in the conversation content before and after the current authentication request, using the formula:
[0144] ;
[0145] Calculate and output the session topic consistency coefficient , analyze the correlation matching value between the current session and the historical sessions, and determine whether the topic has changed based on a threshold. Among them, represents the feature vector of the b-th current session message, represents the feature vector of the b-th historical session message, represents the total number of messages participating in the calculation;
[0146] Based on the session time feature parameters, calculate the data correlation degree between the current session and the historical sessions, and determine whether there is a topic change in the conversation content before and after the current authentication request. In an actual application scenario, the continuous email interaction pattern of users can be analyzed for the enterprise internal email system. For example, if an employee sends 5 emails on a certain working day, and the first 4 emails are all related to market analysis, and the 5th email suddenly involves the modification of financial data, then there may be a topic change and further analysis of its relevance is needed. The calculation of the session data correlation degree can adopt the time series similarity calculation method, considering the time distribution of messages, content vectors, and keyword matching situations. When calculating specifically, first perform text vectorization processing on the message content in the current session. Suppose a session contains 3 messages, and their vector representations are as follows: , , , and the corresponding message vectors in the historical session are represented as , , , where , substitute the values for calculation:
[0147] ;
[0148] Finally, the calculated . The setting of the preset threshold is based on the statistical analysis of historical session data, and this value changes with the similarity of session message content, the degree of message keyword matching, and the fluctuations of historical session patterns. After statistically analyzing a large amount of normal session data, the mean value of the calculated session topic consistency coefficient is about 0.73, and the standard deviation is 0.12. Therefore, the threshold is set to 0.7, so that normal sessions and abnormal sessions can be effectively distinguished within a 99% confidence interval. Since the calculated value is higher than 0.7, it can be judged that this session and the historical session have a high consistency in topic, and the session topic consistency coefficient is obtained.
[0149] S413: Based on the session topic consistency coefficient, combined with the session time feature parameters, comprehensively calculate the session authentication continuity of the authentication request, and obtain the analysis result of the session authentication continuity;
[0150] Based on the session topic consistency coefficient and combined with the session time characteristic parameters, comprehensively calculate the session authentication continuity of the authentication request. In practical applications, for example, in a banking system, if a user continuously performs account inquiries, fund transfers, and credit card repayments within a short period of time, these operations usually belong to a highly continuous session. However, if a fund transfer is made first and then an attempt is made to modify the account password within a short period of time, it may indicate an abnormality in session continuity and further review is required. During the calculation process of authentication continuity, first calculate the time interval distribution based on the session time characteristics. Set the time interval threshold to 5 minutes. If a user performs multiple authentications within 1 minute, it can be determined as a highly continuous behavior. Then, judge the consistency of the message content based on the session topic consistency coefficient. Assume that the topic consistency coefficient , higher than the threshold of 0.7, then it can be further determined that the session is a session with a relatively high consistency. Finally, perform a weighted calculation by combining the two:
[0151] ;
[0152] where, is the time matching degree, and through similarity calculation it is 0.9, then
[0153] ;
[0154] The setting basis of the preset continuity determination threshold is based on the analysis and statistics of a large amount of normal session data. This value is mainly affected by session time characteristics, session content similarity, and abnormal session detection results. After classifying 50,000 normal sessions and 5,000 abnormal sessions, the calculated mean value of the highly continuous session distribution is 0.82, and the standard deviation is 0.07. Therefore, set 0.8 as the determination threshold so that abnormal sessions can be effectively excluded within a 98% confidence interval and the occurrence of misjudgment can be reduced. Since the calculated 0.88 is higher than the threshold of 0.8, it can be determined that this session belongs to a highly continuous authentication behavior, and the analysis result of session authentication continuity is obtained.
[0155] Table 7 Session Time Characteristic Data
[0156]
[0157] As shown in Table 7, there are certain changes in the time characteristics of different sessions. Among them, the topic consistency coefficients of sessions 1001 and 1003 both exceed 0.8, indicating a relatively high authentication continuity of the sessions, while the topic consistency coefficient of session 1002 is relatively low and its legitimacy needs to be further analyzed.
[0158] Please refer to Figure 6 , and the S5 step is:
[0159] S511: Calculate the context consistency value of the authentication request based on the analysis result of session authentication continuity. Analyze the keyword distribution, semantic features, and context relationship in the current session, extract context feature parameters, and obtain the context consistency value.
[0160] Based on the analysis result of session authentication continuity, first extract the key context features in the authentication request, including word frequency, syntactic structure, and the correlation relationship between words, and calculate the usage of keywords involved in the current request. Subsequently, establish a set of context feature parameters, where keywords can be transformed through a word vector model to obtain the similarity score between different words. For example, in the enterprise authentication scenario, if an employee often uses terms such as "remote login" and "work email" during normal authentication, but uses deviated words such as "system management" and "privileged access" under abnormal circumstances, then calculate its context consistency value. In addition, it is also necessary to parse the context to determine the semantic relationship between the current authentication request and the historical request. For example, if a user has been performing business-related authentication in the previous session and suddenly a non-business-related request appears, such as accessing sensitive system permissions, it may indicate an anomaly. Combine the historical session data, calculate the context matching degree using the cosine similarity of keyword semantic vectors, perform weighted summation on the calculated similarity of each keyword, and finally obtain the context consistency value. This value is used to determine whether the current authentication request conforms to the user's daily behavior pattern and obtain the context consistency value.
[0161] S512: According to the context consistency value, judge the deviation degree of the user's keyword usage, calculate the semantic change range, and combine the historical session data to analyze the keyword stability, evaluate the context matching degree of the authentication request, and obtain the authentication request credibility.
[0162] According to the context consistency value, further analyze the deviation degree of the user's keyword usage, calculate the semantic change range, and evaluate the context matching degree of the authentication request. First, extract the set of keywords used by the user at different time periods, calculate the occurrence frequency of these keywords in historical authentication requests, and count their deviation degrees. For example, in a banking system, if a user usually uses keywords such as "transfer" and "balance query" during the login process, and the keywords in this authentication request change to "server access" and "remote management", etc., it is necessary to calculate the keyword deviation degree and judge its abnormality according to the set reference value. The keyword deviation degree can be measured by calculating the Jaccard similarity between the keyword set of the current request and the keyword set of the historical request. The setting of this threshold is based on the keyword stability analysis of the actual business scenario. The specific calculation method is to count the Jaccard similarity of all normal authentication requests within a month and take the 5th percentile of this distribution as the anomaly threshold to ensure that more than 99% of the normal requests will not be misjudged as abnormal. After statistical analysis, in the enterprise authentication environment, this threshold usually ranges from 0.25 to 0.35, so it is set to 0.3 to ensure the effectiveness of anomaly detection. In addition, combined with the context change trend, analyze the semantic conversion mode of different authentication requests. For example, in a long time span, the semantic change may be large, but the sudden change in a short time is usually more abnormal. Therefore, it is necessary to dynamically set the context matching threshold under different time windows. Specifically, for a short time window within 1 hour, the normal range of keyword similarity is usually between 0.6 and 0.8, while for a one-day time window, this range can drop to 0.4 to 0.6. If it is found that the context matching degree of the current request is lower than the set threshold (such as 0.3), it indicates that the current request may be abnormal and additional authentication measures need to be triggered. Finally, comprehensively obtain the authentication request credibility, which reflects the rationality of the current authentication request in terms of context matching, and obtain the authentication request credibility.
[0163] S513: Based on the authentication request credibility, adjust the verification intensity of the authentication and perform re-verification of the user identity;
[0164] Adjust the verification strength of authentication based on the credibility of the authentication request and re-perform user authentication. First, divide the authentication levels according to the credibility value. For example, when accessing the enterprise internal system, if the credibility value is higher than 0.8, single-factor authentication (such as password input) can be used. If the credibility value is between 0.5 and 0.8, two-factor authentication (such as SMS verification code) needs to be added. And if the credibility is lower than 0.5, advanced verification mechanisms such as biometric recognition or security challenge need to be adopted. The setting of the credibility threshold is based on the statistical analysis of the historical authentication success rate. The specific calculation method is to select the credibility distribution of all successful authentication requests in the past three months and use the 10th percentile as the trigger point for advanced verification and the 30th percentile as the trigger point for two-factor authentication. In the enterprise network environment, this threshold is usually set to 0.8, 0.5, and 0.3 and dynamically adjusted according to the data to reduce the misjudgment rate. In addition, during the process of adjusting the verification strength, the user's historical login behavior also needs to be combined. For example, if a user has always accessed the system from a fixed IP address and this request comes from a different IP, the authentication process needs to be dynamically adjusted in combination with the credibility calculation. Specifically, if more than 90% of the user's logins in the past 30 days come from a fixed IP address, when the IP changes, an additional reduction factor should be introduced in the credibility calculation, such as reducing the credibility score by 0.2 - 0.3, to reflect the mutation of the access behavior. Finally, obtain the user authentication adjustment parameter, which is used for optimizing the subsequent authentication process and obtaining the user authentication adjustment parameter.
[0165] Table 8 Example of calculating the context deviation degree of keywords
[0166]
[0167] As shown in Table 8, the occurrence frequencies of keywords such as remote login and account management in the historical session and the current request do not change much, while the usage frequency of "server access" suddenly increases, and the deviation degree reaches 0.80, indicating that there is a large deviation in the user's current authentication request.
[0168] Taking the calculation of authentication credibility as an example, assume that the keyword set of a user in historical authentication is {"login", "transfer", "balance query"}, and the keyword set in the current authentication request is {"remote management", "system access", "login"}, and calculate the Jaccard similarity:
[0169] ;
[0170] Among them:
[0171] X = {"login", "transfer", "balance query"};
[0172] Y = {"Remote Management", "System Access", "Login"};
[0173] Intersection: {"Login"}, size = 1;
[0174] Union: {"Login", "Transfer", "Balance Inquiry", "Remote Management", "System Access"}, size = 5;
[0175] Calculation result:
[0176] ;
[0177] This value is lower than the set confidence threshold of 0.3 and falls within the outlier range of the statistical data for the past month (the normal range is usually 0.25 - 0.35). Therefore, additional authentication measures, such as two - factor authentication or biometrics, need to be triggered to prevent potential unauthorized access.
[0178] A user authentication system for a communication software, comprising:
[0179] The authentication field mapping module is used for S1: Obtaining the authentication request data packet in the communication protocol, decoding the authentication field information, extracting the fixed fields, dynamic fields and variable fields, calculating the data bit offset value, performing structure mapping and obtaining the authentication field mapping result;
[0180] The authentication feature matching module is used for S2: According to the authentication field mapping result, calculating the matching features for the fixed fields, verifying the arrangement sequence of the data packet format, establishing the field matching rules, parsing the data range of the dynamic fields, calculating the time span value of the timestamp field, judging whether the timestamp field conforms to the time matching reference value, calculating the correlation matching degree between the variable fields, and comprehensively establishing the authentication field matching feature matrix;
[0181] The authentication legitimacy analysis module is used for S3: Based on the authentication field matching feature matrix, performing field arrangement order verification on the authentication request data, calculating the field matching consistency metric value, comparing whether the storage offset of the authentication fields conforms to the authentication field mapping result, calculating the legitimacy degree of the authentication request, and outputting the authentication request legitimacy data;
[0182] The session continuity detection module is used for S4: Reading the authentication request legitimacy data, parsing the current session data, calculating the correlation degree between the current session and the historical session data, judging whether there is a topic change, and obtaining the session authentication continuity analysis result;
[0183] The authentication credibility evaluation module is used for S5: according to the session authentication continuity analysis result, calculate the context consistency value of the authentication request, judge the deviation degree of the user keyword usage, calculate the context consistency value of the authentication request, adjust the verification strength of the authentication and re-perform the authentication.
[0184] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the art may use the disclosed technical content to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A user authentication method for a communication software, characterized in that, Including the following steps: S111: Obtain the authentication request data packet in the communication protocol, decode the authentication field information, extract the fixed fields, dynamic fields, and variable fields associated with authentication, calculate the data bit offset value, and obtain the authentication field position information; S112: Based on the authentication field position information, perform authentication field structure mapping, analyze the relative offsets of each field in the data packet and the association degree between fields, and use the formula: ; Calculate the offset error value of each authentication field , obtain the mapping error data of the authentication field, where represents the calculated offset of the th field, represents the theoretical offset of the th field, represents the standard offset unit of the th field, represents the importance weight of the th field, represents the total number of authentication fields; S113: Based on the authentication field mapping error data, adjust the structural relationship of the authentication fields, match the field mapping rules, and obtain the authentication field mapping result; S2: According to the authentication field mapping result, calculate the matching features for the fixed fields, perform permutation sequence verification on the data packet format, establish field matching rules, parse the data range of the dynamic fields, calculate the time span value of the timestamp field, determine whether the timestamp field meets the time matching reference value, calculate the association matching degree between the variable fields, and comprehensively establish an authentication field matching feature matrix; S3: Based on the authentication field matching feature matrix, perform field permutation order verification on the authentication request data, calculate the field matching consistency metric value, compare whether the storage offset of the authentication field conforms to the authentication field mapping result, calculate the legality degree of the authentication request, and output the authentication request legality data; S411: Read the authentication request legality data, parse the current session data, extract the message content, message order, and time characteristics, calculate the time interval, transmission delay, and data consistency between messages, and obtain the session time characteristic parameters; S412: According to the session time characteristic parameters, and determine whether there is a topic change in the conversation content before and after the current authentication request, and use the formula: ; Calculate the consistency coefficient of the output session topic , analyze the correlation matching value between the current session and the historical session, and judge whether the topic has changed according to the threshold. Among them, represents the feature vector of the th current session message, represents the feature vector of the th historical session message, represents the total number of messages participating in the calculation; S413: Based on the session topic consistency coefficient, combined with the session time characteristic parameters, comprehensively calculate the session authentication continuity of the authentication request, and obtain the session authentication continuity analysis result.
2. The user identity authentication method of the communication software according to claim 1, characterized in that, The authentication field mapping result includes field offset values, field structural relationships, and field decoding information. The authentication field matching feature matrix includes fixed field matching features, dynamic field data ranges, variable field association matching degrees, and timestamp matching references. The authentication request legality data includes field permutation order consistency, field matching consistency metric values, storage offset matching situations, and legality evaluation results. The session authentication continuity analysis result includes message content association degrees, message order matching degrees, time characteristic consistencies, and conversation topic change situations.
3. The user identity authentication method of the communication software according to claim 1, characterized in that, The specific steps of S2 are: S211: Based on the authentication field mapping result, calculate the matching features for the fixed fields, extract the field values of the fixed fields, and count the matching patterns to determine the fixed field matching rate and obtain the fixed field matching features; S212: According to the fixed field matching features, establish field matching rules based on the protocol header information, parse the data range of the dynamic fields, and count the time span value of the timestamp field, and use the formula: ; Calculate the time matching deviation value , set a time matching reference value in combination with the time interval of normal authentication requests, and determine whether the timestamp field conforms to the time matching reference value to obtain time matching deviation data, where represents the time value of the th timestamp field, represents the time value of the previous timestamp field, represents the number of timestamp fields, represents the number of time points for calculating the time span; S213: Calculate the association matching degree between variable fields based on the time matching deviation data, and comprehensively establish an authentication field matching feature matrix by combining the matching features of fixed fields and dynamic fields.
4. The user authentication method of the communication software according to claim 1, wherein The specific steps of S3 are as follows: S311: Based on the authentication field matching feature matrix, perform field arrangement order verification on the authentication request data, analyze the storage order of the fields, and check the offset of the field arrangement to obtain the field order offset record. S312: According to the field order offset record, compare whether the storage offset of the authentication field conforms to the authentication field mapping result, using the formula: ; Calculate the matching consistency metric value of the computed fields , and combine with the threshold setting to determine the matching criteria, and obtain the matching analysis result of the authentication fields, where represents the storage location of the th field represents the standard storage offset location of the th field represents the storage step of the th field represents the total number of authentication fields; S313: Based on the authentication field matching analysis result, analyze the legitimacy degree of the authentication request and output the authentication request legitimacy data.
5. The user identity authentication method of the communication software according to claim 1, characterized in that, The method further includes S5. S5: Calculate the context consistency value of the authentication request according to the session authentication continuity analysis result, judge the deviation degree of the user keyword usage, calculate the authentication request credibility, adjust the verification strength of the authentication, and re-perform user authentication.
6. The user identity authentication method of the communication software according to claim 1, characterized in that, The specific steps of S5 are as follows: S511: Calculate the context consistency value of the authentication request based on the session authentication continuity analysis result, analyze the keyword distribution, semantic features and context relationship in the current session, extract the context feature parameters, and obtain the context consistency value. S512: According to the context consistency value, judge the deviation degree of the user keyword usage, calculate the semantic change range, and combine the historical session data to analyze the keyword stability, evaluate the context matching degree of the authentication request, and obtain the authentication request credibility. S513: Based on the authentication request credibility, adjust the verification strength of the authentication and perform re-verification of the user identity.
7. A user authentication system for a communication software, characterized in that, The system for executing the method according to any one of claims 1-6 includes: The authentication field mapping module is used for S1: Obtain the authentication request data packet in the communication protocol, decode the authentication field information, extract the fixed field, dynamic field and variable field, calculate the data bit offset value, perform structure mapping and obtain the authentication field mapping result. The authentication feature matching module is used for S2: According to the authentication field mapping result, calculate the matching feature for the fixed field, perform arrangement sequence verification on the data packet format, establish a field matching rule, parse the data range of the dynamic field, calculate the time span value of the timestamp field, judge whether the timestamp field conforms to the time matching reference value, calculate the association matching degree between variable fields, and comprehensively establish an authentication field matching feature matrix. The authentication legitimacy analysis module is used for S3: Based on the authentication field matching feature matrix, perform field arrangement order verification on the authentication request data, calculate the field matching consistency metric value, compare whether the storage offset of the authentication field conforms to the authentication field mapping result, calculate the legitimacy degree of the authentication request, and output the authentication request legitimacy data. The session continuity detection module is used for S4: reading the legality data of the authentication request, parsing the current session data, calculating the correlation degree between the current session and the historical session data, determining whether there is a topic change, and obtaining the analysis result of session authentication continuity; The authentication credibility evaluation module is used for S5: according to the analysis result of session authentication continuity, calculating the context consistency value of the authentication request, determining the deviation degree of user keyword usage, calculating the authentication request credibility, adjusting the verification strength of authentication and re-performing authentication.
Citation Information
Patent Citations
Method and device for optimizing authentication and authorization system
CN118802549A
Method for automatically verifying security of communication software
CN119071073A