Code scanning payment security enhancement method based on ambient light sensor

By using ambient light sensors to collect data and train a random forest classifier, the security and privacy issues of scanning code payment in the existing technology are solved, and efficient and secure payment code payment verification is achieved.

CN119941248APending Publication Date: 2025-05-06XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510118761.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to effectively judge the effectiveness of the code scanning behavior and improve the security of payment code payment, especially when there are privacy issues and data processing complexity in motion sensor-based solutions.

Method used

The payment security enhancement method for scanning codes based on ambient light sensor is used. By collecting ambient light intensity data when the user displays the QR code, filling missing values ​​and non-uniform corrections are performed, signal characteristics are extracted and random forest classifiers are trained to determine whether the user has made payment gestures to confirm the effectiveness of the scanning code behavior.

Benefits of technology

It realizes that without increasing the user's operation burden, accurately judge the effectiveness of scanning code behavior, improve the security of payment code payment, and protect user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119941248A_ABST
    Figure CN119941248A_ABST
Patent Text Reader

Abstract

The invention discloses a code scanning payment security enhancement method based on an ambient light sensor. The method comprises the following steps: step 1, when a user displays a two-dimensional code to carry out passive code scanning payment, acquiring ambient light intensity data by using an ambient light sensor on a mobile phone, and obtaining a data sample; 2, carrying out missing value filling and non-uniform correction preprocessing operation on the ambient light sensor data sample; step 3, extracting signal features from the preprocessed ambient light sensor data sample, and training a random forest classifier by using the features in combination with payment gesture and non-payment gesture data sets; 4, when a payment request is received, the classifier is used for speculating whether the user makes a payment gesture or not, and therefore the validity of the code scanning behavior is confirmed. According to the method, the validity of the code scanning behavior can be accurately judged, the payment security of the payment code is improved, and meanwhile, the operation burden of the user is not increased or privacy concern is not caused.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and in particular relates to a code scanning payment security enhancement method based on an ambient light sensor (Ambient Light Sensor, ALS). Background Art

[0002] Payment security research covers many aspects, including secure payment systems, payment protocols and standards, payment application security, and mobile payment security. All of the above aspects are important contents that need to be considered and paid attention to in payment security research. Through comprehensive research and design, more secure and reliable payment systems and services can be established for users.

[0003] In 2016, Shrestha et al. designed a new gesture-centric NFC biometric authentication mechanism that is completely transparent to the user. The gesture of tapping a smartphone against an NFC terminal is a natural gesture that users make before making an NFC transaction. Because tapping is a biometric gesture that is unique to each user and difficult to imitate, it can be used to identify the user, making it impossible for unauthorized users to use NFC payments. The paper shows how to use multiple sensors of the phone and a machine learning classifier to extract the biometric features of the NFC payment gesture in a highly robust way.

[0004] Similarly, in 2022, Sturgess et al. showed that the tap gesture performed by a user when tapping a smartwatch against an NFC terminal to make a payment is a biometric feature that can implicitly authenticate the user and simultaneously identify payment intent. The proposed system can be deployed as software without requiring updates to payment terminals, is agnostic to terminal type and location, and the intent recognition part does not require any training data from users. The above two works significantly enhance the security of NFC transactions without adding any additional burden to users. However, their work mainly relies on motion sensors built into smartphones and smartwatches, and solutions based on motion sensors are prone to privacy issues.

[0005] At the same time, NFC payment is significantly different from QR code payment, which leads to obvious differences in user gestures when using NFC payment and QR code payment, and there is currently no research on QR code payment gestures.

[0006] The starting point of a payment gesture is difficult to determine in a payment code payment. Since most people usually hold their phones in their hands before making a payment code payment, it is very difficult to determine the starting point of a gesture in the continuously collected ambient light sensor data. At the same time, the position and posture of the phone in the hand may vary from person to person, and even for the same gesture, different people may start performing it in slightly different ways. The continuous collection of sensor data has little impact on the battery life of the phone, but it has a great impact on the gesture segmentation and classification tasks, which are difficult to complete with existing hardware. In addition, there is a lot of research on eavesdropping using motion sensors on mobile phones, so users may have privacy concerns about solutions based on motion sensors.

[0007] Secondly, compared with other mobile payment methods, such as NFC payment, payment code payment has greater directional changes. In NFC payment, users only need to bring their mobile phones close to the NFC terminal without changing the direction of the phone to complete the payment. However, in payment code payment, users need to align the payment code on their mobile phone with the scanning device, which requires users to follow the physiological movements of their wrists and arms until the phone is facing the scanning device. Considering the physiological conditions, payment gesture habits and the diversity of scanning device models of different users, these characteristics increase the complexity of payment code payment scenarios.

[0008] The operating system of a smartphone limits the sampling rate of ALS to a low level, usually below 20Hz. In addition, the ALS signal has unevenness and missing values, which further complicates data processing. Summary of the invention

[0009] In order to overcome the shortcomings of the above-mentioned prior art, the purpose of the present invention is to provide a method for enhancing the security of scanning code payment based on ambient light sensor, which can not only accurately judge the effectiveness of scanning code payment and improve the security of payment code payment, but also does not increase the user's operation burden.

[0010] In order to achieve the above object, the technical solution adopted by the present invention is:

[0011] A method for enhancing security of scanning code payment based on an ambient light sensor comprises the following steps:

[0012] Step 1: When the user displays the QR code for passive scanning payment, the ALS on the mobile phone is used to collect ambient light intensity data and obtain ALS data samples;

[0013] Step 2: performing preprocessing operations of filling missing values ​​and performing non-uniform correction on the ALS data samples;

[0014] Step 3: Extract signal features from the preprocessed ALS data samples, and train a random forest classifier using the signal features in combination with the payment gesture and non-payment gesture datasets;

[0015] Step 4: When receiving a payment request, the classifier is used to infer whether the user has made a payment gesture to confirm the validity of the scanning behavior.

[0016] The specific method steps for collecting ambient light intensity data in step 1 are:

[0017] 1.1): Unify the time servers of all devices and check the time on the time server before collecting ALS signals each time; check the error between the system time and the precise time through the time server to correct the transaction point timestamp, that is, the time point when the scanner records the reading of the QR code;

[0018] 1.2): Record the user's ALS signal on the mobile phone, and the barcode scanner records the transaction point timestamp;

[0019] 1.3): When the payment code payment is completed, gesture judgment is required. Only the data before the transaction point can be used for gesture judgment. In order to segment each payment gesture, the transaction point timestamp T is used. 0 As the right end point of each time window, the data in the time window of size s on the left side of the transaction point is regarded as a payment gesture, that is, the retrieval start time is T s Payment gestures, where T s =T 0 -s,T 0 It is also the end time;

[0020] The payment gesture is divided into an approach phase, an alignment phase, and a retraction phase;

[0021] In the approach phase, the user moves his arm and rotates his wrist to bring the smartphone closer to the scanning device and aim it at the code scanning device. Since the relative position of the smartphone ALS and the light source is constantly changing, a peak value will appear in this phase.

[0022] In the alignment stage, the distance between the smartphone and the barcode scanning device is relatively close, and the barcode scanning device will block the light from the light source in the environment from shining on the ALS, so the data value received by the ALS is at a lower level;

[0023] During the alignment phase, the light source of the scanner (guide light, fill light) will cause the light intensity received by the ALS to increase briefly;

[0024] The retraction phase is similar to the alignment phase. The action of retracting the smartphone will cause a peak in the ALS signal.

[0025] The step 2 is specifically as follows:

[0026] 2.1) The data points collected by ALS are used as sample points. When the change in the signal strength directly received by the sample point is smaller than the resolution of the smartphone ALS, the ALS cannot detect the change in light intensity and missing values ​​will appear in the sample. In this case, interpolation is used to fill in the missing values.

[0027] For example, in zero-order interpolation, the values ​​between two adjacent data points are set to the same value, which is usually the middle value of the two adjacent data points. 1 ,y 1 ) and (x 2 ,y 2 ), where x 1 <x 2 , the zero-order interpolation function f(x) is expressed as:

[0028]

[0029] In x 1 and x 2 In the interval between 1 , and in x 2 The function value at is equal to y 2 , the result of zero-order interpolation is a step-like function with the original data points as nodes;

[0030] Alternatively, the missing values ​​can be estimated by fitting the entire sample set (including the missing intervals) to a smooth curve using cubic spline interpolation;

[0031] When a set of data points (x 0 ,y 0 ),(x 1 ,y 1 ),...,(x n ,y n ) for cubic spline interpolation, it is required that at each adjacent data point (x i ,y i ) and (x i+1 ,y i+1 ) construct a cubic polynomial S i (x), so that in [x i ,x i+1 ]The interpolation function S(x) in the interval satisfies the following conditions:

[0032] Interpolation condition: S i (x i )=y i and S i (x i+1 )=y i+1, that is, the value of the interpolation function at the data point is equal to the function value of the given data point;

[0033] Smoothing condition: S′ i (x i+1 ) = S′ i+1 (x i+1 ) and S″ i (x i+1 )=S″ i+1 (x i+1 ), that is, the interpolation function of adjacent data segments is in x i+1 The first and second derivatives at are equal;

[0034] According to the above conditions, the cubic polynomial function S in each data segment is obtained. i (x), whose general form is:

[0035] S i (x) = a i (xx i ) 3 + b i (xx i ) 2 + c i (xx i ) + d i (2)

[0036] where a i ,b i ,c i ,d i is the unknown coefficient, which is solved according to the interpolation condition and smoothing condition;

[0037] The final cubic spline interpolation function is a collection of interpolation functions on all data segments:

[0038]

[0039] The cubic spline interpolation function S(x) constructed in this way is i The function value at the given data point is equal to the function value y i , and the first and second order derivatives at the data points are continuous, thus achieving a smooth interpolation effect.

[0040] 2.2) Non-uniformity correction: When the sampling of ALS in the smartphone is non-uniform, according to the Nyquist-Shannon sampling theorem, the N non-uniform samples (t i ,r i ) with sampling rate T′ s Converted into M uniform samples, the new sampling time point jT′ sThe value of p j The original data at time t i The degree of influence ij As shown below:

[0041]

[0042] Use element b ij The influence matrix B and the original sampling value r = (r 0 ,r 1 ,...,r N1 ) T , solve the value p=(p 0 ,p 1 ,...,p M-1 ) T :

[0043] p=(B T B) -1 B T r (5)

[0044] The uniform data p obtained according to formula (5) can be used to reproduce the original signal through the sampling theorem, giving f(t) as shown in the formula:

[0045]

[0046] The step 3 is specifically as follows:

[0047] 3.1): Build multiple different training data sets;

[0048] 3.1.1): Through a typical payment scenario, let the user interact with the barcode scanner and perform steps 1 and 2 to obtain payment gesture data. Repeat this process to obtain a payment gesture dataset;

[0049] 3.1.2): Simulate common non-payment scenarios, such as the gesture of holding a mobile phone while queuing, and perform steps 1 and 2 to obtain non-payment gesture data. Repeat this process to obtain a non-payment gesture dataset.

[0050] 3.2): Extract data signal features from the uniform data p in the training data set; signal features include statistical features, distribution features, frequency domain features and waveform features.

[0051] 3.3): Use the training data set to train different decision trees and form a random forest classifier. The random forest consists of multiple decision trees, each of which is trained based on a different data set and randomly selected features; in this classifier, all users' payment gestures are defined as positive samples, and all non-payment gestures are defined as negative samples; a ten-fold cross-validation method is used to make better use of the data and reduce the variance of the results, thereby improving the reliability of model evaluation.

[0052] The step 3.3) is specifically as follows:

[0053] 3.3.1): During the training of each decision tree, samples are randomly selected. If the number of samples is N, the number of samples selected is generally N' <N。

[0054] 3.3.2): When each node is split, a portion of the features are randomly selected from all M features to consider splitting. The number of features selected is

[0055] 3.3.3): Assume that the random forest contains T decision trees. For an input sample x, the final classification result is determined based on the voting results of all decision trees. If a sample x is classified as category c by the tth tree t The probability is p t (c t |x), the final classification result is:

[0056]

[0057] The statistical characteristics described in 3.1) include the maximum value, minimum value, peak-to-valley difference, median, mean, variance, standard deviation and interquartile range of the ALS samples;

[0058] The interquartile range is calculated by dividing the data set consisting of sample points into four equal parts. When calculating the interquartile range, you first need to find the upper quartile (Q1) and lower quartile (Q3) of the data set. The upper quartile is the value that 25% of the observations in the data set are less than or equal to, while the lower quartile is the value that 25% of the observations in the data set are greater than or equal to. Then, the interquartile range is calculated using the following formula:

[0059] IQR = Q3 - Q1 (7)

[0060] Among them, Q1 represents the lower quartile and Q3 represents the upper quartile.

[0061] The distribution characteristics include kurtosis, skewness, and peak count;

[0062] Kurtosis is a statistic that describes the sharpness of the peak of a probability distribution. It measures the sharpness of the peak of the probability distribution curve relative to the normal distribution curve. Kurtosis is the sharpness of the peak of the probability distribution curve of a random variable at the peak, reflecting the steepness of the distribution curve near the peak.

[0063] When the kurtosis value is greater than 0, the distribution curve is sharper than the normal distribution; when the kurtosis value is less than 0, the distribution curve is flatter than the normal distribution. If the kurtosis is equal to 0, it means that the shape of the distribution curve is similar to the normal distribution. Suppose the probability distribution function of the random variable is f(x), its mean is μ, its standard deviation is σ, and x i is the sample value, n is the number of samples, and the kurtosis Kurt is calculated by the following mathematical formula:

[0064]

[0065] Skewness indicates the degree to which the distribution curve deviates to the left or right from the mean. A skewness value greater than 0 indicates that the distribution curve is skewed to the right (positive skewness), while a skewness value less than 0 indicates that the distribution curve is skewed to the left (negative skewness). If the skewness is equal to 0, it means that the distribution curve is symmetric with respect to the mean. Suppose the probability distribution function of the random variable is f(x), its mean is μ, and its standard deviation is σ;

[0066] Skewness is calculated using the following mathematical formula:

[0067]

[0068] Peak counting first needs to find the peak value in the ALS signal. Assume there is an ALS signal f(x), where x is the time coordinate of the ALS signal and f(x) is the light intensity at that time point.

[0069] To find the peak in the ALS signal, you first need to define a condition for a local maximum. Then, use a search algorithm to find the local maximum that meets the condition in the ALS signal to determine the location of the peak.

[0070] Specifically, this work uses a window size of w to search for the local maximum. For each time point x in the ALS signal i , check the x i The signal value in the window centered at i ) is greater than the signal value of all other points in the window, then x i It is a local maximum, that is, a peak.

[0071] The frequency domain feature analyzes the ALS data from the frequency domain perspective of the signal to find important frequency information in the data. Discrete Fourier Transform (DFT) converts a discrete time domain signal into its frequency domain representation, and its formula is:

[0072]

[0073] The overall shape of the spectrum shows a gradually decreasing trend, representing an ALS signal with obvious main frequency components in the low-frequency region.

[0074] The waveform feature refers to the full-segment slope of the ALS signal at different stages. By extracting the slope feature, the n peaks and valleys of the ALS signal are first determined, and then the signal is divided into n-1 segments based on them. The peak-to-valley difference of each segment is then calculated. If the peak-to-valley difference is less than a preset threshold t, the segment is discarded, and then the full-segment slope of each segment is calculated, that is, the slope is calculated using the coordinates of the start and end points of the signal segment. If the slope is greater than 0, it is an ascending segment, and if the slope is less than 0, it is a descending segment. Finally, the number of ascending and descending segments is obtained, and the average slope of the ascending and descending segments is calculated.

[0075] Statistical features reflect the basic numerical properties of the signal: such as center position, fluctuation degree, symmetry and sharpness;

[0076] Distribution characteristics reflect the distribution form of signal values: such as frequency distribution, cumulative probability and probability density. Frequency domain characteristics reflect the characteristics of the signal in the frequency domain: such as frequency components, main frequencies, frequency centers, frequency distribution ranges and uniformity of frequency components;

[0077] Waveform characteristics reflect the morphology and dynamic characteristics of the signal: such as waveform shape, period, amplitude, rise time and fall time;

[0078] These features reflect the changing patterns of light sensor data caused by different payment gestures of users from different angles. By combining these features with random forests, the performance and interpretability of the model can be effectively improved.

[0079] The step 4 is specifically as follows:

[0080] 4.1): When the barcode scanner successfully scans the payment code and is ready to deduct the payment, it sends a request to the user account, including the transaction point timestamp;

[0081] 4.2): When the user's mobile phone receives a payment request, it reads the ambient light sensor data of a window size before the transaction point timestamp, such as 3 seconds;

[0082] 4.3): Execute step 1 and step 2 on the acquired ambient light sensor data to obtain processed uniform data;

[0083] 4.4): Perform step 3.1) on the data processed in step 4.3), extract features, and use the random forest model trained in step 3.2) to classify and determine whether the data corresponds to a payment gesture or a non-payment gesture;

[0084] 4.5): If the data before the transaction point timestamp corresponds to the payment gesture, the transaction proceeds normally;

[0085] 4.6): If the data before the transaction point timestamp corresponds to a non-payment gesture, the transaction is aborted.

[0086] Beneficial effects of the present invention:

[0087] The present invention uses the ambient light sensor data on the user's mobile phone and uses a time window method to define the payment gesture data range to correspond to the entire payment code payment process. This method can start from the transaction point timestamp and then expand the time window forward to capture the entire gesture movement process. This method maintains the continuity of the payment process without the need for additional hardware upgrades, improving the feasibility and practicality of the framework.

[0088] The present invention adopts methods such as filling missing values ​​and performing uneven correction on ALS signals. By taking these measures, the present invention can better utilize existing data, thereby improving the robustness and performance of the framework.

[0089] The present invention meets the user's demand for the convenience of payment code payment, and ensures the security of the payment code payment process and the protection of user privacy. Through a full understanding of the challenges and effective response, the present invention will make an important contribution to the development of QR code payment technology and provide users with a safer and more convenient payment experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0090] Figure 1 It is a schematic diagram of the process of the present invention.

[0091] Figure 2 Schematic diagram of the demographic data of the participants of the present invention.

[0092] Figure 3 This is a schematic diagram of the components of two code scanning devices of the present invention.

[0093] Figure 4 Schematic diagram of an ALS signal sample of the present invention.

[0094] Figure 5 Schematic diagram of the effect of the relative position of the light source and the ALS on the light intensity of the present invention.

[0095] Figure 6 This is the spectrum diagram of ALS signal.

[0096] Figure 7 This is the random forest structure diagram.

[0097] Figure 8 Schematic diagram of the impact of different lighting conditions on ALS data in horizontal mode.

[0098] Fig. 9 ALS data diagram for the backlight.

[0099] Fig.10 ALS data diagram in flip mode.

[0100] Fig.11 This is a schematic diagram of non-payment gesture data.

[0101] Fig.12 Schematic diagram of F1 scores under different time window sizes.

[0102] Fig.13 Schematic diagram of the impact of preprocessing methods on classifier performance. DETAILED DESCRIPTION

[0103] The embodiments of the present invention are further described in detail below with reference to the accompanying drawings.

[0104] like Figure 1 As shown, a method for enhancing security of scanning code payment based on ambient light sensor includes the following steps:

[0105] Step 1: Collect ambient light intensity data using the ALS of a smartphone;

[0106] The step 1 is specifically as follows:

[0107] ALS data collection,Different users have different payment gesture habits and physiological conditions, so a total of 42 participants were recruited to complete the data collection work to ensure the generalization ability of the solution.In order to cope with the diversity of code scanning device models and the complexity of payment code payment scenarios, 6 different scanner positions were set up in an environment with an average light intensity of about 300 lux (simulating a bright indoor environment) to collect ALS data during payment code payment gestures. At the same time, ALS data was also collected during non-payment periods (i.e., when queuing for checkout).

[0108] Before collecting, unify the time servers of all devices. Before collecting ALS signals each time, check the time on the time server. Check the error between the system time and the precise time through the time server to correct the transaction point timestamp, that is, the time when the barcode scanner records the reading of the QR code. Then, record the user's ALS signal on the mobile phone, and the barcode scanner records the transaction point timestamp. And use the transaction point timestamp T 0As the right end point of each time window, the data in the time window of size s on the left side of the transaction point is regarded as a payment gesture, that is, the retrieval start time is T s Payment gestures, where T s =T 0 -s,T 0 It’s also the end time.

[0109] (1) User research: Demographic data of 42 participants Figure 2 As shown. Among them, the participants included 26 males and 16 females with an average age of 32.1 years old, 2 of whom were left-handed for payment code payment, and 40 were right-handed for payment code payment. Each participant collected 1 set of data in each of the 6 setting scenarios. Each set of data requires the collection of 30 payment gestures of the participant. Participants will rest for 5 minutes during the 6 sets of data collection to avoid deformation of payment gestures caused by fatigue. 180 payment gestures were collected from each user, totaling 7,560 sample data. Participants were also asked to simulate queuing in their usual posture, and more than 35 hours of non-payment gesture data were collected. Among the participants, 97.6% said they used payment codes to pay every day, and 100% of the participants had used payment codes to pay. Payment gestures are intuitive, and during the data collection process, no differences were observed between participants who used payment codes to pay every day and those who did not use payment codes frequently.

[0110] (2) Introduction to barcode scanning equipment: The most common barcode scanning guns and barcode scanning boxes in real life were used as barcode scanning equipment in the ALS data collection process.

[0111] The barcode scanner is the M&G 2D imaging wired barcode scanner ADGN5073, the barcode scanning box is the Dazhen DZ668N, and the parts of the barcode scanning equipment are as follows: Figure 3As shown. The barcode scanner consists of a scanning window, an indicator light, a button, and a sound hole. The scanning window is a transparent window located at the front of the barcode scanner. It consists of a red LED guide light, a white LED fill light, and a photoelectric element (such as CCD or CMOS). Among them, the red light beam emitted by the red LED guide light is usually used as an auxiliary positioning to help users aim the barcode scanner at the barcode or QR code. The white LED fill light enhances the light and improves the scanning quality by providing an additional light source. The photoelectric element is responsible for capturing the image of the barcode or payment code. The barcode scanner is usually set to the key trigger mode by default. In this mode, the payee aims the barcode scanner at the product barcode or the payee's QR code and presses the button to start scanning. When the scan is completed, the LED of the scanning window will automatically turn off, and the indicator light will flash once. At the same time, the sound hole will emit a buzzer or other prompt sound to notify the user and the payee that the scan is completed. The barcode scanning box works similarly to the barcode scanning device, but it does not require the payee's interaction. In the induction mode, the payer needs to align the payment code on the smartphone screen with the scanning window of the scanning box, and its photoelectric element will capture the payment code image. After the decoding is completed, the fill light on the scanning window will flash once, and the speaker at the bottom of the scanning box will also emit a prompt sound.

[0112] (3) Scanner position setting: The scanner box is usually fixed in a certain position, but the position is variable. The specific scanner position settings are shown in Table 1. Among them, the placement height refers to the height from the ground to the lowest point of the scanner box. 100cm and 130cm represent the height of a person's waist and chest, respectively, which are also the most common placement heights of the scanner box. The tilt angle refers to the angle between the scanner box and the horizontal plane. 0° means that the scanner box is placed horizontally, and 90° means that the scanner box is perpendicular to the horizontal plane. Position G means using a scanner gun to scan the payment code. At this time, two participants need to interact to complete the scan.

[0113] Table 1 Scanner Position Settings

[0114]

[0115] Step 2: Preprocess the collected ALS data samples, including filling missing values ​​and performing non-uniform correction operations;

[0116] Missing value filling helps maintain the information integrity of the data set. The sampling rate of ALS is originally very low, and each sample may contain important information. If there are missing values, key patterns and regularities may be lost;

[0117] Non-uniform sampling may cause signal information in some areas to be oversampled, while other areas are undersampled. After correction, all parts of the signal can be sampled evenly, thus avoiding this bias and making the extracted features more representative of the true characteristics of the signal.

[0118] If the resolution of ALS is 1lux, then if the difference between the next sample point of ALS and the current sample point is less than 1lux, the received light intensity will not change;

[0119] In step 1, after the ALS signal is collected, the ALS signal needs to be preprocessed because the characteristics of ALS may cause some sample points to be missing.

[0120] The step 2 is specifically as follows:

[0121] The characteristics of ALS in smartphones include limited sampling frequency, non-uniform sampling, and missing values ​​in the sampled data. To address these characteristics, a signal correction method is used to fill in missing values ​​and correct for non-uniform sampling, thereby correcting the sampled data captured by ALS.

[0122] ALS signal description: Figure 4 An ALS signal sample collected. Among them, point 0 is the transaction point, that is, the time point when the payment code payment is completed, which is represented by a red line in the figure. According to this application, gesture judgment is required when the payment code payment is completed to confirm the validity of the code scanning behavior. Therefore, only the data before the transaction point can be used for gesture judgment. In order to segment each payment gesture, the transaction point timestamp T is used. 0 As the right end point of each time window, the data in the time window of size s on the left side of the transaction point is regarded as a payment gesture. That is, the retrieval start time is T s Payment gestures, where T s =T 0 -s,T 0 It’s also the end time.

[0123] Because in T 0 When the application framework needs to determine whether the user has the intention to pay, 0 After that, the transaction has been completed. According to the experimental situation, the time window size of 4 seconds is enough to encapsulate the entire content of each payment gesture.

[0124] In the approach phase, the user moves his arm and rotates his wrist to bring the smartphone closer to the scanning device and aim it at the barcode scanning device. In this process, since the relative position of the smartphone ALS and the light source is constantly changing, a peak value usually appears in this phase.

[0125] During the alignment phase, the distance between the smartphone and the barcode scanner is relatively close, so the barcode scanner will block the light from the ambient light source to the ALS, resulting in a lower data value received by the ALS. It is worth noting that during the alignment phase, the light source of the barcode scanner (guide light, fill light) will cause the light intensity received by the ALS to increase temporarily, because the barcode scanner will immediately turn off its own light source after reading the payment code information.

[0126] The retraction phase is similar to the alignment phase. The action of retracting the smartphone will cause a peak in the ALS signal. Since the retraction phase is the reverse process of the approach phase, the signal shows an overall axial symmetric feature.

[0127] Filling missing values: When the change in the signal intensity directly received by the sample point is smaller than the resolution of the smartphone ALS, the ALS cannot detect the change in light intensity and missing values ​​will appear in the sample. Interpolation can be used to fill missing values. Two methods of filling missing values ​​are used in this embodiment.

[0128] Use zero-order interpolation to fill missing values. Zero-order interpolation is also commonly known as nearest neighbor interpolation. It is a simple interpolation method that usually refers to using the values ​​of adjacent data points for approximation when interpolating between discrete data points. In zero-order interpolation, the values ​​between two adjacent data points are set to the same value, which is usually the middle value of the two adjacent data points. Suppose there are two adjacent data points (x 1 ,y 1 ) and (x 2 ,y 2 ), where x 1 <x 2 , the zero-order interpolation function f(x) can be expressed as:

[0129]

[0130] This formula means that in x 1 and x 2 In the interval between 1 , and in x 2 The function value at is equal to y 2 . Therefore, the result of zero-order interpolation is a step function with the original data points as nodes. Zero-order interpolation is often used to quickly approximate data, but it cannot capture the trend of changes between data because it assumes that the data remains unchanged throughout the interval between two adjacent data points. Its interpolation effect is as follows Figure 5 (a) shown.

[0131] In addition, the missing values ​​can also be estimated by fitting the entire sample set (including the missing intervals) to a smooth curve through cubic spline interpolation.

[0132] When a set of data points (x 0 ,y 0 ),(x 1 ,y 1 ),...,(x n ,y n ) for cubic spline interpolation, this work requires that at each adjacent data point (x i ,y i ) and (x i+1 ,y i+1 ) construct a cubic polynomial S i (x), so that in [x i ,x i+1 ]The interpolation function S(x) in the interval satisfies the following conditions:

[0133] Interpolation condition: S i (x i )=y i and S i (x i+1 )=y i+1 , that is, the value of the interpolation function at a data point is equal to the function value at the given data point.

[0134] Smoothing condition: S′ i (x i+1 ) = S′ i+1 (x i+1 ) and S" i (x i+1 )=S" i+1 (x i+1 ), that is, the interpolation function of adjacent data segments is in x i+1 The first and second derivatives at are equal.

[0135] According to the above conditions, the cubic polynomial function S in each data segment can be obtained i (x), whose general form is:

[0136] S i (x) = a i (xx i ) 3 + b i (xx i ) 2 + c i (xx i ) + d i (2)

[0137] where a i ,b i ,c i ,d iis an unknown coefficient, which can be solved according to the interpolation condition and smoothing condition.

[0138] The final cubic spline interpolation function is a collection of interpolation functions on all data segments:

[0139]

[0140] The cubic spline interpolation function S(x) constructed in this way is i The function value at the given data point is equal to the function value y i , and the first and second order derivatives at the data points are continuous, thus achieving a smooth interpolation effect. This interpolation method ensures the smoothness and continuity of the interpolation curve at the data points, making the interpolation result closer to the original data and effectively approximating the change trend of the original data. The interpolation effect is as follows Figure 5 (b) as shown.

[0141] Non-uniformity correction: When the sampling of the ALS in the smartphone is non-uniform, the N non-uniform samples (t i ,r i ) with sampling rate T′ s Converted into M uniform samples. The new sampling time point jT′ s The value of p j The original data at time t i The degree of influence ij As shown below:

[0142]

[0143] Next, you can use element b ij The influence matrix B and the original sampling value r = (r 0 ,r 1 ,...,r N1 ) T , solve the value p=(p 0 ,p 1 ,...,p M-1 ) T :

[0144] p=(B T B) -1 B T r (5)

[0145] The uniform data p obtained according to formula (5) can be used to reproduce the original signal through the sampling theorem, giving f(t) as shown in the formula:

[0146]

[0147] Step 3: Extract the preprocessed signal features and use these features to train the random forest classifier;

[0148] In order to improve the performance of the random forest classifier and the accuracy of data analysis, four key features covering multiple aspects were selected, including statistical features, distribution features, frequency domain features, and waveform features. The selection of these features not only helps to fully understand the characteristics and structure of ALS data, but also provides rich information for the random forest classifier, so as to better achieve the task of judging user payment gestures.

[0149] (1) Statistical characteristics: Statistical characteristics include the maximum value, minimum value, peak-to-valley difference, median, mean, variance, standard deviation and interquartile range of the ALS sample. Among them, the interquartile range (IQR) is a method of describing the degree of data dispersion in statistics. It represents the range of a set of values ​​around the median of a data set. The interquartile range can be calculated by dividing the data set into four equal parts. When calculating the interquartile range, you first need to find the upper quartile (Q1) and lower quartile (Q3) of the data set. The upper quartile is the value that 25% of the observations in the data set are less than or equal to, while the lower quartile is the value that 25% of the observations in the data set are greater than or equal to. Then, the interquartile range can be calculated using the following formula:

[0150] IQR=Q3-Q1 (7)

[0151] Among them, Q1 represents the lower quartile and Q3 represents the upper quartile. The interquartile range provides important information about the distribution of ALS data. It is not affected by outliers and can therefore be used to describe the degree of dispersion and deviation of ALS data.

[0152] These features can provide basic information about the distribution of ALS data, such as the center position, dispersion, and distribution shape of the data. Through these statistical features, we can quickly understand the overall situation of ALS data and conduct preliminary data exploration in the process of classifier establishment.

[0153] (2) Distribution characteristics: Distribution characteristics mainly include kurtosis, skewness and peak count. Kurtosis is a statistic that describes the sharpness of the probability distribution peak. It measures the sharpness of the peak of the probability distribution curve relative to the normal distribution curve. Specifically, kurtosis is the sharpness of the peak of the probability distribution curve of the random variable at the peak, reflecting the steepness of the distribution curve near the peak. When the kurtosis value is greater than 0, the distribution curve is sharper than the normal distribution; when the kurtosis value is less than 0, the distribution curve is flatter than the normal distribution. If the kurtosis is equal to 0, it means that the shape of the distribution curve is similar to the normal distribution. Suppose the probability distribution function of the random variable is f(x), its mean is μ, its standard deviation is σ, x i is the sample value, n is the number of samples. Kurtosis Kurt can be calculated by the following mathematical formula:

[0154]

[0155] Skewness is a statistic that describes the degree of skewness of a probability distribution. It measures the symmetry of the probability distribution curve relative to the normal distribution curve. Skewness can indicate the degree to which the distribution curve deviates to the left or right from the mean. A skewness value greater than 0 indicates that the distribution curve is skewed to the right (positive skewness), while a skewness value less than 0 indicates that the distribution curve is skewed to the left (negative skewness). If the skewness is equal to 0, it means that the distribution curve is symmetric relative to the mean. Let the probability distribution function of the random variable be f(x), its mean is μ, and its standard deviation is σ.

[0156] The skewness can be calculated by the following mathematical formula:

[0157]

[0158] The peak search algorithm is described in Algorithm 1:

[0159]

[0160] Peak counting first requires finding the peak in the ALS signal. Suppose there is an ALS signal f(x), where x is the time coordinate of the ALS signal and f(x) is the light intensity at that time point. To find the peak in the ALS signal, you first need to define the condition for a local maximum. Usually, the local maximum is required to meet certain conditions, such as it must be the maximum value in the local window, or it must be greater than a certain threshold. Then, a search algorithm can be used to find the local maximum that meets the conditions in the ALS signal, thereby determining the location of the peak. Specifically, assume that this work uses a window of size w to search for the local maximum. For each time point x in the ALS signal i , check the x i The signal value in the window centered at . i) is greater than the signal value of all other points in the window, then x i It is a local maximum, that is, a peak.

[0161] The peak search algorithm is described in Algorithm 1. In practical applications, the window size, threshold and other parameters can be adjusted as needed to obtain more accurate peak detection results. After all peaks are found, the number of peaks in the ALS signal can be obtained. The above distribution characteristics are of great significance for judging the non-normality and symmetry of ALS data, and help to more deeply understand the ALS distribution characteristics and potential laws of the data.

[0162] (3) Frequency domain features: Frequency domain features involve the total signal power of the ALS signal in the frequency domain. This feature can analyze ALS data from the frequency domain perspective of the signal and discover important frequency information in the data, thus providing a basis for subsequent frequency domain analysis and prediction. Discrete Fourier Transform (DFT) can convert a discrete time domain signal into its frequency domain representation. The formula is:

[0163]

[0164] Figure 6 This is the spectrum diagram of the ALS signal. The frequency component with the highest amplitude in the spectrum, that is, the amplitude at the frequency 0Hz is about 700, which is the largest amplitude value in the spectrum. Therefore, the frequency 0Hz may be the most important frequency component in the ALS signal. In addition, the energy of the spectrum gradually decreases with the increase of frequency. There is a large peak at the frequency 0Hz, and then it gradually decreases. The amplitudes of other peaks are smaller. Valley values ​​can be observed between the frequencies of 1Hz and 4Hz, and the amplitude gradually decreases. The overall shape of the spectrum shows a gradually decreasing trend, representing an ALS signal with obvious main frequency components in the low-frequency region.

[0165] (4) Waveform features: Waveform features refer to the full-segment slope of the ALS signal at different stages. By extracting the slope features, the local change trend in the ALS data can be captured, providing a more comprehensive data description for the classifier. These features can well reflect the change trend of the ALS signal in the approaching stage of the payment gesture, as well as the short-term rise of the ALS signal caused by the light source of the barcode scanner. First, the n peaks and valleys of the ALS signal are determined, and then the signal is divided into n-1 segments based on them. Then the peak-to-valley difference of each segment is calculated. If the peak-to-valley difference is less than the preset threshold t, the segment is discarded. Then the full-segment slope of each segment is calculated, that is, the slope is calculated using the coordinates of the start and end points of the signal segment. If the slope is greater than 0, it is an ascending segment, and if the slope is less than 0, it is a descending segment. Finally, the number of ascending and descending segments is obtained, and the average slope of the ascending and descending segments is calculated.

[0166] Use os.listdir to obtain all files in the folder that stores a user's payment data, traverse the folder that stores the low-sampling rate signal, and then traverse all files. At the same time, split the data of the payment gesture part according to the preset time window size. Then, calculate the four key features of the payment gesture data: statistical features, distribution features, frequency domain features, and waveform features; finally, store the features of each payment gesture in the form of a pandas library dataframe table, and then write it into a CSV file.

[0167] The same processing is performed on the fragments obtained after the continuous non-payment gesture data is segmented to extract the features of non-payment gestures. Random forest is an ensemble learning model built on decision trees. The core idea is to integrate multiple decision trees to perform classification or regression tasks, and then average or vote their results to obtain the final prediction result.

[0168] A decision tree is a tree structure in which each internal node represents a judgment of a feature attribute, each branch represents the output of a judgment result, and each leaf node represents a classification result or a regression value. The construction of a decision tree usually adopts the method of recursively splitting the data set to maximize the information gain or Gini impurity to select the splitting attribute. In the decision tree, the Gini Index can be used to select the best split point. The Gini Index is measured by measuring the probability that two samples are randomly drawn from the data set and the categories of the two samples are inconsistent. In the process of building a decision tree, the Gini Index can be used to select the best features and splitting points to maximize the purity of the node. For a data set containing multiple categories, assuming there are K categories, the Gini Index can be calculated by the following formula:

[0169]

[0170] Where D is the data set, p k It is the proportion of samples belonging to the kth category in the data set. The lower the Gini index, the higher the purity of the data set and the more consistent the categories of the samples; the higher the Gini index, the higher the impurity of the data set and the more dispersed the category distribution of the samples.

[0171] The random forest structure is shown in the figure Figure 7As shown, it is achieved by integrating multiple decision trees. Random Forest uses the Bootstrap Sampling method to draw a certain number of samples with replacement from the original training dataset to construct multiple different training datasets for training different decision trees. This can ensure that each decision tree is trained on a different dataset, increasing the diversity of the model. When splitting the nodes of each decision tree, Random Forest does not select the optimal feature for splitting among all features, but randomly selects a part of the features from all features. The purpose of this is to prevent some features from having too much influence on the model and increase the generalization ability of the model. Random Forest consists of multiple decision trees, and each tree is trained based on different datasets and randomly selected features. When making classification or regression predictions, Random Forest will integrate the prediction results of each tree. Common integration methods include the voting method (for classification problems) and the averaging method (for regression problems). This can reduce the variance of the model and improve the stability and generalization ability of the model.

[0172] Suppose there are N samples, M features, D is the dataset, and K is the number of classes. During the training process of each decision tree, samples are randomly drawn. If the number of samples is N, the number of samples drawn is generally N' < N. When splitting each node, a part of the features is randomly selected from the M features to consider for splitting. Generally, the number of features selected is For classification problems, assume that the Random Forest contains T decision trees. For the input sample x, the final classification result is determined based on the voting results of all decision trees. If a certain sample x is classified as class c t with a probability of p t (c t |x), then the final classification result is:

[0173]

[0174] Random Forest has been proven to be effective and has good robustness, capable of handling missing values and imbalanced data. Random Forest has good processing ability for high-dimensional data and large-scale datasets, is applicable to various types of datasets and problems, and can evaluate the importance of features during the training process to provide useful information.

[0175] The payment security enhancement solution of this application uses Random Forest to train a payment gesture classifier, and its training does not depend on a specific user.

[0176] In this classifier, all users' payment gestures are defined as positive samples, and all non-payment gestures are defined as negative samples. In this embodiment, a ten-fold cross validation method is used to make better use of data and reduce the variance of the results, thereby improving the reliability of model evaluation. In order to ensure that the classifier is not related to a specific user, in this embodiment, only the data of other users except the user are used to train the classifier.

[0177] In order to strike a balance between classifier performance and learning time, 100 trees are set in each forest in this embodiment. In order to reduce the impact of random factors on the results and avoid selecting results only from the optimal forest, each classifier is trained and tested ten times in this embodiment, each time using a different random seed, and the results are averaged.

[0178] Using the above method and steps, the ambient light sensor data corresponding to the payment gestures and non-payment gestures of 42 participants were processed to form a data set, and features were extracted. 90% of the data in the data set was used for training to obtain a random forest classifier.

[0179] Step 4: When receiving a payment request, the classifier is used to infer whether the user has made a payment gesture to confirm the validity of the scanning behavior.

[0180] Step 4 in this embodiment is specifically as follows:

[0181] The 10% data that is not used in training is used as a test data set;

[0182] Input the test data set into the random forest classifier trained in step 3 to determine whether the data corresponds to a payment gesture or a non-payment gesture;

[0183] If the data before the transaction point timestamp corresponds to a payment gesture, the transaction proceeds normally; otherwise, if the data before the transaction point timestamp corresponds to a non-payment gesture, the transaction is terminated.

[0184] Experimental results and evaluation:

[0185] 1) Payment scenario analysis:

[0186] The lighting conditions in different scenarios are also different, which can also cause differences in ALS readings. Although the light intensity indoors is much lower than the outdoor light intensity, if the sun can shine directly into the window on a sunny day, it can reach the outdoor light intensity. In addition, the scanner may block the ambient light that hits the smartphone ALS. For example, in the horizontal mode of the payment gesture, if the scanner is scanning directly above the ALS, the scanner will block the light from the ceiling LED. It was also observed that some scanners do not have a light source, such as the scanners in the school cafeteria and some handheld terminals. Therefore, the lighting conditions are also divided into three categories: the intensity of ambient light, whether the scanner blocks light, and whether the scanner has a light source. Combining the three payment gesture modes and these three types of lighting conditions, 24 different payment scenarios were obtained. These payment scenarios are analyzed next.

[0187] (1) Horizontal mode: The impact of different lighting conditions on ALS data in horizontal mode is as follows: Figure 8 As shown. In general, the light intensity increases in the early approach phase of the payment gesture. This is because the smartphone is very close to the user's torso before the payment gesture begins, and the user's torso blocks a large part of the ambient light. In the early approach phase, the phone is out of the shadow of the user's torso, so the light intensity increases in the early approach phase. In the middle and late approach phase, it is found that the ALS data is significantly different depending on whether the scanner is blocked. If the scanner blocks the light of the ambient light source, the light intensity will decrease significantly in this stage. If the scanner does not block the light, the ALS data remains stable. In the alignment phase, regardless of the ambient light intensity and whether the scanner is blocked, the ALS data is relatively stable in the early stage. In the alignment phase, the scanner reads the payment code information, and not all scanners have a light source. When the ambient light intensity is weak, the light emitted by the scanner with a light source will briefly cause the ALS data to increase. The illumination change caused by the scanner light source is not on the same order of magnitude as the illumination change caused by sunlight. Therefore, when the ambient light is strong, the ALS data is relatively stable regardless of whether the scanner has a light source. In other words, the light intensity change caused by the user's slight hand movement during the alignment stage may be greater than the light intensity change caused by the scanner light source.

[0188] (2) Vertical mode: The impact of different lighting conditions on ALS data in vertical mode is similar to that in horizontal mode, so we will not go into details here. It is worth noting that the vertical mode needs to consider the direction of the phone's rotation, which will cause different changes in the ALS data. In the approach stage, a certain point in the smartphone's rotation process will be directly illuminated by the light source, and the ALS data may show a trend of first increasing and then decreasing, and then stabilizing; or the ALS data may continue to increase and remain stable. When the phone is turned to the backlight, such as Fig. 9As shown in the figure, when the barcode scanner has no fill light, the ALS data may show a trend of first decreasing and then increasing, and then tending to be stable; or the ALS data may continue to decrease and remain stable.

[0189] (3) Flip mode: In flip mode, the smartphone faces downward, and the light source is usually set at the top, so the ALS data will drop during the approach phase. In addition, the payment gestures in flip mode all correspond to the barcode scanning box as the barcode scanner. The light source of the barcode scanning box works differently from the barcode scanning gun. Its light source is always on and will flash once after reading the payment code. In other words, the light source of the barcode scanning box will turn off and then on again after the barcode is successfully scanned. This will cause Fig.10 In the early stage of the approach phase, the ALS data increases due to the fill light of the code scanning box, and when the code is scanned successfully, the ALS data drops briefly due to the flashing of the fill light.

[0190] Non-payment gestures, i.e. gesture data when queuing, were analyzed. Many non-payment gestures are significantly different from payment gestures, and the random forest classifier trained by the present invention can distinguish between the two. For example, when a user continues to hold the phone in front of his chest while waiting to check out, the ALS data remains relatively stable, and there is no ALS data change trend like payment gestures. However, there is a type of non-payment gesture data that is similar to the situation where the barcode scanner is not shielded from light and has no light source. This non-payment gesture is an action in which the user lets his hand hang naturally, with the phone facing the user's legs, and then picks it up. The ALS data changes under this action are as follows: Fig.11 As shown in the figure, when the mobile phone is close to the user's legs, the light irradiating to the ALS is blocked, resulting in a lower ALS data. When the user picks up the mobile phone, the light intensity increases because the ALS is not blocked. For this type of non-payment gesture that is difficult to distinguish, although its change trend is similar to the case of no light blocking and no fill light, this gesture is farther away from the ceiling light source and is very close to the user's legs. The mobile phone screen is parallel to the user's legs, which blocks the ambient light irradiating to the ALS to a greater extent. Therefore, a threshold is set. If the average light intensity 0.5 seconds before the transaction point is greater than the average light intensity 0.5 seconds at the beginning of the payment gesture, it is considered to be a non-payment gesture. In the vertical payment gesture where the ALS is least likely to be blocked by the scanner, the ALS data will drop when the scanner is 20 cm away from the mobile phone ALS. The scanning depth of field of most scanning boxes is about 20 cm. This shows that the situation where the scanner does not block the light and the scanner does not have a light source rarely occurs. Therefore, the classifier of the present application can distinguish between payment gestures and non-payment gestures in most cases.

[0191] 2) Classifier performance evaluation indicators

[0192] The performance evaluation of the random forest classifier trained by the present invention adopts common indicators. Each indicator is based on the number of correctly classified payment gestures (TP) and incorrectly classified payment gestures (FN), as well as the number of correctly classified non-payment gestures (TN) and incorrectly classified non-payment gestures (FP). The following indicators are used to evaluate the effectiveness of the model. Precision refers to the ratio between the number of correctly classified positive samples and the total number of all samples classified as positive:

[0193]

[0194] Recall defines how many positive samples are correctly identified overall:

[0195]

[0196] The F1 score is defined as:

[0197]

[0198] Precision reflects security, and it measures the ability of the random forest classifier to reject non-payment gestures. Recall represents usability, because it represents whether the classifier can correctly identify the user's payment gesture to avoid inconvenience to the user. The F1 score is the weighted average of precision and recall (with equal weights). By combining the two, it can more comprehensively reflect the classifier's ability to balance security and usability. The false acceptance rate (FAR) represents the probability of incorrectly accepting a non-payment gesture, and is defined as follows:

[0199]

[0200] The False Rejection Rate (FRR) similarly represents the probability of incorrectly rejecting a payment gesture. It is defined as:

[0201]

[0202] FAR inversely represents safety by measuring the probability that a negative class is falsely accepted. FRR inversely represents availability by measuring the probability that a positive class is falsely rejected. The intersection of FAR and FRR is called the Equal Error Rate (EER), which is a measure of system performance when a balance is considered between safety and availability. The decision threshold θ is the threshold used in the classifier to convert probability values ​​into final class labels. The authors adjust θ to modify the trade-off between safety and availability; larger θ is more resilient to false positives and therefore favors safety, and smaller θ favors availability. To minimize the probability of false negatives, the authors choose θ to optimize the random forest classifier model trained by the present invention to make the FRR less than 1% and, correspondingly, make the FAR as low as possible. FAR and FRR are opposites, because setting θ to favor one will be detrimental to the other. The authors compared the FAR when optimized with the FAR when not optimized to measure how much potential safety gains are sacrificed to minimize the impact on availability.

[0203] 3) Analysis of classifier performance and influencing factors

[0204] Fig.12 The F1 scores of the random forest classifiers trained on payment gesture data split at different time window sizes are shown. Each F1 score is obtained by a 10-fold cross validation method, which divides the dataset into 10 subsets. In each iteration, the model is trained using 9 of the subsets and then validated on the remaining subset. Therefore, each classifier is trained on the same dataset but evaluated on a different validation set. To make the payment gesture compatible with real-world usage, the authors only consider the window size to the left of the transaction point and set the step size to 0.5 seconds. When the time window size is 3 seconds, the average F1 score is 0.911 (with a precision of 0.912, a recall of 0.911, and an EER of 0.0625). This result shows that a 3-second time window is sufficient to capture the characteristics of the payment gesture. However, if the time window is too small or too large, the F1 score will be reduced. If the time window is too small, it will not provide enough gesture information to train the classifier; if the time window is too large, it will contain too much useless information before the payment gesture is made, which will affect the performance of the classifier. Based on the above evaluation results, the authors decided to set the time window size to 3 seconds to ensure that the classifier can accurately capture the payment gesture features.

[0205] This application uses data interpolation and non-uniform correction methods to preprocess the ALS signal. Each method will have a specific impact on the performance of the classifier. Experiments were conducted to evaluate the impact of each preprocessing method on the classifier. The results are shown in Fig.13As shown in the figure. When the classifier is trained using ALS data without any preprocessing, the overall performance of the classifier is low. This is because there are missing values ​​or imbalances in the original data, which causes the classifier to be biased when identifying ALS samples. In this case, the classifier may rely too much on the specific features of the user's gesture and ignore the overall data distribution. Interpolation processing can greatly improve the performance of the classifier. It can fill the missing values ​​in the ALS data and make the signal more complete. In this way, the classifier has more ALS data to learn from and reduces the bias caused by missing values. Non-uniformity correction can help eliminate sampling bias in ALS data, thereby making the sampling frequency of ALS signals more uniform. By performing non-uniformity correction on the ALS signal, the distribution of data can be made more uniform, which helps the classifier to better learn the characteristics of the ALS signal. However, in the device that collected data in this study, only a small number of ALS signal samples were non-uniformly sampled, so the improvement in the overall performance of the classifier was small. Combining the two methods of interpolation and non-uniformity correction can achieve the best performance of the classifier. These two methods can make the distribution of ALS data more uniform while smoothing the signal, further enabling the classifier to predict the user's gesture more accurately and achieve the best level in indicators such as precision, recall and F1 score.

[0206] The above embodiments are only used to illustrate the design ideas and features of the present invention, and their purpose is to enable those skilled in the art to understand the content of the present invention and implement it accordingly. The protection scope of the present invention includes but is not limited to the above embodiments. Any equivalent changes or modifications made based on the principles and design ideas disclosed by the present invention are within the protection scope of the present invention.

[0207] It should be noted that the step numbers in the specification and claims of the present invention are only for a clear description of the implementation scheme of the present invention to facilitate understanding, and the sequence of the step numbers is not limited.

Claims

1. A method for enhancing the security of scanning payment based on an ambient light sensor, characterized in that: Including the following steps; Step 1: When the user displays a QR code for passive QR code scanning payment, use the ambient light sensor on the mobile phone to collect ambient light intensity data and obtain ALS data samples; Step 2: Perform preprocessing operations on the ALS data samples to fill in missing values and perform non-uniform correction; Step 3: Extract signal features from the preprocessed ALS data samples, and combine the payment gesture and non-payment gesture data sets, and use the signal features to train a random forest classifier; Step 4: When receiving a payment request, use the classifier to infer whether the user has made a payment gesture to confirm the validity of the QR code scanning behavior.

2. According to claim 1, a method for enhancing security of scanning code payment based on ambient light sensor is characterized in that: The specific method steps for collecting ambient light intensity data in Step 1 are: 1.1): Unify the time servers of all devices, and check the time on the time server before each collection of ALS signals; view the error between the system time and the accurate time through the time server to correct the transaction point timestamp, that is, the time point when the QR code scanner records reading the QR code; 1.2): Record the user's ALS signal on the mobile phone, and the QR code scanner records the transaction point timestamp; 1.3): When the payment code payment is completed, gesture judgment is required. Only the data before the transaction point can be used for gesture judgment. In order to segment each payment gesture, the transaction point timestamp T0 is used as the right end point of each time window. The data in the time window of size s on the left side of the transaction point is regarded as a payment gesture, that is, the retrieval start time is T s Payment gestures, where T s =T0-s, T0 is also the end time; The payment gesture is divided into an approaching stage, an alignment stage, and a retracting stage; In the approaching stage, the user moves the arm and rotates the wrist to bring the smartphone closer to and align it with the QR code scanning device. Since the relative positions of the smartphone ALS and the light source are constantly changing, a peak will appear in this stage; In the alignment stage, the distance between the smartphone and the QR code scanning device is relatively close, and the QR code scanning device will block the light from the light source in the environment from shining on the ALS, and the data value received by the ALS is at a relatively low level; In the alignment stage, the light source of the QR code scanner will cause a brief increase in the light intensity received by the ALS; The retracting stage is similar to the alignment stage, and the action of retracting the smartphone will cause a peak in the ALS signal.

3. The method for enhancing security of scanning code payment based on ambient light sensor according to claim 2 is characterized in that: Step 2 is specifically: 2.1) Take each data point collected by the ALS as a sample point. When the change in the signal intensity directly received by the sample point is less than the resolution of the smartphone ALS, the ALS cannot detect the change in light intensity, and missing values will appear in the sample. Then use the interpolation method to fill in the missing values; For example, in zero-order interpolation, set the values between two adjacent data points to the same value, which is usually the middle value of the two adjacent data points. Suppose there are two adjacent data points (x1, y1) and (x2, y2), where x1 < x2, and the zero-order interpolation function f(x) is expressed as: In the interval between x1 and x2, the function value is equal to y1, and the function value at x2 is equal to y2. The result of zero-order interpolation is a stepped function with the original data points as nodes; Or, estimate the missing values by fitting the entire sample set to a smooth curve through cubic spline interpolation; When a set of data points (x0,y0),(x1,y1),...,(x n ,y n ) for cubic spline interpolation, it is required that at each adjacent data point (x i ,y i ) and (x i+1 ,y i+1 ) construct a cubic polynomial S i (x), so that in [x i ,x i+1 ]The interpolation function S(x) in the interval satisfies the following conditions: Interpolation condition: S i (x i )=y i and S i (x i+1 )=y i+1 , that is, the value of the interpolation function at the data point is equal to the function value of the given data point; Smoothing condition: S′ i =(x i+1 ) = S′ i+1 (x i+1 ) and S″ i (x i+1 )=S″ i+1 (x i+1 ), that is, the interpolation function of adjacent data segments is in x i+1 The first and second derivatives at are equal; According to the above conditions, the cubic polynomial function S in each data segment is obtained. i (x), whose general form is: S i (x)=a i (x-x i ) 3 +b i (x-x i ) 2 +c i (x-x i )+d i (2) where a i ,b i ,c i ,d i is the unknown coefficient, which is solved according to the interpolation condition and smoothing condition; The finally obtained cubic spline interpolation function is a set of interpolation functions on all data segments: The cubic spline interpolation function S(x) constructed in this way is i The function value at the given data point is equal to the function value y i , and the first and second order derivatives at the data points are continuous, thus achieving a smooth interpolation effect; 2.2) Non-uniformity correction: When the sampling of ALS in the smartphone is non-uniform, according to the Nyquist-Shannon sampling theorem, the N non-uniform samples (t i ,r i ) with sampling rate T′ s Converted into M uniform samples, the new sampling time point jT′ s The value of p j The original data at time t i The degree of influence ij As shown below: Use element b ij The influence matrix B and the original sampling value r = (r0, r1, ..., r N1 ) T , solve the value p=(p0,p1,...,p M-1 ) T : p=(B T B) -1 B T r (5) According to the uniform data p obtained by the formula, reproduce the original signal through the sampling theorem, and give f(t) shown in the formula:

4. The method for enhancing security of scanning code payment based on ambient light sensor according to claim 3 is characterized in that: Step 3 is specifically: 3.1): Construct multiple different training data sets; 3.1.1): Through a typical payment scenario, let the user interact with the barcode scanner and perform steps 1 and 2 to obtain payment gesture data. Repeat this process to obtain a payment gesture dataset; 3.1.2): Simulate common non-payment scenarios, hold the phone in line and perform steps 1 and 2 to obtain non-payment gesture data. Repeat this process to obtain a non-payment gesture dataset. 3.2): Extracting data signal features from uniform data p in the training data set; Signal characteristics include statistical characteristics, distribution characteristics, frequency domain characteristics and waveform characteristics; 3.3): Use the training data set to train different decision trees and form a random forest classifier, where the random forest consists of multiple decision trees, each of which is trained based on a different data set and randomly selected features; in this classifier, all users' payment gestures are defined as positive samples, and all non-payment gestures are defined as negative samples; a ten-fold cross-validation method is used to make better use of the data and reduce the variance of the results, thereby improving the reliability of model evaluation.

5. According to the method for enhancing security of scanning payment based on ambient light sensor in claim 4, it is characterized in that step 3.3) is specifically as follows: 3.3.1): During the training of each decision tree, samples are randomly selected. If the number of samples is N, the number of samples selected is generally N' <N; 3.3.2): When each node is split, a portion of the features are randomly selected from all M features to consider splitting. The number of features selected is 3.3.3): Assume that the random forest contains T decision trees. For an input sample x, the final classification result is determined based on the voting results of all decision trees. If a sample x is classified as category c by the tth tree t The probability is p t (c t |x), the final classification result is:

6. A method for enhancing security of scanning payment based on ambient light sensor according to claim 5, characterized in that the statistical features in step 3.2) include the maximum value, minimum value, peak-to-valley difference, median, mean, variance, standard deviation and interquartile range of ALS samples; The interquartile range is calculated by dividing the data set consisting of sample points into four equal parts. When calculating the interquartile range, you first need to find the upper quartile Q1 and lower quartile Q3 of the data set. The upper quartile is the value in the data set where there are observations less than or equal to it, and the lower quartile is the value in the data set where there are observations greater than or equal to it. Then, the interquartile range is calculated using the following formula: IQR=Q3-Q1 (7) Among them, Q1 represents the lower quartile and Q3 represents the upper quartile.

7. A method for enhancing security of scanning payment based on ambient light sensor according to claim 6, characterized in that: The distribution characteristics include kurtosis, skewness, and peak count; When the kurtosis value is greater than 0, the distribution curve is sharper than the normal distribution; when the kurtosis value is less than 0, the distribution curve is flatter than the normal distribution. If the kurtosis is equal to 0, it means that the shape of the distribution curve is similar to the normal distribution. Suppose the probability distribution function of the random variable is f(x), its mean is μ, its standard deviation is σ, and x i is the sample value, n is the number of samples, and the kurtosis Kurt is calculated by the following mathematical formula: Skewness indicates the degree to which the distribution curve deviates to the left or right from the mean. A skewness value greater than 0 indicates that the distribution curve is skewed to the right, while a skewness value less than 0 indicates that the distribution curve is skewed to the left. If the skewness is equal to 0, it means that the distribution curve is symmetric with respect to the mean. Suppose the probability distribution function of the random variable is f(x), its mean is μ, and its standard deviation is σ; Skewness is calculated using the following mathematical formula: Peak counting first needs to find the peak value in the ALS signal. Assume there is an ALS signal f(x), where x is the time coordinate of the ALS signal and f(x) is the light intensity at that time point. First, a local maximum condition needs to be defined. Then, a search algorithm is used to find the local maximum that meets the condition in the ALS signal, thereby determining the location of the peak. Specifically, this work uses a window size of w to search for the local maximum. For each time point x in the ALS signal i , check the x i The signal value in the window centered at i ) is greater than the signal value of all other points in the window, then x i It is a local maximum, that is, a peak.

8. The method for enhancing security of scanning payment based on ambient light sensor according to claim 6, characterized in that: The frequency domain feature analyzes the ALS data from the frequency domain perspective of the signal to find important frequency information in the data. The discrete Fourier transform converts a discrete time domain signal into its frequency domain representation, and its formula is: The overall shape of the spectrum shows a gradually decreasing trend, representing an ALS signal with obvious main frequency components in the low-frequency region.

9. The method for enhancing security of scanning code payment based on ambient light sensor according to claim 6, characterized in that: The waveform feature refers to the full-segment slope of the ALS signal at different stages. By extracting the slope feature, the n peaks and valleys of the ALS signal are first determined, and then the signal is divided into n-1 segments based on them. The peak-to-valley difference of each segment is then calculated. If the peak-to-valley difference is less than a preset threshold t, the segment is discarded, and then the full-segment slope of each segment is calculated, that is, the slope is calculated using the coordinates of the start and end points of the signal segment. If the slope is greater than 0, it is a rising segment, and if the slope is less than 0, it is a falling segment. Finally, the number of rising and falling segments is obtained, and the average slope of the rising and falling segments is calculated.

10. The method for enhancing security of scanning code payment based on ambient light sensor according to claim 4, characterized in that: The step 4 is specifically as follows: 4.1): When the barcode scanner successfully scans the payment code and is ready to deduct the payment, it sends a request to the user account, including the transaction point timestamp; 4.2): When the user's mobile phone receives a payment request, it reads the ambient light sensor data of a window size before the transaction point timestamp; 4.3): Execute step 1 and step 2 on the acquired ambient light sensor data to obtain processed uniform data; 4.4): Perform step 3.1) on the data processed in step 4.3), extract features, and use the random forest model trained in step 3.2) to classify and determine whether the data corresponds to a payment gesture or a non-payment gesture; 4.5): If the data before the transaction point timestamp corresponds to the payment gesture, the transaction proceeds normally; 4.6): If the data before the transaction point timestamp corresponds to a non-payment gesture, the transaction is aborted.