Subscriber identification system based on SIM card
By building a three-dimensional matrix and straight lines of user traffic, detecting abnormal behaviors, and generating dynamic identity tokens, the security vulnerabilities of the existing SIM card authentication system are solved, and more efficient and secure user authentication is achieved.
Patent Information
- Application Number
- CN202510029953.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-01-08
AI Technical Summary
The existing SIM card-based authentication system has security vulnerabilities, such as being vulnerable to SIM card cloning, and cannot warn of stolen SIM cards, resulting in a threat to network security.
By obtaining the user's traffic matrix, building a three-dimensional matrix, detecting areas with similar traffic usage status, obtaining similar time points, building straight lines, identifying whether the user is abnormal, and generating dynamic identity tokens in real time when the user is abnormal for verification.
It significantly improves the security and efficiency of user identity verification, and can determine whether the SIM card is the original user based on the user's traffic rules, providing strong security guarantees.
Smart Images

Figure CN119967415A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a user identification system based on a SIM card. Background Art
[0002] At present, with the rapid development of mobile communication technology, user identity authentication has become a key link in ensuring network security. SIM card (Subscriber Identity Module) is a smart card used to store user identity information and is widely used in mobile communication devices. Although the traditional SIM card-based identity authentication system is widely used, it still has certain security vulnerabilities, such as being vulnerable to SIM card cloning. SIM cards may be stolen, and ordinary SIM card identity authentication cannot warn of theft. Therefore, the market urgently needs a more secure and efficient user identification system. Summary of the invention
[0003] The purpose of the present invention is to provide a user identification system based on a SIM card to solve the above problems existing in the prior art.
[0004] The embodiment of the present invention provides a user identification system based on a SIM card, including:
[0005] Acquisition module: acquires a traffic matrix; the traffic matrix represents the traffic used by the user at multiple locations at multiple time points;
[0006] Similar area detection module: based on the traffic matrix, construct a three-dimensional matrix to detect areas with similar traffic usage status and obtain multiple similar time points; the similar time points represent the time points at which users have similar behaviors every day;
[0007] Straight line construction module: constructs straight lines based on multiple similar time points to obtain three-dimensional flow straight lines;
[0008] Identification module: based on the three-dimensional flow line, determining whether the user is abnormal;
[0009] Dynamic token generation module: If the user is abnormal, a dynamic identity token is generated in real time based on multiple similar time points to verify the user.
[0010] Optionally, the three-dimensional matrix is constructed based on the traffic matrix to detect areas with similar traffic usage status to obtain multiple similar time points, including:
[0011] Cutting the traffic matrix according to fixed time lengths to obtain multiple traffic cutting matrices;
[0012] Obtain a first traffic cutting matrix and a second traffic cutting matrix; the first traffic cutting matrix and the second traffic cutting matrix are two traffic cutting matrices with adjacent time points among a plurality of traffic cutting matrices;
[0013] Based on the first traffic cutting matrix and the second traffic cutting matrix, detecting time points at which traffic similarity is used in the two traffic cutting matrices, and obtaining a plurality of similarity trees;
[0014] Through the adjacent convolutional network, based on multiple similarity trees, the first traffic cutting matrix and the second traffic cutting matrix, the similar states of traffic changes at adjacent time points are judged to obtain multiple similar time points.
[0015] Optionally, based on the first traffic cutting matrix and the second traffic cutting matrix, detecting time points at which traffic in the two traffic cutting matrices is similar, and obtaining multiple similarity trees includes:
[0016] Extract the position and flow corresponding to each time point in the first flow cutting matrix to obtain a first position flow set; extract the position and flow corresponding to each time point in the second flow cutting matrix to obtain a second position flow set;
[0017] Calculating cluster similarity of the locations and flows together, clustering the first location flow set and the second location flow set to obtain a plurality of cluster sets;
[0018] Taking the value of the first position flow set in a cluster set as a first detection value;
[0019] The first detection value is used as the root node of the tree, and the value of the second position flow set in the cluster set is used as the child node of the root node to obtain a similar tree; multiple values in the first position flow set correspond to multiple similar trees.
[0020] Optionally, the method of determining similar states of flow changes at adjacent time points based on the first flow cutting matrix and the second flow cutting matrix through adjacent convolutional networks to obtain multiple similar time points includes:
[0021] Based on the first flow cutting matrix and the second flow cutting matrix, a first eigenvector and a second eigenvector are obtained;
[0022] Superimposing the first flow cutting matrix and the second flow cutting matrix to obtain a first three-dimensional matrix;
[0023] Through the third convolution kernel, the change between two adjacent days is extracted from the time point from early to late on the first three-dimensional matrix with a step size of 1, and the third eigenvector is obtained;
[0024] The length of the third convolution kernel is 2; the width of the third convolution kernel is 2; the third convolution kernel performs convolution from the direction of the surface formed by the columns and pages of the first three-dimensional matrix;
[0025] Calculate the similarity of the values in the third eigenvector, mark the time points corresponding to the similar values; set the time points corresponding to the similar values to the same label;
[0026] Pruning is performed among the multiple similar trees, and the root nodes and child nodes with the same label are retained to obtain a first similar tree;
[0027] Based on the first feature vector and the second feature vector, detecting time points with similar usage traffic, and obtaining a plurality of second similarity trees;
[0028] In the first similar tree, the same root node and child nodes as those in the second similar tree are retained and pruned;
[0029] Pruning is performed multiple times until the root node of the similar tree contains only one child node, and the time points corresponding to the root node and the child node are marked as similar time points.
[0030] Optionally, performing user identity detection based on the traffic matrix to obtain an identity detection value includes:
[0031] According to the time points from early to late, the first convolution kernel performs convolution on the first flow cutting matrix with a step size of 1, extracts the change relationship between the flow and position between two adjacent time points, and obtains the first eigenvector;
[0032] The width of the first convolution kernel is equal to the number of rows of the first flow cutting matrix; the length of the first convolution kernel is equal to 2;
[0033] According to the time points from early to late, the second convolution kernel performs convolution on the second flow cutting matrix with a step size of 1 to extract the change relationship between the flow and position between two adjacent time points to obtain the second eigenvector;
[0034] The width of the second convolution kernel is equal to the number of rows of the second flow cutting matrix; the length of the second convolution kernel is equal to 2.
[0035] Optionally, the adjacent convolutional network includes a first convolution kernel, a second convolution kernel, a third convolution kernel, an average structure and a pruning structure;
[0036] The input of the first convolution kernel is a first flow cutting matrix; the input of the second convolution kernel is a second flow cutting matrix;
[0037] The outputs of the first convolution kernel and the second convolution kernel are inputs of the average structure;
[0038] The input of the third convolution kernel is the first three-dimensional matrix;
[0039] The output of the average structure and the output of the third convolution kernel are inputs of the pruning structure;
[0040] The pruning structure is self-connected;
[0041] The output of the pruning structure is similar time points.
[0042] Optionally, the parameters of the first convolution kernel and the second convolution kernel are the same;
[0043] The first convolution kernel and the second convolution kernel are trained, and the two convolution kernels with different parameters are averaged using an average structure to obtain the trained first convolution kernel and the second convolution kernel.
[0044] Optionally, constructing a straight line based on multiple similar time points to obtain a three-dimensional flow straight line includes:
[0045] The multiple similar time points are fitted into a straight line using the least square method to obtain a three-dimensional flow straight line.
[0046] Optionally, judging whether the user is abnormal based on the three-dimensional flow line includes:
[0047] The coefficients of the three-dimensional flow line are input into a trained neural discriminant network to determine whether the user is abnormal.
[0048] Optionally, if the user is abnormal, verifying the user based on multiple similar time points includes:
[0049] Randomly extract a similar time point from multiple similar time points as a detection time point;
[0050] Sending the detection time point to a user;
[0051] Receiving a user answer position; the user answer position indicates the user's position at the detection time point input by the user;
[0052] If the position corresponding to the detection time point is equal to the user's answer position, it is considered that the verification is successful.
[0053] Compared with the prior art, the embodiments of the present invention achieve the following beneficial effects:
[0054] An embodiment of the present invention also provides a user identification system based on a SIM card, the system comprising: an acquisition module: acquiring a traffic matrix; the traffic matrix represents the traffic used by the user at multiple time points and multiple locations; a similar area detection module: based on the traffic matrix, constructing a three-dimensional matrix, detecting areas with similar traffic usage status, and obtaining multiple similar time points; the similar time points represent time points at which the user has similar daily behaviors; a straight line construction module: based on multiple similar time points, constructing a straight line to obtain a three-dimensional straight line for traffic; a judgment module: based on the three-dimensional straight line for traffic, judging whether the user is abnormal; a dynamic token generation module: if the user is abnormal, a dynamic identity token is generated in real time based on multiple similar time points to verify the user.
[0055] The present invention first detects the time points in two adjacent days when the usage flow and the location of the usage flow are similar, and constructs a connection structure of the tree according to the similarity relationship to obtain a similar tree. Then, the first convolution kernel and the second convolution kernel are used to detect the relationship between adjacent time points in a day, and the similar tree is pruned to obtain the connection time points that conform to the user's usage flow law. The first flow cutting matrix and the second flow cutting matrix corresponding to the two adjacent days are constructed into a three-dimensional matrix, that is, the first three-dimensional matrix, and the relationship between the usage flow and the location of the adjacent days at the same time is obtained by convolution, and the pruning is performed again, and the convolution kernel pruning operation is repeated. So as to find a time point on the second day that best conforms to the user's usage flow law on the first day. In this way, the user's usage law is found, and the points of the law are constructed as a straight line. If the usage of the flow conforms to the user's usage flow law, then the parameters of the straight line are input into the neural discriminant network, and the user can be detected to be normal. If the usage of the flow does not conform to the user's usage flow law, then the parameters of the straight line are input into the neural discriminant network, and the user can be detected to be abnormal. Therefore, user detection is performed based on whether the user is abnormal, and the positions corresponding to adjacent time points of the random user, which are known to the user and difficult to crawl, are used as identity tokens to verify the user. This can determine whether the user using the SIM card is the original user based on the pattern of user traffic usage, significantly improving the security and efficiency of user identity authentication and providing a strong technical effect of security protection for mobile communication networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 The present invention provides a flowchart of a method corresponding to a SIM card-based user identification system according to an embodiment of the present invention.
[0057] Figure 2 It is a structural schematic diagram of an adjacent convolutional network in a SIM card-based user identification system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0058] The present invention will be described in detail below in conjunction with the accompanying drawings.
[0059] Example 1
[0060] like Figure 1 As shown, an embodiment of the present invention provides a user identification system based on a SIM card, wherein the system 1 includes an acquisition module, a similar region detection module, a straight line construction module, a discrimination module and a dynamic token generation module.
[0061] The acquisition module is used for S101: acquiring a traffic matrix; the traffic matrix represents the traffic used by the user at multiple locations at multiple time points.
[0062] The rows of the traffic matrix represent multiple time points; the columns of the traffic matrix represent multiple locations; the values in the traffic matrix represent traffic; and one row of the traffic matrix contains only one value, which represents the traffic spent at one location at one time point.
[0063] The location represents an area, and the area is divided by the location of the base station receiving the traffic.
[0064] In this embodiment, the flow rate used at one location at one point in time means the flow rate used at one location within one minute.
[0065] The similar area detection module is used in S102: based on the traffic matrix, a three-dimensional matrix is constructed to detect areas with similar traffic usage status, and multiple similar time points are obtained; the similar time points represent time points at which users have similar behaviors every day.
[0066] The straight line construction module is used in S103: constructing a straight line based on multiple similar time points to obtain a three-dimensional flow straight line;
[0067] The determination module is used for S104: determining whether the user is abnormal based on the three-dimensional flow line;
[0068] The dynamic token generation module is used in S105: if the user is abnormal, a dynamic identity token is generated in real time based on multiple similar time points to verify the user.
[0069] Optionally, the three-dimensional matrix is constructed based on the traffic matrix to detect areas with similar traffic usage status to obtain multiple similar time points, including:
[0070] The flow matrix is cut according to a fixed time length to obtain a plurality of flow cut matrices.
[0071] In this embodiment, the fixed time length is 1 day.
[0072] The flow cutting matrix is a two-dimensional image; and the number of rows of multiple flow cutting matrices is the same.
[0073] Obtain a first traffic cutting matrix and a second traffic cutting matrix; the first traffic cutting matrix and the second traffic cutting matrix are two traffic cutting matrices with adjacent time points among a plurality of traffic cutting matrices;
[0074] Based on the first traffic cutting matrix and the second traffic cutting matrix, detecting time points at which traffic similarity is used in the two traffic cutting matrices, and obtaining a plurality of similarity trees;
[0075] Through the adjacent convolutional network, based on multiple similarity trees, the first traffic cutting matrix and the second traffic cutting matrix, the similar states of traffic changes at adjacent time points are judged to obtain multiple similar time points.
[0076] Optionally, based on the first traffic cutting matrix and the second traffic cutting matrix, detecting time points at which traffic in the two traffic cutting matrices is similar, and obtaining multiple similarity trees includes:
[0077] Extract the position and flow corresponding to each time point in the first flow cutting matrix to obtain a first position flow set; extract the position and flow corresponding to each time point in the second flow cutting matrix to obtain a second position flow set;
[0078] The locations and flows are used together to calculate cluster similarity, and the first location flow set and the second location flow set are clustered to obtain a plurality of cluster sets.
[0079] In this embodiment, k-means is used for clustering. When calculating the similarity of clusters, the sum of the Euclidean distance calculated by the location and the Euclidean distance calculated by the flow is used to determine the similarity, thereby performing clustering to obtain multiple cluster sets.
[0080] The value of the first location traffic set in a cluster set is used as a first detection value.
[0081] The first detection value represents a value extracted from a cluster set and belonging to a first location traffic set;
[0082] The first detection value is used as the root node of the tree, and the value of the second position flow set in the cluster set is used as the child node of the root node to obtain a similar tree; multiple values in the first position flow set correspond to multiple similar trees.
[0083] Because a cluster set includes multiple values in the first location traffic set and multiple values in the second location traffic set, the construction of the similarity tree can reflect the similarity relationship between the values in the first location traffic set and the values in the second location traffic set.
[0084] The number of similar trees is equal to the number of elements in the first position flow set.
[0085] Optionally, the method of determining similar states of flow changes at adjacent time points based on the first flow cutting matrix and the second flow cutting matrix through adjacent convolutional networks to obtain multiple similar time points includes:
[0086] Based on the first flow cutting matrix and the second flow cutting matrix, a first eigenvector and a second eigenvector are obtained.
[0087] The first feature vector represents the change state of the flow rate used between adjacent time points of a day.
[0088] The first flow cutting matrix and the second flow cutting matrix are superimposed to obtain a first three-dimensional matrix.
[0089] Through the third convolution kernel, the changes between two adjacent days are extracted from the time point from early to late on the first three-dimensional matrix with a step size of 1 to obtain the third eigenvector.
[0090] The length of the third convolution kernel is 2; the width of the third convolution kernel is 2; and the third convolution kernel performs convolution in the direction of the surface formed by the columns and pages of the first three-dimensional matrix.
[0091] Among them, because the number of pages of the superimposed first three-dimensional matrix is equal to 2, the length of the third convolution kernel is set to 2.
[0092] Calculate the similarity of the values in the third eigenvector, mark the time points corresponding to the similar values; set the time points corresponding to the similar values to the same label;
[0093] Among them, the values whose absolute value of the subtraction is less than 1 are regarded as similar values. For example, the third eigenvector is [4, 2, 8, 2, 7], 2-2 = 0, 0 is less than 1, the subscript corresponding to the first "2" is 1, and the subscript corresponding to the second "2" is 3. The time points corresponding to the subscripts 1 and 0 are marked as 0.
[0094] Pruning is performed among multiple similar trees, and root nodes and child nodes with the same labels are retained to obtain a first similar tree.
[0095] Among them, pruning is performed in the similar tree, and the root nodes and child nodes with the same label are retained, which means that the time points with the same flow change are retained. The flow in the similar tree is the same flow in adjacent days.
[0096] Based on the first feature vector and the second feature vector, time points with similar usage traffic are detected to obtain a plurality of second similarity trees.
[0097] The method for obtaining the second similar tree is the same as the method for obtaining the similar tree, which is modified from judging that the traffic usage in the two traffic cutting matrices is the same to judging that the traffic changes in the related feature vectors are the same.
[0098] Since the second similarity tree detects the relationship between two time points, one child node corresponds to two adjacent time points.
[0099] In the first similarity tree, the root node and child nodes that are the same as those in the second similarity tree are retained and pruned.
[0100] The subnodes of the first similarity tree and the second similarity tree that are connected to the same subnode are retained, and the subnodes of the first similarity tree that do not exist in the second similarity tree are deleted.
[0101] Among them, for example, the value of the root node in the first similarity tree corresponds to the flow rate at the 4th time point on the first day, and the value of the child node corresponds to the flow rate at the 3rd, 5th, and 7th time points on the second day. The root node in the second similarity tree corresponds to the change relationship of the flow rate at the 4th and 5th time points on the first day, and the value of the child node corresponds to the change relationship of the flow rate at the 5th and 6th time points on the second day. Then the child node corresponding to the 5th time point on the second day in the first similarity tree is retained, and the other nodes are deleted.
[0102] Pruning is performed multiple times until the root node of the similar tree contains only one child node, and the time points corresponding to the root node and the child node are marked as similar time points.
[0103] In this embodiment, the 4th time point on the first day and the 5th time point on the second day are marked as similar time points.
[0104] Optionally, performing user identity detection based on the traffic matrix to obtain an identity detection value includes:
[0105] According to the time points from early to late, the first convolution kernel performs convolution on the first flow cutting matrix with a step size of 1, extracts the change relationship between the flow and position between two adjacent time points, and obtains the first eigenvector;
[0106] The width of the first convolution kernel is equal to the number of rows of the first flow cutting matrix; the length of the first convolution kernel is equal to 2;
[0107] According to the time points from early to late, the second convolution kernel performs convolution on the second flow cutting matrix with a step size of 1 to extract the change relationship between the flow and position between two adjacent time points to obtain the second eigenvector;
[0108] The width of the second convolution kernel is equal to the number of rows of the second flow cutting matrix; the length of the second convolution kernel is equal to 2.
[0109] The first convolution kernel and the second convolution kernel are two-dimensional convolution kernels.
[0110] Optionally, the adjacent convolutional network includes a first convolution kernel, a second convolution kernel, a third convolution kernel, an average structure and a pruning structure.
[0111] The structural diagram of the adjacent convolutional network is as follows: Figure 2 shown.
[0112] The input of the first convolution kernel is a first flow cutting matrix; the input of the second convolution kernel is a second flow cutting matrix;
[0113] The outputs of the first convolution kernel and the second convolution kernel are inputs of the average structure;
[0114] The input of the third convolution kernel is the first three-dimensional matrix;
[0115] The output of the average structure and the output of the third convolution kernel are inputs of the pruning structure;
[0116] The pruning structure is self-connected;
[0117] The output of the pruning structure is similar time points.
[0118] Among them, the labeled similar time points are used to train adjacent convolutional networks.
[0119] Optionally, the parameters of the first convolution kernel and the second convolution kernel are the same;
[0120] The first convolution kernel and the second convolution kernel are trained, and the two convolution kernels with different parameters are averaged using an average structure to obtain the trained first convolution kernel and the second convolution kernel.
[0121] Among them, because the first convolution kernel and the second convolution kernel can distinguish the changes of the first flow cutting matrix and the second flow cutting matrix, an adjacent convolution network capable of similar discrimination is obtained, and a convolution kernel capable of inter-discrimination is also obtained.
[0122] Optionally, constructing a straight line based on multiple similar time points to obtain a three-dimensional flow straight line includes:
[0123] The multiple similar time points are fitted into a straight line using the least square method to obtain a three-dimensional flow straight line.
[0124] Optionally, judging whether the user is abnormal based on the three-dimensional flow line includes:
[0125] The coefficients of the three-dimensional flow line are input into a trained neural discriminant network to determine whether the user is abnormal.
[0126] The neural discriminant network is a fully-connected neural network (FCNN), which is trained using labeled values that mark whether the user is abnormal.
[0127] Optionally, if the user is abnormal, verifying the user based on multiple similar time points includes:
[0128] Randomly extract a similar time point from multiple similar time points as a detection time point;
[0129] Sending the detection time point to a user;
[0130] Receiving a user answer position; the user answer position indicates the user's position at the detection time point input by the user;
[0131] If the position corresponding to the detection time point is equal to the user's answer position, it is considered that the verification is successful.
[0132] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious that the structure required for constructing such systems. In addition, the present invention is not directed to any specific programming language either. It should be understood that various programming languages can be utilized to realize the content of the present invention described herein, and the description of the above specific languages is for disclosing the best mode of the present invention.
[0133] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.
[0134] The various component embodiments of the present invention may be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that a microprocessor or digital signal processor (DSP) may be used in practice to implement some or all of the functions of some or all of the components in the apparatus according to an embodiment of the present invention. The present invention may also be implemented as a device or device program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention may be stored on a computer-readable medium, or may have the form of one or more signals. Such a signal may be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
Claims
1. A user identification system based on a SIM card, characterized in that: include; Acquisition module: acquires a traffic matrix; the traffic matrix represents the traffic used by the user at multiple locations at multiple time points; Similar area detection module: based on the traffic matrix, construct a three-dimensional matrix to detect areas with similar traffic usage status and obtain multiple similar time points; The similar time points represent the time points at which the user's behaviors are similar every day; Straight line construction module: constructs straight lines based on multiple similar time points to obtain three-dimensional flow straight lines; Identification module: based on the three-dimensional flow line, determining whether the user is abnormal; Dynamic token generation module: If the user is abnormal, a dynamic identity token is generated in real time based on multiple similar time points to verify the user.
2. A SIM card-based user identification system according to claim 1, characterized in that: Based on the traffic matrix, a three-dimensional matrix is constructed to detect areas with similar traffic usage status, and multiple similar time points are obtained, including: Cutting the traffic matrix according to fixed time lengths to obtain multiple traffic cutting matrices; Obtain a first traffic cutting matrix and a second traffic cutting matrix; the first traffic cutting matrix and the second traffic cutting matrix are two traffic cutting matrices with adjacent time points among a plurality of traffic cutting matrices; Based on the first traffic cutting matrix and the second traffic cutting matrix, detecting time points in the two traffic cutting matrices where traffic is similar, and obtaining a plurality of similarity trees; Through the adjacent convolutional network, based on multiple similarity trees, the first traffic cutting matrix and the second traffic cutting matrix, the similar states of traffic changes at adjacent time points are judged to obtain multiple similar time points.
3. A SIM card-based user identification system according to claim 2, characterized in that: Based on the first traffic cutting matrix and the second traffic cutting matrix, the time points at which similar traffic is used in the two traffic cutting matrices are detected to obtain multiple similarity trees, including: Extract the position and flow corresponding to each time point in the first flow cutting matrix to obtain a first position flow set; extract the position and flow corresponding to each time point in the second flow cutting matrix to obtain a second position flow set; Calculating cluster similarity of the locations and flows together, clustering the first location flow set and the second location flow set to obtain a plurality of cluster sets; Taking the value of the first position flow set in a cluster set as a first detection value; The first detection value is used as the root node of the tree, and the value of the second position flow set in the cluster set is used as the child node of the root node to obtain a similar tree; multiple values in the first position flow set correspond to multiple similar trees.
4. A SIM card-based user identification system according to claim 2, characterized in that: The method uses the adjacent convolutional network to determine the similar states of traffic changes at adjacent time points based on the first traffic cutting matrix and the second traffic cutting matrix, and obtains multiple similar time points, including: Based on the first flow cutting matrix and the second flow cutting matrix, a first eigenvector and a second eigenvector are obtained; Superimposing the first flow cutting matrix and the second flow cutting matrix to obtain a first three-dimensional matrix; Through the third convolution kernel, the change between two adjacent days is extracted from the time point from early to late on the first three-dimensional matrix with a step size of 1, and the third eigenvector is obtained; The length of the third convolution kernel is 2; the width of the third convolution kernel is 2; the third convolution kernel performs convolution from the direction of the surface formed by the columns and pages of the first three-dimensional matrix; Calculate the similarity of the values in the third eigenvector, mark the time points corresponding to the similar values; set the time points corresponding to the similar values to the same label; Pruning is performed among the multiple similar trees, and the root nodes and child nodes with the same label are retained to obtain a first similar tree; Based on the first feature vector and the second feature vector, detecting time points with similar usage traffic, and obtaining a plurality of second similarity trees; In the first similar tree, the same root node and child nodes as those in the second similar tree are retained and pruned; Pruning is performed multiple times until the root node of the similar tree contains only one child node, and the time points corresponding to the root node and the child node are marked as similar time points.
5. A SIM card-based user identification system according to claim 4, characterized in that: The performing user identity detection based on the traffic matrix to obtain an identity detection value includes: According to the time points from early to late, the first convolution kernel performs convolution on the first flow cutting matrix with a step size of 1, extracts the change relationship between the flow and position between two adjacent time points, and obtains the first eigenvector; The width of the first convolution kernel is equal to the number of rows of the first flow cutting matrix; the length of the first convolution kernel is equal to 2; According to the time points from early to late, the second convolution kernel performs convolution on the second flow cutting matrix with a step size of 1 to extract the change relationship between the flow and position between two adjacent time points to obtain the second eigenvector; The width of the second convolution kernel is equal to the number of rows of the second flow cutting matrix; the length of the second convolution kernel is equal to 2.
6. A user identification system based on a SIM card according to claim 5, characterized in that: The adjacent convolutional network includes a first convolution kernel, a second convolution kernel, a third convolution kernel, an average structure and a pruning structure; The input of the first convolution kernel is a first flow cutting matrix; The input of the second convolution kernel is a second flow cutting matrix; The outputs of the first convolution kernel and the second convolution kernel are inputs of the average structure; The input of the third convolution kernel is the first three-dimensional matrix; The output of the average structure and the output of the third convolution kernel are inputs of the pruning structure; The pruning structure is self-connected; The output of the pruning structure is similar time points.
7. A SIM card-based user identification system according to claim 6, characterized in that: The parameters of the first convolution kernel and the second convolution kernel are the same; The first convolution kernel and the second convolution kernel are trained, and the two convolution kernels with different parameters are averaged using an average structure to obtain the trained first convolution kernel and the second convolution kernel.
8. A user identification system based on a SIM card according to claim 1, characterized in that: The method of constructing a straight line based on multiple similar time points to obtain a three-dimensional flow straight line includes: The multiple similar time points are fitted into a straight line using the least square method to obtain a three-dimensional flow straight line.
9. A user identification system based on a SIM card according to claim 1, characterized in that: The determining whether the user is abnormal based on the three-dimensional flow line includes: The coefficients of the three-dimensional flow line are input into a trained neural discriminant network to determine whether the user is abnormal.
10. A user identification system based on a SIM card according to claim 1, characterized in that: If the user is abnormal, verify the user based on multiple similar time points, including: Randomly extract a similar time point from multiple similar time points as a detection time point; Sending the detection time point to a user; Receive a user answer position; the user answer position indicates the user's position at the detection time point input by the user; If the position corresponding to the detection time point is equal to the user's answer position, it is considered that the verification is successful.
Citation Information
Patent Citations
User classifying method and system based on mobile user trajectory similarity
CN106778876A
SIM (Subscriber Identity Module) card anomaly detection method and system, electronic equipment and storage medium
CN116939661A
E-SIM user behavior analysis method and system
CN118984449A
Abnormal behavior detection method and device for encrypted traffic network
CN119030802A
Network node anomaly detection method and device based on tree neural network
CN119071033A