Trust evaluation method based on logarithmic probability regression model
By using logarithmic probability regression model for trust evaluation in FIDO application scenarios, the problem of dynamic trust evaluation is solved, and the effective response to dynamic security risks when users continue to access Internet resources is achieved.
Patent Information
- Application Number
- CN202510168964.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-14
AI Technical Summary
In the FIDO application scenario, it is difficult for the existing technology to achieve dynamic trust assessment and cannot effectively deal with the dynamic security risks of users when they continue to access Internet resources.
The trust evaluation method based on the logarithmic probability regression model is adopted. By obtaining multi-dimensional data (such as authenticator identification, dependant service identification, user role identification, etc.) and performing data preprocessing and normalization processing, it is input into the pre-trained logarithmic probability regression model, outputting the target trust score, and determining the multi-factor authentication judgment based on the score.
It realizes dynamic trust assessment when users continue to access Internet resources in FIDO application scenarios, improves the accuracy and flexibility of security authentication, and can effectively deal with dynamic security risks.
Smart Images

Figure CN119995896A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of network technology and security technology, and in particular to a trust evaluation method based on a logarithmic probability regression model. Background Art
[0002] In the field of network technology and security technology, in the traditional username / password authentication method, user secrets are stored on the server side and compared. Once the server is hacked, all user secrets will be leaked. MFA (Multi-Factor Authentication) means that users must pass two or more authentication factor identification mechanisms before they can be authorized to use Internet resources. Static MFA authentication still has the problem that once the server is hacked, all user secrets will be leaked, which cannot meet the security needs of users to deal with dynamic security risks during continuous access to Internet resources.
[0003] FIDO (Fast Identity Online) aims to create a more secure and easier-to-use online identity authentication standard. The protocol allows users to use local devices (such as smartphones or other personal devices) for authentication without relying on traditional passwords. FIDO technology has been widely used in various scenarios that require user identity verification, such as user login and transfer payment. However, there is currently no solution for how to achieve dynamic trust evaluation during the continuous access of users to Internet resources in FIDO application scenarios. Summary of the invention
[0004] The present application provides a trust evaluation method based on a logarithmic probability regression model, which is used to provide a technical solution for realizing dynamic trust evaluation during the process of users continuously accessing Internet resources in a FIDO application scenario.
[0005] In a first aspect, the present application provides a trust assessment method based on a logarithmic probability regression model, the method comprising:
[0006] In the online fast identity authentication FIDO application scenario, obtain multi-dimensional data of the target user for service authentication based on the first factor; determine the characteristic variables corresponding to each of the multi-dimensional data; wherein the multi-dimensional data includes at least one of the authenticator identifier, the relying party service identifier, the relying party user identifier, the user role identifier, and the universal authentication framework UAF authentication response message identifier;
[0007] The characteristic variables corresponding to each of the multidimensional data are input into a pre-trained logarithmic probability regression model, and a target trust score is determined based on the logarithmic probability regression model; and a multi-factor authentication judgment result is determined according to the target trust score.
[0008] The above technical solution has the following advantages or beneficial effects:
[0009] In this application, a logarithmic probability regression model for service authentication trust assessment is pre-trained. During the reasoning process, in the online fast identity authentication FIDO application scenario, after the target user performs service authentication based on the first factor, multi-dimensional data such as the authenticator identifier, the relying party service identifier, the relying party user identifier, the user role identifier, the universal authentication framework UAF authentication response message identifier, etc. are obtained, and then the characteristic variables corresponding to each of the multi-dimensional data are determined. The characteristic variables corresponding to each of the multi-dimensional data are summarized and input into the trained logarithmic probability regression model, and the target trust score is output. Then, according to the target trust score, the multi-factor authentication judgment result is determined. A technical solution is implemented that dynamically evaluates trust and then guides security authentication during the user's continuous access to Internet resources in the FIDO application scenario.
[0010] Furthermore, determining the characteristic variables corresponding to each of the multidimensional data includes:
[0011] Performing data preprocessing on the multidimensional data; wherein the data preprocessing includes at least one of data cleaning, data integration, data transformation, and data reduction;
[0012] The multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each of the multidimensional data.
[0013] The above technical solution has the following advantages or beneficial effects:
[0014] In order to improve the accuracy of trust assessment, it is first necessary to ensure the accuracy of the characteristic variables corresponding to each multidimensional data. Based on the above considerations, when determining the accuracy of the characteristic variables corresponding to each multidimensional data, this application first uses data cleaning, data integration, data transformation, data reduction and other processing methods to preprocess the multidimensional data, thereby improving the standardization and integrity of the multidimensional data after data preprocessing. Then, the multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each multidimensional data. Thereby ensuring the accuracy of the characteristic variables corresponding to each multidimensional data, thereby providing the basic conditions for improving the accuracy of trust assessment.
[0015] Furthermore, the normalizing of the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data includes:
[0016] Performing standard deviation normalization Z-Score normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data; or
[0017] The multidimensional data after data preprocessing is subjected to minimum and maximum normalization processing to determine the characteristic variables corresponding to each of the multidimensional data.
[0018] The above technical solution has the following advantages or beneficial effects:
[0019] In the present application, in order to improve the accuracy and flexibility of determining the characteristic variables corresponding to each multidimensional data, two methods can be used to determine the characteristic variables corresponding to each multidimensional data. Method 1: Determine the characteristic variables corresponding to each multidimensional data through the standard deviation normalization Z-Score normalization processing method; this method converts the multidimensional data after data preprocessing into characteristic variables of a standard normal distribution with a mean of 0 and a standard deviation of 1. Method 2: Determine the characteristic variables corresponding to each multidimensional data through the minimum and maximum normalization processing method; this method scales the multidimensional data after data preprocessing to characteristic variables between a specified minimum value and a maximum value; the minimum value can be 0, and the maximum value can be 1. Determining the characteristic variables corresponding to each multidimensional data by any of the above two methods improves the accuracy and flexibility of determining the characteristic variables corresponding to each multidimensional data.
[0020] Furthermore, the process of pre-training the log-odds regression model includes:
[0021] For each group of sample data in the training set, the group of sample data is input into the logarithmic probability regression model to be trained, wherein the group of sample data includes sample multidimensional data, a field with a value of 1 and a label field, and the parameter to be trained in the logarithmic probability regression model is a weight vector; the weight vector is estimated by using the logarithmic maximum likelihood method; during the iterative training process, when it is determined that the convergence condition is met according to the estimated weight vector, it is determined that the training of the logarithmic probability regression model is completed.
[0022] The above technical solution has the following advantages or beneficial effects:
[0023] In this application, for the same or different users in the historical authentication process, for each authentication, a set of sample multidimensional data corresponding to the authentication can be collected, and then a field with a value of 1 and a label field are added after the sample multidimensional data to obtain a set of sample data corresponding to the authentication. The label value in the label field is 1 or 0; 1 represents multi-factor authentication, and 0 represents no multi-factor authentication. In this way, multiple groups of sample data can be obtained to form a training set. For each group of sample data in the training set, the group of sample data is input into the logarithmic probability regression model to be trained, and the logarithmic maximum likelihood method is used to estimate the weight vector in the logarithmic probability regression model; when it is determined that the convergence condition is met according to the estimated weight vector, it is determined that the training of the logarithmic probability regression model is completed. Thereby improving the accuracy and efficiency of the training of the logarithmic probability regression model.
[0024] Furthermore, the estimating the weight vector by using the logarithmic maximum likelihood method includes:
[0025] The weight vector is estimated using log-maximum likelihood method and regularization.
[0026] The above technical solution has the following advantages or beneficial effects:
[0027] In the present application, the logarithmic maximum likelihood method and regularization are used to estimate the weight vector, thereby preventing the model from overfitting during the iterative training process, and then determining that the training of the logarithmic probability regression model is completed when the convergence condition is met according to the estimated weight vector. This further improves the accuracy and efficiency of the logarithmic probability regression model training.
[0028] Further, the estimating the weight vector by using logarithmic maximum likelihood method and regularization includes:
[0029] Using the logarithmic maximum likelihood method and regularization, according to the formula estimating the weight vector;
[0030] in, is the sample multidimensional data and the field with a value of 1 in the i-th sample data. x i is the sample multidimensional data in the i-th sample data; β = (w; b), w is the weight, b is the bias term, β is the weight vector; T represents transposition; y i is the label value in the i-th sample data, which takes 1 or 0, 1 represents multi-factor authentication, and 0 represents no multi-factor authentication; α is the regularization parameter, 0<α<1.
[0031] This application estimates the weight vector through the above formula, where, is a regular term. This improves the accuracy of the estimated weight vector.
[0032] Further, determining that a convergence condition is satisfied according to the estimated weight vector includes:
[0033] The magnitude of the gradient vector is determined according to the estimated weight vector, and if the magnitude of the gradient vector is less than a preset first threshold, it is determined that a convergence condition is satisfied.
[0034] Further, determining the magnitude of the gradient vector according to the estimated weight vector includes:
[0035] According to the estimated weight vector and Formula, determine the magnitude of the gradient vector;
[0036] Among them, X is m A matrix composed of m y i The matrix composed of
[0037] The above technical solution has the following advantages or beneficial effects:
[0038] In the present application, the amplitude of the gradient vector is determined by the above formula, thereby improving the accuracy of determining the amplitude of the gradient vector, and then when the amplitude of the gradient vector is less than a preset first threshold, it is determined that the convergence condition is met, thereby improving the accuracy of the logarithmic probability regression model training.
[0039] Further, determining that a convergence condition is satisfied according to the estimated weight vector includes:
[0040] The change value of the weight vector estimated by two adjacent iterative trainings is determined, and if the change value is less than a preset second threshold, it is determined that the convergence condition is met.
[0041] The above technical solution has the following advantages or beneficial effects:
[0042] In the present application, in the iterative process of the logarithmic probability regression model, another scheme for determining whether the convergence condition is met is provided, that is, determining the change value of the weight vector estimated by two adjacent iterative trainings, and judging whether the change value is less than a preset second threshold value, if so, determining that the convergence condition is met, thereby improving the accuracy and flexibility of determining whether the convergence condition is met. It should be noted that the present application includes but is not limited to the above two ways of determining whether the convergence condition is met. For example, it can also be determined that the convergence condition is met when it is judged that the number of iterations reaches a preset number threshold.
[0043] Further, determining the multi-factor authentication decision result according to the target trust score includes:
[0044] If the target trust score is greater than a preset third threshold, determining that the multi-factor authentication decision result is to perform multi-factor authentication;
[0045] If it is determined that the multi-factor authentication decision result is to perform multi-factor authentication, the method further includes:
[0046] According to a preset correspondence relationship between each trust score range and at least one factor, at least one second factor corresponding to the target trust score range to which the target trust score belongs is determined; and the at least one second factor is used for service authentication.
[0047] The above technical solution has the following advantages or beneficial effects:
[0048] In the present application, if the target trust score is greater than the preset third threshold, the multi-factor authentication judgment result is determined to be multi-factor authentication. In addition, the correspondence between each trust score range and at least one factor is preset, including the correspondence between each trust score range and the factor type, and the correspondence between each trust score range and the number of factors. For example, the trust score range is 0.7-1, the corresponding number of factors is 3, and the corresponding factor types are fingerprint recognition, voiceprint recognition, and iris recognition. The trust score range is 0.5-0.7, the corresponding number of factors is 2, and the corresponding factor types are fingerprint recognition and voiceprint recognition. According to the preset correspondence between each trust score range and at least one factor, at least one second factor corresponding to the target trust score range to which the target trust score belongs is determined; and at least one second factor is used for service authentication. Thereby further improving the accuracy and flexibility of service authentication. In addition, different correspondences between trust score ranges and at least one factor can be set according to the needs of different users, thereby improving the adaptability of service authentication to user needs.
[0049] In a second aspect, the present application provides a trust assessment device based on a logarithmic probability regression model, the device comprising:
[0050] A determination module is used to obtain multi-dimensional data of service authentication of a target user based on a first factor in an online fast identity authentication FIDO application scenario; determine characteristic variables corresponding to each of the multi-dimensional data; wherein the multi-dimensional data includes at least one of an authenticator identifier, a relying party service identifier, a relying party user identifier, a user role identifier, and a universal authentication framework UAF authentication response message identifier;
[0051] The evaluation module is used to input the characteristic variables corresponding to each of the multidimensional data into a pre-trained logarithmic probability regression model, determine the target trust score based on the logarithmic probability regression model; and determine the multi-factor authentication judgment result according to the target trust score.
[0052] Furthermore, the determination module is specifically used to perform data preprocessing on the multidimensional data; wherein the data preprocessing includes at least one of data cleaning, data integration, data transformation, and data reduction; the multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each of the multidimensional data.
[0053] Furthermore, the determination module is specifically used to perform standard deviation normalization Z-Score normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data; or to perform minimum and maximum normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data.
[0054] Furthermore, the device also includes:
[0055] A training module is used to input each group of sample data in a training set into a logarithmic probability regression model to be trained, wherein the group of sample data includes sample multidimensional data, a field with a value of 1 and a label field, and the parameter to be trained in the logarithmic probability regression model is a weight vector; the weight vector is estimated by using a logarithmic maximum likelihood method; during an iterative training process, when it is determined that a convergence condition is met based on the estimated weight vector, the training of the logarithmic probability regression model is determined to be completed.
[0056] Furthermore, the training module is specifically used to estimate the weight vector using logarithmic maximum likelihood method and regularization.
[0057] Furthermore, the training module is specifically used to adopt the logarithmic maximum likelihood method and regularization, according to the formula estimating the weight vector;
[0058] in, is the sample multidimensional data and the field with a value of 1 in the i-th sample data. x i is the sample multidimensional data in the i-th sample data; β = (w; b), w is the weight, b is the bias term, β is the weight vector; T represents transposition; y i is the label value in the i-th sample data, which takes 1 or 0, 1 represents multi-factor authentication, and 0 represents no multi-factor authentication; α is the regularization parameter, 0<α<1.
[0059] Furthermore, the training module is specifically used to determine the amplitude of the gradient vector according to the estimated weight vector, and if the amplitude of the gradient vector is less than a preset first threshold, it is determined that the convergence condition is met.
[0060] Furthermore, the training module is specifically used to train the training data according to the estimated weight vector and Formula, determine the magnitude of the gradient vector;
[0061] Among them, X is m A matrix composed of m y i The matrix composed of.
[0062] Furthermore, the training module is specifically used to determine a change value of a weight vector estimated between two adjacent iterative trainings. If the change value is less than a preset second threshold, it is determined that a convergence condition is satisfied.
[0063] Further, the evaluation module is specifically configured to determine that the multi-factor authentication decision result is to perform multi-factor authentication if the target trust score is greater than a preset third threshold;
[0064] The evaluation module is further configured to determine, based on a predetermined correspondence between each trust score range and at least one factor, at least one second factor corresponding to the target trust score range to which the target trust score belongs; and use the at least one second factor to perform service authentication.
[0065] In a third aspect, the present application provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0066] Memory, used to store computer programs;
[0067] The processor is used to implement the method when executing the program stored in the memory.
[0068] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the described method is implemented.
[0069] In a fifth aspect, the present application provides a computer program product, wherein the computer program product comprises an executable program, and the executable program is executed by a processor to implement the described method. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0071] Figure 1 A schematic diagram of the first trust assessment process based on the logarithmic probability regression model provided for this application;
[0072] Figure 2 Component diagram of the FIDO application scenario provided for this application;
[0073] Figure 3 A schematic diagram of the process of determining the characteristic variables corresponding to each multidimensional data provided by this application;
[0074] Figure 4 Schematic diagram of the process of pre-training the log-odds regression model provided for this application;
[0075] Figure 5 A schematic diagram of the second trust assessment process based on the logarithmic probability regression model provided for this application;
[0076] Figure 6A data preprocessing flow chart based on the logarithmic probability regression model in the FIDO application scenario provided by this application;
[0077] Figure 7 A trust assessment flow chart based on the logarithmic probability regression model provided for this application;
[0078] Figure 8 A schematic diagram of the structure of a trust assessment device based on a logarithmic probability regression model provided in this application;
[0079] Fig. 9 This is a schematic diagram of the electronic device structure provided in this application. DETAILED DESCRIPTION
[0080] In order to make the purpose and implementation method of the present application clearer, the exemplary implementation method of the present application will be clearly and completely described below in conjunction with the drawings in the exemplary embodiments of the present application. Obviously, the described exemplary embodiments are only part of the embodiments of the present application, rather than all the embodiments.
[0081] It should be noted that the brief description of terms in this application is only for the convenience of understanding the embodiments described below, and is not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their common and usual meanings.
[0082] The terms "first", "second", "third", etc. in the specification and claims of this application and the above drawings are used to distinguish similar or similar objects or entities, and do not necessarily mean to limit a specific order or sequence, unless otherwise noted. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances.
[0083] The terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device comprising a list of components is not necessarily limited to all the components expressly listed but may include other components not expressly listed or inherent to such product or device.
[0084] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.
[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0086] For the convenience of explanation, the above description has been made in conjunction with specific embodiments. However, the above exemplary discussion is not intended to be exhaustive or limit the embodiments to the specific forms disclosed above. Based on the above teachings, various modifications and variations can be obtained. The selection and description of the above embodiments are to better explain the principles and practical applications, so that those skilled in the art can better use the embodiments and various different variations of the embodiments suitable for specific use considerations.
[0087] The terms used in this application are explained as follows:
[0088] FIDO (Fast Identity Online): The FIDO Alliance, also known as the Fast Identity Online Alliance, is an industry association established in July 2012. Its purpose is to meet market demand and cope with online verification requirements, improve security, protect user privacy and simplify user experience.
[0089] UAF (Universal Authentication Framework): The UAF protocol allows online services to provide a password-free and multi-factor security experience. Users select a local authentication mechanism (generally including biometric authentication such as face recognition, fingerprint recognition, voiceprint recognition, iris recognition, etc.) to generate a public and private key for the user-associated authentication certificate. After registration, when the user needs authentication services, they only need to simply repeat the local authentication action, and then sign the previously generated private key of the user-associated authentication certificate to complete the relevant user authentication. UAF supports multi-factor authentication mechanisms, such as fingerprint + PIN code.
[0090] TLS (Transport Layer Security): TLS is a transport layer security protocol based on TCP. It is mainly used to provide confidentiality, data integrity, and data source verification between client / server applications. Its functions mainly rely on three types of algorithms: hash functions, symmetric encryption, and asymmetric encryption. The TLS protocol consists of two layers: TLS Record Protocol and TLS Handshake Protocol. Its predecessor is SSL (Secure Sockets Layer) Secure Sockets Layer Protocol. Application layer protocols (such as HTTP, FTP, Telnet, etc.) can run transparently on top of the TLS protocol.
[0091] This application proposes a trust assessment method based on a logarithmic probability regression model in a FIDO application scenario. By collecting cross-platform multi-source information such as FIDO authenticator information, relying party service information, relying party user information, UAF registration and UAF authentication request response log information, a trust assessment method based on a logarithmic probability regression model, L2 regularization and gradient descent method is designed. A multi-factor authentication or re-authentication decision is made based on the trust score and the pre-set threshold to achieve dynamic security authentication.
[0092] Figure 1 The first trust evaluation process diagram based on the logarithmic probability regression model provided in this application includes the following steps:
[0093] S101: In an online fast identity authentication FIDO application scenario, obtain multi-dimensional data of a target user performing service authentication based on a first factor; determine characteristic variables corresponding to each of the multi-dimensional data; wherein the multi-dimensional data includes at least one of an authenticator identifier, a relying party service identifier, a relying party user identifier, a user role identifier, and a universal authentication framework UAF authentication response message identifier;
[0094] S102: Inputting the characteristic variables corresponding to each of the multidimensional data into a pre-trained logarithmic probability regression model, determining a target trust score based on the logarithmic probability regression model; and determining a multi-factor authentication decision result according to the target trust score.
[0095] The trust assessment method based on the logarithmic probability regression model provided in the present application is applied to an electronic device, which may be a server or other device of a relying party. A FIDO trust assessment engine is deployed in the electronic device to implement a trust assessment process based on the logarithmic probability regression model.
[0096] The FIDO application scenario of online rapid identity authentication mainly includes six components: Web client, FIDO client, FIDO authenticator, Web server, FIDO server, and FIDO trust assessment engine. Figure 2 This is a schematic diagram of the components in the FIDO application scenario provided by this application. Figure 2 As shown, the user device side includes a web client, a FIDO client, and a FIDO authenticator, and the relying party includes a web server, a FIDO server, and a FIDO trust evaluation engine. The web client and the web server communicate via the TLS protocol. The FIDO client and the FIDO server communicate via the UAF protocol.
[0097] The functions of each component are briefly described as follows:
[0098] Web client: Acts as a user agent for the FIDO client. The web client and the web server communicate via the TLS security protocol.
[0099] FIDO client: uses the Web client as a user agent to interact with the FIDO server via UAF (Universal Authentication Framework) protocol messages (registration, authentication, transaction confirmation, and logout), and then adapts to various specific FIDO authenticators.
[0100] FIDO Authenticator: A security entity connected to or encapsulated in a FIDO user device. It has built-in matchers including biometric authentication such as face recognition, fingerprint recognition, voiceprint recognition, and iris recognition. It can create key materials associated with the relying party (relying party user-associated authentication certificate public and private keys, digital signatures, hashes). The authenticator's own authentication private key and the user-associated authentication certificate private key are stored in the device's secure area. The key can be used to participate in the FIDO strong authentication protocol, such as generating responses to cryptographic challenges to prove itself to the relying party.
[0101] Web server: provides web online services; acts as a proxy for the FIDO server, transmitting UAF protocol messages for interaction between the FIDO client and the FIDO server.
[0102] FIDO server: uses the web server as a proxy to exchange UAF protocol messages (registration, authentication, transaction confirmation, and deregistration) with the FIDO client; accepts metadata services such as the FIDO authenticator public key certificate provided by the FIDO authenticator manufacturer; calls the FIDO trust assessment engine to make MFA multi-factor authentication decisions based on the trust score to achieve dynamic security authentication.
[0103] FIDO Trust Assessment Engine: The design of the trust assessment engine is based on the logarithmic probability regression model, L2 regularization and gradient descent method; it summarizes and analyzes the collected cross-platform multi-source information such as FIDO authenticator information, relying party service information, relying party user information, UAF registration and UAF authentication request response log information, and outputs a trust score; it makes multi-factor authentication or re-authentication decisions based on the trust score and pre-set thresholds to achieve dynamic security authentication.
[0104] In this application, in the online fast identity authentication FIDO application scenario, the user first performs service authentication through the first factor. After the target user performs service authentication based on the first factor, the electronic device obtains multi-dimensional data. The multi-dimensional data includes but is not limited to one of the authenticator identifier, the relying party service identifier, the relying party user identifier, the user role identifier, and the universal authentication framework UAF authentication response message identifier. The first factor is, for example, one of the biometric authentication factors such as face, fingerprint, voiceprint, and iris. After obtaining the multi-dimensional data of the target user for service authentication based on the first factor, the feature variables corresponding to each of the multi-dimensional data are determined. Then, the feature variables corresponding to each of the multi-dimensional data are input into the pre-trained logarithmic probability regression model for trust evaluation, and the target trust score is determined based on the logarithmic probability regression model; according to the target trust score, the multi-factor authentication judgment result is determined. Optionally, when the target trust score is greater than a certain threshold, the multi-factor authentication judgment result is determined to be the need for multi-factor re-authentication; when the target trust score is not greater than a certain threshold, the multi-factor authentication judgment result is determined to be the need for multi-factor re-authentication.
[0105] In this application, a logarithmic probability regression model for service authentication trust assessment is pre-trained. During the reasoning process, in the online fast identity authentication FIDO application scenario, after the target user performs service authentication based on the first factor, multi-dimensional data such as the authenticator identifier, the relying party service identifier, the relying party user identifier, the user role identifier, the universal authentication framework UAF authentication response message identifier, etc. are obtained, and then the characteristic variables corresponding to each of the multi-dimensional data are determined. The characteristic variables corresponding to each of the multi-dimensional data are summarized and input into the trained logarithmic probability regression model, and the target trust score is output. Then, according to the target trust score, the multi-factor authentication judgment result is determined. A technical solution is implemented that dynamically evaluates trust and then guides security authentication during the user's continuous access to Internet resources in the FIDO application scenario.
[0106] Figure 3 The schematic diagram of the process of determining the characteristic variables corresponding to each multidimensional data provided in this application includes the following steps:
[0107] S201: performing data preprocessing on the multidimensional data; wherein the data preprocessing includes at least one of data cleaning, data integration, data transformation, and data reduction;
[0108] S202: normalizing the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data.
[0109] In order to improve the accuracy of trust assessment, it is first necessary to ensure the accuracy of the characteristic variables corresponding to each multidimensional data. Based on the above considerations, when determining the accuracy of the characteristic variables corresponding to each multidimensional data, this application first uses data cleaning, data integration, data transformation, data reduction and other processing methods to preprocess the multidimensional data, thereby improving the standardization and integrity of the multidimensional data after data preprocessing. Then, the multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each multidimensional data. Thereby ensuring the accuracy of the characteristic variables corresponding to each multidimensional data, thereby providing the basic conditions for improving the accuracy of trust assessment.
[0110] In the present application, the multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each of the multidimensional data, including:
[0111] Performing standard deviation normalization Z-Score normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data; or
[0112] The multidimensional data after data preprocessing is subjected to minimum and maximum normalization processing to determine the characteristic variables corresponding to each of the multidimensional data.
[0113] In the present application, in order to improve the accuracy and flexibility of determining the characteristic variables corresponding to each multidimensional data, two methods can be used to determine the characteristic variables corresponding to each multidimensional data. Method 1: Determine the characteristic variables corresponding to each multidimensional data through the standard deviation normalization Z-Score normalization processing method; this method converts the multidimensional data after data preprocessing into characteristic variables of a standard normal distribution with a mean of 0 and a standard deviation of 1. Method 2: Determine the characteristic variables corresponding to each multidimensional data through the minimum and maximum normalization processing method; this method scales the multidimensional data after data preprocessing to characteristic variables between a specified minimum value and a maximum value; the minimum value can be 0, and the maximum value can be 1. Determining the characteristic variables corresponding to each multidimensional data by any of the above two methods improves the accuracy and flexibility of determining the characteristic variables corresponding to each multidimensional data.
[0114] Figure 4 A schematic diagram of the process of pre-training the log-odds regression model provided for this application includes the following steps:
[0115] S301: for each set of sample data in the training set, input the set of sample data into the logarithmic probability regression model to be trained, wherein the set of sample data includes sample multidimensional data, a field with a value of 1 and a label field, and the parameter to be trained in the logarithmic probability regression model is a weight vector;
[0116] S302: The weight vector is estimated by using the logarithmic maximum likelihood method; during the iterative training process, when it is determined that the convergence condition is met according to the estimated weight vector, the training of the logarithmic probability regression model is determined to be completed.
[0117] Estimating the weight vector using the logarithmic maximum likelihood method includes:
[0118] According to the formula Estimate the weight vector β.
[0119] In this application, for the same or different users in the historical authentication process, for each authentication, a set of sample multidimensional data corresponding to the authentication can be collected, and then a field with a value of 1 and a label field are added after the sample multidimensional data to obtain a set of sample data corresponding to the authentication. The label value in the label field is 1 or 0; 1 represents multi-factor authentication, and 0 represents no multi-factor authentication. In this way, multiple groups of sample data can be obtained to form a training set. For each group of sample data in the training set, the group of sample data is input into the logarithmic probability regression model to be trained, and the logarithmic maximum likelihood method is used to estimate the weight vector in the logarithmic probability regression model; when it is determined that the convergence condition is met according to the estimated weight vector, it is determined that the training of the logarithmic probability regression model is completed. Thereby improving the accuracy and efficiency of the training of the logarithmic probability regression model.
[0120] In the present application, the method of estimating the weight vector using the logarithmic maximum likelihood method includes:
[0121] The weight vector is estimated by using the logarithmic maximum likelihood method and regularization. This prevents the model from overfitting during the iterative training process, and then determines that the training of the logarithmic probability regression model is completed when the convergence condition is met according to the estimated weight vector. This further improves the accuracy and efficiency of the logarithmic probability regression model training.
[0122] In the present application, the method of estimating the weight vector using logarithmic maximum likelihood method and regularization includes:
[0123] Using the logarithmic maximum likelihood method and regularization, according to the formula estimating the weight vector;
[0124] in, is the sample multidimensional data and the field with a value of 1 in the i-th sample data. x i is the sample multidimensional data in the i-th sample data; β = (w; b), w is the weight, b is the bias term, β is the weight vector; T represents transposition; y i is the label value in the i-th sample data, which takes 1 or 0, 1 represents multi-factor authentication, and 0 represents no multi-factor authentication; α is the regularization parameter, 0<α<1.
[0125] This application estimates the weight vector through the above formula, where, is a regular term. This improves the accuracy of the estimated weight vector.
[0126] The step of determining according to the estimated weight vector that a convergence condition is satisfied comprises:
[0127] The magnitude of the gradient vector is determined according to the estimated weight vector, and if the magnitude of the gradient vector is less than a preset first threshold, it is determined that a convergence condition is satisfied.
[0128] Determining the magnitude of the gradient vector according to the estimated weight vector includes:
[0129] According to the estimated weight vector and Formula, determine the magnitude of the gradient vector;
[0130] Among them, X is m A matrix composed of m y i The matrix composed of
[0131] In the present application, the amplitude of the gradient vector is determined by the above formula, thereby improving the accuracy of determining the amplitude of the gradient vector, and then when the amplitude of the gradient vector is less than the preset first threshold, it is determined that the convergence condition is met, thereby improving the accuracy of the logarithmic probability regression model training. The preset first threshold is an integer value close to 0, such as 0.1, 0.05, etc.
[0132] Further, determining that a convergence condition is satisfied according to the estimated weight vector includes:
[0133] Determine the change value of the weight vector estimated by two adjacent iterative trainings, and if the change value is less than a preset second threshold, determine that the convergence condition is met. The preset second threshold is, for example, a small value close to 0.
[0134] In the present application, in the iterative process of the logarithmic probability regression model, another scheme for determining whether the convergence condition is met is provided, that is, determining the change value of the weight vector estimated by two adjacent iterative trainings, and judging whether the change value is less than a preset second threshold value, if so, determining whether the convergence condition is met, thereby improving the accuracy and flexibility of determining whether the convergence condition is met. It should be noted that the present application includes but is not limited to the above two ways of determining whether the convergence condition is met. For example, when it is judged that the number of iterations reaches a preset number threshold, it is determined that the convergence condition is met. The preset number threshold is, for example, a value such as 2000 times or 3000 times.
[0135] Figure 5 The second trust assessment process diagram based on the logarithmic probability regression model provided in this application includes the following steps:
[0136] S401: In an online fast identity verification FIDO application scenario, obtain multi-dimensional data of a target user performing service authentication based on a first factor; determine characteristic variables corresponding to each of the multi-dimensional data; wherein the multi-dimensional data includes at least one of an authenticator identifier, a relying party service identifier, a relying party user identifier, a user role identifier, and a universal authentication framework UAF authentication response message identifier;
[0137] S402: Inputting the characteristic variables corresponding to each of the multidimensional data into a pre-trained logarithmic probability regression model, and determining a target trust score based on the logarithmic probability regression model; if the target trust score is greater than a preset third threshold, determining that the multi-factor authentication decision result is to perform multi-factor authentication;
[0138] S403: Determine at least one second factor corresponding to the target trust score range to which the target trust score belongs according to a preset correspondence relationship between each trust score range and at least one factor; and use the at least one second factor to perform service authentication.
[0139] In the present application, if the target trust score is greater than the preset third threshold, the multi-factor authentication judgment result is determined to be multi-factor authentication. The preset third threshold is, for example, a value such as 0.5, 0.6, etc. In addition, the correspondence between each trust score range and at least one factor is preset, including the correspondence between each trust score range and the factor type, and the correspondence between each trust score range and the number of factors. For example, the trust score range is 0.7-1, the corresponding number of factors is 3, and the corresponding factor types are fingerprint recognition, voiceprint recognition, and iris recognition. The trust score range is 0.5-0.7, the corresponding number of factors is 2, and the corresponding factor types are fingerprint recognition and voiceprint recognition. According to the preset correspondence between each trust score range and at least one factor, at least one second factor corresponding to the target trust score range to which the target trust score belongs is determined; and at least one second factor is used for service authentication. Thereby further improving the accuracy and flexibility of service authentication. In addition, different correspondences between trust score ranges and at least one factor can be set according to the needs of different users, thereby improving the adaptability of service authentication to user needs.
[0140] Figure 6 The data preprocessing flow chart based on the logarithmic probability regression model in the FIDO application scenario provided in this application includes the following steps:
[0141] S501: The FIDO server obtains metadata such as the public key certificate of the FIDO authenticator manufacturer from the FIDO Alliance. The user logs in to the relying party's Web service via TLS through the Web client, and registers the public and private key certificates associated with the user with the FIDO server based on the UAF registration protocol. The private key of the certificate is stored in the secure area of the user's device, and the public key of the certificate is stored on the FIDO server after verification and decryption by the FIDO server.
[0142] S502: The user logs in to the relying party's Web service via TLS through the Web client, and the FIDO server triggers a UAF authentication request. After the user passes the biometric verification of the built-in FIDO authenticator, an authenticator response message is generated, and the response message is digitally signed with the relying party user certificate private key generated by the previous registration. The FIDO server verifies and parses the UAF authentication request response message to complete the UAF authentication process.
[0143] S503: The FIDO server aggregates the collected cross-platform multi-source information such as FIDO authenticator information, relying party service information, relying party user information, UAF registration and UAF authentication request response log information, and performs necessary data preprocessing; data preprocessing includes data cleaning (missing value processing, outlier processing), data integration, data transformation (data standardization, normalization and feature extraction), data reduction (feature selection, data dimension reduction) and other tasks.
[0144] S504: The selected feature variables after data preprocessing may include but are not limited to authenticator ID, relying party service ID, relying party user ID, user role ID, UAF authentication response message ID, etc.; the selected feature variables are subjected to Z-Score normalization (converting the data to a standard normal distribution with a mean of 0 and a standard deviation of 1) or min-max normalization (scaling the data to between a specified minimum and maximum value (usually 0 and 1)).
[0145] S505: Assume that there are n feature variables finally selected and the number of training samples is m; label the m training samples manually or automatically with labels y (1 or 0); each training sample data has n feature variable values, and an element that is always 1 is added at the end, so that the m training samples construct a data set D with m rows and (n+1) columns; the m labels corresponding to the m training samples constitute a label vector Y with m rows and 1 column.
[0146] Figure 7 The trust evaluation flow chart based on the logarithmic probability regression model provided for this application includes the following steps:
[0147] Step 1: The "Sigmoid" function corresponding to the logarithmic probability regression model of this application is expressed as:
[0148]
[0149] x is a vector of n rows and 1 column corresponding to n feature variable training samples, w is a weight vector of n rows and 1 column, and b is a bias;
[0150] β=(w;b).
[0151] Step 2: Given the data set D and label vector Y, apply the logarithmic maximum likelihood method to the aforementioned "Sigmoid" function to estimate the weight column vector β, which is equivalent to minimizing the following function:
[0152]
[0153] Step 3: To alleviate model overfitting, L2 regularization, i.e. ridge regression, is introduced. The minimization function becomes:
[0154] The regularization parameter α satisfies 0<α<1.
[0155] Step 4: L(β) is a high-order differentiable continuous convex function about β. According to the convex optimization theory, the gradient descent method can be used to solve its numerical optimal solution:
[0156]
[0157] X is m column vectors The (n+1) row and m column matrix is composed of; σ is an m row and 1 column vector,
[0158] Step 5: The initial value of the weight vector β in (n+1) rows and 1 columns can be a normally distributed random number with a mean of 0 and a standard deviation of 1, k=0; the iteration formula for the (k+1)th step is:
[0159] Where η is the step size or learning rate, 0<η<1.
[0160] Step 6: The iterative convergence conditions of the gradient descent method generally include that the amplitude of the gradient vector is close to 0, the change of the weight vector is less than a preset threshold, or the preset threshold of the number of iterations is reached; when the iterative convergence conditions are met, the weight vector β corresponding to the optimal solution of L(β) can be obtained, and the learning of the logarithmic probability regression model is completed.
[0161] Step 7: Use the "K-fold cross validation method" (K is usually 10) to test and optimize the learned logarithmic probability model; the FIDO server authentication policy module calls the trust assessment scoring engine based on the logarithmic probability regression model, and uses the "Sigmoid" function corresponding to the logarithmic probability regression model The output trust score (a real number in the interval (0,1)) and the pre-set threshold (for example, 0.5) are used to determine whether multi-factor authentication or re-authentication is required, thereby achieving dynamic security authentication.
[0162] This application proposes a trust assessment method based on a logarithmic probability regression model in a FIDO application scenario. A trust assessment method based on a logarithmic probability regression model, L2 regularization and gradient descent method is designed to summarize and analyze cross-platform multi-source information such as FIDO authenticator information, relying party service information, relying party user information, UAF registration and UAF authentication request response log information, and output a trust score. The trust assessment method introduces L2 regularization, namely ridge regression, to effectively alleviate the key model overfitting problem in the field of machine learning. The key algorithm implementation logic of the trust assessment method is briefly described, including the characterization of the minimum solution of the corresponding function of the logarithmic maximum likelihood method, the L2 regularization characterization, the gradient descent method iterative characterization, etc. Make a multi-factor authentication or re-authentication decision based on the trust score and the pre-set threshold to achieve dynamic security authentication.
[0163] Figure 8 A schematic diagram of the structure of a trust assessment device based on a logarithmic probability regression model provided in this application, the device comprising:
[0164] The determination module 11 is used to obtain multi-dimensional data of the target user performing service authentication based on the first factor in the online fast identity authentication FIDO application scenario; determine the characteristic variables corresponding to each of the multi-dimensional data; wherein the multi-dimensional data includes at least one of the authenticator identifier, the relying party service identifier, the relying party user identifier, the user role identifier, and the universal authentication framework UAF authentication response message identifier;
[0165] The evaluation module 12 is used to input the characteristic variables corresponding to each of the multidimensional data into a pre-trained logarithmic probability regression model, determine the target trust score based on the logarithmic probability regression model; and determine the multi-factor authentication judgment result according to the target trust score.
[0166] Furthermore, the determination module 11 is specifically used to perform data preprocessing on the multidimensional data; wherein the data preprocessing includes at least one of data cleaning, data integration, data transformation, and data reduction; the multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each of the multidimensional data.
[0167] Furthermore, the determination module 11 is specifically used to perform standard deviation normalization Z-Score normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data; or to perform minimum and maximum normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data.
[0168] Furthermore, the device also includes:
[0169] The training module 13 is used to input each group of sample data in the training set into the logarithmic probability regression model to be trained, wherein the group of sample data includes sample multidimensional data, a field with a value of 1 and a label field, and the parameter to be trained in the logarithmic probability regression model is a weight vector; the weight vector is estimated by using the logarithmic maximum likelihood method; during the iterative training process, when it is determined that the convergence condition is met based on the estimated weight vector, it is determined that the training of the logarithmic probability regression model is completed.
[0170] Furthermore, the training module 13 is specifically configured to estimate the weight vector using a logarithmic maximum likelihood method and regularization.
[0171] Furthermore, the training module 13 is specifically used to adopt the logarithmic maximum likelihood method and regularization, according to the formula estimating the weight vector;
[0172] in, is the sample multidimensional data and the field with a value of 1 in the i-th sample data. x i is the sample multidimensional data in the i-th sample data; β = (w; b), w is the weight, b is the bias term, β is the weight vector; T represents transposition; y i is the label value in the i-th sample data, which takes 1 or 0, 1 represents multi-factor authentication, and 0 represents no multi-factor authentication; α is the regularization parameter, 0<α<1.
[0173] Furthermore, the training module 13 is specifically configured to determine the magnitude of the gradient vector according to the estimated weight vector, and if the magnitude of the gradient vector is less than a preset first threshold, it is determined that the convergence condition is satisfied.
[0174] Furthermore, the training module 13 is specifically used to train the training data according to the estimated weight vector and Formula, determine the magnitude of the gradient vector;
[0175] Among them, X is m A matrix composed of m y i The matrix composed of.
[0176] Furthermore, the training module 13 is specifically used to determine a change value of a weight vector estimated between two adjacent iterative trainings. If the change value is less than a preset second threshold, it is determined that a convergence condition is satisfied.
[0177] Further, the evaluation module 12 is specifically configured to determine that the multi-factor authentication decision result is to perform multi-factor authentication if the target trust score is greater than a preset third threshold;
[0178] The evaluation module 12 is further configured to determine at least one second factor corresponding to the target trust score range to which the target trust score belongs according to a preset correspondence relationship between each trust score range and at least one factor; and use the at least one second factor to perform service authentication.
[0179] The present application also provides an electronic device, such as Fig. 9 As shown, it includes: a processor 21, a communication interface 22, a memory 23 and a communication bus 24, wherein the processor 21, the communication interface 22, and the memory 23 communicate with each other through the communication bus 24;
[0180] The memory 23 stores a computer program, and when the program is executed by the processor 21, the processor 21 executes any one of the above method steps.
[0181] The communication bus mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0182] The communication interface 22 is used for communication between the above electronic device and other devices.
[0183] The memory may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0184] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.
[0185] The present application also provides a computer storage readable storage medium, wherein the computer readable storage medium stores a computer program executable by an electronic device, and when the program runs on the electronic device, the electronic device implements any of the above method steps when executing.
[0186] The present application provides a computer program product, wherein the computer program product comprises an executable program, and when the executable program is executed by a processor, the method described above is implemented.
[0187] Although the preferred embodiments of the present application have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0188] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A trust assessment method based on a logarithmic probability regression model, characterized in that: The method comprises: In the online fast identity authentication FIDO application scenario, obtain multi-dimensional data of the target user for service authentication based on the first factor; determine the characteristic variables corresponding to each of the multi-dimensional data; wherein the multi-dimensional data includes at least one of the authenticator identifier, the relying party service identifier, the relying party user identifier, the user role identifier, and the universal authentication framework UAF authentication response message identifier; The characteristic variables corresponding to each of the multidimensional data are input into a pre-trained logarithmic probability regression model, and a target trust score is determined based on the logarithmic probability regression model; and a multi-factor authentication judgment result is determined according to the target trust score.
2. The method according to claim 1, characterized in that Determining the characteristic variables corresponding to each of the multidimensional data includes: Performing data preprocessing on the multidimensional data; wherein the data preprocessing includes at least one of data cleaning, data integration, data transformation, and data reduction; The multidimensional data after data preprocessing is normalized to determine the characteristic variables corresponding to each of the multidimensional data.
3. The method according to claim 2, characterized in that The step of normalizing the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data includes: Performing standard deviation normalization Z-Score normalization processing on the multidimensional data after data preprocessing to determine the characteristic variables corresponding to each of the multidimensional data; or The multidimensional data after data preprocessing is subjected to minimum and maximum normalization processing to determine the characteristic variables corresponding to each of the multidimensional data.
4. The method according to claim 1, characterized in that The process of pre-training a log-odds regression model involves: For each group of sample data in the training set, the group of sample data is input into the logarithmic probability regression model to be trained, wherein the group of sample data includes sample multidimensional data, a field with a value of 1 and a label field, and the parameter to be trained in the logarithmic probability regression model is a weight vector; the weight vector is estimated by using the logarithmic maximum likelihood method; during the iterative training process, when it is determined that the convergence condition is met according to the estimated weight vector, it is determined that the training of the logarithmic probability regression model is completed.
5. The method according to claim 4, characterized in that The method of estimating the weight vector by using the logarithmic maximum likelihood method includes: The weight vector is estimated using log-maximum likelihood method and regularization.
6. The method according to claim 5, characterized in that The method of estimating the weight vector by using the logarithmic maximum likelihood method and regularization includes: Using the logarithmic maximum likelihood method and regularization, according to the formula estimating the weight vector; in, is the sample multidimensional data and the field with a value of 1 in the i-th sample data. x i is the sample multidimensional data in the i-th sample data; β = (w; b), w is the weight, b is the bias term, β is the weight vector; T represents transposition; y i is the label value in the i-th sample data, which takes 1 or 0, 1 represents multi-factor authentication, and 0 represents no multi-factor authentication; α is the regularization parameter, 0<α<1.
7. The method according to claim 6, characterized in that The step of determining according to the estimated weight vector that a convergence condition is satisfied comprises: The magnitude of the gradient vector is determined according to the estimated weight vector, and if the magnitude of the gradient vector is less than a preset first threshold, it is determined that a convergence condition is satisfied.
8. The method according to claim 7, characterized in that Determining the magnitude of the gradient vector according to the estimated weight vector includes: According to the estimated weight vector and Formula, determine the magnitude of the gradient vector; Among them, X is m A matrix composed of m y i The matrix composed of 9. The method according to claim 6, characterized in that The step of determining according to the estimated weight vector that a convergence condition is satisfied comprises: The change value of the weight vector estimated by two adjacent iterative trainings is determined, and if the change value is less than a preset second threshold, it is determined that the convergence condition is met.
10. The method according to claim 1, characterized in that Determining the multi-factor authentication decision result according to the target trust score includes: If the target trust score is greater than a preset third threshold, determining that the multi-factor authentication decision result is to perform multi-factor authentication; If it is determined that the multi-factor authentication decision result is to perform multi-factor authentication, the method further includes: According to a preset correspondence relationship between each trust score range and at least one factor, at least one second factor corresponding to the target trust score range to which the target trust score belongs is determined; and the at least one second factor is used for service authentication.
Citation Information
Patent Citations
Multi-factor authentication to achieve required authentication assurance level
CN105144656A
Security authentication method, system and device for network service and computer equipment
CN117061188A
Isolation switch fault risk assessment method and system based on logistic regression, and storage medium
CN118861682A
Substation network security defense system based on artificial intelligence
CN119276602A
PEEiRS: PASSIVE EVALUATION OF ENDPOINT IDENTITY AND RISK AS A SURROGATE AUTHENTICATION FACTOR
US20240419771A1