Continuous user authentication method based on positioning information
Through data fusion of multi-source location information and Kalman filtering algorithm, combined with behavioral learning of LSTM neural network, the problem of traditional positioning authentication methods being susceptible to environmental interference and difficulty in detecting forged identities is solved, and high-precision continuous user authentication and dynamic risk assessment are achieved.
Patent Information
- Application Number
- CN202510457862.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-14
AI Technical Summary
Traditional GPS or WiFi-based positioning authentication methods are susceptible to environmental factors, resulting in large positioning errors, affecting authentication accuracy, and it is difficult to detect forged identity authentication based on user's mobile mode and behavioral characteristics.
Multi-source location information (GPS, Wifi, cellular network and Bluetooth beacon) is used for continuous identity authentication, data fusion and trajectory smoothing are performed through the Kalman filtering algorithm, user behavior feature vector is constructed, and historical behavior learning is combined with LSTM long and short-term memory neural network to detect abnormal trajectories and forged identity behaviors.
It improves the accuracy of user location information, effectively detects abnormal trajectories and forges of identity, reduces the risk of illegal authentication attacks by malicious visitors, and builds an accurate and stable authentication system that supports real-time identity authentication and dynamic risk assessment.
Smart Images

Figure CN119996083A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of user identity authentication, and in particular to a continuous user authentication method based on positioning information. Background Art
[0002] With the development of digitalization and intelligence, user identity authentication has become one of the core technologies to ensure the security of information systems. Traditional identity authentication methods mainly include password authentication, biometric recognition (such as fingerprint, facial recognition) and device-based authentication (such as SMS verification code, hardware token). However, most of these methods are static authentication, that is, users perform one-time authentication when logging in, and cannot continuously monitor the legitimacy of users. They are vulnerable to attacks such as session hijacking and identity theft during the session.
[0003] In order to solve the above problems, continuous identity authentication technology based on behavioral characteristics and environmental information has become a research hotspot in recent years. In particular, identity authentication based on location information can achieve more accurate user identity authentication by continuously collecting user movement trajectories and combining behavioral characteristics analysis. It has broad application prospects, such as financial security, military security, enterprise information system security, and Internet of Things security.
[0004] However, traditional positioning authentication methods based on GPS or WiFi are easily affected by environmental factors, such as signal blocking, reflection, multipath effect, etc., which lead to large positioning errors and affect authentication accuracy.
[0005] In addition, most existing systems are based only on geographic location matching without combining the user's mobility patterns and behavioral characteristics, making it difficult to detect forged identity authentication. For example, attackers may bypass the authentication system through location spoofing technology.
[0006] To address the above issues, it is necessary to propose a continuous user authentication method based on location information. Summary of the invention
[0007] The purpose of the present invention is to solve the problems existing in the background technology and to propose a continuous user authentication method based on positioning information.
[0008] The purpose of the present invention can be achieved through the following technical solutions:
[0009] A method for continuous user authentication based on location information comprises the following steps:
[0010] Step 1: Positioning data collection and preprocessing;
[0011] At every preset time interval Δt, multi-source location information from each user i is collected, including GPS, Wifi, cellular network and Bluetooth beacon, to obtain the location information Xgps(i, t) = (x1t, y1t, z1t) provided by GPS, the location information Xwifi(i, t) = (x2t, y2t, z2t) provided by Wifi, the location information Xcell(i, t) = (x3t, y3t, z3t) provided by the cellular network and the location information Xble(i, t) = (x4t, y4t, z4t) provided by the Bluetooth beacon.
[0012] Construct a spatiotemporal trajectory dataset: . Where N is the total number of target users.
[0013] Use the Kalman filter algorithm to smooth and fuse multi-source location information, reduce errors and noise interference, and improve positioning accuracy. The specific process is as follows:
[0014] Perform state space modeling and construct the state vector of each user i at time t , used to describe the real coordinates and real speed of each user at time t; where, is the real coordinate of the user at time t, is the user's real speed vector at time t. For each user, construct its observation vector at time t , which is used to describe the multi-source location information of each user at time t.
[0015] A state transition model is established to describe the actual movement process of the user. The state transition model formula is: ;in is the state vector of the last preset time interval; where A is the state transfer matrix, describing the influence of the real velocity vector on the real coordinates; ;in is the process noise, which obeys Gaussian distribution: ;in is the covariance matrix of the process noise of user i.
[0016] An observation model is established to describe the relationship between the user's motion process in multi-source location information and the actual motion process. The observation model formula is: ; Where H is the multi-source position transfer matrix, ;in The noise of multi-source location data measurement for user i at time t follows a Gaussian distribution: ;in is the measurement noise covariance matrix of user i, representing the error of the location information obtained through GPS, Wifi, cellular network and Bluetooth beacon.
[0017] Create a prediction step algorithm: ;in is the predicted state vector of user i at time t, representing the optimal estimate of the user coordinates and velocity vector obtained by filtering. is the prediction covariance matrix of user i at time t, representing the uncertainty and error of the user's state estimation before time t; Error propagation caused by state transfer.
[0018] Set up the Kalman gain, state update, and covariance update procedures: ;in is the Kalman gain matrix, which represents the weight of the measurement values of multi-source location information including GPS, Wifi, cellular network and Bluetooth beacon in state estimation. The larger the weight, the greater the influence of the measurement value; where I is the unit matrix.
[0019] After Kalman filtering, the predicted state vector of each user i at time t is obtained: ;in, is the estimated coordinate of user i at time t, is the estimated velocity vector of user i at time t.
[0020] At every preset time interval, the distance between the estimated coordinates of each user i and the estimated coordinates at the last preset time interval is obtained to obtain the first criterion for user identity authentication.
[0021] Step 2: User behavior pattern analysis;
[0022] Based on the predicted state vector of each user i at time t, a user behavior feature vector is constructed, including speed, moving direction and residence time.
[0023] Calculate the total speed of each user i at time t: ;
[0024] Calculate the horizontal movement angle of each user at time t: ;
[0025] Calculate the vertical movement angle of each user at time t: ;
[0026] Calculate the duration of each user's stay at time t. Whenever the user's position change between time t and the last preset time interval, i.e., time t-Δt, is detected, If the distance interval is less than the preset distance interval Lmin, the user i is judged to be in the state of detention between time t-Δt and time t. At every preset time interval, the total time that the user i is judged to be in the state of detention until the current time t is counted and recorded as the total detention time ; At every preset time interval, the total time that user i has not been judged as being in a stuck state until the current time t is counted and recorded as the total exercise time Calculate the total residence time and total exercise time The ratio of is recorded as the hysteresis ratio of the user up to the current moment.
[0027] Construct the user's behavior feature vector: ;
[0028] At every preset time interval, the matching degree between the current behavior feature vector and the historical behavior feature vector is calculated, and the cosine similarity is used for feature comparison:
[0029] Get the historical behavior feature vector of each user i, that is, the data collected at each preset time interval , calculate the average of the specific values of the combined speed, the horizontal movement angle, the vertical movement angle and the hysteresis ratio at each preset time interval: , , and , generate the historical mean vector of the user's behavior characteristics up to the current time t .
[0030] As a preferred method of the present invention, the cosine similarity between the historical mean vector of the behavior characteristics of each user i and the behavior characteristic vector at the current moment is calculated. ;in and They are respectively the modulus of the current behavior feature vector and the historical mean vector of the behavior features.
[0031] Get the second criterion for identity authentication of each user i at the current time t The specific value of the second criterion of identity authentication represents the continuity of the user's behavior characteristics. The larger the value, the more similar the current total speed, horizontal movement angle, vertical movement angle and hysteresis ratio are to the historical data.
[0032] Step 3: Extract historical features of behavioral pattern characteristics;
[0033] The LSTM long short-term memory neural network is used to train historical trajectories, learn users' movement patterns, and capture the potential rules and characteristics in the combined speed, horizontal movement angle, vertical movement angle and hysteresis ratio.
[0034] The behavior feature vector of each user i at each preset time interval Manual labeling to predict labels Representing behavioral feature vector The corresponding judgment result is A value of 1 represents a normal user. A value of 0 indicates an abnormal user.
[0035] The behavioral feature vector and its corresponding prediction label are used as training data for the LSTM long short-term memory neural network. Training and learning are carried out through back propagation and gradient descent algorithms. The weight matrices and bias items of the forget gate, input gate, output gate and memory update unit obtained through training are saved and saved as calculation parameters of the LSTM long short-term memory neural network.
[0036] The weight matrices and bias items of the trained forget gate, input gate, output gate, and memory update unit are substituted back into the LSTM long short-term memory neural network to obtain an LSTM model for behavior pattern feature extraction.
[0037] At every preset time interval, the behavior feature vector of each user i is Input LSTM long short-term memory neural network and get the output prediction label , and recorded as the third criterion for identity authentication of user i at the current moment.
[0038] Step 4: Anomaly detection and risk assessment;
[0039] Based on the first, second and third authentication criteria obtained in steps one to three, authentication anomaly detection is performed.
[0040] At every preset time interval, each user is subjected to the first level identity authentication. The first identity authentication criterion of each user is obtained, and when it is detected that the first identity authentication criterion of user i is greater than a preset threshold, it is determined that the user has a trajectory jump and has failed the first level identity authentication;
[0041] When it is determined that user i has not passed the first level authentication, the second level identity authentication is further performed on the user. The second criterion for the identity authentication of the user is obtained. When the second criterion for the identity authentication of the user is less than a preset threshold, it is determined that the behavior characteristics of the user are discontinuous and the user has not passed the second level identity authentication;
[0042] When it is determined that user i has not passed the third level identity authentication, the third level identity authentication is further performed on the user. The third criterion for the identity authentication of the user is obtained. When the third criterion for the identity authentication of the user is less than a preset threshold, it is determined that the matching result of the potential regularity and characteristics in the user's behavior characteristics is abnormal, and the user has not passed the third level identity authentication.
[0043] Step 5: User identity verification;
[0044] When it is identified that the user has passed one or more combinations of the first level identity authentication, the second level identity authentication, and the third level identity authentication, no unnecessary operations are performed.
[0045] When it is identified that user i has not passed the first level authentication, the user authentication service for the user is stopped and the user is asked to send a text message verification code. When the verification result of the text message verification code is passed, the user authentication service for the user is restarted.
[0046] When it is identified that user i has not passed the second-level authentication, the user's account login status is logged out, the user's user authentication service is stopped, and the user is asked for the account and password submitted during registration. When the account and password verification result is passed, the user's user authentication service is restarted.
[0047] When it is identified that user i has not passed the third-level authentication, the user's account login status is logged out and the user is asked for biometric verification information, including fingerprint, facial recognition information and voiceprint. The administrator is reminded to pay attention to the user movement trajectory of user i. When the verification result of the biometric verification information is passed, the user authentication service of the user is reopened.
[0048] Compared with the prior art, the present invention has the following beneficial effects:
[0049] 1. The present invention uses multi-source location information for continuous identity authentication, and uses the Kalman filter algorithm to perform data fusion and trajectory smoothing to ensure the accuracy of user location information. At the same time, by constructing user behavior feature vectors and combining LSTM long short-term memory neural network for historical behavior learning, abnormal trajectories and forged identity behaviors can be effectively detected. Once an anomaly is found, such as trajectory jumps, behavioral pattern mutations, or potential abnormal pattern matching failures, the system will immediately take security measures to effectively prevent illegal authentication attacks by malicious visitors;
[0050] 2. The present invention builds an accurate and stable authentication system through a multi-level identity authentication strategy (trajectory comparison, behavior feature analysis, and deep learning pattern recognition). First, the positioning data processed based on Kalman filtering reduces noise interference and improves the reliability of location data. Secondly, the cosine similarity is used to calculate the matching degree between the user's current behavior and historical behavior patterns, so that the system can effectively distinguish between legitimate users and potential attackers. Finally, the LSTM neural network is used to further learn the user's movement pattern to ensure that the user's identity can be accurately identified even in a complex dynamic environment, reduce the misjudgment rate, and improve the robustness of authentication;
[0051] 3. The present invention supports real-time identity authentication and dynamic risk assessment. The system can automatically collect and analyze the user's location information and behavior characteristics at each preset time interval, and immediately trigger the multi-level security authentication mechanism when an abnormality is found. The hierarchical authentication method ensures the flexibility and real-time nature of the authentication process, allowing legitimate users to quickly pass the authentication, while malicious visitors find it difficult to bypass security detection, thereby improving overall security and user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings:
[0053] Figure 1 The present invention is a flow chart of the method. DETAILED DESCRIPTION
[0054] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0055] First embodiment:
[0056] See also Figure 1 As shown, a method for continuous user authentication based on location information includes the following steps:
[0057] Step 1: Positioning data collection and preprocessing;
[0058] At every preset time interval Δt, multi-source location information from each user i is collected, including GPS, Wifi, cellular network and Bluetooth beacon, to obtain the location information Xgps(i, t) = (x1t, y1t, z1t) provided by GPS, the location information Xwifi(i, t) = (x2t, y2t, z2t) provided by Wifi, the location information Xcell(i, t) = (x3t, y3t, z3t) provided by the cellular network and the location information Xble(i, t) = (x4t, y4t, z4t) provided by the Bluetooth beacon.
[0059] Construct a spatiotemporal trajectory dataset: . Where N is the total number of target users.
[0060] It should be noted that, assuming that the user's real three-dimensional position coordinates at time t are (xt, yt, zt), but due to noise and measurement errors, the position information directly collected from different data sources has different accuracy and error distribution. By fusing multi-source position information, the user's real position coordinates can be approximately estimated.
[0061] Use the Kalman filter algorithm to smooth and fuse multi-source location information, reduce errors and noise interference, and improve positioning accuracy. The specific process is as follows:
[0062] Perform state space modeling and construct the state vector of each user i at time t , used to describe the real coordinates and real speed of each user at time t; where, is the real coordinate of the user at time t, is the user's real speed vector at time t. For each user, construct its observation vector at time t , which is used to describe the multi-source location information of each user at time t.
[0063] A state transition model is established to describe the actual movement process of the user. The state transition model formula is: ;in is the state vector of the last preset time interval; where A is the state transfer matrix, describing the influence of the real velocity vector on the real coordinates; ;in is the process noise, which obeys Gaussian distribution: ;in is the covariance matrix of the process noise of user i.
[0064] It should be noted that the physical meaning of the state transition model is to reflect the mapping relationship between the user's location information at the previous moment and the location information at the next moment.
[0065] An observation model is established to describe the relationship between the user's motion process in multi-source location information and the actual motion process. The observation model formula is: ; Where H is the multi-source position transfer matrix, ;in The noise of multi-source location data measurement for user i at time t follows a Gaussian distribution: ;in is the measurement noise covariance matrix of user i, representing the error of the location information obtained through GPS, Wifi, cellular network and Bluetooth beacon.
[0066] It should be noted that the physical meaning of the observation model is to reflect the mapping relationship between the user's real location information and the location information obtained through GPS, Wifi, cellular network and Bluetooth beacon.
[0067] Create a prediction step algorithm: ;in is the predicted state vector of user i at time t, representing the optimal estimate of the user coordinates and velocity vector obtained by filtering. is the prediction covariance matrix of user i at time t, representing the uncertainty and error of the user's state estimation before time t; Error propagation caused by state transfer.
[0068] Set up the Kalman gain, state update, and covariance update procedures: ;in is the Kalman gain matrix, which represents the weight of the measurement values of multi-source location information including GPS, Wifi, cellular network and Bluetooth beacon in state estimation. The larger the weight, the greater the influence of the measurement value; where I is the unit matrix.
[0069] After Kalman filtering, the predicted state vector of each user i at time t is obtained: ;in, is the estimated coordinate of user i at time t, is the estimated velocity vector of user i at time t.
[0070] At every preset time interval, the distance between the estimated coordinates of each user i and the estimated coordinates at the last preset time interval is obtained to obtain the first criterion for user identity authentication.
[0071] It should be noted that the estimated coordinates of the same user are continuous. Under good network conditions, the GPS, Wifi, cellular network and Bluetooth beacon data transmission of the same user will not cause delays and packet loss, and the estimated coordinates of the same user will not drift or jump in a very short time interval, which can be used as the basic criterion for continuous user authentication.
[0072] Step 2: User behavior pattern analysis;
[0073] Based on the predicted state vector of each user i at time t, a user behavior feature vector is constructed, including speed, moving direction and residence time.
[0074] Calculate the total speed of each user i at time t: ;
[0075] Calculate the horizontal movement angle of each user at time t: ;
[0076] Calculate the vertical movement angle of each user at time t: ;
[0077] Calculate the duration of each user's stay at time t. Whenever the user's position change between time t and the last preset time interval, i.e., time t-Δt, is detected, If the distance interval is less than the preset distance interval Lmin, the user i is judged to be in the state of detention between time t-Δt and time t. At every preset time interval, the total time that the user i is judged to be in the state of detention until the current time t is counted and recorded as the total detention time ; At every preset time interval, the total time that user i has not been judged as being in a stuck state until the current time t is counted and recorded as the total exercise time Calculate the total residence time and total exercise time The ratio of is recorded as the hysteresis ratio of the user up to the current moment.
[0078] Construct the user's behavior feature vector: ;
[0079] At every preset time interval, the matching degree between the current behavior feature vector and the historical behavior feature vector is calculated, and the cosine similarity is used for feature comparison:
[0080] Get the historical behavior feature vector of each user i, that is, the data collected at each preset time interval , calculate the average of the specific values of the combined speed, the horizontal movement angle, the vertical movement angle and the hysteresis ratio at each preset time interval: , , and , generate the historical mean vector of the user's behavior characteristics up to the current time t .
[0081] Furthermore, the cosine similarity between the historical mean vector of the behavior characteristics of each user i and the behavior characteristic vector at the current moment is calculated ;in and They are respectively the modulus of the current behavior feature vector and the historical mean vector of the behavior features.
[0082] Get the second criterion for identity authentication of each user i at the current time t The specific value of the second criterion of identity authentication represents the continuity of the user's behavior characteristics. The larger the value, the more similar the current total speed, horizontal movement angle, vertical movement angle and hysteresis ratio are to the historical data.
[0083] It should be noted that due to delays and packet loss during data signal transmission, the user's specific location coordinates may jump, affecting the user's continuous identity authentication. However, the user's behavioral characteristics, including speed, moving direction, and hysteresis ratio, are continuous and similar, so different users can be distinguished by behavioral characteristics, and users with similar behavioral characteristics can be marked to provide reference data for continuous user authentication.
[0084] For example, assuming that a user's daily activities are concentrated on the same floor, the user's vertical movement angle The average of the specific values at each preset time interval will approach 0. If the user's account and personal information are leaked, hacked or replaced by an attacker, and the attacker's activity range spans multiple floors, the user's vertical movement angle will change rapidly in a short period of time, which will affect the specific value of the second criterion of the user's identity authentication, resulting in of reduction.
[0085] Step 3: Extract historical features of behavioral pattern characteristics;
[0086] The LSTM long short-term memory neural network is used to train historical trajectories, learn users' movement patterns, and capture the potential rules and characteristics in the combined speed, horizontal movement angle, vertical movement angle and hysteresis ratio.
[0087] The behavior feature vector of each user i at each preset time interval Manual labeling to predict labels Representing behavioral feature vector The corresponding judgment result is A value of 1 represents a normal user. A value of 0 indicates an abnormal user.
[0088] The behavioral feature vector and its corresponding prediction label are used as training data for the LSTM long short-term memory neural network. Training and learning are carried out through back propagation and gradient descent algorithms. The weight matrices and bias items of the forget gate, input gate, output gate and memory update unit obtained through training are saved and saved as calculation parameters of the LSTM long short-term memory neural network.
[0089] The weight matrices and bias items of the trained forget gate, input gate, output gate, and memory update unit are substituted back into the LSTM long short-term memory neural network to obtain an LSTM model for behavior pattern feature extraction.
[0090] At every preset time interval, the behavior feature vector of each user i is Input LSTM long short-term memory neural network and get the output prediction label , and recorded as the third criterion for identity authentication of user i at the current moment.
[0091] It should be noted that the predicted label The actual value is a decimal between 0 and 1, representing the matching result between the user's current behavior pattern and the potential rules and features in the historical behavior pattern.
[0092] Step 4: Anomaly detection and risk assessment;
[0093] Based on the first, second and third authentication criteria obtained in steps one to three, authentication anomaly detection is performed.
[0094] At every preset time interval, each user is subjected to the first level identity authentication. The first identity authentication criterion of each user is obtained, and when it is detected that the first identity authentication criterion of user i is greater than a preset threshold, it is determined that the user has a trajectory jump and has failed the first level identity authentication;
[0095] When it is determined that user i has not passed the first level authentication, the second level identity authentication is further performed on the user. The second criterion for the identity authentication of the user is obtained. When the second criterion for the identity authentication of the user is less than a preset threshold, it is determined that the behavior characteristics of the user are discontinuous and the user has not passed the second level identity authentication;
[0096] When it is determined that user i has not passed the third level identity authentication, the third level identity authentication is further performed on the user. The third criterion for the identity authentication of the user is obtained. When the third criterion for the identity authentication of the user is less than a preset threshold, it is determined that the matching result of the potential regularity and characteristics in the user's behavior characteristics is abnormal, and the user has not passed the third level identity authentication.
[0097] Step 5: User identity verification;
[0098] When it is identified that the user has passed one or more combinations of the first level identity authentication, the second level identity authentication, and the third level identity authentication, no unnecessary operations are performed.
[0099] When it is identified that user i has not passed the first level authentication, the user authentication service for the user is stopped and the user is asked to send a text message verification code. When the verification result of the text message verification code is passed, the user authentication service for the user is restarted.
[0100] When it is identified that user i has not passed the second-level authentication, the user's account login status is logged out, the user's user authentication service is stopped, and the user is asked for the account and password submitted during registration. When the account and password verification result is passed, the user's user authentication service is restarted.
[0101] When it is identified that user i has not passed the third-level authentication, the user's account login status is logged out and the user is asked for biometric verification information, including fingerprint, facial recognition information and voiceprint. The administrator is reminded to pay attention to the user movement trajectory of user i. When the verification result of the biometric verification information is passed, the user authentication service of the user is reopened.
[0102] Second embodiment:
[0103] In this embodiment, taking person A as an example, a specific embodiment of discovering abnormal theft of user authentication services through data collection and analysis is described in detail.
[0104] Assume that the work area of person A is a continuous user authentication monitoring area, and his movement trajectory is required to be strictly monitored. However, a malicious visitor manages to steal or forge A's positioning device and illegally obtains the user authentication service of person A. This article will combine the above steps 1 to 4 to describe how to identify this abnormal situation through the continuous user authentication method and prevent unauthorized access in time.
[0105] Personnel A's location information is collected through multiple sources including GPS, WiFi, cellular networks, and Bluetooth beacons. Data is collected and processed at fixed time intervals to obtain A's precise movement trajectory. Under normal circumstances, A's trajectory should be consistent with his daily work pattern, such as regular movement around a fixed cleaning route within a specified time period.
[0106] When a malicious visitor steals or forges A's positioning device and attempts to forge his identity, his location information will show the following anomalies:
[0107] Abnormal location information that increases the first criterion for identity authentication: abnormal fluctuations in location information caused by loss and mutation of trajectories and rapid jumps in location coordinates; abnormal fluctuations in the smoothing and data fusion results of the Kalman filter algorithm caused by data delays or packet loss through GPS, Wifi, cellular networks, and Bluetooth beacons due to changes in the network environment;
[0108] Abnormal location information that increases the second criterion of identity authentication: A usually has a stable low-speed movement feature during the cleaning process, while an abnormal visitor may show a sudden change in speed, such as suddenly accelerating to a location far away from the daily activity range. A's daily movement direction usually follows certain habitual rules, including trajectory, range, speed and direction rules, including trajectory, range, speed and direction rules, while the trajectory of an abnormal visitor may show random and irregular direction changes, such as quickly leaving the user authentication monitoring area.
[0109] Abnormal location information that increases the third criterion of identity authentication: There are significant differences between the new trajectory pattern and the training data. For example, A never works at night, but the abnormal visitor visits using A's identity late at night; for example, due to the nature of A's work, he often stays briefly at a specific place at a specific time, while the abnormal visitor passes through other areas quickly during that time period.
[0110] At this time, the abnormal visitor will not be able to pass the first-level identity authentication, the second-level identity authentication, and the third-level identity authentication. A's user authentication service will be temporarily frozen to prevent the abnormal visitor from continuing to use his identity to access sensitive areas. The user will be asked to provide a text message verification code, account password, and perform biometric verification. The security personnel will be notified for further investigation and the location of the malicious visitor will be tracked.
[0111] It should be understood that the terms “include” and “comprising” used in the specification and claims of the present disclosure indicate the presence of described features, integers, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0112] It should also be understood that the terms used in this disclosure are only for the purpose of describing specific embodiments and are not intended to limit the disclosure. As used in this disclosure and the claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise. It should also be further understood that the term "and / or" used in this disclosure and the claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes these combinations;
[0113] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to only specific implementation methods. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and use the present invention well. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A method for continuous user authentication based on location information, characterized in that: The following steps are involved: Step 1: Positioning data collection and preprocessing; Collect multi-source location information of the user, and use the Kalman filter algorithm to smooth and fuse the data of the multi-source location information to obtain the optimal estimate of the user's coordinates and velocity vector to improve the positioning accuracy; obtain the first criterion for user identity authentication based on the change of the optimal estimate of the user's coordinates; Step 2: User behavior pattern analysis; Based on the optimal estimation value of the user coordinates and speed vector, the user's behavior characteristics in terms of combined speed, moving direction and dwell time are extracted, and a behavior feature vector is formed according to the extracted behavior feature data; the second criterion for user identity authentication is obtained by comparing the behavior feature vector with the historical behavior feature vector; And calculate the matching degree between current behavior characteristics and historical behavior characteristics; Step 3: Extract historical features of behavioral pattern characteristics; Extract behavioral pattern features, use LSTM long short-term memory neural network to train the user's movement pattern, obtain the predicted label of user behavior based on the behavioral feature vector, and obtain the third criterion for user identity authentication; Step 4: Anomaly detection and risk assessment; Perform multi-level identity authentication based on the first, second and third criteria of identity authentication, screen abnormal users, and conduct risk assessment; Step 5: User identity verification; Users who fail to pass multi-level identity authentication will be subject to graded verification, including SMS verification code, account password verification, and biometric verification, to ensure identity authenticity.
2. A method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of collecting multi-source location information of users and smoothing and fusing data is as follows: At preset time intervals, multi-source location information of each user is collected, including GPS, Wi-Fi, cellular network, and Bluetooth beacon, to obtain location information provided by GPS, location information provided by Wi-Fi, location information provided by cellular network, and location information provided by Bluetooth beacon; The Kalman filter algorithm is used to smooth the data, including establishing a state space model, a state transition model and an observation model, to perform state prediction and update, and to improve the accuracy of user positioning.
3. A method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of obtaining the first criterion of user identity authentication is as follows: The predicted coordinates of the user at the current moment are calculated and compared with the coordinates at the previous moment, and the first criterion for identity authentication is obtained based on the distance difference obtained by the coordinate comparison.
4. The method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of obtaining the second criterion of user identity authentication is as follows: The cosine similarity is used to calculate the matching degree between the current behavior feature vector and the historical behavior feature vector; the historical mean vector of the user behavior feature is calculated, and its cosine similarity with the current behavior feature vector is used as the second criterion for identity authentication.
5. The method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of using LSTM long short-term memory neural network to train the user's movement pattern is as follows: The behavior feature vector of each user i at each preset time interval Manual labeling to predict labels Representing behavioral feature vector The corresponding judgment result is A value of 1 represents a normal user. A value of 0 represents an abnormal user; The behavior feature vector and its corresponding prediction label are used as the training data of the LSTM long short-term memory neural network. The training and learning are carried out through the back propagation and gradient descent algorithms. The weight matrix and bias items of the forget gate, input gate, output gate and memory update unit obtained through training are saved and saved as the calculation parameters of the LSTM long short-term memory neural network. Substitute the weight matrix and bias term of the trained forget gate, input gate, output gate and memory update unit back into the LSTM long short-term memory neural network to obtain an LSTM model for behavior pattern feature extraction; At preset time intervals, the behavioral feature vector of each user is input into the LSTM long short-term memory neural network to obtain the output prediction label, which is recorded as the third criterion for identity authentication of user i at the current moment.
6. A method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of multi-level identity authentication based on the first, second and third criteria of identity authentication is as follows: Perform the first level identity authentication. If the first criterion of identity authentication exceeds the preset threshold, it is determined that the user's trajectory has jumped and the first level authentication has failed; enter the second level identity authentication; Perform the second level identity authentication. If the second criterion of identity authentication is lower than the preset threshold, it is determined that the user behavior characteristics are discontinuous and the second level identity authentication fails. Enter the third level of identity authentication; Perform the third level identity authentication. If the third criterion of identity authentication is lower than the preset threshold, the user behavior characteristics are determined to be abnormal and the third level identity authentication fails.
7. The method for continuous user authentication based on location information according to claim 1, characterized in that: The specific process of performing hierarchical verification on users who fail multi-level identity authentication is as follows: When it is identified that the user has passed one or more combinations of the first level identity authentication, the second level identity authentication, and the third level identity authentication, no unnecessary operations are performed; When it is identified that the user has not passed the first level authentication, the user authentication service of the user is stopped and the user is asked to send a text message verification code; when the verification result of the text message verification code is passed, the user authentication service of the user is restarted; When it is identified that the user has not passed the second-level authentication, the user's account login status is logged out, the user's user authentication service is stopped, and the user is asked for the account and password submitted during registration; When the account and password verification result is passed, the user authentication service of the user is restarted; When it is identified that the user has not passed the third-level authentication, the user's account login status is logged out, and the user is asked for biometric verification information, including fingerprint, facial recognition information and voiceprint; The administrator is reminded to pay attention to the user movement track of the user i; when the verification result of the biometric verification information is passed, the user authentication service of the user is reopened.
8. The method for continuous user authentication based on location information according to claim 1, characterized in that: The total velocity calculation for user behavior pattern analysis is based on the Euclidean distance between the user’s current location and the previous location and converted into a velocity scalar; The movement direction calculation for user behavior pattern analysis is based on the user's speed scalars in the horizontal and vertical directions.
9. The method for continuous user authentication based on location information according to claim 2, characterized in that: The state transition model of the Kalman filter algorithm describes the impact of the user's real velocity vector on the real coordinates, and the process noise follows a Gaussian distribution.
Citation Information
Patent Citations
Mobile device-based mixed identity authentication method
CN106572097A
Continuous identity authentication method and system based on different context environments
CN109871673A
Continuous user authentication method based on positioning information
CN114095233A
Identity authentication system and method based on national cryptographic algorithm
CN119094153A
Identity Authentication Method and Vehicle
US20240386083A1